Last updated: October 9, 2026
This Privacy Policy explains how Staroly Inc. ("Staroly", "we", "us", or "our") collects and processes personal data in connection with the Second Wind mobile application (the "App"), the website secondwindapp.com including quiz.secondwindapp.com (the "Site"), and related digital services (collectively, the "Services").
We recognise the importance of privacy and data protection and are committed to processing personal data in accordance with applicable data protection and privacy laws, including, where applicable, the General Data Protection Regulation (GDPR), the UK GDPR, and relevant United States state privacy laws. We aim to collect and process only the data that is necessary for defined and legitimate purposes connected with the operation and improvement of our Services.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this document, you should not use the Services.
The short version. We collect what you tell us in the quiz and what you log in the App, and we use it to build and run your plan. Information about your body and your joints is health-related data, and we treat it that way: it is never used for advertising and never sold. Optional advertising measurement uses your device’s advertising identifier only if you allow tracking in Apple’s system prompt. If you opt in on iOS, we use Amplitude to understand onboarding, purchases and use of the App, including session completion and duration, under pseudonymous account and random analytics device identifiers. We do not send Amplitude your name, email, questionnaire answers, joint ratings, body measurements, meal details, photos or Apple Health records. Meal photos are analysed on request; we do not save them in your account, and our AI provider may retain them under its API retention policy. In the App, you can delete your account and associated records from our active app systems. For email deletion requests, or requests about records held by analytics, payment and subscription providers, contact support@secondwindapp.com.
Delete your Second Wind account explains how to request deletion and what is deleted or retained.
For the purposes of applicable data protection law, Staroly Inc. acts as the data controller for personal data processed in connection with the Services. This means that Staroly Inc. determines the purposes and means of processing your personal data described in this Privacy Policy.
Where certain technical, hosting, communication, payment or support functions are provided by third-party vendors, those vendors act as our data processors or as independent controllers depending on their role. Where required by law, we enter into appropriate data processing agreements with such providers to ensure that personal data is processed only under documented instructions and subject to appropriate safeguards.
If you have questions about this Privacy Policy you may contact us at:
Staroly Inc.
42 Reads Way, Suite 42V, New Castle, County of New Castle, Delaware
19720, United States
S99 Group LTD
Archiepiskopou Makariou III, 107 Flat/Office 102, Konia, 8300, Paphos,
Cyprus
We may request verification information before responding to privacy requests in order to protect user data from unauthorised disclosure.
This Privacy Policy applies to personal data collected through your interaction with our Services across different channels and touchpoints. It covers data collected when you visit our Site, complete the onboarding questionnaire, create an account, purchase a subscription, use the App, connect Apple Health, contact customer support, receive communications from us, or otherwise interact with our infrastructure.
The Policy applies regardless of whether you access the Services through the iOS or Android App, a desktop browser, a mobile browser, or another digital interface that links to this Privacy Policy. It also applies to communications between you and us by email.
This Privacy Policy does not apply to third-party websites, platforms, or services that may be linked from within our Services, including the Apple App Store and Google Play. Where you follow a link to a third-party resource, their privacy practices will apply independently.
The categories of personal data we process depend on how you interact with the Services, what features you use, and what information you choose to provide. The current joints questionnaire requires a name to use in the App and the answers needed to choose and adapt your exercise plan. Some questions appear only when relevant to earlier answers. Joint journal entries and available food and weight features are optional.
The questionnaire and your first sessions work without providing an email address or password. For guest use, the App automatically creates an account identifier to save your answers and plan. We collect the name you enter in the questionnaire. If you register an account, we also collect your email address and account credentials (a password stored only as a secure hash, or a Sign in with Apple identifier on supported Apple devices). We also process account configuration data, subscription status and service settings connected to your profile. When you sign in with a one-time code sent to your email, we process that email address and the code.
