Privacy Policy
Last updated: 2026-08-26 · Version 5.9
This is the same policy shown inside the Heala app.
1. Who we are
Heala is operated by Heala LTD, company number 11111111, a company registered in England and Wales with registered office at Apartment 1219 Nobel Way, Uhaus Vita Living East, Manchester, England, M1 7FY.
Heala LTD is the controller of the personal data described in this Privacy Policy under the UK GDPR and, where applicable, other data-protection and privacy laws. Heala is developed by Kerem Erol and Ege Yasayanlar.
Privacy contact: hello@heala.fit
If you are in the United Kingdom, you may have the right to complain to the Information Commissioner's Office. If another data-protection regulator has jurisdiction where you live, you may also have the right to complain to that regulator. We would appreciate the opportunity to address your concern first.
2. Age requirement — Heala is for adults
You must be at least 18 years old to create an account or use Heala. Heala does not provide a child or teen service and is not designed for people under 18.
The age rating displayed by an app marketplace is a platform content rating and does not change Heala's own eligibility requirement. If an app store, family account, parental-control setting or other platform mechanism allows a person under 18 to download Heala, that does not make that person eligible to create or use a Heala account.
We use technical measures designed to prevent people who declare that they are under 18 from creating or using an account. We may request a date of birth, age or adult-eligibility declaration as part of account creation.
If the information provided indicates that the person is under 18:
- account creation will be blocked;
- the person must not use Heala;
- we will avoid collecting additional personal or health data through an account.
We do not knowingly collect personal information through Heala accounts from people under 18. If we learn that an account belongs to a person under 18, we may suspend or close the account and delete associated information, subject to information we are legally required or permitted to retain.
If you believe a person under 18 has created a Heala account, contact hello@heala.fit.
3. Information we collect
The information Heala processes depends on which features you choose to use.
Account and profile. Email address; name; Sign in with Apple identifier; account identifier; authentication and session information; date of birth or age; adult-eligibility status; consent records; Privacy Policy and Terms acceptance records; sex or gender where you choose to provide it; height; weight; goals; target information; fitness experience; equipment; profile image; language; units; country or region; preferences.
Training and movement. Workout programs; workout templates; exercises; custom exercises; sets; repetitions; resistance or weight; RPE; warm-up status; duration; distance; cardio sessions; workout notes; personal records; streaks; training volume; strain; progression information; workout analytics; workouts imported from connected services; outdoor workout routes when you use route tracking.
Nutrition. Food entries; meals; calories; macronutrients; water intake; food photographs; nutrition-label photographs; food descriptions; barcode searches; food-search queries; saved foods; recent foods; manually submitted foods; serving information; nutrition goals.
Sleep, recovery and connected health. Sleep logs; sleep duration; sleep stages; bedtime; wake time; steps; active energy; basal energy; workouts; heart rate; resting heart rate; heart-rate variability; body temperature; body mass; body-fat percentage; derived sleep scores; recovery scores; strain scores; readiness scores; trends and related analytics.
Body information. Weight; body-fat estimates; circumference measurements; body measurements; body-scan photographs; estimated skin tone; estimated body shape; generated 3D body-twin files; scan history; scan-credit activity.
Blood biomarkers and lab results. If you choose these features: laboratory blood values (for example glucose, lipid panel, blood count, liver and kidney values, hormones, vitamins); draw dates; lab-report photographs you submit for AI reading; and the biological-age estimate derived from your information.
Cycle and reproductive information. If you choose to use these features: period dates; cycle length; flow; symptoms; mood; energy; notes; reproductive context you voluntarily provide; contraception information; birth-control method; pill-adherence information; pregnancy-related context where voluntarily provided.
Habits and medications. Habit information; medication names; medication doses; schedules; reminders; adherence logs; notes. Medication functionality is intended for logging and reminders and is not a prescribing or clinical service.
AI information. When you deliberately use an AI feature: prompts; assistant conversations; relevant account context; voice transcripts; photographs; meal photographs; nutrition-label images; body images where required for a selected feature; generated output; model information; token usage; cost information; result status; safety and abuse-prevention metadata.
Purchases and subscriptions. Subscription tier; product identifier; billing platform; entitlement state; trial status; transaction identifier; renewal or expiration information; offer or promotional eligibility; scan-credit balance and history; billing country; provider-specific customer identifiers. Heala does not receive your complete payment-card number from Apple or Stripe.
