Legal

Privacy Policy

Effective 4 September 2026Last updated 1 October 2026App com.bellw.app

This app handles health information, so this policy says exactly what leaves your phone, where it goes, and what your family can and cannot see. It applies to the Bellwether mobile app for iOS and Android.

01Who we are

The Bellwether app (“Bellwether”, “we”, “us”, “our”) is operated by Bellwether, a company organized under the laws of the State of California, United States.

Bellwether is a family health and wellness app. It reads wellness data from your phone's health platform — Apple Health (HealthKit) on iOS, Health Connect on Android — and shares a daily summary with the people you have deliberately connected with in the app.

If anything here is unclear, write to us at bellwether.mobile@gmail.com.

What we are not

Bellwether is not a covered entity under HIPAA and is not a medical device. The data it handles is consumer wellness data, not a medical record.

02The short version

We read from your health platformSleep, steps, distance, exercise, energy, heart rate, heart rate variability, VO₂ max, blood oxygen and — if you turn on cycle tracking — menstrual flow.
We write back one thingThe period days you log yourself, saved to Apple Health or Health Connect on your own device so they appear in your phone's own Cycle Tracking. Nothing else is ever written, and the flow you log is never uploaded to our servers.
We never collect locationNo GPS, no workout routes, no map data, no IP-based location tracking. The app asks for no location permission on either platform.
We upload daily totals, not raw dataOne row per person per day. Individual heartbeat samples, sleep records and workout sessions stay on your phone.
Only people you connected with can see youSharing requires a mutual connection. Being in a friend-of-a-friend's circle gives no visibility. A challenge you accept is the one exception, and it shares a single metric (§5.4).
We do not sell your dataNot to anyone, for any price. We do not share it for cross-context behavioral advertising. There are no ad networks or advertising SDKs in this app.
Health data is never sent to analyticsOur analytics tool receives event names only — never a step count, sleep score or heart rate.
AI insights send numbers, not namesDaily figures go to an AI provider (OpenRouter, Anthropic or Google) to generate insight text. Your name, email and account ID do not.
You can turn it offRevoke health access in your phone's system settings and uploads stop immediately.

03What we collect

3.1 Account information

Collected when you create an account or sign in.

DataSourceWhy
Email addressYou, or your Google / Apple accountAccount identity; letting a family member find you by exact address
Display nameYou, or your Google / Apple accountShown to your circle
Profile photo (optional)Your camera or photo libraryShown to your circle
Timezone and regionYour deviceAligning “today” and “last night” to your local day
Account identifierGenerated at sign-upThe pseudonymous ID everything else is keyed to
Sign-in methodGoogle, Apple, or email + passwordAuthenticating you

If you sign in with Google or Apple, we receive only the identity token those providers issue — your email address and, if you allow it, your name. We never receive your Google or Apple password. If you use Apple's Hide My Email, we receive only the relay address Apple gives us and never learn your real one.

Passwords for email sign-in are handled by our authentication provider and are stored salted and hashed. We cannot read them.

3.2 Health and wellness data

Read from Apple HealthKit or Android Health Connect only after you explicitly grant permission on your device. Everything below is read-only with a single exception — the period days you log yourself, which Bellwether writes back to your device's health platform. See What we write back below.

Categories read from your device:

  • Sleep — time asleep, time in bed (iOS), and the light, deep, REM and awake stages
  • Activity — step count and walking/running distance
  • Exercise and energy — exercise minutes, workouts, active calories, total calories and basal energy (iOS, optional)
  • Heart — heart rate samples and heart rate variability (SDNN on iOS, RMSSD on Android)
  • Fitness and oxygen — VO₂ max and blood oxygen (SpO₂), read only if you grant the separate permission the app asks for right after you connect
  • Cycle — menstrual flow, read only if you turn on cycle tracking and grant its own separate permission from that screen's Connect step

What is stored on our servers: we do not upload raw samples. Your phone aggregates each day into a single daily summary, and that summary is what is stored: sleep hours and minutes, sleep score, deep/REM/light/awake minutes, steps, distance, exercise minutes, total and active calories, average/minimum/maximum heart rate, heart rate variability, a derived steadiness (“Calm”) reading, whether your phone judged the day a “win” (two of its three daily bars cleared), the date, which platform the reading came from, and an anonymous identifier for the device that wrote the row.

We read at most the last 30 days from your health platform. We do not request the extended-history permission that would let us reach further back.