Sign-in after installation. Where available, choosing “Get my plan” on our Site lets us copy a one-time sign-in link to your clipboard for use after installation. On an eligible first launch, the App may read clipboard text once to look for this link, subject to iOS paste permission. A recognized Second Wind sign-in credential is sent to our existing authentication provider, Supabase, for verification. Unrelated clipboard text is ignored and is not saved, logged or uploaded. We keep a nonsecret local marker to prevent repeated automatic checks and do not send clipboard contents to analytics or advertising providers. Your device settings may synchronize copied text to your other devices. You can decline paste and instead sign in using the link or code in your email.
Because the Services build an exercise plan around your body, we process the answers you give in the questionnaire. These may include: your goal; which joints or areas you ask us to work around (for example knees, hips, back, shoulders or balance) and other limitations you choose to share (for example shortness of breath or pregnancy); your answers to a short safety checklist of signs we ask you to check with a doctor first (such as a hot or swollen joint, a recent fall, or recent surgery), and your dated acknowledgement of that reminder; your age range; how active your day is; how often and when you want to exercise; what tends to get in the way; and what you want to get back. If you choose the food and weight features, we also process your sex, height, weight and, where you set one, a target weight, in order to estimate a calorie target.
This information is health-related personal data and, in some jurisdictions, sensitive personal information. We apply enhanced care in its handling: it is used only to build, adapt and keep your plan safe for you, and to show your own progress back to you. It is never used for advertising or marketing purposes and never sold.
Completed sessions and session history, weight entries, water, and meals — including calorie and macronutrient estimates from the food scanner. If you use the joint journal, we also store your dated check-ins: the body area, discomfort rating, stiffness duration, selected everyday activity and movement difficulty. We store any after-session feedback you submit about whether your joints feel better, the same or worse. These entries are linked to your account and displayed in your journal.
When you photograph a meal, the photo is sent securely to our server, analysed by Anthropic to estimate calories, protein, carbohydrates and fat, and removed from our request processing. We do not save the photo on our servers or in your food log; we save the resulting nutrition values. The scan request is authenticated to your account, but we do not send your name, email address, account ID or health records to Anthropic with the image. Anthropic's standard API policy deletes inputs and outputs within 30 days, with exceptions for legal obligations and policy enforcement. API inputs are not used for model training by default. See Anthropic's API retention policy.
If you grant permission on your device, the App reads your step count, sleep and weight from Apple Health and writes the weight you log and your completed sessions to Apple Health. Steps and weigh-ins you choose to import are stored in your account like hand-entered entries; sleep is displayed to you in the App and is not stored by us. Health data obtained through Apple Health is used only to provide the features you requested. It is never used for advertising or marketing, never sold, and never disclosed to third parties other than the infrastructure provider that stores your own account data. You can revoke access at any time in the Health app on your device.
When you contact customer support or communicate with us, we process the content of your communications, your email address, and related metadata, so that we can respond, troubleshoot issues, and improve service quality.
If you subscribe, we record your subscription status (which product, whether it is active, when it expires) and related subscription events. Payments themselves are processed by third-party payment service providers: Apple for App Store purchases, Google for Google Play purchases, and Stripe for purchases made on the Site. We do not collect or store full payment card numbers. Depending on your geographic location, billing country, or transaction structure, Staroly Inc. or an affiliated entity may act as the merchant of record for Site purchases and is responsible for billing, invoicing, tax calculation and financial reporting for the transaction. In connection with a Site purchase, we may receive limited transaction metadata from the payment provider, such as truncated card numbers, card brand, card country, expiration date, and transaction status identifiers, which are used for accounting, fraud prevention, customer support, and compliance purposes.
When you use the Services we and our infrastructure providers automatically process limited technical data such as IP address, device type, operating system, app version, language settings, approximate region derived from IP address, request timestamps and error logs. This information helps us maintain security, ensure system stability and diagnose problems. Our subscription provider, Adapty, collects account and device identifiers, purchase events and paywall interactions to manage subscriptions and understand subscription performance. On iOS, access to the advertising identifier (IDFA) is disabled unless you allow tracking through Apple’s App Tracking Transparency prompt.
On iOS, optional product analytics starts only after you agree to it. You can decline and continue using the App, including paid features, and change your choice in the You tab under Privacy → Share app analytics. Your choice applies to the current account on the current device. We use Amplitude to understand where people stop during onboarding or a purchase, which features they use, and whether they return. With your permission, we send selected events such as onboarding progress, screen views, paywall and purchase results, program discovery, session starts and completions, session duration and counts, and the use of logging features. Events include timestamps, app and operating-system information, a random analytics device identifier and your internal account identifier. These identifiers are pseudonymous, not anonymous: we can associate the account identifier with your account.
Amplitude does not receive your name, email address, questionnaire answer values, joint check-in or after-session feedback values, body measurements, meal contents or nutrition values, photos, or Apple Health records. Our Amplitude configuration excludes advertising identifiers and location, disables IP-based location collection, and does not use session replay or automatic interaction capture. This analytics data is used to improve Second Wind, not to target advertising or send audiences to advertising providers. Apple's tracking choice applies to the separate advertising-identifier use described below.
We use the information you enter to build a personalised exercise plan and, if you choose the food features, a calorie estimate. This processing is automated and rule-based, and is used only to provide the Services to you. We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you. The plan and estimates are general wellness content and should not be relied upon as the basis for medical decisions.
We process personal data only where there is a defined and legitimate purpose connected to the operation, delivery, protection, or improvement of the Services. Different categories of personal data are processed for different purposes, and not all data is used for all purposes.
If you are located in the European Economic Area or the United Kingdom, we process your personal data only where we have a valid legal basis under applicable law.
Where processing is necessary to provide the Services you requested, including account creation, building and running your plan, and subscription features, the legal basis is performance of a contract or steps taken at your request prior to entering into a contract. Without this processing, we cannot deliver the requested functionality.
Health-related data (your questionnaire answers about your joints, limitations and safety signs, your weight, and Apple Health data) is processed on the basis of your explicit consent, which you give when you choose to provide it in the questionnaire, log it in the App, or grant Apple Health permission. You may withdraw consent at any time by deleting the relevant data or your account, or by revoking Apple Health permission; withdrawal does not affect processing already carried out.
Where you have actively agreed to specific processing activities, such as receiving marketing communications or allowing non-essential measurement technologies on the Site, the legal basis is consent. You may withdraw consent at any time.
Optional product analytics is based on your consent, including explicit permission for the described session-use information. You can withdraw this consent in the You tab under Privacy → Share app analytics without losing access to the App or your subscription. Withdrawal stops new collection for that account on that device and does not affect processing already carried out. Contact us to request access to or deletion of analytics data already sent.
Certain processing activities are based on our legitimate interests in operating and improving the Services, provided those interests are not overridden by your rights and freedoms. This includes service security, fraud prevention, and system diagnostics. We may also process personal data where necessary to comply with legal obligations, such as financial recordkeeping.
We may send users communications relating to the Services, including service messages and, where permitted, marketing messages. Service communications include transactional and operational messages such as sign-in codes, purchase receipts, subscription notices, renewal reminders, security alerts, and policy updates. These communications are necessary for service delivery and are not dependent on marketing consent.
Marketing communications may include product updates, educational content about staying active, and promotional offers. For users in jurisdictions that require prior consent for electronic marketing, including the European Union and the United Kingdom, we send marketing messages only where we have obtained appropriate consent. For users in jurisdictions that allow opt-out marketing models, including parts of the United States, we may send marketing messages where permitted by law, provided that every message includes a clear and effective unsubscribe mechanism. You may opt out at any time using the unsubscribe link in any marketing email or by contacting us, and opt-out requests are honoured promptly. We maintain suppression lists so that users who unsubscribe are not contacted again for marketing purposes.
In the App: on iOS we ask for permission through Apple’s App Tracking Transparency prompt before enabling access to your device’s advertising identifier (IDFA). If you choose Allow, our subscription provider Adapty can receive that identifier alongside account, subscription and paywall events for advertising attribution and measurement of our own ads. If you decline, IDFA collection remains disabled; sessions, account access and subscriptions still work. You can change this permission in iOS Settings → Privacy & Security → Tracking. Subscription processing continues independently of your tracking choice. We never use or share your questionnaire answers, joint journal, workout records or Apple Health data for advertising. As of September 8, 2026, Meta, AppsFlyer and other external advertising integrations are not connected to the App. Before enabling one, we will update these disclosures and the App Store privacy label to reflect the actual data shared and its purpose.
