Privacy Notice
This Privacy Notice explains how Joize FlexCo (“Joize”, “we”, “us”) collects, uses, discloses, and otherwise processes personal data in connection with Joize, a nutrition and longevity coach you reach over iMessage, and any product, service, or application that references or links to this Privacy Notice.
Joize is available globally. Joize FlexCo is an Austrian company, so we apply the EU General Data Protection Regulation (GDPR), one of the world's strictest privacy standards, as our baseline for all users, wherever you live. Where the laws of your country, region, or state give you additional rights, those apply too. See the Region-Specific Disclosures section below. Our Consumer Health Data Notice supplements this Privacy Notice and describes our privacy practices related to consumer health data.
This Privacy Notice does not address our privacy practices relating to job applicants or employees, nor data that is not subject to applicable data protection laws (such as aggregated or de-identified information). It is not a contract and does not create legal rights or obligations not otherwise provided by law.
Who we are
Data controller: Joize FlexCo (Flexible Kapitalgesellschaft (FlexCo))
Registered address: Marktstraße 37, 6850 Dornbirn, Austria
Company register: FN 659178 f, Landesgericht Feldkirch
VAT ID: ATU82391378
Privacy contact: info@healthblokk.com
Our collection and use of personal data
The categories of personal data we collect depend on how you interact with us. You provide personal data directly when you sign up, text the coach, connect an integration, or contact us. We also collect some data automatically when you use the service, and we receive data from the third-party services you choose to connect. The categories below reflect what we actually store on our servers.
Personal data you provide
- Contact and account information, including your name, email address, phone number, timezone, reply preferences, goals, and similar onboarding answers. We use this to create and administer your account, deliver the service, and communicate with you.
- Customer content, including the text messages you send, photos of meals or lab reports, PDFs, and voice notes (transcribed to text before processing). We use this content to provide coaching, fulfill your requests, and maintain conversation memory.
- Sensitive information, including health and nutrition data such as meal logs, estimated macros, biomarker and lab values you share, Apple Health samples you choose to sync, Strava activity summaries, and coaching notes derived from conversation. See our Consumer Health Data Notice for details.
- Payment information. We use Stripe to process payments. We do not retain payment card numbers or other personally identifiable financial information; you provide that directly to Stripe, whose use of your data is governed by Stripe's privacy policy. We store only a Stripe customer ID and your subscription status.
- Reminders and scheduling requests, including scheduled check-ins, follow-up topics, or literal reminder text you ask the coach to remember.
- Feedback and support information, including the contents of messages you send to our support email or in chat about the service itself. We use this to investigate and respond to your inquiries and to improve the service.
Personal data collected automatically
- Phone number. Your iMessage/SMS number is how we identify your account. We do not require a separate username.
- Usage and service logs, including message timestamps, API call metadata for cost and reliability monitoring, webhook delivery records, and dashboard session activity.
- Device and network information on the web dashboard, including standard server logs (IP address, browser user agent) when you open your magic-link dashboard or OAuth consent pages. We may derive general geographic location from your IP address.
We do not use third-party advertising cookies, tracking pixels, or cross-site tracking technologies, and we do not serve targeted advertising.
Personal data from other sources and third parties
- Connected services (optional). You connect these yourself over OAuth or a personal ingest link:
- Google Calendar & Drive: OAuth tokens (encrypted at rest), calendar events the coach creates, and files the coach uploads to a dedicated folder in your Drive.
- Strava: OAuth tokens (encrypted at rest) and activity data the coach reads to inform coaching.
- Apple Health: metrics you route through our iOS Shortcut webhook (for example steps, sleep, heart rate).
- Public research at signup. If you share a LinkedIn profile, website, or name and company during onboarding, we may run a one-time public web lookup to personalize your coach. We store the resulting summary and source links in your profile.
- Other users. If you interact with the coach in a group conversation, we may receive personal data about you from other participants in that conversation.
- Inferences. We generate inferences about your nutrition, training, and preferences from the data above (for example memory summaries, protein intake patterns, biomarker follow-up suggestions) in order to personalize coaching.
Additional uses of personal data
In addition to the primary purposes described above, we may use personal data we collect to:
- Fulfill or meet the reason the information was provided, such as delivering the coaching, reminders, and integrations you request;
- Manage our organization and its day-to-day operations;
- Communicate with you, including via iMessage/SMS and email, about your account, the service, and your use of it;
- Address inquiries or complaints about our products or services;
- Verify your identity and entitlement to the service;
- Administer, improve, and personalize the service, including by remembering your context across conversations;
- Identify and analyze how the service is used, monitor errors, API latency, and aggregate usage to improve reliability;
- Create aggregated or de-identified information that cannot reasonably be used to identify you;
- Maintain the safety, security, and integrity of our service, including verifying webhook signatures, authenticating dashboard sessions, and detecting misuse, fraud, or illegal activity;
- Defend, protect, or enforce our rights or applicable agreements (including our Terms of Service) and resolve disputes;
- Facilitate business transactions or reorganizations impacting the structure of our business;
- Comply with contractual and legal obligations and requirements;
- Fulfill any other purpose for which you provide your personal data or for which you have otherwise consented.
