Privacy Policy
Last updated: August 17, 2026.
This is a working draft pending final legal review. Bracketed fields (such as the contact details in the final section) are placeholders to be completed, and this page should not be treated as the final Privacy Policy before public launch.
Novabit, LLC (“Novabit”, “us” or “we”) respect your privacy and is committed to protecting it through our compliance with this policy. This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process personal information when you use our services, including our websites, mobile applications, and related Services and services (collectively, the “Services”).
The Services include the AthleteDNA member-facing experience and the StudioPulse features, including StudioPulse Monitor. Certain gyms, studios, trainers, coaches, or other business customers may also have their own privacy notices and obligations with respect to information they collect directly from you or process through their relationship with you.
This Privacy Policy applies to personal information collected through the Services, through health and fitness platforms you authorize to connect with the Services, through information provided by gyms, studios, trainers, coaches, or other business customers in connection with the Services, and through communications between you and us.
Please read this policy carefully to understand our policies and practices surrounding your information and how we will handle it. If you do not agree with our practices, you should not use the Services. You agree to this privacy policy by accessing or using the Services and your continued use of our Services following changes is deemed acceptance of such changes, so please check the policy periodically for updates.
1. Information we collect
a. Information you disclose to us
We may collect information that you provide directly to us, including:
- Account information, such as your username, email address, password, and other account credentials;
- Profile information, such as date of birth, sex, height, weight, fitness goals, activity level, and similar information you choose to provide;
- Payment and transaction information when you purchase a subscription or other paid service. Payment card information may be processed directly by our payment service providers rather than stored by Novabit;
- Health and fitness information that you enter into the Services;
- Communications and support information, including information you provide when contacting us; and
- Information you provide when participating in testing, beta programs, surveys, feedback programs, or other voluntary activities.
You warrant that all personal information that you provide to us will be true, complete, and accurate, and you will notify us of any changes to such personal information.
b. Information automatically collected
We automatically collect certain information when you visit, use, or browse the Services. This information does not reveal your unique identity (such as your name or contact information), but may include information about your device and usage, such as your IP address, browser and device features, operating system, language, communication URL, country, location, information about how and when you use our Services and other technical information. This information is essential to maintain the security and operation of our services and for internal analysis and reporting purposes.
c. Health and fitness data
Depending on the features you use and the permissions you provide, we may process health and fitness information, including:
- Heart rate and heart rate variability;
- Steps, distance travelled, floors climbed, and active or sedentary time;
- Calories burned and active energy;
- Sleep duration, stages, and related sleep information;
- Workout and exercise session data, such as type, duration, intensity, pace, and route or GPS data where applicable;
- Body measurements you choose to provide, such as weight and body-composition information, including information imported from InBody or similar body-composition systems where supported;
- Blood oxygen, respiration, stress, recovery, and similar physiological readings where made available through an authorized integration; and
- Other health, fitness, physiological, or wellness information that you choose to provide or authorize us to receive.
We treat health and fitness information as sensitive information and apply additional protections required by applicable law. Where applicable law requires consent or another specific legal condition for processing health information, we will obtain or rely on the applicable legal basis before processing that information.
d. Health and Fitness Platform Data
AthleteDNA currently connects to health and fitness platforms, including Apple HealthKit and Samsung Health Connect. AthleteDNA does not currently connect directly to individual wearable devices. Where you authorize a supported health platform to provide information to AthleteDNA, we receive the categories of information that you authorize through that platform and the permissions available to the Services.
The health platform provider processes information under its own terms and privacy practices. You can manage or revoke the permissions granted to AthleteDNA through the applicable platform or device settings, subject to the functionality and limitations of that platform.
We may support additional health, fitness, or wearable platforms in the future. When new integrations are introduced, we will access only the information necessary for the applicable functionality and as permitted by your authorization and applicable law.
e. Information we receive from gyms, studios, trainers, or coaches
If you use the Services through a gym, studio, trainer, coach, or other business customer, we may receive information from that organization or person to establish your account, connect you to a program or service, administer the relationship, provide the requested Services, or support authorized coaching and fitness activities. Depending on the configuration of the Services, this may include account and profile information, membership or program information, workout or performance information, and related insights.
f. Information generated or inferred by the Services
The Services may generate derived or inferred information from the information described above. This may include performance trends, recovery or readiness indicators, engagement insights, recommendations, summaries, risk indicators, churn-related scores, and other analytics. These outputs may be generated using models, algorithms, artificial intelligence, or machine-learning technologies.
