Privacy policy

Your records, your connections, and how Haviora uses them.

The short version

Your account can sync health-related records. Requested AI features share relevant information with Anthropic. You control device connections and can request account deletion. The details—and the limits of those controls—are below.

Health processing and AI choices

The updated app asks for explicit health-processing permission before health features start. Sharing with Anthropic (Claude) is a separate, optional choice. Both start off, are saved by account and version, and can be changed in Settings → Privacy & data → Health data & AI sharing. A new consent version requires a fresh choice.

Manual tracking remains available without AI sharing. Turning off AI sharing blocks future coaching, plans, reviews and photo analysis and turns off menu sharing. Turning off health processing pauses health features and new device imports and revokes care-team access. Already-sent requests cannot be recalled. Stored history remains until deletion; deletion and sign-out stay available without permission.

Menu comparisons additionally require their feature-specific sharing choice. Device permissions and photo-submission actions remain separate controls. These changes are under test, not a claim that older installed builds already have them.

Who is responsible

This notice describes the Haviora iPhone app and the website at haviora.app. Riddec Estonia OU, Estonia, operates Haviora and is the controller responsible for the processing described here. The owner-provided address is Laeva 1, Tallinn, 10115, Estonia.

Contact us with privacy questions or requests at [email protected]. This is also the contact for support and account-deletion requests.

Information Haviora handles

Account and profile
Email address, authentication information, name and the profile details you provide, such as age, goals, preferences and health-related notes. Social sign-in supplies account identifiers and the profile details shared by the sign-in provider.
Records you enter
Check-ins, mood and energy, meals and nutrition, workouts, weight, medications and medication logs, reminders, reflections, goals and any lab values you choose to enter.
Connected-device readings
With your permission, supported Apple Health or Oura readings, including sleep, activity, workouts, heart rate, heart-rate variability and other supported measurements. Available data depends on the device, permissions and recorded history.
Conversations and AI features
Your requests, relevant context, coach messages, generated plans and reviews, and any feedback you choose to submit.
Photos
A meal or menu photo you select for analysis, plus your request or portion description. Selecting a menu photo alone does not send it for analysis.
Service and subscription records
Account and device identifiers, sign-in sessions, notification tokens and preferences, subscription entitlements and transaction information, sync versions, usage counts and security/abuse-prevention records.
Support
Your email address, message and attachments when you contact us. Please send only what is needed to explain the problem.

Why it is used

Haviora uses this information to operate your account; save and sync your records; show your history and trends; provide requested wellness suggestions; manage device connections, reminders and membership; answer support requests; and protect the service from misuse.

Health-related information is sensitive. AI suggestions are not medical decisions, diagnoses or clinical assessments. Haviora does not make employment, insurance, credit or other similarly consequential eligibility decisions about you.

Legal-basis review: the final notice must identify the applicable basis for each purpose and the additional condition for sensitive health information, including consent where required. Contractual service provision, consent, legal duties and justified security interests must be assessed against the operator’s location and the markets served; they are not interchangeable.

Apple Health and Oura

You choose whether to connect a supported source. Apple Health access is controlled on your iPhone; Oura uses an authorization flow rather than asking Haviora to store your Oura password. Readings may be saved to your Haviora account so they can appear across your signed-in devices and support features you request.

Manage connections in Settings → Connected devices. You can also review Haviora’s permissions in Apple Health or revoke access through the source provider. Disconnecting stops future access through that connection; it does not automatically delete readings already saved in Haviora or the source app.

HealthKit data must not be used for advertising or sold to data brokers. Haviora’s reviewed app does not include advertising SDKs. Connecting a device is separate from permission to send information for an AI photo comparison.

AI and photo processing

Haviora uses Anthropic (Claude) for AI coach replies, plans, reviews and photo analysis. Requests pass through Haviora’s backend. The provider receives the input needed for the feature, which can include sensitive health information.

  • Coach and plans: your request and relevant profile, goals, health readings, workouts, meals, check-ins, active medication information, reflections and conversation history.
  • Menu comparison: your photo and request, food preferences and relevant synced nutrition, sleep, recovery, check-in, workout, profile and medication context. Menu-sharing permission is remembered for the account and can be turned off in What to order. It does not authorize other AI features.
  • Meal-photo analysis: the food photo and portion description. Review the result and choose whether to save a meal; analysis alone does not create a meal record.
  • Safety and quality checks: an additional AI request may review relevant input and generated output. This is a fallible automated check, not clinical validation.

Menu images are resized and location metadata is removed before analysis. Avoid faces, documents and unrelated private details. Haviora does not save menu images or comparisons in its database or durable app storage; leaving that screen clears the in-memory result. Temporary files may remain in the device’s system-managed cache. Meal-photo analysis does not itself save an image or meal to the server database.

Saved coach conversations, plans and records have different retention from temporary photo results. Turning off sharing cannot recall an already-sent request. Anthropic’s processing and retention terms also apply; this is not a promise of zero provider retention. Provider contract, retention and model-training settings must be verified before the final policy is approved.

Read Anthropic’s privacy information. A policy does not replace clear in-app disclosure and permission before sensitive information is sent.

Services that receive information

Haviora relies on these services for the functions described below. They receive information relevant to their role, not unrestricted access to every feature.

