Privacy Policy - Wellnest

    Last updated: September 13, 2026

    Privacy Policy

    Effective Date: September 13, 2026 Last Updated: September 13, 2026 (Note: Previous versions of this Privacy Policy are available upon request.)

    SUMMARY OF KEY POINTS

      At a Glance:
    • What personal information do we collect? We collect your account details (name, email), daily wellness metrics (mood, energy), social interactions within the app (posts, reactions), your subscription status if you buy Wellnest Plus, and, with your explicit permission, health data from Apple Health on iPhone or Health Connect on Android (steps, sleep, workouts).
    • Do we process any sensitive personal information? Yes. Your health data and wellness metrics are considered sensitive personal information. We treat this data with the highest level of security and never use it for advertising.
    • Do we collect information from third parties? Yes, we receive authentication information from Google (Firebase and Google Sign-In) or Apple when you sign in, health metrics from Apple HealthKit or Health Connect if you choose to connect them, and purchase confirmations from the App Store or Google Play if you subscribe.
    • How do we use your information? We use your data solely to provide the Wellnest service: calculating your daily "rhythm" score, sharing your updates with the specific circles you choose, and unlocking Wellnest Plus when you subscribe.
    • Who do we share your personal information with? We share your data only with essential service providers (like our hosting, authentication, notification and subscription partners) and the family or friend circles you explicitly join. We never sell your personal data.
    • What are your privacy rights? You have the right to access, correct, delete, and port your data, as well as the right to withdraw your consent for health data access at any time.
    • How can you contact us? You can reach our privacy team anytime at privacy@usewellnest.com.

    ---

    1. INTRODUCTION

    Welcome to Wellnest, built by BITROVA LABS LTD. We created Wellnest to help small circles of family and friends stay connected through a shared focus on well-being. Because our app handles deeply personal information, from your daily mood to your sleep patterns, we believe our privacy practices must be as healthy and transparent as the habits we help you build.

    This Privacy Policy explains how we collect, use, and protect your personal information when you use the Wellnest apps for iOS and Android. We have written this document to be clear and direct, avoiding heavy legal jargon wherever possible. Our core philosophy is simple: your data belongs to you. Nothing is public, sharing is strictly controlled by you on a per-circle and per-category basis, and your health data is never used for advertising, never shared with analytics providers, and never sold.

    If you have any questions about this policy or how we handle your data, please reach out to us at privacy@usewellnest.com.

    2. WHAT WE COLLECT & WHY

    To provide you with a meaningful daily "rhythm" score based on our five pillars (movement, rest, mind, mood, and staying in touch), we need to process certain information. We organize this data based on how we receive it.

    Information You Give Us Directly

    When you set up and use Wellnest, you actively provide us with information. We collect this data to fulfill our contract with you (providing the app's core features) and based on your explicit consent.
  1. Account Details: Your email address (or Apple private relay address), display name, chosen avatar or profile photo, and time zone. We need this to create your account and ensure your daily rhythm score resets at the right time.
  2. Wellness Inputs: Manually entered daily metrics, daily mood and energy check-ins, and any optional notes you add.
  3. Social Interactions: Posts, photos, reactions, comments, nudges, circle memberships, and challenge participation. We process this so you can interact with your chosen circles.
  4. Information Collected Automatically

    When you use our app, our servers automatically record certain technical information. We collect this based on our legitimate interest in keeping our service secure and functional.
  5. Device & Connection Data: Your push notification device token (so we can send you nudges and updates) and server request logs, which include the time of your request, the endpoint accessed, and the response code.
  6. Information from Third Parties

