MARN Privacy Notice
Free invite only pilot
Draft version 5 October 2026
Proposed user facing text with review fields to complete before publication
1 Who is responsible and how to contact us
Streamline Studio [TO CONFIRM: full registered name if different, legal form, registration, legal address and country] is responsible for the personal data described in this notice, in the role required by the laws that apply ("MARN", "we", "us"). Privacy contact: [TO CONFIRM: monitored email, postal address and any required data protection officer or local representative].
Effective date: [TO CONFIRM]. Version: 5 October 2026 legal review draft. This notice covers [TO CONFIRM: application, related website and actual pilot countries]. It explains data used for general wellness routines, accounts and enabled community features. A separate notice may be needed for employees, job applicants or other unrelated activities.
2 Where information comes from
Information may come directly from you when you register, update a profile, record an activity, request a suggestion, post content or contact support; from your use of the service and technical logs; and from a sign in provider you choose. The exact fields returned by each approved sign in provider are [TO CONFIRM].
If a permitted guardian, inviter or other user supplies information about you, the source, minimum fields and lawful notification process must be disclosed: [TO CONFIRM]. We do not assume that access to a contact list, a device sensor or an external health service is permitted. Any such integration, data import and device permission must be separately verified and explained before use.
3 Information we handle
The following is a proposed data inventory. The enabled fields and whether each is necessary or optional must be confirmed in the pilot. Fields classified as health or other sensitive data receive the protections and permissions required by the relevant law.
Category | Examples and source | Status to confirm |
|---|---|---|
Account and access | Name or display name, email or phone, account identifiers, sign in provider identifiers, authentication and session records. | Which sign in methods and fields are enabled; required fields; guardian account design. |
Profile and wellness | Date of birth, height, weight, goals, timezone, preferences, food allergies or restrictions, and information entered for routines. | Minimum data needed; health or sensitive classification; age appropriate collection. |
Activity and habits | Exercise, meal or hydration records, habit progress and activity history you enter or generate through use. | Exact records, derived scores and optional fields. |
AI interactions | Requests, relevant profile or routine context sent for suggestions, generated responses and associated feedback. | Provider, minimum fields, logs, model improvement use and whether human review occurs. |
Community and invitations | Posts, comments or other enabled contributions, membership, shared progress, leaderboard entries and invitation information. | Enabled features, public or group audience, default visibility, recipient fields and age restrictions. |
Technical and support | IP address, device or application information, error or security events, usage events, support messages and consent or request records. | Exact telemetry, SDKs, identifiers, attachments and retention. No assumption that every listed item is collected. |
4 Why we use data and the applicable basis
A purpose must have an appropriate legal basis under the law that applies. The alternatives below are review fields, not a claim that every basis is available in every country. Sensitive data and children’s data can require additional consent, permits, safeguards or restrictions even where an ordinary account function is necessary.
Purpose | Relevant data | Basis or decision to approve |
|---|---|---|
Create and operate an account | Account, access and minimum profile data. | [TO CONFIRM] Basis for requested service or other locally recognized basis; capacity and guardian requirements. |
Provide personalized wellness features | Profile, health related fields, habits and activity records. | [TO CONFIRM] Specific sensitive data permission and locally applicable basis; distinguish optional personalization from necessary account data. |
Generate AI suggestions | Approved minimum request and context fields. | [TO CONFIRM] Basis, sensitive data conditions, provider disclosure and any separate choice required before sending. |
Provide community features | Chosen contributions, membership, progress and invitations. | [TO CONFIRM] Basis, intended audience and child feature restrictions; no automatic authority to message contacts. |
Protect and support the service | Access events, technical records and support requests. | [TO CONFIRM] Applicable legal obligation or other permitted basis; necessity and balancing assessment if relying on legitimate interests. |
Record choices and meet legal duties | Consent evidence, rights requests and minimum compliance records. | [TO CONFIRM] Specific duties and necessary records; do not retain whole profiles merely to prove consent. |
Improve performance and product quality | Approved telemetry, feedback and appropriately minimized statistics. | [TO CONFIRM] Whether enabled, legal basis and opt out or consent controls where required. |
Marketing or additional uses | No approved inventory in this draft. | [TO CONFIRM] Whether any marketing, advertising, tracking or sale/sharing model exists. Disclose and obtain required permission before introduction. |
5 Choices and consent
Where we rely on consent, we will ask for a clear and specific choice for the stated purpose and keep the evidence required by law. We will distinguish the acceptance of Terms from sensitive data consent and optional choices. The language, information and verification used for child or guardian consent are [TO CONFIRM: approved country and age flows].
You can withdraw a consent through [TO CONFIRM: working in app control and support route]. Withdrawal does not undo processing that was lawful before withdrawal. It may prevent a feature that genuinely needs that data from working. The affected features, available alternatives and whether any account function remains available are [TO CONFIRM]. Withdrawal must not be described as deleting all data automatically; any other lawful retention is addressed below.
Whether AI personalization can be disabled without closing the account, and whether a nonpersonalized alternative exists, are [TO CONFIRM]. Device notification, analytics, marketing or similar choices, if enabled, will be identified with their effect. We do not infer consent from an invitation or from simply reading this notice.
6 AI providers and other recipients
We may use service providers for approved hosting, authentication, storage, AI processing, technical support and other necessary operations. Before publication, identify their legal names, roles, data received and processing locations in [TO CONFIRM: provider list and accessible link]. Providers acting on our instructions must be covered by appropriate terms and safeguards; any provider acting independently must be identified as such.
