Legal

Privacy Policy

Effective 4 September 2026Last updated 10 October 2026App com.bellw.app

This app handles health information, so this policy says exactly what leaves your phone, where it goes, and what your family can and cannot see. It applies to the Bellwether mobile app for iOS and Android.

01Who we are

The Bellwether app (“Bellwether”, “we”, “us”, “our”) is operated by Bellwether, a company organized under the laws of the State of California, United States.

Bellwether is a family health and wellness app. It reads wellness data from your phone's health platform — Apple Health (HealthKit) on iOS, Health Connect on Android — and shares a daily summary with the people you have deliberately connected with in the app.

If anything here is unclear, write to us at bellwether.mobile@gmail.com.

What we are not

Bellwether is not a covered entity under HIPAA and is not a medical device. The data it handles is consumer wellness data, not a medical record.

02The short version

We read from your health platformSleep, steps, distance, exercise, energy, heart rate, heart rate variability, VO₂ max, blood oxygen and — if you turn on cycle tracking — menstrual flow.
We write back one thingThe period days you log yourself, saved to Apple Health or Health Connect on your own device so they appear in your phone's own Cycle Tracking. Nothing else is ever written, and the flow you log is never uploaded to our servers.
We never collect locationNo GPS, no workout routes, no map data, no IP-based location tracking. The app asks for no location permission on either platform.
We upload daily totals, not raw dataOne row per person per day. Individual heartbeat samples, sleep records and workout sessions stay on your phone.
Only the people in your circles can see youYou share with the people in a circle you joined by invitation, and with nobody else. Being in a circle with someone who is in another circle gives that other circle no visibility. A challenge you accept is the one exception: it shares a single metric, your league, and whether you improved the most (§5.4).
We do not sell your dataNot to anyone, for any price. We do not share it for cross-context behavioral advertising. There are no ad networks or advertising SDKs in this app.
Health data is never sent to analyticsOur analytics tool receives event names only — never a step count, sleep score or heart rate.
AI insights send numbers, not namesDaily figures go to an AI provider (OpenRouter, Anthropic or Google) to generate insight text. Your name, email and account ID do not.
You can turn it offRevoke health access in your phone's system settings and uploads stop immediately.

03What we collect

3.1 Account information

Collected when you create an account or sign in.

DataSourceWhy
Email addressYou, or your Google / Apple accountAccount identity; letting a family member find you by exact address
Display nameYou, or your Google / Apple accountShown to your circle
Profile photo (optional)Your camera or photo libraryShown to your circle
Timezone and regionYour deviceAligning “today” and “last night” to your local day
Account identifierGenerated at sign-upThe pseudonymous ID everything else is keyed to
Sign-in methodGoogle, Apple, or email + passwordAuthenticating you

If you sign in with Google or Apple, we receive only the identity token those providers issue — your email address and, if you allow it, your name. We never receive your Google or Apple password. If you use Apple's Hide My Email, we receive only the relay address Apple gives us and never learn your real one.

The emails that confirm your address, reset your password, or confirm a change of address are sent through our email delivery provider, Resend (§6.8), which receives your email address — and, on a change, the new one — with the message.

Passwords for email sign-in are handled by our authentication provider and are stored salted and hashed. We cannot read them.

3.2 Health and wellness data

Read from Apple HealthKit or Android Health Connect only after you explicitly grant permission on your device. Everything below is read-only with a single exception — the period days you log yourself, which Bellwether writes back to your device's health platform. See What we write back below.

Categories read from your device:

  • Sleep — time asleep, time in bed (iOS), and the light, deep, REM and awake stages
  • Activity — step count and walking/running distance
  • Exercise and energy — exercise minutes, workouts, active calories, total calories and basal energy (iOS, optional)
  • Heart — heart rate samples and heart rate variability (SDNN on iOS, RMSSD on Android)
  • Fitness and oxygen — VO₂ max and blood oxygen (SpO₂), read only if you grant the separate permission the app asks for right after you connect
  • Cycle — menstrual flow, read only if you turn on cycle tracking and grant its own separate permission from that screen's Connect step

What is stored on our servers: we do not upload raw samples. Your phone aggregates each day into a single daily summary, and that summary is what is stored: sleep hours and minutes, sleep score, deep/REM/light/awake minutes, steps, distance, exercise minutes, total and active calories, average/minimum/maximum heart rate, heart rate variability, a derived steadiness (“Calm”) reading, whether your phone judged the day a “win” (two of its three daily bars cleared), the date, which platform the reading came from, and an anonymous identifier for the device that wrote the row.

