JESS MOVEPrivacy Policy

Version 1.0 · effective 27 July 2026

Privacy Policy

Health and wearable information is special-category data. Privacy could not be added to this product after it was built, so it was designed in from the first commit — and the parts that matter are enforced in code rather than promised in a policy.

Never leaves your device

  • Calendar event titles
  • Calendar attendees
  • Meeting descriptions and links
  • Free-text health notes
  • Precise location coordinates
  • Photographs, once a meal estimate is produced

Sent to the engine

  • Busy, free, focus or travel structure — times only, no content
  • A movement capability profile you entered yourself
  • Completion and outcome events
  • Coarse context category (office, home, transit, outdoors)

1. Who is responsible

The operator of JESS MOVE is the data controller for your personal data, and is registered with the Information Commissioner’s Office. Where an employer, school, care provider or council enrols you, that organisation is a controller for the enrolment relationship and we are a controller for your movement and health data. Neither can see the other’s side of that line at individual level.

Data protection enquiries: privacy@jessmove.com.

2. What we collect, and why

Account data

Name, email, verified age band, account type, and — for a minor — the linked guardian. We need this to run your account and to place you in the correct mode, which governs safeguarding rules rather than preferences. Lawful basis: contract.

Movement readiness and capability

Confidence, balance, accessibility requirements, restrictions, injuries and intensity preference. This is health data and we ask for your explicit consent before collecting it. Without it, we can only offer the most conservative variants, so the product works but works less well. Lawful basis: explicit consent (UK GDPR Art. 9(2)(a)).

Schedule structure

If you connect a calendar, events are classified on your device into busy, free, focus and travel. Only that structure — times and a category — is transmitted. Titles, attendees, descriptions and links are never sent to us and never sent to any AI model. You can hide individual calendars. Lawful basis: consent.

Wearable and health-platform data

Steps, heart-rate trend, sleep and recovery indicators, where you connect them. Each provider is a separate switch and each can be revoked without affecting the others. Lawful basis: explicit consent.

Usage and outcomes

Which prompts you accepted, delayed, replaced or declined, and what you completed. This is what makes the next suggestion better; it is also what tells us when to stop suggesting. Lawful basis: legitimate interests, balanced against your rights and subject to your objection.

Food photographs

An image is processed to produce an estimate and is then discarded unless you choose to keep it in your own history. We do not use your photographs to train general models. Lawful basis: explicit consent.

3. Children

For users aged 10–12 a linked guardian account is mandatory and consent is obtained from the guardian. We apply high privacy defaults, age assurance, no targeted advertising, no public profiles, no location sharing and no unrestricted contact from adults.

We do not use children’s data in any way that could be detrimental to their physical or mental health and wellbeing. Concretely: no weight, BMI, calorie or appearance framing is shown to a person under 18 in any mode, and the consent switch is not consulted below 18 — there is no setting that turns it on.

A guardian sees participation, safety flags and consent settings. A guardian does not see private check-ins, mood entries or free-text conversation with the coach.

4. Employers, schools and other organisations

An organisation that pays for your seat sees aggregate figures only, and only where at least 8 people contribute to the figure. The threshold is enforced in the query planner and again as a database constraint, with intersection-attack checks across filter combinations.

There is no individual view. It is not permission-gated, it is absent from the type system — no role, no escalation and no support request can produce it. You can see exactly what your organisation can see, on a permanent transparency screen in your account.

An organisation never receives: health conditions, movement history, heart rate, sleep, disability status, declined activities, calendar content, medical information or an individual risk score.

5. AI processing

Recommendations combine deterministic safety rules, statistical models and, for some explanations, a large language model. Before any prompt reaches a model provider it passes through a redaction layer that removes direct identifiers, calendar content, free-text health notes and precise location.

Safety decisions are never delegated to a generative model. A model may explain a movement; it may not invent one, and it may not widen what the safety layer allowed.

We do not make decisions with a legal or similarly significant effect on you by automated means alone.

6. Your consent centre

11 switches, each independent, each reversible, none of them required to keep using the product:

  • calendar access
  • wearable access
  • location context
  • heart-rate use
  • sleep-data use
  • team participation
  • employer analytics
  • family visibility
  • research participation
  • marketing
  • AI personalisation

Withdrawing consent stops future processing. It does not make the past unlawful, and it does not delete your history unless you ask us to.

7. Sharing

We use processors for hosting, messaging, payments, error monitoring and AI inference. Each is bound by a written contract, processes only on our instructions, and is listed in the sub-processor register available on request.

We never sell identifiable health data. We do not share your health data with advertisers or data brokers. Research partnerships operate only on aggregated, k-anonymised data and require a separate, specific consent.

Measurement on our public pages. If you agree, we use Meta and Google measurement tags on our marketing pages so we can see which routes bring people here. What they are told is that a page was viewed, that somebody began or completed a sign-up, and what a subscription was worth. What they are never told, and what we have no code to send them: your name, your email, your account identifier, or anything at all about your health — no conditions, no medication, no weight, no food, no movement, no falls or balance result.

These tags never load on your account or on any screen showing health information, and they never load for anyone under 18. If you decline, nothing is loaded and neither company is contacted. If your browser sends Do Not Track or Global Privacy Control we treat that as a refusal regardless of what any banner says. Sign-up and payment are counted by our own servers, so that no advertising script is ever present on a page where your data is.

8. Where your data lives

Primary processing is in the UK and the European Economic Area. Where a processor operates outside that, transfers rely on UK adequacy regulations or the International Data Transfer Addendum, with a transfer risk assessment on file.

9. How long we keep it

  • Account data: for as long as your account exists, then 30 days.
  • Movement and completion history: 24 months rolling, unless you export it.
  • Wearable readings: 13 months rolling.
  • Food photographs: discarded after estimation unless you save them.
  • Safety and safeguarding records: 6 years, as a legal obligation.
  • Aggregate, non-identifying statistics: indefinitely.

10. Your rights

Under UK GDPR you have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. Export and deletion are self-service in your account settings; anything else, write to privacy@jessmove.com and we will respond within one month.

If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to fix it first.

11. Security

Encryption in transit and at rest, identity data separated from health and activity data, row-level security in the database, least-privilege access, immutable audit records, and a documented breach procedure with notification to the ICO within 72 hours where required.

12. Changes

We will give at least 30 days’ notice of a material change, in the app and by email, and we will not apply a new purpose to data already collected without asking you first.

Related: Terms of Service · All policies · Platform status