Support. Email address; support messages; bug reports; screenshots; files you voluntarily attach; device/app diagnostic details; correspondence history. Do not send unnecessary health or other sensitive information in a support request.
Product feedback. Star ratings and any comment you choose to submit when Heala asks how a feature went or how you are finding the app; which screen the rating came from; and the app version, build, platform and language at the time. Ratings are linked to your account so that we can follow up on a problem you report. They are not published, and they are not an App Store review — a public review is written on the App Store and we cannot see who wrote it.
Device and technical information. Device type; operating-system version; app version; build number; language; IP address where received through ordinary network requests; push-notification token; integration status; sync status; crash or diagnostic information; security events; account-session information.
Friends and social. Profile card information (username, display name, profile image and the profile stats you enable); friend requests, friendships, blocks and reports; messages you send and receive, including text, photographs, video clips, voice messages and shared workout content; message reactions; challenge participation, including your challenge progress, daily activity within a challenge and streaks, which are visible to other members of that challenge; community membership and messages posted to communities you join; location-sharing status and sampled location points when you enable the friend map.
4. Advertising attribution and campaign measurement
Heala may use Meta and TikTok technologies for limited advertising attribution, campaign measurement, fraud prevention and, where permitted by law and platform rules, advertising optimisation. Heala does not display third-party advertising inside the core Heala service.
Subscription events sent on Heala's behalf. Heala's subscription provider, RevenueCat, may send purchase events — a trial starting, a trial converting to a paid subscription, a renewal — directly to Meta on Heala's behalf, using the advertising identifiers described above. This exists because those things happen on Apple's or Google's servers while the app is closed, and cannot otherwise be measured accurately. It carries the same restrictions as everything else in this section: only the fact of a subscription event, its amount and its currency, and never health information. It operates only where you have allowed advertising measurement, and stops when you withdraw that permission.
Depending on the platform, jurisdiction, consent status and configuration, advertising or attribution providers may process limited information such as device type; operating-system information; app version; IP address or ordinary network metadata; advertising identifier where permitted; installation information; app-open information; campaign source; campaign identifier; attribution information; generic registration completion; paywall interaction; trial conversion; generic subscription or purchase conversion; currency and transaction value where appropriate; consent or tracking status; and fraud-prevention information.
5. Health-data advertising firewall
Heala does not intentionally provide health, fitness or other sensitive Heala content to Meta, TikTok or other advertising partners for advertising, marketing, or other use-based data mining, including audience creation and profiling.
This includes Apple Health / HealthKit information; wearable health information; heart rate; HRV; sleep information; recovery scores; readiness scores; strain; weight; body-fat information; body measurements; calorie consumption; macro consumption; food or meal content; food photographs; nutrition-label photographs; workout content; exercise history; workout performance; cycle information; reproductive information; contraception information; pregnancy-related information; medication information; body-scan images; 3D body-twin information; precise outdoor routes; GPS coordinates; AI prompts; AI conversation content; voice transcripts; health-related photographs; and symptoms or medical information supplied by the user.
Allowing advertising tracking does not change this rule. Opting in to marketing email never changes this either. Advertising and attribution systems are intended to receive only approved, non-health marketing and attribution events.
6. Apple App Tracking Transparency
Where Apple's App Tracking Transparency framework applies, Heala requests the required system permission before engaging in activity that Apple defines as tracking. You may refuse permission.
Refusing tracking permission does not prevent you from using Heala's ordinary health, fitness, nutrition, body, recovery, AI or subscription functionality.
Where tracking permission is denied or restricted:
- Heala does not use the Identifier for Advertisers (IDFA) for tracking;
- we do not attempt to circumvent Apple's choice through device fingerprinting;
- advertising providers are configured according to the applicable restricted state;
- privacy-preserving attribution mechanisms may still operate where allowed.
Apple's tracking permission is separate from any additional consent required under applicable privacy law. If our use of tracking technologies changes, we will request permission through that prompt before the change takes effect.
7. Advertising consent and privacy choices
Where applicable law requires consent before using non-essential advertising, attribution or device-access technologies, Heala will obtain the relevant consent before enabling the affected processing.
Advertising consent is separate from acceptance of the Terms; acknowledgement of this Privacy Policy; HealthKit permission; AI permission; body-scan permission; blood-biomarker permission; and marketing-email consent.
