Consumer Health Data Privacy Policy

Effective date: September 16, 2026 · Last updated: September 16, 2026 · Version 1.0
Who this is from: Soltra LLC, a California limited liability company (“Soltra”, “we”, “us”)

This policy applies to Washington residents and anyone whose consumer health data is collected in Washington, to Nevada residents and anyone whose consumer health data is collected in Nevada, and to Connecticut residents, under Washington's My Health My Data Act, Nevada Senate Bill 370 and Connecticut's consumer health data law. It describes the consumer health data the Soltra iPhone app collects and how it is handled. Our general Privacy Policy covers everything else.


1. The consumer health data we collect

Soltra collects the following categories of consumer health data, all of it only with your permission and only from sources you turn on:

We do not collect data about health conditions, diagnoses, treatments, medications, reproductive or sexual health, gender-affirming care, or biometric identifiers, and we do not infer any of those from what we collect.

2. Where it comes from

3. Why we collect it

We use consumer health data only to provide the features you asked for:

We collect and share consumer health data only to the extent necessary to provide the features you asked for, and otherwise only with your consent, which you give on Soltra's own screens before each source is turned on and can withdraw at any time (Section 6). We do not use it for advertising, marketing, profiling, research, or any purpose other than the features above and we do not use it to make decisions about you.

4. The categories of consumer health data we share, and with whom

Soltra does not sell consumer health data. If that ever changed, we would first obtain the signed authorization the law requires, which you could revoke at any time. Soltra has no affiliates, so none receive it. We share it only as follows:

WhoWhatWhy
Supabase, Inc. (our hosting provider; privacy contact: supabase.com/privacy, [email protected])All categories in Section 1It stores and processes your data on our servers, on our instructions, under a contract that restricts it to that purpose
Apple Inc. (apple.com/privacy/contact)Workouts, routes, energy and distance from activities you record in SoltraOnly if you allow Soltra to write to Apple Health
Strava, Inc. (strava.com/legal/privacy; [email protected])The GPS route, distance, altitude, elapsed and active time, elevation gain, type and title of activities you record in Soltra (a phone recording carries no heart rate, cadence, power or temperature; steps and calories are never sent)Only if you connect Strava, and only until you disconnect. Strava then holds that data under its own privacy policy; its interface gives us no way to delete it, so delete it in Strava if you wish

Mapbox, Inc. (mapbox.com/legal/privacy), whose software draws the map inside Soltra, receives the map area you are viewing so it can draw it. That software can also send Mapbox de-identified location telemetry; Soltra switches that off, and it stays off unless you turn it on yourself from the map's ⓘ menu. We list it here because it is location software running while you may be exercising.

Google LLC (Firebase Cloud Messaging; policies.google.com/privacy, support.google.com/policies) and Apple Inc. (push notifications; apple.com/privacy/contact) deliver the notifications you turn on. Neither receives consumer health data: a notification can name a place you lit up or a rounded figure, but never a coordinate, route, or health reading.

Our usage analytics provider (PostHog) and crash-reporting provider (Google Firebase Crashlytics) receive no consumer health data: analytics events never contain routes, locations, heart rate, calories, or any other health value, nor any count of your activities, photos or files, and automated tests in our code enforce this.

We do not permit any third party to collect consumer health data about you over time and across different websites or online services when you use Soltra.

We may also disclose consumer health data when the law requires it (for example in response to a valid subpoena), to protect someone's safety, or to a successor if Soltra is sold, in which case this policy continues to apply and we will notify you first.

5. Your rights

You have the right to:

6. How to exercise them

We respond within 45 days of receiving a verifiable request and may extend once by a further 45 days if we tell you why. A deletion is completed within 30 days of our verifying the request, and never more than 45 days after we receive it: your data is removed from our servers, copies in our hosting provider's backups expire within 7 days, and we instruct the companies in Section 4 that hold data for us to delete it. Strava's interface gives us no way to delete activities already in your Strava account; where the law requires us to notify Strava of your request, we will. We do not charge for a request unless it is clearly excessive or repetitive and we never treat you differently for exercising a right.

7. Changes to this policy

If we materially change this policy, we will tell you in the app at least 30 days before the change takes effect and update the dates at the top. Earlier versions are available on request.

8. Appeals

If we decline a request, we will tell you why and how to appeal. To appeal, reply to our decision or write to [email protected] with the subject “Appeal”. We will answer within 45 days. If the appeal is denied, you may contact your state attorney general: in Washington, the Office of the Attorney General at atg.wa.gov; in Nevada, the Office of the Attorney General at ag.nv.gov; in Connecticut, the Office of the Attorney General at portal.ct.gov/ag.

9. Contact

Privacy requests and questions: [email protected]
Post: Soltra LLC, 440 N Barranca Ave #5017, Covina, CA 91723, United States