MyMomentum · Connected Health

Privacy Policy

Effective September 6, 2026 · Private pilot

You control the connection. Connecting a wearable is optional. MyMomentum imports selected summaries after you authorize your account. Sharing with Devon starts off; you choose movement, sleep and recovery separately.

You can stop sharing or disconnect in Your Rhythm → Connected Health. For privacy questions or help with deletion, contact devon@devonmcgregor.com.

Who handles your information

Devon McGregor operates MyMomentum’s private coaching pilot in Toronto, Ontario, Canada and is the contact responsible for its privacy practices. This policy covers Connected Health, its wearable connections and the account information needed to provide them. It applies to the pilot even while the portal runs at a separate web address.

The website privacy notice covers visits to devonmcgregor.com, website analytics and inquiries. Each wearable provider also handles information under its own privacy policy. This policy does not replace those notices or any separate agreement for coaching services.

What Connected Health collects

MyMomentum receives selected information from a provider only after you authorize that connection. The following summaries are the current import scope, when the connection is available, you grant permission and the provider has the relevant data:

Supported summary types by provider
ProviderSummaries
OuraSteps, sleep score, main sleep duration, readiness score and average sleep heart rate variability (HRV, RMSSD).
WHOOPCycle strain, main sleep duration, sleep performance, recovery score, resting heart rate and HRV (RMSSD).
Fitbit through Google HealthDaily steps, main sleep duration, daily resting heart rate and HRV (RMSSD).

Apple Watch, Samsung Watch and Garmin connections remain in development. Listing a provider does not mean its connection has completed setup or real-account testing.

Each summary includes its source, date, measurement and unit. MyMomentum uses your account name and sign-in email, where provided, to establish account access. The module links the connection to your MyMomentum account and client identifiers and keeps provider connection status, authorization permissions, consent version and time, sharing choices, last successful sync time and limited error codes. It stores encrypted authorization tokens so it can request the summaries you authorize. You enter your wearable password with the provider; MyMomentum does not receive that password.

The current module does not request wearable profile details, location or exercise routes, reproductive health records, ECG recordings or continuous heart-rate streams. Provider permission groups may cover more information than the selected fields MyMomentum imports.

Why we use it and what you share

We use this information to connect your account, display your recent summaries, maintain the connection, record your choices and troubleshoot failures. If you turn on sharing, Devon can use the categories you select to support conversations about your movement, sleep and recovery.

Permission to import into your private portal and permission to share with Devon are separate choices. You can turn each sharing category off in Connected Health. That stops future access to that category through Devon’s coaching view; it cannot undo a conversation or information he already saw while you allowed sharing. You can continue coaching and appointments without connecting a wearable or sharing its summaries.

Connected Health does not sell your wearable information, use it for advertising, or pass its summaries to MyMomentum’s AI Agent. The module does not send wearable summaries to AI models for prompts, training or evaluation. Please do not copy wearable data into the AI Agent yourself.

Storage, service providers and security

The pilot uses OpenAI’s Sites hosting and sign-in services and Cloudflare’s hosting and database infrastructure. These services process information needed to operate, protect and store the app. Your selected wearable provider processes authorization and data requests. Their processing may take place outside Canada, where local laws may allow government access.

The app encrypts stored wearable summaries and authorization tokens. Access checks associate each connection with its signed-in account and limit the coaching view to the sharing choices in effect. Essential sign-in and security cookies support account access and the connection process. Infrastructure services may process technical information such as request times, network addresses, browser details and errors for operation and security.

The wearable module does not intentionally write health summaries or credentials to application logs or analytics. No online service can eliminate every security risk. Unauthorized access to wearable information could reveal sensitive details about your routines or wellbeing; contact Devon promptly if you suspect someone has accessed your account.

We may disclose information where the law requires it or where necessary and legally permitted to address fraud or a security incident. The normal recipients of shared wearable summaries are you and, for the categories you select, Devon.

How long information stays and how to delete it

The current module imports the day of the sync and the previous seven calendar dates, using Toronto time for the request window. A successful sync replaces the previous summary snapshot. This is an import window, not an automatic deletion deadline: if you stop syncing, the last successful snapshot remains until another successful sync or disconnection. A failed sync keeps the previous snapshot and shows its date.

Choose Disconnect and delete in Connected Health to stop imports and sharing and remove the connection’s tokens and imported summaries from the active app. The app also attempts to revoke provider access. If that step fails, it tells you to remove MyMomentum from your provider’s connected-app settings. Disconnection does not delete the provider’s original records.

The app can retain a minimal disconnected-account and consent record after you use that control. Hosting recovery copies can also follow different retention controls from the active database. Contact Devon for a full deletion request, including any remaining provider-related records or recovery copies, or to confirm what has been removed. Do not assume that deleting the active copy erases every other copy immediately.

We handle requests promptly under applicable law and provider requirements. Oura requires deletion of its user data within 72 hours of a deletion request. A request to end the wearable connection or delete its information does not, by itself, cancel coaching or delete information you separately supplied for appointments and coaching.

Your questions, requests and choices

Email devon@devonmcgregor.com to request access, correction or deletion, withdraw consent, or raise a privacy concern. We may ask for enough information to verify your identity before handling an account request. Please identify the account and provider without sending passwords, secret keys or unnecessary health details.

For a measurement error in the source record, correct it with the wearable provider when possible, then sync again. If the problem comes from MyMomentum’s import or display, contact Devon. If you remain dissatisfied with our response, you can contact the Office of the Privacy Commissioner of Canada.

Before connecting another person’s information, including a child’s, contact Devon so we can establish appropriate account access and consent. The connection controls are intended for a participant’s own account.

Changes to this policy

We will update this page when Connected Health’s practices change. Before introducing materially different data collection, recipients or uses, we will explain the change and obtain any consent it requires. Publishing an updated policy alone does not authorize a new use of information you already shared.

Moving MyMomentum onto devonmcgregor.com will not by itself expand your sharing permissions. We will explain any changes to account access, data handling or provider authorization that the move requires.