Privacy Policy
Plain-English summary: Re stores your supplement logs, wellness check-ins, and profile data on secure servers to power the app. We never sell your data. We never use your health data for advertising. HealthKit data stays on your device and is only used to compute in-app insights. You can export or delete everything at any time.
1. Who We Are
Re ("we," "us," "our") is a supplement tracking and wellness app operated by Devarshi Bhatt. If you have questions about this policy, contact us at privacy@myrewellness.com.
This Privacy Policy explains what personal information we collect when you use the Re mobile application ("App"), how we use it, who we share it with, and the rights you have over it. By using the App, you agree to the practices described here.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address and a hashed password (we never store your password in plain text). Authentication is handled by Supabase Auth.
2.2 Profile Information
For each profile you create in Re (your own or a family member's), we collect:
- Display name
- Age and biological sex (optional — used to personalize RDA-based insights)
- Health goals (optional — used to personalize the Insights tab)
- Profile photo (optional — stored in Supabase Storage)
- Relationship type (self, partner, parent, child, etc.)
2.3 Supplement and Schedule Data
We store everything you enter about your supplements: name, brand, form, dose amount and unit, schedule (days and times), and whether the supplement is active.
2.4 Daily Log Data
Each time you log your supplements, we store:
- Whether each supplement was taken or skipped
- The time it was taken (if logged)
- Skip reason and any personal notes you add
- The date of the log
2.5 Wellness Check-in Data
When you complete a daily check-in, we store your self-reported scores for energy, focus, mood, sleep quality, sleep hours, any symptom tags you select, and any free-text notes you write. This data is used to compute correlations between your supplement habits and how you feel.
2.6 Lab Results
If you choose to enter lab results (blood tests, biomarker panels, etc.), we store the test name, result value, unit, date of the test, and lab name.
2.7 Apple Health Data (Optional — iOS Only)
If you choose to connect Apple Health, we read the following data types on your device to compute correlations on the Insights tab:
- Steps — daily step count
- Sleep — sleep duration and staging
- Heart Rate — resting and average heart rate
- Heart Rate Variability (HRV)
- Blood Oxygen (SpO₂)
- Respiratory Rate — breaths per minute during sleep
This data is processed entirely on your device. It is never uploaded to our servers or shared with any third party. See Section 4 for Apple HealthKit-specific disclosures required by Apple.
2.8 Usage and Crash Data
We collect anonymous event data (e.g., "supplement logged," "check-in saved") through PostHog to understand how the app is used and improve it. We also use Sentry to collect crash reports, which may include device model, operating system version, app version, and the stack trace of the error. These do not contain your supplement or health data.
3. How We Use Your Information
| Data | Purpose |
|---|---|
| Account data | Sign-in, authentication, account recovery |
| Profile data | Personalize RDA recommendations and insights |
| Supplement & log data | Core app functionality — tracking adherence, streaks, history |
| Wellness check-in data | Compute correlations between supplement habits and wellness outcomes |
| Lab results | Display alongside supplement data; future deficiency analysis |
| Apple Health data | On-device correlation with supplement logs on the Insights tab only |
| Usage events (PostHog) | Understand feature usage; improve the app |
| Crash data (Sentry) | Detect and fix bugs |
We do not use any of your data for advertising, targeted marketing, or sale to third parties. We do not build advertising profiles. HealthKit data is never used for any purpose other than in-app insights.
4. Apple HealthKit Disclosure
Re uses Apple's HealthKit framework on iOS. In compliance with Apple's guidelines, we disclose the following:
- Data types read: Steps, Sleep, Heart Rate, HRV, Blood Oxygen, Respiratory Rate
- Purpose: Exclusively to compute correlations between your supplement intake and health metrics on the Insights tab within the App
- On-device only: HealthKit data is processed locally on your iPhone. It is never transmitted to our servers, never stored in our database, and never included in data exports
- Not used for advertising: HealthKit data is never used for advertising, marketing, or sold to or shared with third parties for any commercial purpose
- User control: You can revoke Re's access to Apple Health at any time via iOS Settings → Health → Data Access & Devices → Re. Revoking access disables HealthKit-based correlations but does not affect any other app functionality
5. Multi-Profile and Caregiver Data
Re supports multiple profiles, allowing you to track supplements for family members or people in your care. If you create profiles for others:
- You are responsible for obtaining that person's consent (or their parent/guardian's consent if they are a minor) before entering their health data
- Their data is governed by this same Privacy Policy
- Deleting your account will delete all profiles associated with it
6. Third Parties We Work With
We share data with third parties only as described below. We do not sell personal information to third parties.
6.1 Supabase
We use Supabase as our database, authentication, and file storage provider. All app data (profiles, supplements, logs, check-ins, lab results) is stored on Supabase's infrastructure, hosted on Amazon Web Services (AWS) in the United States. Supabase processes data on our behalf under a Data Processing Addendum. Supabase does not use your data for its own purposes.
