Privacy Policy
Last updated: 17 July 2026
1. Data controller
The data controller for Myo (myo.coach) is VR Express OOD, a company registered in Sofia, Bulgaria. For any privacy question, data-subject request, or GDPR matter contact us at privacy@myo.coach (dedicated privacy contact).
2. What Myo does
Myo is a personal wellness and self-tracking tool that helps you model your dopaminergic state from behavior and biometrics. It is not a medical device and not a substitute for professional care.
3. Data we collect
- Account data: email address and hashed password if you sign up with email/password; or name, email, and Google profile identifier if you sign in with Google (Google OAuth).
- Wellness data you log: activities, natural-language log entries, daily check-ins, computed scores (baseline, phasic, tonic, restore/drain loads).
- Wearable data (optional): if you connect WHOOP via OAuth, we sync sleep, resting heart rate, and heart-rate variability into your account.
- Recovery-module data (optional, consent-gated): if you enable the Recovery module, we store solo sessions, substance-taper entries, bloodwork you enter, supplements, therapy sessions, and weekly reviews. This is special-category health data under GDPR Article 9 and is only collected after you give explicit consent (stored as
gdpr_consent_special_category). - Billing data: handled by Stripe if you subscribe. We store your subscription status and customer ID; we do not store card numbers.
- Technical: auth session in browser local storage. No advertising or third-party analytics trackers.
4. Legal bases (GDPR Art. 6 & 9)
- Performance of the contract — providing the app you signed up for.
- Legitimate interest — securing accounts, preventing abuse, product improvement.
- Consent — for wearable connection, the Recovery module, marketing emails.
- Explicit consent (Art. 9(2)(a)) — for all special-category health data in the Recovery module. You can withdraw at any time from Settings.
5. Processors and subprocessors
We use these providers to run the service:
- Supabase / Lovable Cloud — hosting, database, authentication (EU region).
- Google — Google Sign-In (OAuth).
- WHOOP — wearable OAuth and sleep/HRV/RHR sync (only if you connect it).
- Google Gemini — parsing your natural-language activity logs into structured entries.
- Anthropic Claude — powering the in-app coach chat.
- Resend — sending transactional and daily-nudge emails.
- Stripe — subscription billing.
6. Storage and security
Data is stored in the EU with row-level security so each user can only read and write their own rows. Sensitive recovery data is additionally gated by an explicit consent check at the database level.
7. Your rights
Under GDPR you have the right to:
- Access, rectify, or export your data.
- Erase your account and associated data.
- Withdraw consent (including for the Recovery module and wearables).
- Object to processing and lodge a complaint with your supervisory authority (in Bulgaria: CPDP).
To exercise any of these rights, email privacy@myo.coach. We respond within 30 days.
8. Retention
We keep your data while your account is active. On deletion request we remove your data from live systems and from backups within 30 days.
9. Cookies
We only use strictly necessary storage to keep you signed in (auth session in local storage). No ad tracking, no cross-site tracking pixels.
10. Changes
We'll update this page and the "last updated" date when practices change. Material changes will be announced in-app or by email.