Effective date: not yet in effect (draft).
1. Who we are
Wellboy is operated by Pankka Group Oy, a limited liability company registered in Finland (business ID 3397011-8), Sukkulatie 10, 87700 Kajaani, Finland. Pankka Group Oy is the controller of the personal data described in this policy.
Privacy contact: [email protected]
In this policy, “Wellboy”, “we” and “us” mean Pankka Group Oy, and “the app” means the Wellboy application (iOS, Android, and desktop builds).
2. Summary in plain language
- The app is offline-first: your data lives in a local database on your device and core tracking works without a connection. Syncing, AI features, purchases, sharing, and online product lookups need a connection.
- When online, your content syncs to our cloud database (Google Cloud Firestore) in the EU region europe-north1 (Finland), stored under a private account ID that only your signed-in account can read or write.
- You start automatically as an anonymous account and register a sign-in method (Apple, Google, or email) at the end of onboarding to keep your data across devices.
- AI features (meal photo scan, coach chat, workout generation) send the needed input through Wellboy’s own servers to OpenAI for processing. The app calls our server, and the AI API key is held as a server secret. Requests are sent with OpenAI’s application-state storage turned off; OpenAI may keep API logs for abuse monitoring under its own terms (typically up to 30 days), and neither Wellboy nor OpenAI uses your inputs to train AI models.
- You can optionally connect Apple Health (HealthKit) or Health Connect (Android). The import into the Wellboy app is read-only. If you use the optional Apple Watch companion app to record a workout, the watch saves that workout (with heart rate and active energy) into Apple Health on your own devices; it does not send that data to Wellboy’s servers (section 3.5).
- Wellboy Pro purchases are processed by Apple or Google; we never see your card details. RevenueCat processes purchase receipts for us.
- We run no ads and no third-party product analytics in this version. Google SDK components the app uses (ML Kit, Firebase) report limited technical telemetry to Google (sections 3.4 and 9).
- Crash reporting is optional and off by default. If you turn it on, crash and error reports (technical data only, never your content) go to Google Firebase Crashlytics and are processed in the United States. You can turn it off at any time in Settings (section 3.7).
- Reminder notifications are scheduled on your device and never leave it. The only messages our servers send are optional pricing alerts about the lifetime purchase and an invisible signal that tells the app to refresh its own data (section 3.8).
- Coach chat history, grocery lists, daily step counts, and most app settings never upload to your cloud account. Meal scan photos also stay on your device. The coach’s reply to each charged message is kept in a server-side AI request record (section 5.5).
- Share codes publish a frozen, public snapshot of the shared content that anyone with the code can view.
- You can export your data as a ZIP file (JSON + your image files) and delete your account (with all synced data) directly in the app.
3. Data we collect
3.1 Account data
- An anonymous account (random account ID) is created automatically the first time the app connects, and onboarding asks you to register a sign-in method.
- When you register or link a sign-in method, we store the identifiers that provider gives us: your email address and provider account IDs (Sign in with Apple, Google Sign-In, or email + password), plus email verification status. If the provider shares it, we may also receive the name attached to that provider account (for example from Sign in with Apple).
- We do not offer phone/SMS authentication.
3.2 Content you add (health and fitness data)
Depending on which features you use, this can include:
- meals and nutrition entries (foods, portions, energy, macronutrients), hydration, daily check-in summaries, and nutrition goals,
- your goals (main training goals, target weight, weekly workout target, everyday activity level),
- sleep quality entries,
- workouts: your own workout templates, completed sessions (sets, weights, reps, times, distances), scheduled workouts, and training programs,
- recipes and cookbook content, including recipe photos,
- grocery lists (device only),
- body measurements and progress photos (progress photos are only available to users aged 18 and over, see section 14),
- data imported from Apple Health or Health Connect (section 3.5),
- challenge results (for example push-up challenge scores),
- streaks, experience points (XP), virtual credit history, and receipts for redemptions made with virtual credits,
- share records (metadata about share codes you created) and friend referral records (section 8.3),
- an optional avatar photo,
- coach chat messages (stored on your device only),
- your profile: name, sex, and birth date (used for calorie estimates, coach personalization, and the minimum-age check; your age itself is computed on the fly and never stored).
Much of this is health-related data. We treat all of it as private by default and store it only for providing the service to you.
