Aletheia Privacy Policy ======================= Effective date: September 18, 2026 (replaces the version of September 4, 2026) Aletheia ("the app," "we," "us") is an independently operated personal skin, food, and habit tracking app based in the United States, reachable at the contact address below. This policy explains what data the app collects, exactly how it is used, and the choices and rights you have. The short version: we collect only what the app needs to work, we do not run ads, we never track you across other apps or sell your data, and you can permanently delete everything in one tap inside the app. We measure how the app itself is used — which is described in full in Section 5 — and none of your skin, food, or health data is part of that. Because Aletheia handles health-related information, we also maintain a separate Consumer Health Data Privacy Policy (https://pjiitnetdbdilskbdkwd.supabase.co/functions/v1/legal/consumer-health-data) as required by Washington's My Health My Data Act and similar laws. Where the two overlap, that policy governs consumer health data. 1. Data we collect ------------------ Account information (source: you, or Apple or Google if you use their sign-in button). Email address and, optionally, your name. Used to create, secure, and operate your account. Signing in with Apple or Google. You can create your account with an email and password, or with the Sign in with Apple or Sign in with Google buttons. If you use one of those buttons, that company authenticates you and passes us your name and email address — which also means they learn that you use Aletheia. They are told nothing else: not your logs, your breakouts, your food, your health data, or anything you do in the app after signing in. Their handling of the sign-in itself is governed by their own privacy policies. If you would rather no third party know you use this app, sign up with an email address and password instead. Sign in with Apple also offers Hide My Email, which gives us a private relay address instead of your real one; that works fine here, and it is the address we will use to reach you. Skin and habit data (source: you). Daily logs — sleep hours and quality, stress level, water intake, diet flags (e.g., dairy, sugar, alcohol), new-product use, skin rating, and optional notes; breakout entries (date and facial region); custom triggers you create; suspected triggers you select during onboarding. Onboarding questionnaire answers (source: you). Before you create an account, Aletheia asks about your skin history and routine: how long you have had breakouts, where they appear, your age, what you have tried before, how your skin affects your confidence and day-to-day behaviour, what you are hoping to achieve, and roughly how many days a week you eat dairy and sugar, how many hours you sleep, and your typical stress level. These answers are kept on your device, in storage tied to your account, and are used to shape what the app shows you. Two of them — the name you asked to be called and the suspected triggers you picked — are saved to your account on our server so that they follow you to a new device. Your age is used to confirm you meet the minimum age in our Terms. If you sign out or delete the app, the on-device answers go with it. Food and ingredient data (source: you, and the Open Food Facts database). When you scan a barcode or add a food by hand, Aletheia stores: the barcode, the product name and brand, the product's ingredient list, the acne-relevant ingredient categories the app matched in that list (e.g., dairy, added sugar, refined carbohydrate, whey), how many times you have logged it, and when. Foods you attach to a day are stored on that day's log along with the skin score the product had at the time. Camera (source: your device). If you use the barcode scanner, the app opens a live camera preview and looks for a barcode in the frame, on your device, using Apple's on-device VisionKit. No photo or video is ever captured, saved, or transmitted — the only thing that leaves the frame is the barcode digits. Aletheia has no photo library access at all. You can refuse or later revoke camera access in iOS Settings and the food features still work: you can type a barcode number or add a food by hand. Apple Health data (source: Apple Health, only if you connect it). Read-only access to sleep, resting heart rate, heart-rate variability (HRV), step count, exercise time, and dietary water — used solely to pre-fill your daily log. A value becomes part of your stored data only when you save that log. We never write to Apple Health, and we do not store Apple Health data in iCloud. App usage and diagnostics (source: your device). So we can see where the app confuses people and where it breaks, we record a short name for certain actions you take — for example that an onboarding step was reached, that a food was scanned, or that the paywall was shown — along with your device model, iOS version, app version, and approximate country. We do not record which screens you open. Crashes additionally send a stack trace and the app's state at the moment it crashed. No health, skin, food, or log content is ever attached to any of this. Section 5 describes it in full, including how to turn it off. Data we do NOT collect. No precise location, no photo library access, no contacts, no advertising identifiers, no device fingerprinting, no cross-app tracking. We do not capture, store, or transmit camera images, and we do not record your screen. Our iOS privacy manifest declares no tracking, and the App Store privacy label matches this policy. 2. How we use your data ----------------------- • To provide the service you asked for: showing your history, streaks, calendars, and trends; computing correlations between your habits, your food, and your breakouts on your device. • To score food: a product's 0–100 skin score is calculated on your device, by combining published research weights for the ingredient categories found in that product with what your own logs have shown so far. Nothing is uploaded to score a product. • To generate AI insights: if you opt in, a summary of your logged patterns is sent through our own server to Anthropic's Claude API to write a plain-language explanation. Section 3 lists exactly what is and is not sent. Your name, email, and account identifiers are never included in these requests. • To improve the app: counting how many people finish onboarding and where they stop, whether people come back after a week, and which features get used — so the app can be fixed where it fails rather than where we guess it fails. Section 5 covers this. • To operate your subscription: purchases are