Privacy Policy
Effective Date: September 13, 2026 Last Updated: September 13, 2026 (Note: Previous versions of this Privacy Policy are available upon request.)
SUMMARY OF KEY POINTS
- At a Glance:
- What personal information do we collect? We collect your account details (name, email), daily wellness metrics (mood, energy), social interactions within the app (posts, reactions), your subscription status if you buy Wellnest Plus, and, with your explicit permission, health data from Apple Health on iPhone or Health Connect on Android (steps, sleep, workouts).
- Do we process any sensitive personal information? Yes. Your health data and wellness metrics are considered sensitive personal information. We treat this data with the highest level of security and never use it for advertising.
- Do we collect information from third parties? Yes, we receive authentication information from Google (Firebase and Google Sign-In) or Apple when you sign in, health metrics from Apple HealthKit or Health Connect if you choose to connect them, and purchase confirmations from the App Store or Google Play if you subscribe.
- How do we use your information? We use your data solely to provide the Wellnest service: calculating your daily "rhythm" score, sharing your updates with the specific circles you choose, and unlocking Wellnest Plus when you subscribe.
- Who do we share your personal information with? We share your data only with essential service providers (like our hosting, authentication, notification and subscription partners) and the family or friend circles you explicitly join. We never sell your personal data.
- What are your privacy rights? You have the right to access, correct, delete, and port your data, as well as the right to withdraw your consent for health data access at any time.
- How can you contact us? You can reach our privacy team anytime at privacy@usewellnest.com.
---
1. INTRODUCTION
Welcome to Wellnest, built by BITROVA LABS LTD. We created Wellnest to help small circles of family and friends stay connected through a shared focus on well-being. Because our app handles deeply personal information, from your daily mood to your sleep patterns, we believe our privacy practices must be as healthy and transparent as the habits we help you build.
This Privacy Policy explains how we collect, use, and protect your personal information when you use the Wellnest apps for iOS and Android. We have written this document to be clear and direct, avoiding heavy legal jargon wherever possible. Our core philosophy is simple: your data belongs to you. Nothing is public, sharing is strictly controlled by you on a per-circle and per-category basis, and your health data is never used for advertising, never shared with analytics providers, and never sold.
If you have any questions about this policy or how we handle your data, please reach out to us at privacy@usewellnest.com.
2. WHAT WE COLLECT & WHY
To provide you with a meaningful daily "rhythm" score based on our five pillars (movement, rest, mind, mood, and staying in touch), we need to process certain information. We organize this data based on how we receive it.
Information You Give Us Directly
When you set up and use Wellnest, you actively provide us with information. We collect this data to fulfill our contract with you (providing the app's core features) and based on your explicit consent.Information Collected Automatically
When you use our app, our servers automatically record certain technical information. We collect this based on our legitimate interest in keeping our service secure and functional.Information from Third Parties
With your explicit permission, we connect with third-party services to seamlessly build your rhythm score. We process this data strictly based on your consent, or to fulfill our contract with you where you buy a subscription.3. HOW WE USE YOUR INFORMATION
We are highly intentional about how we use your data. Every piece of information we collect serves a specific purpose in making Wellnest work for you.
What We Don't Do: We never use your health data for marketing or advertising. We never share your health data with analytics providers or subscription providers. We never sell your personal information to anyone.
4. WHEN WE SHARE YOUR INFORMATION
Because Wellnest is designed for private circles, your data is inherently shielded from the public. However, to operate our service, we do share information in a few strictly limited scenarios.
5. YOUR PRIVACY RIGHTS
Depending on where you live (including under the GDPR, UK GDPR, and CCPA/CPRA), you have fundamental rights regarding your personal data. We extend these rights to all our users globally.
To exercise any of these rights, please email privacy@usewellnest.com. We aim to respond to all requests within 30 days.
6. DATA SECURITY
We take the security of your intimate wellness data seriously and have built Wellnest with privacy-by-design principles.
7. DATA RETENTION
We keep your data only for as long as you need our service. Our retention schedules are designed to minimize the data we hold.
