Legal
Privacy Policy
Last updated: August 31, 2026
Not a medical product. Wellness Project is a personal logging and informational tool, not a medical service or health professional. See the full medical disclaimer.
1. Our Core Principle - Your Data, Your Control
Wellness Project is a health passport built for you. Five commitments shape how we treat your data, and everything else in this policy is designed to give effect to them:
- You own your data. The health and fitness information you put into the app belongs to you.
- We keep sharing limited. We share data only as described in this policy or as required by law.
- You can disconnect any integration at any time. Every supported integration can be turned off from the Settings page or the applicable platform controls. Disconnecting halts further data flow to or from that service going forward.
- You can download everything. One click on Export All My Data at the bottom of the Settings page produces a complete copy of your data in a portable spreadsheet format, no questions asked.
- You can delete everything. One click on Delete Account at the bottom of the Settings page, or a request submitted at our public deletion-request page at wellnessproject.ai/delete-account if you cannot sign in, permanently removes your account and associated health data from our systems, subject only to the limited backup and legal-retention exceptions described in Section 10.
If you are a Washington, Nevada, Connecticut, or Colorado resident, our Consumer Health Data Privacy Policy describes the additional rights and disclosures that apply to your health data under those state laws.
2. What We Collect
We collect information you provide, authorize, or generate through your use of the Service, including:
- Account information. When you sign in through a third-party sign-in provider, we obtain information about your profile from that provider for purposes of creating and maintaining your user profile.
- Subscription and payment data. If you purchase a paid subscription, we and our payment, app-store, and subscription-management providers receive and process information necessary to process, complete, administer, and manage your subscription, payments, refunds, chargebacks, and related tax or accounting obligations.
- Health, fitness, and wellness data you provide or authorize. Information you choose to enter, upload, connect, or authorize the Service, your device, a wearable, or another integration to provide, including health, fitness, activity, exercise, nutrition, body, sleep, recovery, wellbeing, reproductive-health, laboratory, biometric, sensor, image, note, and other data supported by current or future Service features.
- Reproductive health data. If you use features involving menstrual-cycle or other reproductive-health information, we collect the data you choose to share with us or authorize us to receive.
- Wearable and health-platform data you connect. If you enable a supported wearable, health platform, or device integration, we receive the data you authorize that integration to provide. Additional platform-specific information required by Apple and Google appears in Section 7.
- Chat content you send to an AI advisor. Messages, prompts, files, photos, and related context you submit to an in-app chat, challenge-advisor conversation, or other AI-powered feature.
- Basic technical data. Session cookies used to keep you logged in, and standard security and operational logs such as IP address, access times, device, browser, network, diagnostic, and usage information.
- Attribution data. We may collect information about how you find, access, and interact with the Service and our marketing, and may use service providers for analytics, attribution, advertising, and measurement, subject to applicable law and platform controls.
- Ad measurement data. We may use advertising and measurement partners to understand the effectiveness of our marketing. This does not include health data.
- Optional data. No health or fitness data is required to create or maintain an account; users choose what health data to provide or connect, and features that depend on data the user does not provide may be unavailable or less useful.
3. How We Use Your Data
- Service delivery: displaying your logs, generating insights and summaries, rendering charts, and providing the core functionality of the app.
- AI features you invoke: forwarding your chat message and the necessary context to whichever AI provider powers the feature, so it can return a reply.
- Communications: service-related messages (verification, security alerts, feature notices) and - until you opt out - promotional messages about the app.
- Aggregated and de-identified analysis: creating and using aggregated or de-identified information, including information derived from health, fitness, wellness, service, and usage data, for population-level statistical analysis, benchmarking, internal reporting, research, product and service improvement, reliability, debugging, and other internal analysis, where permitted by applicable law and platform rules.
- Legal compliance and safety: responding to valid legal process and enforcing our Terms of Service.
De-identified information. When we treat information as de-identified, we take reasonable measures designed to ensure it cannot reasonably be associated or linked with an individual, commit not to attempt to re-identify it except as permitted by law to test or maintain de-identification safeguards, and require recipients to comply with applicable restrictions when we disclose de-identified information.