2. Use of your information
We may use your information for the following purposes:
- To create, maintain, authenticate, and secure accounts;
- To provide, operate, maintain, and improve the Services;
- To provide AthleteDNA features, including performance reports, workout summaries, trends, goal tracking, readiness or recovery insights, and related analytics;
- To provide StudioPulse and StudioPulse Monitor functionality to authorized gyms, studios, trainers, coaches, and other business customers;
- To facilitate coaching, gym, studio, and training services, including sharing information or insights with authorized recipients as described in this Privacy Policy and the applicable consent or business arrangement;
- To personalize features, recommendations, goals, content, and user experiences;
- To process transactions and provide customer support;
- To communicate with you about the Services, including service-related notices, security notices, account notices, and support matters;
- To conduct testing, debugging, analytics, quality assurance, research, and service improvement;
- To detect, prevent, and investigate fraud, abuse, security incidents, and other harmful or unlawful activity;
- To comply with applicable legal obligations and respond to lawful requests from authorities;
- To evaluate or conduct a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar business transaction; and
- For other purposes disclosed at the time of collection or otherwise permitted by applicable law.
3. Our compliance
Legal basis for processing personal information under GDPR / UK GDPR
We may process personal information under the following conditions:
- Consent. You have consented to us processing your personal information for a specific purpose.
- Performance of a contract. The provision of personal information is necessary for the execution of a contract with you and/or for pre-contractual obligations.
- Legal obligations. The processing of personal information is necessary for the fulfilment of a legal obligation to which Novabit is subject.
- Vital interests. The processing of personal information is necessary to protect your important interests or the important interests of another natural person.
- Public interests. The processing of personal information is related to an activity carried out in the public interest or in the exercise of the official power vested in Novabit.
- Legitimate interests. The processing of personal information is necessary for the legitimate interests pursued by Novabit.
Health and fitness data receives additional protection. Because this information is “special category data” under Article 9 of the GDPR and UK GDPR, we rely on your explicit consent as our legal basis for processing it. Where consent is required, Novabit will seek consent through an appropriate affirmative action and will provide information sufficient for the individual to understand what is being consented to. You can manage this consent in the ‘Your Consent Choices’ section within your account settings, and you may withdraw it at any time.
In any case, Novabit will be happy to help you clarify the specific legal basis for the processing, especially if the provision of personal information is a legal or contractual requirement, or a requirement that needs to be met for contracting.
Your Rights under the GDPR
Novabit undertakes to respect the privacy of your personal information and to ensure that you can exercise your rights. You have the right under this privacy policy, and by law if you are within the EU or UK, to:
- Request access to your personal information. The right to access, update or delete the information we have about you. Whenever possible, you can request access to, update or request deletion of your personal information directly within your account settings section. If you are unable to perform these actions yourself, please contact us for assistance.
- Request the correction of the personal information we hold about you.
- Object to the processing of your personal information. This right remains when we rely on legitimate interests as a legal basis for processing and in certain circumstances related to your situation that require you to object to the processing of your personal information on this basis. You also have the right to object to the processing of your personal information for legitimate marketing purposes.
- Request that your personal information be deleted. You have the right to ask us to remove or delete personal information without compelling reasons for us to continue to do so.
- Request the transfer of your personal information. We will provide your personal information to you or to a third party of your choice in a structured, user-friendly, and machine-readable format. Please note that this right only applies to automated information that you initially consented to us using, or when we use that information to perform a contract with you.
- Withdraw your consent. You have the right to withdraw your consent to our use of your personal information. If you withdraw your consent, we may not be able to provide you with access to certain features of the Service.
Your rights under the GDPR / UK GDPR
Lodge a complaint. Under the UK’s Data (Use and Access) Act 2025, we operate a data protection complaints process: you may complain to us directly, and we will acknowledge your complaint within 30 days and respond without undue delay.
You can exercise your right of access, rectification, cancellation, and opposition by contacting us. Please note that we may ask you to verify your identity before responding to such requests. We will do our best to respond to your request as soon as possible.
Your privacy rights in the United States
Depending on your state of residence, you may have additional rights under U.S. state privacy laws. Where these laws apply to you, they commonly give you the right to:
- Know what personal information we have collected about you, and access a copy of it.
