Privacy Policy
Last updated: 2 August 2026 · Version 1.4 · Applies to: Supplova iOS app and supplova.com
This Privacy Policy explains how Supplova ("we", "us", "our") collects, uses, stores and protects your personal data when you use the Supplova mobile application and website at supplova.com. We are committed to protecting your privacy and handling your data — particularly your health data — with the care it deserves.
Supplova is operated by Rhys Buttle, a sole trader based in England and Wales, United Kingdom. ICO Registration Number: 00014651127.
To contact us about your data: [email protected]
1. What Data We Collect
1.1 Account Data
- Full name
- Email address
- Password (stored as a secure hash — we never see your actual password)
- Year of birth (retained as proof of our age-verification check)
- Biological sex (optional — used only to personalise wellness recommendations)
- Height and weight (optional)
- Your health goals
- Your timezone and display unit preference (metric or imperial)
1.2 Health & Wellness Data
This is special category data under UK GDPR Article 9 and receives the highest level of legal protection. We only collect it with your explicit consent.
- Sleep data — hours slept and sleep stages — read from Apple Health
- Resting heart rate — read from Apple Health
- Steps and daily activity — read from Apple Health
- Your daily check-in: quick self-ratings for energy, sleep, soreness and mood (each on a 1–5 scale) that you enter yourself in the app
- Health goals you tell us about
- Any sensitivities or medical conditions you choose to share
Apple Health is read-only. We read your Apple Health data through Apple's on-device HealthKit framework on a read-only basis — primarily your sleep and resting heart rate, plus activity such as steps. We use it to correlate against the supplements you take. We do not write anything back to Apple Health other than your own Supplova logs, we never use your health data for advertising, and we never share it with third parties without your consent.
1.3 Supplement Data
- Supplements you log manually or through the app (your stack)
- Dosage, timing and frequency of each supplement
- Whether you took or skipped each scheduled dose, and your adherence history
1.4 AI Feature Data
- Messages you send to the AI Coach chat and the responses generated for you
- The plain-language summary of your own data we send to the AI as context — your stack, recent logs, sleep and resting-heart-rate trends, and per-supplement result summaries (see Section 4)
- Label text and barcodes captured by the label scanner when you scan a product
- The AI model used and approximate token count (for cost management)
1.5 Basic Technical Data
- Device type and operating system version (recorded in our server request logs to keep the service running and secure)
1.6 Payment Data
- Subscription status (free or Pro)
- Transaction identifiers from the Apple App Store
- We never see or store your payment card details — these are handled entirely by Apple
2. Why We Collect It — Lawful Basis
2.1 Explicit Consent (UK GDPR Article 6(1)(a) & Article 9(2)(a)) — our primary lawful basis for all health-data processing. We obtain explicit consent separately for: reading health data from Apple Health; and using the app's AI features — the daily insight, the AI Coach chat and the label scanner — which send a summary of your own data to Claude AI (Anthropic). You can withdraw any consent at any time in Profile > Privacy without losing access to core app features.
2.2 Contract (UK GDPR Article 6(1)(b)) — we process account data (name, email) because it is necessary to provide you the Supplova service.
2.3 Legitimate Interests (UK GDPR Article 6(1)(f)) — we use limited, aggregated technical logs (such as device type and operating system version) to keep the app working and secure. This never includes your health data, supplement data, or AI conversations.
3. How We Use Your Data
- To create and manage your account
- To personalise the app based on your health data and goals
- To correlate the supplements you take against your Apple Health data and your daily check-in, so we can show whether there is a signal in your own data — a pattern, not proof of cause
- To generate your daily plain-language insight, power the AI Coach chat, and analyse supplement labels you scan — by sending a summary of your own data to Claude AI (Anthropic); see Section 4 for exactly what is sent
- To remind you to take your supplements at times you choose (delivered locally on your device — see Section 4)
- To track supplement adherence and show you your progress over time
- To process your Pro subscription payment through Apple
- To send you important account emails (verification, password reset, policy updates)
4. Third Parties We Share Data With
We do not sell your data. We do not share your data with advertisers.
4.1 Anthropic (Claude AI) — the app's AI features send data to Anthropic PBC, which provides the Claude AI model. These features are: the daily insight (a plain-language read of your recent data on your Home screen), the AI Coach chat, and the label scanner (which analyses supplement labels you photograph). None of them sends anything until you have given explicit permission in the app.
Depending on the feature, we send a summary of your own data as context, which may include:
- Your sleep — hours slept and sleep-stage breakdown
- Your resting heart rate, steps and daily activity, and recent trends in these
- Your active supplement stack — names, doses, units and how often you take them
- Your recent supplement logs and how many of today's scheduled doses you have taken
- Per-supplement result summaries — how a supplement appears to line up with your own data
- Your daily check-in ratings
- Your health goals, biological sex and approximate age
- Anything you type into the AI Coach, and your last few chat messages for context
- For the label scanner: the label text and barcode recognised from the product you scanned
We do not send your name, email address, account ID, or any directly identifying information to Anthropic. Anthropic cannot identify you from what we send.
Equal protection. We confirm that Anthropic provides the same or equal protection for your data as this policy commits to. Anthropic processes your data solely as our processor under its Data Processing Addendum, does not use API inputs or outputs to train its models, does not sell your data, and deletes API logs by default within a short retention window. See: anthropic.com/privacy
Turning it off. You can withdraw this permission at any time in the app under Profile → Privacy → AI features. When you do, Supplova immediately stops sending anything to Anthropic and the AI features switch off. Every other part of the app keeps working.
