Skip to content
Cohort Mielo Village
Join waitlist

Consumer Health Data

Consumer Health Data Privacy Policy — Cohort Health

Cohort Health, LLC ("Cohort Health," "we," "us"). Effective 1 September 2026. Applies to the Cohort, Village, and Mielo mobile applications and cohort.health (together, the "Services").

This policy exists as a separate document because laws including the Washington My Health My Data Act, Nevada SB 370, and similar statutes require specific disclosures about consumer health data. It supplements our general Privacy Policy; for consumer health data, this document controls.

"Consumer health data" means personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status — including conditions, symptoms, treatments, medications, biometric or fitness data, and inferences about your health. We apply this policy to all of it.

0. How we protect it — end-to-end encryption

For Cohort's health measurements and for everything in Village, encryption happens on your device with keys derived from your passphrase that never leave your device. Our servers store only ciphertext, so we cannot read this consumer health data at all. Mielo is different: fair competition requires our server to validate your runs, so Mielo's exercise, heart-rate, and route data is readable by our servers (still never sold, still never used to make decisions about you). This section governs how we treat all of it regardless.

1. Our baseline rule

We collect no consumer health data for analytics or sharing without your separate, affirmative, revocable consent for that category. Accepting our terms is not that consent. Enabling general analytics is not that consent. The Contribute setting is off by default; each category is requested specifically, before any sharing, in plain language, and you can withdraw at any time. (Data you log for your own use inside an App stays on your device / in your end-to-end-encrypted vault; the consent above governs any use beyond showing you your own information.)

2. Categories of consumer health data

AppCategoriesStored how
CohortResting heart rate; heart-rate variability; VO₂max; body composition (weight, body-fat %, DEXA); blood-panel results; strength, balance, and mobility test results; cognitive-test results; daily activity/health metrics imported from Apple Health / Android Health Connect or Strava; and health-related habit and check-in entries. The derived Health Score and its domain sub-scores are computed from these.Measurements end-to-end encrypted (we can't read them); the derived Score/sub-scores are server-readable to power your cohort comparison.
VillageA child's name and date of birth, and health information logged by a parent/guardian: feeding, sleep, diapers, growth (weight/height), medications and vitamins, and related notes.End-to-end encrypted (we can't read it); the server sees only encrypted membership edges and entry dates — and, if you opt into local Groups, a coarse self-reported area, a rough ~2-week age window, and locally-noised aggregate figures.
MieloExercise and fitness data: runs/races (times, pace), heart rate during runs, VO₂-related fitness, and — where you enable it — the GPS route of a run (precise location).Server-readable (needed to validate competition); route visible only to you.

Precise location. Mielo uses precise location (GPS), with your permission, to record your runs and routes. Cohort and Village do not use precise location (Village's optional Groups feature uses only a coarse area you type). We do not infer your presence at or near any health-care facility (Section 7). We do not collect genetic data.

3. Sources of consumer health data

You, and the device platforms and accounts you choose to connect. Consumer health data comes from what you directly enter or log, and — with your per-connection consent — from Apple Health / Android Health Connect (Cohort and Mielo), Strava (Cohort), your phone's GPS (Mielo runs), and a chess.com public username you connect (Cohort). We do not purchase health data about you, receive it from data brokers, or derive it from third-party trackers.

4. Why we collect it

To provide the features you use it for — recording, viewing, and organizing your own information (which, for Cohort and Village, stays end-to-end encrypted); to maintain, debug, and secure the Services; and, only with your Contribute consent, to produce de-identified, aggregated, population-level analytics. We do not use consumer health data for advertising, and we do not use it to make, inform, or evaluate any decision about you.

5. Who we share it with

We do not share consumer health data that identifies you with anyone for their own use. Contribution itself is privacy-preserving by construction: when you opt in, your device sends only coarse buckets with noise added on-device, through an oblivious relay that structurally separates who you are from what you send — no raw measurement can be submitted, and no account identifier travels with the data. The disclosures that occur are:

Population-scale analytics. We produce de-identified, aggregated analytics only from data contributed by consenting users — never data identifying you, and never our end-to-end-encrypted content — subject to a minimum reporting cohort of at least 8 individuals plus added statistical noise and suppression controls designed to prevent re-identification.

Categories of third parties:

  • Service providers / processors — infrastructure vendors processing data on our written instructions, prohibited from using it for their own purposes.
  • Research institutions — universities, academic medical centers, and comparable bodies, which may receive de-identified, aggregated data only, under written data-use agreements prohibiting re-identification, prohibiting linkage that could enable re-identification, prohibiting redistribution, prohibiting use for advertising or decisions about individuals, requiring institutional review where applicable, and requiring aggregate-only publication above the minimum cohort size.
  • Legal recipients — only where required by law, as in the Privacy Policy. For end-to-end-encrypted content we can produce only ciphertext we cannot decrypt.

On request we will provide a list of all third parties with whom we have shared your consumer health data, with a contact mechanism for each. Because our sharing is limited to the de-identified, aggregated flows above, that list is expected to be short.

6. We do not sell consumer health data

We do not sell consumer health data, and will not absent the separate, signed, revocable authorization applicable law requires — an authorization we do not currently seek from anyone.

7. No geofencing around care

We do not implement geofences around any facility that provides health-care services — not to identify you, track you, collect data from you, or message you. Mielo's location use is limited to recording your own runs and routes at your request; it is never used to detect proximity to care facilities.

8. Your rights

If you are a resident of Washington, Nevada, or another state with a consumer health data law — and as a matter of policy, any user, anywhere:

  • Right to know / access: confirm whether we collect, share, or have sold your consumer health data, and receive a copy, including the third-party list in Section 5.
  • Right to withdraw consent: withdraw any health-data consent at any time, as easily as it was given; collection/sharing for that category stops immediately.
  • Right to delete: request deletion. We delete it from active systems and, on the schedule backups permit, from archives; we instruct our processors and any recipients to delete it, and your contributions are excluded from every aggregate rebuilt after your request. Honest limit: aggregate statistics already published cannot be unpublished. (For end-to-end-encrypted content, deletion removes the ciphertext we hold.)
  • Right to non-discrimination: we will not deny features, charge different prices, or degrade your experience for exercising a right.

How to exercise: in-app via Settings → Privacy, or email hello@cohort.health. We verify using the account or install the request concerns, and respond within 45 days (extendable once by 45 days for complex requests, with notice).

9. Appeals

If we decline a request, you may appeal by replying to our decision or emailing hello@cohort.health with "Appeal" in the subject. A person not involved in the original decision reviews it and responds in writing within 45 days. If your appeal is denied and you are a Washington resident, you may contact the Washington Attorney General at www.atg.wa.gov/file-complaint; residents of other states may contact their state attorney general.

10. Changes

Changes are posted here with a new effective date. We will not collect additional categories of consumer health data, or use or share it for new purposes, without obtaining new consent first — a revised policy is not consent.

11. Contact

Cohort Health, LLC — 609 E. Liberty Ave., Round Rock, TX 78664. hello@cohort.health · In-app: Settings → Privacy.

Last updated 1 September 2026.

Cohort cohort.health · Privacy · Health Data · Support

Not medical advice · wellness tracking only
Not evaluated by the FDA