You may be able to manage advertising preferences in Profile → Account & Privacy → Privacy Choices and through your device privacy settings.
Withdrawing optional advertising consent does not remove core Heala functionality.
8. Apple Health and Health Connect
Connecting a health store is optional, and Heala works without one. On iOS the store is Apple Health, reached through Apple's HealthKit framework; on Android it is Health Connect. Heala reads from whichever store the device has, and only after you grant the operating system's own permission. "Apple Health", "HealthKit" and "Health Connect" refer to the same data in this policy: information held by the platform rather than by Heala.
Depending on the features you choose, Heala may request access to information such as steps; heart rate; resting heart rate; heart-rate variability; active energy; total or basal energy; distance; body mass; height; body-fat percentage; basal body temperature; sleep; workouts or exercise sessions; and workout routes.
The two platforms do not hold identical information, and Heala does not pretend otherwise. Health Connect has no basal-energy record, so resting energy is derived only where another application has written a combined total and is otherwise left empty rather than estimated. Health Connect has no equivalent of Apple's sleeping wrist temperature, so that measurement is not read on Android at all and the features relying on it are unavailable there. Where a measurement is missing, Heala shows it as missing.
Heala reads only the data types you authorise. This information may be used for functionality such as dashboard information; workout import; cardio; body-history information; sleep; recovery; strain; readiness; cycle-related functionality where enabled; and trends and related analytics.
Permissions are requested per feature rather than in one grant. Basal body temperature is a fertility indicator and is requested only where you use cycle functionality; it is never included in a general health permission request on either platform.
Heala does not automatically bulk-copy every sample simply because permission exists. Information deliberately imported into a Heala feature may be saved to your Heala account where required to provide sync, history and related functionality. Other information may be read on-device or cached temporarily to provide a requested feature.
Where you separately grant write permission, Heala may write supported information that you enter into Heala back to the health store. We do not write false or inaccurate data back to Apple Health or Health Connect.
Health store advertising prohibition. Apple Health, HealthKit and Health Connect information is never used for advertising, advertising attribution, marketing audience creation or advertising profiling. It is not intentionally sent to Meta for advertising, to advertising networks, or to data brokers, and it is not sold or transferred. Advertising permission does not override this restriction.
Heala does not use Apple Health or Health Connect information to train general-purpose artificial-intelligence models.
You may revoke access at any time: through iOS Settings on Apple devices, or through the Health Connect application on Android. Heala treats a revoked permission as absent information rather than continuing from a cached copy. Revocation stops further reading; it does not by itself delete information already imported into your Heala account, which you may delete using the in-app deletion controls or by deleting your account.
9. Connected health services
You may optionally connect supported third-party services such as Oura, WHOOP, and Fitbit or supported Google health services.
When you connect a provider, Heala may process OAuth authorisation information; access and refresh tokens; and supported health or fitness records needed for the requested integration.
We use connected information only for functionality you request and purposes described in this Privacy Policy. Disconnecting an integration stops future access through that connection, subject to information already imported into your Heala account.
10. Location and outdoor cardio
Precise location is used only for functionality requiring it. If you deliberately start an outdoor run, walk or cycle and grant location access, Heala may use GPS to calculate route, distance, pace, speed and session information.
Route coordinates may be stored with the relevant workout so that you can review the session. Heala no longer trims the ends of a route, so a shared route begins and ends where the activity did — see the sharing warning below.
Heala does not intentionally provide precise workout routes or GPS coordinates to advertising partners. Location is not used to build health-related advertising audiences. You can revoke location permission in device settings.
Sharing warning. A route card can reveal where a workout began or ended. If you begin or finish a workout at your home or another sensitive location, the resulting route may reveal that location. Review route information before sharing it outside Heala.
Friend map (optional). If you deliberately turn location sharing on, Heala records your movement as sampled location points — a new point after roughly 75 metres of movement or five minutes stationary, never a continuous track — and shows your latest position and recent trace to friends you have accepted, subject to the visibility controls in the app. Ghost mode hides you and pauses recording without discarding your setup. Turning sharing off deletes your stored location points. Location sharing is off by default, collects only in accordance with your device permission, and is not used for advertising.