What we write back: one category, and only from your own action. When you log a period day in Bellwether, the app writes that flow entry to Apple Health or Health Connect; when you clear the day, it deletes that entry again. This keeps your phone's own Cycle Tracking in step with what you logged. It happens only on your own device, only for days you log yourself, and only after you grant menstrual-flow access from the cycle tracking screen's Connect step. We write nothing else to your health platform, and the flow you log is never uploaded to our servers.

Never read or stored

Location or GPS coordinates, workout routes, blood glucose, blood pressure, body measurements, nutrition, medications, clinical records, or any health category not listed above. We request no health permission beyond the ones named here — you can verify this in the app's system permission screen.

3.3 Circle and social data

  • Your circle membership list, and the relationship label and group you assign to each person
  • Invitations you send or receive: the invite code, its status and its expiry (codes expire after 7 days)
  • Reports and blocks: if you report someone, the reason you chose, any note you added, and a copy of the message you reported, kept so we can review it (the person reported is never told who reported them). If you block someone, the fact that you did, so neither of you can connect to the other again. The person blocked cannot see the block.
  • Feedback: if you send feedback from your profile, or answer the short survey when you cancel a subscription, what you wrote, the reasons you chose, whether it was a trial or a paid plan, and the app version, platform and language you were using, so we can read it in context. Only we can read it.
  • “Nudges” — the short encouragement messages you send, including the message text, emoji, category, and whether the recipient has read it
  • In-app notifications generated when someone accepts your invite or sends you a nudge
  • Challenges you create or are invited to: the title, the preset it came from, the metric being counted (steps, exercise minutes, sleep minutes or win days), the target, the dates it runs, the circle its invitations were drawn from, and whether you were invited, accepted, declined or left
  • What happens inside a challenge: the day you joined, declined, left or cleared the bar, and — once it finishes — your final total and placing
  • Win streaks and achievements: your current and longest run of win days, the date of the last one, and the badges a finished challenge awards. These are readable by you alone; nobody in your circle or your challenges can see them.
  • How closely you watch each person — the “priority” or “weekly” level you set for them, which decides how often the app may prompt you to check in. This is yours alone; the person it is about never sees it.

3.4 Device and technical data

  • Push notification token — issued by Firebase Cloud Messaging, stored with your platform name so we can deliver notifications. Removed when you sign out.
  • A random per-installation identifier — generated on your device with no link to any hardware ID, advertising ID or phone number. It exists so that when one account syncs from two devices (say an iPhone and an iPad), we can tell which device recorded a given day and avoid stitching together a day neither of them actually observed. It is never shown to your circle.
  • Device model and manufacturer — read on-device to detect Samsung phones (which need extra Health Connect setup) and simulators. Used for on-screen guidance; not uploaded.
  • App version, shown on your profile page.

3.5 Usage analytics

We use Mixpanel to understand how the app is used. It receives automatic events (app opens, sessions, app updates) and named events: Signed Up, Signed In, Signed Out, Tab Viewed (which tab), Screen Viewed (which screen), Notification Opened (type), Health Connect Result (success or failure), Invite Created, Invite Sent, Invite Answered (accepted or declined), Circle Joined, Nudge Sent (category) and Account Deleted. It also receives milestones — App Installed, Circle Created (the first person joined your circle), Invite Opened and Member Joined (how: a code or a direct invite), Wearable Connected, First Nudge Shown, Trial Started, Trial Converted and Subscription Cancelled (the plan’s name and whether it was a trial, never a price or payment detail) — and Feedback Sent and Cancellation Survey Shown, Submitted (the reasons you chose and whether you wrote a note, never the note itself) or Skipped.

These events are tied to your pseudonymous account identifier. By design, no health value, email address, display name or text you typed is ever sent to analytics. This is a hard rule enforced in our code, not a promise about intent. Analytics identity is detached the moment your session ends.

3.6 Messages you send us

When you write to us — by email, or through the form on the support page — we receive what you put in it: your email address, your name if you give one, the topic you picked, the platform and app version if you fill them in, and the text of your message.

The form posts to our own server, which turns the message into an email to bellwether.mobile@gmail.com. It is not routed through a help-desk product or a form-hosting service, and the message is not stored in a database, linked to your account record, or sent to analytics.

We use it to answer you and to fix what you reported, and we keep the correspondence in that mailbox for as long as it is useful for support history. Please do not put health readings or medical details in it — we never need them, and the note on the form says so too.

