Healtheak Privacy Policy
Last updated: 30 August 2026
1. Data controller
The controller of personal data processed in the Healtheak app (the “App”) is the Healtheak publisher shown in the App Store as “Sold by” (and the equivalent seller on Google Play). That legal name is the same entity on the Paid Applications Agreement in App Store Connect.
For privacy matters, use Support in the App (Profile → Support) or the contact details on the Healtheak store listing.
2. Nature of the App
Healtheak is a wellness app for everyday prevention (nutrition, Body Check, habits). It does not make medical diagnoses, does not treat, and is not a medical device. It does not read Apple Health / HealthKit. Information and any optional AI analysis are only for personal observation and comparison with your own history.
3. Data we collect
Depending on how you use the App, we may process:
- Account data: user identifier, email address (after you sign up), and sign-in provider data (Apple, Google) as needed to authenticate. An account may start as anonymous.
- Profile data: display name, onboarding goals, language, preferences (including hiding Body Check thumbnails, notifications).
- Observational and health-related data you enter: daily nutrition stack, habit completions, Health Freak Score (how consistently you follow the system — not a medical health metric), Body Check entries (type, notes, symptoms, self-rated change), and Body Check photos (tongue, eyes, nails, urine, stool).
- Purchases: Premium subscription status (store customer identifier, product, period, renewal) — processed by Apple or Google and RevenueCat.
- Technical data: session tokens on the device, push notification token, device type, language, event timestamps.
- Advertising identifiers and app events (Meta): when a given build includes the Meta SDK (Facebook App Events) — see section 6.
We do not sell personal data.
4. Purpose and legal basis
- Providing the App (account, sync, nutrition, Body Check, habits, notifications, Premium) — performance of a contract / service on request.
- Optional AI analysis of Body Check photos — your request (you start the analysis in the App).
- Measuring campaign performance and matching Healtheak ads (Meta) — ATT consent on iOS (advertising identifier) and legitimate interest for app events without IDFA, within the law.
- Security, abuse prevention, legal obligations.
5. Body Check photos and OpenAI
Photos are stored in a private store linked to your account (Supabase infrastructure) and are not publicly accessible. Thumbnails of sensitive types (urine, stool) may be hidden by default. Photos do not appear in notifications.
Optional AI analysis: if you run an analysis, the selected photo (and a limited number of earlier photos of the same type) is sent to the OpenAI API (OpenAI, LLC) to describe change relative to your history. This is not a diagnosis. We do not use these photos to train our own advertising models or for targeting.
OpenAI processes the submitted content as a processor to perform the analysis you requested. This may involve a transfer outside the EEA (including the United States).
6. Meta (Facebook App Events)
In native builds with the Meta SDK configured, we may:
- show the iOS App Tracking Transparency (ATT) system prompt;
- after ATT consent, collect the advertising identifier (IDFA) and associate it with app events;
- record app events (including launch, start of purchase / InitiatedCheckout) to measure campaigns and better match Healtheak ads.
If you deny ATT, we do not enable IDFA-based ad tracking. The SDK may still send limited app events without the advertising identifier, to the extent allowed by Apple and Meta.
Meta Platforms Ireland Limited / Meta Platforms, Inc. may process this data as an independent controller or as a processor — according to Meta’s policies. We do not send Body Check photos or in-app health content to Meta.
7. Premium subscription
Premium (Healtheak Pro entitlement) unlocks Body Check, among other features. Payment is handled by Apple (App Store) or Google (Play). We read entitlement status through RevenueCat (RevenueCat, Inc.), which receives the App user identifier and store transaction information — not Body Check photos.
- The subscription renews automatically until you turn renewal off.
- Payment is charged to your Apple / Google account when you confirm the purchase and again at each renewal.
- Cancellation: iOS — Settings → [Your name] → Subscriptions; Android — Google Play → Payments & subscriptions. In the App: Profile → manage subscription and Restore purchases.
- Price, period (monthly / yearly) and any trial are shown in the purchase sheet before you confirm.
Apple and Google process the payment themselves; we do not store your full card number.
8. Processors we work with
As needed to run the App, we use among others:
- Supabase — database, authentication, file storage, server functions.
- OpenAI — optional Body Check photo analysis (only when you start it).
- Meta — App Events / campaign measurement (when the SDK is in the build).
- RevenueCat — Premium subscription status.
- Apple / Google — sign-in, store, payments, system notifications, ATT.
- Expo — push notification delivery.
Some providers may process data outside the EEA. We use the standard contractual safeguards available from those providers.
9. Retention
We keep data for as long as you use the account. After you delete the account in the App, we delete associated user data (including Body Check photo objects), subject to backups, short-lived technical logs, and data that Apple / Google / tax authorities must keep independently (for example store purchase history).
10. Your rights
Depending on applicable law (including the GDPR), you may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent (for example ATT in iOS settings) without affecting the lawfulness of prior processing.
In the App you can:
- delete the account or anonymous account data (Profile → Delete account / Delete data);
- restore purchases and manage the subscription (Profile);
- turn off notifications (Profile and system settings).
You can also request a copy of your data via Support. You have the right to lodge a complaint with a supervisory authority (in Poland: the President of UODO).
11. Children
The App is not intended for children under 16. We do not knowingly collect children’s data.
12. Changes
The current version is in the App (Profile) and at the public policy URL. We will notify you in the App of material changes when required.