Legal
Privacy Policy
Not yet effective. Contact details and retention, deletion, and data-handling practices must be confirmed before publication.
01. About this policy
OmniBand is operated by C&Si Unlimited Space Innovation Technology (Shenzhen) Co., LTD (“we”, “us”, or “our”).
This policy describes how OmniBand processes information when you create an account, connect supported health providers, import Apple Health files, and use your dashboard. Provider services have their own privacy policies.
02. Information we process
- Account information: your email address or phone number, account profile, and authentication information used for registration, sign-in, and account recovery.
- Connected health information: records made available by Oura, WHOOP, or Google Health (Fitbit) under the permissions you grant. Depending on your source, these may include sleep, activity, workouts, heart rate, and recovery metrics.
- Imported information: the Apple Health ZIP file you upload, supported records extracted from it, and import progress information.
- Connection and service information: provider authorization credentials held by the backend, synchronization status, and operational information needed to deliver and troubleshoot the service.
03. How information is used
OmniBand uses account information to authenticate you and manage your session. Connected and imported health information powers the dashboard, provider views, readings, and trends you request. Connection and import status helps show whether data is available and whether an operation needs attention.
The application uses session cookies for authenticated requests. The browser does not store or refresh provider access or refresh tokens. It may store an Apple Health import job identifier locally so it can resume displaying import progress.
04. Google & Fitbit data
Connecting Google Health (Fitbit) sends you to the provider’s authorization flow. Review the consent screen for the exact permissions requested. OmniBand uses the authorized data to provide its health synchronization and dashboard features.
Proposed Limited Use commitment, pending operator confirmation: OmniBand’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Such data will not be sold, used for advertising, or used to train generalized AI or machine-learning models. Human access and transfers will be limited to the purposes and exceptions permitted by that policy.
You can review or remove Google account connections at Google Account connections. Other providers offer access controls in their account settings.
06. Retention & deletion
Revoking provider access prevents future access under that authorization; it does not by itself delete information already imported into OmniBand.
Before publication, the operator must specify how long account information, health records, uploaded files, logs, and backups are retained, and provide a working process for requesting account and data deletion, including any legal retention exceptions.
07. Your choices
You choose whether to connect a provider or upload an Apple Health file. You can decline provider permissions or revoke an existing authorization in the provider’s settings; features requiring that data may then be unavailable.
Depending on where you live, you may have rights to access, correct, export, or delete personal information and to object to or restrict certain processing. A verified contact channel for exercising these rights must be included before publication.
08. Contact & updates
Publication details pending: the privacy contact has not yet been supplied. This draft must not be used as the final consent-screen privacy policy until those details and the outstanding practices above are confirmed.
The final policy will display an effective date. Material changes to privacy practices should be communicated through an appropriate service notice.
See also our terms of service.
OmniBand