Key Points — Plain-Language Summary
This summary is for convenience only. The full policy below governs our handling of your consumer health data.
- What this policy covers: Health questionnaire responses, habit completion records, HealthKit-derived data, wellness scores, and custom health habits.
- We do NOT sell your health data. Ever.
- Why we collect it: To provide personalized habit recommendations, track your progress, and generate your wellness score.
- Who sees it: Only Supabase (our database provider). Not advertisers, not analytics platforms, not data brokers.
- Your rights: You can access, delete, or withdraw authorization for your health data at any time.
- Two separate consents: We obtain separate consent for the health disclaimer (liability) and health data processing (data use) — they are never bundled.
- No geofencing: We never use location tracking near healthcare facilities.
- Contact: support@theparallellab.com
This Consumer Health Data Privacy Policy is published in compliance with the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (SB 370), and similar state consumer health data laws. This policy supplements our general Privacy Policy and applies specifically to "Consumer Health Data" as defined by applicable state law.
This policy is maintained by Parallel Labs Pte. Ltd., a company incorporated in the Republic of Singapore ("Company," "we," "us," or "our").
1. Categories of Consumer Health Data Collected
We collect the following categories of Consumer Health Data through the Thrive mobile application ("App"):
| Category | Description | Source |
|---|---|---|
| Health Questionnaire Responses | Self-reported data about sleep quality, energy levels, exercise habits, stress, dietary habits, supplement use, and lifestyle factors relevant to men's health | Directly from you during onboarding and periodic reassessments |
| Habit Completion Records | Records of which health-related habits you completed and when, including habits related to exercise, sleep, nutrition, and stress management | Directly from you through in-app tracking |
| HealthKit-Derived Data | Habit completion records auto-generated from Apple HealthKit data (e.g., "steps goal met"), where you have granted HealthKit access. Raw biometric values from HealthKit are not stored on our servers. HealthKit integration will be available in a future release. | From Apple HealthKit with your explicit authorization (when feature is available) |
| Wellness Scores and Profiles | Algorithmically generated wellness scores and wellness profile categorizations based on your questionnaire responses | Generated by the App from data you provide |
| Custom Health Habits | Custom habits you create related to health and wellness, including their names, descriptions, and schedules | Directly from you |
2. Purpose of Collection
We collect Consumer Health Data solely for the following purposes:
- Providing Core App Functionality: Generating your personalized wellness score, wellness profile, and habit recommendations.
- Habit Tracking: Recording and displaying your habit completion history, streaks, and progress.
- Personalization: Tailoring in-app content, insights, and recommendations to your health profile.
- App Improvement: Analyzing aggregated, de-identified usage patterns to improve App features (we do not use identifiable Consumer Health Data for this purpose).
We do not collect Consumer Health Data for advertising, marketing to third parties, or data mining purposes.
2.1 Retention of Consumer Health Data
We retain Consumer Health Data only for as long as necessary to fulfill the purposes described in this policy:
| Category | Retention Period |
|---|---|
| Health Questionnaire Responses | Duration of your account; permanently deleted within 30 days of account deletion |
| Habit Completion Records | Duration of your account; permanently deleted within 30 days of account deletion |
| HealthKit-Derived Data | Raw HealthKit data is processed in real-time and not stored on our servers. Derived habit completion records (e.g., "steps goal met") are retained for the duration of your account |
| Wellness Scores and Profiles | Duration of your account; permanently deleted within 30 days of account deletion |
| Custom Health Habits | Duration of your account; permanently deleted within 30 days of account deletion |
| Consent Records | For the duration of the processing activity, plus a minimum of 5 years after account deletion or consent withdrawal, to demonstrate compliance |
3. Sources of Consumer Health Data
All Consumer Health Data is collected from:
- You directly: Through your responses to the health and lifestyle questionnaire, your habit completion inputs, and custom habits you create.
- Apple HealthKit: With your explicit, informed authorization through the iOS system permission prompt. You may revoke HealthKit access at any time through your device's Settings > Health > Data Access & Devices.
We do not collect Consumer Health Data from third-party data brokers, public records, or any source other than those listed above.
4. Sharing of Consumer Health Data
We do not sell Consumer Health Data.
We share Consumer Health Data only with the following categories of service providers, pursuant to written contracts that require equivalent protections:
| Service Provider | Purpose | Consumer Health Data Shared |
|---|---|---|
| Supabase, Inc. | Database hosting and storage | Health questionnaire responses, habit completion records, wellness scores, custom habits |
Important: Our payment processing, subscription management, and push notification providers do not receive Consumer Health Data. They receive only pseudonymous user IDs, subscription data, device tokens, and technical metadata.
5. Your Rights
Under the Washington My Health My Data Act and similar state consumer health data laws, you have the following rights:
5.1 Right to Know
You have the right to confirm whether we are collecting, sharing, or selling your Consumer Health Data, and to know the specific categories of Consumer Health Data we have collected about you.
5.2 Right to Access
You have the right to request access to your Consumer Health Data. You may submit an access request by contacting us at support@theparallellab.com.
5.3 Right to Deletion
You have the right to request deletion of your Consumer Health Data at any time. To exercise this right:
- In the App: Navigate to Settings > Account > Delete Account.
- By email: Send a deletion request to support@theparallellab.com from the email address associated with your account.
