
Effective: March 21, 2026 · Version 1.2
CardioCommand, operated by Smith & Williams Holdings LLC ("we," "our," "us"), is a personal health intelligence platform designed to help individuals track, understand, and share their cardiometabolic health data. This Privacy Policy describes how we collect, use, store, and protect your information.
Account Information: Email address, display name, username, and authentication credentials.
Health Data: Glucose readings, blood pressure, medications, lab results, body composition, dietary logs, exercise data, and other health metrics you choose to enter.
Usage Data: Actions taken within the platform, feature usage patterns, and session information for product improvement.
Device Data: Browser type, operating system, and IP address for security and functionality.
If you subscribe to a paid plan, payment is handled entirely by Stripe. We never see or store your full card number. We retain only the identifiers Stripe gives us — a customer reference, a subscription reference, and your plan status — which is what tells the app whether your subscription is active.
We may use de-identified, aggregate data — data that has been stripped of all personally identifiable information — for the following purposes:
What this means: Your personal data is never shared, sold, or exposed. Only anonymized patterns — like “users in this age group with these conditions tend to benefit from X” — are used to make the system smarter for everyone. You can opt out of aggregate data contribution in Settings at any time.
We do not sell your personal health data. Your health information is shared only:
Your data is stored in Google Cloud / Firebase infrastructure with encryption at rest and in transit. Access to your data is controlled through role-based access controls and audit logging. All clinician access to patient data requires explicit consent authorization.
This section applies to consumer health data and is written to meet state consumer health data laws, including the Washington My Health My Data Act and Nevada SB370. We are not a HIPAA covered entity, and CardioCommand is not a medical record system.
What we collect. Only what you enter or upload:
Where it comes from. You. We do not buy health data, we do not infer it from your browsing, and we do not receive it from data brokers, advertisers or your insurer.
Why we collect it. To provide the service you asked for: organizing your data, computing your scores and trends, answering your questions about it, and producing the reports you choose to generate. We do not use it for advertising or profiling, and we do not sell it. We would not sell it for any price — there is no consent flow for that because there is no such sale.
Who else sees it.
Your rights over it. You can see all of it in the app, export all of it from Settings > Data, and delete all of it — permanently — from the same place. You can withdraw consent for AI processing by not using the AI features; the rest of the app keeps working. You can withdraw provider sharing at any time. We do not charge you, slow you down or reduce your service for exercising any of these.
How to ask. Email support@axiomops.io from the address on your account. We will respond within 45 days. If we deny a request we will say why, and you can appeal by replying to that response.
No geofencing. We do not use geofences around health facilities, and we do not collect precise location at all.
CardioCommand is designed with healthcare privacy principles in mind. We implement administrative, physical, and technical safeguards including access controls, audit logging, encryption, and minimum necessary data access principles. CardioCommand is not a certified electronic health record system and has not been independently audited for regulatory compliance.
We may update this policy from time to time. When we make material changes, we will notify you through the platform and request re-acceptance. Previous versions are retained for your records.
For questions about this Privacy Policy or your data, contact us at support@axiomops.io.