3.3 Settings
Units, language, theme, notification preferences, training defaults, an optional coarse location at country/city level, and an optional profile photo path are stored on your device only (see 4.3). The exceptions are your name, sex, and birth date, which sync to your cloud account as your profile (together with a flag noting that you completed onboarding and, if you answered it, your optional “where did you hear about us” choice, section 3.6) so they follow you to a new device.
Location detail: you can type your country and city in yourself, or grant the operating system’s coarse-location permission. The app never requests precise GPS location. Location is used for regional content only.
3.4 Data collected automatically
- We include no advertising SDKs and no third-party product-analytics SDKs. Google SDK components used by the app (ML Kit pose detection, Firebase) report limited technical telemetry to Google (device, app, configuration, performance, and error data; see section 9).
- Using Google services necessarily exposes standard technical data (IP address, device information, timestamps) to Google as our service provider when the app talks to authentication, database, or server endpoints.
- The app uses Firebase App Check device/app attestation to help verify that requests come from a genuine, unmodified Wellboy app. Attestation exchanges an integrity token issued by Apple or Google; it does not identify you personally.
- To enforce daily limits fairly across time zones, our server stores your device’s most recent IANA time zone name (for example “Europe/Helsinki”) on your account and uses it (or Europe/Helsinki, if no zone is stored) for the daily boundaries. A time zone is a coarse regional signal, not a location trace.
- Barcode scanning sends the barcode digits only to our own product mirror service (food.wellboy.net, hosted on Cloudflare). If the mirror does not return a usable product (unknown barcode, missing nutrition values, or a mirror error), the digits are then sent to Open Food Facts and, for users in the US market, to USDA FoodData Central as fallback lookups. Each service necessarily sees your IP address as part of the request; no account identifier is sent. Results with nutrition values are cached on-device for 30 days, so repeat scans of the same product make no network request.
- Exercise demonstration videos are streamed from our CDN (cdn.wellboy.net), which sees standard web request logs.
- Optional crash and error reporting is off by default and described in section 3.7; nothing is collected for it while it is off.
- On iOS and Android, the app registers a push routing token with Google Firebase Cloud Messaging so our server can deliver the messages described in section 3.8. The token is stored on your account and is created even if you decline visible notifications (it also carries the invisible refresh signal).
3.5 Health app import (Apple Health / Health Connect)
If you connect Wellboy to Apple Health (iOS) or Health Connect (Android), the app reads, with your permission, only these types:
- weight, body fat percentage, lean body mass, resting heart rate, and (on iOS) waist circumference: imported entries are stored like manually typed body measurements, marked with their source, and sync to your cloud account like other body measurements,
- daily step counts and, if you have enabled workout calories in Wellboy’s settings, daily active energy: mirrored into the app’s activity view and challenges, stored on your device only, never synced,
- heart rate samples during a workout (only if you enable workout heart rate): read live to show your heart rate and estimated calories during and after the session; the samples themselves are never stored; only the workout summary you save is kept.
The import from your phone’s health store is read-only: the Wellboy phone app reads only the types listed above and does not write to your health store.
Apple Watch companion app: if you install the optional Wellboy watch app and record a workout with it, the watch measures the session through HealthKit and, with the HealthKit permissions you grant on the watch, saves the workout with its heart rate and active energy into Apple Health, so the workout counts toward your Activity rings. This writing happens inside your own health store on your own devices; the watch does not upload the workout, heart rate, or energy data to Wellboy’s servers.
You can disconnect at any time in the OS settings (iOS: Settings > Health > Data Access; Android: Health Connect app), and an optional automatic top-up sync can be turned off in Wellboy’s settings. Health data is never used for advertising or marketing and is never shared with third parties for their own purposes.
3.6 Where you heard about us (optional marketing question)
At the end of onboarding we ask where you heard about Wellboy. Answering is optional and you can continue without picking anything. If you answer, the one choice you picked (a friend, Instagram, TikTok, YouTube, Facebook, the app store, a podcast, or “other”) is stored with your profile (section 4.2) and used to understand which channels bring users to Wellboy. This is marketing data, not diagnostics: it is not part of the crash reports described in section 3.7, nothing is sent to the platform you pick, it is not used for advertising or tracking, and it is deleted with your account.