When it is uploaded: when you open the app, and in the background, so your circle sees a current day without your having to open it. On Android the phone runs this about once an hour. On iPhone, Apple Health wakes the app when new steps, heart rate or sleep are recorded, even after you have closed it, and a silent push (§6.3) can wake it too. A background upload is the same daily summary, read the same way; revoking health access stops it.

We read at most the last 30 days from your health platform. We do not request the extended-history permission that would let us reach further back.

What we write back: one category, and only from your own action. When you log a period day in Bellwether, the app writes that flow entry to Apple Health or Health Connect; when you clear the day, it deletes that entry again. This keeps your phone's own Cycle Tracking in step with what you logged. It happens only on your own device, only for days you log yourself, and only after you grant menstrual-flow access from the cycle tracking screen's Connect step. We write nothing else to your health platform, and the flow you log is never uploaded to our servers.

Never read or stored

Location or GPS coordinates, workout routes, blood glucose, blood pressure, body measurements, nutrition, medications, clinical records, or any health category not listed above. We request no health permission beyond the ones named here — you can verify this in the app's system permission screen.

3.3 Circle and social data

  • Your circle membership list, and the relationship label and group you assign to each person
  • Invitations you send or receive: the invite code, its status and its expiry (codes expire after 7 days)
  • Reports and blocks: if you report someone, the reason you chose, any note you added, and a copy of the message you reported, kept so we can review it and cleared 90 days after the report is closed (the person reported is never told who reported them). Each report is also emailed to our support inbox through our email delivery provider (§6.8), so that someone reviews it within a day; that email carries the reason, your note, both people’s display names and account identifiers, the circle’s name, and the copy of the reported message. If you block someone, the fact that you did, so neither of you can connect to the other again. The person blocked cannot see the block.
  • Feedback: if you send feedback from your profile, or answer the short survey when you cancel a subscription, what you wrote, the reasons you chose, whether it was a trial or a paid plan, and the app version, platform and language you were using, so we can read it in context. Only we can read it; new feedback, with what you wrote, reaches our support inbox in a daily email sent through our email delivery provider (§6.8).
  • “Nudges” — the short encouragement messages you send, including the message text, emoji, category, and whether the recipient has read it
  • Circle chat: the messages you post in a family circle’s chat, which message one answers, and when it was sent or edited. Everyone in the circle can read them, except people who joined after they were sent
  • In-app notifications generated when someone accepts your invite or sends you a nudge
  • Challenges you create or are invited to: the title, the preset it came from, the metric being counted (steps, exercise minutes, sleep minutes or win days), the target, the dates it runs, the circle its invitations were drawn from, and whether you were invited, accepted, declined or left
  • What happens inside a challenge: the day you joined, declined, left or cleared the bar, and — once it finishes — your final total and placing, how many league points it gave you or took away, and whether it marked you “most improved” (§5.4)
  • League points: the points your finished challenges have added up to, which place you in one of five leagues, and how many challenges they count
  • Win streaks and achievements: your current and longest run of win days, the date of the last one, and the badges a finished challenge awards. These are readable by you alone, with one exception: whether a challenge marked you “most improved” is shown to everyone in that challenge (§5.4). The percentage behind it stays in your own badge.
  • Personal win goals you set for steps, sleep, or exercise: the target and the days it holds for, kept so that every phone you sign in on counts your streak against the same goals. Readable by you alone; a challenge always scores everyone against the standard goals, never yours.
  • Notification choices: which kinds of push you have turned off in Profile → Notifications — among them the morning recap a running challenge sends — kept on the account so that every phone you sign in on respects them
  • How closely you watch each person — the “priority” or “weekly” level you set for them, which decides how often the app may prompt you to check in. This is yours alone; the person it is about never sees it.

