envyu

Legal

Privacy Policy

Mobile policy version: 2026-07-18.mobile-v1 · Last updated July 18, 2026

Controller and contact

Stefan Radic, operating as Scailara Labs for Envyu, is the controller for the Envyu website and mobile app. Privacy and rights requests: support@envyu.app.

What the mobile app processes

  • Account data: Supabase user ID, email address, authentication provider, session and consent records.
  • Body and wellbeing data you report: age, sex, height, weight, goals, activity and training preferences, nutrition preferences and allergies, sleep, energy, stress, soreness, check-ins, rituals and reflections.
  • Your content: identity anchors, Coach conversations, feedback, plan actions and other text you choose to enter.
  • Derived information: assessments, plans, patterns, readiness or rhythm descriptions, suggested actions and other inferences generated from your inputs.
  • Purchase data: product, StoreKit environment, transaction identifiers, subscription status and entitlement dates. Envyu does not receive your full payment-card details.
  • Usage and diagnostic data: app version, platform, session and product-interaction events, AI request type, success/error status, timing and token/cost estimates. AI request logs are designed not to store prompt or response text.
  • Technical and security data: IP address, user agent, requested URL, timestamps and server/security logs generated by hosting providers.

The current app does not connect to Apple Health or HealthKit. Envyu uses only the body and wellbeing information you enter directly. We do not claim to measure, diagnose or treat a medical condition.

Website and communication data

Waitlist signup processes your email and consent evidence, source/page, locale, user agent, IP address where available, confirmation and unsubscribe status. If you contact us, we process the address and content you send. A protected editorial tool can process staff uploads and notes with an AI provider; it is not a public app feature.

Where data is stored

App information is stored in an account- or installation-scoped area on your device. When you sign in or use cloud features, account information is also stored in Supabase. Relevant context is sent through Envyu's Vercel-hosted API to OpenAI only when an AI-supported feature is requested. Apple processes authentication and App Store purchases. Resend processes email delivery. Expo/EAS may process build, update-delivery and related technical request data.

Purposes and legal bases

  • Service and contract: account access, cloud sync, purchases and requested app features (GDPR Art. 6(1)(b)).
  • Explicit consent: personalized processing of self-reported body/wellbeing information and AI-provider processing (Arts. 6(1)(a) and, where the data is special-category health data, 9(2)(a)).
  • Legitimate interests: proportionate security, abuse prevention, debugging and service reliability (Art. 6(1)(f)).
  • Legal obligations: records that must be kept for accounting, disputes or binding legal requirements (Art. 6(1)(c)).

Where US state consumer-health or sensitive-data law applies, Envyu relies on the point-of-collection consent presented before personalization and offers withdrawal and deletion controls. This policy is not a substitute for rights available under local law.

AI-supported features

Assessment, daily-plan, insight and Coach requests can include relevant profile, check-in, plan or conversation context. Envyu sends this through its server to OpenAI to generate the response. The client does not contain an OpenAI secret key. AI output can be incomplete or wrong, is not medical advice, and should not be used for diagnosis, treatment or emergencies. Do not enter information that is unnecessary for the feature.

Processors and international transfers

Envyu uses Supabase (authentication/database/storage), Vercel (API and website hosting), OpenAI (requested AI generation), Apple (authentication, App Store and subscription services), Resend (email) and Expo/EAS (app build/update infrastructure). These providers may process data outside the EU/EEA. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Provider scope and settings must be confirmed in the final launch data-processing review.

Retention and deletion

Account content is kept while your account is active unless you delete it or a shorter feature-specific period applies. Account deletion removes the account-scoped local namespace, application database rows, user-owned Storage objects and the Supabase Auth user. Analytics events, AI request logs and Apple transaction-event rows linked to the user are explicitly deleted rather than retained with the user field removed.

A minimal Apple original-transaction ownership tombstone can remain without an Envyu user ID to prevent the same receipt being attached to another account. It contains transaction identity, environment, product and fraud-control timestamps/reason—not health, coaching or behavioural content. Deletion saga audit records contain no email or app payloads and are scheduled to expire after 90 days. Backup copies and provider security logs may persist for a limited recovery/security cycle before deletion or overwrite. Any longer retention required by law or a dispute is limited to that purpose.

Deleting Envyu does not cancel an Apple subscription. Manage or cancel billing in Apple ID Settings. See the account-deletion guide. If a processor step cannot be verified, the app reports a partial result and provides a deletion reference instead of claiming full completion.

Your choices and rights

  • Withdraw personalization and AI consent in Settings; the affected features stop until consent is provided again.
  • Delete the account in Settings. Local deletion proceeds even if cloud deletion needs support follow-up.
  • Request access, correction, restriction, portability or deletion by emailing support.
  • Object to legitimate-interest processing and lodge a complaint with your competent supervisory authority.
  • Unsubscribe from waitlist email using the link in the message.

Withdrawal does not affect processing already carried out lawfully. The current in-app JSON export is limited and is not represented as a complete GDPR access/portability response; contact support for a full rights request.

No sale, advertising or cross-app tracking

Envyu does not sell personal data, use it for third-party advertising, or track people across other companies' apps or websites. The public site does not intentionally load advertising cookies, marketing pixels or public behavioural analytics.

Security and limits

Envyu uses account-scoped local storage, authenticated APIs, row-level database controls and server-side secrets. No system is perfectly secure. Contact support if you suspect an account or privacy incident. Envyu is a general wellbeing product, not emergency or medical care; seek qualified professional or emergency help when appropriate.

Policy changes and contact

Material mobile-policy changes require a new in-app notice and consent where applicable. Questions and rights requests: support@envyu.app.