3.7 Crash and error reporting (optional, off by default)
To find and fix crashes and hidden errors, the app includes Firebase Crashlytics (Google). Crash reporting is off by default and turns on only if you enable it, on the onboarding page that asks about it or later in Settings. It is never pre-selected and never enabled as a side effect of anything else. While it is off, nothing is collected or sent for this purpose.
If you enable it, Wellboy sends Google Crashlytics:
- crash reports and non-fatal error reports (errors the app caught and survived, for example a failed sync attempt or a failed server call), with the technical trace of the error,
- device model, operating system version, app version, and technical device state at the moment of the report (for example available memory),
- a Crashlytics installation identifier: a random ID for the app installation, used to count how many devices an issue affects. We do not set any identifier that would link a report to your Wellboy account,
- timestamps,
- for non-fatal errors, a small set of technical context values: which app subsystem reported the error, technical reason codes, error and HTTP status codes, and small counts. The allowed context keys are a fixed technical allowlist enforced in the app’s code.
Crash and error reports never include your content or health data: no workouts, no meals, no weight or measurements, no photos, no names, no email addresses, and no coach messages.
Crash data is processed by Google in the United States (Crashlytics does not offer a choice of data location). This is a deliberate, documented exception to the EU storage described in section 4.2, and one reason the feature is opt-in. The transfer relies on Google LLC’s certification under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback safeguard (section 9).
Crash reports and their identifiers are retained for 90 days and then deleted automatically. Crashlytics offers no per-user erasure: reports already sent cannot be selectively deleted afterwards, so turning reporting off, or deleting your Wellboy account, does not retroactively remove reports that were already sent; they age out within the 90-day period. Because no account-linked identifier is set, reports cannot be looked up by user either.
The legal basis for this processing is your consent (section 12). You can withdraw it at any time by turning crash reporting off in Settings; the change takes full effect the next time the app starts.
3.8 Push notifications and the push token
Notifications in Wellboy come from two different places, and the difference matters:
- Reminders are made on your device. Workout reminders, the combined evening check-in and credits reminder, the morning digest, and hydration reminders are scheduled locally by the app from data already on your phone. They never leave the device, and no server is involved in sending them.
- Only two kinds of message come from Wellboy’s servers, delivered through Google’s Firebase Cloud Messaging (FCM): optional pricing alerts about the lifetime purchase (a warning when the current price level is nearly full, and a last-hour notice before it closes), shown only if notifications are allowed for the app; and an invisible background refresh signal that tells the app to fetch fresh data from your own account (for example right after our server has granted you experience points). The refresh signal displays nothing to you and carries no content, only the instruction to refresh.
Pricing alerts are addressed to an anonymous per-currency topic (for example “price_eur” for everyone whose store prices are in euros), not to you personally: the server does not pick recipients by account.
To route these messages, your device holds an FCM registration token: a push routing address issued by Google Firebase Cloud Messaging. It identifies your app installation for message delivery; it is not your account ID and it contains no personal details. The app stores each device’s current token under your own account data (users/{uid}/pushTokens), together with the platform (“ios” or “android”) and created/updated timestamps, and uses it solely to deliver the messages described above: never for advertising, profiling, or cross-app tracking.
Token lifecycle: the operating system and the Firebase SDK refresh the token from time to time, and the app then replaces the stored one. Signing out removes the device’s token from your account on a best-effort basis; if Google reports a token as no longer valid, our server prunes it automatically; and the token records are deleted with everything else under your account when you delete it (section 10.3). The token is created for the background refresh signal even if you decline the notification permission (the refresh signal shows nothing, so the operating system does not require a permission for it); declining the permission means no visible notification is ever shown to you. Push messages themselves never carry your content or health data.
4. Where your data is stored
4.1 On your device
The local database is the working copy of everything, so core tracking works offline; online features (sync, AI, purchases, sharing, online product lookups) need a connection. Image files (avatar, recipe photos, meal scan photos, progress photos) are stored in the app’s private storage on the device.
