© 2026 Wellness Project™ · Not medical advice. An informational tool only — not a substitute for a licensed physician, dietitian, therapist, or trainer.

TermsPrivacyConsumer Health DataMedical Disclaimer

Legal

Privacy Policy

Last updated: July 23, 2026

!

Not a medical product. Wellness Project is a personal logging and informational tool, not a medical service or health professional. See the full medical disclaimer.

1. Our Core Principle — Your Data, Your Control

Wellness Project is a health passport built for you. Five commitments shape how we treat your data, and everything else in this policy is designed to give effect to them:

  • You own your data. The health and fitness information you put into the app belongs to you.
  • Nothing is shared without your action. We do not share your personal or health data with any third party except as strictly necessary to operate the services you have chosen to use (e.g., our cloud database, or an AI provider you message), or where required by law.
  • You can disconnect any integration at any time. Every integration, from Apple Health, Health Connect, Fitbit, and Oura to any AI connection (Claude, ChatGPT, Gemini), can be turned off from the Settings page. Disconnecting halts further data flow to or from that service going forward.
  • You can download everything. One click on Export All My Data at the bottom of the Settings page produces a complete copy of your data in a portable spreadsheet format, no questions asked.
  • You can delete everything. One click on Delete Account at the bottom of the Settings page, or a request submitted at our public deletion-request page at wellnessproject.ai/delete-account if you cannot sign in, permanently removes your account and associated health data from our systems, subject only to the limited backup and legal-retention exceptions described in Section 12.

If you are a Washington, Nevada, Connecticut, or Colorado resident, our Consumer Health Data Privacy Policy describes the additional rights and disclosures that apply to your health data under those state laws.

2. What We Collect

We collect only what the service needs:

  • Account information. When you sign in with Google or with Sign in with Apple, we receive your email address, display name, and (from Google) profile image. If you use Sign in with Apple with “Hide My Email,” we receive only the private-relay address Apple generates on your behalf.
  • Health and fitness data you enter. Workouts, exercises, sets and reps, meals and macros, body metrics, sleep logs, wellbeing ratings, injuries, supplements, recovery sessions, runs, lab markers and lab results, and any notes, descriptions, or photos you attach.
  • Menstrual cycle data (optional, separate consent required). If you enable cycle tracking, we store the period start and end dates you log, and nothing else. This data is collected only after your separate, explicit consent and is covered in full in Section 17.
  • Wearable and health-platform data you connect. If you enable Apple Health (HealthKit, on iOS), Android Health Connect (on Android), Fitbit, Oura, or another supported source, we import only the categories of data you explicitly authorize. The specific data types we may request from Android Health Connect are enumerated in Section 8.
  • Chat content you send to an AI advisor. Messages you type into an in-app chat or a challenge-advisor conversation, together with the minimum subset of your logged data the conversation needs to answer you.
  • Basic technical data. Session cookies used to keep you logged in, and standard security logs (such as IP address and access times) used to protect the service and prevent abuse.
  • Attribution data. To understand where our users come from, we record basic acquisition signals when you arrive and sign up: any campaign tags in the link you followed, the page you first landed on, the referring website, and — if you choose to answer the optional one-tap “How did you hear about us?” prompt after signing up — your answer. This is first-party analytics about our own marketing; it is not health data and is never used for cross-site tracking or advertising.
  • Ad measurement data. If you reach our website from an ad in ChatGPT, we receive the ad click reference and, if you sign up, we report back to OpenAI that its ad led to a signup. The report identifies the ad, not you, and contains no health data. Section 14 explains how to turn advertising measurement off.

3. How We Use Your Data

  • Service delivery: displaying your logs, generating insights and summaries, rendering charts, and providing the core functionality of the app.
  • AI features you invoke: forwarding your chat message and the necessary context to whichever AI provider powers the feature, so it can return a reply.
  • Communications: service-related messages (verification, security alerts, feature notices) and — until you opt out — promotional messages about the app.
  • Product improvement and debugging: aggregated or de-identified usage patterns used to improve reliability and features.
  • Legal compliance and safety: responding to valid legal process and enforcing our Terms of Service.

