← Legal

HealthyWell Privacy Policy

Effective: October 21, 2025

This Privacy Policy explains how the HealthyWell iOS application (the "App") handles information. HealthyWell is designed to work primarily on-device for speed and privacy. The App does not create user accounts, does not track you across apps or websites, and does not show ads.

If you have questions, contact us at: contact@ejorgensen.com

Who We Are

Controller. HealthyWell is provided by [Full Legal Entity Name], [full mailing address]. Contact: contact@ejorgensen.com

EEA/UK representative (if applicable). If we are not established in the EEA or UK and offer the App there, our representative under GDPR Art. 27 is [Name, address, email].

Summary

  • No account and no login.
  • No advertising, SDK-based tracking, or cross-app tracking; we do not request App Tracking Transparency (ATT) permission.
  • On-device storage of your activity status and preferences using Apple's iOS storage.
  • Optional local notifications for timers (no push tokens, no remote notifications).
  • Optional Apple Health integration (read-only of workouts) to help auto-complete Cardio and Resistance activities. Health data stays on your device and is not transmitted to our servers.
  • Read-only requests to Supabase to download public content (recommendations and daily inspiration). Your IP address and basic device/network metadata may be seen by that service as part of normal internet traffic.
  • Subscriptions and purchases are processed by Apple; we do not receive your payment details.

Information We Handle

On-Device Data (stored locally on your iPhone)

The App stores the following data on your device using Apple's iOS storage mechanisms (e.g., UserDefaults):

  • Daily activity list and status (completed, skipped, pending), by day.
  • Weekly targets you set for each activity (e.g., days per week, sleep hours, water liters).
  • Hidden/visible activity preferences.
  • Streak count and the last date of a fully-met week.
  • Small UI preferences (e.g., whether the inspiration banner is collapsed, whether onboarding has been seen, acceptance of Terms).
  • End timestamps for active timers so a local notification can fire if the App is backgrounded.
  • Subscription status necessary to enable paid features on your device.

We do not upload or sync this information to our servers.

Apple Health (optional; read-only)

If you grant permission, the App reads certain Apple Health workout data to help auto-complete Cardio and Resistance activities.

  • Scope: Read-only access to relevant workout summaries; we do not write data to Apple Health.
  • Purpose: To suggest or auto-mark applicable activities as complete and to show "Today from Apple Health" summaries.
  • Storage/Sharing: Health data is used on-device and is not transmitted to our servers. We do not use Health data for advertising or marketing.

We request granular HealthKit permissions only for the specific data types you choose. We do not use Health data for advertising or marketing, do not sell it, and do not store personal health information in iCloud. You can revoke access at any time in Settings → Health → Data Access & Devices.

Network Requests (read-only)

The App makes read-only requests to our Supabase project to fetch public content (e.g., recommendations, daily inspiration). We do not append identifiers to these requests. Like any internet request, our vendor may receive your IP address, timestamps, and standard device/OS metadata for delivery and security. We treat Supabase as our processor, and we have a Data Processing Addendum in place that includes Standard Contractual Clauses for international transfers. We instruct our vendor not to retain logs longer than necessary.

App Store Privacy Label

Apple's rules require disclosure of data "collected" from your app, including via third-party code; processing solely on-device is not "collected." If our vendor does not retain IP address after servicing the request, we will indicate "Data Not Collected." If limited retention is necessary, we will disclose the appropriate data types and mark the use as App Functionality/Security only.

Subscriptions and Purchases

Auto-renewing subscriptions are processed by Apple via in-app purchase. Purchases are processed by Apple; we don't receive your card details. We process receipt status on-device solely to enable your local features. Apple's privacy practices apply to your transactions with Apple.

Notifications

If you enable notifications, the App schedules local notifications on your device to alert you when a timer ends. No notification tokens are created or transmitted to any server, and we do not use remote push notifications.

Audio

The App plays included audio files to signal timer events. The App does not access your microphone and does not record audio.

Diagnostics and Analytics

We do not integrate third-party analytics SDKs. Apple and service providers may receive standard device or network metadata as part of normal operation and their own system logs.

Retention

  • On-device data: Remains until you delete it or uninstall the App.
  • Support emails: Retained for up to 24 months (or shorter where required) and then deleted or archived.
  • Network/security logs (processor): Configured for minimal retention necessary to ensure service integrity and detect abuse.

What We Don't Collect

  • No name, email, phone number, or contact list (except if you email us directly for support).
  • No precise location.
  • No photos, camera, microphone input, or user files.
  • No advertising identifiers or cross-app tracking identifiers.
  • No HealthKit data unless you explicitly grant read permission, and we do not transmit Health data to our servers.

How You Can Control Your Data

  • Delete on-device data: Delete the App from your device to remove locally stored data.
  • Adjust notifications: iOS Settings → Notifications → HealthyWell.
  • Adjust Health access: iOS Settings → Health → Data Access & Devices → HealthyWell.
  • Adjust activity visibility and targets: Use in-App settings for each activity.

Data Sharing and Sale

We do not sell your personal information. We do not share your on-device data with third parties. The third parties contacted by the App are:

  • Apple (for App Store purchases/receipts and system services).
  • Supabase (for read-only public content), which receives standard network metadata as described above.

Children's Privacy

HealthyWell is not directed to children under 13 and does not knowingly collect personal information from children. If you believe a child provided us with personal information, contact us to request deletion.

For the UK/EEA, we also consider the Age-Appropriate Design Code; if your use of the App is likely to involve children, our defaults and notices are designed for a high level of privacy.

International Transfers

Where your data goes. Network requests to Apple and our processor (Supabase) may be handled in the United States or other regions. For EEA/UK users, transfers rely on:

  • Standard Contractual Clauses (SCCs) in our DPA with Supabase; and
  • Apple's transfer safeguards and participation in recognized transfer frameworks where applicable.

Legal Bases (EEA/UK)

  • Contract (Art. 6(1)(b) GDPR) to deliver core features you request.
  • Legitimate interests (Art. 6(1)(f) GDPR) for essential, minimal network traffic.
  • Consent (Art. 6(1)(a) & 9(2)(a) GDPR) for HealthKit access; you can withdraw consent at any time.

We do not perform profiling or automated decision-making.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, port, and object/restrict processing. Because we don't maintain server-side profiles, most information is stored only on your device.

  • EEA/UK: You may also withdraw consent and lodge a complaint with your supervisory authority.
  • US states: You may request access/deletion and opt out of sale/sharing/targeted advertising (we do not sell/share or use targeted ads). We respond within 45 days where required.

For questions or requests, contact us at contact@ejorgensen.com.

Data Security

On-device data is stored using iOS storage mechanisms and protected by iOS Data Protection. HealthKit data remains in the Health database unless you authorize access. We do not export Health data off-device. No method of transmission or storage is perfectly secure.

Email and Support

If you email us, we receive your email address and any information you include in your message. We use this information only to respond and maintain support records as needed, then retain or delete them consistent with operational needs and legal requirements.

Changes to This Policy

If we make material changes, we will notify you in-app (and on our website, if applicable) with at least 30 days' notice before they take effect. Changes apply prospectively.

Contact

If you have questions or requests regarding this policy, contact: contact@ejorgensen.com