WearBean Inc. ("Bean," "we," "our," or "us"), respects your privacy and is committed to protecting it through compliance with this Privacy Policy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal information when you visit our website (the "Site"), use our mobile application (the "Bean App" or "App"), purchase, set up, and use the Bean smart wearable device and any related accessories, firmware, or software (the "Bean Device" or "Product"), and use any other services, features, or functionality we make available (collectively, the "Bean Services" or "Services"). By accessing or using the Bean Services, creating an account, purchasing a Product, or otherwise interacting with WearBean Inc., you acknowledge that you have read, understood, and agree to the collection, use, disclosure, and retention of your information as described in this Privacy Policy and in our Terms of Service. This Privacy Policy is governed by and shall be construed in accordance with the laws of the State of Wyoming, without regard to its conflict-of-law principles, except where superseded by applicable federal law or the privacy laws of your state of residence as set forth in this Policy.
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to all information collected through the Bean Services, including information collected through the Site, the App, the Bean Device, customer support channels, and any related email, text message, push notification, or other electronic communications between you and WearBean Inc.
This Privacy Policy does not apply to information collected by third parties, including websites, applications, platforms, or services that may link to or be accessible from the Bean Services but are not owned, operated, or controlled by WearBean Inc. We are not responsible for the privacy practices or content of such third-party services, and we encourage you to review their privacy policies before providing any personal information or authorizing any data connection. Additionally, this Privacy Policy does not apply to information collected by employers, insurance companies, healthcare providers, researchers, or other entities that may receive your data through an enterprise program, wellness platform, research study, or health records integration. The privacy practices of those entities are governed by their own policies.
Bean is a consumer wellness technology company. The Bean Device and Bean Services are consumer wellness products and are not medical devices. The data, insights, scores, and recommendations provided through the Bean Services are for general health and wellness purposes only and are not intended to diagnose, treat, cure, monitor, or prevent any disease, medical condition, or injury. Always consult a qualified healthcare professional before making any medical decisions.
2. INFORMATION WE COLLECT
We collect information you provide to us directly, information generated automatically through your use of the Bean Device and the Bean App, information from third-party sources, and information derived or inferred from the data we process. Some of this information constitutes "personal information," "sensitive personal information," "consumer health data," or "biometric information" under applicable United States federal and state laws.
2.1 Information You Provide Directly
Account and Profile Information. When you create a Bean account, we collect your name, email address, password, date of birth, gender, height, weight, and, where you choose to provide it, a profile photograph and your mobile telephone number. You may also choose to provide additional profile details such as fitness goals, dietary preferences, and biographical information. The provision of optional profile information is voluntary.
Payment and Billing Information. When you purchase a Bean Device, accessories, or subscription services through our Site or App, we collect your name, billing address, shipping address, and payment card details, including card number, expiration date, and CVV. Payment card information is transmitted directly to our PCI-DSS-compliant third-party payment processors and is not stored on Bean's own servers. We retain only the last four digits of your card number, the card type, and the expiration date for transaction verification, customer support, and recurring billing management. For additional detail, see Section 7 (Payments).
Communications and Customer Support. When you contact our customer support team — whether by email, through in-app chat, by telephone, or through our AI-powered virtual support assistant — we collect the content of your messages, your contact information, and any attachments or information you choose to share. If you participate in surveys, promotions, contests, or product feedback programs, we collect the information you submit in connection with those activities.
User-Generated Content. You may choose to provide content within the Bean App, including notes, tags, journal entries, meal logs, symptom logs, menstrual cycle tracking data, medication logs, photographs, and free-text entries. You may also post content in community features or share data with other Bean users through social features. For additional detail, see Section 11 (Community and Social Features).
Third-Party Integration Authorizations. When you choose to connect your Bean account with third-party services — such as Apple HealthKit, Google Health Connect, third-party fitness applications, or health record platforms — you authorize those services to share data with us. The data we receive depends on the permissions you grant and may include historical and ongoing health, activity, and clinical data from those platforms. For additional detail, see Section 13 (Health Records You Import).
Contact List. If you choose to use friend-finding or social connection features within the Bean App, we may, with your separate and express permission, access the contact list on your mobile device to identify which of your contacts are also Bean users. We do not store your contact list on our servers and delete the contact list data from our systems immediately after completing the matching process. You may disable contact list access at any time through your mobile device's permission settings.
2.2 Information Collected Automatically from Device Sensors
The Bean wearable device contains sensors that continuously or periodically collect physiological, biometric, environmental, and motion data. The specific data collected depends on the sensors equipped in your Bean Device model, the features you have enabled, and the permissions you have granted. This category of data is classified as "sensitive personal information" under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and may constitute "biometric information" or "consumer health data" under applicable state laws, including the Illinois Biometric Information Privacy Act (BIPA), the Washington My Health My Data Act, and others. Bean processes the following categories of sensor-derived data:
Cardiovascular Data. Heart rate (both continuous and resting), heart rate variability (HRV), pulse waveform characteristics, and blood oxygen saturation (SpO2).
Thermal Data. Skin temperature (absolute values and variation from your personal baseline), ambient temperature, and temperature trends across sleep and activity cycles.
Respiratory Data. Respiratory rate (breaths per minute), respiratory depth, and breathing regularity and disturbances during sleep and activity.
Motion and Activity Data. Step count, distance traveled, floors climbed, cadence, pace, elevation gain and loss, calories burned (estimated), active minutes, sedentary time, exercise type detection, and movement intensity metrics captured through the Device's accelerometer, gyroscope, and altimeter sensors.
Sleep Data. Sleep duration, sleep onset and wake times, sleep stage architecture (awake, light sleep, deep sleep, REM sleep), sleep efficiency, sleep latency, sleep fragmentation, restlessness, and snore detection where the Device hardware supports it.
