Privacy policy
How Cortisol+ handles your biometric data: on-device processing, no data selling, opt-in cloud sync, and your rights under GDPR and CCPA — in plain English.
Updated October 5, 2026 · By Cortisol+ Editorial
Effective date: October 5, 2026.
This Privacy Policy describes how Elevated Systems LLC ("we," "our," "us") collects, uses, and protects information when you use the Cortisol+ mobile app (the "App"), the cortisolplus.com website (the "Website"), and any related services (together, the "Service").
Questions or requests: admin@elevatedsystems.info.
1. Summary
- Your biometric data stays on your device. We do not upload your Apple HealthKit data to our servers.
- We do not sell your data — ever. Not to advertisers, insurers, employers, or third parties.
- We measure our ads, not your health. The App includes Meta's SDK (and AppsFlyer on iPhone) so we can tell which ads lead to installs and subscriptions. Health readings are never part of this. See section 3.6.
- You can delete the App and all on-device data at any time. If you have an account, you can delete it in-app.
2. Who we are
The Service is operated by Elevated Systems LLC, the data controller for purposes of GDPR and similar laws.
- Legal name: Elevated Systems LLC
- Studio website: https://elevatedagency.org/
- Privacy contact: admin@elevatedsystems.info
3. Information we collect
3.1 Biometric data from Apple HealthKit (on-device only)
With your explicit consent, the App reads the following data types from Apple HealthKit:
- Heart rate, heart rate variability (HRV / SDNN), resting heart rate
- Sleep stages (REM, deep, core, awake) and sleep timing
- Wrist temperature deviation (Apple Watch Series 8+)
- Blood oxygen (SpO₂)
- Activity (steps, active calories, VO₂ max, workouts)
- Date of birth and biological sex (used only to personalize baselines)
This data is processed entirely on your device. It is never uploaded to our servers, never shared with third parties, and never used for advertising. We use HealthKit in read-only mode and never write data back to your Health record.
3.1a Biometric data from Fitbit via the Google Health API (optional)
If you choose to connect a Fitbit account, the App reads the following data from Google's Health API with your explicit consent, granted through Google's sign-in and permission screens:
- Heart rate, nightly heart rate variability, resting heart rate
- Sleep sessions and sleep stages (REM, deep, light, awake)
- Nightly skin temperature variation, blood oxygen (SpO₂), breathing rate
- Activity (steps, active calories, cardio fitness / VO₂ max)
Google user data is handled the same way as HealthKit data: processed on your device, read-only, never sold, never used for advertising. You can disconnect Fitbit at any time in the App (Settings → Health Data) or revoke access at myaccount.google.com/permissions.
3.2 Account information (only if you create an account)
If you create a Cortisol+ account to use social or sync features, we collect:
- Email address
- Display name and (optional) profile photo
- App preferences and friend connections you choose to add
- Authentication identifiers (e.g., Apple Sign-In token if used)
3.3 Transaction information (subscriptions)
All subscription transactions are processed by Apple through the App Store. We do not receive your payment method, card details, or full billing information. Apple provides us with anonymized transaction identifiers and subscription status only. On Android, subscriptions are processed by Google Play in the same way. We use RevenueCat to check subscription status; it receives your purchase receipts and an app user ID, not your payment details.
3.4 Diagnostic data (opt-in)
If you opt in, the App may send anonymized crash reports and aggregated usage metrics (e.g., which features are used, error rates). This data does not contain biometric values or personally identifying information.
3.5 Website information
The Website at cortisolplus.com may collect basic, non-identifying analytics (page views, referrer, country-level location, browser type) to help us understand which content is useful. Google Analytics and the Meta Pixel run on the Website only if you opt in; see Website analytics and cookie choices.