    With your explicit permission, we connect with third-party services to seamlessly build your rhythm score. We process this data strictly based on your consent, or to fulfill our contract with you where you buy a subscription.
  7. Apple Health Data (iPhone): If you grant us permission via Apple HealthKit, we read your step count, exercise minutes, workouts, sleep duration, bedtime, and mindful minutes. We also write back meditation sessions and manually logged workouts to your Apple Health app.
  8. Health Connect Data (Android): If you grant us permission via Health Connect, we read your steps, exercise sessions, sleep sessions, and mindfulness sessions. We also write back meditation sessions and manually logged workouts to Health Connect. We use Health Connect data only to show and score your day in Wellnest, in line with the Health Connect Permissions policy.
  9. Authentication Data: We use Firebase Authentication (provided by Google), Sign in with Apple, and Google Sign-In on Android to securely sign you in. We receive basic profile identifiers to verify your identity.
  10. Subscription Data: If you subscribe to Wellnest Plus, payment is handled entirely by the Apple App Store or Google Play. We never receive your card or bank details. Through our subscription provider RevenueCat, we receive your subscription plan, status, trial, renewal and expiry dates, and store transaction identifiers, linked to your Wellnest account ID.
  11. 3. HOW WE USE YOUR INFORMATION

    We are highly intentional about how we use your data. Every piece of information we collect serves a specific purpose in making Wellnest work for you.

  12. Core Service Delivery (Contract): We use your health data and manual inputs to calculate your daily rhythm score. We use your social data to display your day's summary to the specific circles you have joined, respecting your per-category sharing switches.
  13. Subscriptions (Contract): We use your subscription status to unlock Wellnest Plus features on your devices and to restore your purchase when you sign in on a new device.
  14. Service Improvement (Legitimate Interest): We analyze server request logs to troubleshoot bugs, monitor app performance, and ensure our API runs smoothly.
  15. Communication (Contract & Consent): We use your device token to send push notifications for circle challenges, nudges from friends, and important account updates.
  16. Security and Fraud Prevention (Legitimate Interest): We use authentication tokens and server logs to verify that every API request is legitimate and to protect your account from unauthorized access.
  17. Legal Compliance (Legal Obligation): We may process your information if required to comply with applicable laws or regulations, including tax and accounting rules for purchases.
  18. What We Don't Do: We never use your health data for marketing or advertising. We never share your health data with analytics providers or subscription providers. We never sell your personal information to anyone.

    4. WHEN WE SHARE YOUR INFORMATION

    Because Wellnest is designed for private circles, your data is inherently shielded from the public. However, to operate our service, we do share information in a few strictly limited scenarios.

  19. Your Chosen Circles: Your daily summaries, posts, and reactions are shared with the specific family and friend circles you join. You control exactly what categories of data are shared with each circle using our in-app switches.
  20. Essential Service Providers: We share necessary technical data with trusted infrastructure partners who help us run the app: Vultr (hosting for our API and database in the United States), Google (Firebase Authentication, Google Sign-In, and Firebase Cloud Messaging for Android notifications), Apple (Sign in with Apple and push notifications), RevenueCat (subscription management), the Apple App Store and Google Play (subscription payments), and Cloudflare (domain name services and forwarding of emails you send to our support and privacy addresses). These providers are legally bound to protect your data and can only use it to provide services to us.
  21. Legal Requirements: We will share information if we are legally required to do so by a valid court order, subpoena, or similar legal process.
  22. Business Transitions: If BITROVA LABS LTD is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.
  23. 5. YOUR PRIVACY RIGHTS

    Depending on where you live (including under the GDPR, UK GDPR, and CCPA/CPRA), you have fundamental rights regarding your personal data. We extend these rights to all our users globally.

  24. Right to Access: You can request a copy of the personal data we hold about you.
  25. Right to Correction: You can update your display name, avatar, and time zone directly in the app. If you need to correct other data, contact us.
  26. Right to Deletion: You can delete your account at any time directly within the Wellnest app. Doing so immediately removes your profile, health data, posts, reactions, memberships, and device tokens from our active database. Deleting your account does not cancel a subscription; cancel it in your App Store or Google Play settings.
  27. Right to Data Portability: You can request a copy of your data in a structured, commonly used, and machine-readable format.
  28. Right to Withdraw Consent: You can revoke our access to your health data at any time in the Health app on iPhone or in Health Connect settings on Android. This will not affect the lawfulness of our processing before you withdrew consent.
  29. Right to Opt-Out: While we do not sell your data or use it for targeted advertising, you have the right to opt out of any future marketing communications we might send.
  30. To exercise any of these rights, please email privacy@usewellnest.com. We aim to respond to all requests within 30 days.