Electrodermal and Stress Data. Electrodermal activity (EDA), galvanic skin response (GSR), and derived stress, recovery, strain, and readiness scores based on multimodal sensor fusion across cardiovascular, thermal, respiratory, motion, and electrodermal data streams.
Additional Biometric Measurements. Where the Device hardware supports it: blood pressure estimation, blood glucose trend monitoring, electrocardiogram (ECG) recordings, body composition estimates, and hydration level indicators. Not all Bean Device models include all sensors, and certain biometric measurements require specific hardware capabilities.
Audio Data. If your Bean Device includes microphone functionality and you enable voice features, audio recordings of voice commands and, where applicable, ambient sound analysis may be collected. Voice data is processed in accordance with the permissions you grant through your Device and mobile operating system settings.
2.3 Location Data
With your consent, the Bean App collects precise geolocation data through GPS, Wi-Fi access points, Bluetooth beacons, and cell tower triangulation from the mobile device paired with your Bean wearable. This data is used to map outdoor activities, record workout routes, provide location-based features, and generate contextual insights about your movement patterns. You may disable location collection at any time through your mobile device settings, though certain features of the Bean Services — such as GPS-tracked workout mapping — may be unavailable or degraded without location data. We also derive approximate location from your IP address when you access our Site or Services.
2.4 Usage and Technical Data
When you interact with the Bean App, visit our Site, or access the Bean Services, we automatically collect technical and usage information, including: your IP address; device type, device identifier, and advertising identifier (IDFA or AAID); operating system version, browser type and version, mobile network carrier, and time zone setting; App usage data, including features accessed, screens viewed, buttons tapped, session duration, and crash logs; Site interaction data, including pages visited, referring and exit URLs, clickstream data, and search queries; device pairing and synchronization logs, including Bluetooth connection events, firmware version, and data sync timestamps; and cookie data and similar tracking technologies, as further described in Section 17 (Cookies and Tracking Technologies).
2.5 Derived and Inferred Data
Using the data described above, Bean generates derived metrics, scores, and inferences through algorithmic processing, including machine learning models. These derived outputs may include, but are not limited to: readiness scores; recovery scores; sleep quality scores; activity intensity scores; stress and resilience scores; energy reserve or "body battery" estimates; training load and strain calculations; cardiorespiratory fitness (VO2 max) estimates; biological age estimates; illness risk indicators; circadian rhythm phase assessments; and wellness trend predictions and personalized recommendations. For additional detail on how AI and ML models are used to generate these outputs, see Section 9 (Artificial Intelligence and Machine Learning) and Section 10 (Automated Decision-Making and Profiling).
2.6 Data from Third-Party Sources
We may receive information about you from third-party sources, including: connected third-party services you link to your Bean account, such as Apple Health, Google Health Connect, Strava, MyFitnessPal, clinical health record platforms, and other fitness or wellness applications; employers, insurance companies, or wellness program administrators, if you receive a Bean Device through an enterprise or employer wellness program; marketing and analytics partners, who may provide campaign performance data and audience segment information to help us measure the effectiveness of our marketing; and social media platforms, if you interact with Bean's social media pages or choose to authenticate through a social media account.
3. HOW WE USE YOUR INFORMATION
We use the categories of personal information described above for the following business and commercial purposes.
To Provide and Maintain the Bean Services. We use your information to create and manage your account; authenticate your identity; pair and synchronize your Bean Device with the Bean App; process and display your sensor data and derived metrics on your in-app dashboard; deliver personalized health and wellness insights, scores, and recommendations; enable community and social features you choose to use; process and fulfill orders for Bean Products and subscription services; and deliver the core functionality of the Services for which you created your account. This processing is necessary to perform our contract with you under our Terms of Service.
To Improve, Personalize, and Develop the Services. We use your information to analyze usage patterns and trends; identify bugs, performance issues, and areas for improvement; conduct research and development; train, test, validate, and refine our machine learning and AI models, including models that power personalized wellness insights, sleep staging, activity classification, health trend forecasting, and virtual support assistants; develop new features, products, and Services; and personalize your experience, including customizing the content, insights, and recommendations you see. Where we use data to train or improve AI and ML models, we implement privacy-protective measures such as pseudonymization, aggregation, and de-identification where technically feasible. For additional detail, see Section 9 (Artificial Intelligence and Machine Learning).
To Communicate with You. We use your information to send service-related communications, including account verification messages, security alerts, device pairing confirmations, firmware update notifications, order confirmations, shipping updates, and changes to our terms or policies; respond to your customer support inquiries and requests; send marketing and promotional communications about Bean Products, features, and offers, where permitted by applicable law and subject to your opt-out rights; and deliver in-app messages and push notifications about your activity, insights, reminders, and recommendations. You may control marketing communications through your notification preferences in the Bean App (Settings, Notifications) or by using the unsubscribe link included in any marketing email. You may control push notifications through your mobile device settings. For practices relating specifically to SMS and text messaging, see Section 8 (SMS and Text Messaging).
To Promote Safety, Security, and Integrity. We use your information to detect, investigate, and prevent fraudulent transactions, unauthorized access, security incidents, and other illegal or prohibited activities; authenticate users and devices; enforce our Terms of Service and other policies; protect the rights, property, and safety of Bean, our users, employees, and the public; and comply with legal obligations, regulatory requirements, law enforcement requests, and court orders.
To Market and Advertise. We use non-sensitive personal information, such as your email address, device type, App usage data, and Site interaction data, to send you marketing communications about Bean Products and Services; display contextual advertising for Bean Products on third-party platforms; and measure the effectiveness of our advertising campaigns. We do not use your sensitive biometric data, health data, or precise geolocation data for marketing or advertising purposes. We do not sell your personal information for monetary consideration, and we do not share your personal information for cross-context behavioral advertising.
