SUPERSTARIQ PRIVACY & DATA USE

SuperstarIQ Privacy & Data Use Notice

The prelaunch privacy baseline for SuperstarIQ, including health-data separation, AI processing, user-directed sharing, product-versus-training purposes, and future regional or regulated workflows.

Effective: September 9, 2026  ·  Last reviewed: September 9, 2026  ·  Architecture: RTH Governance 2.0

Status: Prelaunch governance standard. The public RestartingTheHeart.com website does not currently accept external health records or wearable-health feeds through these future product workflows. This notice defines controls that must be in place before the described capability is activated.

1. Scope

This notice describes the privacy baseline for SuperstarIQ and related RTH health-intelligence product functions in development. It supplements the general RTH Privacy Policy. Product screens, consent flows, connected-data permissions, research consent, institutional agreements, and regional supplements may provide additional terms that control for the specific workflow.

2. Product status and intended use

SuperstarIQ is in development and validation. It is intended to help organize longitudinal information, preserve source provenance, surface changes and uncertainty, support reflection, and improve communication with trusted professionals. It is not currently represented as a diagnostic system, treatment system, emergency-monitoring system, implanted-device interpretation service, autonomous clinical decision system, or return-to-play clearance system.

3. Categories of information a future product may process

  • account and identity information needed to operate a user account;
  • user-entered symptoms, reflections, goals, notes, questionnaires, and communication preferences;
  • wearable, activity, sleep, heart-rate, HRV, recovery, readiness, or similar data that the user chooses to connect;
  • documents or records the user is specifically authorized to upload through a controlled product workflow;
  • source metadata, timestamps, device/provider identity, consent records, provenance, validation state, and transformation history;
  • product-security, diagnostic, audit, and usage records reasonably needed to operate and protect the service.

4. Purpose limitation

RTH will define a purpose before collecting product data and limit use to that purpose, compatible operational uses, legal obligations, security, and any additional use separately disclosed and authorized. Data collected to provide a personalized product feature is not automatically authorized for research, marketing, advertising, or model training.

5. Product use is not model-training consent

Ordinary use of SuperstarIQ, including personalized retrieval, summarization, user memory, evidence organization, or generation of a user-requested response, does not by itself constitute consent to train or fine-tune a general-purpose RTH model. Any program that uses personal data to train, fine-tune, or materially improve an RTH-owned model will require a separately defined purpose, data-governance review, applicable legal basis or consent, source-license review, and user-facing disclosure. Additional rules appear in the AI & Model Governance Notice.

6. Consumer health data

Health, wellness, biometric, wearable, reproductive-health, symptom, clinical, and inferred health information can be sensitive. RTH will apply data minimization, purpose limitation, access controls, retention rules, consent/authorization where required, and product-specific rights appropriate to the data and applicable law. See the Consumer Health Data Privacy Notice.

7. Connected sources

Connections to Apple Health, Google Health Connect, Samsung, Garmin, Oura, WHOOP, medical-record sources, or other providers will be permission-based and source-aware. RTH will honor provider-specific terms and restrictions even when a user would otherwise be willing to authorize a broader use. See Connected Health Data & Permissions.

8. AI processing and human review

SuperstarIQ may route tasks among deterministic software, approved local models, approved third-party models, and future RTH-owned models according to capability, privacy, safety, and validation requirements. Consequential health, youth, legal, safety, research, or public scientific outputs require heightened controls and human review where defined by RTH governance. RTH does not permit AI to autonomously diagnose, prescribe, clear exercise participation, interpret serious implanted-device events, or substitute for emergency care.

9. Third-party AI providers

Personal or health data will not be sent to a third-party model provider merely because that provider offers an AI service. RTH requires documented vendor approval, purpose limitation, appropriate contract/data-processing terms, security review, and restrictions on provider training. For sensitive health workflows, zero-training and minimum-retention or zero-retention configurations are the target baseline when technically and contractually available. Any material exception requires documented approval and user-facing disclosure.

10. Sharing and clinician-facing outputs

RTH will not treat a clinician-ready summary as permission to transmit it automatically. Sharing with a clinician, coach, parent, school, researcher, employer, insurer, or other third party must follow the user’s direction, an authorized institutional workflow, or another lawful basis. The recipient’s own privacy practices may apply after a user directs a transfer.

11. Advertising and sale

RTH does not intend to sell consumer health data or use personal health data for cross-context behavioral advertising. Product analytics and service improvement must be separated from advertising uses and governed according to the applicable product notice and consent choices.

12. Youth and institutional use

General-purpose personalized AI and health-data workflows are adult-first. A youth or school deployment requires a separate launch review addressing age, parent/guardian authorization where required, school/student privacy, data minimization, safeguarding, role-based access, retention, and prohibited scoring. See the Youth Safeguarding Standard.

13. Research and model-development studies

Product beta testing, quality improvement, scientific research, and model-development research are not automatically the same activity. Research participation must be clearly identified, use an appropriate consent process, and obtain institutional or regulatory review where required. See Research & Pilot Governance.

14. Rights, retention, and deletion

Users will be given rights and controls appropriate to the product and applicable law, including access, correction, deletion, portability, consent withdrawal, or appeal where required. Product retention schedules must be approved before launch and account for backups, legal holds, research records, security evidence, and data that a user previously directed to another recipient. See Data Rights & Requests and Data Retention & Deletion.

15. Security and incidents

RTH will use administrative, technical, and organizational safeguards appropriate to sensitive product information. A health-data incident will be evaluated under applicable breach-notification laws and contractual obligations, including consumer-health-data requirements where applicable.

16. HIPAA and clinical-service separation

Consumer health data is not automatically protected health information under HIPAA merely because it concerns health. If a future RTH workflow operates as or for a HIPAA covered entity, business associate, clinical provider, or another regulated healthcare participant, the applicable BAA, Notice of Privacy Practices, security controls, and clinical governance will be added for that workflow. The general consumer product notice will not be used as a substitute.

17. International and regional supplements

Before offering covered product functions in jurisdictions that require additional notices, legal bases, representatives, transfer mechanisms, data-protection impact assessments, or AI-specific disclosures, RTH will publish and implement the applicable regional supplement.

Privacy and data requests: privacy@restartingtheheart.com. Do not send medical records, passwords, authentication codes, government identifiers, or other unnecessary sensitive information by ordinary email.

Security reports: security@restartingtheheart.com. See the Vulnerability Disclosure Policy before performing security testing.

General questions may use the RTH contact page.