4. What We Do Not Do With Your Data
- We do not sell your personal data or health data to anyone.
- We do not share your personal data or health data with any third party for that third party's own advertising or marketing purposes.
- We do not use health, fitness, or medical data - including data from connected health platforms, wearables, or lab results you enter - for advertising or marketing measurement. We also do not use connected-platform health data for data-mining or similar purposes prohibited by applicable platform rules.
- We do not allow AI providers we route requests through for WP-powered features to train, fine-tune, evaluate, or otherwise improve their generalized models on data we submit under provider arrangements that prohibit those uses.
- We disclose data to third parties only as described in this policy or as required by law.
- We do not provide your health or fitness logs to payment or subscription providers for payment or subscription processing. Those providers receive information necessary to process and manage payments and subscriptions.
5. Third-Party Services and Integrations
We use service providers to operate, analyze, and market the Service, and we support optional integrations that you control.
Services and integrations may include:
- Sign-in providers: third-party providers used to authenticate you and provide profile information for your account.
- Wearables and health platforms: supported wearable, device, and health-platform integrations you choose to connect.
- AI providers: third-party model, routing, gateway, and infrastructure providers used to power AI-enabled features, including providers accessed directly or through services such as Vercel AI Gateway.
- Infrastructure providers: providers used for database, authentication, hosting, storage, delivery, security, and related operations.
- Payment and subscription providers: providers used to process and manage purchases, subscriptions, billing, refunds, and related records.
- Analytics and measurement providers: providers used to understand use of the Service and the effectiveness of our marketing.
When you enable a third-party integration, the third party's own terms and privacy policy also apply to how they handle your data. We do not control a third party's internal processing.
6. AI Providers - What Happens to Chat Content
When you use a built-in “WP-powered AI” feature, such as an in-app AI advisor, the text of your message and the subset of your logged data necessary to answer it is transmitted to the underlying AI provider used for that feature, directly or through an AI routing or gateway service.
Once the content reaches the AI provider, it is processed under that provider's data-handling practices, which we do not control. To protect that content for WP-powered AI features we: (i) use provider arrangements that prohibit using your messages or attached data to train, fine-tune, evaluate, or otherwise improve generalized models; (ii) send only the data appropriate to operate the feature; and (iii) do not share identifying account metadata beyond what is appropriate for the feature or required by the provider's API.
However, if you choose to connect external AI services via MCP or another user-controlled integration, the content of your messages and the related context will be processed by that third-party provider under your own contract and its own data-handling practices, not our provider contracts.
Limits of our control. We choose WP-powered AI providers and bind them by contract, but we cannot see inside their systems, and once content reaches any provider its handling is that provider's responsibility. Our Terms of Service describe how responsibility is allocated if a provider mishandles content.
Photos attached to AI chats. Any photo you attach to an AI chat (for example, a meal photo for macro analysis) may be sent to the AI provider for analysis and may be retained or otherwise processed as described in this policy and the applicable provider arrangement.
AI processing of photos (photo meal scanning). Photo meal scanning is opt-in. When you use “Find meals in today's photos,” your photos are sent to contracted AI providers for analysis, and our provider arrangements prohibit providers from training generalized models on them.
Chat retention. Saved chat history, full tool traces, operational metadata, and related records may be retained without a fixed retention period for your reuse and for our records, including account functionality, security, reliability, cost review, dispute resolution, and other legitimate business purposes, subject to applicable deletion rights and legal requirements.
Do not type into an AI chat, or attach to an AI chat, any information you would not be comfortable being processed by the underlying AI provider.
