Privacy Policy
Privacy at a Glance
We know privacy matters, especially when it comes to ADHD, wellness, personal reflection, coaching, and community participation. Here’s a plain-English overview of how privacy works across Shimmer’s Services, including Shimmer ADHD coaching, community features and events, body doubling and coworking, and Indy by Shimmer.
The essentials:
- We do not sell your data or allow third parties to use your data to train their own AI models
- Coaching and Indy are supportive tools, not therapy, medical care, or emergency services. In a crisis, call 911 or 988.
- Your coaching sessions, Indy entries, and notes are private to you. If you reach Shimmer through an employer or sponsor, they never see what you discuss.
- We keep your information only as long as we need it, sensitive session recordings and transcripts are deleted soon after, and you can ask us to delete your data at any time.
- In community and body-doubling sessions, you choose what to share and are never required to share anything personal.
- You control your data: access, correct, download, or delete it at privacy@shimmer.care.
What we collect
- Information you choose to share, such as account details, reflections, goals, messages, community posts or interactions, event registrations, and other content you submit through the Services
- Coaching-related information if you participate in 1:1 ADHD coaching
- Participation and usage information related to community features, body doubling and coworking, live or virtual events, learning experiences, and other Shimmer web or mobile app features
- App and website usage data to help us understand what’s working and what’s not
- Payment information, processed securely by third-party payment providers
How we use your information
- To provide, operate, personalize, secure, and improve the Shimmer Services, including ADHD coaching, community features, body doubling and coworking, events, learning and productivity tools, and Indy
- To facilitate your participation in community programming and events and, where relevant, interactions with coaches, facilitators, speakers, or other members
- To communicate with you about the Services, updates, events, support, and administrative matters
- To improve our tools and services through research, analysis, evaluation, and product development
What Shimmer is not
- Shimmer is not a healthcare provider. Coaching is not therapy, medical treatment, or crisis support
- Coaches do not diagnose conditions or provide clinical care, even where a coach holds a healthcare license
- We do not create or hold medical records, and we cannot produce them
AI and Indy
- Indy provides supportive insights and reflections and is not intended to provide medical advice, diagnosis, or treatment
- Indy uses artificial intelligence, including third-party providers such as OpenAI, to generate responses and insights
- Your identifiable information is not used to train external AI models without your explicit consent
- We do not sell or share your Indy conversations. Any use to improve Shimmer’s own tools relies on de-identified or aggregated data where feasible. You can delete your Indy history at any time
- Where feasible and consistent with providing the requested feature, we use de-identified, anonymized, or aggregated information for AI-related analysis and development
Research and insights
- We may use anonymous, aggregated, or de-identified data derived from Shimmer coaching, community features, body doubling and coworking, events, other Shimmer app features, and Indy to better understand ADHD and improve our Services
- These insights may be shared in academic papers, blog posts, public reports, conferences, workshops, educational events, or industry events
- We do not include information in those materials that identifies you personally
What we don’t do
- We do not sell your personal data, and we do not share it for cross-context behavioral advertising
- We do not permit third-party AI providers to use your identifiable information to train their own AI models without your explicit consent
- We do not share individual coaching sessions or private Indy entries with employers, schools, or other organizations except as described in this Privacy Policy or with your consent
Your choices
- Coaching sessions are recorded only if both you and your coach agree, and either of you can stop a recording at any time
- You can unsubscribe from marketing emails
- You can request access to, correction of, or deletion of your information, subject to applicable law
- You can contact us at privacy@shimmer.care with questions or concerns
Our intent
Our goal is simple: to build better tools and support for people with ADHD. We use privacy-protective practices so we can learn what works, without compromising your trust.
Effective as of May 1, 2022
Last updated on August 21, 2026
This “Privacy Policy” describes the privacy practices of Shimmer, Inc. and our subsidiaries and affiliates (collectively, “Shimmer,” “we,” “us,” or “our”) in connection with our websites, mobile and web applications, products, features, programs, content, communications, and services (collectively, the “Service” or “Services”), and our direct marketing communications. The Services include, without limitation, Shimmer ADHD coaching; community and peer-support features; body doubling and coworking sessions; live and virtual events such as summits, workshops, webinars, classes, and other educational or community programming; learning, reflection, planning, productivity, and other features available through Shimmer’s web or mobile applications; and Indy by Shimmer, our AI-powered application that provides ADHD-aligned support, reflection, organization, and scaffolding. We may use third-party service providers, including artificial intelligence providers, to support certain features, subject to the protections and limitations described in this Privacy Policy. By registering as a member or by visiting, browsing, or using the Service in any way, you (as a “user”) acknowledge and agree to the practices described in this Privacy Policy, which forms a binding agreement between you and Shimmer.