- Delete personal information we hold about you.
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information and of targeted advertising.
- Limit the use of your sensitive personal information, including health information
- Not be discriminated against for exercising any of these rights
Novabit is not a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act (HIPAA), and the health and fitness information you provide through the Services is generally not protected by HIPAA.
Your Rights under California Consumer Protection Act (“CCPA”)
This section applies only to California residents. Under CCPA, you have the rights listed below.
The California Code of Regulations defines a “resident” as:
- every individual who is in the State of California for other than a temporary or transitory purpose; and
- every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose.
All other individuals are defined as “non-residents”.
If this definition of “resident” applies to you, Novabit must adhere to certain rights and obligations regarding your personal information.
Your rights with respect to your personal data
- Right to request deletion of the data. If you ask Novabit to delete your personal information, Novabit will respect your request and delete your personal information, subject to certain exceptions provided by law.
- Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights.
- Verification process. Upon receiving your request, Novabit will need to verify your identity to determine you are the same person about whom Novabit has the information in our system. These verification efforts require Novabit to ask you to provide information so that Novabit can match it with information you have previously provided Novabit.
Your Rights under Swiss Federal Act on Data Protection
Where the Swiss Federal Act on Data Protection (“FADP”) applies, Novabit will process personal data in accordance with applicable Swiss requirements. This includes providing appropriate information about the identity and contact details of the controller, purposes of processing, categories of data and recipients, international disclosures and applicable safeguards, retention or retention criteria, and rights available under Swiss law.
Individuals in Switzerland may have rights under the FADP, including rights to information and access, correction, deletion where applicable, and data portability, subject to statutory conditions and exceptions. Where an automated individual decision is made within the meaning of applicable Swiss law, Novabit will provide the notices and rights required by the FADP, including applicable rights to information about the decision and human review.
4. Artificial intelligence and automated processing
We may use third-party artificial intelligence and machine-learning service providers to support some features. Where a third-party provider processes information on our behalf, we will use safeguards appropriate to the provider’s role and applicable law. These outputs are intended to provide informational and decision-support functionality.
AI-generated or algorithmically generated outputs may be incomplete, inaccurate, or unsuitable for a particular individual or circumstance. Users should exercise appropriate judgment and should not rely on such outputs as a substitute for professional medical, healthcare, or other qualified professional advice.
5. Sharing of your personal information
We respect your privacy and understand that your information is important for you. We may disclose personal information in the following circumstances:
- For business transfers. We share or transfer your personal information to another company in connection with or during negotiations for a merger, acquisition of our company’s assets, financing or sale of all or any part of our company.
- With your consent. We may disclose your personal information for other purposes with your consent.
- Health and Fitness platform Integrations. When you authorize a health or fitness platform integration, information may be exchanged with that platform according to the permissions and functionality you authorize.
- With gym staff, trainers, and coaches. We share relevant performance insights such as program completion, or summary performance trends with the gym, personal trainer, or coach connected to your account. Your gym or coach acts as an independent controller of the information shared with them, and their further use of it is governed by their own privacy practices, not this policy. If you withdraw the consent, we will stop sharing new information, but your gym or coach may retain information already shared with them under its own retention practices, please contact them directly to request its deletion.
- With service providers and sub-processors. We may engage third-party service providers to perform services on our behalf, including categories such as cloud hosting and storage, authentication, payment processing, customer communications, artificial intelligence and machine-learning services, analytics and security, health and fitness platform integrations, gym or studio management integrations, and technical support. Where a provider acts as our processor or sub-processor, we require appropriate contractual obligations concerning confidentiality, security, and use of personal information.
- Legal and Safety Reasons. We may disclose information when reasonably necessary to comply with law, regulation, legal process, or governmental requests; enforce our agreements; protect the rights, safety, or property of Novabit, our users, or others; detect or prevent fraud or security incidents; or otherwise as permitted or required by law.
Novabit does not sell personal information for monetary consideration. We also do not sell health or fitness information. We do not use health information obtained through Apple HealthKit for advertising, targeted advertising, or use-based data mining, and we do not disclose or sell such information to advertising platforms. Any future use of health information will remain subject to applicable law, user authorization where required, and applicable platform requirements.
6. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by applicable law. Our retention periods may vary depending on the nature of the information, the purpose for which it was collected, contractual requirements, legal obligations, security needs, and whether the information remains necessary to provide the Services.
