Ren

Privacy Policy

Last updated: July 20, 2026

1. Who we are

Ren is operated by Frontback Labs, Inc. ("Ren," "we," "us," or "our"). Ren is a consumer wellness application that helps you design and run structured personal experiments ("n-of-1" experiments) on your own health — defining a hypothesis, choosing a protocol, tracking adherence and outcomes, and interpreting the results.

This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have. It applies to our iOS mobile app, our website at ren.so, and related services (together, the "Service").

If you do not agree with this policy, please do not use the Service.

2. A plain-language summary

We know nobody reads these. Here's the short version — the rest of the document is the binding detail.

  • You own your health data. We collect it to run your experiments and give you results.
  • We do not sell your data, and we do not use your health data to serve you third-party advertising.
  • We do not use your personal health data to train third-party AI models. When we use AI to help interpret your experiments, we send the minimum data needed to vendors who are contractually barred from training their models on it.
  • You can export or delete your data at any time from within the app or by contacting us.
  • We use vetted infrastructure providers (cloud hosting, wearable connectivity, analytics, AI) listed in Section 9. We hold data-protection agreements with them.

3. What we collect

3.1 Information you provide

  • Account information: name, email address, and authentication identifiers.
  • Profile information: details such as date of birth, sex, height, weight, and goals.
  • Experiment data: protocols you choose, interventions you test, adherence logs, subjective ratings, and any notes or outcomes you record.
  • Health and wellness inputs you enter manually (e.g., symptoms, supplements, sleep notes, mood).
  • Communications: messages you send to support and your responses to surveys or research prompts.

3.2 Information from connected devices and services

If you connect a wearable, health platform, or device, we receive the data you authorize through that connection — for example, steps, heart rate, heart-rate variability, sleep stages, workouts, and similar metrics. This connectivity is provided through our integration partners (see Section 9). You control which sources you connect and can disconnect them at any time.

On Apple devices, where you grant permission, we read data you select from Apple Health (HealthKit). Consistent with Apple's requirements, we do not use HealthKit data for advertising or marketing, and we do not share it with any party that will use it for those purposes.

3.3 Information we collect automatically

  • Usage and product analytics: screens viewed, features used, session timing, and in-app events, collected through our analytics provider (see Section 9). We configure analytics to avoid capturing your health content wherever feasible.
  • Device and technical data: device model, operating system, app version, language, time zone, IP address, and crash/diagnostic logs.
  • Cookies and similar technologies on our website (see Section 12).

We do not collect precise geolocation.

4. How we use it

We use your information to:

  • Provide the Service — create and manage your account, run your experiments, sync connected data, and display results.
  • Generate insights — analyze your data to help you interpret experiment outcomes, including with the help of AI tools (see Section 5).
  • Maintain and improve the product — debug, secure, and develop new features, using aggregated or de-identified data wherever possible.
  • Communicate with you — send service messages (which you cannot opt out of while you have an account) and, with your consent where required, product updates and marketing (which you can opt out of at any time).
  • Protect the Service and comply with law — prevent fraud and abuse, enforce our Terms, and meet legal obligations.

We process sensitive consumer health data only with your consent and only as needed to provide the features you have chosen to use. We do not use your health data for purposes incompatible with running your experiments without first obtaining your consent.

5. How we use AI

Ren uses artificial intelligence to help you design experiments and interpret results. When we do this, we send relevant data — which may include health inputs — to our AI infrastructure provider (see Section 9) to generate a response back to you.

  • Our agreements with our AI provider prohibit them from using your data to train their models.
  • We send the minimum information necessary for the feature you are using, and we de-identify or minimize inputs where feasible.
  • AI-generated insights are informational, not medical advice, and are not a substitute for a licensed clinician. The Service does not diagnose, treat, or prescribe.

6. How we share information

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California and other state privacy laws. We disclose information only as described here:

  • Service providers / subprocessors. We share information with vendors who process data on our behalf to run the Service — cloud hosting, database infrastructure, wearable connectivity, analytics, AI, and customer support. They are bound by contract to use the data only to provide services to us. Our current subprocessors are listed in Section 9.
  • At your direction. When you connect a third-party service or choose to share an experiment or result, we share what you authorize.
  • Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to protect the rights, safety, or property of you, us, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you and honor the commitments in this policy, and any acquirer will be bound by them.