Shimmer is committed to protecting the privacy of your Personal Information. Personal Information is information about you, including demographic information, that may identify you and that relates to your past, present or future physical or mental health or condition, or to related services or payment.
Table of Contents
- Personal Information We Collect
- Health Information
- Recordings, Community, Event, Audio and Video Data
- How We Use Your Personal Information
- Research and Insights Sharing
- How We Share Your Personal Information
- How Long We Keep Your Information
- Requesting Your Information
- Members Under 18
- Your Choices
- Other Sites, Mobile Applications and Services
- Security Practices
- International Data Transfers
- Changes to this Privacy Policy
- How to Contact Us
- European Economic Area (EEA) & United Kingdom Privacy Addendum
- California Privacy Rights Addendum
- Consumer Health Data Addendum
Personal Information We Collect
Information you provide to us. Personal information you provide to us through the Services or otherwise may include:
- Account Information, such as your name, email address, mailing address, account credentials, and other information you provide when creating an Account.
- Content you choose to upload, submit, or share through the Services, such as text, images, audio, video, messages, reflections, prompts, goals, free-form responses, community posts or comments, information shared during coaching, and information entered into Indy, together with associated metadata.
- Session Records, meaning the minimum information a coach needs to identify you and document the coaching Service you received, such as internal notes and dates of service.
- Community and event information, such as information you provide when joining community spaces, participating in body doubling or coworking sessions, registering for or attending summits, workshops, webinars, classes, or other events, interacting with facilitators or other members, or using related interactive features.
- Registration information related to coaching, community membership, body doubling and coworking, a summit, webinar, workshop, class, training opportunity, or other Shimmer program or event.
- Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us.
- Demographic information, such as your city, state, country of residence, and zip code.
- Usage information, such as information about how you use the Services and interact with us.
- Financial and billing information, such as the payment card details you use to pay for the Services, and your Service-related billing information and transaction history.
- Marketing information, such as your preferences for receiving communications about our activities, events, and publications, and details about how you engage with our communications.
- Other information that we may collect that is not specifically listed here but which we will use in accordance with this Privacy Policy or as otherwise disclosed at the time of collection.
Information we obtain from social media platforms. We may maintain pages for Shimmer on social media platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use, and processing of your personal information. You or the platforms may provide us with information through the platforms, and we will treat such information in accordance with this Privacy Policy.
Information we obtain from other third parties. We may receive personal information about you from third-party sources, such as business partners, publicly available sources, and data providers.
Cookies and other information collected by automated means. We and our service providers may automatically log information about you, your computer or mobile device, and activity occurring on or through the Services. This may include device and operating system type, browser type, device identifier, IP address, general location information such as city or state, the website you visited before ours, and information about your use of and actions on the Services, such as pages viewed, time spent, navigation paths, and access times. This information is collected using cookies, browser web storage, web beacons, and similar technologies. See Your Choices below for information about your options.
Health Information
Shimmer is not a Covered Entity under the Health Insurance Portability and Accountability Act (“HIPAA”), does not provide healthcare services, and does not create or maintain Protected Health Information as HIPAA defines it. Use of the Services does not require HIPAA compliance.
We recognize that health information is defined more broadly under the GDPR and under several U.S. state consumer health data laws, to include general wellbeing and any information relating to a person’s physical or mental health. We treat all health-related information as sensitive and apply additional security and privacy protections to it.
Shimmer does not maintain medical records, clinical records, treatment records, or diagnoses, and cannot produce them. Coaching produces service documentation, not clinical documentation. If you need documentation of a health condition for a medical, legal, employment, insurance, or benefits purpose, please contact a licensed healthcare provider.
Recordings, Community, Event, Audio and Video Data
Coaching session recordings. A coaching session is recorded only where both you and your coach have agreed to the recording. Either of you may decline before a session or stop a recording at any point during it, and the recording will end promptly. Declining does not affect your access to coaching.
