Skip to content
Privacy

What we collect,in plain words.

Most privacy policies are written for litigation. This one is written for you. Nine sections, in the order of the questions people actually ask. We’ll update this page as the product evolves — better to be accurate than to pin ourselves to a promise we can’t keep.

§ I

Our approach

WellPal is in active development. As a small team, we want to be honest about what we’re still figuring out: the exact shape of analytics, how we’ll measure growth, what telemetry helps us make the app better. We’d rather tell you what’s true today than promise something for forever that we may need to adjust as we learn.

§ II

What we collect

A short list, in plain words. An email address when you join the WellPal waitlist or sign in, so we can send launch updates or keep your account and history with you. The Apple Health data you choose to share — read on your device to notice patterns and help. Basic, aggregate signals about how the app is used and where it breaks, so we can fix problems and make it better. And, in Ai4RD, the messages you send while a session is open. We try to keep each of these to the minimum that makes the product work.

§ III

What we try to do

Collect only what helps us build a better product. Tell you, in plain English, what we collect and why. Avoid selling data to advertisers. Avoid building a profile of who you are. When something changes, update this page and surface the change inside the app.

§ IV

WellPal specifics

WellPal reads your Apple Health data on your device, read-only, to notice patterns and help. To explain what your numbers mean, Pal sends a short, structured summary of the relevant context to a language model through a privacy-respecting proxy. It never sends your raw HealthKit history, and no identity is attached to those requests. Your health data is never sold.

§ V

Ai4RD specifics

Ai4RD sessions stream through OpenRouter for inference and through Perplexity for source retrieval. The route does not log message content. Sessions are stored client-side in your browser’s localStorage so you can revisit them; clearing your browser data clears them on our side.

§ VI

Keeping & deleting your data

We keep what we collect only as long as it’s useful for the purpose we collected it. Waitlist emails are kept in a private Vercel Blob store and used for launch updates; you can ask us to remove yours at any time. You can delete your WellPal account from inside the app, which removes the data tied to it. Ai4RD sessions live in your browser — clearing your browser data clears them. We protect what we hold with standard safeguards: encrypted connections, sign-in handled through a dedicated authentication provider, and credentials kept in the device keychain rather than in plain text.

§ VII

Children

WellPal is intended for users 12 and older. We do not knowingly collect data from children under 13. Ai4RD is intended for adults — clinicians for the doctor mode, and adults seeking to organise questions for a clinician in patient mode.

§ VIII

Changes to this policy

As the product evolves, this page will too. When something material changes, we update the date below and surface the change inside the app rather than quietly editing in place. If a change affects how your data is handled, we’d rather you hear it from us than find out later.

§ IX

Contact

Privacy questions: privacy@wellpal.io. We respond within seven days, by hand. If something here is unclear, we’d rather hear about it directly than have you walk away with a wrong impression.