To stop the form being used to send mail in bulk, two more things happen. The form may show a check from Cloudflare Turnstile (§6.7), which loads only once you start filling it in, not when you open the page. And our server caps how many messages it accepts from one network address and for one email address — five an hour each. It counts them under a one-way keyed code made from each, never the address itself, and deletes the count within the hour.

3.7 What we do not collect at all

Location or GPS · contacts or address book · microphone or audio · calendar · SMS or call logs · advertising identifiers (IDFA / GAID) · payment or financial information · biometric identifiers for identification · browsing history outside the app · any data about people who are not Bellwether users.

There are no advertising SDKs, no ad networks and no third-party trackers in this app.

04How we use your data

PurposeData used
Show you your own health summary and trendsHealth data
Show your circle your daily summary, and show you theirsHealth data, circle membership
Score a challenge you joined and show its standingsOne metric's daily figures, challenge membership (see §5.4)
Generate AI insight text and suggested nudgesDaily health figures (see §6.2)
Deliver push notifications — invites, nudges, background syncPush token, circle data
Keep your data fresh while the app is closedHealth data, push token, device identifier
Let a family member find you by exact email addressEmail, display name, photo
Understand feature usage and fix problemsUsage analytics
Keep accounts secure and enforce rate limitsAccount and technical data
Comply with lawAs required

We do not use your data to build advertising profiles, we do not make automated decisions that produce legal or similarly significant effects about you, and we do not use your health data for marketing.

05Who can see your health data

5.1 Your circle — and only by mutual connection

Bellwether's sharing model is mutual membership. Another person can see your daily summary only if one of you is a member of the other's own circle — that is, only if a direct connection was created by an invitation one of you accepted.

Being in the same circle as someone does not make you visible to them. If your mother has both you and your cousin in her circle, your cousin cannot see your data, read your profile or send you nudges. Visibility is direct and mutual, never transitive — enforced at the database level by row-level security, not just in the app's screens.

There is one way to share beyond a direct connection, and you have to opt into it each time: joining a challenge. See §5.4.

5.2 What a connected person sees

  1. Sleep — how long you slept, the light, deep and REM stages, time awake, and a nightly score
  2. Steps and distance — your daily step count and how far you walked. Never where you walked.
  3. Exercise and energy — active minutes, and calories burned in total and through movement
  4. Heart — your average, lowest and highest heart rate for the day, and heart rate variability
  5. Calm — a single steadiness reading worked out from your heart figures

They also see your display name, profile photo, and the email address you signed up with.

They do not see: which platform or device your data came from, your device identifier, your timezone, individual samples or timestamps within a day, anything older than the history window the app displays, or any health category not listed above.

5.3 Ending sharing

  • Revoke health access in iOS Settings → Privacy & Security → Health → Bellwether, or in Android's Health Connect settings. New data stops being read and uploaded immediately.
  • Remove a person from your circle, and leave theirs. Visibility is mutual, so both directions need to end for sharing to fully stop.
  • Delete your account in the app, at Profile → Delete Account (see §9).

Revoking health access stops new uploads; summaries already uploaded remain until you delete them or your account. Ask us and we will remove them.

5.4 Challenges

A challenge is a scoreboard for one metric over a set stretch of days. Whoever creates it can only invite people they are directly connected to, but the people invited are not necessarily connected to each other — your mother can invite both you and your cousin to the same step challenge.

Accepting an invitation to a challenge shares one metric with everyone else in it. For as long as the challenge runs, the others see your display name, your profile photo, your running total for that one metric, and a feed of the days you cleared the bar, with the figure at the time. That is the whole of it: your sleep stages, heart figures, the other metrics and your daily summaries stay behind the mutual-connection rule in §5.1, and a challenge never reveals a day you did not clear.

The same feed and roster are visible to people who have been invited but have not yet answered, so they can see what they are being asked to join. Until you accept, you share nothing — an unanswered invitation and a declined one both put you nowhere in the standings and no events in the feed.

Leaving a challenge stops the sharing at that moment: the standings are built from accepted participants only, so leaving takes your running total out of them. The days you had already cleared stay in that challenge's feed, and we will remove them if you ask. When a challenge finishes, the final placings and totals stay visible to the people who took part.

Challenges do not change who can see your daily summary, and being in one with somebody does not connect you to them in your circle.

06Service providers

We use a small number of processors. Each receives only what it needs.

