Hart Platforms LLC d/b/a Harthos • Last updated August 20, 2026 • Effective August 20, 2026
Hart Platforms LLC, a Texas limited liability company doing business as Harthos ("Harthos," "we," "us"), located in Dallas, Texas, is the controller of the personal information described in this policy.
This policy covers the Harthos application, harthos.app, and related services. If anything here is unclear, email privacy@harthos.app.
Account and identity. Email address, display name, username, date of birth (to verify you are 18 or older), profile photo, biological sex where you provide it for health metric context, and phone number where you provide it.
Health and fitness data. With your permission, performance data from the sources you connect, which may include Apple Health, Apple Watch, Google Health Connect, Garmin, Whoop, and Fitbit. Depending on the source and the Challenge, this includes steps, distance, pace, active calories, exercise minutes, heart rate, resting heart rate, heart rate variability, sleep duration and quality, blood oxygen, and VO2 max.
Financial information. Stripe processes payments. We do not store card or bank account numbers. We store a Stripe token, your Wallet balance, and your transaction history. Where required for payouts or compliance, we or Stripe may collect identity verification information and tax identification information.
Location. Your device's approximate location, with your permission, together with IP address and device signals, used to determine which jurisdiction you are in. This enforces eligibility for paid Challenges and may result in access being blocked. We ask for approximate location only when you enter a paid Challenge, and we store only the resulting state, never your coordinates. We do not collect precise GPS location. Free Challenges never require location.
Usage and device data. Screen views, navigation, session data, sign-in events, Challenge activity, crash reports, error logs, application version, platform, and push notification tokens.
Website data. On harthos.app we use cookies and similar technologies for essential site function and basic analytics. You can control cookies through your browser settings. We do not use third-party advertising cookies.
The table below summarizes the categories of personal information we collect, why we collect them, and who we disclose them to for a business purpose.
| Category | Purpose | Disclosed to |
|---|---|---|
| Identifiers and account data | Account creation, age verification, support, security | Cloud hosting, authentication, support providers |
| Health and fitness data (sensitive) | Health score calculation, Challenge outcomes, anti-cheat | Cloud hosting only. Never sold, never used in advertising |
| Commercial and financial data | Deposits, entries, prizes, fee calculation, tax reporting | Payment processor, tax and identity verification providers |
| Geolocation (approximate) | Jurisdictional eligibility for paid Challenges | Cloud hosting, network provider |
| Internet and device activity | Product improvement, crash diagnosis, fraud detection | Analytics and crash reporting providers |
| Inferences (rank, health score) | Competition, matchmaking, leaderboards | Other competitors, in the ways described in Section 6 |
We also use this information to operate your account, provide support, secure the Service, detect cheating and coordinated accounts, and comply with legal, tax, and financial record-keeping obligations.
Health data receives stricter treatment than anything else we hold. It is sensitive personal information, and we process it only with your consent.
We will not use it for advertising or marketing, ours or anyone else's, and we will not use it for data mining.
We will not use it to train artificial intelligence models, our own or a third party's, and we will not provide it to anyone else for that purpose, without your separate and specific opt-in consent.
We will not disclose it to your employer, your insurer, or any third party except as necessary to operate the Service or where the law compels disclosure.
We collect it only with your explicit permission, granted through the permission flow of each source you connect. You may revoke that permission at any time in your device settings or by disconnecting the source in the application. Revoking mid-Challenge stops progress tracking.
We use it only to calculate your health score, determine Challenge outcomes, detect cheating, provide support, and secure the Service.
You may withdraw consent at any time by disconnecting your sources, and you may request deletion of health data we hold without deleting your account by emailing privacy@harthos.app.
We create aggregated and de-identified information from Service data, and we may use, publish, and commercialize it. Examples include population-level fitness benchmarks, engagement and performance research, and insights we may share with partners or publish.
We de-identify to a standard that makes re-identification not reasonably possible. We publicly commit not to attempt to re-identify this information, we maintain it in de-identified form, and we contractually require the same of any recipient. Aggregated and de-identified information is not personal information, and this policy does not restrict its use.
Other competitors. Your display name, profile photo, and Challenge progress are visible to competitors in your Challenges. Your display name, image, and record appear on leaderboards visible to other signed-in users only if you turn on the leaderboard setting. It is off until you turn it on, and you can turn it off again at any time in Settings. Leaderboards are not publicly accessible outside the Service.
Service providers, who may use the information only to perform services for us: Stripe (payments), Google Firebase and Google Cloud (authentication, database, storage, analytics, crash reporting), Cloudflare (network and email routing), Apple and the wearable platforms you connect, and identity verification and tax reporting providers.