4.2 In our cloud (synced collections)
When the device is online, the app syncs the following content to Cloud Firestore (region europe-north1, Finland), operated by Google as our processor. Each user’s data lives under their own private account ID:
| Synced content | Notes |
|---|---|
| Workout templates | Your own saved workouts |
| Completed workout sessions | Sets, weights, reps, times |
| Scheduled workouts | Calendar entries |
| Training programs | Program state and progress |
| Meal entries | Foods, portions, nutrition values |
| Hydration entries | Drink amounts |
| Daily check-in approvals | Day summaries incl. hydration total |
| Nutrition goals | Energy and macro targets |
| User goals | Main goals, target weight, weekly target, activity level |
| Sleep entries | One quality rating per day |
| Recipes | Your cookbook content |
| XP grants | Experience point history |
| Credit entries | Virtual credit earn/spend ledger |
| Shop redemptions | Receipts for virtual-credit redemptions |
| Challenge results | For example push-up challenge scores |
| Body measurements | Weight and other metrics, incl. health-app imports |
| Progress photos | Photo record and the compressed image itself |
| Share records | Metadata about your share codes |
| Streak state | Daily streak counters |
| User images | Avatar, recipe, and progress photos as compressed images |
| Profile | Name, sex, birth date, optional “where did you hear about us” answer |
Notes on images:
- Avatar, recipe, and progress photos sync as small compressed image blobs so they follow you to a new device. Deleting one also wipes the image bytes from the server.
- Meal scan photos do not sync: they are kept only on your device as meal thumbnails. The meal entry does sync the photo’s file path as a piece of text metadata, but the image bytes never upload.
In addition to the synced content, our server keeps small operational records under your account: AI request records (section 5.5), support tickets (section 8), your Pro membership status (section 6), and the push routing tokens of your devices (section 3.8).
4.3 Never synced (device only)
Coach chat history, grocery lists, daily step counts and active energy, water challenge state, app settings other than your profile (including the country/city fields and profile photo path), meal scan photos, and in-progress meal drafts stay on your device and are not uploaded.
4.4 Access control
Access to our database is controlled by deny-by-default security rules: only requests authenticated as your account can read or write your synced content, and the server-side records described in this policy (for example purchase events and public share snapshots) are readable only as their own sections describe. The rules are version-controlled and changed only by explicit deployment.
5. AI features (OpenAI)
All AI requests go through Wellboy’s own server (a Google Cloud Function in the EU), which holds the AI API key as a server secret, checks your plan’s usage limits, and forwards only the needed input to OpenAI for processing. Because the request to OpenAI is made by our server, OpenAI receives the server’s network address rather than your IP address, and Wellboy does not add your account ID to the request (text you type yourself is sent as it is, so avoid typing identifiers you do not want to send). Requests are sent with OpenAI’s application-state storage turned off (“store: false”), which our server enforces on every request; OpenAI may retain API logs for abuse monitoring under its own terms (typically for up to 30 days). Neither Wellboy nor OpenAI uses your inputs to train AI models.
5.1 Meal photo scan
When you scan a meal, the photo is normally cropped to a centered square and downscaled on your device (about 768 px); if that processing fails, the original photo is sent instead. The image is sent, together with the optional name/notes you typed, to estimate nutrition. The estimate is stored in your meal log. The photo itself is kept only on your device as the meal card thumbnail; Wellboy does not upload it to Wellboy-controlled storage.
5.2 Coach chat
Messages you type to the AI coach are sent for processing together with the last few messages of the conversation. The coach can ask for app data, but data is shared only when you explicitly approve a specific request card in the chat. On approval, a compact text summary (recent workouts, approved-day nutrition, sleep, body measurements, or streak) is generated on your device and sent; exactly the summary text that is shown and stored in the chat is what leaves the device, never the raw database. Chat history is stored on your device only and is not uploaded as a conversation; the coach’s reply to each charged message is, however, kept in the server-side AI request record described in section 5.5.
5.3 Workout generation
If you use AI workout generation, your equipment list, experience level, and your choices in the generator (time, place, focus, optional free-text wishes) are sent to compose a workout suggestion.
5.4 Usage limits and charging
AI actions consume in-app virtual credits on the free plan and are subject to daily and monthly limits on both plans as an anti-abuse measure (the Pro fair-use caps are published in the Terms of Use, and the app shows your remaining uses). Charges and refunds are recorded in the credit ledger in your account.
