Privacy policy
Last updated
This policy explains what personal data Deriw OÜ collects when you use the WellRep app on iPhone, Apple Watch and Android, and this website, what we do with it and the choices you have. We have tried to keep it short and plain.
Who we are
WellRep is made by Deriw OÜ, a company registered in Estonia (registry code 12038717). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For anything about your data, email privacy@wellrep.app. It reaches the people who build the app.
What we collect and why
Your account
You sign in with Apple or with Google; there is no separate WellRep password. When you do, the provider shares your name and email address with us, along with an ID for your account with that provider. If you choose Apple's Hide My Email, we only ever see a private relay address. Google may also share a link to your profile picture, which is kept with your sign-in details but not used by the app. We never see your Apple or Google password.
We use these details to create your account and keep it secure, to show you who is signed in, and to reply when you send us feedback. Your account also has an internal account ID that ties your data together.
Your habits and progress
For each habit you set up, we store:
- its name, icon and colours;
- whether it is something you want more of or less of;
- its unit and weekly target;
- the amount you log for it each day, with the date.
We also keep a few markers of your progress through the app: when you finished setup, saw the guided tour and logged for the first time, and the highest weekly score the app has celebrated with you. This is what lets the app work out your WellRep Score, show your history and keep your phone and watch in step.
Habit names are free text, so what you track can say something about your health or lifestyle, such as "Less alcohol" or "Sleep by 11". We use this data only to run the app for you. We do not analyse it, profile you or use it for anything else, and you decide what to enter.
Feedback you send
If you send feedback from Settings, we store your message (up to 2,000 characters), the optional 1 to 5 rating and the time you sent it, linked to your account. A copy is emailed to our team inbox with your account email address as the reply-to address and your account ID, so that we can answer you. Emails you send to our support or privacy addresses are kept in the same inbox.
Crash and error reports
When the app crashes or hits an error, the released app sends a technical report to Sentry so that we can find and fix the problem. A report contains the error and where in the code it happened, your device model, operating system and app version, a short trail of what the app was doing just before, and warnings and errors the app logged. It can also include a brief screen recording of the moments before the error, in which all text and images are masked, so your habit names and numbers are not visible. Sentry also counts whether an app session ended in a crash, using a random identifier created on your device.
The app does not attach your name, email address, account ID or IP address to these reports, and we do not use them to identify you. Our servers report their own errors the same way, without anything that identifies you.
Reminders
The daily reminder is scheduled on your phone by the operating system. It is not sent from our servers, and we do not receive a push notification token or know whether you have a reminder turned on.
Apple Watch
The Apple Watch app gets everything it shows from your iPhone, and hands anything you log on it back to your iPhone to save. It never connects to our servers itself. The watch face complication reads a small snapshot of this week's score that the watch app keeps on the watch.
On your device
To keep you signed in, the app stores a session token in its own storage on your phone. It is removed when you sign out, delete your account or delete the app.
This website
This website sets no cookies and runs no analytics or third-party scripts. It is hosted by Cloudflare, which, like any web host, processes your IP address and basic request details to deliver pages and protect the site from abuse. Emails to our wellrep.app addresses are forwarded to our inbox by Cloudflare Email Routing.
What we do not collect
We do not use advertising or analytics tools, and we do not track you across other apps or websites. The app does not access your location, contacts, photos, camera, microphone, Apple Health or Health Connect, and it has no in-app purchases.
Our legal bases
The GDPR requires a legal basis for each way we use personal data. Ours are:
| What we do | Legal basis |
|---|---|
| Create your account, store your habits and entries, and sync them to your devices | Performing our contract with you, which is our terms of use (Article 6(1)(b)) |
| Read, answer and learn from your feedback and support emails | Our legitimate interest in helping you and improving the app (Article 6(1)(f)) |
| Collect crash and error reports | Our legitimate interest in keeping the app stable and secure (Article 6(1)(f)) |
| Keep server and website logs to protect the service from abuse | Our legitimate interest in running a secure service (Article 6(1)(f)) |
| Keep records we are required to keep, and answer lawful requests | Compliance with a legal obligation (Article 6(1)(c)) |
Where we rely on legitimate interests, we have weighed them against your rights and kept the data to the minimum, and you can object at any time. Reminders use your device's notification permission, which you can withdraw in your phone's settings whenever you like.
