Back to Home

Privacy Policy

Last updated: May 8, 2026

For a plain-language summary of what we can and cannot read about you, see our Transparency page.

1. Introduction & Our Commitment

søvei ("we," "our," or "us") is committed to protecting your privacy and the security of your personal health information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our health and fitness tracking application.

We understand that health data is among the most sensitive personal information, and we have designed our systems with privacy as a core principle. Your health data belongs to you, not us.

Our Privacy Promise: We will never sell your personal health information. We only share data with third parties when absolutely necessary to provide our services, and we anonymize your data before any AI processing. You have complete control over your data and can export or delete it at any time.

2. Health Data We Collect

To provide our health tracking services, we collect the following categories of data with your explicit consent:

Health & Fitness Data

  • Nutrition: Food logs, calories, macronutrients, micronutrients, water intake, meal timing
  • Workouts: Exercise type, duration, sets, reps, weights, workout history
  • Labs: Lab test results, biomarker values (de-identified from original reports)
  • Sleep: Sleep duration, quality, patterns
  • Body Metrics: Weight, body measurements, body fat percentage
  • Menstrual Cycle: Period dates, symptoms, flow, predictions (if you choose to track)
  • Medications: Medication names, dosages, schedules, refill reminders
  • Supplements: Supplement names, dosages, timing
  • Injuries: Injury type, affected body areas, recovery status
  • Mobility: Assessment results, range of motion data

Account & Profile Data

  • Email address (required for account creation)
  • Name (optional, used for personalization)
  • Age or date of birth (used for health calculations)
  • Biological sex (used for health calculations and cycle tracking)
  • Height (used for BMI and nutrition calculations)
  • Activity level (used for calorie calculations)
  • Health goals (used for personalized recommendations)

Technical Data

  • Device information (type, operating system, app version)
  • IP address (for security and fraud prevention)
  • Usage patterns (feature usage, session duration)
  • Crash reports (to improve app stability)

You can choose not to provide certain data, but some features may be limited without it.

3. We Do Not Sell Your Data

søvei does not sell, rent, or trade your personal health information to third parties. Period.

While we require certain health data to provide our services (nutrition tracking, workout logging, lab results analysis, medication reminders), we have no intention of monetizing this data through sales to advertisers, data brokers, research institutions, or any other third parties.

What We Mean by "No Data Sale"

  • We do not sell your health data to advertisers
  • We do not sell your health data to data brokers
  • We do not sell your health data to insurance companies
  • We do not sell your health data to employers
  • We do not sell your health data to pharmaceutical companies
  • We do not sell your health data to research institutions without your explicit consent
  • We do not share your health data with third parties for their marketing purposes

Future Data Monetization Policy

If our business model ever changes to include any form of data monetization or sharing beyond what is currently described in this policy, we commit to:

  1. Advance Notice: We will notify you at least 30 days before any such change takes effect
  2. Opt-In Only: Any new data sharing will be strictly opt-in. Your data will never be shared without your explicit consent
  3. Compensation: If you choose to opt-in to data sharing programs, you will receive compensation in the form of app credit or subscription discounts
  4. Granular Control: You will be able to choose exactly what data to share and with whom
  5. Easy Withdrawal: You can withdraw consent at any time without penalty

Under California law (CCPA/CPRA): We confirm that we have not sold personal information of California consumers in the preceding 12 months and do not intend to do so.

4. Labs Data: Special Privacy Protections

We apply enhanced privacy protections to lab result data. This data is among the most sensitive health information, and we treat it with the highest level of care.

On-Device Processing

When you upload a lab report PDF or take a photo of your results, the file is processed entirely on your device (in your web browser or mobile app). The original PDF or image is never uploaded to or stored on our servers. We use client-side technology to extract text from the document without transmitting the file itself.