If you consent to a recording, it may be used to evaluate the quality and effectiveness of coaching. That may include aggregate call statistics such as number of speaker turns, transcript and text analysis including key words, themes, and sentiment, audio analysis, and, where applicable, video analysis. We may use de-identified insights derived from recordings to improve the Services, including Indy’s AI-driven features, in accordance with this Privacy Policy.
Recordings and transcripts are never used to train general-purpose artificial intelligence models or third-party large language models. Where we work with third-party vendors to analyze this data, we provide it in de-identified form wherever possible, and we require those vendors by contract never to sell data, to maintain strict privacy and security controls, and not to use any data received from Shimmer to train their own models. Recordings are stored securely in the United States, and Shimmer personnel access them only where there is a need to do so.
Community and event recordings. Some community, body doubling, coworking, or live or virtual event experiences may use audio or video functionality. If Shimmer records a community session, event, workshop, webinar, summit, or similar experience, we will provide notice and obtain consent where required by applicable law.
Content that you voluntarily make visible or audible to other participants may be seen or heard by those participants. We encourage you not to share information in group settings that you do not want other participants to know.
How We Use Your Personal Information
We use personal information to provide, operate, secure, personalize, maintain, and improve the Services; provide ADHD coaching; facilitate community features and interactions; administer body doubling and coworking sessions; organize and deliver summits, workshops, webinars, classes, and other live or virtual events; provide learning, reflection, planning, productivity, and other app features; operate Indy; communicate with you about Services and programs in which you participate; provide support; and respond to requests, questions, and feedback.
We may use personal information and usage data for research and development, data analysis, evaluating effectiveness, identifying usage trends, improving products and marketing, and developing, evaluating, and improving Shimmer’s machine learning and artificial intelligence systems.
Indy uses artificial intelligence to generate supportive insights, reflections, and guidance based on user input. Shimmer may use third-party AI service providers, including OpenAI, to provide certain AI functionality. We require service providers to process information only as directed or authorized by Shimmer and subject to contractual privacy and security protections. Shimmer does not permit third-party AI providers to use identifiable user information to train their own models without the user’s explicit consent. Where feasible and consistent with providing the requested feature, Shimmer uses de-identified, anonymized, or aggregated information for AI-related analysis and development.
To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
For compliance, fraud prevention, and safety. As we believe necessary or appropriate, we may use your personal information and disclose it to law enforcement, government authorities, and private parties to protect the rights, privacy, safety, or property of you, us, or others, including by making and defending legal claims; to enforce the terms that govern the Services; and to protect against, investigate, and deter fraudulent, harmful, unauthorized, unethical, or illegal activity.
To create anonymous, aggregated, or de-identified data. We may create anonymous, aggregated, or de-identified data from personal information by removing or not using information that makes the data personally identifiable. We may use and share this data for our lawful business purposes, including to analyze and improve the Services.
Research and Insights Sharing
As part of our mission to improve ADHD support, we may use anonymous, aggregated, or de-identified data derived from use of the Services, including coaching, community features, body doubling and coworking, events and educational programming, Shimmer web and mobile app features, and Indy, to conduct internal research, generate insights, evaluate effectiveness, and develop and improve our Services and AI-powered features.
Research findings and insights may be shared externally in academic papers, blog posts, public reports, or presentations at conferences, workshops, educational events, or industry events. These materials will not include information that identifies you personally, and we apply safeguards designed to reduce the risk of re-identification.
How We Share Your Personal Information
We do not share your personal information with third parties without your consent, except in the following circumstances or as described in this Privacy Policy:
- Affiliates. We may share your personal information with our corporate parent, subsidiaries, and affiliates, for purposes consistent with this Privacy Policy.
- Coaches. We share the information your coach needs to work with you. Coaches are subject to contractual confidentiality obligations.
- Service providers. We share personal information with providers of hosting, communications, video conferencing, payments, analytics, customer support, and artificial intelligence functionality, who may use it only as we direct and subject to contractual privacy and security obligations.
- Other users. Other users may be able to see information you choose to share in community spaces, body doubling and coworking sessions, live or virtual events, public profiles, chats, comments, or other interactive portions of the Services. We do not control how other participants use information you voluntarily disclose to them.
