Privacy Policy
Last updated: 2026-05-04
Privacy is supposed to be simple.
Here's the short version: we securely keep what you give us, use it to show you your health balance, and that's it. We don't share it with third parties, and we don't sell it. We never have, and we never will.
That's it. Want the long version? Read on - we've tried to keep this as friendly and understandable as possible.
Who we are
Bank of Health helps you see your health the way you see your money — as a balance, built by your daily choices. It's made by The Good Years Project, LLC. If you have questions about this policy or your data, you can reach us at [email protected].
What we collect and why
We only collect what we need. Here's what that means in practice:
Identity & access
When you sign up, we ask for your email address, a password and optionally your first name. That's it. We use your email and password to log you in. We use your email to send you notifications, and to contact you if needed. If you give us your first name, we use it to personalize the site (e.g. "Hi, Steven"). We don't sell or share your identity information with anyone.
Your health data
Bank of Health runs on your health data — that's the whole product. Because it's health data, we ask for your explicit consent before we store any of it, and we treat it with the care it deserves. That consent is the legal basis we rely on to process your health data (GDPR Article 9(2)(a)), and you can withdraw it at any time by deleting your data. Specifically, we keep:
- Your basic health profile — age, sex, height, weight, and country
- Your daily logs — workouts, sleep, drinks, smoking, weight, and social time
- Your health history — the decade-by-decade habits you share during onboarding
- Connected tracker data — if you connect a fitness tracker (Apple Health, Google Health, Whoop, Strava, Oura), we receive the workouts, sleep, weight, and recovery data those services send us
This data is used solely to calculate your numbers and show you your balance. We never share your health data with anyone. We don't sell it, we don't give it to advertisers, and we don't feed it to an AI.
Billing information
Bank of Health is a subscription, and payments are processed by Stripe. We never see or store your full credit card number. We keep a record of your subscription status, your Stripe customer ID, and your transaction history for accounting and support. Where sales tax or VAT applies, Stripe collects your billing country (and VAT ID, if you provide one) so the right tax is charged; we keep those records for accounting.
Website analytics
We collect basic, first-party analytics (page views, feature usage) to understand how Bank of Health is used and to fix bugs. We do not use any third-party analytics or tracking services. No Google Analytics, no Facebook pixels, nothing like that.
Cookies
We use essential cookies only — a session cookie to keep you logged in and a CSRF cookie to protect against cross-site attacks. That's it. We don't use advertising cookies, tracking cookies, or any third-party cookies. Our cookies are:
- Essential for the service to function (authentication and security)
- Encrypted and served over HTTPS only
- Session cookie expires after 90 days of inactivity (refreshed each time you visit)
- CSRF cookie is temporary (cleared when you close your browser)
When we access or share your data
We don't sell your data to anyone, and we don't share it with third parties for marketing.
Here are the limited cases where your data may be accessed or shared:
- To sync tracker data: If you connect a fitness tracker, we exchange data with that provider (Whoop, Strava, or Oura) using your authorized connection. We only request the data needed to power Bank of Health, and you can disconnect at any time.
- To process payments: Stripe processes your payment information and, where tax applies, your billing country.
- To send email: Amazon SES (Simple Email Service) delivers transactional emails like account verification, notifications, and your weekly recap. Only your email address is shared with AWS for this purpose.
- To send notifications: If you turn on push notifications, we deliver them through Apple (APNs), Google (Firebase Cloud Messaging), or your browser's push service. They receive your device's push token and the text of the notification — never your health data.
- To fix problems: If you contact support or something breaks, we may need to look at your account data to help. We'll never access your content without a reason.
- When required by law: If we receive a legally binding request from law enforcement, we will comply. We will notify you if legally permitted to do so.
Your rights
We respect your rights over your data. These rights apply to all users, regardless of where you live:
- Right to access: You can export all of your data at any time from your settings.
- Right to correction: You can update your profile and logs at any time in the app.
- Right to erasure: You can delete your health data, or your whole account, from your settings in a couple of clicks. When you do, we permanently delete it. Anonymized cost records are retained for accounting.
- Right to portability: Our data export gives you a complete file of all your data that you can take anywhere.
- Right to object: You can contact us at any time to object to processing of your data.
If you're in the EU, you also have the right to lodge a complaint with your local data protection authority.
For Washington residents
This page also serves as our Consumer Health Data Privacy Policy under Washington's My Health My Data Act. Everything above applies: what we collect, why, who can access it, and how to exercise your rights.
Data security
All data is transmitted over HTTPS/TLS. Passwords are hashed and never stored in
plain text. Tracker connection tokens are encrypted at rest. Session cookies are encrypted and marked Secure, HttpOnly, and
SameSite=Lax. Our servers are hosted in the EU. We maintain automated backups, access restrictions, and data security policies consistent with industry standards.
Data retention and deletion
We keep your data for as long as you have an active subscription (or trial). Health data shouldn't sit around without a good reason, so when your subscription ends, you choose what happens to yours:
- Delete it now. We permanently delete your health data right away.
- Keep it for one year. If you think you might come back, we'll hold your data for one year. We'll remind you by email before that year is up, and if you haven't returned, we'll permanently delete it.
If you don't choose, we default to keeping your data for one year and then deleting it — with reminders first, so nothing disappears by surprise. You can export everything, or delete everything, at any point along the way.
Backups that contain deleted data are cycled out within 30 days. Anonymized cost records may be retained for accounting.
Data location
Our servers are hosted in the EU (Finland). Payment processing through Stripe may involve data transfer to the United States. By using the service, you consent to this transfer.
Changes to this policy
We may update this policy from time to time. If we make significant changes, we'll notify you by email or by placing a prominent notice on the site. The date at the top of this page tells you when the policy was last updated.
Questions?
If you have any questions about this policy or your data, please contact us at [email protected].
This privacy policy is adapted from the Basecamp open-source policies, used under CC BY 4.0. Thank you, Basecamp, for making these available.