Welcome to CloserLook. This Privacy Policy explains how NexusPoint LLC, a Massachusetts limited liability company ("CloserLook," "we," "us," or "our"), collects, uses, and shares information when you use our services, including:
(collectively, the "Service").
We are committed to protecting your personal information, and in particular your health data. Please read this policy carefully. By using the Service, you agree to the collection and use of your information as described here.
If you have questions about this policy or wish to exercise your privacy rights, contact us at support@closerlook.health.
When you create a CloserLook account, we collect:
We do not store your password. Password authentication is handled entirely by Firebase Authentication (a Google service); CloserLook's servers never receive or store your password.
Skin tone note: Your skin tone selection is used solely to optimize the accuracy of the photoplethysmography (PPG) sensor on your device (which measures heart rate, SpO₂, and related metrics). It is not used for any other purpose and is not shared with advertisers or third-party analytics providers.
Your CloserLook device continuously collects physiological data. When you sync your device with the app, this data is stored on your device and, if you have an account, it will be synced to our servers. Health data collected includes:
The CloserLook app stores and uses your CloserLook device's Bluetooth MAC address as a unique device identifier for pairing, reconnection, and ensuring data is attributed to the correct device.
If you purchase a CloserLook Membership through our store, your payment and order information is processed by Shopify Inc. (via Shopify Payments). This includes your name, email address, billing address, shipping address, and payment card details. CloserLook does not have access to your full payment card number. Your transaction history (order dates, subscription status, renewal dates) is retained by CloserLook for account management and customer support purposes.
To identify and fix bugs, we use Firebase Crashlytics (a Google service) to collect crash reports when the app fails. These reports include device model, operating system version, application version, and a stack trace of the error. Our Crashlytics integration is configured to exclude personal health data from crash reports — only non-identifiable technical information is captured.
When you contact us by email or through the app, we retain the content of your message and your contact information to respond to your inquiry and improve our support.
We use the information we collect to:
We do not sell your personal information. Our business model is subscription-based. We do not monetize your health data or share it with advertisers.
We do not use your health metrics for advertising. Your health data is processed solely to provide you with the Service.
We do not sell your personal information. We share it only in the following circumstances:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Google — Firebase Authentication | User account authentication and sign-in | Email address, account identifiers |
| Google — Firebase Crashlytics | App crash reporting and diagnostics | Device model, OS version, app version, crash traces (no health data) |
| Google Cloud Platform | Cloud infrastructure — database, API hosting, key management | Account data and health data (for users who create accounts and enable cloud sync) |
| Shopify Inc. | Payment processing, order management | Name, email, billing/shipping address, payment card data, order history |
| Resend Inc. | Transactional email delivery | Name, email address |
If you use the Care feature to share your health data with family members or friends, your health data will be accessible to the person you invite for the duration of your sharing. You control who you share with and can revoke access at any time.
We may disclose your information if required by law, court order, or lawful request from a government authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of CloserLook, our users, or the public.
If CloserLook is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and subject to a materially different privacy policy.
Your health data is stored on your device first. The CloserLook app stores all your health data in an encrypted local database on your phone. This data is transmitted to our servers when you create a CloserLook account.
Device data is encrypted. The local database on your device is protected with AES-256 encryption. The encryption key is stored in your device's secure hardware enclave (iOS Keychain / Android Keystore).
You can view and update your account information at any time through the app's settings.
You can delete your account from within the app. When you initiate account deletion:
If you have shared your health data with someone via the Care feature, you can revoke their access at any time by navigating to the Care tab in the app, selecting the person's card, and choosing Stop sharing.
We implement appropriate technical and organizational measures to protect your personal information, including:
No security system is completely impenetrable. If you believe your account has been compromised, contact us immediately at support@closerlook.health.
We retain your account information and health data for as long as your account exists. If you delete your account, we delete your data as described above. We may retain certain records for longer periods when required by law.
The CloserLook Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from users under 18. If you are a parent and believe your child has created a CloserLook account, please contact us at support@closerlook.health.
Our website uses only functional cookies necessary to operate the site. We do not use third-party analytics cookies or advertising tracking technologies. The CloserLook mobile app does not use cookies.
If you are a Washington State resident, you have the right to confirm, access, delete, and withdraw consent to our collection of your consumer health data. We do not sell consumer health data. To exercise your rights, contact support@closerlook.health with the subject line "Washington Health Data Request."
If you are a California resident, you have the right to know, delete, correct, limit use of sensitive personal information, opt out of sale (we do not sell), and non-discrimination. To exercise your rights, contact support@closerlook.health with the subject line "California Privacy Request."
Several other US states have enacted privacy laws granting similar rights. To exercise any state privacy rights, contact us at support@closerlook.health.
If you are located in the EEA or the United Kingdom, NexusPoint LLC is the data controller for your personal information. We process your data on the bases of contract performance, consent, legitimate interests, and legal obligation. You have the right to access, rectify, erase, restrict, port, and object to processing of your data. Contact us at support@closerlook.health to exercise these rights.
Your personal information is processed in the United States. Transfers from the EEA or UK rely on EU Standard Contractual Clauses incorporated into our data processing agreements. You have the right to lodge a complaint with your local data protection authority: edpb.europa.eu (EU) or ico.org.uk (UK).
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and through a notice in the app before the changes take effect.
Email: support@closerlook.health
Mail: NexusPoint LLC, 1 Elm Square, Unit 2F, Andover, MA 01810, USA