On the Site: we may use advertising measurement and attribution technologies, such as pixels provided by advertising platforms (for example Meta), to measure the performance of our own advertising and understand how visitors arrive at the Site. Where we do, these technologies may disclose to the advertising partner identifiers such as cookie IDs and IP address, page events, and approximate location. We never pass your questionnaire answers, health-related data or Apple Health data to advertising partners. These disclosures may constitute "sharing" of personal information for cross-context behavioural advertising under California law and "targeted advertising" under the laws of Colorado, Virginia and other US states. We do not sell personal information in exchange for monetary compensation.
The Site uses strictly necessary browser storage to keep your place in the questionnaire and to complete a purchase. Where required by applicable law, non-essential measurement technologies are used only with your consent, and you can withdraw it through the Site's consent controls where offered, through your browser settings, or by enabling Global Privacy Control (GPC), which we honour where supported. You may also opt out of targeted advertising or sharing at any time by emailing support@secondwindapp.com.
| Data category | Who | Processing purpose | Lawful basis (EU/EEA/UK) | Lawful basis (United States) |
|---|---|---|---|---|
| Email address, account credentials, Sign in with Apple identifier / Identifiers | Registered users | Account creation, sign-in, account management, service communication | Contract performance | Contract performance |
| Questionnaire answers about joints, limitations, safety signs; weight, height, sex, age range / Sensitive personal information (health); Inferences | Users who complete the questionnaire | Building and adapting a personalised exercise plan; calorie estimate where chosen | Explicit consent; Contract performance | Contract performance; Consent |
| Joint check-ins, after-session feedback, session history, weight, water and meal logs / Sensitive personal information (health) | App users | Scheduling, tracking and progress display | Explicit consent; Contract performance | Contract performance |
| Apple Health data (steps, sleep, weight) / Sensitive personal information (health) | Users who grant Health permission | Progress display; walking and weight tracking | Explicit consent | Consent / user-controlled permission |
| Meal photos / User content | Users of the food scanner | Nutrition estimate; no photo saved in your account; provider retention described above | Contract performance | Contract performance |
| Subscription status and events / Commercial information | Customers | Subscription management, access control | Contract performance; Legal obligation | Contract performance; Legal obligation |
| Payment metadata (last 4 digits, card brand, country, expiry, transaction status) / Commercial information | Users who purchase on the Site | Payment verification, fraud prevention, accounting, disputes | Contract performance; Legal obligation; Legitimate interest | Contract performance; Legal obligation; Fraud prevention |
| Support communications / Identifiers; Internet activity | Users contacting support | Responding to inquiries, troubleshooting, dispute resolution | Contract performance; Legitimate interest | Legitimate business purpose |
| Technical log data (IP address, timestamps, device, app version) / Identifiers; Internet activity | All users | Security, error diagnosis, system integrity | Legitimate interest | Legitimate business purpose |
| Device identifiers collected by our subscription provider's SDK / Identifiers | App users | Receipt validation and subscription management | Contract performance; Legitimate interest | Contract performance |
| Product analytics: account and analytics device IDs, onboarding, purchase and feature-use events, session completion and duration / Identifiers; Internet activity; Commercial information; fitness activity | App users | Understanding onboarding, purchases, feature use and return visits; improving the App | Consent; explicit consent for health-related activity | Optional service improvement with consent |
| Advertising measurement identifiers on the Site (cookie IDs, pixel events) / Identifiers; Internet activity | Site visitors, where measurement is enabled | Measurement and attribution of our own advertising | Consent | Legitimate business purpose; Opt-out right |
| Marketing preferences and consent records / Identifiers | Users | Consent tracking and compliance | Legal obligation; Legitimate interest | Legal compliance |
Sensitive personal information (California disclosure). Under California law, the health-related information described above is "Sensitive Personal Information". We use it only to provide the Services you requested, maintain security, and for the related operational purposes described in this Privacy Policy. We do not sell or share Sensitive Personal Information for cross-context behavioural advertising, and we do not use or disclose it for purposes other than those permitted by law. We do not collect precise geolocation data.