7. Connected Health Platforms
Apple Health / HealthKit. If you enable Apple Health, the Service may access or write supported HealthKit data types where a feature supports that functionality and you authorize the applicable permission. HealthKit data we may collect from the device includes activity and workouts, heart and cardiovascular measurements, respiratory and oxygen measurements, sleep, body measurements and composition, nutrition, reproductive-health information, and other supported HealthKit data types that the Service requests and you authorize. We use HealthKit data only for health, fitness, and wellness purposes within the Service. We do not use HealthKit data for advertising, marketing, or use-based data mining, do not sell HealthKit data to advertising platforms, data brokers, or information resellers, and do not store personal health information obtained through HealthKit in iCloud. We disclose HealthKit data only as permitted by Apple's requirements and with any permission those requirements require. You can change or revoke HealthKit permissions through Apple's system controls.
Android Health Connect. If you enable Health Connect, the Service may access or write supported data types where a feature supports that functionality and you authorize the applicable system permission. We use Health Connect data for health, fitness, and wellness features and do not use it for advertising or similar prohibited purposes. You can change or revoke Health Connect permissions through Android's system controls.
Google Health API / Fitbit. If you connect Google Health API or Fitbit functionality, we collect only data covered by the permissions you authorize, which may include activity and fitness, health measurements, sleep, nutrition, ECG or rhythm information, profile or settings information, and other Google Health API data types required by features you choose to use. The exact permissions requested are shown in Google's authorization flow. We use Google Health API data only to provide or improve health and fitness features visible in the Service and for other uses permitted by the Google Health API policies.
Google Health API data may be stored or processed by Supabase and Vercel for infrastructure and application operations and, when you invoke an AI-powered feature that uses the data, by Vercel AI Gateway and Anthropic, OpenAI, or Google, as applicable to the feature. Other model providers may be used for Service features that do not receive Google Health API data unless and until any additional disclosure or consent required by Google's policies is provided. We transfer Google Health API data to other parties only as permitted by the Google Health API policies, including where necessary to provide or improve a user-facing feature with the required consent, for security, or to comply with law. Human access is limited as required by those policies.
Wellness Project's use of information received from the Google Health API and/or Developer Tools adheres to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
You can revoke Google access through your Google Account or disconnect the integration from the Service. Storage and deletion are described in Sections 9 and 10.
8. Email Communications
By creating an account, you consent to receive email communications from us:
- Transactional emails: account verification, password resets, security alerts, and service notifications.
- Promotional emails: product announcements, feature updates, health and fitness content, tips, and special offers related to Wellness Project.
You can opt out of promotional emails at any time by clicking the “unsubscribe” link included in every promotional email, or by contacting us. Opting out does not affect transactional emails necessary to operate your account.
We never share your email address with third parties for their own marketing purposes.
9. Data Storage, Security & International Transfers
Wellness Project is operated by Wellness Project LLC, a Delaware limited liability company, which acts as the data controller for the personal information described in this policy. Your data is stored with the infrastructure providers described in Section 5 under applicable data-processing terms. We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption in transit and at rest, strict per-user access controls at the database level, and controls over privileged access.
Wellness Project maintains a Record of Processing Activities covering its recurring processing of personal and special-category data, including processing purposes, data categories, recipients, international transfers, retention periods, and applicable safeguards.
International transfers. Wellness Project LLC is based in the United States. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction with data-transfer restrictions, your personal data may be transferred to and processed in the United States and in countries where our service providers operate. Where applicable law requires a transfer mechanism or safeguard, we use an appropriate mechanism or safeguard available under our provider arrangements. We do not rely on transfer mechanisms that our vendor agreements do not actually implement.
No internet-connected service can be made completely secure. We do not promise that our measures will prevent every possible breach, but we commit to using reasonable measures and to complying with applicable breach-notification requirements.
10. Data Retention and Deletion
We retain your account and health data for as long as your account is active and only as long as we need it to provide the service. When you delete your account (via Delete Account in the app's Settings page, or via our public deletion-request form at wellnessproject.ai/delete-account if you cannot sign in), we delete your records from our production systems within 30 days, and deleted data ages out of encrypted backups on a rolling schedule within a few months. We may retain a minimal set of records longer where required for legal, tax, fraud-prevention, or dispute-resolution purposes, and will keep any such retention narrowly scoped and protected.
