Consumer Health Data Privacy Policy
Version 1.8 — last updated September 14, 2026
Ultimate Team Posters, LLC ("Built Different", "we", "us") runs a parent-managed youth fitness membership. This policy is about one specific kind of information: what some state laws call consumer health data. Washington's My Health My Data Act and Nevada's SB370 both require a policy that is separate from a general privacy policy, and both reach fitness and activity information collected by an app, not only records made by a doctor.
We are not a healthcare provider and this is not medical information in the everyday sense. We publish this policy because the law is written broadly and we would rather be plainly inside it than argue we are outside it. It sits alongside our Privacy Policy and, for anyone under 13, our Children's Privacy Notice. Where this policy says something more specific about health data, this one controls.
What we do not collect
We do not collect medical or clinical records, diagnoses, prescriptions, treatment information, medical history, symptoms, test results, insurance information, biometric identifiers, precise location, or information about reproductive or sexual health. We do not ask about injuries, conditions, medications, or disabilities, and there is nowhere in the app to enter them. We do not connect to Apple Health or any other health app, and we do not read data from a wearable.
The health data we do collect
Treated as consumer health data because it describes bodily activity and physical fitness:
- Fitness level and goal. The starting level and main goal chosen for a participant — for example "beginner" and "more movement".
- Weekly activity target. How many days a week a participant is aiming for.
- Activity completed. Which workouts and classes were done, when, and for how long, including workouts logged by hand that happened outside the app.
- Active minutes. The running total, per participant, and the streaks, badges, points and rankings calculated from it.
- Age and age group. Date of birth is collected to confirm eligibility and to group participants fairly; it is stored encrypted.
Where it comes from
- The adult account holder, who types the fitness level, goal and target when creating a profile.
- The app, which records a workout or class as it is completed.
- An adult logging a workout by hand for themselves or for someone in their family.
- A code shared after a live class, redeemed in the app to credit the minutes.
We do not buy health data, receive it from data brokers, or infer it from anything other than the activity described above.
What we use it for
Only to run the service the account holder asked for: choosing and delivering workouts, showing progress, streaks, badges and totals, crediting class attendance, and calculating standings. We also use it in aggregate to understand which workouts are being completed so we can make better ones.
We do not use health data for advertising, we do not build advertising profiles, we do not use it to train machine learning models, and we do not sell it. We have never sold consumer health data and we do not have a process for doing so.
Who we share it with
Inside a family. The account holder and any adults they add can see the activity of everyone on the account. That is the product working as intended.
On the leaderboard, only with separate consent. Showing a participant to other households is not necessary to deliver a workout, so it is never bundled with signing up. It is off for every participant until someone turns it on, and turning it on needs a code emailed to the account address. That opt-in is the health-data sharing consent these laws describe. When it is on, other families see a nickname we assign, an age group, active minutes and a rank — never the participant's display name or last initial, and nothing else. It can be withdrawn at any time in the app, with no code and no waiting.
Service providers, on our instructions only. A provider is allowed to handle this information only where it acts on our instructions alone, is not permitted to use it for its own purposes, and has given us written assurances that it will keep it confidential and secure. Who receives what:
- Application and database hosting — the profile and activity categories listed above, because that is where the account is stored.
- Video hosting and delivery — the request needed to play a workout video, together with the technical information any such request carries.
- Email and SMS delivery — the account holder's address or number, and the contents of the message being sent, which for a class reminder includes the participant's display name and the name and start time of the class, and for the weekly progress recap each participant's display name with their workouts, live classes, active minutes and new badges for the week.
- Apple — the membership product, subscription status and transaction identifiers. Apple does not receive activity data.
- Other households — an assigned nickname, age group, active minutes and rank, and only after the leaderboard opt-in described above. No display name, no last initial, and nothing else identifying.
Affiliates. Ultimate Team Posters, LLC does not share consumer health data with any affiliate.
We may also disclose information where the law requires it or to protect someone's safety. We would tell the account holder unless we were legally prevented from doing so.
Consent, and taking it back
Collecting the health data listed above is necessary to provide the membership that was requested — a fitness app that does not record what you did cannot show you progress. For a participant under 13, the parent gives verifiable consent before any of it is collected, as described in the Children's Privacy Notice.
Sharing that data outside the household is a separate decision and is treated as one. You may withdraw the leaderboard consent at any time without giving a reason and without losing anything you have earned; the participant simply stops being shown. Withdrawing consent does not undo sharing that already happened, and it does not affect the membership.
Your rights
Anyone whose consumer health data we hold may ask us to:
- Confirm whether we hold it, and get a copy in a portable format.
- Tell them which categories of third parties we have shared it with.
- Withdraw consent to collection or to sharing.
- Delete it, including from our backups on their normal cycle.
The account holder can export everything on their account, and delete a profile or the whole account, from the app without contacting us.
A participant may exercise these rights themselves. Participants aged 13 to 17 do not hold their own login, and adults added to a family do not either. That does not make the information any less theirs. Write to us at the address below and say what you want; you do not need an account, and you do not need the account holder's permission to ask. If the request is to stop being shown on the leaderboard, we will act on it first and verify afterwards — the safe direction is to stop sharing.
We will respond within 45 days and may extend once by a further 45 days where a request is complex, telling you why. Verification is proportionate: leaving the leaderboard needs almost none, while a copy of a full history or a permanent deletion needs enough for us to be confident we are not handing a person's records to someone else.
If we say no
You may appeal any decision by replying to it, or by writing to the address below with "Appeal" in the subject line. A different person reviews an appeal from whoever decided it first. We will respond within 45 days with our decision and the reasons for it. If we deny the appeal, we will tell you how to complain to your state attorney general — including, for Washington residents, the Washington State Office of the Attorney General.
How long we keep it
For as long as the account is open, so that progress and streaks continue to mean something — but not forever if nobody comes back. If there is no active membership and the account has had no sign-in, profile change, export or other meaningful activity for 12 consecutive months, we email the account holder, give them at least 30 days, and then delete the participant profiles and their activity records; a legal hold or an unresolved request suspends that. Deleting a participant deletes their activity with them. Deleting an account deletes everything on it. A single participant profile is hidden straight away and permanently erased from our live systems after 30 days, a window that exists only so an accidental deletion can be undone; deleting the whole account erases records from our live systems straight away with no such window. Our database keeps a rolling one-day history for disaster recovery, so a deleted record stays technically recoverable for up to 24 hours and cannot be reached that way afterwards; we keep no separate long-term snapshots, and our hosting platform keeps request logs for 24 hours. The Children's Privacy Notice explains this in full. We keep no shadow copy for analysis. We do produce aggregate counts internally — how many times a workout was completed, for example — to decide what to make next; those are counts, not a second copy of anyone's record, and no third-party analytics service is involved.
Contact us
Ultimate Team Posters, LLC
Mailing address for legal and privacy correspondence:
2170 Dalewood Ct, Plainfield, IL 60586
(630) 864-7869
hello@builtdifferent.com
