Help us deliver Shiftwave Recovery Systems to L.A. fire stations. Learn More →

ShiftwaveMobile — Consumer Health Data Privacy Notice

Version 2026-09-23 · Effective 2026-09-23 · Cofactor Systems, Inc., doing business as Shiftwave · shiftwave.co/pages/health-data-notice

1 · What this notice is, and when it wins

This notice explains how Shiftwave handles consumer health data — information about your body and your health that Shiftwave collects, keeps, uses or shares. It applies to the extent required by US state consumer-health-data laws (Washington's My Health My Data Act, Nevada's SB 370, Connecticut's health-data provisions, and any similar law), and it applies wherever you are if you would rather read it than the Privacy Policy.

If anything in this notice conflicts with the Shiftwave Privacy Policy or any other Shiftwave document, this notice controls for consumer health data.

This notice is about ShiftwaveMobile, our app for your phone or tablet, and the chair it runs. It does not cover the earlier Shiftwave and Shiftwave Controller apps. If you use Shiftwave through a clinic, coach or team, they have their own notice for their records. If that clinic is a health-care provider covered by HIPAA, its notice governs the records it holds; this one governs what Shiftwave holds.

2 · What we mean by "health data" here

Any information that identifies you, or can reasonably be linked to you, and that says something about your physical or mental health — including things we infer about your body from what we measure, and what you tell us about your health, not only what a sensor records.

Shiftwave is not a medical device and is not a treatment for any condition. The data below describes your body's response to a session. It does not diagnose anything.

3 · What we collect — the categories

Shiftwave needs an account. Before your first session you create one, confirm the safety agreement, and agree to the Terms. From then on, everything below describes what your account sends and what we keep. How the app works with your sessions — the picture we call your twin — is described in the App Terms (section 9) and in this notice. It runs because the service needs it. Accepting the Terms is not a consent to it, and we will never say it is; the things that do need your separate yes are listed in §8.

3.1 · The assistant

When you type or speak to the assistant, your whole message is sent to our servers and on to the AI service that answers you. What the assistant is given, and nothing else: - your message; - the hour of day; - up to eight short lines assembled on your phone from your sessions — how often and how long you Shiftwave, what you come back to, up to three words you used in a note (from a fixed list of twenty), and, once a few of your sessions have a star rating, a sentence about how you tend to rate them or naming a protocol that rated low; - if you correct one of those lines with the Not quite? control, the short line you typed replaces it and is sent the same way — it is a short line, and apart from your message itself it is the one place your own words reach the assistant.

The assistant is not given your scores. It can be given a sentence computed from them, as above. It is not given your name or your account id — the message has no field for one, unless you type them yourself. Our servers know it was your account that asked; the log entry we keep does not record that.

Our servers keep none of the words you send or receive. They keep the shape of each exchange — what kind of ask it was, which of our fixed starting and ending states it was filed under (for example "Stressed""Calm"), the hour, a count of the lines sent with it — and, if a message reads as a crisis, a marker without the words. These entries are kept for one month. Neither the AI service nor the company that made the model uses your message to train anything, and the company that made the model never sees it (§6).

If you speak instead of typing, your speech becomes text on your phone where your phone can do it, and by Apple where it cannot. Apple's handling of that is governed by Apple.

3.2 · What each session sends

Your safety agreement. Before your first session you confirm that none of the listed conditions apply to you. We keep the date and the version of the agreement you accepted. That record shows you told us none of those conditions applied — and it is health data. Wearable makers do not ask; we do, because the chair is physical. If you tell us one applies, we record nothing about which — only that no agreement is on file, and sessions stay off until you can confirm.

Session records. When it started, how long it ran, whether you finished, which protocol you ran, and where it came from. With it go the display name you choose, your birth year (or the fact that you chose not to give it), and the preferences you set (what you want from Shiftwave, how often, and when).

Your sensor readings. If you use the chair's sensor, the beat-to-beat timing, the pulse signal and the blood-oxygen reading recorded during the session are uploaded as separate files. If you do not use the sensor, nothing from it is collected — the session record above is still sent.

