Cadence

Privacy Policy

Effective date: 2026-07-10

This Privacy Policy explains how Cadence ("the Service," operated by Brady Thistle Holdings LLC, a New York limited liability company doing business as Cadence Health) collects, uses, and shares your information.

1. Information we collect

  • Account: email address and authentication data.
  • Profile & intake: name, date of birth, and the health and lifestyle details you provide — symptoms (including digestive symptoms), history, diagnoses, medications, supplements, allergies, and goals.
  • Daily tracking: check-in scores and notes, weight if you log it, and — if you enable cycle tracking — menstrual data (period flow logs and the cycle-phase estimates we compute from them).
  • Food & photos: meals you log, including photos of food, menus, or your fridge that you choose to send.
  • Health records you upload: files and screenshots (for example lab reports or old symptom journals) and the AI-generated summaries of them.
  • Coaching data: your chat messages with the coach, the coach's replies, saved memories and playbook entries, and text embeddings (numerical representations of your messages and notes that power the coach's memory search).
  • Community content: posts and comments you choose to publish are visible to other members along with your display name/avatar.
  • Communications data: whether you've opted in to push notifications (with your device's push token and timezone offset) and a log of the emails we send you.
  • Technical: basic device/usage information and, for legal records (your acceptance of these documents and any SMS opt-in), your IP address and browser user-agent.

2. How we use your information

To provide and personalize the Service (including generating AI coaching responses tailored to you); to compute your patterns, insights, and reports; to operate and secure the Service; to maintain records of your agreement to our legal terms; and to communicate with you about your account — including a daily reminder push notification if you turn it on, and a small number of "checking in" emails if you go quiet (each has one-click unsubscribe, and you can turn all non-essential email off in Profile & settings).

3. AI processing

To power the coach, your messages, photos, uploads, and relevant context are sent to our AI provider (OpenAI) to generate responses. Per our configuration and OpenAI's API terms, your data is not used to train OpenAI's models; OpenAI may retain API data briefly (up to about 30 days) for abuse monitoring before deletion. We instruct the coach to act as a non-diagnostic wellness tool. Please don't share information you're not comfortable processing this way.

4. Service providers

We share information only with the vendors that operate the Service on our behalf, acting as our processors: Supabase (database, authentication, file storage), OpenAI (AI responses, reading uploaded reports), Vercel (hosting), Resend (sending our emails), and USDA FoodData Central (food/nutrient lookups — we send food names only, never your identity). If we launch text messaging, our SMS provider will be added here before the first message is sent. We do not have "data partners," and no vendor may use your data for its own purposes.

5. We do not sell your personal information

We do not sell or rent your personal information, and we do not share it for advertising. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with, or sold to, any third parties. (Message and data rates may apply to any future SMS program; reply STOP to opt out.)

6. Consumer health data

Much of what Cadence collects is consumer health data — symptoms, digestive health details, menstrual data, medications, and health records. For this data we commit to the following, which also serves as our consumer health data privacy policy under laws like Washington's My Health My Data Act:

  • We collect it only with your affirmative consent, given when you accept these documents and check the separate health-data consent at sign-up, and only for the purposes in Section 2 — never for advertising.
  • We never sell consumer health data, and we will never share your menstrual data with anyone except the processors in Section 4 acting on our instructions.
  • You can withdraw consent at any time by deleting your account (Section 8) or emailing brady@cadencehealth.io — we'll stop processing and delete your health data per Section 9.
  • Deletion reaches derivatives too: deleting your data includes the AI summaries, insights, and embeddings computed from it.
  • We do not use geofencing, and we do not collect precise location.

Story submissions (before you have an account). Our free written-report tool collects your story, symptoms, history, and email from you before you create an account, only with the separate affirmative health-data consent you check on the submission screen. We use it solely to create and deliver your report (processed by our AI provider under Section 3 — not used to train their models) and, if you choose, one follow-up check-in email — never for advertising, and our advertising pixels are never present on the pages where you enter or read health information. If you don't create an account and claim your report, we delete the entire submission — story, answers, and report — 45 days after you submit it. If you do claim it into an account, it becomes account data covered by this policy, including deletion under Section 8. You can request earlier deletion any time at brady@cadencehealth.io.

Wearable & device data. If you connect a wearable (such as an Oura ring or a Whoop band), we collect the daily metrics you authorize on the device maker's own consent screen — for example sleep, readiness, heart-rate variability, resting heart rate, breathing rate, blood-oxygen, temperature, and activity. When you connect, we retrieve your recent history (up to roughly 60 days) as well as new data going forward. This is consumer health data, handled under this Section: it is read by the AI coach that powers Cadence (processed by our AI provider under Section 3, and not used to train their models) to surface patterns alongside your check-ins, and it is never sold and never shared with advertisers — our advertising pixels are never present inside the app. You can disconnect a device at any time in your settings; disconnecting deletes the data we pulled from it, by default, and you can delete it or your whole account anytime under Section 8. We retain connected wearable data for the life of your account unless you disconnect the device or delete it sooner.

7. Legal process & government requests

If we receive a subpoena, court order, or other legal demand for your data, we will disclose only what we are legally compelled to disclose, after reviewing the demand's validity; where the law allows, we will notify you before responding so you can object. We do not volunteer member data to law enforcement.

8. Your rights & choices

Wherever you live, we honor these rights: you may access your information, correct it (much of it is editable in the app), export it, and delete your account and data — email brady@cadencehealth.io from your account email and we will verify and fulfill your request within 30 days, or use the tools in the app where available. We will never discriminate against you for exercising a privacy right. California residents: the categories above include "sensitive personal information," which we use only to provide the Service, and we do not sell or "share" personal information as the CCPA defines those terms; you may exercise all rights via the same email. If you are in a jurisdiction with additional rights, we will honor a verifiable request to the same address.

9. Data retention

We keep your information while your account is active. When you delete your account (or ask us to), we delete your personal data — including chats, check-ins, cycle logs, uploads, memories, and embeddings — within 30 days, except: records of your legal acceptances and anything we must keep to meet legal obligations, which we retain as required and then delete. Backups age out on our providers' standard schedules.

10. Security & breach notification

We protect your information with access controls, per-user database security rules, and encryption in transit and at rest via our providers, and we maintain a written data-security program. No system is perfectly secure. If a breach affects your unsecured health information, we will notify you without unreasonable delay consistent with the FTC Health Breach Notification Rule and state breach-notification laws, and tell you what happened and what we're doing about it.

11. Cadence is not a HIPAA service

Cadence is a direct-to-consumer wellness product, not a healthcare provider or health plan, so the data you give us is not covered by HIPAA. This policy — not HIPAA — is what protects it. (If you export a summary and give it to your clinician, their copy is covered by their obligations.)

12. Cookies & tracking

Inside the app, we use only the cookies required to keep you signed in — no advertising cookies, no third-party analytics trackers, no social-media pixels, ever. Our public marketing pages (such as the landing page) use Meta's standard measurement pixel so we can tell whether our ads work; it is never present inside the signed-in app, and nothing about your health data, check-ins, or coaching is ever shared with advertisers. Your data is processed and stored on servers in the United States.

13. Children

The Service is for adults 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has used the Service, contact us and we will delete the information.

14. Changes

We may update this policy. If we make material changes, we will update the effective date and ask you to re-accept in the app before continuing.

15. Contact

Questions about your privacy: brady@cadencehealth.io — Brady Thistle Holdings LLC (d/b/a Cadence Health), 116 Westmont Avenue, Elmira, NY 14905.