    6. DATA SECURITY

    We take the security of your intimate wellness data seriously and have built Wellnest with privacy-by-design principles.

  31. Our Security Measures: All traffic between your app and our servers is encrypted using TLS. We use encryption at rest for our Postgres database and all backups. Furthermore, we enforce Firebase ID token verification on every single API request to ensure only authorized users can access their data.
  32. Your Controls: We provide granular, per-circle sharing controls with per-category switches, meaning you always dictate who sees what.
  33. Inherent Limitations: While we use industry-standard security practices, no system is 100% secure. We cannot guarantee absolute security against highly sophisticated cyberattacks.
  34. Your Responsibility: Please protect your Apple ID, Google account and email accounts with strong passwords and two-factor authentication, as these control access to your Wellnest account.
  35. Breach Notification: In the unlikely event of a data breach that compromises your personal information, we will notify you and the relevant authorities within the timeframes required by law (typically within 72 hours).
  36. 7. DATA RETENTION

    We keep your data only for as long as you need our service. Our retention schedules are designed to minimize the data we hold.

  37. Active Account Data: We retain your profile, wellness metrics, and social interactions for as long as your account exists.
  38. Account Deletion: When you delete your account in the app, your profile, health data, posts, reactions, memberships, and device tokens are deleted immediately from our active database.
  39. Subscription Records: Purchase records held by RevenueCat and the app stores are kept for as long as tax and accounting laws require, even after you delete your account.
  40. Technical Logs: Our server request logs automatically age out and are permanently deleted within 30 days.
  41. Backups: Our encrypted database backups are overwritten within 30 days. This means that if you delete your account, all traces of your data will be completely purged from our backup systems within one month.
  42. 8. COOKIES & TRACKING

    Because Wellnest is a native iOS and Android application, we do not use traditional web cookies for tracking. However, we do use essential technical tokens (like Firebase Authentication tokens and push notification device tokens from Apple and Firebase Cloud Messaging) to keep you logged in securely and to deliver notifications.

    We do not use any third-party tracking SDKs, advertising trackers, or behavioral analytics tools in our app. Your activity within Wellnest remains entirely private to you and your circles.

    9. CHILDREN'S PRIVACY

    Wellnest is designed for consumers aged 13 and over. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created an account, please contact us at privacy@usewellnest.com. If we discover that we have inadvertently collected data from a child under 13, we will delete that account and all associated data immediately.

    10. INTERNATIONAL TRANSFERS

    BITROVA LABS LTD operates globally. Your information may be transferred to, stored, or processed in countries other than your own, including the United States, where our servers are hosted. When we transfer data originating from the European Economic Area (EEA) or the UK to other countries, we ensure it is protected by implementing appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office.

    11. CHANGES TO THIS POLICY

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. If we make material changes, we will notify you by sending a push notification, an email, or displaying a prominent notice within the Wellnest app before the changes take effect. Your continued use of the app after the effective date constitutes your acceptance of the updated policy.

    12. CONTACT US

    We welcome your questions, concerns, and feedback regarding this Privacy Policy.

  43. Privacy Email: privacy@usewellnest.com
  44. Support Email: support@usewellnest.com
  45. Response Time: We typically respond to all privacy inquiries within 3-5 business days.
  46. ---

    13. CATEGORIES TABLE (CCPA/CPRA)

    For our users in California, the California Consumer Privacy Act (CCPA) as amended by the CPRA requires us to provide a specific mapping of the personal information we have collected over the past 12 months.

    Notice regarding Sensitive Personal Information: We collect health data and wellness metrics, which qualify as Sensitive Personal Information under California law. You have the right to limit the use and disclosure of this information. However, because we only use this data to provide the core Wellnest service you requested (and never for advertising or analytics), our current use already falls within the strict limitations permitted by the CPRA.