Background sharing (optional, off by default, asked separately). By default the friend map records only while Heala is open, so a walk with your phone in your pocket leaves no trace. You may separately choose to let it record while Heala is closed. That choice is made on its own screen that describes what is recorded, when, who can see it, the battery cost and how to stop; it is never bundled with another permission, never pre-selected, and your answer is recorded with the date and the wording you were shown. It requires the operating system's own "Always" location permission in addition to your answer here, and it stops immediately if either is withdrawn. The sampling rule above is unchanged: background points are the same sampled points at the same 75 metre / five minute spacing, not a continuous track. On Android a permanent notification is shown while it is running; on iOS the system location indicator is shown. You can stop it at any time by turning it off in Heala, using ghost mode, or revoking the permission in your device settings. If you do not turn it on, a route you record with a cardio session you started yourself may still appear, because that session already records your route with your permission.
11. Body scans and 3D body twins
When you choose a body-scan or body-twin feature, Heala may process photographs of your body. Depending on the feature, Heala may use one front image; front, side and rear images; or numeric body parameters.
Body-scan images may be sent to selected service providers to produce requested measurements or 3D output. Current services may include OpenAI or another disclosed AI vision provider for supported analysis; Tripo / VAST AI Research; and Clad for applicable numeric-parameter processing. The provider receives only information required for the requested feature.
Body images and derived body information are sensitive. They are not intentionally used to identify you; perform face recognition; build an advertising profile; create advertising audiences; personalise advertising; or train Heala's own general-purpose models.
Body imagery is not intentionally provided to advertising partners. You may delete supported body scans or delete your account.
12. AI and third-party AI services
Heala uses third-party AI providers to deliver features you deliberately request. Current providers may include OpenAI and the body-processing providers identified elsewhere in this Privacy Policy.
AI functionality may include assistant or coach responses; meal analysis; nutrition-label interpretation; workout generation; program generation; program auditing; image analysis; lab-report reading; and measurement estimation.
Depending on your request, Heala may send your prompt; relevant goals; relevant recent workouts; nutrition context; weight trend; recovery context; sleep context; meal image; nutrition-label image; lab-report image; body image; or voice transcript. We seek to provide only the information reasonably required to fulfil the request.
We do not intentionally send passwords, Apple authentication credentials or full payment-card information.
Where permission is required before personal information is disclosed to a third-party AI service, Heala provides an appropriate disclosure and obtains the relevant affirmative permission. You can choose not to use optional AI functionality.
Heala stores feature/model/token/cost and result-status metadata per account. AI operational metadata may be retained for reliability, safety, fraud prevention, cost control and abuse prevention. Conversation content may be stored where necessary to provide conversation history or another feature you request.
13. Sensitive and special-category information
Information processed by Heala may qualify as health data, special-category data, sensitive personal information or consumer health data under applicable laws. Examples include cardiovascular data; HealthKit information; sleep; recovery; body measurements; medication information; blood biomarkers and laboratory results; cycle information; reproductive information; body imagery; and precise fitness routes.
Where UK or EU data-protection law applies and special-category information is processed, Heala relies on an appropriate Article 9 condition in addition to an Article 6 lawful basis. Where explicit consent is the applicable condition, Heala seeks a specific affirmative indication and allows consent to be withdrawn prospectively. Withdrawal may mean the relevant optional feature can no longer operate.
Sensitive information is not sold for advertising purposes and is not intentionally used for advertising targeting.
14. How we store and secure information
Backend. Account information, feature information, consent records, billing state, referral state and integration records may be stored using Supabase/Postgres infrastructure. Access is protected using authentication and authorisation controls, including Row-Level Security where applicable.
Files. Private account files such as profile photographs, body-scan photographs, generated 3D body files and support attachments are stored using access-controlled storage. Private files may use time-limited signed links or similar controls.
Device. Authentication tokens are stored using supported secure operating-system storage where available. Heala may locally store preferences, temporary caches, pending offline writes, limited thread or assistant state, and other information required for app functionality.
Security measures may include HTTPS; authentication; access controls; restricted service credentials; least-privilege permissions; signed webhooks or links; security logging; monitoring; and deletion procedures.
No internet-connected system can guarantee absolute security.
15. Service providers and recipients
We disclose information only where reasonably necessary to provide, protect or operate Heala, comply with law, or where you have deliberately requested the relevant feature.
- Supabase — database, authentication, backend functions and storage.
- OpenAI — AI assistant, generation, food/label interpretation and supported image or measurement functionality.
- Tripo / VAST AI Research — body-image-to-3D processing.