To Enable Third-Party Integrations. When you choose to connect your Bean account with third-party services, platforms, or applications, we process your data as necessary to facilitate that integration. The third party's use of your data is governed by its own privacy policy, and you may disconnect any integration at any time through your Bean App account settings.
For Research and Analytics. We may process personal information, including sensor-derived biometric and health data, for research and analytics purposes related to human performance, health, wellness, and product development. Where feasible, we use de-identified or aggregated data for such purposes. When we conduct or facilitate research studies, participants are required to review and sign a separate informed consent form that describes the specific data collection, use, and retention terms applicable to that study.
4. LEGAL BASES FOR PROCESSING
Where required by applicable laws, we process personal information under one or more of the following lawful bases.
Contractual Necessity. We process personal information when it is necessary to perform a contract with you, including our Terms of Service. This includes processing to create and maintain your Bean account, provide the core functionality of the Bean Services, process and fulfill product orders, and manage payments.
Consent. We process sensitive personal information — including biometric data, health data, and precise geolocation data — only with your affirmative consent. You may withdraw your consent at any time through the Bean App settings, by disabling sensor or location permissions through your device operating system, or by contacting us at the website contact form. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to the withdrawal. Where we process personal information for marketing communications sent via email, SMS, or push notification, we do so based on your consent where required by applicable law.
Legitimate Interests. We process personal information based on our legitimate business interests when we: improve, personalize, and develop the Bean Services; conduct analytics and research; provide customer support; send marketing communications where consent is not required by applicable law; detect and prevent fraud, security incidents, and illegal activity; and enforce our Terms of Service and other policies. When we rely on legitimate interests, we carefully balance our interests against your privacy rights and do not process personal information where your rights override our legitimate interests.
Legal Obligation. We process personal information when necessary to comply with applicable laws, regulations, legal process, or enforceable governmental requests, including tax, accounting, consumer protection, and data breach notification obligations.
5. HOW WE DISCLOSE AND SHARE YOUR INFORMATION
Bean does not sell your personal information to third parties for monetary consideration, and we do not share your personal information for cross-context behavioral advertising. We disclose personal information only in the following circumstances and to the following categories of recipients.
Service Providers and Processors. We engage third-party companies and individuals to perform services on our behalf and at our direction. These service providers are contractually bound to use your personal information only as necessary to provide the services we have engaged them to perform and are prohibited from using your data for their own independent purposes. The categories of service providers we use include: cloud infrastructure and data storage providers that host the Bean platform and store your data; PCI-DSS-compliant payment processors that handle payment card transactions on our behalf; customer support platforms, including providers of CRM, help desk, and AI-powered support chatbot services; analytics providers that help us understand how users interact with the Bean App and Site; marketing and email communication platforms that enable us to deliver email, push notification, and SMS communications; authentication and security providers that assist with identity verification, fraud detection, and security monitoring; and survey and feedback platforms that host and manage user surveys and product feedback collection.
Third-Party Integrations You Authorize. When you choose to connect your Bean account with a third-party application, platform, or service, you direct us to share your information with that third party. The information shared is limited to the data types you authorize at the time of connection. Once your data is transmitted to the third party, that party's privacy policy and terms govern its use and handling of your data. Bean is not responsible for the privacy practices of third parties you choose to connect. You may review and revoke third-party integrations at any time through your Bean App account settings. Revoking access prevents future data sharing but does not affect data the third party has already received. Because we cannot recall data a third party has already obtained, you should also exercise any deletion or withdrawal rights directly with the third party.
Affiliates and Corporate Group. We may share information within the WearBean Inc. corporate group, including current and future subsidiaries and affiliates, for the purposes described in this Privacy Policy. Any affiliate that receives your data is required to comply with this Privacy Policy.
Business Transfers. If WearBean Inc. is involved in a merger, acquisition, reorganization, sale of assets, financing, bankruptcy, or similar corporate transaction, your personal information may be transferred as part of that transaction. We will provide notice to you before your personal information is transferred to a different entity and becomes subject to a different privacy policy, where required by applicable law.
Legal and Regulatory Disclosures. We may preserve, access, or disclose your personal information when we believe in good faith that such action is necessary to: comply with applicable laws, regulations, legal process, or enforceable governmental requests; respond to valid legal process, including search warrants, subpoenas, and court orders; enforce our Terms of Service and investigate potential violations; detect, prevent, or address fraud, security, or technical issues; or protect against harm to the rights, property, or safety of Bean, our users, employees, or the public, as required or permitted by law. Where permitted by law and not prohibited by court order or exigent circumstances, we will make reasonable efforts to notify you before disclosing your information in response to legal process.
Aggregated and De-Identified Data. We may disclose aggregated, de-identified, or anonymized information — from which individual identities cannot reasonably be determined — for research, scientific publication, product development, benchmarking, marketing, and other lawful purposes. When we de-identify data, we commit to maintaining and using the data only in de-identified form and to not attempting to re-identify the data except as permitted by applicable law.
With Your Consent. We may disclose your personal information for any other purpose with your prior affirmative consent or at your express direction.
6. SENSITIVE PERSONAL INFORMATION AND BIOMETRIC DATA
6.1 Categories of Sensitive Data
We collect are classified as "sensitive personal information," "sensitive data," or "consumer health data": biometric information processed for the purpose of uniquely identifying an individual, including physiological and behavioral characteristics derived from Bean Device sensors; health data, including data concerning your physical and mental health, reproductive health, sleep, activity, stress, recovery, and general wellness; precise geolocation data collected through GPS and other location technologies from your paired mobile device; account log-in credentials in combination with any required security code, password, or credentials allowing access to your account; and the contents of your communications with us, where such communications contain sensitive content.