We do not use your messages or health data to train public AI models.
Legal bases for processing
Under the GDPR, we rely on the following legal bases when we process your personal data:
- Contract (Art. 6(1)(b)), processing necessary to deliver the service you signed up for by texting us or completing checkout, including performance of our Terms of Service.
- Consent (Art. 6(1)(a)), optional integrations (Google, Strava, Apple Health), marketing if we ever send it, and processing of health data, which is special-category data under Article 9 GDPR and is processed based on your explicit consent; see the Consumer Health Data Notice.
- Legitimate interests (Art. 6(1)(f)), securing the service, preventing fraud, and improving reliability, balanced against your interests and fundamental rights.
- Legal obligation (Art. 6(1)(c)), tax, accounting, and regulatory retention for payments.
You are not required to provide personal data to us, but we rely on it to provide the service. If you choose not to provide certain personal data, we may not be able to provide you the service you request.
AI processing
We use Anthropic's Claude models to generate replies, extract biomarkers from images, estimate meals, refresh your memory summary, and run optional research passes. Your message content is sent to Anthropic for inference only, under our API terms, Anthropic may not use your data to train its models.
Joize is not a licensed medical provider. Outputs are coaching and educational, not diagnosis or prescription.
Our disclosure of personal data
We do not sell your personal data and we do not share it with ad networks or data brokers. We disclose or otherwise make personal data available in the following ways:
- To service providers that perform services on our behalf: Anthropic (AI inference), Groq (voice-note transcription), Sendblue (iMessage delivery), Supabase (database hosting), Vercel (application hosting), and Stripe (payments). These providers process personal data under contracts that limit their use to our instructions.
- To services you connect or direct us to use, such as saving lab PDFs to your own Google Drive, creating events on your Google Calendar, or reading your Strava activities.
- In connection with a business transaction or reorganization, such as a merger, acquisition, financing, or sale of company assets, in which personal data may be disclosed, transferred, or assigned to a third party as part of the transaction.
- To facilitate legal obligations and rights, including to legal advisors and law enforcement: in connection with the establishment, exercise, or defense of legal claims; to comply with laws or respond to lawful requests and legal process; to enforce our agreements and terms; to detect or prevent fraud; or to protect the health and safety of us, our customers, or any person.
- With your consent or direction, to other third parties or publicly.
Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services necessary to deliver messages to you.
Your iMessage thread vs our servers
On your phone: Messages between you and Joize live in your iMessage (or SMS) app. If you delete that conversation on your device, the copy on your phone is removed. Apple or your carrier controls that local copy, not us.
On our servers: We separately store conversation history, memory, biomarkers, meal logs, and related data so the coach can remember context and serve you over time. Deleting the chat on your phone does not automatically delete our server-side records.
Your privacy choices
Communication preferences
- Text messages: reply STOP at any time to stop receiving messages from the coach. Please note we may still need to send certain service-related messages (such as confirming a deletion request).
- Email: you can stop receiving promotional email (if we ever send it) via the unsubscribe link in any such email. You cannot opt out of essential service emails such as magic-link sign-in messages.
Withdrawing your consent
Where we process your personal data based on consent (for example optional integrations), you may withdraw consent at any time: disconnect Google, Strava, or Apple Health from your dashboard, or revoke access in the provider's own settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Modifying or deleting your personal data
To delete data we hold, text delete my data from your registered number, use the dashboard when available, or email info@healthblokk.com. We will confirm before permanently erasing your account. To correct inaccurate data, update your profile in the dashboard or tell the coach in chat. We may not be able to modify or delete personal data in all circumstances (for example, records we must keep by law).
Device-specific preferences
Your device may provide additional choices about the data you share with us. For example, iOS lets you control which Apple Health metrics the Shortcut may read, and you can disable the Shortcut entirely at any time. Please refer to your device manufacturer's guides for details; we do not control these settings.
Your rights
We extend the rights below, which originate in the GDPR, to all users worldwide, you do not need to live in the EU to exercise them. Subject to certain limitations at law, you have the right to:
- Access (Art. 15), obtain confirmation of whether we process personal data about you, and a copy of that data and information about its processing;
- Rectification (Art. 16), correct or update inaccurate or incomplete personal data;
- Erasure (Art. 17), have us erase your personal data where its continued processing is not otherwise justified;
- Restriction (Art. 18), require us to limit processing where continued processing is not justified, such as where you contest the accuracy of the data;
- Portability (Art. 20), receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller;
- Objection (Art. 21), object to processing based on our legitimate interests on grounds relating to your particular situation;
- Withdrawal of consent (Art. 7(3)), withdraw previously provided consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact info@healthblokk.com from the email address or phone number on your account, specifying the right you wish to exercise. We may need to verify your identity before processing your request, and we respond within one month as required by Article 12 GDPR (extendable where requests are complex). If exercising these rights limits our ability to process personal data, we may not be able to continue providing the service in the same manner.