4. What We Do Not Do With Your Data

  • We do not sell your personal data or health data to anyone.
  • We do not share your personal data or health data with any third party for that third party's own advertising or marketing purposes. The only ad-related report we ever send is that an ad we paid for worked, and that report identifies the ad, not you.
  • We do not use health, fitness, or medical data — including data from Apple HealthKit, Android Health Connect, Fitbit, Oura, or lab results you enter — for advertising, marketing, or data-mining purposes.
  • We do not allow Anthropic, OpenAI, Google, or any other AI provider we route requests through to train, fine-tune, evaluate, or otherwise improve their models on any data you submit to the Service. Every AI provider we use is contractually prohibited from training on your data.
  • We do not share your data with third parties except as strictly necessary to operate the services you have chosen to use (for example, passing a chat message to the AI provider that generates the response, or storing your logs in our cloud database), or as required by law.
  • We do not place advertising or tracking cookies inside the logged-in app or the mobile apps, and we show no third-party ads anywhere. The small set of cookies on our public marketing pages is described in Section 14, never touches your health data, and is yours to control.

Looking ahead. The commitments in this section describe our current practices. If we ever decide to change them — for example, to introduce an ad-supported free tier, to share de-identified or aggregated data for research, or to offer any other use or disclosure not described above — we will update this policy and notify you in advance in accordance with Section 16. Any new use of personal or health data we collected before the change takes effect will require your separate affirmative consent, not merely your continued use of the Service. Where state law requires a specific form of consent (for example, for any sale or share of consumer health data under the Washington My Health My Data Act or similar statutes), we will obtain consent in the form the law requires, and you can always decline.

5. Third-Party Integrations You Control

The app supports optional integrations with several third-party services. Each is off by default and must be enabled by you. Once enabled, any integration can be turned off at any time from the Settings page; disconnecting stops further data from flowing to or from that service going forward.

Current integrations:

  • Sign-in providers: Google (Google Sign-In) and Apple (Sign in with Apple). Used only to authenticate you.
  • Wearables and health platforms: Apple Health (HealthKit, on iOS), Android Health Connect (on Android), Fitbit, Oura. These are one-way reads into the app of the categories of data you have explicitly authorized.
  • AI providers: Anthropic (Claude), OpenAI (ChatGPT / Custom GPT), Google (Gemini). Invoked only when you send an in-app chat message or use an AI-powered feature.
  • Infrastructure providers: Supabase (database and authentication host) and Vercel (application host). These are not user-toggleable because they are the platforms the app runs on; they process data only under written data-processing terms.

When you enable a third-party integration, the third party's own terms and privacy policy also apply to how they handle your data. We do not control a third party's internal processing.

6. AI Providers — What Happens to Chat Content

When you use an in-app AI advisor (Coach Jamie, Casey, Evelyn, etc.) or a Custom GPT integration, the text of your message and the subset of your logged data necessary to answer it is transmitted to the underlying AI provider — currently Anthropic (Claude), OpenAI, and/or Google (Gemini), depending on the feature.

Once the content reaches the AI provider, it is processed under that provider's data-handling practices, which we do not control. To protect that content we: (i) use only AI providers that are contractually prohibited from using your messages or attached data to train, fine-tune, evaluate, or otherwise improve their models; (ii) send only the minimum data needed to answer the message; and (iii) do not share your identifying account metadata with the provider beyond what the API requires.

Limits of our control. We choose providers carefully and bind them by contract, but we cannot see inside their systems, and once content reaches a provider its handling is that provider's responsibility. Our Terms of Service describe how responsibility is allocated if a provider mishandles content.

Photos attached to AI chats. Any photo you attach to an AI chat (for example, a meal photo for macro analysis) is sent to the AI provider for real-time analysis and is not kept on our servers afterward. The provider may briefly retain it under its own API data-handling policy.

AI processing of photos (photo meal scanning). Photo meal scanning is opt-in. When you use “Find meals in today's photos,” your photos are sent to our contracted AI providers for analysis only; we never keep the images on our servers, and our contracts prohibit providers from training on them. Providers may retain images for a limited period for safety review and then delete them, and we keep only the text descriptions and nutrition estimates for a limited period, or until you log them as meals.

Do not type into an AI chat, or attach to an AI chat, any information you would not be comfortable being processed by the underlying AI provider.

7. Apple HealthKit

If you enable the Apple Health / HealthKit integration on iOS, the app reads only the HealthKit data categories you explicitly authorize in the native iOS permission sheet. HealthKit data is used solely to display your metrics back to you inside the app and to power the insights, charts, challenges, and AI summaries you choose to interact with.

In line with Apple's HealthKit requirements, we:

  • do not use HealthKit data for advertising or similar services, and do not sell HealthKit data to advertising platforms, data brokers, or information resellers;
  • do not disclose HealthKit data to any third party for advertising, marketing, or data-mining purposes;
  • do not use HealthKit data for any purpose other than improving health, fitness, or wellness management within this app;
  • do not store HealthKit data in iCloud; and
  • do not write into HealthKit any data that was not produced by you using the app.

You can revoke the app's HealthKit access at any time through iOS Settings > Health > Data Access & Devices, or by disabling the integration from inside the app.

