Privacy Policy
Slynk processes health data to verify wellness objectives. Your employer sees that you completed your goal — never your specific health metrics. Here is exactly how it works.
Effective July 25, 2026
1. Our Privacy Principles
We limit how personal information is used and give members meaningful choices over connected health data.
- Minimum Necessary Data: For Apple Health, Slynk requests the data types needed for the objective you select. Other tracking providers may bundle multiple permissions; their authorization screen shows what access is requested.
- Employer Sees Outcomes Only: Your employer sees whether you completed your objective and how much you earned. They never see your step counts, sleep data, heart rate, or any raw health metric.
- Encrypted at Rest and in Transit: All data is encrypted using industry-standard protocols. Health data is encrypted at rest in our database and in transit between your device, our servers, and third-party providers.
- Isolated by Company: Slynk uses tenant access controls designed to separate one participating organization's information from another's.
- Deletion Requests: You can request deletion of your account and associated data through the app or by contacting support. Your account remains active while we review active challenges, earned rewards, pending withdrawals, raffle entries and applicable retention requirements. We will respond within 30 days and confirm when processing is complete.
- No Profiling or Scoring: We do not build health profiles, assign risk scores, or use your data for anything beyond objective verification. There is no algorithmic health assessment.
2. What Data We Collect
The information collected depends on how you use Slynk, the objective you select, and the tracking provider permissions you grant.
Account Information
Provided by you, your participating organization, or your identity provider to establish eligibility and operate your account.
- Name
- Work email address
- User and company identifiers
- Company association
- Profile image URL, if provided
Health and Activity Data
Collected with your permission from Apple Health or a connected provider. Depending on the provider permissions granted, available data may extend beyond the metric used for your current objective.
- Steps, distance and active calories
- Workout type, time, duration and distance
- Sleep duration
- Provider-authorized heart, body, respiratory, temperature or nutrition metrics
- Location-related workout data, where a provider includes it
Device and Provider Information
Technical and connection information used to authenticate, sync activity, send notifications, secure the Service and troubleshoot issues.
- Tracking provider and connection identifier
- Device and installation identifiers
- Push-notification token
- Device model and operating system
- Timezone, locale and app version
Usage and Analytics
Firebase and our systems collect information about app use, reliability and performance. Analytics and crash reports may be associated with your Slynk user ID or an app installation identifier.
- Screen views, taps and feature usage
- Challenge and provider selections
- Crash reports and error details
- Performance traces and network timing
- Session and app-installation identifiers
Rewards and Financial Records
Information required to administer employer-funded rewards and withdrawal requests. The iOS app does not collect payment-card or bank-account details.
- Reward and raffle balances
- Credits earned
- Withdrawal amount and status
- Transaction and claim history
Support, Surveys and Communications
Information you choose to submit when contacting support, requesting deletion, or responding to an in-app survey.
- Support category, subject and message
- Deletion requests
- Survey ratings and selections
- Free-text survey responses
- Device diagnostics included with support requests
Website and Contact Information
When you visit our website or contact our business team, our hosting and communications providers may process technical request data and the information you submit.
- IP address and browser information
- Pages visited and basic website analytics
- Name, work email and company
- Contact or demo-request message
3. How We Use Your Data
- Verify daily progress toward your wellness objective by comparing your activity data against your selected goal.
- Display your progress, balance, and history within the Slynk app so you can track your own performance.
- Generate aggregated, anonymized reports for your employer showing participation rates and program outcomes — never individual health data.
- Process payout claims when you request to receive your earned benefit credits as cash.
- Send you notifications about your objective status, new periods, and important account updates.
- Authenticate your account, maintain provider connections, prevent fraud, secure the Service, and troubleshoot support requests.
- Measure product usage, diagnose crashes and performance issues, respond to surveys, and improve Slynk.
4. Sources, Service Providers and Disclosures
We receive information from you, your participating organization, your identity provider, your device, and tracking providers you choose to connect. We use service providers to operate Slynk; they may process information only for contracted services and subject to applicable obligations.
Terra API and connected tracking providers
Terra facilitates connections to providers such as Garmin, Fitbit and WHOOP and processes provider connection identifiers and health and fitness data authorized through the provider. Each provider controls its own permission screen and may bundle several data types into a permission.
Apple Health
The Slynk iOS app reads the Apple Health data types requested for your selected objective after you review Apple's permission sheet. Slynk does not write data to Apple Health.