- Clad — applicable body-generation processing using numeric body parameters.
- Apple — Sign in with Apple, HealthKit, App Store purchases, push services and other selected Apple platform functionality.
- RevenueCat — App Store product and entitlement management.
- Stripe — web checkout, payment processing, subscription billing, fraud prevention, billing portal and invoices.
- Oura, WHOOP and Google Health/Fitbit — only when you choose to connect the applicable service.
- Expo and operating-system push services — application infrastructure and push delivery.
- Resend — service and opted-in marketing email delivery.
- Cloudflare — website delivery, protection and localisation-related infrastructure.
- Map providers — depending on the feature, Mapbox, CARTO, Esri or Apple mapping functionality may be used to provide maps.
- Food data providers — USDA FoodData Central, FatSecret and OpenFoodFacts may be used for food or barcode searches.
- Meta — advertising campaign measurement, attribution and permitted optimisation.
The precise legal role of a third party can depend on the service and configuration. A third party may act as our processor/service provider for some processing and may process certain information under its own legal responsibilities for other processing.
We do not authorise advertising providers to receive Heala health content for advertising targeting.
16. Purchases and scan credits
Heala Pro and other eligible products may be purchased through Apple's App Store or Stripe on heala.fit.
Apple purchases. Apple processes the payment. RevenueCat may receive an app-scoped Heala identifier and relevant product, offer, purchase, receipt, transaction and entitlement information.
Stripe purchases. Stripe processes payment and billing information. Heala may create a Stripe customer associated with your account. Stripe may process email; payment information; billing information; billing country; and fraud-related information. Stripe processes and stores card details; Heala does not receive the complete card number.
Subscription deletion warning. Deleting the Heala account does not cancel an Apple or Stripe subscription automatically, and deleting your Heala account does not automatically cancel billing. You should cancel the subscription through the applicable billing provider before deleting your account if you do not want it to renew.
17. Notifications
Heala may provide local reminders and remote push notifications.
Local notifications may include workouts, habits, medication reminders and cycle reminders.
Remote notifications may include service reminders; milestones; referral status; billing or trial information; completed background tasks; account information; and important service notices.
A push token may be associated with your account. We seek to avoid unnecessary sensitive health detail in lock-screen notification content. You can manage notification permissions through Heala and operating-system settings.
18. Service and marketing email
We use Resend as our email-delivery processor. Resend may receive the recipient email address, message content and delivery metadata.
Service email. Service messages may include security notices; account notices; authentication information; purchase information; billing; trial information; referral information; export or deletion information; and important product or legal notices. These messages may be sent where necessary to provide the service, comply with law or protect the account.
Marketing email. Marketing messages may include feature announcements, promotions, product updates and fitness content. Where consent is required, marketing email is sent only after an affirmative opt-in.
Marketing consent is optional; separate from the Terms; separate from advertising tracking; and not required to use Heala. The box is never pre-selected for you. You are asked in the app and on heala.fit, and the answer is the same record in both places. You may unsubscribe from any marketing message, and every marketing email carries a working unsubscribe link.
What marketing is NOT based on. We do not use HealthKit information; wearable health information; cycle or reproductive information; medication logs; body scans; body-scan imagery; body measurements; nutrition history; workout performance; precise workout routes; or AI health conversations to segment, target or personalise marketing email or advertising audiences.
19. Food and exercise catalogues
Food searches may use Heala's own database/cache, USDA FoodData Central, FatSecret or OpenFoodFacts.
External food services receive the query or barcode and ordinary technical information required to provide the result. They are not intentionally sent your full Heala health history as part of an ordinary food search.
If you manually submit a food, it goes to an admin review queue and may be reviewed through automated and human quality checks. Approved catalogue information may be added to a shared food catalogue without publicly identifying you as the submitter.
Do not enter personal or sensitive information into food names or catalogue submissions.
20. Information you deliberately share
Heala includes social features. The information in this section is visible to other people because you choose to use those features.
Profiles. Your profile card — username, display name, profile image and the profile stats you enable — may be visible to other Heala users. You control what the card exposes in Profile settings.
Friends and messaging. Friendships require mutual acceptance. In a conversation, the messages you send — text, photographs, video clips and voice messages — are visible to the other participant, delivered through Heala's servers and stored until deleted. Deleting a message for everyone removes its content for both participants and leaves a "message deleted" marker. One-to-one messages are not routinely pre-screened; blocking and reporting are the enforcement tools, and Heala acts on reports.