6.2 How We Use and Disclose Sensitive Data
We use and disclose sensitive personal information only for the following purposes: to provide the Bean Services and the core functionality you request and expect from a smart wearable device; to detect and prevent security incidents, fraud, and illegal activity; to ensure the physical safety of individuals; for short-term, transient use, including non-personalized advertising, provided the data is not disclosed to third parties or used to build user profiles; to perform services on our behalf, including maintaining and servicing accounts, providing customer service, processing orders and transactions, verifying customer information, and processing payments; to verify, maintain, and improve the quality and safety of the Bean Services; to comply with legal obligations; and for purposes that do not involve inferring characteristics about you beyond those necessary to provide the Bean Services. We do not use or disclose your sensitive personal information for targeted advertising or cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you beyond those necessary to provide the Services.
6.3 Biometric Data Specific Provisions
Where we collect biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington My Health My Data Act, or similar state biometric privacy laws, we: obtain your informed consent before collecting your biometric data and disclose the specific purpose and duration for which your biometric data is collected, stored, and used; do not sell, lease, trade, or otherwise profit from your biometric data; store, transmit, and protect your biometric data using a reasonable standard of care within our industry, and in a manner that is at least as protective as the manner in which we protect other sensitive personal information; and retain your biometric data only until the first of the initial purpose for collection being satisfied, or three years after your last interaction with the Bean Services, unless a longer retention period is required by law or you provide renewed consent.
7. PAYMENTS
7.1 Payment Information We Process
Depending on the transaction, Bean and our payment processors may process your payment card number, expiration date, and security code (CVV); billing name and billing address; shipping address; and transaction amount, date, and merchant information. Full payment card details are transmitted directly from your browser or device to our PCI-DSS-compliant payment processors and are not stored on Bean's own servers. We retain only the last four digits of your card number, the card type, and the expiration date for transaction verification, customer support, and recurring billing management where applicable.
7.2 Payment Processors and Financial Partners
Bean uses PCI-DSS-compliant third-party payment processors, card networks (such as Visa, Mastercard, and American Express), and, for contactless payment features within the Bean App, issuing banks and token service providers to process your transactions. These partners receive only the minimum information necessary to facilitate and settle your transaction and are bound by their own privacy policies and security obligations.
7.3 PCI DSS Compliance
Bean maintains a payment environment designed to align with the Payment Card Industry Data Security Standard (PCI DSS). Our payment processors are PCI DSS-validated service providers. Bean does not store complete payment card numbers, magnetic stripe data, or card verification codes on our systems. All payment card data transmitted between your browser or device and our payment processors is encrypted in transit using Transport Layer Security (TLS) 1.2 or higher.
7.4 Transaction Records
We retain transaction records, which contain truncated card numbers only, for as long as necessary to comply with accounting, tax, and other legal obligations, to resolve disputes, and to enforce our agreements. These records are stored securely, and access is restricted to authorized personnel with a legitimate business need.
8. SMS AND TEXT MESSAGING
8.1 Enrollment in Messaging Services
Bean may offer a messaging program through which you may receive text messages (SMS or MMS), including shipping notifications, order updates, account verification codes, service alerts, and, where you have separately and affirmatively opted in, marketing and promotional communications (the "Messaging Service"). By providing your mobile telephone number and affirmatively opting into the Messaging Service, you consent to receive text messages from Bean at the number you provided.
8.2 Information Collected Through the Messaging Service
When you enroll in the Messaging Service, we may collect your phone number, your mobile carrier information, your opt-in consent record, messaging history including delivery and read receipts, and the content of messages you send to us through the Messaging Service. If you participate in promotions, surveys, contests, or research programs associated with the Messaging Service, we may collect additional information you voluntarily provide in connection with those activities.
8.3 Use of Messaging Information
Information collected through the Messaging Service may be used to: deliver messages, notifications, and alerts to you; analyze messaging service performance and delivery rates; personalize messaging content and frequency; improve the operation of the messaging program; and comply with legal obligations. Bean may engage third-party service providers to assist in delivering messaging communications. Such providers may process messaging data solely for the purpose of providing services on behalf of Bean and are contractually prohibited from using messaging data for their own independent purposes.
8.4 No Condition of Purchase
You are not required to consent to receive marketing text messages as a condition of purchasing any Bean Products or using any Bean Services. Your consent to receive non-marketing operational messages — such as order confirmations, shipping updates, or account verification codes — is separate and is based on our contractual obligation to provide the Services you have requested.
8.5 Opt-Out and Revocation of Consent
You may opt out of receiving marketing text messages from Bean at any time by replying with any of the following standard opt-out keywords to any text message you receive: STOP, END, CANCEL, UNSUBSCRIBE, or QUIT. After you submit an opt-out request, we will send you a single confirmation message confirming that you have been unsubscribed, and we will not send you further marketing text messages unless you subsequently re-enroll. You may also opt out by adjusting your communication preferences in the Bean App (Settings, Notifications, SMS) or by contacting customer support at the website contact form.
8.6 Message Frequency and Data Rates
Message frequency will vary depending on your interactions with the Bean Services, your notification preferences, and the specific messaging program in which you are enrolled. Message and data rates may apply according to your mobile service plan. Please consult your mobile carrier for details on applicable rates and charges.
8.7 Sharing of Messaging Opt-In Consent Data
Bean does not share or sell your text messaging opt-in consent data, phone number, or messaging history with any third party or affiliate for their own marketing or promotional purposes. Messaging data is shared only with our service providers who assist in delivering messaging communications, and only to the extent necessary to provide those services. Aggregated or anonymized messaging data that does not identify individual users may be shared for analytical or operational purposes.
9. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING
9.1 AI-Powered Features in the Bean Services
The Bean Services incorporate artificial intelligence (AI), machine learning (ML), and algorithmic processing to power core features of the product. These include, but are not limited to: personalized readiness, sleep, and activity scoring; health and wellness trend forecasting; illness risk indicators; exercise and activity classification; sleep stage detection; stress and recovery assessment; circadian rhythm analysis; and AI-powered virtual support assistance. The AI and ML models that power these features are trained and refined using data collected through the Bean Services.
