JST Fitness — Consumer Health Data Privacy Policy
Last updated: 21 August 2026
This document is the Consumer Health Data Privacy Policy required by Washington State's My Health My Data Act. It is a separate document from our general Privacy Policy — linked at the foot of this page — which still applies to everything else the app does: accounts, error reports, feedback and the rest.
It covers consumer health data: the health-related information you type into JST Fitness. If you are a Washington or Nevada resident, this page is written for you, but the practices it describes are the same for everyone who uses the app, wherever they live.
What consumer health data we collect, and why
Almost everything in this list is data you type in yourself. There is no sensor reading it and no third party sending it to us. (If you switch on Lock the app, your phone's fingerprint sensor runs a lock check — the app never receives a fingerprint, and nothing from that sensor is in this list, on our servers, or anywhere else in the app.) The one thing the app works out for itself is named at the bottom of this list, because working something out from what you typed still counts as collecting it.
- Your body weight — every weight you log, with its date. Collected so the app can show you your own weight history, chart your trend, and measure progress towards a goal you set.
- Your body measurements — waist, chest, arms and the other measurements the app offers. Collected so the app can show you those numbers over time, for the same reason as weight.
- The figures behind BMI, BMR and TDEE — your height, your age (from the date of birth you entered), your sex and your activity level, plus the BMI/BMR/TDEE results calculated from them. Collected because the calorie and macro maths cannot run without them: these are the inputs to your daily calorie target, and there is no way to produce that number without them.
- Your food log — the meals and foods you record, their calories and macros, any recipes you build, and your calorie and macro targets. Collected so the app can total your day against your target and show you your own eating history.
- Your water log — how much water you record drinking, with dates. Collected so the app can show you your daily total against your goal.
- Your workout history — the exercises, sets, reps and weights you log, and your routines and schedule. Collected so the app can show you what you did, what you lifted last time, and how it is changing. Some rows record time rather than reps — a yoga segment is logged in minutes, a follow-along interval in seconds — and the session remembers which it was. If you mark a set as bodyweight ("BW"), the app records your most recent logged body weight as that set’s weight so the session’s volume adds up — a copy of a weight you already entered, not a new measurement. A session can also carry one optional "Following" line: free text you type naming a class, a channel, a video title or a link you paste. It is stored with the session and syncs with it, and because it is free text, whatever you choose to put in it is treated as consumer health data like the rest of the session. The app only stores it and shows it back to you: it never loads the page, never fetches a thumbnail, and never tells anyone you watched anything.
- Your step count, if you switch on Health Connect — the daily total, plus today's hourly entries while you have that breakdown open (those are never saved) — read from Android's Health Connect with your permission. Collected only to show you your own steps inside the app. This one never leaves your device at all, not even to your own account: it is excluded from cloud sync deliberately.
- Your meditation log — how long each session lasted and the day you sat, written down when you use the timer. Collected only to show you your own practice inside the app. The log itself never leaves your device, not even to your own account, and that was a deliberate decision rather than an oversight: a record of a mind-and-body practice is the kind of thing we would rather not hold on a server. It is included in the backup file you can export, so it remains yours to keep and to move. One exception, stated rather than buried: three achievements are earned from this log — a first sit, ten days sat, five hundred lifetime minutes — and unlocked achievements do sync with your account, together with the date each unlocked. So we can hold the fact that you passed one of those three marks, and when. Never a session, never a length, never a list of days. One smaller side effect, named rather than left out: sitting earns XP like everything else in the app, so the number of days you have sat forms part of your level — and your level is one of the counts that can be attached to a feedback message. That only happens if you tick the "include usage" box, which is off unless you turn it on, and the app prints every number it would send before you send it. The app records duration and date only. It does not ask how you felt, whether it helped, or why you sat, and there is nowhere in the app to tell it — so no mood, symptom, or mental-health assessment of any kind is collected, derived, or inferred.
- Whether the height and weight you entered put you below a BMI of 18.5 — one of the figures in this list the app works out rather than being told. It is calculated from numbers you typed in yourself, it is not stored anywhere, and it is used for exactly one purpose: deciding whether the app will show you a weight-loss calorie target. If it won't, it tells you so and suggests talking to a doctor or dietitian. It is not a diagnosis and the app is not measuring anything — it is arithmetic on two numbers you provided.
The app also works out training figures from what you log — an estimated one-rep max and the personal records and progress charts built from it, your weekly training volume per muscle group, and which areas of the body you have and have not trained recently. These are derived from the workouts you entered; Washington's My Health My Data Act counts data that is inferred or derived as consumer health data just as much as data you typed, which is why they are named here.