Challenges. Joining a challenge shares your relevant progress with that challenge's members — totals, ranking, recent daily activity and streaks — for the duration of the challenge and in its final results. Challenge invitations identify you to the person you invite.
Communities. If you join a community, its members can see your membership and the messages you post there. Community access may in some cases be a paid product.
Friend map. See the Location section: while sharing is on, your latest position and recent trace are visible only to accepted friends.
Sharing outside Heala. You can deliberately share cards and links outside Heala, such as workout cards, body-progress cards, route cards, challenge cards and body-twin links. Once information leaves Heala through a share function, recipients may save, copy, forward or republish it. Heala cannot control copies that have already been shared outside the service. Review information carefully before sharing.
21. What we do not do
Heala does not intentionally sell HealthKit information; sell health information to data brokers; use HealthKit information for advertising; use wearable health information for advertising targeting; use weight history for advertising targeting; use meal contents for advertising targeting; use workout details for advertising targeting; use cycle or reproductive information for advertising targeting; use medication information for advertising targeting; use body scans for advertising targeting; use precise exercise routes for advertising targeting; use AI health conversations for advertising targeting; send health information to Meta to build advertising audiences; use body imagery for face recognition; or display third-party advertisements as part of the core Heala experience.
Heala does use limited advertising attribution and measurement technologies, namely Meta, as described above.
22. Legal bases under UK/EU data-protection law
Where UK GDPR or EU GDPR applies, different processing activities may rely on different legal bases.
Contract — Article 6(1)(b). Processing necessary to provide requested services may include account creation; authentication; logging; sync; programs; subscriptions; purchases; integrations; exports; and support.
Consent — Article 6(1)(a). Consent may apply to marketing; optional advertising or tracking; optional device permissions; and optional processing where consent is the appropriate legal basis.
Explicit consent — Article 9(2)(a). Where applicable, explicit consent may be relied on for optional processing involving special-category information, including certain connected health functionality; cycle/reproductive functionality; body-processing functionality; and AI health-context processing.
Legitimate interests — Article 6(1)(f). Where appropriate and not overridden by your rights, legitimate interests may apply to security; fraud prevention; abuse prevention; rate limiting; diagnostics; service reliability; catalogue quality; first-party product measurement; and aggregate operational statistics. We do not use legitimate interests to bypass a consent requirement that applies to tracking technologies.
Legal obligation — Article 6(1)(c). We may process information where required for tax; accounting; consumer protection; regulatory obligations; and valid legal requests.
23. International transfers
Some providers may process personal information outside the United Kingdom or EEA.
Where restricted transfers are subject to UK or EU data-protection requirements, we use an applicable lawful mechanism where required, which may include adequacy regulations or decisions; Standard Contractual Clauses; UK Addendum; International Data Transfer Agreement; or another legally recognised safeguard.
Contact hello@heala.fit if you require information about applicable transfer safeguards.
24. California
Where applicable California privacy law gives you rights, these may include knowing/access; correction; deletion; portability; opting out of qualifying sale or sharing; and protection against unlawful discrimination.
Heala does not sell health information. Heala does not intentionally use sensitive health information for advertising targeting.
Limited device, attribution and generic conversion information may be processed by Meta as described in this Privacy Policy. Where applicable law treats a particular activity as "sharing" for cross-context behavioural advertising, applicable opt-out rights will be honoured.
25. Washington consumer health data
Where Washington's consumer-health privacy law applies, Heala may process consumer health information including health measurements; fitness information; sleep; nutrition; weight; body information; reproductive/cycle information; medication information; health-related AI information; and precise location associated with a fitness activity.
Sources. Information may come from you; Apple Health; wearable services you connect; or information inferred or derived from data you provide.
Purposes. Consumer health information is used to provide the health and fitness services you request.
Sharing. Consumer health information may be disclosed to service providers where necessary to provide requested features, secure the service or otherwise as permitted by applicable law. Consumer health information is not intentionally disclosed to Meta for advertising targeting.
Rights. Where applicable, you may have rights to confirm processing; access information; request information about certain recipients; withdraw consent; request deletion; and appeal certain decisions.
Requests may be submitted using in-app privacy tools or hello@heala.fit. We do not sell consumer health data.