- Sponsors and third-party funded access. Some members access Shimmer through an employer, health plan, school, government or non-profit agency, or another organization that arranges or pays for the Services (“Sponsors”). Where that is the case, we may share limited information with the Sponsor, such as enrollment status, session dates and attendance, and program completion, so the Sponsor can administer and evaluate the program. We do not share the content of your coaching sessions, your coach’s notes, your Indy entries, or your survey or assessment responses with a Sponsor. Where a Sponsor arrangement requires additional reporting, record retention, or other handling of your information, we will tell you what that involves before you enroll, and those requirements may differ from the practices described elsewhere in this Privacy Policy.
- Payment processors. Payment card information you use to make a purchase is collected and processed directly by our payment processor, and we never receive or store your full payment card information.
- Professional advisors. We may share personal information with lawyers, auditors, insurers, and similar advisors where necessary in the course of the professional services they provide to us.
- Legal and safety. We may share personal information where we believe it is necessary to comply with applicable law, respond to lawful requests and legal process, protect the rights, safety, or property of you, us, or others, enforce our terms, or investigate fraud or misuse.
- Business transfers. We may share personal information in connection with a merger, acquisition, financing, reorganization, or sale of assets, and will make reasonable efforts to require the recipient to honor this Privacy Policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
How Long We Keep Your Information
We keep information only for as long as we need it. How long that is depends on why we collected it, how sensitive it is, whether it may be needed to resolve a dispute or respond to a complaint, and whether the law requires us to keep it.
You can ask us at privacy@shimmer.care how long we keep a particular type of information.
Legal holds. If we receive a subpoena, court order, demand letter, regulatory complaint, or written notice of a matter reasonably likely to give rise to a legal claim, we place a hold on the records relevant to that matter and keep them until it is resolved. A legal hold overrides the periods above.
Anonymous, aggregated, and de-identified information may be kept indefinitely, because it can no longer be linked to you.
Requesting Your Information
How to request. Email privacy@shimmer.care to request data or deletion of data.
Verifying your identity. We verify your identity before producing any information. We issue account credentials to you and not to anyone acting on your behalf, so a request made by an attorney, agent, or other representative must be made in writing and accompanied by proof of your authorization. We may decline a request we cannot reasonably verify as authentic.
Timing. We respond within 30 calendar days. We may extend once by a further 30 days, and will tell you in writing if we do.
What you can get. Your account information, your Service Record, coach working notes, transcripts while we still hold them, your Indy entries, your community and event participation record, and your billing history.
What is not included. You do not have a right to copies of information held in research datasets, or in datasets we use to study and improve the quality of our Services, to train our team, or to manage the legal and financial aspects of our business. We may provide a summary of this material at our discretion.
Cost. One request in any 12-month period is free. For additional requests we may charge a reasonable cost, and will give you an estimate before proceeding.
Corrections. You may ask us to correct information you believe is inaccurate. If we decline, you may submit a statement of disagreement, which we will keep with the record.
Deletion. You may ask us to delete your personal information. We will do so, except where we need to keep it to comply with a legal obligation, for billing and tax records, where a legal hold applies, or where we need it to establish, exercise, or defend a legal claim, which includes the Service Records and coach notes described above. Where an exception applies to part of your information, we delete the rest.
Requests connected to legal proceedings. If a request is made in connection with actual or contemplated litigation, or by or on behalf of your attorney, we route it to our legal counsel rather than handling it as a routine privacy request. We will still provide what we are obliged to provide.
No retaliation. We will not deny you service, charge you a different price, or provide a lower quality of service because you exercised a privacy right.
Members Under 18
Shimmer offers coaching designed for teens. Where a member is under 18, the following applies in addition to the rest of this Privacy Policy.
Age. Shimmer accounts are available to people aged 13 and over. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with information, contact us at privacy@shimmer.care and we will delete it.
Consent. A member under 18 may only participate in coaching with the consent of a parent or legal guardian, who must review and accept our Terms of Service and this Privacy Policy on the member’s behalf.
What a parent or guardian receives. Coaching only works when a teen can speak openly. So a parent or guardian receives confirmation of participation, session dates and attendance, general themes and progress at a high level, and billing information. A parent or guardian does not routinely receive the content of coaching sessions, session recordings or transcripts, or the coach’s notes.