3.6 Advertising measurement (App)
We advertise Cortisol+ on platforms such as Facebook and Instagram. To learn which ads work, the App includes Meta's software development kit (the "Meta SDK") on iPhone and Android, and AppsFlyer on iPhone. These tools collect:
- App events: that the App was installed and opened, and when a subscription or free trial starts or renews
- Device identifiers: your device's advertising identifier (Android advertising ID; on iPhone, only if you allow tracking when asked) and a Meta anonymous ID
- Basic device information: device model, operating system, app version, language, time zone and IP address
They never receive your health, biometric, Fitbit, Health Connect or HealthKit data, your stress scores, your name or your email address. Subscription events may be sent by the App or by RevenueCat, our subscription provider. Meta and AppsFlyer process this data under their own privacy policies and may use it to measure and improve ad delivery.
You can limit this at any time. On Android, open Settings → Privacy → Ads (or Settings → Google → Ads) and delete or reset your advertising ID. On iPhone, choose "Ask App Not to Track" when prompted, or turn off Settings → Privacy & Security → Tracking.
4. How we use information
- Compute your real-time cortisol score and surface biometric trends (on-device only)
- Deliver the features you've signed up for (insights, Zen mode, friend connections)
- Provide customer support when you contact us
- Improve the App through aggregate, anonymized analytics (only with your opt-in consent)
- Measure which of our ads lead to installs and subscriptions (see section 3.6)
- Communicate important service changes, security notices, or required legal updates
- Detect and prevent fraud, abuse, and security incidents
We do not use your information to make automated decisions that have legal or similarly significant effects on you.
5. Legal bases (GDPR / UK GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, we rely on the following lawful bases:
- Consent — for HealthKit access, diagnostic opt-in, and any optional features
- Contract — to provide the Service you sign up for
- Legitimate interest — for security, fraud prevention, basic service improvement, and measuring our advertising (where the law requires consent for ad measurement, we rely on consent instead)
- Legal obligation — to comply with tax, accounting, and regulatory requirements
6. How we share information
We share information only in these limited cases:
- Apple Inc. — for App Store distribution, subscription billing, and HealthKit infrastructure (governed by Apple's privacy policy)
- Google — for Google Play distribution and subscription billing on Android
- Meta Platforms and AppsFlyer — the limited advertising-measurement data described in section 3.6
- Cloud hosting providers — for storing account data only (Cortisol+ accounts are hosted with industry-standard providers; biometric data is never sent to them)
- Friends you connect with in-app — display name and selected wellness milestones you opt to share
- Legal compliance — when required by law, subpoena, or to protect rights/safety
- Business transfer — in the event of a merger or acquisition, with notice and same protections continuing
We never sell or rent your personal data, and we never share health or biometric data for advertising. The only data shared for advertising purposes is the ad-measurement data described in section 3.6.
7. Where data lives and international transfers
Biometric data stays on your device. Account data (if you create an account) is stored on cloud infrastructure that may be located in the United States. If you are in the EEA, UK, or Switzerland and account data is transferred to the US, the transfer is protected by Standard Contractual Clauses or equivalent safeguards.
8. Data retention
- On-device biometric data: kept until you delete the App or revoke HealthKit access
- Account data: kept while your account is active; deleted within 30 days of account deletion
- Support communications: kept up to 2 years for service-quality and audit purposes
- Anonymized analytics: aggregated and kept indefinitely; cannot be tied back to you
- Legal/tax records: kept for the period required by applicable law (typically 7 years)
9. Your rights
You can at any time:
- Revoke HealthKit access via iOS Settings → Privacy & Security → Health → Cortisol+
- Delete the App, which removes all on-device data
- Delete your account (if you created one) via in-app Settings → Account → Delete
- Request a copy of your account data by emailing admin@elevatedsystems.info
- Opt out of diagnostic data collection in App Settings
- Unsubscribe from any non-essential email by clicking the unsubscribe link
9.1 EEA, UK, Swiss residents (GDPR)
You also have the right to: access, rectify, erase, restrict processing, port, and object to processing. You can lodge a complaint with your local supervisory authority.
9.2 California residents (CCPA / CPRA)
You have the right to know what categories of personal information we collect, to delete it, to correct it, to opt out of "sale" or "sharing", and to non-discrimination for exercising your rights. We do not sell personal information. Sending device identifiers and app events to Meta and AppsFlyer to measure our ads may count as "sharing" for cross-context behavioral advertising; you can opt out by deleting or resetting your advertising ID as described in section 3.6, or by emailing us. Verifiable requests: admin@elevatedsystems.info.
