Skip to content
Cohort Mielo Village
Join waitlist

Privacy Policy

Privacy Policy — Cohort Health

Cohort Health, LLC ("Cohort Health," "we," "us," "our"). Effective 1 September 2026. Applies to the Cohort, Village, and Mielo mobile applications (together, the "Apps") and cohort.health (the "Site"). Contact: hello@cohort.health · In-app: Settings → Privacy.

This policy explains what we collect, why, what we share, and the controls you have across all three Apps and the Site. Our consumer-health-data disclosures required by the Washington My Health My Data Act, Nevada SB 370, and comparable laws live in a separate Consumer Health Data Privacy Policy; Section 7 below summarizes them, and for consumer health data that separate policy controls.

The short version

  • Your most sensitive data is end-to-end encrypted — we cannot read it. In Cohort, your health measurements, and in Village, everything you track about your family, are encrypted on your device with keys derived from your passphrase that never leave your device. Our servers store only ciphertext. This is stronger than ordinary "encrypted at rest": even we cannot read it. (Mielo is the exception — a fair competition requires our server to validate your runs.)
  • Nothing leaves your device for analytics unless you opt in. Data contribution is off by default; you turn it on explicitly and can turn it off any time.
  • We do not sell personal data. We do not show targeted advertising. We do not use your data to make decisions about you.
  • What we share with researchers is de-identified and aggregated, disclosed only in groups of at least 8 people, with statistical noise added, so no individual can be picked out.
  • You can access, export, or delete your data at any time, and we tell you honestly what deletion can and cannot undo.

1. The three Apps at a glance

AppWhat it isHow your content is stored
CohortA personal health-and-performance tracker that compares you against an anonymized cohort of similar people.Your health measurements are end-to-end encrypted (we can't read them); a derived Health Score is server-readable to power the comparison.
VillageA private log for parents of their family's daily routines and caregiving.End-to-end encrypted (we can't read it). Because it can describe a child's health, we protect it as consumer health data — our strictest category — even though we cannot read it.
MieloA competitive running game (timed miles, ELO, leagues).Server-visible — a fair competition requires our server to validate runs. Not end-to-end encrypted.

2. Information we collect

Account information

One account works across all three Apps. When you sign up we collect your email address, an optional display name (we do not require your legal name), and authentication material — we store a password verifier, never your password itself, plus session tokens. At sign-up you also provide basic demographics (age band, sex, and country); these are stored in readable form and used to match you to a comparison cohort and to normalize measurements.

End-to-end encrypted content (we hold only ciphertext)

For the data below, encryption and decryption happen on your device using keys derived from your passphrase; the keys never reach our servers, so we cannot read this content:

  • Cohort — your health measurements: resting heart rate, heart-rate variability, VO₂max, body composition (weight, body-fat %, DEXA), blood-panel results, strength/balance/mobility test results (including finger-strength), cognitive-test results, daily metrics imported from Apple Health / Android Health Connect, and habit / check-in entries.
  • Village — everything you log about your family's routines, including a child's name and birth date, feeds, sleep, diaper changes, growth notes, medications or vitamins given, enrichment, and free-text notes. This is your own private record, encrypted end-to-end, and we never read it. Because it can describe a child's health, we treat it as consumer health data under our Consumer Health Data Privacy Policy — the encryption doesn't lower the standard we hold it to; it is how we meet it.

Server-visible content

Some data must be readable by our servers to make a feature work, and is not end-to-end encrypted:

  • Cohort — your derived Health Score (a 0–100 composite) and its domain sub-scores; your cohort membership; the insight cards and feed shown to your cohort; the connection status of your data sources; and, if you connect them, your chess.com rating (from a public username you provide) and Strava activity.
  • Village — the membership edges of a child's care circle (who may access it) and the dates of entries (never their contents); invite metadata. If you opt into local Groups, a coarse self-reported area and a rough ~2-week age window, plus locally-noised aggregate figures (Section 5).
  • Mielo — your runs and races (times, pace), ELO rating, leagues, challenges, friends, achievements, heart rate during runs, training-run flags, and, where you enable it, the GPS route of a run. Your route is visible only to you.

Location

Mielo uses precise location (GPS), with your permission, to record your runs and routes; you can decline (some run features then won't work). Cohort does not use precise location. Village does not use precise location — its optional Groups feature uses only a coarse area you type. None of the Apps performs geofencing around health-care facilities (Section 8).

Device and diagnostic information

Device model, operating-system version, App version, language, time zone, crash reports, and a pseudonymous install identifier we generate (not your name, email, advertising ID, or device serial number; resettable in settings).

Behavioral telemetry — only if you opt in

With your consent (the "Contribute" setting, Section 3), the Apps record usage events keyed to the pseudonymous install identifier. At the Off setting — the default — these events are not created, queued, or transmitted at all; this is enforced in the software, not filtered on a server.

What we deliberately do not collect

No advertising identifiers, no third-party advertising or data-broker SDKs, no contact-list uploads, and no precise-location tracking except Mielo's run/route recording described above.

3. Consent, in tiers

SettingWhat it meansDefault
OffNo telemetry or contribution is created or transmittedYes — the default
ContributeCoarse, locally-noised, de-identified metrics are shared for the aggregate analytics in Section 5Opt-in only
Health-data contributionA category-specific opt-in before any of your health data is shared for analyticsOpt-in only, separate from the above

The Contribute setting is off by default and enforced on your device. Downgrading to Off purges any locally queued events.

4. How we use information

We use information to operate the Apps and your account; provide support; maintain safety, security, and abuse prevention; debug and fix crashes; comply with law; and — only for data shared under the Contribute setting or a health-data contribution consent — to produce de-identified, aggregated, population-level analytics as described in Section 5.