Automatic De-identification

Before any extracted text leaves your device, we automatically remove personally identifiable information (PII) including:

  • Patient names
  • Dates of birth
  • Social Security Numbers
  • Medical Record Numbers (MRN)
  • Account and insurance numbers
  • Addresses, phone numbers, and email addresses
  • Ordering physician names
  • Lab facility identifiers
  • Specimen and accession numbers
  • Insurance information

What We Store

We only store the extracted biomarker values (e.g., "Total Cholesterol: 180 mg/dL") after you review and approve them. These values are associated with your anonymous account identifier but contain no identifying information from the original lab report.

Stored lab data includes: marker name, numeric value, unit of measurement, reference range, and test date. We do not store: the original PDF, patient name, doctor name, lab name, or any other identifying information.

AI Processing

To extract structured data from lab reports, we use artificial intelligence services. The AI only receives de-identified text containing lab values—it never sees your name, date of birth, or any other personal identifiers. The AI cannot determine whose lab results it is processing. See the "AI Processing & Anonymization" section for more details on how we protect your data during AI analysis.

Labs Data Is Never Shared

Your lab results are never shared with third parties except for the de-identified AI processing described above. We do not share your lab data with:

  • Insurance companies
  • Employers
  • Research institutions (without explicit opt-in consent)
  • Pharmaceutical companies
  • Healthcare providers (unless you explicitly choose to export your data)

5. Medication Tracking Privacy

Medication data is highly sensitive information that could affect insurance coverage, employment, or personal relationships if disclosed. We apply special protections to this data.

What Medication Data We Collect

  • Medication names (using standardized RxNorm identifiers)
  • Dosage information
  • Schedule and timing
  • Adherence tracking (whether you marked a dose as taken)
  • Notes you add (optional)

Medication Data and AI Processing

When medication data is included in AI-powered features such as health insights or program generation, medication names and dosages may be shared with AI providers to ensure accurate recommendations and safety checks (e.g., exercise contraindications). Your medication data is associated only with an anonymous identifier — AI providers cannot determine your identity.

Medication Data Is Never Shared

Your medication information is never shared with:

  • Insurance companies
  • Employers
  • Pharmaceutical companies
  • Pharmacies
  • Healthcare providers (unless you explicitly export your data)
  • Family members or emergency contacts (unless you configure this feature)

Data Source

We use RxNorm, maintained by the U.S. National Library of Medicine, for medication identification. This is a one-way lookup—no personal data is sent to RxNorm; we only retrieve standardized medication information.

6. AI Processing & Anonymization

søvei uses artificial intelligence to provide features like meal plan generation, workout programming, lab results analysis, and health insights. We take extensive measures to protect your privacy when using AI services.

AI Providers We Use

We currently use AI services from:

  • Anthropic (Claude): Health analysis, recommendations, coaching, and content processing
  • xAI (Grok): Health analysis, recommendations, coaching, and content processing

Both providers may be used interchangeably for any AI-powered feature. The specific provider used for a given request may vary based on availability and performance.

These providers have committed to not training their models on data submitted through their APIs. Your health data is used only to generate responses for you, not to improve their general AI models.

How We Protect Your Data During AI Processing

Before any data is sent to AI providers, we strip all personally identifiable information. The following is never sent to AI providers:

  • Name and identity: Your name, email address, username, and account ID are never included in AI requests
  • Contact information: Phone numbers, mailing addresses, and other contact details are never shared
  • Location: Geographic information is stripped entirely
  • Financial and insurance data: Payment information, insurance details, and employer information are never sent
  • Appearance and demographics: Photos, hair color, eye color, ethnicity, and other physical descriptors are never shared

Health Data Shared With AI for Accuracy

To provide accurate, personalized health recommendations, certain health metrics are shared with AI providers. These are essential for calculating nutritional needs, generating safe workout programs, and interpreting lab results:

  • Age: Used to calculate basal metabolic rate, recommend age-appropriate exercise intensity, and interpret lab reference ranges
  • Biological sex: Used for accurate nutritional targets, exercise programming, and lab result interpretation
  • Weight and height: Used for calorie and macronutrient calculations, workout load recommendations, and BMI-based health assessments
  • Fitness profile: Goals, experience level, available equipment, injuries, and dietary restrictions — needed for safe, relevant recommendations
  • Health data you log: Nutrition entries, workout history, sleep patterns, lab values, and other data you choose to track — used to generate insights about your specific health trends

This health data is associated only with an anonymous identifier and cannot be linked back to your identity by AI providers.