We do not sell your personal data. We do not authorise third parties to use your personal data for their own independent purposes except as described in this Privacy Policy. We share personal data with third parties only where this is necessary and proportionate for defined purposes and subject to appropriate safeguards:
Because we rely on specialised infrastructure, AI, payment and communication providers to operate the Services, certain personal data is processed by third-party service providers acting on our behalf under contractual data processing agreements. These providers are not permitted to use personal data for their own unrelated purposes. Each receives only what its job requires. The main providers we use are listed below.
| Category | Purpose | Name | What it handles |
|---|---|---|---|
| Database, authentication and hosting | To store your account and the data described above, and to send sign-in emails | Supabase (supabase.com/privacy) | Your account and everything described above, encrypted in transit and at rest |
| AI analysis | To estimate nutrition from meal photos in real time | Anthropic (anthropic.com/privacy) | The photo without account ID, name or email; provider API retention applies; no model training by default |
| Subscriptions and optional advertising measurement (App) | To manage subscription status, measure subscription performance and, with tracking permission, attribute advertising | Adapty (adapty.io/privacy) | Account ID, subscription events, paywall interactions and device identifiers; iOS advertising identifier only with ATT permission. No health or workout records. |
| Product analytics (App) | To understand onboarding, purchase completion, feature use and use of guided sessions | Amplitude (Privacy Notice) | Pseudonymous account and analytics device IDs, selected usage and purchase events, session completion and duration, and app/device context. No name, email, health-answer values, body measurements, meal details, photos, Apple Health records, advertising identifiers or location. |
| App Store payments | To process purchases made through the App Store | Apple (apple.com/legal/privacy) | Your purchase, under Apple's own terms; Apple Health data stays on your device unless you import it |
| Google Play payments | To process purchases made through Google Play | Google (Privacy Policy) | Your purchase, under Google's own terms and privacy policy |
| Payments on the Site | To process purchases made on the Site | Stripe (stripe.com/privacy) | Your email address and card details, under Stripe's own terms |
| Website hosting | To host the Site | Netlify (netlify.com/privacy) | Standard web server logs, including your IP address |
| Typefaces on the Site | To display fonts on the Site (not the App) | Google Fonts (policies.google.com/privacy) | Your IP address, as with any web resource request |
| Advertising measurement on the Site | To measure the performance of our own ads, where enabled | Meta Pixel (facebook.com/privacy/policy) | Cookie identifiers, page events, approximate location; never questionnaire or health data |
Because Staroly Inc. is incorporated in the United States and we use international infrastructure and service providers, personal data may be transferred to and processed in countries other than the country in which you are located, including the United States and other jurisdictions where our service providers operate.
Where personal data originates from the European Economic Area or the United Kingdom and is transferred to a country that has not been recognised as providing an adequate level of data protection, we implement appropriate safeguards as required under applicable data protection laws. These safeguards may include Standard Contractual Clauses approved by the European Commission or the UK authorities, together with supplementary contractual, organisational, and technical measures where appropriate. You may contact us for additional information about the transfer safeguards applicable to your data.
We retain personal data only for as long as it is reasonably necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Account and profile data, questionnaire answers, and activity logs are retained while your account exists, so that your history and plan keep working. If you start the questionnaire on the Site but do not create an account or complete a purchase, the anonymous record is deleted or anonymised within approximately 30 days. We do not retain meal photos; Anthropic's API retention is described in the Meal photos section. Subscription and transaction records are retained for the period required by accounting and tax law. Support communications are retained for a limited period to ensure continuity of service and proper handling of complaints. Technical logs are retained for limited security and diagnostic periods.
Product analytics is retained separately by Amplitude to understand usage over time and improve the App. You can request deletion of the analytics data associated with your account by contacting us. Deleting your account in the App does not automatically erase data already held by Amplitude; we handle those requests separately. We do not describe a device-identifier reset or signing out as deletion of stored analytics.
