MyMomentum · Client portal
Privacy Policy
Updated September 12, 2026 · Private pilot
You choose what to share. Assessment drafts stay private until you submit them to Devon. AI-assisted assessment briefs require a separate choice. Connecting your own Oura account is optional; sharing its movement, sleep and recovery summaries with Devon starts off.
Manage assessment choices in Assessment and Oura sharing in Connected Health. For privacy questions or help with deletion, contact devon@devonmcgregor.com.
Who handles your information
Devon McGregor operates MyMomentum’s private coaching pilot in Toronto, Ontario, Canada and is the contact responsible for its privacy practices. This policy covers shared coaching, assessments, optional AI-assisted Coach Briefs, Connected Health and the account information needed to provide them.
The website privacy notice covers visits to devonmcgregor.com, website analytics and inquiries. Each wearable provider also handles information under its own privacy policy. This policy does not replace those notices or any separate agreement for coaching services.
Assessments and optional AI assistance
The assessment asks about your goals, activity, preferences, everyday support and health or safety context. Continue saves a completed section; Save and close also saves an unfinished section. Saved drafts are available only to your active client account through the portal. Devon’s review queue receives your answers only after you explicitly submit them.
On submission you can separately allow Devon to ask OpenAI to organize your answers into a private draft Coach Brief. This choice starts off and is optional: you can submit for Devon’s direct review without it. If you allow it, MyMomentum sends the assessment answers and their safety context to OpenAI only when Devon requests a brief. It does not add your account name, email, appointments or wearable readings. Anything you type into the answers is included, so avoid unnecessary identifying details and do not copy Oura data into the assessment.
OpenAI processes the request through its API. MyMomentum requests that the response not be stored as a retrievable API response; this does not eliminate OpenAI’s separate security, abuse-monitoring or legal retention. OpenAI’s API data controls explain its processing and retention. Processing can occur outside Canada. The generated brief may be inaccurate and is a draft for Devon to check against your original answers.
MyMomentum encrypts saved answers, generated briefs and Devon’s review notes. Your account can see its own answers and review status. Briefs and notes are private to Devon’s authorized owner account in the portal. The app also records submission time, consent version, your AI choice and a history of reviews and changes to that choice. Submitting does not automatically generate advice, create a program or send a message.
Use Withdraw permission for future AI briefs on a submitted assessment to stop new AI requests for it. A request already sent to OpenAI cannot be recalled. Existing briefs remain in Devon’s review history until the assessment is deleted. Updated answers are submitted as a new assessment; the original submission remains unchanged.
Assessments and their review history remain until you delete them or request deletion. From Assessment, open a saved draft or select a record under Your submitted assessments and use its delete control. Confirming deletion removes that record, its generated briefs and review history from the active app. It does not delete other assessments or information you shared separately. Recovery copies may have different retention controls; contact Devon for access, correction, withdrawal or deletion help, including if your account is no longer active.
Your coaching page
Devon prepares summaries, goals, practice and resource links for individual clients. His drafts stay private until he publishes them to that client’s active portal account. Your progress values, completion choices and optional update notes are shared with Devon when you select Save update. Recent updates remain visible so you and Devon can review changes over time.
MyMomentum encrypts stored coaching text and update notes. The app records the client, publication dates and revision history needed to keep drafts separate and prevent conflicting changes. Revoking portal access stops that account from reading or updating coaching records. A replacement invitation does not automatically inherit previously shared material.
These coaching controls do not automatically send messages or submit content to an AI model. They do not copy your assessments, private Coach Briefs or Oura readings into the coaching page. Resource links open the destination website, which handles your visit under its own privacy practices.
Coaching records and updates remain until Devon deletes the item or handles a deletion request. Deleting an item removes its update history from the active app. Hiding it stops client access but keeps the draft and saved history. Contact Devon for corrections or deletion help, including if your account is no longer active. Recovery copies may follow different retention controls.
What Connected Health collects
MyMomentum receives selected information from a provider only after you authorize that connection. The following summaries are the current import scope, when the connection is available, you grant permission and the provider has the relevant data:
| Provider | Summaries |
|---|---|
| Oura | Steps, sleep score, main sleep duration, readiness score and average sleep heart rate variability (HRV, RMSSD). |
Oura Ring is the only wearable integration currently offered in this web portal. Apple Health and other providers are not offered here.