Sponsors and partners. Where a Challenge, event, or reward is sponsored, we may share aggregate participation information with that sponsor. We share your individual information with a sponsor only with your consent, given at the point you enter or claim.
Legal and safety. Where required by law, subpoena, or regulator, and to investigate fraud, enforce our Terms, or protect rights and safety.
Business transfers. If we are acquired, merge, or sell assets, information may transfer as part of that transaction, subject to this policy or a successor policy providing equivalent health data protections.
With your consent, in any other case, which we will describe at the time we ask.
We do not currently sell or share any other category of personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not sell or share the personal information of anyone under 18, and the Service is not available to them.
If that ever changes for non-health information, we will update this policy, provide notice before the change takes effect, and offer an opt-out mechanism. We honor opt-out preference signals, including Global Privacy Control. Where the law requires opt-in consent, we will obtain it first.
We send transactional messages about Challenges, results, wallet activity, security, and changes to our terms. These are part of the Service and continue while your account exists.
We may also send promotional messages and show you promotions and sponsored content in the application. Promotional targeting uses account and usage information only, never health data. You may opt out of marketing in your notification settings or through the unsubscribe link in any marketing email, without affecting transactional messages.
Financial incentives. We may offer referral bonuses, promotional credits, or similar rewards. Where such a program involves your personal information, we will describe its material terms, the value we assign, and how to withdraw, at the point we offer it. Participation is voluntary and you may withdraw at any time.
Automated systems flag anomalous performance data for review. A flag can lead to a voided result, a forfeited Entry, or a restricted account, which are decisions with real financial consequences.
| Category | Retention |
|---|---|
| Account profile | Until deletion; purged within 30 days of a confirmed request |
| Health and activity data | While your account is active; deleted once the 30-day deletion grace period ends |
| Challenge results | Retained in pseudonymized form for competitive integrity |
| Financial transaction records | Seven years from the transaction date, as tax and financial law require |
| Identity verification records | As required by applicable compliance obligations |
| Push notification tokens | Until the device is removed or the account is deleted |
| Analytics events | Two to fourteen months |
| Server access logs | 30 days |
| Crash reports | 90 days |
On account deletion, financial records are pseudonymized and access-restricted rather than erased: identifiers are removed from routine access, while amounts and dates are retained. We do not describe this as anonymization, because it may need to be reversed for a chargeback, a fraud investigation, or a tax inquiry.
Data is stored on Google Cloud infrastructure in the United States, encrypted in transit and at rest. Controls include TLS for all traffic, database security rules restricting client access, server-side validation of every financial transaction, role-based access on the principle of least privilege, and monitoring for anomalous health data.
No system is perfectly secure. Where a breach affecting your personal information occurs, we will notify you and the relevant authorities as the law requires.
Wherever you live, you may:
Residents of states with comprehensive privacy laws, including Texas, California, Colorado, Connecticut, Virginia, Oregon, Montana, and others, also have the right to confirm whether we process your personal information, to obtain a copy, to correct it, to delete it, and to opt out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. Nevada residents may direct us not to sell covered information under NRS Chapter 603A.
Email privacy@harthos.app or use the in-application controls. We verify your identity through your registered account, and we may ask for additional confirmation where a request concerns sensitive or financial information. We respond within 45 days, extendable once by a further 45 days where we tell you why. There is no charge for a reasonable request.
If we deny your request, we will explain why and how to appeal. Email appeals@harthos.app within 30 days. A reviewer not involved in the original decision will consider the appeal and respond within 60 days. If we deny the appeal, you may complain to your state Attorney General, and we will provide contact details.
An authorized agent may submit a request on your behalf with proof of authority. We will not discriminate against you for exercising any right under this policy.
We do not track users across third-party websites for advertising, so we do not respond differently to browser Do Not Track signals. We do honor Global Privacy Control signals as described in Section 7.
Harthos is for adults. We do not knowingly collect personal information from anyone under 18, and we verify age at registration. If we learn we have collected information from a minor, we delete it promptly and close the account. Contact privacy@harthos.app if you believe a minor has registered.
The Service is offered only within the United States, and information is stored and processed there. We do not offer the Service in the European Economic Area, the United Kingdom, or Canada, and it is not directed to residents of those regions.
We may update this policy. For material changes we will give at least 30 days' notice in the application or by email before they take effect, and we will not apply a materially different use to information already collected without a fresh legal basis or your consent.
The effective date above identifies the current version. We retain prior versions together with the dates each was in effect, and will provide the version applicable to you on request.
Hart Platforms LLC d/b/a Harthos
Dallas, Texas
Privacy: privacy@harthos.app
Appeals: appeals@harthos.app
Support: support@harthos.app