If you leave the weekly report switched on, the app also writes itself a small weekly summary — averages and totals for the week just ended, including your weight and your calories — so one week's report can be compared with the next. Your steps and the days you sat appear in the report on screen, but they are read fresh from their own records each time and are never copied into the stored summary. The app keeps at most your 26 most recent weekly summaries; it lives only on your device, is included in the backup file you can export, and is deleted with everything else when you delete your account or when a different account signs in on this device. Switching the weekly report off in Preferences stops new summaries being written. If you choose to share a report image, the card you share carries training figures and your weekly step total — never your weight, your calories or your meditation — and it goes only where you send it through Android's own share sheet.
Each item is collected for the purpose written beside it and for nothing else. None of it is used for advertising, profiling, scoring, or any purpose other than showing you your own data inside the app you put it into.
Where it comes from
Mostly, you type it in. Every category above comes from you entering it in the app — except your step count, which comes from Android's Health Connect after you grant that permission, and the nutrition figures attached to a scanned barcode, which come from the public Open Food Facts database. We do not buy health data, nobody else sends it to us, and nothing is inferred from what you do outside the app.
The rest the app works out for itself, from numbers you already gave it. Washington's My Health My Data Act counts what is derived exactly like what you typed, so those figures are named in the list above rather than left implied: the BMI, BMR and TDEE maths behind your calorie target; the check on whether your height and weight put you below a BMI of 18.5; the training figures built from the workouts you logged — an estimated one-rep max, the personal records and progress charts built from it, your weekly volume per muscle group, and which areas you have not trained lately; the achievements and XP you earn from what you record; and, if you leave the weekly report switched on, the weekly summary itself. Every one of them is arithmetic on what you entered. None of it is a measurement, and none of it is a diagnosis.
Who we share it with
Nobody, in the ordinary sense of the word. No consumer health data is disclosed to advertisers, data brokers, analytics companies, insurers, employers or anyone else.
One thing that is worth saying plainly before the list, because it happens whether or not you ever make an account: the exercise demonstration clips are streamed from our hosting. Playing one — in the library, during a workout, or through a follow-along circuit, which fetches a clip per station — carries your IP address to that host, the way any video on the internet does. We build no record of which clips you play, and the clips are the same for everyone: nothing about you is sent in order to fetch one. Those requests appear briefly in routine server logs that age out on their own.
The only company that holds your consumer health data is the one that stores it for us. One other service sees a single, narrow thing when you choose to use it, and it is listed second:
- Supabase (a US company) — runs the database and sign-in system behind the app. Supabase holds your account and everything you choose to sync. It acts only as a processor on our behalf: it stores and serves the data so the app works, on our instructions, and it is not permitted to use it for its own purposes. The general Privacy Policy says where that arrangement stands and what is still being put in place.
- Open Food Facts (a French non-profit) — when, and only when, you scan a barcode, the app asks their free public food database what that product is. They receive the barcode number and, as with any request your phone makes over the internet, your IP address. They receive nothing you have logged, no account information, and nothing else about you: the app is asking about a product, not telling anyone about a person. They are an independent service the app queries on your behalf rather than a processor working for us, and their own privacy policy applies to what they receive.
One more thing belongs here, because it is the only place in the app where something you typed can be seen by another person, and because "share" is exactly the word the Act uses. If you add a food to the food list yourself, you can switch that food to shared, and it then appears in every other user's food list marked "Community". What appears is the product — its name, brand, serving, barcode and the label figures you typed. It is the same for everyone who sees it, it says nothing about you, and it is not connected to your food log: not whether you ate it, not when, not how much. Nobody is shown who shared it; there is no name, profile or "shared by" line anywhere in the app. We keep, privately, a scrambled reference to the account that shared each entry so that reports can be acted on; it is never shown to anyone and it is cut when the account is deleted or sharing is switched off. So what other users receive is information about a food, not consumer health data about you. Even so, the switch is off unless you turn it on, food by food, the app tells you beside it what will be shown before you do, and we treat turning it on as your specific authorization for that one food. Nothing is shared for a food you never switched on, and your food log itself is never shared with anyone.
Nothing on the list above is collected in order to be passed to anyone else. Supabase holds it because it runs the database the app stores it in, and it holds it on our instructions. Open Food Facts receives a barcode number and your IP address, and only when you choose to scan one. Nobody else receives any of it. The one sharing switch in the app is the one on a food you added yourself, described above; it shares that product's label facts with other users and nothing about you, and it is off unless you turn it on.