8. Android Health Connect

If you enable the Android Health Connect integration, the app reads only the data types you explicitly authorize in the system Health Connect permission sheet. The categories we may request access to are:

  • Activity: active calories burned, total calories burned, distance, exercise sessions, floors climbed, steps, respiratory rate.
  • Body measurements: basal metabolic rate, body fat, height, weight, basal body temperature.
  • Sleep: sleep sessions and stages.
  • Vitals: blood glucose, blood pressure, body temperature, heart rate, heart rate variability, oxygen saturation, resting heart rate.
  • Wellbeing: mindfulness sessions.

Health Connect data is used solely to display your metrics back to you inside the app, to power the insights, charts, daily Fit Score, and AI advisor responses you choose to interact with, and to reduce the need to log the same data manually.

In line with Google's Health Connect requirements, we:

  • do not use Health Connect data for advertising or similar services, and do not sell Health Connect data to advertising platforms, data brokers, or information resellers;
  • do not disclose Health Connect data to any third party for advertising, marketing, or data-mining purposes;
  • do not use Health Connect data for any purpose other than improving your health, fitness, or wellness management within this app; and
  • do not write into Health Connect any data that was not produced by you using the app.

You can revoke the app's Health Connect access at any time through Android Settings > Apps > Health Connect > App permissions, or by disabling the integration from inside the app.

9. Google User Data (Google Sign-In, Google Health API & Fitbit)

Two of our optional integrations involve Google user data: signing in with your Google Account, and connecting your Fitbit data through the Google Health API (the service Google provides for accessing Fitbit data). This section explains exactly what we access and how we handle it.

  • Google Sign-In. Used only to authenticate you. We receive your email address, display name, and profile image, and nothing else.
  • Google Health API (Fitbit data). If you connect Fitbit, we read only the categories you explicitly authorize on the Google consent screen: activity and fitness (steps, active minutes), health metrics and measurements (heart rate, heart rate variability, weight, body fat), sleep, and nutrition. These are one-way reads into the app.

Google user data is used solely to display your metrics back to you inside the app and to power the insights, charts, daily Fit Score, challenges, and AI advisor responses you choose to interact with. In line with Google's requirements, we:

  • do not use Google user data for advertising, and do not sell it to advertising platforms, data brokers, or information resellers;
  • do not transfer Google user data to third parties except as necessary to provide or improve the user-facing features you use (for example, storing it in our cloud database under data-processing terms), for security purposes, or to comply with applicable law;
  • do not use Google user data to train generalized AI or machine-learning models, and contractually prohibit the AI providers we route requests through from doing so; and
  • do not allow humans to read this data, except with your affirmative consent for a specific piece of data, where necessary for security or to comply with law, or in aggregated, de-identified form for internal operations.

Wellness Project's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke the app's access to your Google user data at any time from your Google Account's third-party access page, or by disconnecting the integration from the Settings page. We retain and delete imported data as described in Section 12.

10. Email Communications

By creating an account, you consent to receive email communications from us:

  • Transactional emails: account verification, password resets, security alerts, and service notifications.
  • Promotional emails: product announcements, feature updates, health and fitness content, tips, and special offers related to Wellness Project.

You can opt out of promotional emails at any time by clicking the “unsubscribe” link included in every promotional email, or by contacting us. Opting out does not affect transactional emails necessary to operate your account.

We never share your email address with third parties for their own marketing purposes.

11. Data Storage and Security

Wellness Project is operated by Wellness Project LLC, a Delaware limited liability company, which acts as the data controller for the personal information described in this policy. Your data is stored with the infrastructure providers listed in Section 5, under written data-processing terms. We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit and at rest, strict per-user access controls at the database level, and audited privileged access.

No internet-connected service can be made completely secure. We do not promise that our measures will prevent every possible breach — but we commit to using reasonable measures, to notifying affected users without undue delay if we become aware of a breach affecting their data, and to not collecting or retaining data we do not need.

12. Data Retention and Deletion

We retain your account and health data for as long as your account is active and only as long as we need it to provide the service. When you delete your account (via Delete Account in the app's Settings page, or via our public deletion-request form at wellnessproject.ai/delete-account if you cannot sign in), we delete your records from our production systems within 30 days, and deleted data ages out of encrypted backups on a rolling schedule within a few months. We may retain a minimal set of records longer where required for legal, tax, fraud-prevention, or dispute-resolution purposes, and will keep any such retention narrowly scoped and protected.