We tell the teen member, in plain language and at the start, exactly what their parent or guardian will and will not see, so they know where they stand before they share anything.
Safety exceptions. A coach will share more with a parent or guardian, and where appropriate with emergency services or other authorities, if they believe there is a risk of serious harm to the member or to someone else, or where the law requires it. We explain this to both the member and the guardian before coaching begins.
Rights. A parent or guardian may exercise privacy rights on behalf of a member under 18. Where a member is old enough to exercise those rights themselves under applicable law, we take their views into account and may require their agreement before disclosing coaching content.
How long we keep it. Records relating to a member who was under 18 are kept until the member turns 25, and for no less than seven years.
Your Choices
In this section, we describe the rights and choices available to all users.
Access, update, or delete your information. See Requesting Your Information above, or contact us at privacy@shimmer.care.
Coaching session recordings. A session is recorded only if you and your coach both agree. You may decline before any session or end a recording during a session. You may also contact privacy@shimmer.care to turn recording off for your account. Some features that depend on recordings, such as automated session summaries, will not be available if you do.
Marketing communications. You may opt out of marketing emails by following the unsubscribe instructions at the bottom of the email, or by contacting privacy@shimmer.care. You may continue to receive service-related and other non-marketing emails.
Cookies and other technologies. Most browsers let you remove or reject cookies through your browser settings. Many browsers accept cookies by default until you change your settings. If you set your browser to disable cookies, the Services may not work properly.
Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. If that ever changes, we will update this Privacy Policy and provide an opt-out before the change takes effect.
Do Not Track. Some browsers can be configured to send “Do Not Track” signals. There is no common industry standard for responding to them, and we do not currently respond to “Do Not Track” or similar signals.
Other Sites, Mobile Applications and Services
The Services may contain links to other websites, mobile applications, and other online services operated by third parties. These links are not an endorsement of, or a representation that we are affiliated with, any third party. We do not control third-party websites, mobile applications, or online services, and we are not responsible for their actions. They follow different rules regarding the collection, use, and sharing of your personal information, and we encourage you to read their privacy policies.
Security Practices
The security of your personal information is important to us. We use administrative, technical, and physical safeguards designed to protect the personal information we collect, including encryption in transit and at rest where appropriate, access controls, and workforce training. Security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
International Data Transfers
Our headquarters is in the United States and we use service providers in other countries. Your personal information may be transferred to the United States or other locations outside your state, province, or country, where privacy laws may not be as protective as those where you live. Where required, we use appropriate safeguards for those transfers.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on the Services. We may, and if required by law will, also provide notification of changes in another way that we believe is reasonably likely to reach you, such as by email or another manner through the Services.
Any modifications will be effective upon our posting the new terms or upon implementation of the changes on the Services, or as otherwise indicated at the time of posting. In all cases, your continued use of the Services after the posting of a modified Privacy Policy indicates your acceptance of it.
How to Contact Us
Please direct any questions or comments about this Privacy Policy or privacy practices to privacy@shimmer.care. You may also write to us via postal mail at:
Shimmer, Inc.
Attn: Legal
1015 Fillmore St. #12411
San Francisco, CA 94115
European Economic Area (EEA) & United Kingdom Privacy Addendum
This section applies to individuals located in the European Economic Area (EEA) or the United Kingdom and supplements the Privacy Policy above. To the extent of any conflict, this Addendum applies for EEA and UK users.
Controller and Processor
Shimmer is the controller of personal data we handle in our direct relationship with members. Where a Sponsor arranges access to the Services on your behalf, Shimmer may act as a processor for certain personal data provided by that Sponsor.
Legal Bases for Processing
Where the General Data Protection Regulation (“GDPR”) or UK GDPR applies, Shimmer processes personal data on one or more of the following legal bases:
- Performance of a contract, where processing is necessary to provide and operate the Services, including Shimmer ADHD coaching, community features, body doubling and coworking, live and virtual events and educational programming, other Shimmer web and mobile app features, and Indy by Shimmer;
- Legitimate interests, including improving, securing, and maintaining the Services; developing and evaluating AI-powered features; conducting internal research and analytics; establishing, exercising, or defending legal claims; and preventing fraud or misuse, provided such interests are not overridden by the rights and freedoms of individuals;
- Consent, where required by applicable law or where Shimmer explicitly requests it, including for session recordings; and
- Legal obligation, where we are required to process personal data to comply with the law.
