Thank you for choosing to join the Arena Strive program. We are humbled by the trust you have put in us to be your teammate and coach. You have the right to control your own data and can choose to have your information deleted at any point. The principles below describe how we steward this sacred information.

 

Arena aims to be your trusted teammate and coach.

We hold your data, help you understand how to use it to be better, and only share the parts of it externally that will make your work environment and your teammates better. No names. No specifics. Period. Arena Labs will only access your personal information when required to provide services or support. We do not monetize your personal information for any purpose. Our priority is establishing ourselves as a safe haven for your information so you can learn from it and grow.

 

To Be Better, You Need Data. 

At Arena, we believe strongly that your individual data is a critical component of better understanding yourself, your stress, your recovery, and ultimately, how to be a better clinician. In the end, that’s the path to better patient care.

 

To Be Smarter, Hospitals Need Data–But not Yours Individually!

Understanding when people are over-worked, under-rested, and being pushed too far is critical. Hospitals don’t have this data. At Arena, we provide it — without names or personally identifying information. We want your hospital to be smarter so they can take better care of clinicians, but we don’t provide them with your information.

1. Scope of This Policy

This Privacy Policy describes how Arena Labs, Inc. (“Arena Labs,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use the Arena Strive program, our mobile and web applications, our coaching services, and our website at arenalabs.co (collectively, the “Services”).

By using the Services, you agree to the collection and use of information in accordance with this Policy.

1.1 Data Controller

For purposes of applicable data protection laws, Arena Labs, Inc. is the data controller for personal information collected through the Services. While your hospital or employer may enroll you in the program, Arena Labs independently determines the purposes and means of processing your personal information. Your employer does not have access to your individual data (see Section 4.1).

2. Information We Collect

2.1 Information You Provide Directly

  • Account information — name, email address, employer/hospital affiliation, role, and credentials you provide when registering.
  • Profile and program inputs — self-reported wellness check-ins, journal entries, coaching session notes, goals, and feedback you submit through the Services.
  • Communications — messages you send to your coach, support requests, and survey responses.

2.2 Information from Your Employer

When your hospital or organization enrolls you in the Arena Strive program, they may provide us with your name, work email address, department, unit, role, and employment status. This information is a separate source of data from the information you provide directly. We use it solely to set up your account and associate you with the correct organizational group for aggregate reporting.

2.3 Information from Connected Devices and Wearables

With your permission, we collect biometric and behavioral data from wearable devices and health platforms you choose to connect (for example, heart rate variability, sleep stages, resting heart rate, activity, and recovery metrics). You control which devices to connect and may disconnect them at any time.

Biometric and sensitive data notice. The physiological data collected from wearable devices (such as heart rate variability, sleep stages, and recovery metrics) may be classified as biometric or sensitive personal information under applicable laws. We collect this data only with your explicit consent, apply additional safeguards including encryption at rest and in transit, and restrict access to authorized personnel. You may withdraw consent and disconnect your device at any time through the app settings.

2.4 Information Collected Automatically

  • Usage data — how you interact with the Services, features used, time spent, and in-app events.
  • Device and technical data — device type, operating system, app version, IP address, and crash logs.
  • Cookies and similar technologies on our website for essential functionality and analytics.
  • Analytics and monitoring providers — we currently use analytics and monitoring tools such as PostHog for product analytics, Sentry for application performance and error monitoring, and Metabase for internal reporting. We may also use other tools as our data architecture evolves. These providers may place cookies or collect device identifiers where needed to provide their services. We do not use advertising cookies or third-party ad trackers.

2.5 Information We Do Not Collect

We do not knowingly collect protected health information (PHI) governed by HIPAA, patient records, or any clinical data tied to the patients you care for. The Services are designed to support clinicians, not to process patient data.

3. How We Use Your Information

We use personal information to:

  • Provide, maintain, and improve the Services and your personalized Arena Strive experience.
  • Generate the insights, reflections, and coaching recommendations that are surfaced to you.
  • Communicate with you about your account, program updates, and support requests.
  • Produce de-identified, aggregated insights for your hospital or organization (see Section 4).
  • Conduct research and product development to improve clinician performance and well-being.
    • This may include use of de-identified, aggregated data in peer-reviewed research publications (such as our published study in JAMA Network Open) to advance the science of clinician well-being. Published research never contains individually identifiable information.
  • Detect, prevent, and address security incidents, fraud, or abuse.
  • Comply with legal obligations.