5.5 AI request records on our server
To charge correctly, our server keeps a small AI request record in your account for each charged AI action: the AI feature used, status, cost, timestamps, and the AI result (for example the generated workout, the scan estimate, or the coach’s reply). Your prompt text and photos are never stored in these records. Wellboy’s AI application logs are designed to avoid your prompts, photos, and results; they contain identifiers (account and request IDs), status, latency, and token counts. Request records are deleted with your account.
6. Purchases (Wellboy Pro)
- Payment for Wellboy Pro (subscriptions and lifetime purchases) is processed by Apple’s App Store or Google Play under their own terms. We never receive your card or bank details.
- We use RevenueCat, Inc. (USA) as our purchase-management processor. RevenueCat receives your random Wellboy account ID, the store purchase receipt/token, and your purchase history for this app, together with basic technical data its SDK collects (device model and type, OS version, app version, and last-seen timestamps), and tells us which membership is active. If you used a creator code, the code is attached to the purchase. We do not send RevenueCat your name, email, or content.
- Our server receives purchase events (product, price, currency, time, account ID) via RevenueCat and stores your membership status in your account, plus an event log used for accounting, fraud prevention, and creator-code sales attribution. Creators have no direct access to these records; any sales reports we provide to creators exclude account IDs and contain aggregated figures only.
- The app stores themselves also keep your purchase history under their own privacy policies (Apple and Google act as independent controllers of the payment transaction).
7. Processing that stays primarily on your device
- Push-up challenge: camera frames are analyzed on-device with ML Kit pose detection. No video or frames are transmitted anywhere; the ML Kit library itself reports technical telemetry to Google (section 3.4), but never your images or pose results. The optional screen recording is saved to your own photo library only.
- Barcode scanning: detection runs on-device; only the barcode digits are sent out, primarily to our own product mirror (food.wellboy.net), with Open Food Facts (and, for US-market users, USDA FoodData Central) as fallbacks when the mirror has no usable product. Cached results are served without any network request.
- Food text search: the generic food database (based on Fineli and USDA open data) is bundled inside the app, so food searches run entirely on-device and transmit nothing.
- Daily steps: step counts read from your health store are shown and evaluated for challenges on the device and stay there.
8. Sharing, referrals, and support
8.1 Share codes
Creating a share code publishes a frozen snapshot of the selected content (a recipe, workout, recovery session, or program, including compressed images) at a random code in a public area of our database. Anyone who has the code can view and import that snapshot. Snapshots do not update when you later edit the original.
When someone redeems your code, we record the redeeming account’s ID and the time, so that distinct redemptions can be counted. You see counts, not identities.
You can deactivate (and reactivate) your codes at any time in Settings > My share codes. Deactivated codes can no longer be viewed or redeemed.
8.2 Shares and account deletion
Deleting your account also permanently deletes the public share snapshots you published (the snapshot, its images, and its redemption records), as part of the deletion cascade described in section 10.3. Content that other users already imported from your codes remains in their accounts (it became their copy at import).
8.3 Friend referrals
If you create a friend code or enter one, we store the code, the account IDs of the referring and referred accounts, and the reward status, so that the friend reward can be granted once to each side. Friend codes are share-by-choice identifiers, not secrets. Referral records are deleted in the account-deletion cascade.
8.4 Support requests (Contact us)
When you send a message through Settings > Contact us, we store the ticket in your account and read it out of band. A ticket contains your message, an optional contact email and, on exercise requests, an optional reference video link you provide, plus diagnostics whose extent depends on the request type: feature and exercise requests carry a compact set (app version, build type, platform and OS version, app language), while bug reports and help requests also include the device model, device time zone, region and language settings (locale), units and theme, notification and health-sync settings, your account ID, sign-in provider type, account email, Pro/level/credit status, sync status, and counts (numbers only, never content) of your main data types. Bug reports additionally attach up to 12 truncated one-line error messages from the current app session. Sending is rate-limited to prevent abuse. If the ticket cannot be sent, the app offers a pre-filled email to [email protected] instead; email then travels outside the app.
8.5 System share sheet
Content you send through the operating system’s share menu (for example the data export or a share code) goes to the app you pick and is outside our control.