processed entirely by Apple; we never see your payment details. • To secure the service: authentication, abuse prevention, and rate limiting. We do not use your data for advertising or marketing, and consistent with Apple's HealthKit rules, health and fitness data is never used for advertising, other use-based data mining, or sold to data brokers — full stop. 3. AI features and our AI provider (Anthropic) ---------------------------------------------- Aletheia's written explanations of your patterns are generated by a third party: Anthropic's Claude API, operated by Anthropic PBC in the United States. This section describes that sharing in full. Nothing is sent until you opt in. The first time you run an AI analysis, Aletheia shows you this same list and asks for your explicit permission. Declining is a real choice: no data is sent, and the app keeps working — your patterns, statistics, and food scores are still calculated on your device, and only the written explanation is withheld. You can withdraw permission at any time in Settings → Privacy & Data, which stops all further sending immediately. If we ever change what is sent or who it is sent to, your existing permission stops applying and the app asks you again. What is sent, once you opt in: • Your daily logs — averages and day counts from what you log: sleep hours and quality, stress level, water intake, skin rating, and how many days included dairy, high-glycemic food, alcohol, or a new product. • Your breakout events — how many breakouts you logged and when, so the days before them can be compared against your clearer days. When Aletheia comments on a breakout you just logged, its type and facial region are included too. • Apple Health metrics, if you have connected Apple Health — averaged resting heart rate, heart-rate variability (HRV), step count, and active minutes. Only averages are sent, never individual readings, and nothing at all if you have not connected Apple Health. • Names of things you logged — the names of custom triggers you created, the suspected triggers you picked during onboarding, the names of any new skincare products you logged, and the name of a food you logged, but only when that specific food is one of the factors the analysis is explaining. Food names are sent as a factor label and a count of the days it was eaten — never your whole food library, never barcodes, and never ingredient lists. What is never sent: • Your identity. Your name, email address, and account ID are never included. Anthropic receives a statistical summary with no way to identify you. • Your log notes. The free-text notes you write on a log entry are never sent. They stay in your own account. • Your onboarding questionnaire answers. The answers described in Section 1 stay on your device and are not part of any AI request. How it is sent. Requests go through Aletheia's own server, which attaches the API key — your device never talks to Anthropic directly. Everything is transmitted over TLS. What Anthropic does with it. Anthropic acts as our processor: it uses the request solely to generate the explanation and return it to us, is contractually barred from using your data for its own purposes, and does not train its models on it. Anthropic is contractually required to protect this data to a standard at least equivalent to the protections described in this policy. 4. Barcode lookups and Open Food Facts -------------------------------------- When you scan or type a barcode, the app asks Open Food Facts — a free, open, community-run food database operated by the non-profit Open Food Facts association in France — what product that barcode belongs to. This is the one part of the app that talks to a service we do not control, so it is worth being precise about. What they receive: the barcode digits, and, unavoidably for any internet request, your device's IP address and our app's identifying User-Agent string. They do not receive your name, email, account ID, logs, breakouts, health data, or anything else about you, and there is nothing in the request that ties one lookup to another or to you. What we receive back: the product's name, brand, ingredient list, and a thumbnail image URL. That information is crowdsourced by volunteers, is published by Open Food Facts under the Open Database License, and may be incomplete, out of date, or wrong. The app treats it as unverified data. Open Food Facts is an independent third party and not our processor — their handling of the request is governed by their own privacy policy at openfoodfacts.org. If you would rather not contact them at all, add foods by hand instead of by barcode; hand-entered foods never leave your account. 5. Analytics and crash reporting -------------------------------- One third-party tool tells us how the app is doing: PostHog, which counts what happens in the app and records crashes. This section describes it in full, because "we use analytics" is exactly the kind of sentence that hides more than it says. What we use it for. Almost all of it is onboarding and retention. Onboarding is long, and without measurement we cannot tell a step people think about from a step people quit on — so we count how many people reach each step and how many go on to the next one. Beyond that: whether people come back after a day, a week, and a month; which features are actually opened; and how many people who see the paywall subscribe. These are counts of events, not readings of individuals. What is sent: • Events — a short name for the thing that happened ("onboarding step reached", "food scanned", "paywall shown", "daily log saved") and when it happened. The name of the event only: that a food was scanned, never which food. These are a fixed list of named events written into the app's code — automatic screen-view tracking is switched off, so opening a screen is not itself recorded. • A pseudonymous identifier for your install, so that a sequence of events can be recognised as one person's session rather than a crowd of strangers. • Technical context — device model, iOS version, app version, language, and time zone. • Approximate location — your country and region, derived from the IP address the request arrives from. Not GPS, and never a precise location. • Crash reports — a stack trace and the app's state at the moment it crashed. No trail of what you were doing beforehand is attached. What is never sent: • Anything from Apple Health. No sleep, heart rate, HRV, step, exercise, or water value reaches PostHog, in any form. Apple's rules for HealthKit data prohibit this and we treat it as an absolute line rather than a setting. • Anything you logged. No skin ratings, breakouts, notes, food names, barcodes, ingredient lists, custom triggers, or onboarding answers. • Your identity. No name and no email address. • Screen recordings or screenshots. Session replay and screenshot capture are switched off. We do not record your screen, and a crash report never carries a picture of it. Turning it off. This is on when you install the app, and you can switch it off at any time in Settings → Privacy & Data. The app works exactly the same without it — nothing is withheld from you for turning it off, and we do not ask you to turn it back on. Who they are. PostHog Inc. acts as our processor: it holds this data on our behalf, under a contract that forbids it from using the data for its own purposes, and it is required to protect it to a standard at least equivalent to the protections described in this policy. PostHog is not an advertising company, and we do not sell or share this data for advertising. 