26. Your privacy rights
Depending on applicable law, you may have rights including access; correction; deletion; portability; restriction; objection; withdrawal of consent; advertising opt-out; and regulatory complaint. We do not unlawfully discriminate against you because you exercise a privacy right.
Export. Use Profile → Account & Privacy → Export My Data, or contact us where necessary.
Correction. Edit supported fields within Heala or contact us.
Delete. Use Profile → Account & Privacy → Delete account, in the app. Account deletion is designed to remove applicable account-owned live information including authentication identity; profile information; health information; workouts; nutrition; sleep; cycle information; habits; medication logs; AI account history where applicable; integration credentials; push tokens; private body images; and generated body files.
Narrow legal, accounting, fraud-prevention, dispute and backup retention may continue where permitted or required.
Withdrawal. You may withdraw relevant consent prospectively. Withdrawal does not make processing that occurred lawfully before withdrawal unlawful.
27. Retention
We keep information only for as long as reasonably necessary for the applicable purpose, subject to legal obligations.
Unless another requirement applies:
- active account feature history — while required to provide history, trends and sync;
- security/access/delivery logs — up to 12 months;
- anti-abuse/rate-limit information — up to 90 days;
- temporary OAuth state and signed URLs — minutes to days;
- operational AI metadata — up to 12 months;
- support cases and attachments — up to 24 months after closure;
- deleted private media in encrypted backup cycles — targeted for removal within 35 days;
- marketing consent records — while relevant and for up to 24 months after withdrawal where required to evidence consent;
- advertising/privacy choice records — as reasonably required to evidence and honour the choice;
- transaction/tax/accounting records — up to seven years or the applicable statutory period;
- records relevant to legal claims or regulatory matters — for as long as reasonably required for the matter.
When an account is deleted, live account data is removed according to the deletion process, subject to the limited retention above. Independent platforms such as Apple and Stripe may retain their own records under their own legal responsibilities.
28. Security incidents and breaches
Heala maintains processes designed to identify, investigate and respond to security incidents.
Where applicable law requires notification following a personal-data or consumer-health-data breach, we will provide the legally required notifications to affected individuals, regulators or other parties.
29. Changes to this Privacy Policy
We may update this Privacy Policy when features change; service providers change; advertising technologies change; our data practices change; platform requirements change; or laws or regulatory requirements change.
We will update the date and version. Where a change requires additional notice or new consent, we will provide that notice or request before the affected future processing begins.
30. Website visitors
This section applies to heala.fit.
The website may process ordinary connection information; approximate country information; language; referral/UTM information; first-party funnel events; a random session identifier; and an unfinished onboarding plan stored in browser storage.
Forms. The support form and the creator application form on heala.fit collect what you type into them — your name, email address, the organisation you give where you give one, and your message — and deliver it to Heala's support address. See the Support entry in the section on information we collect, and the section on the creator and partner programme.
The website may query Heala systems to display pricing, public statistics and publicly available product information.
Advertising measurement on heala.fit. The website uses the Meta Pixel and the TikTok Pixel to measure advertising campaigns. Neither loads, and neither sets a cookie, until you have been asked: in the United Kingdom, the European Economic Area and Switzerland the pixels stay off until you accept them, and elsewhere they run with an option to decline. Your choice is stored on your device and can be changed at any time.
Where you accept, Heala may also send the same conversion from its own servers, so that a measurement is not lost to an ad blocker or a closed tab. Each event carries an identifier shared with the browser copy so that the two are counted once rather than twice. Your email address is never sent to an advertising partner in readable form; where it is included, it is reduced to an irreversible hash first.
These events are deliberately generic: that a page was viewed, that an onboarding flow was started, that someone joined the waiting list. No health, nutrition, body, cycle, medication or AI-conversation information is included, in line with the health-data advertising firewall described above.
Health information is not intentionally used to create website advertising audiences.
Privacy questions, access requests, deletion requests and other privacy matters: hello@heala.fit — Heala LTD, company number 11111111, registered in England and Wales, Apartment 1219 Nobel Way, Uhaus Vita Living East, Manchester, England, M1 7FY.
31. Android, Google Play and device identifiers
This section applies to the Android application distributed through Google Play.
Google Play billing. Where you purchase a subscription or other paid item on Android, the transaction is processed by Google Play under Google's own terms. Heala receives confirmation of entitlement and related purchase metadata through its subscription provider; Heala does not receive or store your full payment-card details.
