Privacy Policy

Last updated: 2 August 2026 · Version 1.4 · Applies to: Supplova iOS app and supplova.com

This Privacy Policy explains how Supplova ("we", "us", "our") collects, uses, stores and protects your personal data when you use the Supplova mobile application and website at supplova.com. We are committed to protecting your privacy and handling your data — particularly your health data — with the care it deserves.

Supplova is operated by Rhys Buttle, a sole trader based in England and Wales, United Kingdom. ICO Registration Number: 00014651127.

To contact us about your data: [email protected]

1. What Data We Collect

1.1 Account Data

1.2 Health & Wellness Data

This is special category data under UK GDPR Article 9 and receives the highest level of legal protection. We only collect it with your explicit consent.

Apple Health is read-only. We read your Apple Health data through Apple's on-device HealthKit framework on a read-only basis — primarily your sleep and resting heart rate, plus activity such as steps. We use it to correlate against the supplements you take. We do not write anything back to Apple Health other than your own Supplova logs, we never use your health data for advertising, and we never share it with third parties without your consent.

1.3 Supplement Data

1.4 AI Feature Data

1.5 Basic Technical Data

1.6 Payment Data

2. Why We Collect It — Lawful Basis

2.1 Explicit Consent (UK GDPR Article 6(1)(a) & Article 9(2)(a)) — our primary lawful basis for all health-data processing. We obtain explicit consent separately for: reading health data from Apple Health; and using the app's AI features — the daily insight, the AI Coach chat and the label scanner — which send a summary of your own data to Claude AI (Anthropic). You can withdraw any consent at any time in Profile > Privacy without losing access to core app features.

2.2 Contract (UK GDPR Article 6(1)(b)) — we process account data (name, email) because it is necessary to provide you the Supplova service.

2.3 Legitimate Interests (UK GDPR Article 6(1)(f)) — we use limited, aggregated technical logs (such as device type and operating system version) to keep the app working and secure. This never includes your health data, supplement data, or AI conversations.

3. How We Use Your Data

4. Third Parties We Share Data With

We do not sell your data. We do not share your data with advertisers.

4.1 Anthropic (Claude AI) — the app's AI features send data to Anthropic PBC, which provides the Claude AI model. These features are: the daily insight (a plain-language read of your recent data on your Home screen), the AI Coach chat, and the label scanner (which analyses supplement labels you photograph). None of them sends anything until you have given explicit permission in the app.

Depending on the feature, we send a summary of your own data as context, which may include:

We do not send your name, email address, account ID, or any directly identifying information to Anthropic. Anthropic cannot identify you from what we send.

Equal protection. We confirm that Anthropic provides the same or equal protection for your data as this policy commits to. Anthropic processes your data solely as our processor under its Data Processing Addendum, does not use API inputs or outputs to train its models, does not sell your data, and deletes API logs by default within a short retention window. See: anthropic.com/privacy

Turning it off. You can withdraw this permission at any time in the app under Profile → Privacy → AI features. When you do, Supplova immediately stops sending anything to Anthropic and the AI features switch off. Every other part of the app keeps working.

4.2 Supabase — our database and authentication provider (Supabase Inc., a US company). All app data (your account, supplement logs, health snapshots and AI conversation history) is stored in the Supabase project region we have selected: Central EU (Frankfurt, Germany · eu-central-1). Because this region is inside the EU, your stored data remains within the European Economic Area and is protected by equivalent data-protection standards to the UK. Where personal data is otherwise accessed from a country outside the UK/EEA, that transfer is covered by the safeguards described in Section 4.7. Supabase provides a GDPR-compliant Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum. See: supabase.com/privacy and supabase.com/legal/dpa

4.3 Apple (HealthKit & App Store) — if you connect Apple Health, Apple provides your health data to the app through the on-device HealthKit framework. We do not send HealthKit data back to Apple. See: apple.com/legal/privacy

4.4 Product & ingredient databases (label scanner) — when you scan a supplement label, the recognised label text or barcode is also looked up in public product and ingredient databases to identify the product and check its doses and forms: the NIH Dietary Supplement Label Database (DSLD) and Open Food Facts. These are open-data sources. We send only the label text or barcode needed for the lookup — never your health data, supplement logs, name or any identifying information. Open Food Facts data is made available under the Open Database Licence, and we acknowledge Open Food Facts and DSLD as its sources.

4.5 RevenueCat (subscription management) — we use RevenueCat, Inc. (a US company) to manage and validate your in-app subscription. When you subscribe or restore a purchase, RevenueCat receives your Apple App Store transaction identifiers, your subscription status and the product you purchased, and a pseudonymous app-user identifier that links your subscription to your Supplova account. RevenueCat does not receive your name, email address, health data, supplement data or AI conversations, and it never sees your payment card details — those are handled entirely by Apple. RevenueCat acts as our data processor under a GDPR-compliant Data Processing Addendum. See: revenuecat.com/privacy

4.6 Supplement Reminders — supplement reminders are scheduled and shown locally on your device by Apple's on-device notification system. Their content stays on your device — it is not sent to us or to any third party.

4.7 International Data Transfers — some of the providers above are based outside the United Kingdom, so providing the service involves transferring personal data internationally. We only do this where an appropriate safeguard recognised by UK GDPR (Chapter V) is in place:

You may request a copy of the relevant safeguard by emailing [email protected]. If you do not want your data transferred to Anthropic in the United States, do not grant AI consent (or turn it off in Profile > Privacy > AI features) — the rest of the app remains fully available.

5. How Long We Keep Data

6. Your Rights Under UK GDPR

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

7. Children's Privacy

Supplova is not intended for anyone under the age of 16. We use a date-of-birth check at registration to prevent under-16s from creating accounts. If we become aware that a user is under 16, we will immediately delete their account and all associated data. If you believe a child under 16 has created an account, please contact us at [email protected].

8. Data Security

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and in-app notification at least 30 days before the change takes effect. The current version is always available at supplova.com/privacy and in the app under Profile > Privacy Policy.

10. Contact Us

Email: [email protected]
Website: supplova.com/privacy

We aim to respond to all data-related enquiries within 5 working days and will always respond within 30 days as required by UK GDPR.