At Smarty Wellness (smartywellness.com) we value your privacy and are committed to protecting your personal data. This Privacy Policy explains how Smarty Wellness collects, uses, stores, and protects your information when you use our wellness guidance service. Our practices comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the ePrivacy Directive 2002/58/EC, and applicable data protection laws worldwide.
1. Data We Collect
Account & Profile Data
- Name, email address, and password (stored hashed) when you create an account.
- Optional profile information: display name, timezone, and notification preferences.
- Billing information needed to process any membership payment (handled by our payment processor — we do not store full card numbers).
Wellbeing & Lifestyle Data
- Self-reported information such as age, life focus areas, daily energy, mood, sleep, stress and focus ratings, and personal notes you write.
- Your missions, challenges, bucket-list goals, journey history and review entries.
- Wellbeing-related answers you choose to provide, which may reveal information about your physical or mental health.
Usage & Technical Data
- Technical data such as IP address, browser type, device type, and operating system.
- Aggregated usage analytics (which features you use, missions completed).
2. How We Use Your Data
- Generate your personalized daily missions, coach guidance and recommendations.
- Adapt guidance to your focus areas, energy level and preferences.
- Save your check-ins and journey history so you can track progress over time.
- Process any membership payment and manage your subscription.
- Send transactional emails (account, billing, security) and, with consent, product updates.
- Improve Smarty Wellness through anonymized, aggregated analytics.
- Ensure legal compliance and platform security.
We will never sell or rent your personal data to third parties.
3. Legal Basis for Processing (GDPR Article 6)
- Consent (Art. 6(1)(a)): Marketing emails, optional analytics.
- Contractual necessity (Art. 6(1)(b)): Running your account, generating guidance, processing any membership payment, and saving your journey history.
- Legal obligation (Art. 6(1)(c)): Record keeping, tax compliance, fraud prevention.
- Legitimate interests (Art. 6(1)(f)): Service security, product improvement.
- Health-related self-reports (Art. 9(2)(a)): Mood, stress, sleep and similar entries are processed only with your explicit consent and used solely to make your guidance more relevant. We do not share them for any other purpose.
4. Data Sharing & Sub-Processors
- Cloud hosting provider — database hosting and authentication.
- AI provider(s) — used only to generate your personalized guidance. No direct identifiers (name, email) are sent to the AI provider unless strictly required.
- Payment processor — securely handles any membership billing.
- Email delivery provider — for transactional and (with consent) marketing emails.
All processors are required to comply with GDPR standards and maintain appropriate technical and organizational security measures.
5. Data Retention
- Account data: retained while your account is active and deleted when you delete your account, except where short operational backup windows or legal obligations apply.
- Check-in & journey data: retained while your account is active and deleted with your account.
- Transaction records: retained for 7 years as required by tax law.
- Marketing preferences: retained until you withdraw consent.
- Anonymized analytics: may be retained beyond account deletion in fully anonymized form.
6. Your Rights Under GDPR
- Right of Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17) — delete your account and data from settings.
- Right to Restrict Processing (Art. 18)
- Right to Data Portability (Art. 20) — download your data in JSON format.
- Right to Object (Art. 21)
- Right to Withdraw Consent (Art. 7)
- Right to Lodge a Complaint with your local data protection authority.
7. Security Measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Hashed passwords and secure session management.
- Row Level Security (RLS) ensuring each user can only access their own data.
- Strict access controls and least-privilege principles.
- Regular dependency, infrastructure, and security reviews.
8. Cookies & Local Storage
Smarty Wellness uses cookies and local storage for the following purposes:
- Essential: authentication tokens, session security, fraud prevention.
- Functional: UI preferences, check-in and mission progress.
9. Children
Smarty Wellness is intended for users aged 18 and over. Users between 13 and 18 may only use Smarty Wellness with parental or guardian supervision and consent. We do not knowingly collect data from children under 13.
10. International Transfers
Your data is primarily processed within the EU. Where transfers outside the EU are necessary, we rely on Standard Contractual Clauses or other lawful transfer mechanisms approved under GDPR.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via the app or email.
12. Contact
Data Controller: Smarty Wellness (smartywellness.com). Contact smartywellness@outlook.com.