What AI Providers Cannot Determine

AI providers cannot determine:

  • Your identity, name, or email address
  • Your location or address
  • Your employer or insurance provider
  • Your appearance or demographic information
  • Any way to contact you directly

Anonymous Account Identifiers

Throughout our system, your health data is associated with an anonymous identifier (UUID), not your email address or name. This means even our internal systems do not directly link your personal identity to your health records in most operations.

Aggregate Analytics

Any analytics we perform on user data for product improvement use aggregated, de-identified data that cannot be traced back to individual users. For example, we might analyze "average protein intake across users in their 30s" but never "what John Smith ate for lunch."

7. Third-Party Services

We use third-party services to provide our functionality. We carefully select partners who maintain high privacy and security standards. Here is a complete list of services that may process your data:

AI Service Providers

Two paths exist. Managed AI (default for paid tiers) routes through providers we have a contract with — your de-identified data only goes to xAI or Anthropic. Bring-Your-Own-Key (BYOK) lets you supply your own API key for any supported provider; in that mode the request goes from your browser directly to the provider you chose, under their terms — we are not in the request path and have no record of what was sent.

  • xAI (Grok) — managed + BYOK. Health analysis, meal plans, workout programs, coaching, content processing. Only de-identified data is shared.
  • Anthropic (Claude) — managed + BYOK. Same scope as xAI. Only de-identified data is shared.
  • Google (Gemini)— BYOK only. Available when you add your own Gemini API key in settings. De-identified context is sent directly from your browser to Google under Google's terms.
  • Local / OpenAI-compatible endpoint — BYOK only. If you point søvei at a self-hosted or third-party OpenAI-compatible endpoint, your context goes to whatever URL you configured. We do not validate or inspect the destination.
  • Cloudflare Workers AI — managed only. Image moderation pre-filter (portraits + recipe photos) and audio transcription. Cloudflare processes the bytes only for the immediate inference call and does not retain training-eligible copies under their Workers AI terms.

Infrastructure & Hosting

  • Supabase: For secure data storage, authentication, and database hosting. Supabase is SOC 2 Type II certified and provides encryption at rest (AES-256) and in transit (TLS 1.3).
  • Vercel: For web application hosting. Vercel processes only technical data (IP addresses, request logs) and does not have access to your health data.
  • Upstash: For caching services that improve app performance. Only anonymous identifiers are used for caching.
  • Cloudflare R2: For object storage of user-uploaded images (profile photos, recipe photos, progress photos). Files are stored under random UUID keys with no correlation to your account email or name. Progress photos are end-to-end encrypted in your browser before upload — Cloudflare holds only ciphertext that we have no key to decrypt.

Error Monitoring

  • Sentry: For application error and crash reports. Health-data fields and identifiers are stripped from every event before it leaves your browser by an in-process scrubber; Sentry receives only the error type, stack trace, and a per-session correlation ID. Session replay is disabled. Sentry is a processor, not an analytics or advertising service.

Address Autocomplete

  • Google Places API: When you type an address into a search field that supports autocomplete, the partial query is sent to Google to return suggestions. No health data is included; the query is the address fragment you typed.

Payment Processing

  • Stripe: For payment processing and subscription management. Stripe processes your payment information but does not have access to your health data. Stripe is PCI DSS Level 1 compliant.

Nutrition Data Sources

  • USDA FoodData Central: We query the USDA food database to provide accurate nutrition information. No personal data is sent to the USDA—we only send food search queries.
  • Open Food Facts: We query this open food database for barcode lookups. No personal data is sent to Open Food Facts—we only send barcode numbers.

Verification Services

  • SheerID: For student, military, and healthcare worker discount verification. SheerID receives only the information needed to verify your eligibility status (name, email, institution). SheerID does not receive any health data.