6.2 PostHog
We use PostHog for product analytics. PostHog receives anonymous usage events (e.g., "supplement_taken," "checkin_saved") associated with an anonymous user ID. No supplement names, health scores, or personal profile data are included in these events. You can opt out of PostHog analytics by contacting us at privacy@myrewellness.com.
6.3 Sentry
We use Sentry for crash reporting and error monitoring. Sentry receives crash reports that include device model, OS version, app version, and error stack traces. These do not contain your health, supplement, or profile data.
6.4 NIH Dietary Supplement Label Database (DSLD)
When you search for supplements, the App queries the NIH DSLD API. Only your search query text is sent to this API — no account or profile data is transmitted.
6.5 Legal Disclosure
We may disclose your information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Re, our users, or the public.
7. Data Retention
- Active accounts: Your data is retained for as long as your account remains active.
- Deleted accounts: When you delete your account, your personal data is permanently deleted from our production database within 30 days.
- Backups: Encrypted database backups may retain your data for up to 30 additional days after deletion before being overwritten.
- Analytics events (PostHog): Anonymous event data may be retained for up to 2 years.
- Crash reports (Sentry): Retained for 90 days.
- Export before deletion: We strongly encourage you to export your data (Settings → Data & Export) before deleting your account, as deletion is permanent and irreversible.
8. Your Rights and Choices
You have the following controls over your data, available directly in the App:
- Access & Export: Export all your data at any time via Settings → Data & Export (PDF, CSV, or JSON)
- Correct: Edit your profile, supplements, and logs directly in the App
- Delete your account: Settings → Account → Delete Account permanently deletes all your data
- Revoke HealthKit access: iOS Settings → Health → Data Access & Devices → Re
- Notification opt-out: Settings → Notifications, or iOS Settings → Notifications → Re
- Analytics opt-out: Email privacy@myrewellness.com to opt out of PostHog event tracking
For requests we cannot fulfill in-app (such as requesting a copy of your data in a specific format), email privacy@myrewellness.com. We will respond within 30 days.
9. Security
We take reasonable technical and organizational measures to protect your data:
- Encryption in transit: All data transmitted between the App and our servers uses HTTPS/TLS
- Encryption at rest: Supabase encrypts stored data using AES-256
- Row-Level Security (RLS): Database-level policies ensure each user can only access their own profiles' data — no cross-user data leakage is architecturally possible
- Authentication: Passwords are never stored in plain text; Supabase Auth handles secure password hashing
- HealthKit data: Never leaves your device
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at privacy@myrewellness.com.
10. Children's Privacy
Re is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, contact us at privacy@myrewellness.com and we will delete it promptly.
The multi-profile feature allows parents to track supplements for their children. In this case, the parent or guardian is the account holder and is responsible for the information entered.
11. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months
- Right to Delete: Request deletion of personal information we hold about you (subject to certain exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights
To exercise these rights, email privacy@myrewellness.com with "California Privacy Request" in the subject line. We will respond within 45 days.
Categories of personal information collected in the last 12 months: Identifiers (email), personal records (profile data), health and medical information (supplement logs, wellness check-ins, lab results), and internet/electronic activity (usage events, crash reports).
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
12. Washington State Health Data Rights (My Health My Data Act)
If you are a Washington State resident, the Washington My Health My Data Act (MHMDA) provides you with additional rights over "consumer health data," which includes your supplement logs, wellness check-in data, and lab results stored in Re.
- Right to Access: Confirm whether we are collecting your consumer health data and access a copy
- Right to Delete: Request deletion of your consumer health data (use Settings → Account → Delete Account, or email us)
- Right to Withdraw Consent: Withdraw consent to the collection or sharing of your consumer health data at any time
- Right to a List of Third Parties: Request a list of third parties with whom we have shared your consumer health data (see Section 6 — we share with Supabase only, as infrastructure)
To exercise these rights, email privacy@myrewellness.com with "Washington Health Data Request" in the subject line. We will respond within 45 days.
Consumer health data we collect: Supplement intake logs, wellness check-in scores and notes, symptom tags, and lab results you voluntarily enter. We do not sell consumer health data. We do not share consumer health data with third parties for advertising or marketing.
13. HIPAA Disclaimer
Re is not a HIPAA covered entity and is not a business associate of any HIPAA covered entity. The App is not a medical device and does not provide medical advice, diagnosis, or treatment. Do not use Re as a substitute for professional medical care. Always consult a qualified healthcare provider before making changes to your supplement regimen.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting a notice in the App on your next login, and/or
- Sending an email to the address on your account
We will provide at least 30 days' notice before material changes take effect. The "Last updated" date at the top of this page always reflects the most recent version. Continued use of the App after the effective date constitutes acceptance of the updated policy.
15. Contact Us
For privacy questions, data requests, or to report a concern:
- Email: privacy@myrewellness.com
- General: tryrewellness@gmail.com
We aim to respond to all privacy-related inquiries within 30 days.