9.3 Other US states
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have similar rights. Contact us using the email above to exercise them.
10. Apple HealthKit specific terms
The App's use of HealthKit data complies with Apple's HealthKit Terms and Conditions and the Apple Developer Program License Agreement. Specifically:
- HealthKit data is never used for advertising or similar services
- HealthKit data is never shared with third parties for marketing
- HealthKit data is never sold
- HealthKit data is processed on-device unless you opt into a feature that explicitly requires sync
10a. Google API Services / Fitbit data (Limited Use disclosure)
Cortisol+'s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data (your Fitbit heart, sleep, and activity data) to provide the App's user-facing stress and recovery features you can see in the App
- We do not transfer Google user data to third parties, and we do not sell it
- We do not use Google user data for advertising, credit-worthiness, or lending purposes
- No humans read this data, except with your explicit consent for support, for security purposes, to comply with law, or as part of aggregated and anonymized internal operations
- Access tokens are stored securely in the iOS Keychain on your device; biometric values are processed on-device
11. Children's privacy
Cortisol+ is not directed to and is not intended for users under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact admin@elevatedsystems.info and we will delete it.
12. Security
We use reasonable administrative, technical, and physical safeguards designed to protect your information, including HTTPS/TLS in transit, encryption at rest for account data, and Apple's secure enclave protections for HealthKit data on-device. No system can be 100% secure; we cannot guarantee absolute security but we work continuously to maintain industry-standard protections.
13. Third-party services
The Service relies on a small set of third-party providers:
- Apple Inc. — App Store, HealthKit, Sign in with Apple, iCloud (if you opt into iCloud sync)
- Crash reporting (opt-in) — anonymized crash data only
- Cloud hosting — for account data storage (Cortisol+ accounts only; never biometrics)
- Google — Google Play and Health Connect on Android; Firebase for accounts, notifications and app configuration
- RevenueCat and Superwall — subscription status and paywall screens
- Meta Platforms — the Meta SDK, for advertising measurement (section 3.6)
- AppsFlyer — advertising measurement on iPhone (section 3.6)
Each operates under its own privacy policy. We do not embed advertising, tracking, or analytics SDKs in the App beyond those listed.
14. Do Not Track
Our Website does not respond to "Do Not Track" browser signals because we do not perform cross-site tracking.
15. Changes to this policy
We will update this policy as the Service evolves. The "Effective date" at the top will reflect the latest version. Material changes will be announced in-app and on cortisolplus.com at least 30 days before they take effect when feasible. Continued use after the effective date constitutes acceptance.
16. Contact
For privacy questions, data requests, or to exercise any of your rights:
Email: admin@elevatedsystems.info
Operator: Elevated Systems LLC
Website analytics and cookie choices
With your permission, Google Analytics measures website page views and clicks to the App Store. We send the page path and a broad referral category, such as Google, Bing or ChatGPT; we strip query strings and conversation URLs. We do not send quiz answers, results, HealthKit records, email addresses or account identifiers from these website tools. Automatic form tracking is disabled.
If you allow analytics, download links also include Apple's public developer token and a broad campaign label, such as “website-chatgpt” or “website-google”. Apple uses these labels for aggregate App Store campaign reports. We do not include your health information, the article you read, search terms, conversation links or a personal identifier in the campaign link. If you decline analytics, download links remain untagged.
Advertising cookies are a separate choice. When allowed, Meta Pixel measures visits and App Store clicks on product pages, not our medical articles or quizzes. You can change your choice using “Privacy choices” in the footer. Optional analytics and advertising tags remain off until you opt in; declining does not affect the tools or app download.
Google and Meta process permitted events under their own privacy policies. Browser protections and consent choices can limit reporting. An App Store click is not proof of an installation or purchase.
Delete your account
See our account deletion instructions to request removal of your Cortisol+ account and associated data.