Who processes your data
We use a small number of service providers to run WellRep. They process data only on our instructions, under data processing agreements, and may not use it for their own purposes.
| Provider | What it does for us | Where the data is |
|---|---|---|
| Supabase | Database, sign-in and server functions: stores your account, habits, entries and feedback | Sydney, Australia |
| Sentry | Crash and error reports | Germany (EU) |
| Resend | Delivers feedback from the app to our team inbox | Japan |
| Cloudflare | Hosts this website and forwards email sent to our addresses | Global network |
Our team inbox is hosted by an email provider acting on our behalf in the same way.
Apple and Google are not our processors. When you sign in with them, download the app from their stores or use their operating systems, they handle your data as independent controllers under their own privacy policies.
International transfers
Your account and app data are stored in Australia, feedback from the app is delivered through Japan, and some providers above are based in or reach data from the United States, all outside the European Economic Area. Japan has an EU adequacy decision, so transfers there need no further safeguards. Australia does not, so transfers there and to the United States are protected by the European Commission's Standard Contractual Clauses in our providers' data processing agreements. For US providers certified under the EU-US Data Privacy Framework, that framework applies as well. Email us if you would like a copy of the safeguards.
How long we keep your data
- Account, habits, entries, progress and stored feedback: kept until you delete them or your account. Deleting your account removes all of it from our database immediately.
- Backups: our database provider keeps rolling backups for disaster recovery. They are overwritten automatically, so deleted data drops out of them within 30 days.
- Feedback and support emails: kept in our inbox while we need them to help you and improve the app, and for no longer than 24 months. Deleting your account does not delete these emails, but we will delete them if you ask.
- Crash and error reports: deleted automatically by Sentry after 30 days.
- Server and website logs: kept by Supabase and Cloudflare for a short, rolling period, typically days, for security and troubleshooting.
- On your device: the session token stays until you sign out or delete the app.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and get a copy of it.
- Rectification, to correct data that is wrong. You can edit your habits in the app; your name and email come from Apple or Google, so email us if they need correcting.
- Erasure, to have your data deleted. You can do this yourself in the app, see how to delete your account.
- Portability, to receive the data you gave us in a structured, machine-readable format.
- Object to processing based on our legitimate interests.
- Restriction, to ask us to pause using your data while a concern is resolved.
- Withdraw consent wherever you gave it, such as notification permission, without affecting anything done before.
To use any of these rights, email privacy@wellrep.app, ideally from the email address linked to your account. We may ask you to confirm it is you before acting. We will answer within one month, and it is free.
Complaints
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to a data protection authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, aki.ee. You can also complain to the authority in the EU country where you live or work.
Children
WellRep is not directed at children under 13, and they should not use it. In the European Economic Area, if you are under 16, or the lower age your country sets, please use the app only with the permission of a parent or guardian where your country requires it. If we learn that a child has used WellRep without the permission they needed, we will delete their account.
Security
All traffic between the app and our servers is encrypted in transit, and our database provider encrypts stored data at rest. Access rules in the database mean each account can only ever read and change its own data. The Apple Watch app never connects to the internet itself, and access to our production systems is limited to the people who run WellRep. No system is perfectly secure, but if a breach ever puts your data at risk, we will tell you and the authorities as the law requires.
We do not sell your data
We do not sell your personal data, share it for advertising, or pass it to data brokers. It is only disclosed to the service providers listed above, to run the app, or where the law requires it.
Changes to this policy
We will update this policy when the app or the law changes, and change the date at the top when we do. If a change significantly affects how we use your data, we will tell you in the app or by email before it takes effect.
Contact us
Deriw OÜ
Email: privacy@wellrep.app