Privacy policy


Mȳth Health LLC ("Mȳth," "we," "us," "our") respects your privacy. This policy explains what personal data we collect when you use bymyth.com, the Mȳth app, or the Mȳth Recovery Sensor, how we use it, and your rights over it.

We do not sell your personal data. We do not share your health or biometric data with advertisers. We do not use your HRV or recovery data to profile you for third-party commercial purposes.

Data We Collect

Account data — name, email address, password (hashed) — collected to create and manage your account.

Health and biometric data — RMSSD, SDNN, pNN50 readings; session cost scores; heart rate zones; rep and set counts — collected to deliver the app's core measurement and recovery functions.

HealthKit / Apple Health data — sleep data, if you grant permission — collected to contextualize recovery predictions. Access requires your explicit opt-in.

Device and sensor data — sensor firmware version, Bluetooth connection status, adhesive session logs — collected to diagnose hardware issues and improve accuracy.

Transaction data — order ID, billing address, last four digits of card (stored by payment processor) — collected to process purchases and subscriptions.

Usage data — feature usage frequency, session duration, crash reports — collected to improve the app and diagnose bugs.

We do not collect biometric data passively. The Mȳth sensor only transmits data when you intentionally tap your phone to begin or end a session. No background collection occurs.

How We Use Your Data

We use your data to deliver the session cost score and recovery guidance you requested; to build your personal 30-day recovery model within the app; to process and fulfill your orders and subscription deliveries; to provide customer support; to improve the accuracy and reliability of our sensors and algorithms; and to send transactional emails including order confirmation, shipping updates, and subscription renewals. Marketing emails require a separate opt-in.

Health Data — Specific Commitments

We do not sell your health data. We do not share your biometric or HRV data with insurance companies, employers, advertisers, or data brokers — ever. Your recovery data belongs to you.

Health and biometric data is processed on the legal basis of your explicit consent, provided when you create an account and begin using the sensor. You may withdraw consent and request deletion at any time (see Your Rights below).

We may use de-identified, aggregated data — data that cannot be linked back to you — for internal research to improve our measurement algorithms. Aggregated data is never sold.

Third-Party Service Providers

We work with a limited set of vetted service providers who process data on our behalf under contractual data protection obligations.

Payment processing is handled by Stripe, which is PCI-DSS Level 1 compliant. We never see or store your full card number.

Cloud infrastructure is provided by AWS. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.

Order fulfillment partners receive your name, shipping address, and order contents only — no health data.

Analytics and crash reporting tools such as Sentry receive no health data.

We do not use Facebook Pixel, Google Ads pixels, or any third-party advertising trackers that receive health or biometric data. Advertising pixels, if used on bymyth.com, are restricted to anonymized page-level events only and receive no account or health data.

Data Retention

We retain your account and health data for as long as your account is active. If you close your account, we delete your personal data within 90 days, except where legal or tax obligations require us to retain certain transaction records, typically up to seven years for financial records.

Your Rights

Depending on where you live, you have the right to access the personal data we hold about you; to correct inaccurate data; to delete your data; to export your data in a portable format; to withdraw consent for health data processing; and to opt out of marketing communications at any time via the unsubscribe link in any email or by contacting us directly.

To exercise any of these rights, email support@bymyth.com with "Privacy Request" in the subject line. We respond within 30 days.

California Residents (CCPA / CPRA)

California residents have the right to know what personal information is collected and how it is used; the right to delete personal information; the right to opt out of sale or sharing (we do not sell or share personal information for cross-context behavioral advertising); and the right to non-discrimination for exercising privacy rights. To submit a California privacy request, email support@bymyth.com.

Children's Privacy

Mȳth is intended for users 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us immediately and we will delete the data.

Changes to This Policy

We will notify you of material changes by email and by posting a notice on bymyth.com before the change takes effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.


© 2026 Mȳth Health LLC · bymyth.com · support@bymyth.com · All rights reserved.