Flarewatch Ltd
Flat 62, John Wetherby Court East, 22 High St, London, E15 2PP
Email: redgepartington@gmail.com
FlareWatch is a health monitoring service that uses data from wearable devices to help people with chronic health conditions track and anticipate flare-ups. This policy explains what personal data Flarewatch Ltd ("we", "us", "our") collects, why we collect it, how we protect it, and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018).
Please read this policy carefully before using FlareWatch. By creating an account and connecting your device, you give your explicit consent to us processing your health data as described here.
We collect two categories of personal data:
Account data
Health data from your wearable (special category data)
When you connect a wearable device, we receive and store the following metrics:
Health data you enter manually (special category data)
You may also choose to log the following directly in the app:
All manually entered data is optional and used solely to help contextualise your flare risk score.
We do not collect continuous heart rate readings, GPS location, audio, or any data not listed above.
We collect health data through a secure OAuth 2.0 connection to your device manufacturer's API. This means you explicitly authorise FlareWatch to read your data from your device account (Oura, Fitbit, Whoop, Polar, Withings, or Garmin). We never receive your device account password — authentication is handled entirely by the device manufacturer.
You can revoke this access at any time through your device manufacturer's account settings.
| Purpose | Data used | Legal basis (UK GDPR) |
|---|---|---|
| Providing the FlareWatch service — computing your personalised flare risk score | Health metrics | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) |
| Account management and authentication | Username, password hash | Contract — necessary to provide the service (Art. 6(1)(b)) |
| Sending flare alert emails | Alert email address, flare score | Explicit consent (Art. 6(1)(a)) |
| Improving the algorithm | Anonymised, aggregated health metrics | Legitimate interest (Art. 6(1)(f)) — data is fully anonymised before any analysis |
We do not sell, rent, or share your personal data with third parties for marketing. We use the following data processors to operate the service:
We may disclose your data if required to do so by law or in response to a valid request from a law enforcement authority.
Your data is hosted by Render Services Inc, a company based in the United States. We are in the process of establishing a formal Data Processing Agreement (DPA) with Render to cover these transfers in accordance with UK GDPR requirements. For more information on Render's data practices, see render.com/privacy.
Under UK GDPR you have the following rights. To exercise any of them, email us at redgepartington@gmail.com. We will respond within one month.
We take reasonable technical and organisational measures to protect your data, including:
No system is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours as required by law.
FlareWatch uses a single session cookie to keep you logged in. This cookie is strictly necessary for the service to function and does not track you across other websites. We do not use advertising or analytics cookies.
FlareWatch is not intended for use by anyone under the age of 18. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
We may update this policy from time to time. We will notify you of significant changes by email (if you have provided one) or by posting a notice in the app. The "last updated" date at the top of this page will always reflect the current version.
If you have a concern about how we handle your data, please contact us first at redgepartington@gmail.com and we will do our best to resolve it.
If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: