This Consumer Health Data Privacy Policy is a standalone policy required by the Washington My Health My Data Act (RCW 19.373). It applies specifically to "consumer health data" as that term is defined by Washington law, and it exists separately from — and in addition to — our general Privacy Policy. If anything here conflicts with the general Privacy Policy on how we handle consumer health data, this policy controls.
You do not need to be a Washington resident for this policy to apply to your account; it describes how we handle consumer health data for everyone, consistent with how Fuse actually processes data today.
The short version: We collect the health and fitness data you connect or log, only to run Fuse for you. We ask for your separate, affirmative consent before we start — this isn't bundled into agreeing to our Terms. We never sell your health data. You can withdraw consent or delete your data at any time, and if we ever deny a rights request, you can appeal it.
Consumer health data, under MHMDA, means data that identifies a consumer's physical or mental health status. For Fuse, that is:
This is the same data described in §1.1–1.3 of our general Privacy Policy; this section restates it here because MHMDA requires the health-data categories to be listed in this standalone document, not only in the general one.
We receive this data from three sources, and only from actions you take:
We do not purchase, license, or otherwise acquire consumer health data about you from any data broker or third party.
We use consumer health data solely to operate Fuse for you:
We do not use consumer health data for advertising, to build advertising profiles, or for any purpose unrelated to providing you the Fuse service.
We do not sell consumer health data, and we do not share it with any third party for marketing or advertising. The only entities that receive consumer health data are the service providers (sub-processors) that help us operate Fuse, each bound by a data processing agreement or published terms that govern how they may use it:
| Provider | Role | Consumer Health Data Involved |
|---|---|---|
| Terra | Wearable data ingestion — receives and normalizes data from connected devices before it reaches Fuse | Biometric health data from connected wearables (Oura, Whoop, Garmin, Samsung Health, Apple Health) — heart rate, HRV, sleep, activity, and recovery metrics |
| Anthropic | AI inference for our AI coaching engine | Health context shared to generate your coaching responses (fitness metrics, recovery data, coaching history); Anthropic does not train on this data |
| OpenRouter | AI request routing to Anthropic for our coaching engine | Health context in transit to Anthropic's Claude API (fitness metrics, recovery data, coaching history, check-in notes) — OpenRouter forwards this data and does not train models on it per its published policy |
| Render | Cloud hosting | All app data, including consumer health data, as stored data on Render's infrastructure |
| Backblaze B2 | Encrypted backups | Encrypted database snapshots, which include consumer health data |
| Stripe | Payments | None — Stripe receives payment information only, no health data |
No human at Fuse reviews your individual health data in the normal course of operations — it's processed by software, not read by staff, except where you contact us directly for support or where access is necessary to diagnose a technical issue or respond to a security incident (all such access is logged).
We do not share consumer health data with health insurers, life insurers, employers, or government agencies, except where required by law.
You have the following rights over your consumer health data, regardless of where you live:
You can confirm whether we process your consumer health data and access it directly in the app at any time (your dashboard shows your full history), or request a copy by emailing hello@fuse.fit with the subject "MHMDA Access Request."
You can withdraw your consent to Fuse collecting and processing your health data at any time from Settings → Health Data Consent. Withdrawing stops new health-data collection; it does not delete data already collected — use the deletion right below for that.
You can delete your consumer health data at any time from Settings → Delete My Data, or by emailing hello@fuse.fit with the subject "MHMDA Deletion Request." We will delete your data, and direct our sub-processors listed in §4 to do the same, within [[pending outside-counsel confirmation of the statutory deletion-response window]].
If we deny your access or deletion request, you may appeal within [[pending outside-counsel confirmation of the appeal window]] by emailing hello@fuse.fit with the subject "MHMDA Appeal" and a description of the original request. We will respond in writing within [[pending outside-counsel confirmation of the response window]] explaining our decision. If we uphold the denial, we will tell you how to file a complaint with the Washington State Attorney General.
We do not sell consumer health data, so there is no separate authorization process to opt out of — there is nothing to opt out of. We do not use geofencing near health care facilities to target advertising, and we do not target advertising based on consumer health data at all.
Consumer health data is retained while your account is active, or until you delete it, whichever comes first. Upon account deletion, all personal data — including consumer health data — is permanently deleted within 30 days, consistent with §4 of our general Privacy Policy. Encrypted backups age out of retention on the same B2 backup cycle described there.
MHMDA requests (access, withdrawal, deletion, appeal):
Email: hello@fuse.fit
Mailing address:
Dasan LLC, doing business as Fuse, Privacy Team
2108 N St Ste N, Sacramento, CA 95816
This policy is separate from, and supplements, our general Privacy Policy and Terms of Service. Where this policy is silent, the general Privacy Policy applies.