PRIVACY POLICY
Last updated: July 9, 2026
This Privacy Policy explains how we (the developer of Primalyst) collect, use, and share information when you use the App. By using the App you agree to this Policy.
A. INFORMATION WE COLLECT.
- Account information: your first name, email, and password (stored securely by our authentication provider), and profile details you add (such as last name, gender, body metrics, location, and goals).
- Wellness data you log: foods and nutrition, habits and tasks, steps and activity, sleep and circadian settings, progress photos, streaks, and similar entries.
- Community content: posts, comments, direct messages, reactions, and anything else you share in the community.
- AI conversations: the messages you send to Primalyst AI, and any voice recordings you choose to send for voice-to-text.
- Purchase information: your subscription status and transaction identifiers (payment card details are handled by the app store, not by us).
- Device and usage information: app version, device type and operating system, and basic diagnostic and usage data needed to run and improve the App.
- Permissions you grant: for example, motion/step data, photos/camera, microphone, and approximate location — each used only for the related feature, and only if you allow it.
B. HOW WE USE INFORMATION.
To create and operate your account; provide and personalize features (including your protocol, targets, and AI responses); enable the community; process subscriptions; keep the App safe and prevent abuse; provide support; comply with law; and maintain and improve the App. We do not use your information to make automated decisions with legal or similarly significant effects, and we do not sell your personal information.
C. HOW WE SHARE INFORMATION.
- With other users: content you post to the community, and your public profile details, are visible to others by design.
- With service providers ("processors") who run the App on our behalf, under contracts that limit their use of your data, including: our database and authentication host (Supabase); the app-store, billing, and sign-in platforms (Apple — including Sign in with Apple — and, where used, a subscription manager such as RevenueCat); AI providers that generate Primalyst AI responses and transcribe voice (such as Anthropic and Groq); our email-delivery provider, which sends account emails such as password-reset and verification links (such as Resend); and an image-moderation provider that automatically screens photos you upload to detect and block sexually explicit content (Amazon Web Services). We send each provider only the content needed to perform its function.
- For legal reasons: to comply with law, enforce our Terms, or protect the rights, safety, and security of users, the public, or us.
- In a transfer of the App: if the App is ever transferred to another operator, subject to this Policy. We do not sell your personal information and do not share it for cross-context behavioral advertising.
D. LEGAL BASES (EEA/UK USERS).
Where the GDPR/UK GDPR applies, we process your data to perform our contract with you (to provide the App), based on your consent (for optional permissions and sensitive data you choose to log), to comply with legal obligations, and for our legitimate interests in operating, securing, and improving the App.
E. HEALTH-RELATED AND SENSITIVE DATA.
Some data you choose to log may be sensitive (for example, health, body, and dietary information). We process it only to provide the features you use, based on your choice to provide it, and we never share it for advertising. You can delete this data or your account at any time.
F. DATA RETENTION.
We keep your personal and health-related data for as long as your account is active and as needed to provide the App, comply with law, resolve disputes, and enforce our agreements. If you delete your account, we delete your associated personal data within 30 days, except where we are legally required to keep certain limited records longer (such as transaction records for tax purposes). We may retain fully anonymized data that can no longer identify you.
G. SECURITY.
We use reasonable technical and organizational measures to protect your information, including access controls and encryption in transit. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.