6. Legal bases (EEA/UK users) ----------------------------- Where the GDPR or UK GDPR applies: we process account data as necessary to perform our contract with you; we process health-related data (your logs, breakouts, food records, questionnaire answers, and connected Apple Health values) on the basis of your explicit consent (Article 9(2)(a)), which you give by entering that data or connecting Apple Health, and which you may withdraw at any time by disconnecting Apple Health in iOS Settings, deleting individual entries, or deleting your account; we process security logs, and the app-usage and crash data in Section 5, under our legitimate interest in keeping the service safe and working — or on your consent where local law requires us to ask first, which you can withdraw in Settings. 7. Who can access your data --------------------------- We have no affiliates and no advertising partners. Your data is disclosed only to service providers (processors) acting on our documented instructions under contracts that prohibit them from using your data for their own purposes: Provider Role Location --------------------------------- --------------------------------------------------------------------------------------------------------------------------------------------- ------------- Supabase (on Amazon Web Services) Database and authentication hosting United States Anthropic Generates AI insight text from de-identified pattern summaries; does not train models on this data United States PostHog Product analytics — counts app events so onboarding and features can be improved. No health, log, or account data. See Section 5 United States Apple Payment processing, App Store distribution, and — only if you use the button — Sign in with Apple United States Google Only if you use the Sign in with Google button: authenticates you and returns your name and email. Receives no health, log, or app-usage data United States One third party is not a processor and is listed separately because it receives a request directly from your device: Third party What it receives Location --------------- -------------------------------------------------------------------------------------------- ----------- Open Food Facts A barcode you scanned, plus your IP address. No account data, no health data. See Section 4. France / EU Beyond these: no one. We may disclose data if legally compelled (e.g., a valid court order), and we will tell you unless legally prohibited. If Aletheia is ever acquired, your data remains subject to this policy and you will be notified before any change takes effect. 8. International transfers -------------------------- Data is stored and processed in the United States. Barcode lookups described in Section 4 go to a service in the European Union. If you use Aletheia from the EEA, UK, or elsewhere, you understand your data is transferred to the US; where required, we rely on your explicit consent and contractual safeguards with our processors. 9. Security ----------- Data is encrypted in transit (TLS) and at rest. Database-level row security ensures your records — including your food library and the foods on each day's log — can only ever be read by your authenticated account. On your device, authentication tokens and personal details live in the iOS Keychain (encrypted, excluded from unencrypted backups). Our AI endpoint requires authentication and is rate-limited server-side. No system is perfectly secure. If a breach of your unsecured, identifiable health information occurs, we will notify you and the relevant regulators as required by applicable law, including the FTC Health Breach Notification Rule, without unreasonable delay. 10. Retention and deletion -------------------------- Your data is kept while your account exists — the app's purpose is showing your history over time. Delete your account any time in Settings → Delete Account: this immediately and permanently erases your account and all associated server data (logs, breakouts, insights, triggers, food library, logged foods, profile) via cascading deletion. Individual foods can be removed from your library at any time without deleting your account. Local device data, including your onboarding questionnaire answers, is removed on sign-out or app deletion. There are no backups retained beyond our host's standard short-term disaster-recovery window. 11. Your rights --------------- Everyone can access all of their data in the app and delete everything in-app. In addition, depending on your location (GDPR, UK GDPR, CCPA/CPRA, Washington MHMDA, and similar laws), you may have the right to: access a copy of your data, correct it, delete it, port it, withdraw consent (including switching off analytics and crash reporting in Settings → Privacy & Data), and not be discriminated against for exercising rights. We do not sell or "share" (for cross-context advertising) personal information as defined by the CCPA, so there is nothing to opt out of. To exercise any right, email AletheiaSupport@proton.me from your account email. We will respond within 30 days (or sooner where the law requires). If we refuse a request, you may appeal by replying to our decision; we will respond to appeals within 45 days. EEA/UK users may also lodge a complaint with their supervisory authority. 12. Children ------------ Aletheia is not directed at children under 13, and we do not knowingly collect their data (COPPA). If you believe a child under 13 has an account, contact us and we will delete it. 13. Changes ----------- If this policy changes materially, we will notify you in the app before the change takes effect and update the date above. We will never retroactively weaken protections on previously collected health data without your consent. Contact ------- AletheiaSupport@proton.me