Privacy Policy
Last updated: September 9, 2026
1. Local by Default
Welly was built with a single core principle: your health data is yours. Health correlations and daily metrics are calculated and stored locally on your device unless you explicitly use a feature that needs a server request.
2. Sign in with Apple
Welly uses Sign in with Apple to authenticate your account. We never receive your Apple password. Our server converts Apple's account identifier into a protected lookup value and assigns your Welly account a separate, random identifier. Apple's identifier, name, and email address are not sent to RevenueCat, AppsFlyer, Meta, or TikTok.
3. Subscriptions & Billing
Transactions are handled by the Apple App Store, so Welly does not receive or store your credit card details. RevenueCat processes your random Welly account identifier, product, purchase status, price, currency, and subscription lifecycle to provide entitlements across devices and measure subscription performance.
4. Data Collection & Usage
- •Health Data: Welly reads data from your Apple Health app (HealthKit) to calculate wellness metrics on your device. Health data is sent for cloud chat only after you opt in and ask a question.
- •AI Meal Logging: After you allow AI meal processing, the meal description or photo you submit is sent through Welly's backend to third-party AI service providers to estimate nutrition. Your choice is remembered for future AI meal submissions. Estimates are saved locally for review; they are written to Apple Health only after you confirm the meal and allow HealthKit writes. You can turn off AI meal processing in Nutrition settings and continue using manual and saved meals.
- •AI Health Chat: If you enable cloud chat, your messages, conversation context, and selected health summaries are sent through Welly's backend to third-party AI service providers to generate answers. Context can include sleep, recovery, workouts, nutrition, body measurements, symptoms, medications and other tracked inputs, and cycle logs. A question may request additional relevant history. Conversations and the data used for answers are saved locally on your device, separately for each account. You can stop generation, revoke cloud-chat consent in Chat settings, or delete saved chats. Welly does not maintain a server-side chat or health-history database for this feature; service providers may retain request data under their applicable retention settings.
- •No Model Training: Data sent through our AI service providers' APIs is not used to train models by default. We do not claim zero retention unless the applicable provider settings support it and are enabled.
- •Local Health Storage: Welly does not maintain a general server-side copy of your Apple Health history. Optional AI requests and connected-wearable imports use the server flows described in this policy.
- •Connected Wearables: If you connect Oura, Welly's backend retrieves and forwards the health and activity records needed for your device to display and calculate your metrics. We store encrypted connection credentials, provider identifiers, and synchronization metadata while the connection is active. You can disconnect the wearable in Welly to revoke access and remove the connection records.
- •AI Usage and Service Operations: Welly keeps account-associated feature-use, timing, model-usage, usage-accounting, and request identifiers to manage weekly AI allowances and prevent duplicate or conflicting requests. These records do not contain copies of your chat messages, meal photos, or nutrition results. Server operational logs record request outcomes and usage without the submitted health content.
- •Account and Subscription Data: Welly stores a random account identifier and short-lived account sessions. RevenueCat receives that identifier and App Store subscription information so it can provide Premium access, process restores, and report subscription lifecycle events.
- •Limited Advertising Measurement: Welly uses the strict AppsFlyer iOS SDK to measure installs and app sessions. AppsFlyer assigns an installation identifier and derives approximate city and country from network information; IP masking is enabled. RevenueCat sends the installation identifier, Welly's random account identifier, and subscription lifecycle events to AppsFlyer for acquisition and lifetime-value reporting.
- •No Cross-App Identifier Access: This version does not request App Tracking Transparency permission, access Apple's IDFA, collect IDFV through AppsFlyer, set an AppsFlyer customer user ID, or include the Meta or TikTok SDK. Advanced matching and advanced data sharing remain disabled.
- •No Health Data for Advertising: Heart rate, sleep, stress, cycle, recovery, nutrition, workout, symptom, and other HealthKit or wellness information is never sent to RevenueCat, AppsFlyer, Meta, or TikTok for advertising measurement.
5. Service Providers, Retention & Deletion
Welly uses service providers including Apple, RevenueCat, AppsFlyer, Upstash, Vercel, and third-party AI service providers for the functions described above. We keep account and service records only as long as needed to operate and secure Welly and to meet legal obligations. AI providers may retain submitted content for service operation, safety, and abuse prevention under their applicable retention settings; disabling AI processing stops future submissions but does not immediately erase previously submitted requests.
You can delete your account in Welly. Deletion revokes active Welly sessions, removes the Apple-to-Welly account mapping, and submits deletion requests to RevenueCat and, when an installation identifier is available, AppsFlyer. When you confirm deletion with Sign in with Apple, Welly also revokes that authorization. To finish deletion after temporary failures, Welly keeps a limited retry record and, while Apple revocation is pending, an encrypted authorization token. The token is removed after successful revocation. A short-lived tombstone prevents deleted sessions from being reused. Failed deletion steps are retried for up to 30 days from the original request; retrying does not extend that retention period. Acceptance of a request by a provider is separate from completion of erasure. Contact support if you need help confirming deletion across devices or with a provider. Deleting Welly does not cancel an App Store subscription or remove Apple Health records; those remain under your control in Apple's settings and Health app.
6. Contact
For privacy questions or help with a deletion request, visit our support page.