Sinoa Legal

Privacy Policy

Clear, public-facing policy information for how Sinoa operates, how your data is handled, and how to use the product responsibly.

Safety pagePrivacy Policy
Last updated: 2026-08-27
For questions: security@rhythmiqi.com

1. Scope and Controller

This Policy explains how RhythmIQ Insights LLC handles personal information through SINOA. Consumer health data is also governed by the separate Consumer Health Data Privacy Policy.

The Data Retention Policy version 2026-08-27-candidate.1 (SHA-256 51413ab89629b9aa983ae514d5b54b3d127f23a38247525af2aa66e72fd01c6b) and Account Deletion disclosure version 2026-08-27-candidate.1 (SHA-256 77ed8d32398710b0f283adeab77d0517a44854fe42cbff08714b4508f67719ae) are incorporated into this Policy. They are supporting disclosures and do not replace the separate consumer-health consent required before health-data collection.

2. Information We Collect

We do not intentionally send ECGs, Pattern Summary content, names, emails, tokens, passwords, filenames, medical conclusions, medical details, or job/report identifiers to PostHog.

  • Account, preference, age-acknowledgment, authentication, verification, multifactor, session, and security information.
  • ECG recordings and files, device and file metadata, notes, and processing information you submit.
  • Pattern Summaries, model observations, segment evidence, history, trends, comparisons, and share-link content derived from recordings.
  • Provider, offering, interval, product, paid-period, subscription, cancellation, refund, and limited hashed reconciliation references. SINOA does not store full payment credentials.
  • Verification, password-reset, support, deletion, legal opt-out, and optional marketing records.
  • Device, browser, IP-derived security, request, rate-limit, diagnostic, error, and operational logs.
  • Limited website product-analytics events and a pseudonymous subject identifier only after affirmative analytics consent.

3. Sources

We receive information from you; the files, devices, and services you choose; Apple or Google authentication; Stripe, Apple App Store, or Google Play; your browser or app; and service providers operating for us.

4. How We Use Information

  • Create, authenticate, secure, and support accounts.
  • Process recordings and provide Pattern Summaries, history, trends, comparisons, exports, and user-requested sharing.
  • Administer trials, usage limits, subscriptions, cancellations, refunds, restores, and billing disputes.
  • Send verification, security, password-reset, service, legal, support, and consented marketing communications.
  • Detect abuse, investigate incidents, maintain reliability, enforce terms, troubleshoot diagnostics, and comply with law.
  • Measure public website, onboarding, account, and billing flows after analytics consent.

5. When We Disclose Information

We do not sell personal information or consumer health data. We do not use consumer health data for targeted advertising or share personal information for cross-context behavioral advertising.

  • Infrastructure, database, storage, backup, security, monitoring, email, and support providers operating the Service.
  • Stripe, Apple, and Google for purchases, authentication, subscription state, cancellation, restore, fraud, refund, and billing support.
  • PostHog for limited consented analytics.
  • Recipients or anyone possessing a share link when you deliberately create or send it.
  • Authorized personnel for user-approved support, security, or legally permitted access; professional advisers under safeguards; and authorities when lawfully required.

6. Retention

Encrypted source-data backups rotate through up to 12 hourly snapshots and 14 daily backups. Encrypted durable customer-data backups rotate through up to 12 hourly snapshots, 7 daily snapshots, and 14 daily backups. Active deletion may occur before encrypted backup copies expire. Deletion controls must be reapplied after a disaster-recovery restore.

  • Source ECG uploads: up to 6 hours after accepted upload.
  • Trial Pattern Summaries and detailed result artifacts: up to 7 days and at most 7 retained artifacts.
  • Paid SINOA Pattern Summaries and detailed result artifacts: up to 365 days and at most 1,000 retained artifacts.
  • A historical limited entitlement may retain Pattern Summaries and detailed result artifacts for up to 30 days and at most 100 retained artifacts while that entitlement remains valid.
  • Derived Pattern History used for Trends: while the account exists unless separately deleted; a subscription change may restrict visibility without deleting history.
  • Synced mobile diagnostics: up to 30 days unless deleted sooner.
  • Pseudonymized legal acceptance and minimal billing/deletion evidence: two years after account deletion.

7. Account Deletion and Choices

Supported settings let you export retained data, delete categories or ranges, revoke shares, withdraw optional consent, and delete the account. Account deletion removes supported live ECGs, Pattern Summaries, Pattern History, shares, notes, diagnostics, sessions, identities, and support-access records.

Only narrowly scoped pseudonymized legal, opt-out, deletion, and minimal billing evidence remains for two years. It excludes ECGs, Pattern Summaries, health-derived content, name, email, address, payment credentials, and the raw account identifier.

Deleting SINOA does not cancel Apple or Google store billing. SINOA requests Stripe cancellation at period end before successful paid-account deletion. Email security@rhythmiqi.com from the account email if you cannot use the app.

8. State Privacy Rights

Depending on applicable law, you may request access, correction, deletion, portability, confirmation of processing, consent withdrawal, or appeal. We may verify identity. To appeal a denied request, reply with Privacy Appeal; we will provide regulator information where required.

9. Security

We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including encryption in transit and at rest, access controls, secrets management, logging, backups, vulnerability management, incident response, and recovery testing. RhythmIQ maintains incident response procedures designed to evaluate whether an event constitutes a reportable breach under applicable federal or state law, including the FTC Health Breach Notification Rule, and to satisfy any resulting notification obligations. No system is perfectly secure.

10. Children

SINOA is for adults age 18 and older and is not directed to children. Contact us if you believe a child provided information.

11. United States Processing

SINOA is currently release-gated for United States availability. Information is processed in the United States and by providers serving the United States. Other-country availability requires separate approval.

12. Changes

Material changes are published as a new immutable version and presented for renewed acceptance when required. Separate health-data consent is renewed when its version changes.

13. Contact

  • RhythmIQ Insights LLC
  • 1014 Douglas St., Forest Grove, OR 97116, United States
  • security@rhythmiqi.com
  • +1 503-862-9233
Public policy information for Sinoa. For safety-specific guidance, see the Safety page.
© 2026 RhythmIQ Insights LLC. All rights reserved.