Privacy Policy

Review draft — October 4, 2026. Pending legal, retention and deployed-practice verification. This is not a newly effective agreement.

1. Who we are and scope

Ellara Health LLC operates Ellara, an adults-only wellness app. This policy describes account, health, location, device, subscription, sharing, support and website information handled to provide our services. This October 4 review draft must be reconciled with deployed configuration and approved retention decisions before publication.

2. Account and eligibility information

We use your email address and sign-in credentials or Apple/Google sign-in information to create and secure your account. A display name is optional. Enrollment asks for age in years and records adult eligibility, the time of acknowledgement, and the accepted terms version. We do not request your date of birth. Fitness age, delivery dates and pregnancy information you enter are separate from date of birth. Accounts for people under 18 are not permitted; contact Support to report an underage account.

3. Health and wellness records

When you separately allow health features, the records you choose to enter may include cycle and period dates, symptoms and severity, mood, sleep, notes, selected conditions, pregnancy outcomes and postpartum information, meals and nutrition, workouts, and fitness details such as height, weight, age and activity level. Ellara uses these records for logs, charts, estimates and personalized wellness suggestions. Declining or withdrawing health consent turns health features off; it does not automatically delete previously saved records. Support, rights and account deletion remain available.

4. Precise location, background tracking and maps

GPS tracking is optional. For an outdoor activity, Ellara collects positions and timestamps to display your route and estimate distance, pace and calories. Route points are stored on your device and are saved to your cloud account when you save the activity. A separate background-location choice allows collection during an active activity while the screen is locked or the app is in the background. Indoor/manual distance entry is available without GPS.

Map tiles use OpenStreetMap, or CARTO when that map integration is configured. Tile requests reveal the area displayed and ordinary network request information to the map provider. Tiles may be cached on your device. Stop the activity or withdraw location choices in Health settings to stop collection; device operating-system permissions are managed separately. Withdrawing a choice does not delete previously saved routes.

5. Optional health-platform and watch sync

Apple Health and Google Health Connect have separate choices for steps, workout import and workout export. Enabled sync may handle activity type, date, duration, distance, calories and external record identifiers. Imported workouts are saved in your Ellara account. Exported records can be available to other apps you authorize in the destination platform. Turning a choice off stops future sync but does not remove saved or exported records or revoke operating-system permissions. Watches can queue activities while disconnected and transfer them when reconnected.

6. Guidance requests and service providers

The app sends relevant cycle, symptom, condition, pregnancy/recovery and fitness context to Ellara’s content API to calculate wellness suggestions and estimates. Application logging is designed to omit health/GPS request values. Infrastructure, database, authentication, hosting and vendor systems may retain operational metadata or request information under their configurations; we do not promise that every service keeps no request history.

Supabase supports account authentication and cloud records. Email delivery can involve Resend, with support messages handled by the configured inbound mail and forwarding providers. RevenueCat manages subscription entitlement information associated with your Ellara account identifier; Apple or Google processes store purchases. Website/API hosting, maps, email and these vendors handle information needed for their services. Their deployed configurations, access and retention must be confirmed for the final policy.

Offline recommendation-catalog embedding jobs use OpenAI for catalog content. That source observation does not establish that personal health records are submitted to OpenAI, and the final policy requires verification of deployed jobs and any other AI data flows.

7. Exports and copies

Exported workout records and files you choose to share may be available to other apps or people you authorize. Copies saved by recipients or stored in a destination platform are controlled by that recipient or platform. Turning off future exports or deleting your Ellara account does not retract independent copies, screenshots or previews. Contact Support for questions about these limits.

8. Device storage, security and access

Ellara stores device copies needed for charts, favorites, health-sync state, route recovery and map display. Native sign-in sessions use the device keychain or keystore; the web app uses browser storage. Cloud records are tied to their account and protected through access controls. Authorized administration, service operations and reviewed support actions may require access. These controls reduce risk but do not guarantee perfect security or mean that no operator can access records.

9. Billing, support, website and operational information

Subscription services handle purchase, entitlement and transaction information; payment and refund processes are governed by the store where you purchased. Account deletion does not cancel a store subscription. Support inquiries contain your contact information, message and any attachments you choose to send. Do not send unnecessary medical records. Website and API services receive ordinary request information. API rate-limit history includes API-key identifier, route template, status and time; logs, backups and provider records have separate handling and retention.

10. Your choices and privacy requests

Review or correct your entries in the app, withdraw optional health/location/sync choices in Health settings, and delete individual entries or your account. For access, a copy, correction, deletion, consent withdrawal or an appeal where applicable, contact [email protected]. We verify account ownership before fulfilling requests and review the rights and response requirements that apply to the request. We do not require you to send health records to establish identity.

11. Retention and deletion

Account deletion removes active account records and coordinates device cleanup. Device cleanup can require a retry; a disconnected watch, exported health records and copies held by other people have separate limits. Backups, support cases, operational records, billing records and reserved public-link codes may have distinct retention and legal handling. The final policy must state approved periods, triggers and exceptions after retention review; this draft does not invent a period or promise total immediate erasure.

12. Updates and contact

Material changes will be identified with a policy version and the applicable notice or acknowledgement process. Changing a website draft does not change the terms version recorded in existing assent receipts. Contact Ellara Health LLC through Support for questions, security concerns or privacy requests. Data-region, international-transfer and vendor arrangements require verification before the final policy is published.

Ellara Health LLC — [email protected]. Support · Data deletion · Terms of Service