9. Third-party services
| Service | Role | What it receives |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Functions, App Check, Cloud Messaging) | Processor / service provider | Account identifiers, synced content (section 4.2), push tokens and the push messages they route (section 3.8), technical request data |
| Google Firebase Crashlytics | Crash and error reporting (only if you enable it) | Crash and error reports with technical device/app data (section 3.7); processed in the United States |
| OpenAI API | AI processing (via our server) | The AI inputs described in section 5; no IP address, no account ID |
| Apple App Store / Google Play | Payment processing (independent controllers) | Purchase and payment data under their own terms |
| RevenueCat, Inc. | Purchase management processor | Random account ID, store receipts, purchase history, basic device data (model, OS version, app version, last seen), optional creator code |
| Sign in with Apple | Sign-in provider | Standard sign-in exchange |
| Google Sign-In | Sign-in provider | Standard sign-in exchange |
| Wellboy food mirror (food.wellboy.net, Cloudflare Workers + KV) | Primary product lookup, operated by us | Barcode digits of scanned products |
| Open Food Facts | Independent food database (fallback when our mirror has no usable product) | Barcode digits of scanned products |
| USDA FoodData Central | US government food database (fallback for US-market users) | Barcode digits of scanned products |
| Wellboy CDN (cdn.wellboy.net, backed by Cloudflare R2) | Content delivery | Standard web request logs when demo clips are streamed |
| ML Kit pose detection (Google) | On-device processing library | Camera frames and pose results stay on the device; the library reports technical device/app telemetry to Google |
International transfers: the controller is established in the EU and your synced content is stored in the EU (europe-north1). Some of our processors are US-based (OpenAI for the AI features; RevenueCat for purchase management; Cloudflare for the food mirror and the media CDN), and Google may process limited technical data in other locations under the Google Cloud data processing terms. If you enable crash reporting (section 3.7), crash data is processed by Google in the United States; that transfer relies on Google LLC’s certification under the EU-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback safeguard. Push message delivery (section 3.8) runs on Google’s global Firebase Cloud Messaging infrastructure, so push tokens and message routing data can be processed outside the EU under the same Google Cloud data processing terms. Those transfers rely on the providers’ data processing terms, EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You can request a copy of the safeguards used for these transfers (for example the relevant Standard Contractual Clauses) by contacting [email protected].
10. Retention, deletion, export
10.1 Content deletion
Your content is kept until you delete it or delete your account. When you delete an individual item, a minimal deletion marker (with no content) is kept so your devices converge on the deletion; the markers are deleted with your account. Deleted images also have their image bytes wiped from the server.
10.2 Sign-out
Signing out wipes the app on that device back to a factory state. Synced data remains in your cloud account and returns when you sign in again. Anonymous accounts cannot be signed back into: if you use Wellboy without registering and sign out or lose the device, access to that data is permanently lost.
10.3 Account deletion
Settings > Account > Delete account permanently deletes your published share snapshots, your friend-referral records, and everything stored under your account (all synced collections in section 4.2, AI request records, support tickets, membership status, push tokens), deletes your authentication record, and wipes the local copy on the device. This cannot be undone. A technical deletion-job record (your account ID and progress timestamps, no content) is kept for 7 days after completion to make sure the deletion finishes, and is then removed automatically. Purchase records held by Apple, Google, and RevenueCat, and our purchase event and creator-sales records (section 6), are retained after account deletion under their respective policies and legal retention duties (accounting and fraud prevention). Crash and error reports already sent to Crashlytics (section 3.7) cannot be selectively erased and are not linked to your account; they are deleted automatically when their 90-day retention period ends.
10.4 Export
The Account page has an Export data action that produces a ZIP file containing your data as JSON (all synced content plus your app settings) and your available app-owned image files (avatar, recipe photos, progress photos, and meal photos stored in the app’s own storage), and opens the system share sheet so you can save it where you want.
The export does not include data that only lives on the device and is never synced: coach chat history, grocery lists, daily step counts and active energy, water challenge state, and in-progress drafts. It also does not include the server-side operational records described in this policy (AI request records, support tickets, purchase events, push tokens); support tickets you have sent are cloud records that are deleted with your account.
