1. Data We Collect
1.1 Account information: your sign-in method and email address. With email and password, we store your email address. With Apple, Apple shares an email address with us (it may provide a private relay address). If the provider also shares a name, it stays in the authentication record held by our authentication provider; it is not used as your in-app display name. Your display name is generated by us (a random name such as "User482913") and you can change it at any time.
1.2 Profile: the display name, gender, and age you provide in the app, and your interface language preference. These are used to compute the constitution score and tailor wellness guidance.
1.3 Assessment answers (per-question responses): uploaded when you submit the assessment, used to generate your wellness guidance and stored with your account.
1.4 Assessment outcome (converted scores and judgments per constitution): uploaded and stored with your account.
1.5 Wellness plan content: when you generate a wellness plan, we store the generated plan text (title, daily focus, expected timeline, cautions, and the recommended tasks and notes grouped by category) together with the language it was generated in and the assessment it was based on. This content is permanent: once generated it is never overwritten or re-generated, and it stays viewable even if your unlock is refunded.
1.6 Purchase and refund records: when you unlock a report, we store the transaction identifier supplied by the App Store together with the unlock state; if a purchase is refunded, we store a record of that refund. These records are kept for as long as your account exists and determine whether a report remains unlocked.
1.7 Feedback content: text you voluntarily submit through the in-app feedback form, used solely to improve the product and stored with your account.
1.8 Server operating records: we keep limited technical records needed to run the service securely — a copy of the payment events we receive from RevenueCat, which contains your account identifier and transaction details (retained for 90 days), and rate-limit counters keyed by your account identifier, which record when an action such as generating a plan or exporting data was performed (kept for no more than 24 hours). These are used for fraud prevention, troubleshooting, and preventing abuse.
We do not collect your precise location, contacts, photos, or device fingerprint. We include no third-party analytics, advertising, or crash-reporting components, and we do not use advertising identifiers (IDFA). Our payment processor RevenueCat does receive standard device and app information through its SDK, which we describe in section 3.
2. Sensitive Health Data (Explicit Consent)
Gender, age, assessment answers, and assessment outcomes are treated as sensitive health-related personal data. We process them only after you grant explicit consent, and only to compute the constitution assessment and generate wellness guidance. This consent is collected just before your first wellness plan is generated (scope: ai_wellness_generation) — not at sign-in or sign-up. You can withdraw this consent at any time under Profile → Withdraw Privacy Consent. When you withdraw, we stop using this data for any further processing; data already uploaded stays stored with your account until you delete it (section 5) or delete your account. Withdrawing consent does not sign you out: you stay signed in, already generated plans stay viewable, and you can consent again at any time. The next time you try to generate a new plan we will ask for your consent again before proceeding.
3. How We Use Your Data
Your data is used only to provide the constitution assessment and the AI-generated wellness guidance service. Wellness guidance is generated by an AI model (DeepSeek) on our server; the AI does not train on your data and does not retain it beyond the request. We share data with carefully selected processors solely for the following purposes. Each processor below is bound by contract to protect your data to a standard no lower than this policy and applicable law, including GDPR:
- Supabase (Auth, Postgres, Edge Functions) — account authentication, database storage, and server-side processing. Hosted in the United States under GDPR-compliant data processing agreements.
- DeepSeek (AI) — receives your gender, age, assessment answers, and assessment outcomes under encrypted transmission, used solely to generate your personalized wellness guidance on demand. Your name, email address, and display name are never sent to DeepSeek. DeepSeek is operated by Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd., and its servers are located in mainland China; this transfer outside the EU/UK is based on your explicit consent given before your first wellness plan is generated (GDPR Art. 49(1)(a), scope
ai_wellness_generation). - RevenueCat — verifies in-app purchase receipts and tracks unlock state. We identify you to RevenueCat by your account identifier, and its SDK receives standard device and app information (device model, operating system version, app version, and a vendor identifier). RevenueCat is based in the United States. We do not see your payment card details.
- Apple App Store — processes payments for the one-time unlock of a report, and handles the in-app rating prompt if you choose to rate the app. We do not see or store your payment card number or payment account.
- GitHub Pages — hosts this policy and our other legal documents. When you open a legal document it is loaded in your system browser from GitHub's servers, so GitHub may receive technical information such as your IP address and browser user agent.
We do not sell personal data. We do not share data with advertising networks, data brokers, or analytics providers. The share feature on the result page is triggered only by you: an image summarizing your assessment outcome is passed through the system share sheet solely to the destination you choose (e.g., Messages or a social app); we are not involved in that process.
4. Storage & Security
Your sign-in session is managed by Supabase Auth and stored only on your device. The session is refreshed automatically while you remain signed in and is revoked on sign-out, account deletion, or after extended inactivity. Draft answers that you have not submitted stay on your device only, in encrypted form, and are never uploaded. A draft is erased when you submit it, when you restart the assessment, or when you delete your account; it is kept when you simply sign out, so that you can pick up where you left off after signing in again. Locally cached report-list and profile snapshots exclude per-question answers and are erased from your device when you sign out or delete your account. Submitted assessment answers and outcomes are stored on Supabase infrastructure with HTTPS encryption in transit and access controls at rest. We retain your personal data until you delete your account; account deletion permanently removes all of your data as described in section 5.
5. Your Rights
Regardless of where you live, you have the right to:
- Access the personal data we hold about you.
- Correct your profile — display name, gender, and age (Profile → Edit). A submitted assessment is kept as a historical record and its answers cannot be edited; to remove them, delete your account as described below.
- Delete your account and all associated data ("right to be forgotten").
- Export your data in a portable format ("data portability").
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before you withdraw it.
EU/UK residents may also lodge a complaint with your local data protection authority. California residents may exercise the rights above and request information about data sharing for cross-context behavioural advertising (we do none).
Delete your account — Profile → Delete Account. Deletion is immediate and permanent: there is no grace period and no way to restore the data afterwards. Because it cannot be undone, we ask you to sign in again first (with Apple or your password) to confirm it is really you. Deleting your account removes your authentication record, profile, assessment history with per-question answers, wellness plans and related records, purchase and refund records, feedback records, and the server operating records described in section 1.8.
Export your data — Profile → Export My Data. While you are signed in, tapping it immediately returns a complete JSON file covering your account profile and sign-in method, assessment history with per-question answers, wellness plans, unlock and refund status, feedback records, and the payment events we hold about you. If any part of the export cannot be assembled, the whole export fails rather than returning an incomplete file. Purchase transaction identifiers are not included in the export; full receipts remain available from your App Store account.
If you want to ask us to restrict or object to a particular processing activity, or to make any other request, contact us at contact@welltao.top — we respond within 15 business days at no charge.
6. Age Requirement
Welltao is intended for adults and is not directed to children. You must be at least 16 years old to take the constitution assessment and generate wellness guidance: the app asks for your age before scoring, and both the app and our server reject an age below 16. If you are under 16, do not submit an assessment.
7. International Transfers
Where data is transferred outside your country of residence, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards approved under GDPR.
8. Changes to This Policy
Material changes will be presented to you in-app and require your renewed consent before they take effect. Continued use after the effective date of any change constitutes acceptance of the updated policy.
9. Contact
Privacy questions or complaints: contact@welltao.top — we respond within 15 business days.