For each AI feature, disclose the provider and model or service, fields sent, whether health or child data is permitted, prompt and output retention, provider training or improvement use, human access and available controls: [TO CONFIRM]. No promise of zero retention, no training or a particular hosting region is made by this draft.
Other users receive information only through the audience and sharing behavior of an enabled feature: [TO CONFIRM: visibility by field, default settings, searchability and leaderboards]. Choosing to post can expose information beyond your intended audience if recipients copy or share it. Avoid sensitive details in community content.
We may disclose information when legally required, or when a lawful, necessary and proportionate disclosure protects rights or safety. Any business transfer or similar event requires appropriate legal review, safeguards and notice where required. No disclosure to an acquirer is preauthorized by this draft. We do not include an unverified promise that data is never sold, used for advertising or disclosed for independent purposes. Finalize the actual practice before publication.
7 International transfers and locations
Data storage, access and processing countries are [TO CONFIRM: countries for each operator, provider, support team and backup location]. Remote access from another country can itself be relevant to transfer rules.
Where a cross border transfer is permitted, we will use the mechanism and safeguards required by the applicable law: [TO CONFIRM: adequacy, approved contractual safeguards, assessment, permit or other permitted mechanism and how to obtain information about it]. Consent does not automatically resolve every transfer restriction. Local health data, child data and localization requirements must be assessed before enabling the transfer.
8 Children and guardians
The ages eligible for MARN and the features available to each age group in each country are [TO CONFIRM: approved schedule]. This draft does not establish an adult only service or promise unrestricted access for children. Rules on a child’s consent and legal capacity vary; a single global age threshold is not approved.
Where guardian authorization or regulatory permission is required, we must obtain and verify it before the relevant collection or processing. The verification method, minimum supporting information, guardian controls, child friendly notice and process for changing or withdrawing authorization are [TO CONFIRM].
If you believe a child’s information has been collected without the required authorization, contact [TO CONFIRM: privacy contact]. We will assess the report, restrict affected processing as appropriate and take the steps required by law, which may include deletion. The investigation and guardian request process must avoid collecting unnecessary additional identity information.
9 Retention deletion and anonymization
We keep personal data only for a defined, lawful purpose and for the period justified by that purpose and applicable requirements. The approved retention periods or clear criteria, starting events and deletion methods are [TO CONFIRM: complete the retention schedule in the reviewer appendix and publish a user facing summary]. This draft does not prescribe a number of days or promise immediate deletion from every system.
An account closure request can disable access, revoke sessions, remove or deidentify profile records, and trigger other deletion steps only as the verified process provides: [TO CONFIRM: exact live behavior and completion timing]. Authentication providers, AI providers, logs, exports, backups and other processors need their own verified handling; an application deletion endpoint alone does not prove that these copies were erased.
Anonymization means information can no longer identify a person in the manner required by applicable law. Merely removing a name, hashing an identifier or replacing an account label may leave personal data that remains protected. We will not describe such data as anonymous unless the applicable standard is met.
Certain minimum records may need to be retained for a legal obligation, a specific dispute, fraud prevention or another legally permitted purpose: [TO CONFIRM: categories, basis, duration, access restrictions and deletion trigger]. Backup aging, restoration safeguards and handling of content already copied by other users are [TO CONFIRM]. Requests will be assessed against applicable rights and lawful exceptions.
10 Your rights and how to request them
Depending on applicable law, you may have rights to information, access, a copy of your data, correction, completion, deletion or destruction, withdrawal of consent, restriction or objection, and portability where the conditions apply. You may also have rights concerning automated decisions and to complain to a competent regulator. These rights and lawful exceptions vary by country.
Submit a request using [TO CONFIRM: verified in app route and monitored privacy contact]. We will use proportionate steps to verify identity and any representative or guardian’s authority. Do not send unnecessary identity documents, passwords or authentication codes. The applicable response deadline, extensions and escalation process are [TO CONFIRM: jurisdiction specific workflow].
An available account export may provide certain data in JSON. [TO CONFIRM: enabled route, fields, scope, format and secure delivery]. This feature does not define or limit a statutory access or portability right. Likewise, deleting an account is not the only way to make a privacy request.
Relevant regulator and complaint details are [TO CONFIRM: actual countries and competent authorities]. You may complain without first contacting us where the law allows. If a request is restricted or refused, we will provide the explanation and challenge options required by law.
11 Automated suggestions and profiling
MARN may use profile information, goals and recorded activity to adapt suggestions, routines or progress displays. The inputs, general logic, intended effects and available controls are [TO CONFIRM]. These may amount to profiling under applicable law.
The service is intended to support user choices about general wellness. It must not be described as making a medical diagnosis or a legally binding eligibility decision. Confirm whether any solely automated decision has legal or similarly significant effects; if so, disclose it and implement the required safeguards before use, including human review or contest rights where applicable. [TO CONFIRM: actual decision inventory].
12 Security incidents and updates
We use safeguards appropriate to the nature and risks of the processing, as verified for the actual service. [TO CONFIRM: accurate, nontechnical summary of access controls, data protection, monitoring and supplier oversight]. No system can be guaranteed completely secure. We do not promise a security certification, a particular encryption standard or legal compliance that has not been verified.
We assess suspected incidents and make notifications and take protective steps as required by the law that applies. Incident contacts, escalation duties and regulator or individual notification deadlines must be implemented in an internal response procedure; this notice does not replace it.
We will update this notice when practices or applicable requirements change and identify the version and effective date. Material changes will be communicated through [TO CONFIRM: notice channels and timing]. A notice update does not itself create consent for a new purpose. We will obtain any additional consent or authorization required before the relevant new processing.