Complaints
If you have a concern about our processing of personal data, you have the right to lodge a complaint with the supervisory authority where you reside, work, or where an alleged violation occurred. Our lead supervisory authority is the Austrian Datenschutzbehörde. Contact details for other authorities: EEA, United Kingdom, Switzerland. We would appreciate the chance to handle your concerns directly first. Please contact us at info@healthblokk.com.
Retention
- Active accounts: coaching data kept while you use the service.
- Pending buffers: short-lived webhook and meal-confirmation rows (minutes to hours).
- Dashboard sessions: up to 30 days after issue.
- API usage logs: rolling deletion after approximately 180 days.
- After deletion request: personal data erased within 30 days except where law requires longer retention (for example Stripe invoices and tax records).
In general, we retain personal data no longer than reasonably necessary to fulfill the purposes for which it was collected, in accordance with our legitimate business interests and applicable law. Where necessary, we may retain data longer as required by law or as needed to resolve disputes or protect our legal rights. Once retention is no longer necessary, we delete or de-identify the data or, where that is not immediately possible (for example backup archives), securely store and isolate it until deletion is possible.
Security of personal data
We have implemented reasonable physical, technical, and organizational safeguards designed to protect your personal data. OAuth tokens are encrypted at rest, traffic uses TLS, and access to production data is limited to people who need it to operate the service. We also take steps designed to ensure third parties with whom we share personal data provide a similar level of protection. However, no system is perfectly secure and we cannot completely ensure or warrant the security of your personal data. Please do not send passwords or payment card numbers in chat.
International transfers of personal data
We engage third-party providers in various jurisdictions, including the United States, so personal data may be transferred to, stored in, or processed in a country other than the one in which it was collected. The destination country may not provide the same level of protection for personal data as your home country. When we transfer personal data outside of the EEA, UK, or Switzerland, we rely on appropriate safeguards recognized under applicable law, including:
- Adequacy decisions, transfers to countries the European Commission (or other relevant regulatory authority) has deemed to adequately safeguard personal data;
- Standard Contractual Clauses, contractual safeguards adopted by regulatory authorities for transfers to countries without an adequacy decision;
- EU–U.S. Data Privacy Framework, where a U.S. recipient participates in the Framework, we may rely on that participation to ensure adequate protection.
For more information on the specific safeguards we use, contact info@healthblokk.com.
Automated processing
We use automated processing to provide the service you request, including generating coaching replies and personalized subscription pricing bands. We do not process your personal data for purposes that produce a legal or similarly significant effect without appropriate safeguards; you can request human review of pricing decisions that materially affect you by contacting info@healthblokk.com.
Children's personal data
Our services are not directed to, and we do not knowingly collect personal data from, children under the age of 16. If you are under 16, please do not use the service or provide us any personal data. If you believe a child under 16 has provided personal data to us, please contact us and we will promptly delete it.
Third-party websites and services
Our website and service may include links to third-party websites, applications, or services (for example Google, Strava, Apple, and Stripe). This Privacy Notice does not apply to the personal data practices of those third parties. To learn about their practices, please review their respective privacy notices.
Region-specific disclosures
United States state privacy laws
Residents of California, Washington, Nevada, and other states with privacy laws may have additional rights (to know, delete, correct, and opt out of sale or sharing). We do not sell personal information and do not share it for cross-context behavioral advertising. For Washington My Health My Data and similar laws, see our Consumer Health Data Notice. To exercise any of these rights, contact info@healthblokk.com.
United Kingdom and Switzerland
The UK GDPR and the Swiss Federal Act on Data Protection grant rights substantially similar to those described in the Your Rights section above, all of which we already extend to you. Complaints may be directed to the UK Information Commissioner's Office or the Swiss FDPIC.
Other jurisdictions
If the privacy laws of your country or region (for example Brazil's LGPD, Canada's PIPEDA, or Australia's Privacy Act) grant you rights beyond those described in this notice, we will honor them as required by law. Contact info@healthblokk.com to exercise any right available to you.
Updates to this Privacy Notice
We may update this Privacy Notice from time to time. When we do, we will change the “Last updated” date at the top of this page. If we make material changes, we will notify you by message to your registered number, by email, or by prominent posting on this website. All changes are effective from the date of publication unless otherwise stated.
Contact us
If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please contact us at info@healthblokk.com.
Joize FlexCo
Marktstraße 37, 6850 Dornbirn, Austria
FN 659178 f, Landesgericht Feldkirch · VAT ID ATU82391378