9.2 Training of Bean's First-Party AI and ML Models
We may use personal information — including sensor-derived biometric and health data, usage data, and user-provided content — to develop, train, test, validate, improve, and support Bean's own first-party AI and machine learning models, including models that generate personalized wellness insights and large language models that power virtual support assistants and in-app conversational features. When we use personal data for AI and ML training and development, we implement privacy-protective measures including, where technically feasible, pseudonymization, aggregation, data minimization, and de-identification. Access to training data is restricted to authorized personnel with a legitimate need, and training datasets are subject to the same security controls as other sensitive personal information.
9.3 Third-Party AI and Large Language Model Providers
Where Bean engages third-party AI, machine learning, or large language model providers to process data on our behalf — for example, cloud-based AI inference services, third-party LLM APIs used in customer support features, or external model-training infrastructure — such providers act as our service providers or processors. They are contractually bound to process your data only for the purposes we specify, are prohibited from using your data to train their own models or for any independent purpose, and must implement security measures at least as protective as those described in this Privacy Policy.
9.4 No Sale of Data for Third-Party AI or LLM Training
Bean does not sell, license, or otherwise make available your personal information — including your biometric data, health data, or any other data collected through the Bean Services — to any third party for the purpose of training, developing, or improving that third party's own artificial intelligence, machine learning, or large language models. Any use of your data for AI or ML purposes is strictly limited to powering the features of the Bean Services, improving and developing Bean's own first-party models, and supporting the research and analytics purposes described in this Privacy Policy.
9.5 User Control Over AI Feature Data
Where an AI-powered feature relies on data you voluntarily provide — such as text you submit to a virtual assistant, journal entries, or tags — you may choose not to use that feature. For features that rely on sensor data, you may control data collection through your device permissions and Bean App settings.
10. AUTOMATED DECISION-MAKING AND PROFILING
10.1 Use of Automated Processing
The Bean Services use automated processing, including AI and algorithmic analysis, to generate personalized wellness insights, scores, recommendations, and trend predictions. This processing involves the automated analysis of your sensor data, profile information, user-provided content, and usage patterns to produce outputs displayed to you through the Bean App dashboard, in-app messages, push notifications, and, where enabled, email or SMS communications.
10.2 Nature of Automated Decisions
The automated outputs generated by the Bean Services — including readiness scores, recovery scores, sleep quality scores, activity recommendations, stress assessments, illness risk indicators, and similar wellness insights — are designed to provide general health and wellness information and guidance. These outputs are not medical diagnoses, are not intended to replace the advice of healthcare professionals, and do not constitute decisions that produce legal effects concerning you or similarly significant effects. You should always consult a qualified healthcare provider before making medical, health, or lifestyle decisions based on information from the Bean Services.
10.3 Right to Information About Automated Processing
Where required by applicable state privacy laws, you have the right to request meaningful information about the logic involved in our automated decision-making processes, including the categories of personal information used and the general purpose and outcome of the processing. To exercise this right, submit a request as described in Section 15 (Your Privacy Rights and Choices).
11. COMMUNITY AND SOCIAL FEATURES
11.1 Social Sharing Within the Bean App
The Bean App may include community and social features that allow you to connect with other Bean users, share selected personal information, and interact with content posted by others. These features may include friend connections, leaderboards, activity challenges, shared circles or groups, in-app messaging, and the ability to post comments, reactions, or encouragement on other users' shared data.
11.2 Data You Choose to Share
When you use Bean's social features, you choose what information to share and with whom, subject to the privacy settings you configure. Depending on the specific feature and your settings, you may share information such as: your name and profile photograph; your activity statistics, including steps, distance, active minutes, and calories burned; your sleep data, including sleep duration and sleep score; your readiness, recovery, or stress scores; your workout summaries and route maps; and content you post, such as comments, reactions, tags, and photographs. You control what data is visible to other users through your privacy settings in the Bean App (Settings, Privacy, Social Sharing). You may change these settings at any time, or opt out of social sharing entirely by disabling all social features.
11.3 Friend Finding and Contact List Access
If you choose to use friend-finding features, the Bean App may, with your express permission, access the contact list on your mobile device to identify which of your contacts are also Bean users. We use this information solely to facilitate connection requests. We do not store your contact list on our servers, and we delete the contact list data from our systems immediately after completing the matching process. You may disable contact list access at any time through your mobile device's permission settings.
11.4 Visibility and Third-Party Sharing
Information you share through Bean's social features may be visible to other Bean users according to your privacy settings. Once you have shared information with other users, those users may be able to view, screenshot, or otherwise retain that information even after you change your sharing settings or delete your account. Do not share information through social features that you would not want to become public or that you would not want other users to retain. Bean is not responsible for how other users handle information you choose to share through social features.
11.5 Social Features and Children
Social features that involve sharing personal information with other users or that allow communication between users are not available to users under the age of sixteen. See Section 16 (Children's Privacy) for additional information.
12. ENTERPRISE AND EMPLOYER WELLNESS PROGRAMS
12.1 Program Participation
Bean may make the Bean Services available through enterprise, employer, or organizational wellness programs (each, an "Enterprise Program"). If you receive a Bean Device or access Bean Services through an Enterprise Program, your participation is governed by the terms of that program and by this Privacy Policy. The organization sponsoring the Enterprise Program (your "Program Sponsor") may be your employer, an insurance company, a healthcare provider, a coach, a trainer, a researcher, or another entity.
12.2 Information Shared by the Program Sponsor
When you enroll in an Enterprise Program, your Program Sponsor may share certain information with Bean to facilitate your enrollment, which may include your name, email address, employee or member identification number, program eligibility status, and program-specific preferences or requirements. Bean processes this information to create or link your Bean account, verify your eligibility, and configure your Services in accordance with the Enterprise Program parameters.
12.3 Information Shared with the Program Sponsor
If you choose to participate in an Enterprise Program, you will be asked to consent to the sharing of certain personal information — which may include your activity data, sleep data, readiness scores, heart rate data, heart rate variability, and other metrics — with your Program Sponsor. The specific categories of data shared, the duration of sharing, and the purposes for which the Program Sponsor may use the data will be described to you in the consent request and, where applicable, in the Enterprise Program's terms and privacy notice. You are not required to consent to data sharing with your Program Sponsor, and declining to share data with the Program Sponsor will not affect your ability to use the core features of your Bean Device and Bean App for personal use.
12.4 Program Sponsor as Data Controller
Once your personal information is transferred to a Program Sponsor through an Enterprise Program, the Program Sponsor — not Bean — becomes the controller of that data and is responsible for its subsequent use, processing, retention, and protection. The Program Sponsor's own privacy policy governs its handling of your data. Bean is not responsible for the Program Sponsor's processing of your data or for the security of any personal data the Program Sponsor has extracted from the Bean platform. Before consenting to share your data through an Enterprise Program, we strongly encourage you to review the Program Sponsor's privacy policy and to direct any questions about their data practices to the Program Sponsor.
12.5 Withdrawal of Consent and Data Deletion
You may withdraw your consent to share data with a Program Sponsor at any time by adjusting your settings in the Bean App (Settings, Privacy, Enterprise Programs) or by contacting Bean at the website contact form. Withdrawing consent will stop the flow of new data to the Program Sponsor but will not affect data the Program Sponsor has already received. To request deletion of data already shared with a Program Sponsor, you must contact the Program Sponsor directly.
12.6 Aggregated Enterprise Data
Bean may use aggregated and de-identified data derived from Enterprise Program participants for analytics, statistics, research and development, and product improvement purposes. Such aggregated data does not identify individual users and is not personal information.
13. HEALTH RECORDS YOU IMPORT
13.1 Connecting Health Record Sources
The Bean App may allow you to connect and import your electronic health records from third-party sources, including healthcare providers, health systems, health plans, clinical data networks, and other sources of health information. When you choose to connect a health record source, you direct that organization to share your health records with Bean. You are in control of this connection: you choose which source of records to connect, what categories of records to import, and when to disconnect. Depending on the source you connect and the permissions you grant, imported records may include visit summaries, clinical notes, diagnoses, medications, allergies, immunizations, lab results, vital signs, imaging reports, care plans, and other health information.
13.2 How Imported Health Records Differ from Bean Sensor Data
Data collected by your Bean Device is generated by sensors you wear and is processed to derive wellness insights as described in this Privacy Policy. Imported health records, by contrast, come from third-party clinical sources you direct to share records with us. Imported health records may contain information generated by healthcare professionals in clinical settings and are subject to the accuracy, completeness, and formatting of the source system.
13.3 Bean's Role as Data Controller
Once your health records are imported into the Bean Services, Bean acts as the data controller of those records, and this Privacy Policy governs our processing. When you authorize a healthcare provider or other entity regulated by the Health Insurance Portability and Accountability Act (HIPAA) to disclose your health records to Bean, the disclosure is made at your request under the individual's right of access under HIPAA, not at the direction of the covered entity. Bean is not a Business Associate of your healthcare provider for purposes of this patient-directed disclosure, and the records we receive are not protected by HIPAA while in Bean's possession. The privacy rights described in Section 15 (Your Privacy Rights and Choices) and the state-law protections described in Sections 20 and 21 apply to your imported health records.
13.4 Use of Imported Health Records
We use imported health records to: provide you with a unified view of your health and wellness information alongside your Bean Device data; generate more comprehensive and personalized insights and recommendations; improve the accuracy of our algorithms, AI models, and health metrics; and for the research and analytics purposes described in this Privacy Policy, subject to de-identification where feasible.
13.5 Managing and Deleting Imported Health Records
You may view, export, or delete your imported health records through the Bean App (Settings, Privacy, Health Records). You may disconnect any health record source at any time, which stops new records from flowing to Bean. Deleting imported health records from Bean does not affect the records maintained by the healthcare provider or other source. To request deletion of records held by the source, contact the source directly.
14. DATA RETENTION
We retain personal information for as long as your Bean account is active, or as long as necessary to provide the Services you have requested, comply with our legal obligations, resolve disputes, and enforce our agreements. Our specific retention practices include:
Account information is retained for the life of your account. If you delete your account, your account information is deleted within thirty days, though residual copies in backup systems may persist for up to ninety days while those systems complete their deletion cycles.
Sensor and biometric data is retained for the life of your account to enable long-term trend analysis, historical comparisons, and continuous improvement of your health insights. Upon account deletion, this data is deleted within thirty days, subject to backup system lag as described above.
Payment information: full payment card details are not stored by Bean. Transaction records with truncated card numbers are retained as necessary for accounting, tax, and dispute resolution purposes.
Usage and technical data is retained for up to twenty-four months from the date of collection, unless a longer period is required for security investigations or legal proceedings.
Marketing communication data is retained until you opt out of marketing communications. Once you opt out, your contact information is suppressed from future marketing lists.
Data subject to a legal hold — such as a litigation preservation obligation — is retained until the hold is released.
AI and ML training datasets derived from personal information are retained only as long as necessary for the specific training, validation, or improvement purpose and are deleted or de-identified when no longer needed for that purpose.
When data is no longer needed for any of the purposes described above, we securely delete or de-identify it using industry-standard methods.
15. YOUR PRIVACY RIGHTS AND CHOICES
Bean extends the following privacy rights to all users, regardless of state of residence. If you reside in a state with enhanced privacy rights — including but not limited to California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Delaware, Texas, and others as their laws come into effect — the rights described below are provided in accordance with and to the extent required by those laws.
Right to Know and Access. You have the right to request that we disclose to you: the categories of personal information we have collected about you; the categories of sources from which we collected the personal information; the business or commercial purposes for collecting, selling, or sharing your personal information; the categories of third parties to whom we disclose personal information; and the specific pieces of personal information we have collected about you. You may submit a request to know up to two times in any twelve-month period.
Right to Correction. You have the right to request that we correct inaccurate personal information we hold about you. Many data fields — including height, weight, gender, and other profile details — can be corrected directly through the Bean App (Settings, Profile). For other data, you may submit a correction request as described below.
Right to Deletion. You have the right to request that we delete personal information we have collected from you, subject to certain exceptions — such as when retention is required by law, for security purposes, to complete a transaction, or to comply with a legal obligation. To delete your account and associated data, use the account deletion function in the Bean App (Settings, Account, Delete Account) or submit a deletion request using the contact methods described below.
Right to Opt Out of Sale or Sharing. Bean does not sell your personal information for monetary consideration, and we do not share your personal information for cross-context behavioral advertising. As such, there is no sale or sharing to opt out of. To the extent any future practice could be construed as a "sale" or "sharing" under applicable law, we will provide notice and an opt-out mechanism before engaging in such activity.
Right to Limit Use and Disclosure of Sensitive Personal Information. You have the right to direct us to limit the use and disclosure of your sensitive personal information to only those uses that are necessary to provide the Bean Services and as otherwise permitted by applicable law. You may exercise this right through the Bean App (Settings, Privacy, Limit Use of Sensitive Data) or by contacting us using the methods described below.
Right to Data Portability. You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format. Data export is available through the Bean App (Settings, Privacy, Export My Data). Exported data includes sensor data, derived metrics, account information, and other personal data in commonly used file formats such as CSV and JSON.
Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge different prices, provide a different quality of service, or suggest that you may receive a different price or quality of service as a result of exercising your rights.
Right to Appeal. If we deny your privacy rights request, you have the right to appeal our decision. Our denial response will include instructions for submitting an appeal. We will respond to your appeal within the time period required by applicable law.
Exercising Your Rights. To exercise any of the rights described above, you may use the self-service tools available in the Bean App (Settings, Privacy), email us at the website contact form, call our privacy toll-free line at [Toll-Free Number], or submit a request through our web portal at [www.bean.com/privacy-request].
To protect your data from unauthorized access, alteration, or deletion, we verify your identity before processing your request. Verification may involve confirming your name, email address, and other account details, or requiring you to log into your Bean account. If we are unable to verify your identity to a reasonable degree of certainty, we may deny your request.
You may designate an authorized agent to submit a request on your behalf. We may require the authorized agent to provide proof of their authorization from you and may require you to verify your identity directly with us before we process the request.
We aim to respond to verifiable requests within forty-five days. If additional time is required — up to an additional forty-five days where permitted by applicable law — we will notify you in writing of the reason for the extension and the expected response timeline.
16. CHILDREN'S PRIVACY
The Bean Services are not directed to children under the age of thirteen, and we do not knowingly collect personal information from children under thirteen without verified parental consent as required by the Children's Online Privacy Protection Act (COPPA) and related Federal Trade Commission rules. If we learn that we have collected personal information from a child under thirteen without verified parental consent, we will promptly delete that information. If you believe a child under thirteen has provided personal information to us, please contact us at the website contact form.
For children between the ages of thirteen and sixteen, certain data practices — such as the sale of personal information (which Bean does not engage in) or the use of sensitive personal information for purposes beyond the core Services — require the affirmative consent of the child under California law. Where applicable, we obtain such consent before collecting or processing data from users in this age range. In addition, social features that involve sharing personal information with other users are not available to users under the age of sixteen.
Parents or guardians who have consented to their child's use of the Bean Services may review the child's personal information, direct us to delete it, and refuse to permit further collection or use of the child's information by contacting us at the website contact form.
17. COOKIES AND TRACKING TECHNOLOGIES
17.1 Cookies and Similar Technologies
Our Site and App use cookies, web beacons, pixels, software development kits (SDKs), and similar tracking technologies to collect information about your browsing and interaction patterns. Cookies are small data files stored on your device that allow websites and applications to recognize your browser or device. We use both session cookies, which expire when your browser is closed, and persistent cookies, which remain stored on your device until they are deleted or expire. These technologies help us: remember your preferences and login state (strictly necessary cookies); analyze how you use our Site and App (analytics and performance cookies); deliver contextual advertising and measure campaign effectiveness (marketing cookies, where applicable); and provide enhanced functionality such as embedded videos and social sharing (functional cookies).
17.2 Your Cookie Choices
You may control cookies through your browser settings, where you can block, delete, or restrict cookies; through the cookie consent banner presented when you first visit our Site; and through your mobile device settings, where you can reset your advertising identifier or limit ad tracking. Disabling certain cookies may affect the functionality of our Site and Services.
17.3 Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) signal. Because there is currently no uniform industry standard governing the interpretation of DNT signals, our Site does not currently respond to DNT signals. However, we do honor the Global Privacy Control (GPC) signal as a valid consumer request to opt out of the sale or sharing of personal information under California law, to the extent GPC technology is enabled in your browser and recognized by our systems.
