Welltao Privacy Policy

Effective Date: August 8, 2026 · Last Updated: September 1, 2026 (policy updates)

1. Data We Collect

1.1 Account information: your sign-in method and email address. With email and password, we store your email address. With Apple, Apple shares an email address with us (it may provide a private relay address). If the provider also shares a name, it stays in the authentication record held by our authentication provider; it is not used as your in-app display name. Your display name is generated by us (a random name such as "User482913") and you can change it at any time.

1.2 Profile: the display name, gender, and age you provide in the app, and your interface language preference. These are used to compute the constitution score and tailor wellness guidance.

1.3 Assessment answers (per-question responses): uploaded when you submit the assessment, used to generate your wellness guidance and stored with your account.

1.4 Assessment outcome (converted scores and judgments per constitution): uploaded and stored with your account.

1.5 Wellness plan content: when you generate a wellness plan, we store the generated plan text (title, daily focus, expected timeline, cautions, and the recommended tasks and notes grouped by category) together with the language it was generated in and the assessment it was based on. This content is permanent: once generated it is never overwritten or re-generated, and it stays viewable even if your unlock is refunded.

1.6 Purchase and refund records: when you unlock a report, we store the transaction identifier supplied by the App Store together with the unlock state; if a purchase is refunded, we store a record of that refund. These records are kept for as long as your account exists and determine whether a report remains unlocked.

1.7 Feedback content: text you voluntarily submit through the in-app feedback form, used solely to improve the product and stored with your account.

1.8 Server operating records: we keep limited technical records needed to run the service securely — a copy of the payment events we receive from RevenueCat, which contains your account identifier and transaction details (retained for 90 days), and rate-limit counters keyed by your account identifier, which record when an action such as generating a plan or exporting data was performed (kept for no more than 24 hours). These are used for fraud prevention, troubleshooting, and preventing abuse.

We do not collect your precise location, contacts, photos, or device fingerprint. We include no third-party analytics, advertising, or crash-reporting components, and we do not use advertising identifiers (IDFA). Our payment processor RevenueCat does receive standard device and app information through its SDK, which we describe in section 3.

2. Sensitive Health Data (Explicit Consent)

Gender, age, assessment answers, and assessment outcomes are treated as sensitive health-related personal data. We process them only after you grant explicit consent, and only to compute the constitution assessment and generate wellness guidance. This consent is collected just before your first wellness plan is generated (scope: ai_wellness_generation) — not at sign-in or sign-up. You can withdraw this consent at any time under Profile → Withdraw Privacy Consent. When you withdraw, we stop using this data for any further processing; data already uploaded stays stored with your account until you delete it (section 5) or delete your account. Withdrawing consent does not sign you out: you stay signed in, already generated plans stay viewable, and you can consent again at any time. The next time you try to generate a new plan we will ask for your consent again before proceeding.

3. How We Use Your Data

Your data is used only to provide the constitution assessment and the AI-generated wellness guidance service. Wellness guidance is generated by an AI model (DeepSeek) on our server; the AI does not train on your data and does not retain it beyond the request. We share data with carefully selected processors solely for the following purposes. Each processor below is bound by contract to protect your data to a standard no lower than this policy and applicable law, including GDPR:

We do not sell personal data. We do not share data with advertising networks, data brokers, or analytics providers. The share feature on the result page is triggered only by you: an image summarizing your assessment outcome is passed through the system share sheet solely to the destination you choose (e.g., Messages or a social app); we are not involved in that process.

4. Storage & Security

Your sign-in session is managed by Supabase Auth and stored only on your device. The session is refreshed automatically while you remain signed in and is revoked on sign-out, account deletion, or after extended inactivity. Draft answers that you have not submitted stay on your device only, in encrypted form, and are never uploaded. A draft is erased when you submit it, when you restart the assessment, or when you delete your account; it is kept when you simply sign out, so that you can pick up where you left off after signing in again. Locally cached report-list and profile snapshots exclude per-question answers and are erased from your device when you sign out or delete your account. Submitted assessment answers and outcomes are stored on Supabase infrastructure with HTTPS encryption in transit and access controls at rest. We retain your personal data until you delete your account; account deletion permanently removes all of your data as described in section 5.

5. Your Rights

Regardless of where you live, you have the right to:

EU/UK residents may also lodge a complaint with your local data protection authority. California residents may exercise the rights above and request information about data sharing for cross-context behavioural advertising (we do none).

Delete your account — Profile → Delete Account. Deletion is immediate and permanent: there is no grace period and no way to restore the data afterwards. Because it cannot be undone, we ask you to sign in again first (with Apple or your password) to confirm it is really you. Deleting your account removes your authentication record, profile, assessment history with per-question answers, wellness plans and related records, purchase and refund records, feedback records, and the server operating records described in section 1.8.

Export your data — Profile → Export My Data. While you are signed in, tapping it immediately returns a complete JSON file covering your account profile and sign-in method, assessment history with per-question answers, wellness plans, unlock and refund status, feedback records, and the payment events we hold about you. If any part of the export cannot be assembled, the whole export fails rather than returning an incomplete file. Purchase transaction identifiers are not included in the export; full receipts remain available from your App Store account.

If you want to ask us to restrict or object to a particular processing activity, or to make any other request, contact us at contact@welltao.top — we respond within 15 business days at no charge.

6. Age Requirement

Welltao is intended for adults and is not directed to children. You must be at least 16 years old to take the constitution assessment and generate wellness guidance: the app asks for your age before scoring, and both the app and our server reject an age below 16. If you are under 16, do not submit an assessment.

7. International Transfers

Where data is transferred outside your country of residence, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards approved under GDPR.

8. Changes to This Policy

Material changes will be presented to you in-app and require your renewed consent before they take effect. Continued use after the effective date of any change constitutes acceptance of the updated policy.

9. Contact

Privacy questions or complaints: contact@welltao.top — we respond within 15 business days.