8. COOKIES & TRACKING
Because Wellnest is a native iOS and Android application, we do not use traditional web cookies for tracking. However, we do use essential technical tokens (like Firebase Authentication tokens and push notification device tokens from Apple and Firebase Cloud Messaging) to keep you logged in securely and to deliver notifications.
We do not use any third-party tracking SDKs, advertising trackers, or behavioral analytics tools in our app. Your activity within Wellnest remains entirely private to you and your circles.
9. CHILDREN'S PRIVACY
Wellnest is designed for consumers aged 13 and over. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created an account, please contact us at privacy@usewellnest.com. If we discover that we have inadvertently collected data from a child under 13, we will delete that account and all associated data immediately.
10. INTERNATIONAL TRANSFERS
BITROVA LABS LTD operates globally. Your information may be transferred to, stored, or processed in countries other than your own, including the United States, where our servers are hosted. When we transfer data originating from the European Economic Area (EEA) or the UK to other countries, we ensure it is protected by implementing appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. If we make material changes, we will notify you by sending a push notification, an email, or displaying a prominent notice within the Wellnest app before the changes take effect. Your continued use of the app after the effective date constitutes your acceptance of the updated policy.
12. CONTACT US
We welcome your questions, concerns, and feedback regarding this Privacy Policy.
---
13. CATEGORIES TABLE (CCPA/CPRA)
For our users in California, the California Consumer Privacy Act (CCPA) as amended by the CPRA requires us to provide a specific mapping of the personal information we have collected over the past 12 months.
Notice regarding Sensitive Personal Information: We collect health data and wellness metrics, which qualify as Sensitive Personal Information under California law. You have the right to limit the use and disclosure of this information. However, because we only use this data to provide the core Wellnest service you requested (and never for advertising or analytics), our current use already falls within the strict limitations permitted by the CPRA.
14. AUTOMATED DECISION-MAKING
Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
While Wellnest uses automated algorithms to calculate your daily "rhythm" score based on your inputs and health data, this profiling is strictly for your personal wellness tracking and social sharing within the app. We do not engage in any automated decision-making or profiling that produces legal or similarly significant effects on you.
15. PRIVACY SIGNALS
Various US state laws (including California, Colorado, Connecticut, Montana, and Texas) require businesses to honor the Global Privacy Control (GPC) browser signal as a valid opt-out of the sale or sharing of personal data for targeted advertising.
Because we do not sell your personal data or share it for targeted advertising under any circumstances, your privacy is already protected to the highest standard regardless of whether your browser or device transmits a GPC signal. However, we acknowledge and respect GPC signals where technically applicable to our web presence.
16. SUB-PROCESSORS
- To provide our services, we use a limited number of third-party sub-processors. Our current sub-processors are:
- Vultr: Hosting for our API, database, and backups in the United States.
- Google (Firebase and Google Sign-In): Secure user authentication and push notification delivery on Android.
- Apple: Sign in with Apple, push notification delivery on iPhone, and HealthKit integration.
- RevenueCat: Subscription management for Wellnest Plus.
- Apple App Store and Google Play: Payment processing for subscriptions.
- Cloudflare: Domain name services and forwarding of emails sent to our support and privacy addresses.
We maintain a current list of all sub-processors. If you would like to view this list or subscribe to be notified before a new sub-processor is added to our systems, please email privacy@usewellnest.com with the subject line "Sub-processor Updates."
17. EU/UK REPRESENTATIVE
Under Article 27 of the GDPR and UK GDPR, businesses established outside the EU/UK that offer services to individuals in those regions may be required to appoint a local representative. We have not yet appointed one. Until we do, you can raise any EU or UK data protection matter directly with our privacy team at privacy@usewellnest.com, and we will handle it with the same care and within the same timeframes.
18. SUPERVISORY AUTHORITY
If you are located in the European Economic Area or the United Kingdom and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your relevant supervisory authority.
For users in the UK, this is the Information Commissioner's Office (ICO) (https://ico.org.uk). For users in the EEA, you may contact the Data Protection Authority in your country of residence (for example, the Irish Data Protection Commission).