Automated processing. The Services use algorithms and machine learning to generate personalized insights, stress and recovery scores, and coaching recommendations based on your biometric and self-reported data. These automated outputs are designed to support (not replace) human coaching. Your Arena coach reviews and contextualizes automated recommendations. You may request human review of any automated output by contacting us.

We do not sell your personal information, and we do not use it for advertising or to train third-party AI models.

4. How We Share Your Information

4.1 With Your Hospital or Employer — De-Identified Only

We share aggregated, de-identified insights with your hospital or organization to help them understand workforce trends such as fatigue, recovery, and stress at the team or unit level. These reports never include your name, contact information, or any data that could reasonably be used to re-identify you.

Our de-identification process follows the HIPAA Safe Harbor method, removing all 18 categories of identifiers. We enforce minimum group sizes for aggregate reporting so that individual patterns cannot be inferred from small teams. We do not provide per-individual data to employers under any circumstances, including in response to employer requests.

4.2 With Your Arena Coach

If you participate in coaching, your assigned Arena coach has access to the information needed to support you. Coaches are bound by confidentiality obligations.

4.3 With Service Providers

We share information with vendors who help us operate the Services — for example, cloud hosting, analytics, customer support tools, and email delivery. These vendors are bound by contracts that require them to protect your information and use it only for the services they provide to us.

A current list of our sub-processors is available upon request. We will notify enterprise customers of material sub-processor changes in advance where required by contract or applicable law.

4.4 Business Transfers

If Arena Labs is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you and any successor will be bound by the commitments in this Policy.

5. Your Rights and Choices

You have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate or out of date.
  • Delete your account and associated personal information.
  • Export a copy of your data in a portable format.
  • Withdraw consent for connected devices or specific processing at any time.
  • Opt out of non-essential communications.

To exercise any of these rights, contact us using the details in Section 12.

Additional Rights by Jurisdiction

California residents (CCPA/CPRA)

You have the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale or sharing of personal information. Arena Labs does not sell your personal information. To submit a request, email help@arenalabs.global with “California Privacy Request” in the subject line. We will verify your identity and respond within 45 days.

Washington state residents

Under the My Health My Data Act, health data (including biometric data from wearables) receives additional protections. We collect such data only with your consent and do not sell, share, or use it for advertising.

European users (GDPR)

Arena Labs acts as the data controller. Our legal bases for processing are: (a) contract performance for the Strive experience; (b) explicit consent for biometric data; (c) legitimate interests for research, product improvement, and security; and (d) legal obligation. You have additional rights to data portability, restriction of processing, and to lodge a complaint with your local data protection authority.

Other jurisdictions

We comply with applicable local data protection laws. Contact us with questions about your specific rights.

Account Deletion

To comply with app store privacy policies, you can request deletion of your data at any time by emailing help@arenalabs.global. We will confirm receipt and complete the deletion within 30 days, retaining only what we are legally required to keep.

help@arenalabs.global

6. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Services. Specific retention periods:

  • Biometric and wearable data — deleted or de-identified within 30 days of account deletion or device disconnection.
  • Account and profile information — deleted within 30 days of account deletion, except as required below.
  • De-identified, aggregated data — retained indefinitely, as it cannot be linked back to you.
  • Legal and compliance records — retained as required by applicable law (typically 3 to 7 years for financial and tax records).

To determine appropriate retention periods, we consider the sensitivity of the data, the purposes for which it was collected, and applicable legal requirements.

7. Data Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, access controls, audit logging, and regular security reviews. No system is perfectly secure, but we work hard to keep your data safe and to notify you in the unlikely event of a breach affecting your personal information.

8. International Users

Arena Labs is based in the United States, and your information is processed and stored in the U.S. If you access the Services from outside the U.S., you understand that your information will be transferred to, processed in, and stored in the United States.

Where we transfer personal information from Europe or other jurisdictions with data transfer restrictions, we rely on appropriate safeguards including the EU-U.S. Data Privacy Framework, Standard Contractual Clauses approved by the European Commission, or other mechanisms permitted under applicable law. You may contact us for information about the specific safeguards applied to your data transfer.

9. What Happens When You Leave Your Employer

If you leave the hospital or organization that enrolled you, your Arena Strive account and personal data remain yours. Your former employer will not be notified of your departure through our Services and will not have access to your individual information at any point. You may continue using the Services if available, request a full data export, or delete your account. Aggregate, de-identified data that was included in organizational reports prior to your departure remains part of those historical reports but cannot be traced back to you.

10. Children’s Privacy

The Services are intended for adult clinicians and healthcare professionals. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top and, for material changes, provide additional notice (such as in-app or by email). Your continued use of the Services after a change becomes effective indicates your acceptance of the updated Policy.