Health Platform Integrations

  • Apple Health / HealthKit (iOS): If you connect Apple Health, we import health data (steps, weight, sleep, workouts) with your permission. You may optionally enable export to send your manually logged data back.No data is sent to Apple unless you explicitly enable export—HealthKit runs entirely on your device.
  • Google Fit / Health Connect (Android): If you connect Google Fit or Health Connect, we import health data (steps, weight, sleep, workouts) with your permission. You may optionally enable export to send data back. No data is sent to Google unless you explicitly enable export in your sync settings.

Email Communications

  • Resend: For transactional emails (password reset, subscription confirmations). Resend receives your email address but no health data.

Note: We do not use any third-party advertising, tracking, or analytics services that would share your data with advertisers.

8. Data Security

We implement comprehensive security measures to protect your health data:

Encryption

  • All data in transit is encrypted using TLS 1.3
  • All data at rest is encrypted using AES-256 encryption
  • Database connections use encrypted channels
  • Backup data is encrypted

Access Controls

  • Row-Level Security (RLS) ensures users can only access their own data
  • Production database access is limited to essential personnel only
  • All administrative access is logged and audited
  • We use multi-factor authentication for all administrative accounts

Infrastructure Security

  • We use SOC 2 Type II compliant cloud infrastructure (Supabase)
  • Regular security assessments and penetration testing
  • Automated vulnerability scanning
  • Rate limiting to prevent abuse
  • DDoS protection

Secure Development

  • Secure coding practices following OWASP guidelines
  • Input validation on all user-submitted data
  • No secrets or API keys in client-side code
  • Regular dependency updates for security patches

9. Your Rights

You have comprehensive rights over your health data. We have built tools directly into søvei to help you exercise these rights:

Access

You can view all data we store about you at any time through the app. Navigate to Settings → Your Data to see a complete overview of your stored information.

Export (Data Portability)

You can export your data in standard formats (JSON, CSV) at any time. Your export includes:

  • Profile information
  • All nutrition logs
  • All workout logs
  • Lab results
  • Sleep logs
  • Cycle tracking data
  • Medication tracking
  • AI conversation history
  • Settings and preferences

Correction

You can correct or update any inaccurate data directly in the app. If you need assistance, contact us at privacy@sovei.me.

Deletion

Two deletion paths exist and they behave differently — please choose carefully.

Per-category deletion (Settings → Your Data → delete a specific category, e.g. Sleep, Workouts, Cycle): the rows are immediately hidden from the app and enter a 30-day soft-deletion recovery window. You can restore them at any point in those 30 days from Settings → Privacy. After 30 days they are permanently and irreversibly purged.

Full-account deletion (Settings → Your Data → Delete Account): this is immediate and irreversible. There is no 30-day recovery window. Your account row, every health-data table tied to your account, and your authentication record are removed in one transaction the moment you confirm. We cannot recover the account afterwards. If you may want your data back later, export it first (Settings → Your Data → Export).

In both cases:

  • Audit logs are retained for 6 years per regulatory requirements (these contain only metadata, not your actual health data)
  • Payment records may be retained as required by financial regulations
  • Backups are purged on the platform provider's standard schedule (typically within 90 days)

Opt-Out

You can opt out of:

  • Marketing emails (via unsubscribe link or Settings)
  • Push notifications (via device settings)
  • Specific feature data collection (via Settings → Privacy)
  • Health platform integrations (disconnect anytime in Settings)

Restrict Processing

You can request that we restrict processing of your data while you verify its accuracy or while we assess a deletion request.

How to Exercise Your Rights

Most rights can be exercised directly in the app under Settings → Your Data. For any requests that cannot be completed in-app, or if you need assistance, contact us at privacy@sovei.me. We will respond within 30 days.

10. Data Retention

We retain your health data for as long as your account is active. This allows you to track trends over months and years. If you delete your account, the data is removed immediately (see §9 above for the difference between per-category and full-account deletion). The exceptions are limited records we are required by law to retain — primarily audit metadata and payment records — described below.