We do not sell your consumer health data
No consumer health data is sold — not for a price, and not for anything else of value, under any of the broader definitions of "sale" that privacy laws use. There is no authorization on file permitting it, because we have never asked for one. If that ever changed, the law would require a separate, specific authorization that you would have to sign for that one purpose: it cannot be folded into anything you have already agreed to, and nothing you have agreed to so far permits it. The app has no advertising, no ad identifiers, no third-party analytics and no data brokers anywhere in it.
We never track your location
JST Fitness holds no location permission of any kind. Not precise location, not approximate location, not background location — the app does not request them and Android does not grant them. The app therefore cannot and does not use a geofence around any location, and specifically does not use one around a healthcare facility, pharmacy, clinic or any other place, for any purpose whatsoever.
Nothing syncs unless you ask it to
If you never create an account there is nothing to sync: none of the data listed above is uploaded, and it stays in local storage on your device. The app works fully offline.
Two things still leave the phone without an account, and both are described elsewhere on this page rather than buried here. Playing a demonstration clip fetches it from our hosting, which carries your IP address the way any video on the internet does — that is the "Who we share it with" section above. And if you send feedback with the "include usage" box ticked, the counts the form prints for you before you send go with the message; your level is one of them, and your level is partly earned from what you log. Neither happens on its own, and neither sends your logs. The general Privacy Policy covers the rest of what the app sends, including crash reports.
If you do create an account, the app asks you for explicit consent before it uploads anything, and records which wording you agreed to and when. You can pause all uploading at any time at Settings → Preferences → "Sync my data to the cloud", which stops the syncing without deleting anything.
How to see, correct or delete your consumer health data
You have the right to know what consumer health data we hold about you, to be told whether any of it is shared or sold and who else has held it, to have it deleted, and to withdraw the consent you gave for it to be collected or shared. Here is how each one works:
- See it — the app can export a backup file of your own data at Profile → Settings → Backup & Restore → Back Up Data. It is a plain, readable JSON file and it covers everything you synced, including the record of the consent you gave — which wording, and when. That record is written into the file for you to read, but a file can never put one back into the app: consent has to be given in the app, by you, or it is not yours.
- See who has held it — that is the "Who we share it with" section above: Supabase, and Open Food Facts if you have scanned a barcode — and, if you shared a food, every other user of the app holds that product's label facts, which are not consumer health data about you and carry nothing that is. Supabase and Open Food Facts publish their own privacy policies covering what they receive. Email us and we will send you that list in writing, with a current contact route for each of them, so you can go to them directly.
- Correct it — everything in the list above is directly editable in the app, on the screen you entered it on, with two exceptions we would rather name than let you discover. Your step count comes from Health Connect and is corrected there, not here. And your meditation log is deleted as a whole rather than one sit at a time: deleting your account erases the whole practice log from this device along with everything else, and so does clearing the app's data or uninstalling it. What is not built yet is editing or removing a single session — that is on the list.
- Delete it — Profile → scroll to the bottom → Delete Account, inside the app. You type DELETE to confirm, and it immediately and permanently removes your account and every piece of synced data listed above from our servers, along with your sign-in credentials. There is no grace period and no archive, so back up first if you want to keep a copy. Uninstalling the app removes the copy on your device. A food you shared stays in the list, with its link to your account cut (see "Who we share it with").
- Withdraw consent — pause syncing at Settings → Preferences → "Sync my data to the cloud", or delete your account to withdraw it permanently.
Or simply email the address below and ask. Requests are answered within one month, and using any of these rights costs you nothing and changes nothing about how the app works for you.
If we ever refuse a request, we will tell you why, and you can appeal by replying to that email. If the appeal is denied you may complain to the Washington State Attorney General at www.atg.wa.gov/file-complaint.
Who is responsible
JST Fitness is built and run by one person, who is responsible for what happens to your data and is the person to write to about it:
Tristan Allard Email: [email protected]
There is no company behind the app.
Changes to this document
If this document changes, the "last updated" date above will change with it. The general Privacy Policy, linked at the foot of this page, describes the same practices in more detail; the two are kept in step deliberately, so a material change here normally moves that document too — and when the Privacy Policy changes materially, anyone with an account is shown it again and asked to agree before carrying on. Without an account there is no agreement for us to re-record, so the "last updated" date is the signal instead.
Changes to this document are recorded below, newest first, in the words they were written in. Nothing is removed from them.