5. How we share information — and how the de-identified flow actually works

Service providers. Cloud infrastructure vendors that host and store our systems and process crash reports, on our written instructions and prohibited from using data for their own purposes.

The de-identified contribution mechanism. When you opt in, your device computes coarse bucket indices (for example a decile or a change-band — never a raw value) and adds statistical noise on the device before anything is sent. It travels through an oblivious relay that structurally separates who you are from what you send: the relay sees your network address but only an encrypted blob it cannot read, while the receiving gateway can read the contents but sees only the relay, never you, and no account identifier travels with the data. Results are disclosed only for groups of at least 8 individuals with added noise, so no individual can be re-identified. No raw measurement is ever submittable — the system accepts only the declared coarse buckets.

Population-scale analytics. We produce de-identified, aggregated, population-level analytics only from data contributed by users who opted in — never data that identifies you, and never our end-to-end-encrypted content, which we ourselves cannot read.

Research institutions. We may make the same de-identified, aggregated data available to universities, academic medical centers, and comparable research bodies under written data-use agreements that prohibit re-identification, prohibit linkage that could enable it, prohibit redistribution, prohibit use for advertising or decisions about individuals, and require aggregate-only publication.

Legal. We may disclose information if required by law, subpoena, or court order, or to protect rights, safety, or property; where lawful we will notify you first. For end-to-end-encrypted content we can produce only ciphertext we cannot decrypt.

Business transfers. If Cohort Health is acquired, data already collected remains subject to these commitments and any successor must honor them.

6. What we never do

We do not sell your personal data. We do not license or disclose data that identifies you, to anyone, for their own use. We do not show targeted advertising or share data with advertisers or data brokers. We do not use your data to make, inform, or evaluate decisions about you — including decisions about employment, insurance, credit, housing, or clinical care. Our analytics exist to understand populations, not people.

7. Consumer health data — summary; the separate policy controls

"Consumer health data" means personal information linked or reasonably linkable to you that identifies your physical or mental health status, including inferences about your health. In our Apps it comprises: Cohort's measurements and derived scores (Section 2); Mielo's exercise, heart-rate, fitness, and run data; and Village's family log, because information a parent records about a child — feeding, growth, medications — can describe that child's health. Village's classification does not make it readable to us; it means the strictest rules apply to data we already cannot read.

Our baseline rule. We collect no consumer health data for analytics or sharing without your separate, affirmative, revocable consent for that category. Accepting our terms is not that consent; enabling general analytics is not that consent. Data you record for your own use stays yours; consent governs any use beyond showing you your own information. Sharing, where you opt in, happens only through the de-identified mechanism in Section 5.

The full disclosures — categories per App, sources, recipients, your rights to access (with a list of recipients), withdraw, and delete, the honest limits of deletion, how to exercise each right, and the appeals process — are set out in the Consumer Health Data Privacy Policy, a separate document those laws require. For consumer health data, it controls over this policy.

8. No geofencing around care

We do not implement geofences around any facility that provides health-care services — not to identify you, track you, collect data from you, or message you. Mielo's location use is limited to recording your own runs and routes at your request; it is never used to detect proximity to care facilities.

9. Retention

  • Account information: kept while your account is active; deleted within 30 days of account deletion, except records we must keep by law.
  • Telemetry / contribution records: retained 24 months, then deleted or irreversibly aggregated.
  • Crash logs: retained 90 days.
  • Consent records (which disclosure version you agreed to, and when): retained as long as any data collected under them is in use.
  • End-to-end-encrypted content: retained until you delete it; because we cannot read it, we delete it as opaque ciphertext on request.

10. Your choices and rights (all users, everywhere)

  • Access and export a machine-readable copy of your data.
  • Correct account information.
  • Withdraw consent — Contribute drops to Off immediately, queued events are purged, and your prior contributions are excluded from source data and from every aggregate rebuilt afterward.
  • Delete your account and data.

Honesty about limits: analytics already published in aggregate form cannot be unpublished, and past contributions inside them cannot be extracted retroactively. Everything going forward stops.

We respond to requests within 45 days and do not discriminate against you for exercising any right. Residents of Texas, California, Virginia, Colorado, and other states with comprehensive privacy laws may exercise these rights through the same channels; we honor them regardless of state and do not "sell" or "share" personal data as those laws define it.

11. Security

Your most sensitive data — Cohort's health measurements and everything in Village — is end-to-end encrypted with keys we never hold. All other data is encrypted in transit and at rest. Access is limited to personnel who need it, under confidentiality obligations, and all analytical access to contributed data passes through a single enforcement layer that applies the minimum-group and noise controls. No system is perfectly secure; if a breach affects your data we will notify you as required by law, including the FTC Health Breach Notification Rule where it applies.

12. Children

The Apps are intended for adults. Cohort and Mielo are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Village is used by parents and adult caregivers: the account holder is an adult, a child never uses the service, and the information an adult records about a child is end-to-end encrypted, protected as consumer health data under our Consumer Health Data Privacy Policy, and never used for advertising or profiling. If you believe a child under 13 has created an account, contact hello@cohort.health and we will address it.

13. Changes to this policy

We post changes here with a new effective date and version. If a change materially expands how we collect, use, or share data collected before the change, we will ask for your consent again — an updated document is not consent.

14. Contact

Cohort Health, LLC — 609 E. Liberty Ave., Round Rock, TX 78664. Privacy requests: hello@cohort.health · In-app: Settings → Privacy.

Last updated 1 September 2026.

Cohort cohort.health · Privacy · Health Data · Support

Not medical advice · wellness tracking only
Not evaluated by the FDA