Legal
Grio Washington Consumer Health Data Privacy Policy
Washington-specific notice for consumer health data collected, used, shared, retained, and deleted by Grio.
Last updated: 2026-08-06
Scope
This Washington Consumer Health Data Privacy Policy supplements the Grio Privacy Policy. It applies only to Washington consumers and only to personal information that is consumer health data under the Washington My Health My Data Act. Terms not defined here have the meanings given in the Grio Privacy Policy.
Grio is a general wellness and weight-management service. It is not a healthcare provider, medical device, or emergency monitoring tool.
1. Consumer Health Data We Collect
Depending on the features a user chooses, Grio may collect or create the following categories of consumer health data:
- Profile and goal data: age, selected sex, height, current weight, target weight, weight-management goal, and related onboarding answers
- Meal and nutrition data: meal logs, food names, meal descriptions, meal photos selected by the user, nutrition estimates, and review notes
- Activity and body data: manual activity records, workout summaries, weight records, body measurements, and related trends
- Apple Health data, if explicitly permitted: sleep, steps, active energy, heart rate, HRV, workouts, respiratory rate, wrist temperature, derived daily summaries, indicators, trends, readiness or energy context, sync status, diagnostic metadata, and other wellness context
- Coaching and diary inputs: coach settings, instructions, ritual answers, chat messages, journal entries, and doodles that may reveal wellness or health status
- Derived wellness context: personalized coaching context, readiness or energy indicators, trends, meal and activity interpretations, quality labels, review notes, and other inferences created to provide, evaluate, develop, or improve Grio
- Support, security, and diagnostic information that may include or relate to the categories above when a user contacts us or when we investigate service issues
Grio does not sell consumer health data. Grio does not use HealthKit data, meal records, chat history, or wellness-sensitive content for advertising targeting.
2. Sources of Consumer Health Data
- Directly from the user, including onboarding, manual logs, chat, diary, photos, support messages, and account settings
- From the user's device, Apple Health, or operating-system permission flows when the user chooses to connect those sources
- From the user's interactions with Grio, including app actions needed to operate, debug, and secure the service
- From service providers acting on our behalf, such as AI or infrastructure processors that return analysis, embeddings, summaries, storage records, or diagnostics from data provided to Grio
- From app store billing systems for subscription state and account entitlement information
3. Why We Collect and Use Consumer Health Data
- Provide, operate, personalize, maintain, evaluate, develop, test, and improve Grio's wellness coaching features
- Calculate, store, review, analyze, evaluate, and improve meal, nutrition, activity, body, sleep, readiness, energy, trend, and goal context requested by the user or useful for Grio features
- When the relevant feature is used, analyze meal photos or descriptions and generate, review, evaluate, and improve coaching language, summaries, and personalized context
- Operate accounts, subscriptions, support, account deletion, security, fraud prevention, abuse prevention, diagnostics, internal quality review, product research, and legal compliance
- Create internal notes, labels, summaries, test cases, deidentified data, or aggregated product-quality signals where permitted by law or consent where required
- Communicate service, policy, support, security, billing, and account information
4. Consumer Health Data We Share
Grio may share the categories of consumer health data listed above as needed or useful to provide, operate, personalize, maintain, evaluate, develop, test, secure, support, or improve Grio; at the user's direction; with the user's consent where required; for security; for legal compliance; or with processors that act on our behalf.
Raw HealthKit samples are not sent to Grio servers or AI models. Grio may store, process, analyze, review, combine, summarize, evaluate, and use derived Apple Health summaries, indicators, trends, readiness or energy context, sync status, diagnostic metadata, and other wellness context when needed or useful for requested features, operation, support, quality review, safety, AI evaluation, product research, or product improvement. If a user explicitly chooses or consents to a feature that needs additional health-related data or more detailed derived context, Grio may process that information for the disclosed feature and related operation, support, quality, safety, and improvement purposes.
5. Third Parties and Affiliates
Grio may share consumer health data with the following categories of third parties or processors, limited to the purpose described and subject to consent where required:
- Cloud hosting, database, and storage providers for backend operations and uploaded user-selected photos
- AI processors, including OpenRouter and Google Gemini services, for coaching, meal analysis, memory search, embeddings, summaries, quality evaluation, and feature improvement when the relevant feature is used
- Analytics and diagnostics providers, including PostHog and Sentry, for low-sensitivity product analytics, crash reporting, and debugging under Grio's data-minimization rules
- App store billing systems for subscription status, entitlement, receipts, and billing-support workflows
- Security, legal, compliance, or support providers when needed to protect users, operate the service, respond to requests, or comply with law
Grio does not currently share consumer health data with any specific affiliate.
6. Your Washington Consumer Health Data Rights
Washington consumers may request to confirm whether Grio collects, shares, or sells consumer health data about them; access that data; receive information about third parties or affiliates with whom it has been shared or sold; withdraw consent; or delete consumer health data.
Users can delete their account and data in the app at Settings -> Account and Subscription -> Account deletion. Users can also submit a request by emailing support@getgrio.com from the email address associated with their Grio account or by including enough information for us to authenticate the request.
Grio will respond to authenticated requests as required by applicable law. If we deny a request in whole or in part, the user may appeal by replying to the decision email or emailing support@getgrio.com with "Washington appeal" in the subject line and a reference to the request decision.
7. Consent, Withdrawal, and Permissions
Apple Health connection is optional and controlled through iOS permission flows. Users may revoke HealthKit permission in iOS Settings. When a user uses an AI, image-analysis, embedding, or voice feature, Grio may share the information needed for that feature with the processors and for the purposes described above.
If Grio materially changes the categories of consumer health data it collects, the purposes for collection or use, or the categories of consumer health data it shares, Grio will update this policy and obtain consent where required before the new collection, use, or sharing.
8. Contact
Privacy contact: support@getgrio.com