4.2 Supabase — our database and authentication provider (Supabase Inc., a US company). All app data (your account, supplement logs, health snapshots and AI conversation history) is stored in the Supabase project region we have selected: Central EU (Frankfurt, Germany · eu-central-1). Because this region is inside the EU, your stored data remains within the European Economic Area and is protected by equivalent data-protection standards to the UK. Where personal data is otherwise accessed from a country outside the UK/EEA, that transfer is covered by the safeguards described in Section 4.7. Supabase provides a GDPR-compliant Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum. See: supabase.com/privacy and supabase.com/legal/dpa
4.3 Apple (HealthKit & App Store) — if you connect Apple Health, Apple provides your health data to the app through the on-device HealthKit framework. We do not send HealthKit data back to Apple. See: apple.com/legal/privacy
4.4 Product & ingredient databases (label scanner) — when you scan a supplement label, the recognised label text or barcode is also looked up in public product and ingredient databases to identify the product and check its doses and forms: the NIH Dietary Supplement Label Database (DSLD) and Open Food Facts. These are open-data sources. We send only the label text or barcode needed for the lookup — never your health data, supplement logs, name or any identifying information. Open Food Facts data is made available under the Open Database Licence, and we acknowledge Open Food Facts and DSLD as its sources.
4.5 RevenueCat (subscription management) — we use RevenueCat, Inc. (a US company) to manage and validate your in-app subscription. When you subscribe or restore a purchase, RevenueCat receives your Apple App Store transaction identifiers, your subscription status and the product you purchased, and a pseudonymous app-user identifier that links your subscription to your Supplova account. RevenueCat does not receive your name, email address, health data, supplement data or AI conversations, and it never sees your payment card details — those are handled entirely by Apple. RevenueCat acts as our data processor under a GDPR-compliant Data Processing Addendum. See: revenuecat.com/privacy
4.6 Supplement Reminders — supplement reminders are scheduled and shown locally on your device by Apple's on-device notification system. Their content stays on your device — it is not sent to us or to any third party.
4.7 International Data Transfers — some of the providers above are based outside the United Kingdom, so providing the service involves transferring personal data internationally. We only do this where an appropriate safeguard recognised by UK GDPR (Chapter V) is in place:
- Anthropic (Claude AI) — United States. When you use the app's AI features, the data described in Section 4.1 is processed by Anthropic in the United States. This transfer is governed by Anthropic's Data Processing Addendum, which is incorporated into Anthropic's Commercial Terms of Service and includes the EU Standard Contractual Clauses (Module Two) together with the UK International Data Transfer Addendum. Anthropic does not use API inputs or outputs to train its models, and its API logs are deleted by default within a short retention window.
- Supabase — Central EU (Frankfurt, Germany · eu-central-1). Your stored data resides in the EU, so no transfer outside the UK/EEA occurs for data at rest. To the extent Supabase (a US company) accesses data for support or operational purposes, that access is covered by Supabase's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK Addendum.
- Apple. To the extent Apple processes your data outside the UK, it relies on its own appropriate transfer safeguards (such as the Standard Contractual Clauses and the UK Addendum), as set out in its privacy policy linked above.
- RevenueCat — United States. Your subscription status and Apple App Store transaction identifiers are processed by RevenueCat in the United States. This transfer is governed by RevenueCat's Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Product & ingredient databases (DSLD, Open Food Facts). The label scanner's lookups query databases hosted outside the UK, but we send only the label text or barcode of the product you scanned — no personal data — so no transfer of your personal data takes place.
You may request a copy of the relevant safeguard by emailing [email protected]. If you do not want your data transferred to Anthropic in the United States, do not grant AI consent (or turn it off in Profile > Privacy > AI features) — the rest of the app remains fully available.
5. How Long We Keep Data
- Account data: retained for the lifetime of your account plus 30 days after deletion
- Health data snapshots: retained for 13 months, then automatically deleted
- Supplement logs: retained for the lifetime of your account plus 30 days after deletion
- AI conversation history: retained for 12 months, then automatically deleted
- Year of birth: retained indefinitely as proof of our age-verification check
- Payment records: retained for 7 years as required by UK tax law
- Consent records: retained for the lifetime of your account plus 3 years
6. Your Rights Under UK GDPR
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
- Right of Access: request a copy of all personal data we hold about you
- Right to Rectification: ask us to correct inaccurate data
- Right to Erasure: delete your account and all associated data in Profile > Delete Account
- Right to Restrict Processing: ask us to stop processing your data in certain ways
- Right to Data Portability: request a copy of your supplement history and health data in a machine-readable format by emailing [email protected]
- Right to Object: object to processing based on legitimate interests (Section 2.3)
- Right to Withdraw Consent: withdraw any consent at any time in Profile > Privacy
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
7. Children's Privacy
Supplova is not intended for anyone under the age of 16. We use a date-of-birth check at registration to prevent under-16s from creating accounts. If we become aware that a user is under 16, we will immediately delete their account and all associated data. If you believe a child under 16 has created an account, please contact us at [email protected].
8. Data Security
- All data is encrypted in transit using HTTPS/TLS 1.3
- All data is encrypted at rest using AES-256 in Supabase
- Row-level security ensures you can only access your own data
- API keys and service credentials are stored in server-side environment variables — never in the app code
- Your password is hashed — we never store or see your actual password
- In the event of a personal-data breach, we will report it to the ICO within 72 hours of becoming aware where required by UK GDPR Article 33, and notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34)
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and in-app notification at least 30 days before the change takes effect. The current version is always available at supplova.com/privacy and in the app under Profile > Privacy Policy.
10. Contact Us
Email: [email protected]
Website: supplova.com/privacy
We aim to respond to all data-related enquiries within 5 working days and will always respond within 30 days as required by UK GDPR.