SureFiz is a connected weight-management service built around the SureFiz® smart scale. To support your goals we handle personal and health-related information, including information that may be protected health information under HIPAA when you are enrolled by a healthcare provider. This policy explains what we collect, why we collect it, who we share it with, and the choices and rights you have. We do not sell, rent, or trade your personal information, and we do not use your health data for advertising.
Effective date: August 10, 2026 | Last modified: August 10, 2026
Published by Rasimo Systems, LLC ("Rasimo," "we," "us," "our"), developer and operator of the SureFiz platform and related services.
This Privacy Policy explains how we collect, use, disclose, and protect information when you visit surefiz.com, use the SureFiz or SureFiz Pro mobile applications, use the SureFiz web portal, or use the SureFiz smart scale (together, the "Services").
SureFiz is a scale-based service. The Services collect weight and body-composition measurements from the SureFiz smart scale and the information you enter yourself. They do not collect data from smart rings, blood pressure cuffs, glucose meters, or other clinical monitoring devices; those devices belong to our separate SureMediks platform, which is governed by its own privacy policy at suremediks.com/Privacy/user.
This Policy does not apply to the independent privacy practices of your healthcare provider, trainer, coach, employer, health plan, or any third-party website or application that we do not control. If you were enrolled by a healthcare provider, that provider's own Notice of Privacy Practices governs how the provider uses your health information.
Our role depends on how you reach us:
When you pair a SureFiz smart scale, we collect the measurements the scale produces. This may include:
Bluetooth and location permissions. Bluetooth is used solely to discover and communicate with your paired SureFiz scale. On some versions of Android, the operating system requires a location permission before an app is allowed to scan for nearby Bluetooth devices. We request that permission only to enable scale pairing and syncing. We do not collect, derive, store, or share your physical location, and we do not use Bluetooth or location permissions for advertising, profiling, or tracking of any kind.
The Services are intended for adults. We do not knowingly collect personal information from children under 13, and the consumer Services are not directed to individuals under 18. If a minor is enrolled in a program, that enrollment is made by the provider and a parent or legal guardian in accordance with applicable law. If you believe a child has provided us information without authorization, contact us and we will delete it.
We do not sell, rent, license, or trade your personal information. We do not use your health information for advertising or marketing to you on behalf of third parties, and we do not permit third parties to use it for their own purposes.
We share information only in these circumstances:
| Who | Why |
|---|---|
| Your trainer, coach, provider, or care team | To deliver and coordinate the program you enrolled in and to track your progress toward your goals. |
| Service providers (subprocessors) | Cloud hosting, database, and communications infrastructure that we use to run the Services. They act only on our instructions, are contractually restricted from using your information for their own purposes, and, where PHI is involved, are bound by a Business Associate Agreement. |
| People you designate | Family members, caregivers, or others you explicitly authorize. |
| Legal and safety | When required by law, subpoena, or lawful government request, or where necessary to protect the rights, safety, or property of you, us, or others, or to prevent or address a serious threat to health or safety. |
| Business transfer | In connection with a merger, acquisition, financing, or sale of assets, subject to the protections of this Policy and applicable law. We will notify you of any change in control of your information. |
If you grant access to Apple Health (HealthKit) or Google Health Connect:
We may de-identify or aggregate information derived from your data. Only after de-identification consistent with HIPAA or other applicable law may that information be used for product improvement, validation, research, and publications. We do not attempt to re-identify such information or permit others to do so. De-identified and aggregated information does not identify you and is not personal information.
We keep your information for as long as your account is active and for as long as needed to provide the Services. Where we hold PHI as a Business Associate, retention is governed by our agreement with your provider and by applicable medical-record retention laws, which may require records to be kept for a number of years after the last date of service. Backups, audit logs, and records we must retain for legal, tax, security, or regulatory reasons persist for their defined retention periods and are then deleted or de-identified.
You can request deletion of your SureFiz account and its data at any time:
When you confirm a deletion request we close your account immediately and stop all further collection and syncing of your data. Your profile, scale measurements, and associated health data are then permanently erased from our servers 30 days later. During those 30 days you can contact us to restore your account; after the 30 days have passed, deletion is permanent and we cannot recover it. We retain only information we are legally required to keep, and information that is part of a medical record held on behalf of your provider — that record is controlled by the provider and must be requested from them. Backup copies are purged on their normal rotation and are not restored into active use.
You can view and edit your profile and measurements in the app. If you are enrolled through a healthcare provider and want to access, amend, or restrict the medical record they hold, contact that provider directly; HIPAA gives you those rights against the Covered Entity, and we will support your provider in fulfilling them.
You can turn off Bluetooth, notifications, camera, photo, and health-data permissions in your device settings, and you can unsubscribe from non-essential email at any time. Some features will not function without the permissions they depend on. We may still send you transactional and safety-related messages about your account.
Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Texas, and others), you may have rights to know what personal information we hold, to obtain a copy, to correct it, to delete it, and to appeal a denial — and a right not to be discriminated against for exercising them. Note that information governed by HIPAA and information used in clinical research is generally exempt from these state laws; where an exemption applies we will tell you and direct you to the correct route. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. To make a request, contact us using Section 13; we will verify your identity before acting.
The Services are operated from the United States and your information is stored and processed there. Privacy laws in the United States may differ from those in your country. By using the Services you understand that your information will be transferred to and processed in the United States.
We maintain safeguards designed to align with the administrative, physical, and technical safeguard requirements of the HIPAA Security Rule, where applicable. These include encryption of data in transit (TLS) and at rest, salted password hashing, role-based access controls and least-privilege access, audit logging of access to health records, network segmentation and firewalling, monitoring, and periodic review of our controls.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Protect your own account by using a strong, unique password and keeping your device locked. If we discover a breach of unsecured protected health information or personal information, we will notify affected individuals, our provider customers, and regulators as required by HIPAA and applicable state law.
Our Services may link to sites we do not operate. We are not responsible for their content or privacy practices, and we encourage you to read their policies. Likewise, information you choose to disclose in a public forum, blog comment, or public profile area is visible to others and is not protected by this Policy.
We may update this Policy from time to time. We will revise the "Last modified" date above and, if the changes are material, provide additional notice through the Services or by email before they take effect. By continuing to use the Services after the effective date, you acknowledge the updated Policy to the extent permitted by applicable law.
Questions, privacy requests, or complaints:
Rasimo Systems, LLC
Attn: Privacy Officer
4801 Glenwood Avenue, Suite 200
Raleigh, NC 27612, USA
Email: info@rasimo.com
Phone: +1 919-457-1947 (Mon–Fri, 9:00 AM – 5:00 PM ET)
© 2026 Rasimo Systems, LLC. All rights reserved. Rasimo, SureMediks, SureFiz, and Realistic Intelligence® are marks of Rasimo Systems, LLC.