Subject to applicable law and actual system capabilities, our general retention approach is:
- Account and profile information: while your account is active and generally for up to 12 months after account closure, unless a longer period is required for legal, security, contractual, or dispute-resolution purposes;
- Health, fitness, and connected-platform information: while your account is active and generally for up to 12 months after account closure, subject to applicable law, contractual requirements, and deletion limitations of systems;
- Transaction and payment records: for the period required by applicable tax, accounting, financial, or other legal requirements;
- Security and technical logs: generally up to 12 months, unless a longer period is reasonably necessary for security investigations, fraud prevention, or legal purposes; and
- Backup copies: may remain in secure backups for a limited period, generally up to 90 days after deletion from active systems, subject to backup architecture and legal requirements.
We may retain de-identified or aggregated information that can no longer reasonably be associated with an individual for longer periods, including for analytics, research, security, and service-improvement purposes. If a shorter retention period is required by applicable law or a contractual obligation, the shorter period will apply.
7. International data transfers
Novabit and its service providers may process personal information in countries other than your country of residence, including the United States. Where applicable law requires a transfer mechanism or other safeguard, Novabit will rely on an applicable adequacy decision or other legally recognized mechanism. Depending on the transfer and jurisdiction, Novabit may implement appropriate safeguards for international transfers, including relying on legally recognized transfer mechanisms.
Where required, Novabit may implement additional contractual, technical, or organizational safeguards appropriate to the transfer. The actual transfer mechanism used for a particular vendor depends on the vendor’s location, certification status, contractual arrangements, and the applicable jurisdiction.
8. Data security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction. The measures used may include access controls, authentication, encryption where appropriate, logging, monitoring, secure development practices, vendor controls, and other safeguards appropriate to the nature of the information and the risks involved.
No method of transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for using the Services in a reasonably secure environment
9. Data security incidents and breach notification
If Novabit becomes aware of a security incident involving personal information, we will investigate and take reasonable steps to contain, remediate, and assess the incident. Where notification is required by applicable law, we will notify affected individuals, customers, regulators, or other parties within the timeframes and using the methods required by the applicable law. Notification may be delayed where permitted by law, including where necessary to avoid compromising an investigation or law-enforcement activity.
10. Cookie disclosure
We currently use cookies and similar technologies that are necessary for the operation, security, authentication, and functionality of the Services. We do not currently use non-essential advertising or tracking technologies for targeted advertising based on health or fitness information.
If we introduce analytics, advertising, pixels, or other non-essential tracking technologies in the future, we will update this Privacy Policy and implement consent, opt-out, or other controls where required by applicable law.
11. HIPPA
Unless otherwise expressly agreed in writing, Novabit does not currently operate as a HIPAA covered entity or business associate with respect to consumer health and fitness information processed through the Services. Information concerning health or fitness is not necessarily “protected health information” under HIPAA merely because it concerns an individual’s health or fitness.
If Novabit enters into a relationship or arrangement that causes HIPAA to apply, the applicable contractual and compliance requirements, including any required business associate agreement, will be addressed separately.
12. Links to other sites
The Services may contain links to third-party websites, applications, platforms, or services that we do not control. Third-party services may collect or process information under their own privacy notices. We encourage you to review the privacy practices of any third-party service before providing information or connecting an account.
13. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly permit individuals under 13 to create accounts or use the Services. If we learn that we have collected personal information from a person under 13 in circumstances where collection was not permitted by applicable law, we will take reasonable steps to delete the information.
If a jurisdiction imposes a different mandatory age threshold or parental-consent requirement for a particular service, we will apply the requirements of that jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our Services, data practices, technology, legal requirements, or business operations. We will post the updated Privacy Policy and update the “Last Updated” date. Where required by applicable law, we will provide additional notice or obtain consent before implementing material changes to our processing activities.
15. Contact us
If you have questions, concerns, or requests relating to this Privacy Policy or your personal information or to exercise a privacy right, please contact us:
- Novabit, LLC
- 520 N Kingsbury St, Chicago, IL 60654, United States
- Website: www.myathletedna.com
- Privacy email: hello@myathletedna.com
If an EU representative, UK representative, Swiss representative, or other local representative is appointed in the future where required by applicable law, the applicable representative’s details will be added to this Privacy Policy.