Effective Date: July 25, 2026
How Health Data is processed
Your Privacy is Even Realities priority, particularly when it comes to your health data. To give you meaningful control over how your information is handled, we offer you flexible options tailored to your preferences. Before you start using the health monitoring features of Even R1, we will seek your clear consent and authorization for the processing of your health data. Even Realities provides two processing options for your consideration: local processing via the Even App, and cloud-based processing. Here is how each option works:
When Health tracking is enabled, Even R1 collects your health data and metrics. These data are initially processed locally on the Even App to generate basic health analytics — including activity status, caloric expenditure, heart rate, HRV, and SpO₂.
Should you further authorize Health data cloud computing, your health data will be securely transmitted to cloud servers for advanced analysis. This enables us to deliver more valuable health insights, such as your productivity score, sleep score, and temperature-based analytical reports. Additionally, once stored in the cloud, your health data becomes accessible across all devices logged in under the same user account, ensuring a seamless and unified experience.
How your data is used
- Generating basic health analytics via local processing on the Even App
- Delivering advanced health insights (Productivity Score, Sleep Score, and temperature-related analysis) through cloud computing, if authorized
- Synchronizing health data across multiple devices under the same user account for a consistent experience, if cloud computing is enabled
- Not used for AI model training
- Not shared with third parties for advertising or marketing purposes
- Not used for any form of insurance underwriting or employment decision-making
What is the legal basis for processing
We process your health data solely on the basis of your explicit consent. Health Tracking is only activated if you have opted in. Health data cloud computing is a separate authorization and is only enabled if you have explicitly granted permission, either by agreeing during first-time setup, or by turning on the "Health Data Cloud Computing" toggle via Settings > Privacy > Health Data at any time.
You may withdraw your consent at any time by disabling Health Tracking or Health Data Cloud Computing respectively. Please note that withdrawal of consent does not affect the lawfulness of data processing activities that have already taken place prior to the withdrawal.
How to manage your health data
You are always in full control. You can enable or disable Health Tracking and Health Data Cloud Computing at any time via Settings > Privacy > Health Data.
- If Health Tracking is disabled, Even R1 will cease collecting new health data. Previously collected data, if any, will remain stored locally on your device unless manually deleted.
- If Health Tracking is enabled but Health Data Cloud Computing is disabled, your health data will be processed locally on the Even App only, and will not be transmitted to the cloud. Under this mode, data will not be synchronized across devices.
- If both Health Tracking and Health Data Cloud Computing are enabled, your health data will be processed locally and transmitted to the cloud for advanced analytics, and will be accessible across all devices associated with your account.
How we help protect your sensitive health information
Even R1 is designed with privacy and security as foundational priorities. We implement comprehensive technical, organizational, and contractual safeguards to protect your health data against unauthorized access, loss, or disclosure:
- Encryption: All health data is encrypted in transit and at rest using industry-standard protocols — including Bluetooth encryption from device to app, TLS 1.2 (or higher) for app-to-cloud transmission, and AES-256 encryption for data stored in the cloud.
- Access Controls: We enforce role-based access control (RBAC), adhere to the principle of least privilege, and require multi-factor authentication (MFA) for all internal systems containing personal data. Access is strictly limited to authorized personnel on a need-to-know basis.
- De-identification and Anonymization: Wherever feasible, we apply de-identification, anonymization, or aggregation techniques to your data prior to analysis, ensuring that insights cannot be traced back to you as an individual.
- Data Retention Limitation: We retain your health data only as long as necessary to fulfill the purposes described in this notice or as required by law. Upon expiry of the retention period, data is securely deleted or permanently anonymized.