18 August 2026
Change — a food you add can now be shared with other users, and this document says how that fits. The "Who we share it with" section used to end by saying there is no sharing screen in the app because there is nothing beyond Supabase and Open Food Facts to ask you about. There is now one switch: on a food you added to the food list yourself, you can turn sharing on, and the product — name, brand, serving, barcode and label figures — then appears in every other user's food list marked "Community". The section now describes it in full: what appears is information about a food and is the same for everyone; nothing about you appears with it, nobody is shown who shared it, and your food log is never shared. We keep a private, scrambled reference to the sharing account so reports can be acted on; it is never shown and is cut when the account is deleted or sharing is switched off. Because the switch is off unless you turn it on, food by food, and the app tells you beside it what will be shown, we treat turning it on as your specific authorization for that one food, even though what is shown is not consumer health data about you. Nothing about your log, your weight, your measurements or anything else on the list above changed today.
14 August 2026
Change — this document said the app derives one figure. It derives several. The "Where it comes from" section said "the single figure the app derives is the BMI calculation". Thirty lines earlier, the list above it already named the training figures the app works out from your workouts — an estimated one-rep max, the records and charts built from it, your weekly volume per muscle group, and which areas you have not trained lately — along with the BMI, BMR and TDEE maths. The section now names all of them, plus the achievements and XP you earn and the weekly summary. Nothing about what the app calculates changed today; the sentence describing it was wrong, and it was wrong in the part of this document that has to say where your data comes from.
Change — "nothing ever leaves your phone" without an account was too absolute. The "Nothing syncs unless you ask it to" section said that if you never create an account, nothing on the list ever leaves your phone. Two things do, and both were already described elsewhere on this page: playing a demonstration clip fetches it from our hosting, which carries your IP address; and feedback sent with the "include usage" box ticked carries the counts the form prints for you first, one of which is your level. Neither happens on its own. The section now says so where you read it, instead of leaving you to piece it together from two other sections further up the page.
Change — how the sharing section explains itself. It used to say that because no data is collected in order to be shared, "no separate sharing authorization is required". That was us publishing a conclusion about our own legal position, and it used the wrong word for it — Washington's Act asks for consent to share and authorization to sell, and they are not the same thing. The conclusion is gone. What stands in its place is the fact: Supabase holds your data because it runs the database, on our instructions; Open Food Facts receives a barcode number and your IP address when you scan one; nobody else receives any of it.
Change — "under contract". The Supabase entry said your data is stored under contract. The general Privacy Policy says the standard data processing agreement is still being completed, so this page should not have claimed it was already done. It now says "on our instructions" and points you at the Privacy Policy for where that stands.
Change — what the backup file actually contains. The "See it" answer said the export "covers everything you synced", and until today one thing was missing from it: the consent record — which wording you agreed to, and when — which syncs with your account but was written into no export at all. That was the one record a formal data request asks for first. The app now writes it into the file, so the sentence is true as it stands, and the answer says so. A consent cannot travel the other way: a record sitting in a file you could edit is not a consent you gave, so restoring a backup ignores it.
New — you can ask who has held your data. Washington's Act gives you the right to a list of everyone your consumer health data has been shared with, and a way to contact them. That was answerable only by reading the "Who we share it with" section and working it out. It is now its own bullet in the rights list, with an offer to send the list in writing with contact details.
Fix — a change note pointed at a section that does not exist. The 13 August entry below said "the section on what leaves your phone" was updated. There is no section by that name. The paragraph went into "Who we share it with", and the entry now says so — which matters, because the section a reader would have guessed at is the one that was still carrying the too-absolute sentence corrected above.
13 August 2026
Change — one "never will" withdrawn from the sale section. Until today the section above said there is no authorization to sell your consumer health data on file "because we have never asked for one and never will". The words and never will have been removed.
What stands in their place says there is no such authorization on file and that we have never asked for one — both still true — and then says what would have to happen if that ever changed: the law would require a separate, specific authorization that you would have to sign for that one purpose, which cannot be folded into anything you have already agreed to, and nothing you have agreed to so far permits it.
The same day, the general Privacy Policy dropped the matching word from its California section, which had promised no cross-context behavioural advertising "— ever".
Why. This app may one day use what it already holds for features built on top of it, or carry advertising to pay for itself. Neither is planned and neither is built. But a promise made for all time is either kept forever or broken, and a broken "never" is worse for you than an honest statement of today with a date on it, because it is the sentence you would have relied on.
What did not change. No consumer health data is sold. Nothing is shared beyond the two companies named above. There is no advertising, no ad identifier, no third-party analytics and no data broker anywhere in the app, and the app still holds no location permission of any kind. The withdrawal is forward-looking only: it permits nothing to be done with data you have already given us, and it is not a consent to anything.
Also on 13 August: the "Who we share it with" section now names the follow-along circuit, which streams a demonstration clip per station and so carries your IP address to our hosting once per station, the way any video on the internet does. We build no record of which clips you play.
Contact
Questions about this document, or requests about your consumer health data: