Effective: Sep 17, 2026
The short version
We built EnergyPoints to help people manage cancer-related fatigue, sleep problems and quality of life. Here is what matters most, in plain language. The full detail follows.
- We do not sell your information. Not to anyone, not ever, under any definition.
- We do not use your data to train AI models.
- You choose whether to connect a wearable. The app works without it. If you connect one, we read sleep, activity, and heart-related data, as listed in Section 3. Connecting is optional.
- You can close your account in the app, on the contact form, or by email. We start within 45 days. Section 9 says what is removed right away and what waits.
- If you are in our clinical trial, the consent form you signed governs, and your study data is protected by a federal Certificate of Confidentiality.
- We are not a HIPAA covered entity. We hold ourselves to HIPAA Security Rule standards anyway. Section 8 explains why we would rather say that than let you assume otherwise.
- The community feed is peer support, not medical care, and it is not monitored in real time. If you are in crisis, call or text 988, or dial 911.
Two companion documents: our Subprocessor List names every company that handles data for us, and our Washington Consumer Health Data Privacy Policy covers rights specific to Washington residents.
1. Who we are and what this covers
5 Point App, Inc. (“5 Point App,” “EnergyPoints,” “we,” “us,” “our”) operates:
- The EnergyPoints app, on the App Store and Google Play.
- The EnergyPoints research app, a private, invitation-only version for participants enrolled in our clinical trial.
- Our website, energypointsapp.com.
We are a small company. This policy is written to be read. If anything is unclear, write to privacy@5pointapp.com and a person will answer you.
If you are enrolled in our clinical trial, the informed consent document you signed governs your participation. Where this policy and that document differ, your consent document controls. Section 5 explains what that means.
2. What we collect
You give us: your name, email address, phone number (optional), date of birth, country, ZIP or postal code, anything you post in the community feed, and anything you write to us.
We collect as you use the app: which acupressure rituals you start and finish and when, your answers to in-app symptom and wellbeing questions, device and app information, IP address, and general usage activity. Our website uses cookies to work and to understand how it is used. We do not use advertising cookies or advertising identifiers in the app.
With your permission, from a connected health account: your sleep data and your activity data and heart-related measurements.
We do not ask for your Social Security number, your government ID, your financial account details, or your payment card. We do not need them and we do not want them.
3. Health data we access
We do NOT use Google user data for advertising, credit or lending decisions, sale to data brokers, building marketing profiles, creating unrelated databases, or to develop, improve, or train generalized / non-personalized AI or ML models.
Google Health (optional)
This part is handled under rules that apply only to Google user data. If you connect a Google account, we request only these read-only scopes, on both the research project (qualified-smile-499223-k5) and the public project (energypoints-public-499123):
- https://www.googleapis.com/auth/googlehealth.sleep.readonly
- https://www.googleapis.com/auth/googlehealth.activity_and_fitness.readonly
- https://www.googleapis.com/auth/googlehealth.health_metrics_and_measurements.readonly
Sleep, activity, and heart-related measurements. We do not request write access, email, contacts, calendar, files, location history, or anything else in your Google account. We do not run a live Google Fit connect. Old Google Fit names in the app are leftover only.
Fitbit (optional) – not Google data
If you connect Fitbit, we request activity, heartrate, sleep, and settings. We use activity, sleep, and heart rate in the app. Settings is required for the Fitbit link to work. We reject the connection if any of those four is missing.
Apple Health (optional, iPhone) – not Google data
If you allow it, we read sleep, steps, calories, distance, flights climbed, exercise time, stand time, heart rate, and heart-rate variability. We do not write to Apple Health.
How we store it
In the United States, on Amazon Web Services. Our application runs on AWS Lambda with a MySQL database, and credentials are held in AWS Secrets Manager.
Encryption. Data is encrypted in transit using TLS 1.2 or higher. The access and refresh tokens that connect us to your health account are encrypted at rest using AES-256. The production MySQL databases are encrypted at rest with AWS KMS. Files we store in Amazon S3, including profile photos, are encrypted at rest.
Who can see it
Members of the engineering and privacy teams who need it to operate the service: Research Engagement Coordinators, the developers who maintain the system, and our Security and Privacy Officer. Admin sign-in uses a password plus a one-time code sent to email.
No human at EnergyPoints reads your Google user data except:
- where necessary for security (investigating abuse or a suspected breach),
- to comply with applicable law,
- with your affirmative, express consent for a specific view of that data.
Who we share it with
Only the service providers on our Subprocessor List, and only to the extent they need it to provide the service.
We do not sell your Google user data. We do not share it for advertising. We do not transfer it to determine creditworthiness or for lending. We do not send your Google user data to any AI model, including the models that screen posts or draft ZenAI messages. We do not use it to train a model. We do not permit anyone else to use it to train a model.
How long we keep it, and how it is deleted
See Section 9 for retention. To delete it: disconnect your health account in the app, which stops anything further reaching us, then use any of the deletion routes in Section 9.
Limited Use
4. Cookies
Our website uses cookies to make the site work and to understand how it is used. You can control them in your browser. Turning off non-essential cookies will not break the site.
5. Health data and the clinical trial
EnergyPoints runs a decentralized clinical trial funded by the National Institutes of Health (grant 5R44CA297977) under IRB protocol IRB_00182341.
If you are enrolled as a participant, three things are true that are not true for other users.
Your informed consent document governs. It describes what is collected, how it is used, who sees it and how long it is kept, in more detail than this policy. Where the two differ, the consent document controls. If you no longer have your copy, ask the study team.
Your study data is protected by a Certificate of Confidentiality, issued automatically under 42 U.S.C. 241(d). Federal law prohibits us from disclosing identifiable, sensitive information about you to anyone not connected with the research, including in response to most subpoenas and legal demands. Three narrow exceptions: where another federal, state or local law requires disclosure; where it is necessary for your medical treatment and you gave prior written consent; or where you consent to the disclosure yourself.
Your study data is held in our research systems, which are separate from the public app. The two are separate applications, and moving from one to the other happens deliberately, with the study team, at the end of your participation.
Withdrawing is always your right and does not affect your care. Ask the study team. Data already collected and analyzed may not be removable from the study record; your consent document explains what happens.
6. The community feed
The feed lets people using EnergyPoints share experiences with each other.
The community feed is peer support. It is not medical advice, it is not care, and it is not monitored in real time. It is not an emergency service.
If you are in crisis, or thinking about harming yourself, call or text 988 (the Suicide and Crisis Lifeline) or dial 911. Do not post and wait.
What is public. Anything you post can be seen by other people using EnergyPoints. Please do not post anything you would not want another person to read, and please do not post other people’s health information.
Automated screening (research app only). In the research app, posts and comments are screened by an Amazon Bedrock model (Claude) running in our own AWS Lambda in the United States. The prompt contains the post or comment text and a small amount of nearby community text. It does not contain sleep, activity, heart rate, or other wearable data. Anything the model flags is held for a person to review, and a moderator clears that queue twice each weekday. The public app does not use this screening.
ZenAI (research app). ZenAI is a bot that can draft community posts. Those drafts are written by Claude on Amazon Bedrock in the same AWS account, then reviewed by a person before they go out. The prompt can include the group name, the thread text, and display names. It does not include wearable data. The in-app Zen Energy videos are a separate character. They do not call a model.
AI-assisted content. Some educational posts and comments are drafted with the help of an AI assistant. A person at EnergyPoints reviews and approves every one before it appears. Nothing written by the assistant publishes automatically.
Moderation. We may remove content and suspend accounts at our discretion. We review reports as resources permit. We do not promise a response time.
7. Who we share information with
Only in the situations below. We do not sell it.
Service providers, named individually on our Subprocessor List, under contracts requiring them to protect the information and use it only to perform the service.
The research team. If you are a study participant, your study data is shared with the investigators and staff named in your consent document, subject to the Certificate of Confidentiality.
When the law requires it, subject to the Certificate of Confidentiality where it applies.
To protect people, where we believe in good faith it is necessary to prevent serious harm.
In a business transfer. If the company is acquired or merges, information may transfer. Any acquirer remains bound by the commitments in this policy for information collected under it.
We do not share your information with advertisers, data brokers or social media platforms for their own purposes. We do not use advertising pixels or tracking tags that transmit your health information to third parties.
8. Security
We maintain administrative, technical and physical safeguards aligned to the HIPAA Security Rule: encryption in transit, access controls, secrets management, multi-factor authentication on administrative access, and periodic independent security assessment.
Our application is undergoing a Cloud Application Security Assessment (CASA) at Assurance Level 1 through the App Defense Alliance, performed by an independent authorized laboratory. We have also completed an independent HIPAA Security Risk Assessment.
An honest statement about what that does and does not mean. We are not a HIPAA covered entity, and we are not a HIPAA business associate in our direct relationship with you. We do not bill insurance and we do not conduct HIPAA standard transactions. We hold ourselves to HIPAA Security Rule standards because your health information deserves that level of care, not because a regulator requires it of us here. We would rather say that plainly than let you assume a legal protection that does not apply.
No system is perfectly secure and we will not claim otherwise. If we discover a breach affecting your information, we will notify you as required by law.