    CategorySourcesBusiness PurposeCategories of Third Parties Disclosed ToRetention Period
    Identifiers (Name, email, account ID, device tokens)Directly from you; automatically via appAccount creation, authentication, notifications, subscriptionsAuthentication providers (Google/Apple), push notification services (Apple, Google), subscription provider (RevenueCat), hosting provider (Vultr)Until account deletion
    Commercial Information (Subscription plan, status, renewal dates, store transaction IDs)Apple App Store or Google Play, through RevenueCatProviding and restoring Wellnest PlusSubscription provider (RevenueCat), app stores (Apple, Google)As long as tax and accounting laws require
    Protected Classifications (Age/Date of birth if inferred from Health data)Apple HealthKit or Health Connect (with permission)Calculating wellness metricsNoneUntil account deletion
    Biometric / Health Information (Steps, sleep, workouts, mindful minutes)Apple HealthKit or Health Connect (with permission)Calculating daily rhythm scoreHosting provider (Vultr), as storage onlyUntil account deletion
    Internet / Network Activity (Server request logs)Automatically collectedSecurity, debugging, API performanceHosting provider (Vultr), as storage only30 days
    Sensory Data (Profile photos, shared photos)Directly from youSocial sharing within circlesHosting provider (Vultr), as storage onlyUntil account deletion
    Inferences (Daily rhythm score, mood trends)Generated by our appProviding the core wellness serviceHosting provider (Vultr), as storage onlyUntil account deletion

    14. AUTOMATED DECISION-MAKING

    Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

    While Wellnest uses automated algorithms to calculate your daily "rhythm" score based on your inputs and health data, this profiling is strictly for your personal wellness tracking and social sharing within the app. We do not engage in any automated decision-making or profiling that produces legal or similarly significant effects on you.

    15. PRIVACY SIGNALS

    Various US state laws (including California, Colorado, Connecticut, Montana, and Texas) require businesses to honor the Global Privacy Control (GPC) browser signal as a valid opt-out of the sale or sharing of personal data for targeted advertising.

    Because we do not sell your personal data or share it for targeted advertising under any circumstances, your privacy is already protected to the highest standard regardless of whether your browser or device transmits a GPC signal. However, we acknowledge and respect GPC signals where technically applicable to our web presence.

    16. SUB-PROCESSORS

      To provide our services, we use a limited number of third-party sub-processors. Our current sub-processors are:
    • Vultr: Hosting for our API, database, and backups in the United States.
    • Google (Firebase and Google Sign-In): Secure user authentication and push notification delivery on Android.
    • Apple: Sign in with Apple, push notification delivery on iPhone, and HealthKit integration.
    • RevenueCat: Subscription management for Wellnest Plus.
    • Apple App Store and Google Play: Payment processing for subscriptions.
    • Cloudflare: Domain name services and forwarding of emails sent to our support and privacy addresses.

    We maintain a current list of all sub-processors. If you would like to view this list or subscribe to be notified before a new sub-processor is added to our systems, please email privacy@usewellnest.com with the subject line "Sub-processor Updates."

    17. EU/UK REPRESENTATIVE

    Under Article 27 of the GDPR and UK GDPR, businesses established outside the EU/UK that offer services to individuals in those regions may be required to appoint a local representative. We have not yet appointed one. Until we do, you can raise any EU or UK data protection matter directly with our privacy team at privacy@usewellnest.com, and we will handle it with the same care and within the same timeframes.

    18. SUPERVISORY AUTHORITY

    If you are located in the European Economic Area or the United Kingdom and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your relevant supervisory authority.

    For users in the UK, this is the Information Commissioner's Office (ICO) (https://ico.org.uk). For users in the EEA, you may contact the Data Protection Authority in your country of residence (for example, the Irish Data Protection Commission).

    Privacy Policy - Wellnest | PolicyForge