13. Your Rights and Controls

You can exercise the following controls at any time, free of charge:

  • Access: review everything you have logged directly inside the app.
  • Download (Export): use Export All My Data at the bottom of the Settings page to receive a complete copy of your data in spreadsheet form.
  • Delete: use Delete Account at the bottom of the Settings page, submit a request at our public deletion form at wellnessproject.ai/delete-account (no sign-in required), or email us, to permanently delete your account and associated data.
  • Disconnect integrations: turn off Apple Health (iOS), Android Health Connect (Android), Fitbit, Oura, Google, an AI provider, or any other third-party connection from the Settings page. Disconnecting halts further data flow with that service.
  • Opt out of promotional email: click “unsubscribe” in any promotional email.
  • Cookie choices: use the “Cookie settings” link in the footer of any public page to turn analytics or advertising measurement on or off at any time. See Section 14.
  • Correct or amend: edit or delete any individual log entry directly in the app.

Depending on where you live, you may have additional rights under applicable privacy law (for example, the California Consumer Privacy Act, the Washington My Health My Data Act, and the Connecticut, Nevada, and Colorado consumer-health-data statutes). We honor those rights regardless of where you reside; to exercise them formally, email us at support@wellnessproject.ai.

14. Cookies, Analytics & Advertising Measurement

Two separate worlds, by design. The logged-in app, on the web and in the iOS and Android apps, contains no advertising trackers and no third-party marketing analytics, full stop. Our public marketing pages use a small set of cookies in three groups:

  • Essential. Signing you in, keeping the site secure, and remembering your preferences and your cookie choice. Always on, never used for tracking.
  • Analytics. Google Analytics, on our public pages only and with its advertising features turned off, shows us which pages are useful, and a first-party cookie remembers which page or campaign first brought you here so we can measure our own marketing. None of it runs on logged-in pages, follows you to other sites, or ever touches health data.
  • Advertising measurement. Only if an ad in ChatGPT brings you here: an OpenAI measurement cookie recognizes the ad click, and if you sign up we report back to OpenAI that its ad led to a signup. That report identifies the ad click, not you. It contains no name, no email address, and nothing about your health, and this category never runs on logged-in pages.

In the European Economic Area, the United Kingdom, Switzerland, and Canada, analytics and advertising measurement stay off until you accept them, and declining is as easy as accepting. Everywhere else they are on by default, and the banner tells you so. Either way, the consent banner describes each category before anything runs, your choice lasts 12 months, and you can change it at any time through the “Cookie settings” link in the footer of every public page. Turning a category off deletes its cookies. We also honor Global Privacy Control browser signals, which keep advertising measurement off automatically.

15. Children

The service is intended for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will promptly delete it.

16. Changes to This Policy

We may update this policy from time to time. If we make a material change — especially one that narrows your rights or expands the categories of data we collect — we will provide reasonable advance notice (by email to the address on file, by an in-app notice, or both) before the change takes effect. Non-material updates (wording, clarifications, structural changes) may be made by updating the date at the top of this page. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy going forward.

Prospective vs. retroactive changes. A change that introduces a new data-sharing, data-sale, advertising, or similar monetization use of personal or health data takes effect only on a prospective basis — that is, it applies only to data you submit, or events that occur, after the change becomes effective — unless you separately and affirmatively consent to apply the new use to data we collected earlier. Continued use of the Service after such a change is consent to the new practice going forward, but it is not, by itself, consent to apply any new monetization use to data we already hold.

17. Menstrual Cycle Data

Cycle tracking is an optional feature that requires a separate, un-bundled, affirmative consent before any data is collected. The consent screen explains exactly what is stored and can be declined at any time without affecting any other feature.

  • What we store. Period start dates and period end dates you manually log. No symptom scores, no flow intensity, no inferred cycle states. The phase label you see is calculated on the fly from the dates you logged and is never saved anywhere.
  • AI processing under contract, with your consent. Cycle data is never sold, and is not shared with analytics or advertising services; if you use an AI feature, only the cycle data needed to answer you is processed by our AI providers acting as our service providers under contracts that prohibit them from training on or retaining it. Cycle data is also kept out of our error and crash reporting.
  • No fertility prediction. This feature does not predict fertile days, ovulation, or safe periods. It is a wellness logging tool, not a contraceptive device.
  • Your control. You can delete all cycle data permanently in one tap from the Cycle page in Health. Deleting your account also removes all cycle data. You can also disable the feature at any time in Settings without deleting your data.
  • State law. We comply with the Washington My Health My Data Act and similar consumer-health-data statutes. Separate consent, the right to delete, and no sharing without additional consent apply to cycle data by design.

18. Contact

For questions about this privacy policy, to exercise a data right, to opt out of promotional emails, or to report a concern, contact Wellness Project LLC at support@wellnessproject.ai.

← Back to home