3.4 Device and technical data

  • Push notification token — issued by Firebase Cloud Messaging, stored with your platform name so we can deliver notifications. Removed when you sign out.
  • A random per-installation identifier — generated on your device with no link to any hardware ID, advertising ID or phone number. It exists so that when one account syncs from two devices (say an iPhone and an iPad), we can tell which device recorded a given day and avoid stitching together a day neither of them actually observed. It is never shown to your circle.
  • Device model and manufacturer — read on-device to detect Samsung phones (which need extra Health Connect setup) and simulators. Used for on-screen guidance; not uploaded.
  • App version, shown on your profile page.
  • Crash reports — when the app crashes, or an operation fails in a way that means a feature has stopped working (an upload that did not land, a sync that did not run), a report goes to Firebase Crashlytics (§6.3): the error and where in the app’s code it happened, the device model, operating system and app version, an identifier Crashlytics generates for the installation, and your pseudonymous account identifier. A crash report never carries a health value, email address, display name or text you typed. It is how we find and fix what breaks on real phones, and it is not affected by the usage analytics switch in §3.5.

3.5 Usage analytics

We use Mixpanel to understand how the app is used. It receives automatic events (app opens, sessions, app updates) and named events: Signed Up, Signed In, Signed Out, Tab Viewed (which tab), Screen Viewed (which screen), Notification Opened (type), Health Connect Result (success or failure), Invite Created, Invite Sent, Invite Answered (accepted or declined), Circle Joined, Nudge Sent (category), Circle Message Sent (nothing about the message: not its words, not the circle) and Account Deleted. It receives your progress through setup and the guides: Notification Permission Result (whether you allowed notifications, and where you were asked), Onboarding Step (which first-run step, and whether you did it or passed it by), Onboarding Finished (whether you skipped setup, and how many steps you did), Health Walkthrough Started, Health Walkthrough Finished, App Tour Started and App Tour Finished (whether you closed the walkthrough or tour before its last step). It also receives milestones — App Installed, Circle Created (the first person joined your circle), Invite Opened and Member Joined (how: a code or a direct invite), Wearable Connected, First Nudge Shown, Trial Started, Trial Converted and Subscription Cancelled (the plan’s name and whether it was a trial, never a price or payment detail) — and Feedback Sent and Cancellation Survey Shown, Cancellation Survey Submitted (the reasons you chose and whether you wrote a note, never the note itself) or Cancellation Survey Skipped.

These events are tied to your pseudonymous account identifier. By design, no health value, email address, display name or text you typed is ever sent to analytics. This is a hard rule enforced in our code, not a promise about intent. Analytics identity is detached the moment your session ends.

You can turn usage analytics off in Profile → Privacy → Share usage analytics. The choice is saved on your account, so from then on Mixpanel receives nothing from any device you sign in on, until you turn it back on.

3.6 Messages you send us

When you write to us — by email, or through the form on the support page — we receive what you put in it: your email address, your name if you give one, the topic you picked, the platform and app version if you fill them in, and the text of your message.

The form posts to our own server, which hands the message to our email delivery provider, Resend (§6.8), to deliver to bellwether.mobile@gmail.com. It is not routed through a help-desk product or a form-hosting service, and the message is not stored in our database, linked to your account record, or sent to analytics.

We use it to answer you and to fix what you reported, and we keep the correspondence in that mailbox for as long as it is useful for support history. Please do not put health readings or medical details in it — we never need them, and the note on the form says so too.

To stop the form being used to send mail in bulk, two more things happen. The form may show a check from Cloudflare Turnstile (§6.7), which loads only once you start filling it in, not when you open the page. And our server caps how many messages it accepts from one network address and for one email address — five an hour each. It counts them under a one-way keyed code made from each, never the address itself, and deletes the count within the hour.

3.7 What we do not collect at all

Location or GPS · contacts or address book · microphone or audio · calendar · SMS or call logs · advertising identifiers (IDFA / GAID) · payment or financial information · biometric identifiers for identification · browsing history outside the app · any data about people who are not Bellwether users.

There are no advertising SDKs, no ad networks and no third-party trackers in this app.

04How we use your data

PurposeData used
Show you your own health summary and trendsHealth data
Show your circle your daily summary, and show you theirsHealth data, circle membership
Score a challenge you joined, show its standings, and work out leagues and who improved the mostOne metric's daily figures — for “most improved”, also the 14 days before the challenge — and challenge membership (see §5.4)
Generate AI insight text and suggested nudgesDaily health figures (see §6.2)
Deliver push notifications — invites, nudges, challenge reminders and morning recaps, background syncPush token, circle data, challenge standings
Keep your data fresh while the app is closedHealth data, push token, device identifier
Let a family member find you by exact email addressEmail, display name, photo
Send the emails that confirm your address or reset your passwordEmail address (see §6.8)
Answer your messages, and review reports and feedbackWhat you sent us (see §3.3, §3.6)
Understand feature usage and fix problemsUsage analytics, crash reports
Keep accounts secure and enforce rate limitsAccount and technical data
Comply with lawAs required

We do not use your data to build advertising profiles, we do not make automated decisions that produce legal or similarly significant effects about you, and we do not use your health data for marketing.