What you write after a session. If you write a note after a session, it is stored with that session on our servers, like the session's other data, and we read it to understand what the protocols do for people. Up to three words from it, matched on your phone against a fixed list of twenty such as wired, foggy or settled, can also be given to the assistant (§3.1). If you tick public on the form, we may later pick a short quote from your note and ask you to approve it; nothing is shown to anyone without that second yes. You can ask us to delete what you wrote, or to withdraw the tick, at any time (§8). A spoken note stays on your phone as a recording.

3.3 · What we derive and infer — this is health data too

From your heartbeat timing, your session records and your birth year, we compute and store: - Session scores — a star rating, a one-word summary, and named component scores (renewal, vitality, engagement, potential), with the contributors behind them and a short written story of the session. - A personal range — how each session sits against your own earlier sessions, and a running index that reflects your history. These compare you only with yourself; there is no population "normal" behind them. - Signal quality — how readable the sensor recording was, and why a score was withheld when it was. - Inner Form and your strongest pillar — summaries across recent sessions, computed from the scores above.

These are inferences about your body's response to a session. They are stored on our servers as part of your account, and they are the kind of data this notice exists for.

3.4 · Things you connect — each asks you at the moment you connect it

Apple Health. If you connect it, we read what you allow in Apple's own permission sheet — today, sleep, step count, active energy, heart rate variability and resting heart rate. What you allow is used on your phone, and stays on your phone: nothing from Apple Health is sent to us or to the AI service. What you don't allow is not read.

Calendar. If you connect it, it is read on your phone. Nothing from your calendar is sent to us.

3.5 · Experimental features (Labs)

Sessions you run in Labs are recorded and sent like any other session (§3.2). Experimental sensors you may use there — a chest strap, a finger ring, a headband — are read on your phone during the session; their recordings are not sent to us today. The Labs agreement is three separate items — research use of your Labs sessions, experimental risk, and ideas you contribute — and it is kept on your phone with the version and wording you saw; it is not sent to us. Leaving Labs, in Settings or by signing out, stops research use of future sessions.

3.6 · What we do NOT collect

We do not collect your location. We do not use geofencing. We do not collect anything from Apple Health or your calendar beyond what §3.4 says. We do not keep the words you say to the assistant on our servers. Your conversation with it is kept on your phone, up to the last 200 messages, so you can read it back, and it is deleted when you sign out or delete the app. We do not run advertising or analytics trackers in the app. No other company collects your health data across other apps or websites when you use Shiftwave.

4 · Where it comes from

  • You — what you type, say, set, confirm, or connect, including your safety agreement.
  • The chair's sensor, through the app, during a session you run.
  • Apple Health and your calendar, only if you connect them, and only on your phone.
  • Our own computation — the derived and inferred data in §3.3 comes from our servers, and from your phone, processing what is above.
  • The AI service's classification — the assistant's fixed-list states in §3.1 are assigned by the model that answers you.

5 · Why we collect it

We collect only what each purpose below needs, and nothing for a purpose that is not listed here.

  • To run the service you asked for — which means keeping and working from your sessions (your twin), on your phone and on our servers: your plan, your scores and range, the assistant's answers, your sessions on any phone.
  • Your safety before a session — the agreement in §3.2 is the check we make before the chair runs, and the record that we made it.
  • To run your session and show you your report, your range and your trends.
  • To build and adjust your plan, and to answer you when you ask the assistant.
  • To understand what each protocol does for people — by reading the notes you write after sessions (§3.2).
  • To share what Shiftwave did for you with other people — only a quote you ticked public for and then approved (§3.2, §6).
  • To keep the service running, secure and honest — including knowing that the assistant's crisis path fired, without keeping the words.

We do not use your health data for advertising. We do not sell it. We do not share it for anyone else's marketing.

6 · Who else receives it

We share consumer health data only with service providers who process it on our instructions, under a data-processing agreement, and who may not use it for their own purposes.

category who, today what reaches them
Cloud hosting, storage, and the AI service that answers the assistant Amazon Web Services, including its Bedrock AI service, running a Claude model made by Anthropic. The model runs inside AWS; the company that made the model does not see your messages, and neither AWS nor the model's maker uses them to train anything. everything in §3.1–3.4 that is sent
Speech-to-text, when your phone cannot do it itself Apple your spoken words, to be turned into text
Sign-in Amazon Cognito (our sign-in service, on AWS), and Apple or Google if you sign in with them your sign-in — never your health data
The public — people reading about Shiftwave only if you ticked public on a note and then approved the exact quote that approved quote, and nothing else from your account — no name with it

We have no affiliates that receive your health data. We do not share it with data brokers, advertisers, or analytics companies. We do not share it with any clinic, coach or team unless you ask us to in writing.