Google Firebase
Firebase supports authentication, analytics, crash reporting, performance monitoring, cloud messaging and backend functionality. Depending on the service, Google processes user or installation identifiers, product interactions, device details, crash information, performance data, IP-derived country and push-notification tokens.
Workplace identity providers
Google Workspace or Microsoft Entra may authenticate your work account. Slynk receives authentication results and account information needed to create and maintain your session.
Participating organizations and other providers
Your participating organization provides eligibility and program information and receives the limited program outcomes described below. We may also use hosting, security, communications and professional-service providers and disclose information when required by law or to protect rights, safety and the Service.
We do not sell personal information or health data, and we do not use health or fitness information for third-party advertising, data-broker activity, insurance underwriting or employment decisions.
Service providers may process information outside your province, state or country, including in Canada, the United States and other locations where they operate. Information in another jurisdiction may be subject to that jurisdiction's laws and lawful access requests.
5. What We Never Do
These commitments govern how Slynk uses personal information.
- We never sell your data to third parties. Not to advertisers, data brokers, insurers, or anyone else.
- We never share your individual health metrics with your employer. They see completion status and earned credits — nothing more.
- We never use your health data for insurance underwriting, employment decisions, or any form of discrimination.
- We do not retain health data indefinitely; we retain it only for the operational, audit, dispute-resolution and legal periods described below.
- The Slynk iOS app does not request device location permission. A connected provider may include location-related workout information if its permission screen authorizes that data.
- We never use your data to train machine learning models or build predictive health profiles.
6. What Your Employer Can and Cannot See
Privacy boundaries are enforced by system architecture. These are not configurable settings — they are hard limits.
Your employer CAN see
- Whether you have an active objective this period
- Whether you completed or did not complete your objective
- How much you earned in benefit credits
- Claim amounts on invoices (when you request a payout)
Your employer CANNOT see
- Your step counts, sleep data, or any raw health metric
- Which objective type you chose (walking, running, cycling, sleep)
- Your daily progress or qualifying day counts
- Your connected tracking provider or device information
7. Data Security and Retention
Slynk uses administrative, technical and organizational safeguards designed to protect personal information. Communications use TLS encryption, databases use encryption at rest, and authentication tokens are stored in the iOS Keychain. No method of storage or transmission is completely secure.
We retain account, program, objective, reward and transaction records while your account or participating program is active and afterward as reasonably required for program administration, unclaimed rewards, audits, disputes, security, legal compliance and enforcement. Health and activity records are retained for objective verification, audit and dispute-resolution needs rather than indefinitely.
Firebase and other service providers apply their own documented retention schedules. For example, diagnostic and performance records may be retained for limited service-specific periods. Provider access continues until disconnected, revoked or otherwise terminated.
We respond to a verified deletion request within 30 days. Submitting a request does not immediately delete the account or automatically cancel an active challenge, earned reward, pending withdrawal or raffle entry. We review each request, then delete or de-identify information unless limited retention is required or permitted for financial records, legal obligations, fraud prevention, security, disputes or enforcement. We confirm when processing is complete and explain any limited information retained. Aggregated or de-identified information that cannot reasonably identify you may be retained.
8. Your Rights
You have control over your data. Here is what you can do at any time.
Access your data
Request a copy of all personal data we hold about you, including activity records and account information.
Correct your data
If any information we hold about you is inaccurate, contact support and we will correct it promptly.
Delete your data
Request deletion of your account and personal data. Your account remains active during review. We will respond within 30 days, confirm when processing is complete and explain any limited information retained.
Revoke provider access
Disconnect your tracking provider at any time through the app settings or through your provider's settings. This stops future data collection immediately.
Withdraw from the program
Participation in Slynk is voluntary. You can stop participating at any time without penalty from Slynk. Contact your employer about any company-specific wellness program policies.
Complain or appeal
Contact our Privacy Officer if you have a concern about our handling of personal information or a decision concerning a privacy request. You may also contact the privacy regulator with jurisdiction where you live.
9. Changes to This Policy
We may update this policy to reflect changes in our practices, providers, technology or legal obligations. We will post the revised policy and update its effective date. When appropriate, we will provide additional notice in the app or by email before a material change takes effect.
10. Contact the Privacy Officer
To ask a privacy question, exercise an applicable right, request access, correction or deletion, or raise a complaint, use the in-app support feature or email our Privacy Officer. We may need to verify your identity before completing a request.
privacy@slynk.com