05Who can see your health data

5.1 Your circles — and nobody outside them

Bellwether shares inside circles. A circle has an owner and up to eight people in all, and you are in one only because you accepted an invitation to it: one sent to your account, or a link or code someone gave you. Everyone in a circle sees everyone else in it, so before you join, the app shows you the circle's name; once you are in, it shows you who else is there.

Sharing does not reach past a circle. If your mother has one circle with you and another with your cousin, your cousin cannot see your data, read your profile or send you nudges, because you are not in a circle together. Someone joining a circle you are in can see you from then on; leaving that circle, or being taken out of it, ends what you share with its people, unless you are also in another circle with them. Blocking someone stops all sharing between you two, even inside a circle you are both in. This is enforced at the database level by row-level security, not just in the app's screens.

Connections made one-to-one before circles existed work the same way: the two people see each other and nobody else.

There is one way to share beyond your circles, and you have to opt into it each time: joining a challenge. See §5.4.

5.2 What the people in your circles see

  1. Sleep — how long you slept, the light, deep and REM stages, time awake, and a nightly score
  2. Steps and distance — your daily step count and how far you walked. Never where you walked.
  3. Exercise and energy — active minutes, and calories burned in total and through movement
  4. Heart — your average, lowest and highest heart rate for the day, and heart rate variability
  5. Calm — a single steadiness reading worked out from your heart figures

They also see your display name, profile photo, and the email address you signed up with.

They do not see: which platform or device your data came from, your device identifier, your timezone, individual samples or timestamps within a day, anything older than the history window the app displays, or any health category not listed above.

5.3 Ending sharing

  • Revoke health access in iOS Settings → Privacy & Security → Health → Bellwether, or in Android's Health Connect settings. New data stops being read and uploaded immediately.
  • Leave a circle, or, in a circle you own, take someone out of it or delete the circle. You stop sharing with its people, except anyone you are also in another circle with.
  • Delete your account in the app, at Profile → Delete Account (see §9).

Revoking health access stops new uploads; summaries already uploaded stay visible to your circles until you delete them or your account. To delete them, open Profile → Privacy → Delete Uploaded Health Days (while health access is off, the “What your circle sees of you” card offers the same). Every day you uploaded is deleted at once, and so is what was worked out from those days and is still shown to other people: your win streak, the alerts and summaries about you in your circles’ feeds (“had a short night”), and the days you cleared the bar in a challenge’s feed. Challenge totals that counted them go down; in a challenge that has already finished you keep your place, without a total, and the league points and any “most improved” mark it settled stay as they were. Nothing is removed from Apple Health or Health Connect, and a notification already delivered to someone’s phone cannot be taken back. If health access is still on, sharing picks up again the next day, and the days you deleted are not uploaded again.

5.4 Challenges

A challenge is a scoreboard for one metric over a set stretch of days. Whoever creates it can only invite people they share a circle with, but the people invited do not necessarily share one with each other — your mother can invite both you and your cousin to the same step challenge.

Accepting an invitation to a challenge shares one metric with everyone else in it. For as long as the challenge runs, the others see your display name, your profile photo, your running total for that one metric, a feed of the days you cleared the bar, with the figure at the time, and your league: the points your earlier challenges have added up to. When it finishes they also see how many league points it gave you or took away, and whether it marked you “most improved”. That is the whole of it: your sleep stages, heart figures, the other metrics and your daily summaries stay inside your circles (§5.1), and a challenge never reveals a day you did not clear.

“Most improved” looks at the two weeks before the challenge. When a challenge finishes, each player’s daily average for its metric during the challenge is compared with their own average over the 14 days before it started — days you had already uploaded for your circles, but from before you agreed to share anything with this challenge. Whoever rose the most, by at least 5%, is marked. The others see only the mark, never the percentage or the figures behind it; but in a challenge of two or three people, the mark alone tells them that your average rose by at least 5% on your previous fortnight.

The same feed, roster and leagues are visible to people who have been invited but have not yet answered, so they can see what they are being asked to join. Until you accept, you share nothing — an unanswered invitation and a declined one both put you nowhere in the standings, no events in the feed, and no league on show.