Render
Backend hosting and the account database, including records sent to Haviora for sync and processing.
Anthropic
Requested AI generation, photo analysis and related automated quality/safety checks, as explained above.
Apple and RevenueCat
App Store purchases, transaction status and subscription entitlement management. Haviora does not receive your full payment-card number from Apple.
Oura; Apple Health on your device
The device connections you choose to authorize. Their own services and privacy controls also apply.
Resend
Account verification and password-reset emails, including the recipient address and one-time code.
Expo and Apple push services
Notification delivery using device tokens. Haviora’s reminder messages are designed to avoid health readings, medication names and dosages on the lock screen.
Google Workspace
Email correspondence sent to the Haviora mailbox.
Cloudflare
Website delivery and associated request/security processing, such as IP address, requested URL and browser information.
USDA FoodData Central
Food searches and food identifiers requested through Haviora’s backend when that feature is configured. This lookup does not require sending your full health profile.

If you approve care sharing, the approved clinician can access the information provided by that feature. Review and revoke access under Settings → Care sharing. Revocation cannot erase copies already lawfully obtained outside Haviora.

Information may also be disclosed where required by applicable law, to protect people and the service, or in a business transfer subject to applicable safeguards. The reviewed product does not contain an advertising-data sale or targeted-advertising integration.

Storage, retention and deletion

The app keeps downloaded records and queued changes on your device. Account records are also stored on Haviora’s backend. This is not end-to-end encryption: authorized backend processing and requested AI features need access to relevant information.

Account, health history and saved conversations
Kept while your account exists, unless you delete supported individual records or the account. Withdrawal pauses future processing; it does not automatically erase stored history. Account deletion remains available without health permission.
Operational and security records in the beta
The proposed 30-day routine and 90-day security cleanup schedule is not enabled. These records may remain longer than the proposed periods. Account-linked usage, security and delivery records are removed from the primary database where covered by account-deletion cascades; provider and backup copies have separate handling. There is no fixed automatic expiry promise for these beta records.
Short-lived service records
Existing housekeeping expires normal push receipts after 24 hours, sign-in challenge/state records one day after expiry, account tokens seven days after expiry, and refresh tokens 30 days after expiry. Cleanup happens on scheduled runs rather than at the exact expiry instant.
Permissions and allowances
Versioned permission decisions and timestamps, subscription entitlements and lifetime Free allowances stay associated with the account. Permission events contain no health values, messages or photos and are removed with the account from the primary database.
Support correspondence
The proposed 12-month-after-resolution deletion procedure is not yet active and verified in Google Workspace. Contact [email protected] to request deletion; do not assume automatic expiry after 12 months.
Backups and provider copies
These follow each provider’s configuration and contract. Deleting a primary account does not promise immediate deletion from backups or already-sent AI requests. Provider-specific periods and restored-backup handling remain to be verified before publication.

Health-processing withdrawal also revokes active care-team access. Neither withdrawal nor deletion can recall copies already received by another provider or clinician. Deleting Haviora does not cancel Apple billing.

Providers may process information outside your country. A database in Frankfurt does not establish EU-only processing. Transfer locations and safeguards remain publication checks. No EU-only processing, zero provider retention or absolute security guarantee is made.

Your choices and requests

  • Device access: review or disconnect sources in Connected devices and the source provider’s settings.
  • Menu sharing: turn it off in What to order. You can still log meals manually.
  • Reminders: change them in Settings → Reminders or your iPhone notification settings.
  • Downloaded data: Settings → Privacy & data → Remove data → Clear downloaded data & sign out.
  • Cloud account: in the same Remove data section, choose Delete cloud account and complete the confirmation. Cancel Apple subscriptions separately.
  • Care sharing: review and revoke approved access in Care sharing.

Depending on applicable law, you may have rights to access, obtain a copy of, correct or delete personal information; restrict or object to processing; withdraw consent; and complain to a privacy regulator. Withdrawing consent does not undo processing already lawfully performed.

For a request you cannot complete in the app, contact [email protected]. Identity verification may be needed to protect your account. Never email your password or verification code. You can also contact Estonia’s Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority in the place you live, work or where the alleged infringement occurred, as applicable.

Website, cookies and diagnostics

The current marketing site is a static preview. Its launch-update form is a demonstration: it does not send, save or subscribe the entered email. The site code does not include advertising or analytics trackers. Hosting may still process technical requests. A future working signup or analytics service will need an updated notice before collection starts.

The app uses local storage for records, preferences and offline changes; that is separate from website cookies. If you choose “Send minimal diagnostic” after an app screen error, that report contains the error category and platform, not health records, message text, photos or an error stack. Ordinary server/security logs are separate.

Age policy and changes

Haviora is for adults aged 18 and over. The owner has approved this eligibility rule. The new app asks new and existing account holders to confirm their age before using health features. Social sign-in is not proof of age. This is a self-declaration, not identity-document verification, and it is separate from permission to process or share health information.

Someone who cannot confirm eligibility can sign out or delete their account. Please contact [email protected] if a child has supplied information. The matching controls must be deployed before this draft becomes effective.

The final policy will show its effective date. Material changes will be communicated as required by applicable law, with fresh permission where needed for a new use of information. External services have their own terms and privacy notices.

Draft updated 21 September 2026.