Artificial Intelligence and Automated Processing
Indy by Shimmer uses artificial intelligence to generate supportive insights, reflections, and guidance based on user input. Shimmer does not engage in solely automated decision-making that produces legal or similarly significant effects on individuals within the meaning of Article 22 of the GDPR.
Research and De-Identified Data
Shimmer may process personal data for research and development purposes, including evaluating and improving the effectiveness of its Services and AI-powered features. Where feasible, such research is conducted using anonymous, aggregated, or de-identified data. Research findings and insights may be shared publicly, including through publications, reports, or presentations at conferences or educational events, in a manner that does not identify any individual.
Retention
We retain personal data in accordance with the retention section above. Where we cannot state a fixed period, we determine it by reference to the purpose of processing, the sensitivity of the data, the risk of harm from unauthorized use, and any applicable legal or contractual requirement.
International Data Transfers
Personal data may be transferred to and processed in the United States or other countries outside the EEA or UK. Where required, Shimmer relies on appropriate safeguards to protect personal data, such as Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms.
Your GDPR Rights
Subject to applicable law, individuals in the EEA and UK have the right to:
- request access to their personal data;
- request correction or deletion of personal data;
- object to or request restriction of processing;
- request data portability; and
- withdraw consent at any time, where processing is based on consent.
You may exercise these rights by contacting privacy@shimmer.care. You also have the right to complain to your local data protection authority.
California Privacy Rights Addendum
This section applies to California residents and supplements the Privacy Policy above.
Use of Sensitive Personal Information
Shimmer uses Sensitive Personal Information only as permitted by applicable law, including to provide, operate, personalize, improve, secure, and maintain the Services; conduct research and analytics; ensure quality, safety, and integrity; and comply with legal obligations. Shimmer does not use Sensitive Personal Information to infer characteristics for advertising purposes, does not sell such information, and does not share it for cross-context behavioral advertising.
Your California Privacy Rights
- Request to know the categories and specific pieces of personal information Shimmer has collected about you.
- Request correction of inaccurate personal information.
- Request deletion of personal information, subject to applicable exceptions.
- Request to limit the use and disclosure of Sensitive Personal Information where applicable.
- Opt out of the sale or sharing of personal information where applicable.
Shimmer does not sell personal information and does not share personal information for cross-context behavioral advertising. California residents may exercise their rights by contacting privacy@shimmer.care. We may verify your identity before fulfilling a request as permitted by law, and we will not discriminate against you for exercising applicable privacy rights.
Consumer Health Data Addendum
This section applies to consumer health data as defined under applicable state law, including Washington’s My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act, and supplements the Privacy Policy above. It does not apply to information governed by HIPAA, and as described above, Shimmer is not a Covered Entity and does not hold Protected Health Information.
What Consumer Health Data We Collect
Depending on how you use the Services, information you share with us may qualify as consumer health data, including information about ADHD and related conditions, mental and behavioral health, symptoms and challenges you describe, sleep, medication you mention, wellbeing and mood, goals related to your health, and inferences we draw from any of the above.
How We Collect It
Directly from you, through what you share with a coach, enter into Indy, submit in surveys or assessments, or post in community spaces, and through your use of the Services.
How We Use It
To provide and improve coaching, community features, and Indy; to personalize your experience; to conduct research using de-identified or aggregated data; and for security, safety, and legal compliance. We do not use consumer health data for advertising.
Who We Share It With
Your coach. Service providers who process it on our behalf under contract. A Sponsor, but only to the limited extent described in How We Share Your Personal Information above and never at the level of session content. Legal and safety recipients where necessary. We do not sell consumer health data, and we do not require authorization for a sale because we do not conduct one.
Who Can See It Internally
Access to consumer health data is limited to Shimmer personnel and contractors, including coaches, who need it to do their work, and is subject to contractual confidentiality obligations.
Your Rights
You may confirm whether we collect, share, or sell your consumer health data; access it; obtain a list of third parties with whom we have shared it; and withdraw consent to its collection and sharing. You may also request deletion of your consumer health data, including from our archived and backup systems, subject to the exceptions described in Requesting Your Information above. To exercise these rights, contact privacy@shimmer.care. If we deny a request, you may appeal by replying to our decision, and we will respond in writing.