A challenge for one circle announces its winner in that circle’s chat. When a challenge created for a single circle finishes, the circle’s chat shows a line with the winner’s name and the challenge’s title — never a figure — which everyone in the circle can read, including people who did not take part. It is posted only while everybody who played is still in that circle, and only when one or two people won rather than everybody. Like the rest of the chat, it is deleted after 90 days, or sooner if the winner leaves the circle (§8). A challenge made across circles posts nowhere.

While a challenge runs, the app may send you a morning recap: a push saying where you stand and what today needs. In a race it names the person just ahead of or behind you and the gap between you — what the standings already show you; in a daily-bar challenge it counts only your own days. On the last day it may also tell you when the person next to you is within reach. You can turn the morning recap off in Profile → Notifications.

Leaving a challenge stops the sharing at that moment: the standings are built from accepted participants only, so leaving takes your running total out of them. The days you had already cleared stay in that challenge's feed, and we will remove them if you ask. When a challenge finishes, the final placings and totals, the league points each one moved, and the “most improved” mark stay visible to the people who took part (a total goes sooner if its owner deletes their uploaded health days).

Challenges do not change who can see your daily summary, and being in one with somebody does not put you in a circle with them.

06Service providers

We use a small number of processors. Each receives only what it needs.

6.1 Supabase — hosting, authentication, database, file storage

Stores your account, circle data, daily health summaries and profile photos. Hosted in the United States, encrypted in transit (TLS) and at rest, and protected by row-level security policies that enforce the sharing rules in §5 at the database itself.

6.2 AI providers — AI insights and suggested nudges

When you view AI insights, the app sends a request through our own server (never directly from your phone, and never with an API key in the app) to one AI provider at a time, in an order we set. The next provider receives the request only if the one before it failed to answer.

  • OpenRouter forwards the request to one of the companies hosting OpenAI's gpt-4o-mini model. OpenRouter does not store prompts or responses; the hosting company that serves the request handles it under its own terms.
  • Anthropic (claude-haiku-4-5 model). Under Anthropic's commercial terms, data submitted through its API is not used to train its models.
  • Google (Gemini API, gemini-3.5-flash-lite model), on paid terms, under which Google does not use prompts or responses to improve its products and keeps them only for a limited period to detect abuse.

Whichever provider answers receives the same data:

What is sent: your daily figures only — sleep hours and score, deep and REM minutes, steps, distance, exercise minutes, heart rate and its range, heart rate variability, VO₂ max and a stress score; plus the reply language and whether the data belongs to you or “a family member.”

A cycle-tracking insight sends cycle figures in place of the daily ones: the current cycle day and phase, roughly how many days until the next predicted period, your average cycle length, and how many logged cycles that average is based on. No dates and no individual flow levels are sent.

What is not sent: your name, email address, account identifier, device identifier, profile photo, circle membership, or any free text you have typed. When generating a suggested nudge for a family member, the recipient's name is deliberately excluded — it adds nothing to the suggestion.

Requests are rate-limited to 20 per user per hour. The resulting insight text is cached on your device.

If you would rather no health figures reach any AI provider at all, simply do not open the AI insights card; the app falls back to insights computed entirely on your own device.

6.3 Firebase (Google) — push notifications and crash reports

Firebase Cloud Messaging receives your device push token and the content of notifications we send you (for example, “Anna accepted your invitation” or a nudge message). Used for transport only. Some pushes are silent, carrying no content, and exist only to wake the app so it can upload the day's data.

Firebase Crashlytics receives the crash reports described in §3.4, keyed to your pseudonymous account identifier. No health values, emails, names or typed text.

6.4 Mixpanel — usage analytics

Receives only the events in §3.5, keyed to your pseudonymous account identifier. No health values, emails, names or typed text.

6.5 Google Sign-In and Sign in with Apple — authentication

Used only if you choose them. They confirm your identity and return an identity token. We do not receive your credentials.

6.6 Apple HealthKit and Android Health Connect — on your device

These are your phone's own health platforms, not our processors. They grant us access only with your explicit permission. We read from them, and the one thing we ever write to them is a period day you logged yourself (§3.2).

6.7 Cloudflare Turnstile — the support form

Used only on the support page, and only once you start filling in the form. To tell a person from a script, Cloudflare receives your IP address and information about your browser and how the page was used, and tells our server only whether the check passed. It never receives what you wrote in the form. It is not used in the app.