If we are ever sold or merged, your data moves only to a buyer bound by these same promises.

You may ask us for the current list of every third party we have shared your health data with, and how to contact them (§8).

7 · How long we keep it

  • What your account collects: while your account is open.
  • Assistant server entries (no words): one month.
  • Sensor recordings: while your account is open, as files separate from your account record.
  • Notes you write after a session: while your account is open, or until you ask us to delete the note (§8).
  • When you delete your account, what it holds goes from our servers; copies in backups are removed within six months; the copies on your phone go when you delete the app.

8 · Your rights, and how to use them

You have these rights over your consumer health data. To use any of them, contact us at the address in §11, or use the control named below. We will confirm who you are using your account email, and we will not charge you.

Withdraw consent. Each thing you agreed to has its own switch. Withdrawing stops anything further being sent; it does not remove what has already gone — use the delete right for that.

what you agreed to where you turn it off
Apple Health readings and what we work out from them on your phone the Health app → Sharing → Apps → Shiftwave → turn off (or Settings → Health → Data Access & Devices → Shiftwave) — nothing from Apple Health leaves your phone in any case
A quote from your note being used publicly (the public tick) write to us (§11) — we stop offering or using your quote from then on; a quote you already approved and we already published is not taken back; the note itself stays with the session
The note you wrote after a session, and our reading of it write to us (§11) — we remove the note from our servers and anything we worked out from it, and stop using it from then on; a copy in a backup goes the way §7 says
Calendar disconnect it — it is read only on your phone in any case
Labs research use Settings, or sign out
The assistant don't use it — nothing is sent unless you ask it something
Your account itself — sessions, scores, safety agreement, and the twin delete your account (below). The service cannot run without the twin, so there is no separate switch for it; withdrawing from it means deleting the account

Confirm and access. Ask whether we collect, share or sell your health data, and get a copy of it, in a portable and machine-readable form — including a list of every third party and affiliate we have shared it with, and an active email or online contact for each.

Correct. Ask us to correct inaccurate health data — your birth year, your display name, your preferences. On request we can re-score your sessions from the original recordings; scores and stars you have already seen may change.

Delete. Delete your account in the app — Settings → "Delete my account" — and everything it holds goes from our servers — at once. If you ask by email instead, within 45 days. We will tell any third party we shared it with to do the same, and remove copies from backups within six months.

Appeal. If we refuse a request, you may appeal by replying to our refusal. We will answer an appeal within 45 days and tell you why. If we still refuse, you may contact your state's Attorney General — Washington: atg.wa.gov · Nevada: ag.nv.gov · Connecticut: portal.ct.gov/ag.

No penalty. We will not deny you the service, charge you more, or treat you differently for using any of these rights. (The safety agreement and the Terms are conditions of using the chair, not consents you can withdraw and keep using it. Accepting the Terms is not a consent to collect your health data; the twin runs because the service needs it, and you were told.)

We respond to requests within 45 days; if we need longer, we will tell you why and take no more than 45 days more.

9 · Where it is processed

On Amazon Web Services in the United States (Oregon). Where that is outside your country, the transfer is covered by the transfer safeguards in our agreement with AWS — today, the European Commission's Standard Contractual Clauses.

10 · Children

Shiftwave accounts are for adults. You must be 18 or older to create one. If you are under 18, Shiftwave can only be used under a coach, clinic or team that has its own agreement with us and your parent or guardian's permission.

11 · Contact, and changes

Cofactor Systems, Inc., doing business as Shiftwave · 513 Garden St, STE G, Santa Barbara, CA 93101, United States · info@shiftwave.co — write there for anything in §8 and say it is about your health data. We are appointing a representative in the EU and in the UK; their details will be added here when the appointment is confirmed.

If we change this notice in a way that matters to you, we will tell you in the app before the change takes effect, and ask again where a change needs your consent. Widening what leaves under a consent you already gave is a new ask, never a notice.

Version 2026-09-23 · Effective 2026-09-23. This notice describes the app as built on 23 September 2026.