CORLYNX · WEBSITE & APP

Privacy policy

Draft for review · September 2026. The legal operator, contact details, launch territories, and app data practices must be confirmed before this policy is adopted for public use.

1. Scope and responsibility

This draft covers the Corlynx information website, its beta interest list, and the planned Corlynx performance app. The website’s collection is described below. App sections describe intended categories and must be reconciled with the actual beta before release. The legal operator, business address, and privacy contact email are awaiting confirmation.

2. Information on this website

If you join the interest list, the website stores your email address, submission time, consent-text version, and confirmation that you are 18 or older. This is used to manage your interest and contact you about beta opportunities and Corlynx launch updates. The form does not request training files, medical information, passwords, or payment information.

The website is configured for delivery through Firebase App Hosting and Google Cloud. These hosting services may process connection information such as IP address, browser information, requests, and security logs to deliver and protect the site. The interest list is stored in Google Cloud Firestore. No advertising pixels, analytics scripts, or nonessential tracking cookies have been added to this website. Hosting or access-control services may use necessary storage or cookies.

3. App information, when features are enabled

The app is being developed to process the following information as needed for the features you choose:

Joining the website interest list does not authorize any of this app data collection. Available integrations and exact data permissions will be explained before you connect a source or use the relevant feature.

4. Purposes and permissions

Information is used to deliver requested features, associate information with the correct account, analyze training and recovery, calculate and explain performance estimates, provide support, maintain security, and meet legal obligations. Permission to receive launch emails is separate from permission to process app health or activity information.

Where applicable, processing relies on consent for optional communications and sensitive information, performance of the user agreement for requested services, legal obligations, or legitimate interests in security and service operation. The operator must confirm the applicable legal bases and any separate consumer-health-data notice for supported territories before launch.

5. Sharing and service providers

Website service providers receive information needed for hosting, storage, and security. The app architecture plans to use Firebase and Google Cloud for authentication, storage, and computation; the final deployed provider list and locations must be confirmed before beta. If an AI explanation feature is enabled, its provider, information sent, and permitted uses must be disclosed before activation. This website does not send form submissions to an AI model.

The proposed policy is not to sell personal information or use health and activity information for targeted advertising. This commitment, any research use, and any model-training use must be verified against app implementation and vendor agreements before adoption. Authorized disclosures may also be necessary to comply with law, protect people and services, or support a business transfer subject to applicable protections and notice.

6. Your choices and requests

You can withdraw consent to beta and launch emails. Each email should provide an unsubscribe method. The operator’s privacy email must be added here before the list is opened to customers so you can request removal without waiting for an email.

Depending on applicable law, you may have rights to access, correct, delete, or receive a copy of your information; restrict or object to certain processing; withdraw consent; and complain to a supervisory authority. Reasonable identity verification may be needed. Revoking a device or connected-service permission stops future access through that permission but does not by itself delete information already imported. The released app must explain disconnection and deletion options.

7. Retention and deletion

Interest information should be retained only while needed for the beta and launch communications you requested, or for legal obligations. It should be removed from the active list on withdrawal; limited suppression records may be needed to honor that choice. App data should be retained only as needed to provide the service, address disputes, and meet applicable obligations. The operator must confirm the retention periods, backup deletion schedule, and request-handling process before public collection begins.

8. Security, transfers, and incidents

Access to collected information should be restricted to authorized personnel and service providers. The site form validates submissions and stores them server-side; the website does not publish the email list. No system can guarantee absolute security.

Providers may process information outside your state or country. The operator must verify processing locations and legally required transfer safeguards for supported territories. If an incident occurs, Corlynx must assess and provide notifications required by applicable privacy and health-data laws.

9. Children and changes

The interest list is intended for adults aged 18 and older. It is not intended to collect children’s information. The app’s age eligibility will be confirmed before release. If child information is received, the operator should arrange its deletion through the privacy contact.

The final policy will include its effective date. Changes to purposes, providers, or collection will be reflected in an updated policy, with additional notice and consent where required.

← Back to Corlynx