Privacy Policy
Last updated: August 10, 2026
1. Scope
This policy describes what MyoRevive ("we", "us") collects, why, and what happens to it. MyoRevive is a wellness app operated by a sole proprietor in Ontario, Canada, and we handle personal information in line with Canada's PIPEDA principles. MyoRevive is not a clinical service: we do not create medical records, we are not a healthcare provider, and the service is not covered by health-records legislation such as HIPAA. Please still treat what you share in sessions thoughtfully — it can describe your body and how it feels.
2. What we collect
- Account data — name and email address, held by our authentication provider Clerk.
- Onboarding answers — the survey you complete before your assessment report (goals, problem areas, activity patterns).
- Session content — your messages, the AI's responses, range-of-motion observations, muscle-activation findings, prescribed exercises, and homework completion, stored in our Convex database.
- Billing data — subscription status and plan, processed by Stripe. We never see or store your full card number.
- Analytics and errors — product events, and error reports, collected by PostHog and Sentry only after you accept the cookie banner (see section 4).
We do not sell personal information, we do not run third-party advertising, and we do not import or connect to medical records.
3. AI processing
To generate session guidance, your session messages and relevant progress context are sent to Anthropic's Claude API. Under Anthropic's commercial API terms, API inputs and outputs are not used to train Anthropic's models. No human reviews your sessions in real time. Every session carries the notice "AI assistant — not medical advice".
4. Cookies, consent, and analytics
Essential cookies (your sign-in session) are always on — the app cannot work without them. Everything else is off by default: our cookie banner starts in the rejected state, and PostHog analytics and Sentry error reporting stay silent until you click Accept. If you accept, we ask again after 13 months. If you reject, we don't re-prompt you and the app keeps working normally. If session replay is captured (only after consent), the text you type in chat is masked in the replay.
5. How long we keep things
- While your account exists — session history, findings, and homework are kept so your progress tracking works.
- When you delete your account (Settings → Delete account) — your application data (sessions, messages, findings, homework, reports, feedback) is deleted from our database via an automated cascade.
- Clerk retains account records for up to 90 days after deletion, then purges them.
- PostHog analytics events are retained for up to 1 year.
- Stripe billing records are retained for 7 years, as required by tax law.
- Database backups are kept on a rolling window and age out automatically.
6. Who processes data for us
We use a small set of infrastructure providers, each only for the purpose listed:
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | AI model that generates session guidance | USA |
| Clerk | Authentication and account management | USA |
| Convex | Application database (sessions, findings, homework) | USA |
| Stripe | Subscription payments and billing | USA |
| Vercel | Application hosting and delivery | USA |
| Sentry | Error monitoring (consent-gated) | USA |
| PostHog | Product analytics and session replay (consent-gated) | USA |
| Upstash | Rate limiting infrastructure | USA |
| Resend | Transactional email (e.g. your assessment report) | USA |
These providers are located in the United States, so your information is transferred and stored there under their standard data-processing terms.
7. Your rights
You can access most of your data directly in the app (dashboard, session history, homework). You can delete your account and its data yourself in Settings. For access, correction, or deletion requests beyond that — or any privacy question — email support@trymyorevive.com. If you are in a jurisdiction with statutory privacy rights (e.g. PIPEDA in Canada, GDPR in the EU/UK, CCPA in California), we will honour those rights on request.
8. Security
All traffic is encrypted in transit (TLS). Access to production systems is restricted to the operator with least-privilege, scoped credentials. Payment details never touch our servers. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you as required by law.
9. Children
MyoRevive is for adults 18 and over. We do not knowingly collect information from children.
10. Changes and contact
If we materially change this policy we will give notice in the app or by email before the change takes effect. Questions: support@trymyorevive.com.