Each summary includes its source, date, measurement and unit. MyMomentum uses your account name and sign-in email, where provided, to establish account access. The module links the connection to your MyMomentum account and client identifiers and keeps provider connection status, authorization permissions, consent version and time, sharing choices, last successful sync time and limited error codes. It stores encrypted authorization tokens so it can request the summaries you authorize. You enter your wearable password with the provider; MyMomentum does not receive that password.
The current module does not request wearable profile details, location or exercise routes, reproductive health records, ECG recordings or continuous heart-rate streams. Provider permission groups may cover more information than the selected fields MyMomentum imports.
Why we use it and what you share
We use this information to connect your account, display your recent summaries, maintain the connection, record your choices and troubleshoot failures. If you turn on sharing, Devon can use the categories you select to support conversations about your movement, sleep and recovery.
Permission to import into your private portal and permission to share with Devon are separate choices. You can turn each sharing category off in Connected Health. That stops future access to that category through Devon’s coaching view; it cannot undo a conversation or information he already saw while you allowed sharing. You can continue coaching and appointments without connecting a wearable or sharing its summaries.
Connected Health does not sell your wearable information, use it for advertising, or pass its summaries to MyMomentum’s AI Agent. The module does not send wearable summaries to AI models for prompts, training or evaluation. Please do not copy wearable data into the AI Agent yourself.
Storage, service providers and security
The pilot uses OpenAI’s Sites hosting, Cloudflare’s hosting and database infrastructure, and WorkOS for client and owner sign-in. These services process information needed to operate, protect and store the app. Oura processes authorization and data requests; OpenAI processes assessment answers only under the separate AI choice described above. Their processing may take place outside Canada, where local laws may allow government access.
The app encrypts stored wearable summaries and provider authorization tokens. Access checks associate each connection with its signed-in account and limit the coaching view to the sharing choices in effect. Essential sign-in and security cookies support account access and the connection process. Infrastructure services may process technical information such as request times, network addresses, browser details and errors for operation and security.
The wearable module does not intentionally write health summaries or credentials to application logs or analytics. No online service can eliminate every security risk. Unauthorized access to wearable information could reveal sensitive details about your routines or wellbeing; contact Devon promptly if you suspect someone has accessed your account.
We may disclose information where the law requires it or where necessary and legally permitted to address fraud or a security incident. The normal recipients of shared wearable summaries are you and, for the categories you select, Devon.
How long information stays and how to delete it
The current module imports the day of the sync and the previous seven calendar dates, using Toronto time for the request window. A successful sync replaces the previous summary snapshot. This is an import window, not an automatic deletion deadline: if you stop syncing, the last successful snapshot remains until another successful sync or disconnection. A failed sync keeps the previous snapshot and shows its date.
Choose Disconnect and delete in Connected Health to stop imports and sharing and remove the connection’s tokens and imported summaries from the active app. The app also attempts to revoke provider access. If that step fails, it tells you to remove MyMomentum from your provider’s connected-app settings. Disconnection does not delete the provider’s original records.
The app can retain a minimal disconnected-account and consent record after you use that control. Hosting recovery copies can also follow different retention controls from the active database. Contact Devon for a full deletion request, including any remaining provider-related records or recovery copies, or to confirm what has been removed. Do not assume that deleting the active copy erases every other copy immediately.
We handle requests promptly under applicable law and provider requirements. Oura requires deletion of its user data within 72 hours of a deletion request. A request to end the wearable connection or delete its information does not, by itself, cancel coaching or delete information you separately supplied for appointments and coaching.
Your questions, requests and choices
Email devon@devonmcgregor.com to request access, correction or deletion, withdraw consent, or raise a privacy concern. We may ask for enough information to verify your identity before handling an account request. Please identify the account and provider without sending passwords, secret keys or unnecessary health details.
For a measurement error in the source record, correct it with the wearable provider when possible, then sync again. If the problem comes from MyMomentum’s import or display, contact Devon. If you remain dissatisfied with our response, you can contact the Office of the Privacy Commissioner of Canada.
Before connecting another person’s information, including a child’s, contact Devon so we can establish appropriate account access and consent. The connection controls are intended for a participant’s own account.
Changes to this policy
We will update this page when MyMomentum’s practices change. Before introducing materially different data collection, recipients or uses, we will explain the change and obtain any consent it requires. Publishing an updated policy alone does not authorize a new use of information you already shared.