9. How long we keep things, and how to delete them
Retention
| What | How long | Clock starts |
| Sleep, activity, and heart data from a connected account | 90 days after account closure, then deleted | Account closure |
| Account information | 90 days after account closure, then the anonymized row is purged | Account closure |
| Community posts | Until you delete the post, or 90 days after account closure | Deletion request or account closure |
| Clinical trial data | As required by the study protocol, your consent document, and federal research record rules, which extend past the end of the study | End of study |
Deletion
Three routes, all of which work:
- In the app. Close your account from your settings. It requires you to confirm your password and signs you out of every device.
- On the web. Use the request form at https://energypointsapp.com/contact and say that you are making a privacy or deletion request.
- By email. Write to privacy@5pointapp.com.
We will confirm who you are. We then disconnect your tracker, remove your name, email, phone, and profile photos, and sign you out. Sleep and activity records and community posts may remain until we complete the purge in the retention table above. We will finish what we can, and ask our service providers to delete what they hold, within 45 days. If we need more time we will tell you why and take no more than 45 additional days.
Two honest limits. Clinical trial data already collected under your informed consent may need to be kept under federal research rules, and your consent document explains that. And information already published in the community feed may persist in other people’s screens or copies in ways we cannot reach.
Automated MySQL backups are kept for 35 days and then expire. A deletion may remain in those backups until they expire. We do not keep old versions of files in S3. When we delete a profile photo, that object is removed.
10. Your rights and choices
Everyone, wherever you live: ask what we hold, ask us to correct it, ask us to delete it, get a portable copy, disconnect a health account at any time, close your account.
Email privacy@5pointapp.com, or use the contact form at https://energypointsapp.com/contact and say you are making a privacy request.
We verify identity before acting, respond within 45 days, and will not treat you differently for exercising any of these rights.
California
Under the CCPA as amended, California residents have the rights to know, delete, correct and opt out.
Categories we collect: identifiers; personal information listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)); protected classification characteristics; health and medical information; biometric information, which is the category covering sleep, health and exercise data; internet or other network activity; and coarse geolocation from your zip code, not GPS.
Sale and sharing. We do not sell personal information. We have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising. The CCPA gives you the right to opt out of sale and sharing. That right exists whether or not a business sells, and yours is preserved. There is simply nothing here to opt out of.
Sensitive personal information. We collect health information, which is sensitive personal information under the CCPA. We use it only to provide the service you asked for and, for study participants only, as described in your clinical trial consent (Section 5). That is not a separate use of Google user data from the public app. We do not use or disclose it for any purpose that would trigger your right to limit its use.
Washington, Nevada and Connecticut
Washington residents have additional rights over consumer health data. Those are covered in our separate Washington Consumer Health Data Privacy Policy, as Washington law requires. Nevada and Connecticut residents have comparable rights over consumer health data and can use the same contact routes above.
Maryland
The Maryland Online Data Privacy Act prohibits the sale of sensitive data, including health data, outright. We do not sell it.
Other states
Residents of other states with comprehensive privacy laws in effect have rights to access, correct, delete and obtain a portable copy, and to appeal a denied request. Use the contacts above and tell us which state you live in.
Outside the United States
Our service is directed to users in the United States. If you contact us from elsewhere, we will handle your request under the rights described above.
11. Children
EnergyPoints is intended for people aged 18 and older. If you say you are under 18, we ask for a parent or guardian email. We do not currently verify that consent. We do not permit children under 13 to use the Service. If you believe a child under 13 has given us information, write to privacy@5pointapp.com and we will delete it.
12. Changes to this policy
If we change this policy we will update the effective date and, where the change is significant, tell you in the app or by email before it takes effect. We will not apply a materially different use to information we already hold without your consent.
Version history
| Effective | What changed |
|---|---|
Sep 17, 2026 | Clarified Limited Use for Google user data: use limited to providing or improving EnergyPoints’ user-facing features only. Removed clinical-trial analysis as a stated use of Google user data for the public app; research use (if any) is scoped to the research app, informed consent, and Google’s Health Research requirements. Tightened the human-read exceptions. Added an explicit statement that Google user data (including aggregated, anonymized, de-identified, or derived data) is not used to develop, improve, or train non-personalized AI/ML models. |
Sep 13, 2026 | Full rewrite. Added a dedicated Google user data section and Limited Use commitment. Corrected the sale disclosure. Corrected the collected-categories list. Set a 45-day deletion window. Published a subprocessor list. Split out a Washington consumer health data policy. |
Dec 29, 2021 | Prior published version |
13. Contact
5 Point App, Inc.
37 W. 20th St.
Suite 607
New York, NY 10011
https://energypointsapp.com/contact
If you are a study participant with a question about the research rather than the app, contact the study team using the details in your consent document.