Legal

Privacy Policy

Your privacy is sacred to us. This policy explains exactly what data we collect, how we use it, and how we protect it. No legalese — just honest clarity.

Last updated: July 2026GDPR CompliantCCPA Compliant

Our Core Privacy Principle

Your personal wellness data belongs to you. We are stewards, not owners. We will never sell it, never use it for advertising, and never share it without your explicit consent. Full stop.

Information We Collect

Information you provide

When you create an account, we collect your name, email address, and optional profile information such as age, goals, and life priorities.

Check-in & journal data

Daily check-ins, journal entries, voice notes, mood logs, and habit tracking data you input into the platform.

Wearable & device data

If you connect a wearable device (e.g., Apple Watch, Fitbit), we collect health and activity data with your explicit permission.

Usage data

Information about how you interact with the app, including features used, session duration, and navigation patterns.

How We Use Your Information

Personalizing your experience

Your data powers your AI Life Audit, personalized growth plans, and AI Coach recommendations.

Improving the platform

Aggregated, anonymized data helps us improve features, fix bugs, and build better wellness tools.

Communications

We send you service-related notifications, weekly reports, and optional marketing emails (which you can unsubscribe from at any time).

Research

With your consent, anonymized data may be used for wellness and behavioral research to improve mental health outcomes.

How We Protect Your Data

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Your journal entries and check-ins are end-to-end encrypted.

Zero-knowledge architecture

Our AI processes your data without human employees reading your personal entries or conversations.

Access controls

Strict internal access controls ensure only authorized systems can process your personal data.

Regular security audits

We conduct annual third-party security audits and penetration tests to identify and fix vulnerabilities.

Your Rights

Access your data

You can export all your personal data at any time from your account settings in a machine-readable format.

Delete your data

You can permanently delete your account and all associated data at any time. Deletion is irreversible and completed within 30 days.

Correct your data

You can update or correct any personal information from your profile settings.

Opt out

You can opt out of analytics tracking, marketing emails, and research participation at any time from your privacy settings.

Cookies & Tracking

Essential cookies

We use strictly necessary cookies to keep you logged in and ensure the platform functions correctly.

Analytics cookies

With your consent, we use anonymized analytics to understand how users interact with the platform.

No third-party advertising

We do not sell your data to advertisers or use third-party advertising trackers. Your wellness data is never monetized through ads.

Data Retention

Account data

We retain your account information and personal data for as long as your account is active. If you delete your account, all personal data is permanently deleted within 30 days.

Journal & check-in data

Your journal entries, mood logs, and check-in data are retained only while your account exists. Upon account deletion, this data is immediately queued for permanent removal and fully erased within 30 days.

Anonymized analytics

Aggregated, anonymized usage data that cannot be linked back to you may be retained indefinitely for product improvement and research purposes.

Legal obligations

In some cases we may be required to retain certain data longer to comply with legal obligations, resolve disputes, or enforce agreements. In such cases, we retain only the minimum data necessary and for the minimum period required.

Third Parties & Sharing

We never sell your data

Being SPPPFFy™ does not and will never sell, rent, or trade your personal data to any third party.

Service providers

We work with trusted service providers (e.g., cloud hosting, payment processing) who are contractually bound to protect your data.

Legal requirements

We may disclose data only if required by law, court order, or to protect the rights and safety of our users.

Business transfers

In the event of a merger or acquisition, your data protections will be preserved and you will be notified.

Questions About Privacy?

Our Data Protection Officer is here to help.

contact@anuawellness.ca