18. DATA SECURITY
We implement and maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information. Our security measures include: encryption in transit using Transport Layer Security (TLS) 1.2 or higher for all data transmitted between your Bean Device, the Bean App, and our servers; encryption at rest using AES-256 or equivalent encryption standards for sensitive data stored on our servers; role-based access controls with multi-factor authentication, restricting access to personal data to authorized personnel on a need-to-know basis, subject to regular access reviews; network security controls, including firewalls, intrusion detection and prevention systems, and distributed denial-of-service mitigation, supported by regular vulnerability scans and penetration testing; secure software development lifecycle practices, including code review, static and dynamic analysis, and regular security training for engineering staff; and a documented incident response plan. We will notify affected users and relevant regulatory authorities of any data breach as required by applicable law, including under the FTC Health Breach Notification Rule and applicable state data breach notification laws, including the Wyoming data breach notification statute (Wyo. Stat. Ann. Section 40-12-501 et seq.), where health data or personal identifying information is implicated.
No method of electronic storage or transmission is one hundred percent secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials and for taking reasonable precautions to protect your devices.
19. INTERNATIONAL DATA TRANSFERS
WearBean Inc., processes and stores your personal information on servers located in the United States. If you use the Bean Services from outside the United States, your personal information will be transferred to, processed, and stored in the United States, which may have data protection laws that differ from — and may be less protective than — the laws of your country of residence. By using the Bean Services, you acknowledge that your information may be transferred to and processed in jurisdictions outside of your place of residence.
20. CALIFORNIA-SPECIFIC DISCLOSURES
This section supplements the rest of this Privacy Policy and applies solely to California residents as required by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), and the California Online Privacy Protection Act (CalOPPA). These laws apply to Bean because we collect personal information from California residents, not because Bean is domiciled in California. Bean complies with the CCPA/CPRA regardless of its state of incorporation.
Under California Civil Code Section 1798.83 (California's "Shine the Light" law), California residents may request, once per calendar year, information regarding our disclosure of personal information to third parties for their direct marketing purposes during the preceding calendar year. Bean does not disclose personal information to third parties for their own direct marketing purposes.
In accordance with the CCPA/CPRA, we provide the following notice at collection regarding the categories of personal information we have collected in the preceding twelve months.
We collect identifiers — including your name, email address, IP address, device identifier, and account credentials — directly from you and automatically from your devices. These are used to provide the Services, communicate with you, promote safety and security, improve the Services, and for marketing purposes, and are disclosed to our service providers.
We collect personal information categories listed in the California Customer Records statute, including your name, contact information, and payment details, directly from you and from payment processors. These are used to provide the Services, process payments, and fulfill orders, and are disclosed to payment processors and service providers.
We collect characteristics of protected classifications, including your age and gender, directly from you. These are used to personalize insights and improve the accuracy of wellness metrics, and are disclosed to analytics service providers.
We collect commercial information, including your purchase history, directly from you and from payment processors. This is used to process orders, for accounting, and for customer support, and is disclosed to payment and accounting service providers.
We collect biometric information, including heart rate, heart rate variability, sleep data, skin temperature, respiratory rate, blood oxygen saturation, and other sensor-derived physiological measurements, from Bean Device sensors. This is used to provide the core Services, generate personalized wellness insights, improve our algorithms, and for research, and is disclosed only to cloud infrastructure service providers under strict contractual controls.
We collect internet or other electronic network activity information, including your App usage data and Site interaction data, automatically from your devices. This is used to improve the Services, for analytics, for security, and for marketing, and is disclosed to analytics and marketing service providers.
We collect geolocation data, both precise (GPS-based) and approximate (IP-based), from your paired mobile device and from your IP address. This is used for activity tracking, location-based features, and analytics, and is disclosed to cloud and mapping service providers.
We collect audio and similar information, including voice commands and support call recordings, directly from you. This is used for voice features, customer support, and to improve AI models, and is disclosed to AI, voice processing, and support service providers.
We collect inferences drawn from other personal information, including readiness scores, recovery scores, sleep quality scores, stress assessments, wellness trend predictions, and other derived metrics, generated by our systems from sensor and profile data. These are used to provide personalized insights and to improve our algorithms, and are disclosed only to cloud infrastructure service providers.
We collect sensitive personal information as defined under the CCPA/CPRA, including biometric data, health data, and precise geolocation data. These are used only to provide the core Bean Services, to ensure security and integrity, to comply with legal obligations, and for other permitted purposes, and are disclosed only to cloud infrastructure service providers under strict contractual controls. We do not use or disclose sensitive personal information for purposes of inferring characteristics about you beyond those necessary to provide the Services.
In the preceding twelve months, Bean has not sold personal information for monetary consideration and has not shared personal information for cross-context behavioral advertising. Bean does not use or disclose sensitive personal information for purposes other than those expressly permitted by the CCPA/CPRA. We retain each category of personal information for the period described in Section 14 (Data Retention). The criteria used to determine retention periods include the duration of your account, the purpose for which the data was collected, our legal obligations, and whether the data is needed to resolve disputes or enforce agreements.
Bean does not currently offer any financial incentive programs within the meaning of the CCPA. If we offer such programs in the future, we will provide a separate Notice of Financial Incentive describing the material terms of the program, how to opt in, and how to withdraw.
22. THIRD-PARTY LINKS AND SERVICES
The Bean Services may contain links to third-party websites, applications, and services that are not owned or controlled by WearBean Inc. This Privacy Policy does not apply to those third-party services. When you click a third-party link or authorize a third-party integration, we encourage you to review the privacy policy of that third party before providing any personal information or authorizing any data sharing. Bean is not responsible for the content, privacy practices, or data handling of third-party websites or services.
23. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the features of the Bean Services. When we make material changes, we will post the updated Privacy Policy on our Site and in the Bean App; update the "Effective Date" at the top of this Policy; and provide notice through the Bean App or via email to the address associated with your account at least thirty days before the changes take effect, where required by law. Your continued use of the Bean Services after the effective date of an updated Privacy Policy constitutes your acceptance of the updated terms, to the extent permitted by applicable law. If you do not agree with the updated policy, you may delete your account and discontinue use of the Bean Services.