When you delete your account, or when retention periods expire, we delete, anonymise, or irreversibly de-identify personal data. Some data may remain in secure backup systems for limited periods until overwritten in the normal backup cycle.
We implement technical and organisational security measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure. All data travels over encrypted connections (TLS) and is encrypted at rest by our infrastructure provider. On your device, your session is stored in the operating system's secure keychain. Passwords are stored only as secure hashes. Access to personal data is limited to authorised personnel and contractors who require access for legitimate operational purposes and who are subject to confidentiality obligations. Each user can read and write only their own records.
While we take reasonable steps to protect personal data, no method of transmission or storage is completely secure, and absolute security cannot be guaranteed. In the event of a data security incident affecting personal data, we will act in accordance with applicable breach notification laws.
Depending on your location and applicable law, you may have certain rights and choices regarding your personal data. We honour the requests below for everyone, by email, without a form.
You also have the right to lodge a complaint with your local data protection authority if you believe that your personal data has been processed in violation of applicable data protection laws. We encourage you to contact us first so that we may address your concerns directly.
For users located in the United States, and depending on your state of residence, your rights may include: the right to know what categories of personal data we collect and use; the right to access personal data about you; the right to request deletion; the right to correct certain inaccuracies; the right to opt out of targeted advertising or the sharing of personal information; and the right to limit the use of sensitive personal information. We will not discriminate against users for exercising their privacy rights. If we decline to take action on your request, you may appeal our decision by contacting us; we will review your appeal and inform you of the outcome within the required timeframe.
You may exercise applicable privacy rights by emailing support@secondwindapp.com. Requests may include access to personal data, correction of inaccurate data, deletion, restriction, objection to certain processing, portability, and marketing or advertising opt-outs. Please describe your request with enough detail to allow us to understand and respond to it.
We respond to privacy requests within the timeframes required by applicable law. Where permitted, we may extend the response period when requests are complex or numerous, and we will notify you if an extension is needed. There is generally no fee for submitting a privacy rights request; where requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline the request where permitted by law.
To protect users against unauthorised data disclosure or deletion, we may need to verify the identity of the person submitting a privacy request. Verification will usually mean confirming control of the email address associated with the account. We will request only the minimum information necessary for verification and will use it solely for that purpose. If identity cannot be reasonably verified, we may be unable to fulfil certain requests. Where requests are submitted through authorised representatives, we may require proof of authorisation and separate identity verification of the user.
You can review, update, or delete your data directly in the App. The You tab lets you change your goal, plan and targets, manage Apple Health access, manage your subscription, and delete your account. Successful in-app deletion immediately and permanently removes your account, profile, quiz answers, plans, session history, joint check-ins, after-session responses, and food, water and weight logs from our active app systems, subject to the limited retention described above. This action does not automatically erase records held separately by analytics, payment and subscription providers; contact us with requests about those records.
See Delete your Second Wind account for the in-app steps, email request option and deletion timeframes.
The Services are intended for use only by individuals who are 18 years of age or older, or the age of majority in their jurisdiction if higher. We do not knowingly collect personal data from anyone below that age. If you believe that a minor may have provided personal data to us, please contact us so that we can investigate and delete it.
We may update this Privacy Policy from time to time to reflect changes in legal requirements, technology, business practices, or service features. When we make changes, we will update the "Last updated" date at the top of this Policy. If we make material changes that affect how we collect, use, or disclose personal data, we will provide additional notice in the App or by email before the changes take effect, and, where required by applicable law, obtain your consent.
If you have questions about this Privacy Policy, our data practices, or your privacy rights, you may contact us at:
Registered office: Staroly Inc.
42 Reads Way, Suite 42V, New Castle, County of New Castle, Delaware
19720, United States
S99 Group LTD
Archiepiskopou Makariou III, 107 Flat/Office 102, Konia, 8300, Paphos,
Cyprus
If you require this Privacy Policy in an alternative format due to a disability, please contact us and we will make reasonable efforts to provide it in an accessible format.