Per-Category Deletion & Recovery

When you delete a category of health data (e.g. all your sleep logs), the rows enter a 30-day soft-deletion recovery window. During this window:

  • The rows are immediately hidden from the app and no longer visible in your dashboard, logs, or reports
  • You may recover them at any time from Settings → Privacy
  • After 30 days, the rows are permanently and irreversibly deleted and cannot be recovered by you or by us

Full-Account Deletion

Deleting your entire account (Settings → Your Data → Delete Account) is immediate and irreversible. There is no 30-day recovery window for full-account deletion. Export your data first if you may want it later.

Active Account Data

While your account is active, all health data is retained indefinitely unless you choose to delete specific entries. You control what data to keep and what to remove.

Inactive Account Policy

If your account is inactive for 36 months (no logins), we will send you a notification email before taking any action. If you do not respond or log in within 30 days of the notification, we may delete your account and associated data to protect your privacy.

Retention Periods

The following table summarizes how long different categories of data are retained:

Data CategoryRetention Policy
Health data (nutrition, workouts, sleep, body metrics, cycle, medications, supplements, injuries)Retained while account is active; 30-day recovery period after deletion, then permanently deleted
Lab resultsRetained while account is active; 30-day recovery period after deletion, then permanently deleted. Anonymized copies may be retained up to 6 years per healthcare compliance requirements
AI conversations30-day recovery period after deletion, then permanently deleted
Audit logs (PHI access, consent records)6 years (legal compliance; metadata only, no health data)
Payment records7 years (financial compliance)
Edge function logs90 days
Threat detection logs180 days after resolution
BackupsPurged from backup systems within 90 days of deletion

Legal Hold: If required by legal proceedings, relevant data may be preserved beyond the retention periods listed above.

PHI Audit Logs

To comply with healthcare data protection best practices, we maintain audit logs that record when protected health information (PHI) is accessed. These audit logs are retained for 6 years after the access event, even if you delete your account. Audit logs contain only metadata (timestamps, action types, user identifier hashes) and do not contain the actual health data that was accessed.

Consent Records

Records of your privacy consent choices (when you granted or withdrew consent for specific data processing) are retained for 6 years for legal compliance purposes. This helps us demonstrate that we obtained proper consent for data processing.

11. State-Specific Privacy Rights

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You can request deletion of your personal information
  • Right to Correct: You can request correction of inaccurate personal information
  • Right to Opt-Out of Sale: We do not sell your personal information, so there is no sale to opt out of
  • Right to Limit Use of Sensitive Personal Information: You can request that we limit our use of sensitive personal information to what is necessary to provide the service
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

California "Shine the Light" Law: We do not share personal information with third parties for their direct marketing purposes.

Washington Residents (My Health My Data Act)

If you are a Washington resident, you have additional rights under the Washington My Health My Data Act:

  • Right to Know: You can request a list of all third parties with whom we have shared your consumer health data
  • Right to Withdraw Consent: You can withdraw consent for the collection or sharing of consumer health data at any time
  • Right to Delete: You can request deletion of your consumer health data
  • Geofence Prohibition: We do not use geofencing around healthcare facilities to collect or use consumer health data

Virginia, Colorado, Connecticut Residents

If you are a resident of Virginia, Colorado, or Connecticut, you have similar rights under your state's privacy laws, including the right to access, correct, delete, and obtain a copy of your personal data, as well as the right to opt out of targeted advertising (which we do not conduct).

Nevada Residents

Nevada residents have the right to opt out of the sale of personal information. As stated above, we do not sell personal information. If you wish to be added to our internal "do not sell" list, contact privacy@sovei.me.

European Union Residents (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on your explicit consent, which you can withdraw at any time
  • Right to Object: You can object to processing of your personal data
  • Right to Restrict Processing: You can request restriction of processing of your personal data
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority

12. International Data Transfers

søvei is based in the United States. If you are accessing our service from outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States.

For users in the European Economic Area (EEA), we rely on the following mechanisms for international data transfers:

  • Standard Contractual Clauses approved by the European Commission
  • Your explicit consent when you create an account

Our data processors (Supabase, Stripe, AI providers) also maintain appropriate safeguards for international data transfers.

