Innovation Minds Privacy Policy
Health Connect API Data Privacy and Protection
Last updated: August 26, 2026
What We Access
Innovation Minds offers voluntary employee wellness challenges. Users may connect Health Connect to the Innovation Minds mobile app to participate. Connection only happens through the Innovation Minds mobile application, and only after the user grants explicit consent via the Google authorization flow.
We request read-only access to only the minimum data needed to support challenge features:
- Activity and fitness data (daily steps, calories burned) — used for steps and calories-burned challenges
- Sleep data (recorded sleep duration) — used for sleep-hours challenges
We do not request access to health metrics/measurements or mindfulness data, and we cannot create, modify, or delete anything in a user’s Health Connect account.
How We Use This Data
Authorized data is synced daily and evaluated against the user’s active wellness challenges. When a challenge requirement is met, the claim is processed automatically. This data is used solely for wellness challenge functionality — never for advertising, targeted advertising, unrelated profiling, or credit decisions.
Sharing and Disclosure
We do not sell Health Connect data or share it with advertisers, data brokers, or resellers. It is only shared where necessary to:
- Deliver the wellness challenge functionality
- Maintain the security and integrity of our services
- Comply with legal or regulatory requirements
- Meet obligations under the Health Connect API policies
Any third-party service providers processing this data on our behalf are bound by confidentiality, privacy, and security obligations, and access is limited to what’s necessary.
Data Protection and Security
We apply administrative, technical, and organizational safeguards, including encrypted transmission, access controls and authentication, need-based access restrictions, security monitoring, and secure development practices.
Data Retention and Deletion
Health Connect data is retained only as long as reasonably necessary to provide the wellness challenge functionality or meet legal/regulatory requirements, after which it is deleted per our data retention procedures.
User Choice and Consent
Connecting Health Connect is entirely voluntary. Users are informed of what data is requested and how it’s used before authorizing. Users may revoke access at any time; revocation stops new data collection, and previously stored data is handled per our retention and deletion policies.
Compliance
Our use of Health Connect API data adheres to the Health Connect API Developer and User Data Policy, including its Limited Use requirements.
Contact
Questions about this policy can be directed to Innovation Minds’ Privacy Officer. Bala@Innovationminds.com
Regulatory Compliance & Frameworks
Last updated: August 26, 2026
The policy strictly adheres to legal structures concerning the collection, processing, transmission, and protection of personal data:
- HIPAA Standards: Ensures strict compliance with regulations governing individually identifiable health information and medical records.
- California Civil Codes: Integrates statutory guidelines outlined by SB 168 and Civil Code section 1798.85(a) to protect highly sensitive data.
- Universal Protection: Enforces restrictions on physical access, print, electronic communications, facsimiles, telephone exchanges, and traditional mail.
Core Scope & Data Sensitivity
The privacy parameters actively police how private enterprise details and individual consumer metrics are isolated:
- Protected Demographics: Restricts handling and distribution of Social Security Numbers (SSNs), corporate user metrics, and healthcare accounts.
- Application Integrity: Data gathered through their enterprise collaborative platform or mobile applications is encrypted in transit and subject to region-specific configurations.
- Consent Architecture: By accessing or utilizing the Innovation Minds Platform, users provide direct authorization regarding explicit data collection and usage practices.
Security Infrastructure & Trust Controls
In reference to Innovation Minds Trust Center, the technical infrastructure incorporates several high-level protection blocks:
- Endpoint & App Security:
- Full device or container-based storage encryption.
- Continuous malware defense and anti-malware tracking mechanisms.
- Conspicuous links directly navigating back to the active privacy notices within tools.
- Network & Data Integrity:
- Multi-factor Authentication (MFA) requirements for administrative entry.
- Regular data backups alongside formal impact analysis processes.
- Strict limitation on external network connections and transmission confidentiality rules.
- Corporate Oversight:
- Enforced Code of Business Conduct guidelines.
- Rigorous personnel competency and background screening workflows.
Request a Demo
Submit your request now, and we'll quickly reach out to schedule your demo, available as a 25 or 55-minute session based on your needs. We guarantee your privacy and security, never sharing your info.