6.1 Supabase — hosting, authentication, database, file storage

Stores your account, circle data, daily health summaries and profile photos. Hosted in the United States, encrypted in transit (TLS) and at rest, and protected by row-level security policies that enforce the sharing rules in §5 at the database itself.

6.2 AI providers — AI insights and suggested nudges

When you view AI insights, the app sends a request through our own server (never directly from your phone, and never with an API key in the app) to one AI provider at a time, in an order we set. The next provider receives the request only if the one before it failed to answer.

  • OpenRouter forwards the request to one of the companies hosting OpenAI's gpt-4o-mini model. OpenRouter does not store prompts or responses; the hosting company that serves the request handles it under its own terms.
  • Anthropic (claude-haiku-4-5 model). Under Anthropic's commercial terms, data submitted through its API is not used to train its models.
  • Google (Gemini API, gemini-3.5-flash-lite model), on paid terms, under which Google does not use prompts or responses to improve its products and keeps them only for a limited period to detect abuse.

Whichever provider answers receives the same data:

What is sent: your daily figures only — sleep hours and score, deep and REM minutes, steps, distance, exercise minutes, heart rate and its range, heart rate variability, VO₂ max and a stress score; plus the reply language and whether the data belongs to you or “a family member.”

A cycle-tracking insight sends cycle figures in place of the daily ones: the current cycle day and phase, roughly how many days until the next predicted period, your average cycle length, and how many logged cycles that average is based on. No dates and no individual flow levels are sent.

What is not sent: your name, email address, account identifier, device identifier, profile photo, circle membership, or any free text you have typed. When generating a suggested nudge for a family member, the recipient's name is deliberately excluded — it adds nothing to the suggestion.

Requests are rate-limited to 20 per user per hour. The resulting insight text is cached on your device.

If you would rather no health figures reach any AI provider at all, simply do not open the AI insights card; the app falls back to insights computed entirely on your own device.

6.3 Firebase Cloud Messaging (Google) — push notifications

Receives your device push token and the content of notifications we send you (for example, “Anna accepted your invitation” or a nudge message). Used for transport only. Some pushes are silent, carrying no content, and exist only to wake the app so it can upload the day's data.

6.4 Mixpanel — usage analytics

Receives only the events in §3.5, keyed to your pseudonymous account identifier. No health values, emails, names or typed text.

6.5 Google Sign-In and Sign in with Apple — authentication

Used only if you choose them. They confirm your identity and return an identity token. We do not receive your credentials.

6.6 Apple HealthKit and Android Health Connect — on your device

These are your phone's own health platforms, not our processors. They grant us access only with your explicit permission. We read from them, and the one thing we ever write to them is a period day you logged yourself (§3.2).

6.7 Cloudflare Turnstile — the support form

Used only on the support page, and only once you start filling in the form. To tell a person from a script, Cloudflare receives your IP address and information about your browser and how the page was used, and tells our server only whether the check passed. It never receives what you wrote in the form. It is not used in the app.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Beyond the providers above, we disclose data only when compelled by valid legal process, to protect rights and safety, or — with notice to you — as part of a merger or acquisition.

07Apple HealthKit and Health Connect commitments

Where we handle data obtained from HealthKit or Health Connect, we specifically commit that:

  • We never use it for advertising, marketing, or any use-based data mining.
  • We never sell it, trade it, or disclose it to data brokers, insurers, employers or advertising platforms.
  • We disclose it only to the connected people you chose (§5) and, for insight generation, to the AI providers described in §6.2.
  • We use it only to provide the health and wellness features you can see in the app.
  • We store it only where it is needed to provide those features, and we delete it on request.
  • Bellwether reads from your health platform and writes back one thing only: a period day you logged yourself, saved to your own device so it appears in Cycle Tracking (§3.2).

08Retention

DataKept for
Account detailsWhile your account exists
Daily health summariesWhile your account exists, or until you ask us to delete them
Circle membershipsUntil you or the other person ends the connection
InvitationsCodes expire 7 days after creation
Nudges and notificationsUntil you delete them or your account
Challenges, their standings and their feedUntil the challenge is deleted, or your account is
Win streaks, achievements and watch levelsWhile your account exists
Feedback and cancellation-survey answersWhile your account exists
Push tokenUntil you sign out or the token is retired
Health data cached on your phoneEncrypted in the iOS Keychain / Android KeyStore; erased on sign-out
AI insight textCached on your device, refreshed as your data changes
Analytics eventsPer Mixpanel's retention settings for our project
Support correspondenceIn our mailbox, for as long as it is useful as support history
Support form send countsA one-way code of your network address and of your email, deleted within the hour (§3.6)

Deleting your account removes your account row and everything keyed to it — health summaries, circle memberships, invites, nudges, notifications, push tokens, challenge entries and their events, win streaks, achievements, watch levels, feedback you sent and your profile photo — by database cascade. Backups may retain copies for a limited period before rotating out.

