Skip to content
ComniWell

Privacy Policy

Last updated: September 9, 2026

Who we are

ComniWell ("ComniWell", "we", "us") is a health & fitness app built by ComniWell, a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KVK) under number 42155849, at Hoogstraat 16, 7512 GX Enschede, Overijssel, Netherlands. Contact: [email protected]. We are the data controller for your personal data under the GDPR.

Our approach: local-first

ComniWell is local-first. Your data is stored primarily on your device and synced to our backend (Supabase, hosted in the EU) so you can back it up and use it across devices. We do not sell your data, and we do not use it for advertising.

What we collect

Only what the app actually needs to run the features you use:

  • Account data: your email address, for sign-in and account emails.
  • Health & fitness data you enter: workouts and training, nutrition and food logs, gut-health entries, supplements and compounds you log, biomarkers you record, habits, body measurements, sleep, resting heart rate, and related notes.
  • Health Connect data (Android, only with your permission): where you connect it, we read data such as activity, heart rate, and sleep from Android Health Connect to show it alongside your other data, and it may be included in an "Ask your data" answer if relevant to your question (see below). You control this permission and can revoke it at any time in Health Connect.
  • Camera & meal photos (only when you use the AI meal-estimate feature): the photo is sent to our AI backend, which calls Anthropic's Claude API to estimate nutrients, then returns the estimate to your device. We do not store the photo anywhere; it exists only for the duration of that one request and is discarded once the estimate is returned.
  • Recipe text you paste to import a recipe: sent to our AI backend to structure it into ingredients and quantities. The AI only extracts structure; it does not invent nutrition data.
  • Free-text questions you type into "Ask your data": your question is sent to our AI backend, which fetches only the specific categories of your own logged data (for example workouts, nutrition, habits, biomarkers, or Health Connect activity/sleep/heart-rate data) needed to answer that question, capped at the last 90 days, so Claude can generate a plain-language answer grounded in your real data.
  • Basic technical data: app version and, when a request to our backend fails, a short error report (the endpoint called, the status code, and a truncated error message) so we can find and fix problems. This does not include your health data or any photo/image content.
  • We do not currently use any third-party analytics or advertising SDK, and we do not track you across other apps or websites.
  • We do not currently collect a push notification token. Reminders (workout, water, habit, etc.) are scheduled locally on your device and never touch our servers.
  • Subscription data: not applicable yet. ComniWell is currently free to use. If we introduce a paid subscription in the future (planned via Google Play Billing, managed through RevenueCat), this section will be updated first, and Google Play — not us — will process your payment details.

How we use your data

To provide and sync the app's features; to generate AI estimates and answers from data you submit; to authenticate you and send account emails (sign-up confirmation, password reset); to send the local reminders you've enabled; to keep the service secure and fix problems. That's it — we don't use your data for advertising, and we don't sell it.

Legal bases (GDPR)

  • Contract — to provide the app you signed up for.
  • Explicit consent (special-category data) — we process your health data only with your explicit consent, given when you start using the app's health features, withdrawable at any time (Art. 9 GDPR).
  • Consent — for optional features like Health Connect access and local notifications, withdrawable any time.
  • Legitimate interests — to keep the service secure and functioning (e.g. the error reports described above).

Automated processing

Our AI features (meal-photo estimates, recipe import, ask-your-data answers, trend narration, program generation) are automated but informational only. They don't produce legal or similarly significant effects, and we don't use them to make automated decisions about you. Outputs are always framed as estimates or narration, never as exact figures or medical interpretation.

Health data — special care

Health data is sensitive. We process it only to provide the app's features, only with your consent where required, and we never sell it or share it for advertising. Health Connect data (activity, heart rate, sleep) is shown back to you in the app, and may also be included when it's relevant to answering your own question in "Ask your data" — under the same AI safeguards described above, never for any other purpose. Revoking a permission stops that processing.

Supplements, peptides, and compounds you log are treated as neutral data — we record what you tell us without judgment, and we never use it to recommend, endorse, or provide dosing guidance.

Who we share data with (processors)

A small number of service providers who process data only on our instructions, never as data they can use for their own purposes:

  • Supabase — authentication, database, sync, and account emails. Hosted in the eu-west-1 (Ireland) region.
  • Open Food Facts and USDA FoodData Central — public food-database lookups (barcode/text search terms only, no account-identifying data).
  • ComniWell's own AI backend, which calls Anthropic's Claude API server-side — for meal-photo estimates, recipe import, ask-your-data answers, and trend narration, as described above.
  • Google Health Connect — on-device, under your permission (Android only).
  • RevenueCat + Google Play Billing — not in use yet; will be added when a paid subscription launches, and this section will be updated first.

We do not sell your data or share it with data brokers or advertisers.

Where your data is stored / international transfers

Your Supabase-synced data is stored in the eu-west-1 (Ireland) region, within the EEA. Anthropic's API infrastructure sits outside the EEA; that transfer is governed by Anthropic's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses (Module Two, controller-to-processor) as the transfer safeguard. By default, Anthropic does not use data sent through its API to train its models.

How long we keep it

We keep your data until you delete it or your account — including a long-inactive account, which we don't automatically delete. When you delete your account, we delete your personal data from our systems within 30 days, except anything we must retain by law. Backups are retained for a limited period on a rolling schedule and are purged, not kept indefinitely, so a deleted account's data doesn't persist in backups beyond that window either.

Meal photos: not retained at all — see "What we collect" above.

Security

Local-first storage with sensitive values encrypted on-device; encryption in transit (HTTPS/TLS); access controls on our backend. No system is perfectly secure, but we take reasonable measures to protect your data.

Security incidents

If we discover a data breach affecting your personal data, we'll investigate and contain it promptly, and where required by law, notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected users without undue delay.

Your rights

You can access, correct, export, delete, restrict, or object to processing of your data, and withdraw consent at any time. Use the in-app tools below, or email [email protected]. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Deleting or exporting your data

  • In-app: Settings → Account → Delete account immediately deactivates your account and starts the deletion process; your personal data is fully removed from our systems within 30 days, per "How long we keep it" above.
  • Export: a full personal-data export (JSON) is built into the app, in-app and instant.
  • See our Account & Data Deletion page for full steps.

Children

ComniWell is not directed at children and is intended for users 16 and older; we rely on you confirming this when you create an account, rather than an active age-verification check. We do not knowingly collect data from children; contact us if you believe a child has provided data.

Changes

We'll update this page and change the "Last updated" date when our practices change; significant changes will be announced in-app.

Contact

[email protected]· ComniWell (KVK 42155849) · Hoogstraat 16, 7512 GX Enschede, Netherlands