Billing records. If you ever purchased a subscription, deleting your account still deletes all of your health, fitness, and profile data as described above, but we may retain billing, transaction, customer, tax, accounting, refund, chargeback, fraud-prevention, and related records for as long as reasonably necessary for those purposes and as permitted or required by applicable law.
Chat data follows the rule described in Section 6: saved chat history, full tool traces, operational metadata, and related records may be retained without a fixed retention period for your reuse and for our records, subject to applicable deletion rights and legal requirements.
11. Your Rights and Controls
You can exercise the following controls at any time, free of charge:
- Access: review everything you have logged directly inside the app.
- Download (Portability): use Export All My Data at the bottom of the Settings page to receive a complete, machine-readable copy of your data in spreadsheet form. Where the right to data portability applies (for example, under the GDPR), this export satisfies that right.
- Delete (Erasure): use Delete Account at the bottom of the Settings page, submit a request at our public deletion form at wellnessproject.ai/delete-account (no sign-in required), or email us, to permanently delete your account and associated data.
- Correct or amend: edit or delete any individual log entry directly in the app.
- Restrict processing: you may ask us to restrict processing of your personal data in the circumstances set out in Article 18 GDPR (for example, while a correction request is being resolved). Email us at support@wellnessproject.ai.
- Object to processing: where we rely on legitimate interests as our legal basis, you have the right to object to that processing. We will stop unless we can demonstrate compelling legitimate grounds that override your interests. Email us to invoke this right.
- Withdraw consent: where processing is based on your consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
- Disconnect integrations: turn off supported third-party connections from the Settings page or applicable platform controls. Disconnecting halts further data flow with that service.
- Opt out of promotional email: click “unsubscribe” in any promotional email.
- Cookie choices: use the “Cookie settings” link in the footer of any public page or other available controls to manage analytics or advertising measurement where applicable. See Section 12.
Depending on where you live, you may have additional rights under applicable privacy law (for example, the California Consumer Privacy Act, the Washington My Health My Data Act, and the Connecticut, Nevada, and Colorado consumer-health-data statutes). We honor those rights regardless of where you reside; to exercise them formally, email us at support@wellnessproject.ai. EEA and UK residents may also lodge a complaint with their local supervisory authority; see Section 15.
13. Children
The service is intended for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will promptly delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes are effective when posted unless applicable law requires otherwise. Your continued use of the Service after an update is governed by the updated policy. Where applicable law requires notice, consent, or another affirmative choice for a particular new collection, use, or disclosure, we will comply with that requirement.
15. EEA and UK Users - GDPR Legal Bases
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), this section explains the legal bases under Article 6 of the UK GDPR / EU GDPR on which we process your personal data, and our obligations under Article 9 regarding special-category data.
- Contract (Art. 6(1)(b)). Processing your account information, health and fitness logs, and wearable data to provide the core Service you signed up for.
- Consent (Art. 6(1)(a)). Sending promotional emails and analytics or advertising measurement where consent is required.
- Legitimate interests (Art. 6(1)(f)). Security logging (IP address, access times) to protect the Service and its users; aggregated, de-identified product-improvement analytics; fraud prevention; and measuring our own marketing where permitted by law. These interests do not override your right to object; see Section 11.
- Legal obligation (Art. 6(1)(c)). Retaining records where required by law (tax, fraud prevention, dispute resolution).
Special-category data (Art. 9). Health, fitness, wearable, reproductive-health, and other special-category data are processed on the basis of your explicit consent under Article 9(2)(a) where that is the applicable basis, or another valid Article 9 condition where applicable to the processing. You may withdraw consent where consent is the applicable basis, which will not affect the lawfulness of processing before withdrawal.
Supervisory authority. You have the right to lodge a complaint with the data-protection supervisory authority in your EEA member state or in the UK (the Information Commissioner's Office, ico.org.uk). We would, however, appreciate the opportunity to address your concern first; please contact us at support@wellnessproject.ai.
16. Contact
For questions about this privacy policy, to exercise a data right, to opt out of promotional emails, or to report a concern, contact Wellness Project LLC at support@wellnessproject.ai.