13. HIPAA Compliance Notice

søvei is a consumer health application and is not a covered entity under HIPAA (Health Insurance Portability and Accountability Act). HIPAA applies to healthcare providers, health plans, and healthcare clearinghouses—not to consumer health apps like ours.

However, we voluntarily adopt many HIPAA-aligned practices to protect your health information, including:

  • Data encryption at rest (AES-256) and in transit (TLS 1.3)
  • Access controls and authentication
  • PHI audit logging with 6-year retention
  • Employee training on data privacy
  • Incident response procedures
  • Business Associate Agreements with applicable vendors

If you receive lab results through a healthcare provider, their handling of that information is subject to HIPAA. Our handling of data you voluntarily provide to us is governed by this Privacy Policy and applicable consumer privacy laws.

FTC Health Breach Notification Rule

As a provider of personal health records, we are subject to the FTC's Health Breach Notification Rule. In the event of a data breach involving your health information, we will notify you and the FTC as required by law. See the "Data Breach Notification" section below for more details.

14. Children's Privacy

søvei is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA).

Users between 13 and 16 years of age in the European Union may require parental consent under GDPR. If you are in this age group, please ensure you have parental permission before using søvei.

If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at privacy@sovei.me and we will:

  • Verify your parental relationship
  • Delete all personal information associated with the child's account
  • Terminate the child's account
  • Confirm deletion in writing within 10 business days

15. Cookies and Local Storage

søvei uses cookies and similar technologies for the following purposes:

Essential Cookies

Required for authentication and maintaining your session. These cannot be disabled without affecting app functionality. Essential cookies include:

  • Session cookies for authentication
  • CSRF protection tokens
  • Security cookies

Preference Cookies

Store your settings like theme preference (dark/light mode), display units, and other UI preferences. These help us remember your choices so you don't have to set them every time you visit.

Local Storage

We use browser local storage to cache data for offline access and improve performance. Health data cached locally remains entirely on your device and is never transmitted unless you explicitly save or sync.

What We Do NOT Use

  • Advertising cookies
  • Third-party tracking cookies
  • Social media tracking pixels
  • Cross-site tracking
  • Device fingerprinting

We do not sell your browsing data or share it with advertisers.

16. Data Breach Notification

In the unlikely event of a data breach affecting your personal health information, we will:

  1. Notify affected users within 60 days of discovering the breach (or sooner if required by applicable state law)
  2. Notify the Federal Trade Commission (FTC) as required by the Health Breach Notification Rule
  3. Notify state attorneys general as required by state law
  4. Post notice on our website if the breach affects more than 500 individuals
  5. Notify major media outlets if the breach affects more than 500 residents of a single state

Breach notifications will include:

  • A description of what happened
  • The types of information involved
  • Steps we are taking in response
  • Steps you can take to protect yourself
  • Contact information for questions

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • Minor Changes:We will update the "Last updated" date at the top of this page
  • Material Changes: We will notify you by email and/or through a prominent notice in the app at least 30 days before the changes take effect
  • Changes Requiring Consent: If changes require additional consent under applicable law, we will obtain that consent before implementing the changes

We encourage you to review this policy periodically. Your continued use of søvei after changes take effect constitutes acceptance of the revised policy.

A history of previous versions of this Privacy Policy is available upon request.

18. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about our data practices, please contact us at:

Privacy Inquiries:
Email: privacy@sovei.me

Data Protection Officer:
Email: dpo@sovei.me

Email is the canonical channel for privacy inquiries. We'll publish a physical mailing address once incorporation is complete; until then, privacy@sovei.me is the route on record.

We aim to respond to all privacy inquiries within 30 days. For requests involving your data rights (access, deletion, correction), we will acknowledge receipt within 10 business days and complete your request within the timeframe required by applicable law.

Summary:At søvei, we believe your health data belongs to you. We collect only what's necessary to provide our services, we never sell your data, and we go above and beyond to protect your privacy. You can access, export, or delete your data at any time. If you have any questions, we're here to help.