Push notifications. Android push messages are delivered through Firebase Cloud Messaging, a Google service. A device push token is stored so that messages can be addressed to your device, and message content is limited to what is necessary to display the notification. Push may be disabled in the operating system at any time.
Advertising identifier. The Android advertising identifier is used only for advertising attribution and campaign measurement, and only where you have given the applicable permission and local law allows it. It is not used to target advertising at you inside Heala, is not combined with your health, nutrition, body, cycle or medication information, and is not sold. Where permission is refused or withdrawn, the advertising identifier is not collected and the advertising provider is configured to a restricted mode. You can reset or delete the identifier at any time in your Android settings.
Health Connect. Information read through Health Connect is handled as described in the section on Apple Health and Health Connect, and Heala's use of Health Connect complies with the Health Connect Permissions policy, including the restrictions on advertising use, sale and transfer of health information.
Deletion. Deleting your Heala account deletes the information held in your Heala account, including information previously imported from Health Connect. Deleting information inside Health Connect itself is done in the Health Connect application and does not require Heala.
32. Home Screen and Lock Screen widgets
Heala offers optional widgets that you can add to your device's Home Screen and, on iOS, the Lock Screen. Adding one is your choice. Heala works without them and no widget appears unless you place it yourself.
A widget shows information you already track in Heala — for example steps against your goal; calories and macros logged today; habit or medication progress; your recovery score; your training week; or cycle information where you use that feature. To draw it, the app writes a small summary of that day's figures into an area of the device that only Heala and its own widget can read (an App Group on iOS, application-private storage on Android). That summary stays on your device and is not sent anywhere.
The steps widget also reads today's step count from Apple Health or Health Connect at the moment it draws, so the number is current even when the app is not running. It uses the permission you already granted for steps and reads nothing else.
Please consider what this means in practice. Information placed on a Home Screen or Lock Screen can be read by anyone who can see your device, and on iOS a Lock Screen widget can be read without unlocking it. Some of that information is health information. Choose which widgets to add with that in mind.
You can remove a widget at any time using your device's usual controls, which stops it drawing. Signing out of Heala clears the stored summary.
33. Creator and partner programme
This section applies if you apply to, or take part in, the Heala creator programme, and to Heala users who arrive through a creator's link or code.
If you apply. The application form on heala.fit collects your name, email address, social handle, platform, the organisation you give where you give one, your preferred language and the message you write. It is used to assess the application and, if we go ahead, to run the partnership. You may ask us to delete an unsuccessful application at any time.
If you become a partner. Heala holds a partner record — name, handle, platform, contact email, your code and link, commission rate, status and internal notes — together with a payout ledger recording each period, currency, amount, status, reference and payment date. Payments are made outside Heala by ordinary bank transfer or a payment service; Heala does not hold your bank details.
If you arrive through a creator. Heala records which creator you were attributed to and when, the link or code used, and the subscription revenue attributable to you for the period, so that the creator's commission can be calculated. This is subscription and attribution information only. It is not combined with your health, nutrition, body, cycle, medication or location information for this purpose, and it is not used to target advertising at you.
What a creator can see. A creator sees counts, sums and dates for their own code — never your identity, your account, your messages or any health information. Country figures below a small threshold are grouped together so that a small number cannot become a person.
Retention. Partner records and payout ledgers are kept for as long as the partnership runs and afterwards for the period required by tax and accounting law. Attribution records are kept for as long as the commission they support may still be calculated or audited.
Website visitors
This section applies only to heala.fit, the marketing website — not to the Heala app, whose policy is reproduced verbatim above.
- The marketing homepage sets no advertising cookies and loads no third-party advertising or behavioral-analytics SDK.
- The optional /start planning flow stores an unfinished plan and a random session identifier in browser storage, and sends first-party funnel events (step, device/browser context, referral/UTM context, and approximate Cloudflare edge geography) to Heala's backend so we can understand and improve completion. It does not create a Heala account.
- The website also makes anonymous, read-only requests to Heala’s backend to display current prices and public statistics.
- To quote a price in your own currency, the pricing sections ask Cloudflare for the two-letter country your IP resolves to. The country is used to pick a price and is not stored, logged against you, or combined with anything else. Turning it off is not possible from the page, but nothing about you leaves your browser to make it work — only the country comes back.
- We do not sell website activity or share it with advertisers.