LivingMotions

Privacy Policy · Effective 16 September 2026

Your data should work for you.

Who this policy covers

This policy covers the LivingMotions website, two-week beta trial, member account, group insights, wearable summaries and wellness experiments. LivingMotions is intended for adults aged 18 or older and does not provide medical diagnosis or treatment.

Information we collect

Account and program information: name, email, optional mobile number, optional profile photo, city or suburb, password hash, wearable and plan choices, group membership, consent records, personal wellness goal, trial status, challenge check-ins and notes.

Fitbit data through Google Health: only after your separate authorization, we request read-only sleep, activity and fitness, and health-measurement categories. Depending on your device and what is available, this may include sleep duration and stages, steps, distance, active minutes, timestamped heart-rate observations, resting heart rate, HRV, SpO₂ and respiratory rate.

Oura data: only after your separate authorization, we request read-only daily summaries, sleep and readiness data, heart-rate data and SpO₂ data. Depending on your ring and what is available, this may include sleep duration and stages, activity, steps, timestamped heart-rate observations, HRV, respiratory rate, temperature deviation, readiness and Oura scores.

We store OAuth access and refresh credentials in encrypted form so the connection can continue without asking for your provider password. LivingMotions never receives your Google, Fitbit or Oura password.

How and why we use information

We use account information to create and secure your account, operate the trial, form suitable small groups, respond to you and manage wearable availability. We use authorized wearable data to import daily summaries, compare recent periods with your own baseline, evaluate your voluntary wellness experiments and, when you separately enable group sharing, create same-group comparisons.

Group sharing is reciprocal and limited to members assigned to the same group. It shows your name, an optional profile photo you upload, and summarized statistics such as LivingMotions readiness, sleep, steps, resting heart rate, HRV and active minutes for the dates selected. When group sharing is enabled, LivingMotions may send the same summarized group statistics and a short-lived private group link to your registered mobile number. It does not show contact details, private notes, raw provider payloads or connection credentials. We do not sell personal or wearable data, use it for advertising, or determine insurance or employment eligibility.

Consent and control

Wearable connection is optional. Before leaving LivingMotions for a provider's authorization screen, you receive a separate, prominent explanation of the data requested and how it will be used. The provider then lets you review and authorize access. You may decline without creating a connection.

You can enable or withdraw reciprocal group sharing and disconnect Fitbit or Oura in settings. Withdrawing group sharing immediately removes your wearable summaries from the group view, stops daily group-summary messages and removes your access to other members' summaries. Private SMS links expire automatically and should not be forwarded because anyone holding an unexpired link can view that group summary. Disconnecting revokes the provider credential where supported and deletes the imported daily summaries from that provider. You may also revoke LivingMotions in your Google or Oura account. You can permanently delete your account and all associated LivingMotions records from settings after confirming your password.

Sharing and service providers

We disclose information only as needed to operate LivingMotions, provide group sharing you enable, comply with law, protect users, or with your direction. Other consenting members of your assigned group can view your summarized statistics but may not use or disclose them outside the group. Current infrastructure providers may include Supabase for database services, Vercel for website hosting, and Resend for transactional email. These providers process information on our behalf under their own security and contractual controls.

LivingMotions does not automatically send identifiable Google Health or Oura data to a generative-AI service. If you deliberately connect the optional read-only AI connector, the summarized data requested in your AI conversation is sent to the provider you chose, such as Anthropic or OpenAI, at your direction and under that provider's terms and privacy controls. Designated LivingMotions administrators may also use a read-only administrative connector to retrieve customer account, program, challenge and wearable records when operating the service. Administrative connector access excludes passwords, session secrets and wearable-provider credentials. The connector cannot change LivingMotions data, and its access can be revoked in settings.

LivingMotions' use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Oura data is handled subject to the permissions you grant and Oura's applicable developer terms.

Retention and deletion

We keep account information while your account or trial is active and only as long as reasonably needed for the purposes above, security, disputes and legal obligations. Imported wearable summaries and encrypted credentials are kept while the connection remains active. Disconnecting a provider deletes that provider's imported summaries from the live product; deleting your account deletes all live account, credential, wearable and challenge records.

Limited residual copies may remain temporarily in encrypted provider backups until those backups rotate, or where retention is legally required. We do not use deleted information for new product analysis. You may also email us to request access, correction or deletion.

Security and international processing

We use encrypted transport, encrypted OAuth credentials, restricted server-side database access, expiring login sessions and access controls intended to protect health information. No system is perfectly secure. If we identify a breach requiring notice, we will notify affected people and regulators as required.

Our service providers may process information outside Australia. We select established providers and use reasonable safeguards appropriate to the sensitivity of the information.

Your choices and contact

You can access your current account and wearable status in settings, correct signup details by contacting us, disconnect either provider, opt out of program communications, or delete the account. Privacy questions and requests can be sent to info@livingmotions.com.

We may update this policy as the beta changes. Material changes affecting wearable-data use will be disclosed before they apply and, where required, presented for renewed consent.

Terms of Service · Privacy controls · Return home