09Your rights and choices

Everyone, wherever you live, can:

  • Access the data we hold about you
  • Correct your display name, photo and profile details in the app at any time
  • Delete your account and all associated data
  • Export a machine-readable copy of your data
  • Withdraw consent for health access at any time, in your device settings, without losing your account
  • Remove the period days you logged in your phone's own Health or Health Connect app, or by clearing the day in Bellwether. Those entries live in your device's health store, not on our servers, so deleting your Bellwether account does not remove them
  • Turn off push notifications in your device settings
  • Disconnect from any person in your circle

To delete your account, open Profile → Delete Account in the app. You confirm by typing your email address, and the deletion runs immediately — there is no waiting period and no undo.

To exercise any other right, or to delete your account without access to the app, email bellwether.mobile@gmail.com from the address on your account. We will respond within 30 days.

If you are in California

Under the CCPA/CPRA you have the right to know what we collect and why, to delete it, to correct it, to obtain a portable copy, and to limit the use of sensitive personal information. Health data is sensitive personal information; we use it only to provide the service you asked for and for no secondary purpose, which is the limit the law allows you to request. We do not sell or share personal information, so there is nothing to opt out of — but you may still submit a request and we will confirm this in writing. We will never discriminate against you for exercising these rights. You may use an authorized agent; we will verify their authority.

If you are in the EU, UK or Switzerland

Our legal bases are: your explicit consent for health data (Art. 9(2)(a) GDPR — this is special-category data, and the device permission prompt is where you give that consent); performance of a contract for account and circle features; and legitimate interests for security, abuse prevention and product analytics. You have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent at any time without affecting prior processing. You may lodge a complaint with your national supervisory authority.

Your data is processed in the United States. Where personal data is transferred out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into our agreements with the providers in §6.

Other US states

If you live in Colorado, Connecticut, Virginia, Utah, Texas, Oregon or another state with a comprehensive privacy law, you have comparable rights of access, correction, deletion and portability, and the right to appeal a refusal. Use the same address above.

10Security

  • Row-level security in the database enforces the sharing rules in §5 for every read and write, so the rules hold even against direct API calls the app itself would never make.
  • Encryption in transit (TLS) everywhere, and at rest on our servers.
  • On-device encryption — your session and cached health data live in the iOS Keychain or Android KeyStore, not in plain files. Sign-out wipes cached health data, cached circle data and cached profile images, so the next person to use the device cannot see them.
  • No user enumeration — finding someone requires their full, exact email address. Partial-match search was deliberately removed, so nobody can browse the user list or fish for addresses.
  • No secrets in the app binary — the AI provider keys live only in our server environment. The app cannot reach any AI provider directly.
  • Rate limiting on AI requests, and expiring, single-purpose invite codes.

No system is perfectly secure. If you discover a vulnerability, please report it to bellwether.mobile@gmail.com rather than disclosing it publicly, and we will work with you.

11Children

Bellwether is not directed to children under 13, and we do not knowingly collect personal information from them. If you are between 13 and 18, you may use Bellwether only with the involvement and consent of a parent or legal guardian.

Because Bellwether shares health data between family members, we ask parents to be especially deliberate: adding a minor to a circle means an adult can see that minor's sleep and activity data. Please make sure the minor understands and agrees.

If you believe a child under 13 has given us personal information, email bellwether.mobile@gmail.com and we will delete it promptly.

12International users

Bellwether is operated from the United States and your data is processed there. If you use the app from outside the US, you are transferring your data to the US, where privacy laws differ from those in your country. Section 9 describes the safeguards that apply.

13Changes to this policy

We will post any changes here with a new “Last updated” date. For changes that materially affect how we handle your health data, we will notify you in the app or by email before they take effect, and where the law requires it we will ask for your consent again.

14Contact

Email · bellwether.mobile@gmail.com

Support page · bellw.app/support — the form there reaches the same inbox

For privacy requests, please write from the email address on your account, or tell us enough to verify that the account is yours.