We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, product, or business purposes; we will not attempt to re-identify it.

7. Your privacy rights and choices

Depending on where you live, you may have some or all of the following rights:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete your information.
  • Port / export your data in a portable format.
  • Withdraw consent to processing of sensitive health data.
  • Opt out of marketing communications, and of any "sale" or "sharing" (we do neither).
  • Non-discrimination for exercising your rights.

How to exercise them. Contact us at privacy@ren.so. We will verify your request and respond within the period required by applicable law. You may use an authorized agent where the law permits.

7.1 United States — consumer health data (Washington, Nevada, and similar laws)

If you are a resident of Washington (My Health My Data Act), Nevada (SB370), or a state with comparable consumer health data laws, you have the right to access, delete, and withdraw consent for our collection and sharing of your consumer health data. We collect and process consumer health data only with your consent, and we share it with subprocessors only to provide the Service. We do not sell consumer health data. To exercise these rights, contact privacy@ren.so.

7.2 California (CCPA/CPRA)

California residents may request to know, delete, and correct personal information, and to limit the use of sensitive personal information. We do not sell or share personal information as defined by the CPRA. The categories we collect and our purposes are described in Sections 3–6.

8. Health data privacy and HIPAA

As a direct-to-consumer wellness application, Ren is generally not a "covered entity" or "business associate" under HIPAA, and the consumer-facing data you provide is typically not "Protected Health Information" (PHI) as HIPAA defines it. Your data is instead protected under the consumer privacy and health-data laws described above. This may change if and when Ren offers telehealth, clinical, or prescription services and forms relationships with healthcare providers — at which point HIPAA may apply to those specific data flows and this section will be updated.

Where HIPAA does apply to a particular feature, we will: maintain the required administrative, physical, and technical safeguards; enter into Business Associate Agreements with relevant providers; and provide any legally required Notice of Privacy Practices for that feature.

9. Our subprocessors

We rely on the following providers. We maintain data-protection or business-associate agreements with them as appropriate, and we keep this list current.

Provider Purpose Data handled Location
Google Cloud Platform (GCP) Cloud hosting, primary database for sensitive health data, and AI inference Health/experiment data, account data US
PostHog Product analytics Usage/event data (minimized) US
Anthropic AI processing for insights and experiment interpretation Minimized health/experiment inputs; not used for model training US

10. Data retention and deletion

We retain your data only as long as necessary to provide the Service and comply with legal obligations. You may request deletion of your account and associated data at any time by contacting privacy@ren.so. We will delete your data within 30 days unless retention is required by law.

11. How we protect your information

We use technical and organizational safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls and least-privilege principles, network segmentation that isolates sensitive health data, audit logging, and vendor due diligence. No system is perfectly secure, and we cannot guarantee absolute security. If we ever experience a breach affecting your information, we will notify you and regulators as required by law (including, where applicable, the FTC Health Breach Notification Rule).

12. Cookies and tracking on our website

Our website uses essential cookies and limited, privacy-preserving analytics cookies. We do not use advertising or cross-site tracking cookies. Where required, we will request your consent and provide controls via a cookie banner. You can also manage cookies through your browser settings.

13. Children's privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at privacy@ren.so and we will delete it.

14. International data transfers

We are based in the United States and process information there. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S.

15. Third-party services

The Service may link to or integrate with third-party services (e.g., the wearable or health platform you connect). Their privacy practices are governed by their own policies, not this one. Review them before connecting.

16. Changes to this Privacy Policy

We may update this policy from time to time. If we make material changes, we will notify you through the Service or by email before they take effect, and we will update the "Last updated" date above. For changes affecting sensitive health data, we will obtain your consent where the law requires it.

17. Contact us

For questions about this Privacy Policy or your privacy rights, contact us at:

Email: privacy@ren.so

Ren
© Front Back LabsPrivacyTerms