6.8 Resend — email delivery

Sends the emails our server writes, and nothing else:

  • Account emails — confirming your address, resetting your password, confirming a change of address. Resend receives your email address (and, on a change, the new one) and the message.
  • Support messages — what you send through the support form (§3.6): your email address, your name if you gave one, the platform and app version, and your message, delivered to our support inbox.
  • Reports and feedback — the email about each report (§3.3): the reason, the reporter’s note, both people’s display names and account identifiers, the circle’s name, and the copy of the reported message; and the daily email with the feedback sent that day and what was written in it.

Resend keeps a copy of each email, with its delivery record, for 30 days and then deletes it. It never receives a health value, and it handles the emails only to deliver them, as our processor. Our support inbox itself is a Gmail mailbox (Google).

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Beyond the providers above, we disclose data only when compelled by valid legal process, to protect rights and safety, or — with notice to you — as part of a merger or acquisition.

07Apple HealthKit and Health Connect commitments

Where we handle data obtained from HealthKit or Health Connect, we specifically commit that:

  • We never use it for advertising, marketing, or any use-based data mining.
  • We never sell it, trade it, or disclose it to data brokers, insurers, employers or advertising platforms.
  • We disclose it only to the people in the circles you chose to join (§5) and, for insight generation, to the AI providers described in §6.2.
  • We use it only to provide the health and wellness features you can see in the app.
  • We store it only where it is needed to provide those features, and we delete it on request.
  • Bellwether reads from your health platform and writes back one thing only: a period day you logged yourself, saved to your own device so it appears in Cycle Tracking (§3.2).

08Retention

DataKept for
Account detailsWhile your account exists
Daily health summariesWhile your account exists, or until you delete them at Profile → Privacy → Delete Uploaded Health Days
Circle membershipsUntil you leave the circle, are taken out of it, or it is deleted
InvitationsCodes expire 7 days after creation
Circle chat messages90 days, unless you delete one first, leave the circle or are taken out of it, or the circle closes
Nudges90 days, unless you delete one or your account first
Notifications60 days once read, 180 days if never read
Challenges, their standings and their feedUntil the challenge is deleted, or your account is
Win streaks, personal win goals, achievements and watch levelsWhile your account exists
League pointsWhile your account exists. What a challenge gave or took, and its “most improved” mark, go with that challenge
A challenge winner’s line in a circle chatAs circle chat messages: 90 days, unless the winner leaves the circle or is taken out of it, or the circle closes
Notification choicesWhile your account exists
Feedback and cancellation-survey answersWhile your account exists
Reports you file, and reports about youThe copy of the message and the reporter’s note: until 90 days after the report is closed. The rest — the reason, what we did about it, and the dates: 12 months from when the report was filed
Push tokenUntil you sign out or the token is retired
Health data cached on your phoneEncrypted in the iOS Keychain / Android KeyStore; erased on sign-out
AI insight textCached on your device, refreshed as your data changes
Analytics eventsPer Mixpanel's retention settings for our project
Crash reports90 days, then deleted by Crashlytics. Deleting your account does not remove a report already sent; it expires on the same schedule
Emails sent through Resend30 days in Resend, then deleted by Resend
Support correspondenceIn our mailbox, for as long as it is useful as support history
Support form send countsA one-way code of your network address and of your email, deleted within the hour (§3.6)

Deleting your account removes your account row and everything keyed to it — health summaries, circle memberships, invites, nudges, circle chat messages, notifications, push tokens, challenge entries and their events, league points, win streaks, personal win goals, achievements, watch levels, notification choices, feedback you sent and your profile photo — by database cascade. A report is the exception: one you filed, or one filed about you, loses your account id but keeps the copy of the message and the note until it has been closed for 90 days, and is deleted 12 months after it was filed, so that a report can still be reviewed after the account it concerns is gone. Backups may retain copies for a limited period before rotating out.

09Your rights and choices

Everyone, wherever you live, can:

  • Access the data we hold about you
  • Correct your display name, photo and profile details in the app at any time
  • Delete your account and all associated data
  • Export a machine-readable copy of your data, from the app
  • Withdraw consent for health access at any time, in your device settings, without losing your account
  • Delete the health summaries already uploaded, at Profile → Privacy → Delete Uploaded Health Days, without losing your account (§5.3)
  • Remove the period days you logged in your phone's own Health or Health Connect app, or by clearing the day in Bellwether. Those entries live in your device's health store, not on our servers, so deleting your Bellwether account does not remove them
  • Turn off push notifications in your device settings, and usage analytics in Profile → Privacy → Share usage analytics
  • Leave any circle, or block anyone in one

To delete your account, open Profile → Delete Account in the app. You confirm by typing your email address, and the deletion runs immediately — there is no waiting period and no undo.