11. Your rights
Because the controller is established in Finland, the GDPR applies to our processing regardless of where you live, and you may also have additional rights under the law of your own country. You have the right to:
- access your data (the in-app export covers the synced content),
- rectify it (most content you entered is editable in the app; for records you cannot edit yourself, such as ledger rows, contact [email protected]),
- erase it (delete items or the whole account in the app),
- data portability (the ZIP/JSON export),
- object, on grounds relating to your particular situation, to processing based on our legitimate interests (section 12), and restrict processing in the cases the GDPR provides,
- withdraw consent where processing is based on consent (for example coach data sharing is approved per request; crash reporting is turned off in Settings, section 3.7; health-app access, camera, photos, notifications, and location permissions can be changed in OS settings). Withdrawing consent does not affect the lawfulness of processing already carried out. Disconnecting a health app stops new imports; data already imported stays in your account until you delete it,
- complain to a supervisory authority. Our lead supervisory authority is the Office of the Data Protection Ombudsman in Finland (tietosuoja.fi), because the controller is established in Finland; you may also complain to the authority in your own country of residence.
To exercise any right that the in-app tools do not cover, contact [email protected].
12. Legal bases (GDPR)
| Processing | Legal basis |
|---|---|
| Account creation and authentication | Performance of a contract (providing the service) |
| Providing the service (local + synced tracking) | Performance of a contract; explicit consent for health data |
| Health app import | Explicit consent, expressed through the OS health-permission flow |
| AI features (photo scan, coach chat, generation) | Consent, given per use when you start the action; explicit consent for health-related inputs |
| Coach data sharing | Explicit consent per request card |
| Share codes, friend referrals, and support requests | Performance of a contract (features you invoke) |
| Barcode/product lookups and media delivery | Performance of a contract (features you invoke) |
| Optional coarse location (regional content) | Consent, via the OS permission or your own entry |
| Crash and error reporting (Crashlytics, section 3.7) | Consent (opt-in toggle, off by default; withdraw in Settings) |
| Optional marketing question (where you heard about us, section 3.6) | Consent (answering is voluntary) |
| Pricing alert notifications (push, section 3.8) | Consent, via the OS notification permission |
| Background refresh signal (silent push, section 3.8) | Performance of a contract (keeping your devices and account in sync) |
| Purchases and membership management | Performance of a contract; legal obligation (accounting); legitimate interests (fraud prevention and creator-sales attribution) |
| Security and anti-abuse (attestation, rules, caps) | Legitimate interests |
| Optional permissions (camera, photos, notifications) | Consent via OS permission |
Your birth date is needed to pass the minimum-age check when setting up the app, and a purchase requires the data the store’s checkout collects; without these, sign-up or the purchase cannot be completed. Everything else you add is voluntary: features simply work without the data you leave out.
13. Security
Data is encrypted in transit (TLS) and at rest (Google-managed encryption). Access is limited by per-user deny-by-default security rules. Most of the app’s UI reads the local copy of your data (the paywall’s pricing and membership status are read from the server); the cloud is otherwise a sync target, which minimizes data exposure paths. Virtual-credit and XP balances are decided on the server. Our AI application logs are designed to avoid your prompts, photos, and results (section 5.5); other server logs can contain identifiers and technical request details and are used for operations and abuse prevention. We include no third-party advertising code and no third-party product analytics (Google SDK components report limited technical telemetry, section 3.4). Crash and error reporting is optional and off by default (section 3.7).
14. Children
Wellboy is intended for users aged 13 and over, and older where the national digital age of consent is higher (13 to 16 in the EU/EEA; 13 in Finland, 16 in Germany, Ireland and the Netherlands, for example). The app asks for your date of birth and does not accept a date below the minimum age that applies where you live, in onboarding, in Settings and in a one-time prompt for accounts created before the age gate existed. There is no parental-consent route: below the local minimum age you cannot use the app, so we do not knowingly collect data from children under it.
Progress photos are for users aged 18 and over. If you are under 18, the progress photo feature is not offered to you and no progress photo is stored on your device, synced to your account, or uploaded anywhere. Every other feature works normally.
15. Changes to this policy
We will post any updates at https://wellboy.app/privacy and note material changes in the app before they take effect.
16. Language
This policy is drawn up and maintained in English; translations are produced from the English text for convenience. If a translation and the English text differ, the English text is the version we maintain and correct translations against, and we aim to keep every published language materially accurate.
17. Contact
Pankka Group Oy Sukkulatie 10, 87700 Kajaani, Finland Business ID 3397011-8 [email protected]