Upon receiving a verified deletion request, we will delete your Consumer Health Data within 30 days and direct our service providers to do the same.
5.4 Right to Withdraw Authorization
You may withdraw your authorization for the collection and use of Consumer Health Data at any time by:
- Deleting your account (which deletes all Consumer Health Data).
- Contacting us at support@theparallellab.com to request deletion of health questionnaire data while retaining your account in a limited capacity.
- Revoking HealthKit access through your device settings.
Withdrawal of authorization does not affect the lawfulness of processing carried out before the withdrawal.
6. Authorization and Consent
We obtain your affirmative authorization before collecting, sharing, or using Consumer Health Data for any purpose. During the App's onboarding process, you are presented with two separate, distinct actions:
- Health Disclaimer Acknowledgment — a separate screen confirming you understand the App is not medical advice and does not provide medical diagnosis or treatment. This is a liability acknowledgment only and does not constitute authorization for data processing.
- Health Data Processing Consent — a separate, standalone consent screen that specifically authorizes us to collect, process, and store your Consumer Health Data (including health questionnaire responses, habit completion records, HealthKit-derived data, wellness scores, and custom health habits) for the purposes described in Section 2 of this policy. This consent screen lists: (a) the specific categories of Consumer Health Data to be collected; (b) the purposes of collection; and (c) the categories of third parties with whom your data may be shared.
These two actions are presented separately, require independent affirmative action (e.g., separate taps or checkboxes), and cannot be combined into a single acceptance. Your Health Data Processing Consent is recorded with a timestamp and serves as the affirmative authorization required under the Washington My Health My Data Act (RCW 19.373), Nevada SB 370, and similar state consumer health data laws.
We will obtain your separate, affirmative authorization before:
- Collecting any new category of Consumer Health Data not described in this policy.
- Sharing Consumer Health Data with any new category of third party not described in this policy.
- Using Consumer Health Data for any purpose not described in this policy.
Your authorization is recorded with a timestamp and retained in accordance with our data retention practices.
7. Geofencing
We do not use geofencing technology to establish a virtual boundary around a physical health care facility (including but not limited to hospitals, clinics, mental health facilities, reproductive health clinics, or pharmacies) for the purpose of collecting Consumer Health Data, identifying or tracking consumers, sending notifications, or targeting advertising.
8. Exercising Your Rights
To exercise any of the rights described in this policy, contact us at:
- Email: support@theparallellab.com
We will respond to verified requests within 30 days (or within any shorter period required by applicable law).
Identity Verification: We will verify your identity before processing your request. Primary verification is performed by confirming that the request originates from the email address associated with your account. If you use Apple's "Hide My Email" private relay service, or if we cannot verify your identity through email alone, we may request additional verification, such as: (a) confirming your date of birth and account creation date; (b) verifying through the App while logged in to your account; or (c) other reasonable verification methods consistent with applicable law. We will not require you to create a new account or provide unnecessary personal information solely for the purpose of verification.
We will not discriminate against you for exercising your rights under this policy. Exercising your rights will not result in denial of services, different pricing, or a different level of service quality, except to the extent that the requested action (e.g., deletion of health data) makes certain personalized features unavailable.
8.1 Right to Appeal
If we deny or are unable to fully fulfill your request, you have the right to appeal our decision. To submit an appeal, email support@theparallellab.com with the subject line "Consumer Health Data Appeal." We will respond to your appeal within 30 days. If we deny your appeal, our response will include the reasons for the denial and information on how to file a complaint with your state Attorney General's office or other applicable regulatory authority.
9. Nevada-Specific Provisions (SB 370)
If you are a Nevada resident, the following additional provisions apply under Nevada's Consumer Health Data Privacy Law (SB 370, effective March 31, 2025):
- Definition: "Consumer health data" under Nevada law includes data that identifies or is reasonably linkable to a consumer and relates to the past, present, or future physical or mental health of the consumer. Your health questionnaire responses, habit completion records, HealthKit-derived data, wellness scores, and custom health habits constitute consumer health data under this definition.
- No Sale: We do not sell your consumer health data as defined under SB 370.
- Affirmative Consent: We obtain your affirmative, voluntary consent before collecting your consumer health data, as described in Section 6 of this policy.
- Right to Revoke Consent: You may revoke your consent to the collection of consumer health data at any time by deleting your account or contacting us at support@theparallellab.com. Revocation does not affect the lawfulness of processing carried out before the revocation.
- Geofencing Prohibition: We do not use geofencing to establish a virtual boundary around any physical health care facility for the purpose of collecting consumer health data, in compliance with Nevada SB 370.
- Response Timeframe: We will respond to verified requests within the timeframe required under Nevada law, as described in Section 8 of this policy.
- Enforcement: Nevada residents may file complaints regarding violations of SB 370 with the Nevada Attorney General's office.
10. Changes to This Policy
If we make material changes to this Consumer Health Data Privacy Policy, we will notify you via email and/or a prominent in-app notification at least 30 days before the changes take effect. For changes that materially expand the collection, use, or sharing of Consumer Health Data, we will obtain your renewed affirmative authorization before the changes take effect.
11. Relationship to General Privacy Policy
This Consumer Health Data Privacy Policy supplements our general Privacy Policy. In the event of a conflict between this policy and our general Privacy Policy with respect to Consumer Health Data, this policy shall prevail.