To get a copy of your data, open Profile → Download My Data in the app. It prepares a JSON file — your profile, every day of health summaries we hold, your circles, the nudges and circle messages you sent, your challenges, league, win streak, personal win goals and achievements, your settings, and the feedback and reports you filed — and opens your phone’s share sheet so you can save it or send it wherever you choose. Other people appear in it by account id only: what they sent you and anything else of theirs is theirs, not part of your copy. Cycle data is not in it because it never leaves your device; your phone’s Health or Health Connect app can export it.

To exercise any other right, or to delete your account without access to the app, email bellwether.mobile@gmail.com from the address on your account. We will respond within 30 days.

If you are in California

Under the CCPA/CPRA you have the right to know what we collect and why, to delete it, to correct it, to obtain a portable copy, and to limit the use of sensitive personal information. Health data is sensitive personal information; we use it only to provide the service you asked for and for no secondary purpose, which is the limit the law allows you to request. We do not sell or share personal information, so there is nothing to opt out of — but you may still submit a request and we will confirm this in writing. We will never discriminate against you for exercising these rights. You may use an authorized agent; we will verify their authority.

If you are in the EU, UK or Switzerland

Our legal bases are: your explicit consent for health data (Art. 9(2)(a) GDPR — this is special-category data, and the device permission prompt is where you give that consent); performance of a contract for account and circle features; and legitimate interests for security, abuse prevention, crash reporting and product analytics. You have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent at any time without affecting prior processing. To withdraw consent for health data, revoke health access in your device settings; to erase what was uploaded on that consent, open Profile → Privacy → Delete Uploaded Health Days. To object to product analytics, turn off Profile → Privacy → Share usage analytics. You may lodge a complaint with your national supervisory authority.

Your data is processed in the United States. Where personal data is transferred out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with the providers in §6.

Other US states

If you live in Colorado, Connecticut, Virginia, Utah, Texas, Oregon or another state with a comprehensive privacy law, you have comparable rights of access, correction, deletion and portability, and the right to appeal a refusal. Use the same address above.

10Security

  • Row-level security in the database enforces the sharing rules in §5 for every read and write, so the rules hold even against direct API calls the app itself would never make.
  • Encryption in transit (TLS) everywhere, and at rest on our servers.
  • On-device encryption — your session and cached health data live in the iOS Keychain or Android KeyStore, not in plain files. Sign-out wipes cached health data, cached circle data and cached profile images, so the next person to use the device cannot see them.
  • No user enumeration — finding someone requires their full, exact email address. Partial-match search was deliberately removed, so nobody can browse the user list or fish for addresses.
  • No secrets in the app binary — the AI provider keys live only in our server environment. The app cannot reach any AI provider directly.
  • Rate limiting on AI requests, and expiring, single-purpose invite codes.

No system is perfectly secure. If you discover a vulnerability, please report it to bellwether.mobile@gmail.com rather than disclosing it publicly, and we will work with you.

11Children

Bellwether is not directed to children under 13, and we do not knowingly collect personal information from them. If you are between 13 and 18, you may use Bellwether only with the involvement and consent of a parent or legal guardian.

Because Bellwether shares health data between family members, we ask parents to be especially deliberate: adding a minor to a circle means an adult can see that minor's sleep and activity data. Please make sure the minor understands and agrees.

If you believe a child under 13 has given us personal information, email bellwether.mobile@gmail.com and we will delete it promptly.

12International users

Bellwether is operated from the United States and your data is processed there. If you use the app from outside the US, you are transferring your data to the US, where privacy laws differ from those in your country. Section 9 describes the safeguards that apply.

13Changes to this policy

We will post any changes here with a new “Last updated” date. For changes that materially affect how we handle your health data, we will notify you in the app or by email before they take effect, and where the law requires it we will ask for your consent again.

14Contact

Email · bellwether.mobile@gmail.com

Support page · bellw.app/support — the form there reaches the same inbox

For privacy requests, please write from the email address on your account, or tell us enough to verify that the account is yours.