Effective date: 6 July 2026 · Version: 1.0
Feelon ("Feelon", "we", "us") is a mobile app that helps you understand how you feel. The data controller responsible for your personal data is Sixtyfive Security Systems Ltd (registered at Chrysi Dimitriadi, 5, 3106 Limassol, Cyprus, Republic of Cyprus). Questions or requests: support@feelon.io. We have not appointed a Data Protection Officer (not required at our current scale) — privacy requests go to support@feelon.io.
This policy covers the Feelon iOS app and its backend services, including beta versions distributed through Apple TestFlight. It explains what we collect, why, on what legal basis, who we share it with, how long we keep it, and your rights. It does not cover third-party services you choose to connect (Apple Health, WHOOP, Oura) beyond how we use the data you authorize them to share with us — those services have their own privacy policies.
Feelon's core feature — your daily "read" — is generated by sending your check-in and any connected health data to a third-party AI provider (Anthropic) through our backend (Supabase) to produce a personalized response. We do this only to provide the service to you. We never sell your data, we never use it for advertising, and we run no advertising or tracking SDKs. The AI prompt is minimized so that it contains your state and your own words but no name, no email, and no account identifier (see §8).
| Data | Examples | Why | Legal basis (GDPR) |
|---|---|---|---|
| Check-in data | your daily 0–10 rating, free-text notes, voice-dictated text (transcribed on-device where your device supports it — audio never reaches Feelon), chat messages | to generate your read + remember your pattern | Art. 9(2)(a) explicit consent (health data) + Art. 6(1)(b) contract |
| Memory "boxes" | resources/habits, medical constraints/injuries, medications, life context (e.g. a newborn, a move, marathon training) | to keep advice safe + personal | Art. 9(2)(a) explicit consent |
| Reproductive health | cycle phase only (derived on your device from Apple Health menstrual dates, if you connect it) — never a raw cycle day, never a stated gender | to validate how you feel | Art. 9(2)(a) explicit consent |
| Wearable data | sleep, HRV, resting heart rate, respiratory rate, steps, workouts; where your device provides them: skin/body-temperature deviation, sleep efficiency and sleep debt, stress-load measures, sessions you logged (e.g. meditation), and tags you entered on your device (e.g. "alcohol", "late meal") — from Apple Health / WHOOP / Oura, only if you connect them | objective layer for the read + trends | Art. 9(2)(a) explicit consent |
| Derived data (your patterns) | weekly summaries of your entries; statistical patterns computed from your own history (e.g. "short nights hit you the next day"); recurring themes detected in your chat texts (e.g. "work") | to show you your patterns and make the read smarter over time | Art. 9(2)(a) explicit consent (derived from health data) |
| Account | anonymous ID (created on first launch); if you sign in, your Apple identifier (Sign in with Apple, which lets you hide your real email) | to save your data + enable multi-device/billing | Art. 6(1)(b) contract |
| Consent record | consent version + timestamp, tied to your account ID | to prove lawful processing | Art. 6(1)(c) legal obligation |
| Subscription | product, status, Apple transaction id | to unlock/validate the paid tier | Art. 6(1)(b) contract |
| Service metadata | per-request AI usage records (which model ran, when, token counts) — used for weekly free-tier counting, rate limiting, and cost control | keep the free tier honest + prevent abuse | Art. 6(1)(f) legitimate interests + Art. 6(1)(b) contract |
| Technical/diagnostic | crash/error logs, coarse timing | keep the app working + secure | Art. 6(1)(f) legitimate interests |
We do not collect: your name, your contacts, your precise location, advertising identifiers, or browsing history. We use no cookies (there is no web app), no third-party analytics SDKs, and no ad-tracking SDKs. Because we do not track you across other companies' apps and websites, "Do Not Track" signals are not applicable to Feelon.
What we never do with your health data. No advertiser, ad network, marketing platform, or data broker ever receives your data — identified, pseudonymised, de-identified, or aggregated. The app embeds no third-party advertising or marketing SDKs, pixels, or web trackers, and no third party is permitted to intercept or "listen in on" your in-app activity: the only recipients of your data are the processors listed in §8, acting under contract on our documented instructions. If we ever wanted to use your health data for anything beyond providing Feelon to you, we would have to ask you first with a separate, explicit consent — silence or continued use would not count.
Biometrics & voice. Feelon collects no biometric identifiers (no fingerprints, no face geometry, no voiceprints) as defined by biometric-privacy laws such as the Illinois Biometric Information Privacy Act. If you use voice input, transcription runs on your device whenever your device supports it; on devices that don't, Apple's iOS speech service performs the transcription under Apple's terms. Feelon itself never records, stores, or receives your audio — only the resulting text, which is treated like any typed check-in.
If you connect Apple Health, we read only the metrics needed for your read (sleep, HRV, resting heart rate, respiratory rate, steps, workouts, wrist temperature where available, and — only if present — menstrual-flow dates used solely to derive your cycle phase on the device). Per Apple's rules and our own policy: HealthKit data is used only to provide Feelon's features to you, is never used for advertising or marketing, never sold, and never shared with data brokers or used for eligibility decisions (credit, insurance, employment). Reading happens on your device; only the minimized signals needed for your read are sent to our backend. When you first connect, the app performs a one-time read of approximately the last 14 days of these metrics so your trends are meaningful from day one; the same minimization rules apply.
Feelon's reminders are generated locally on your device — we run no push-notification server and hold no push tokens. Notification texts are deliberately generic (e.g. "Find today's next move") and do not include your health details, so nothing sensitive appears on your lock screen. You control notifications entirely via iOS Settings; declining them changes nothing else about the app.
Profiling & automated decision-making (GDPR Art. 22). Feelon personalizes content for you — that is the product — but it makes no automated decisions producing legal or similarly significant effects about you: no scoring for third parties, no eligibility decisions, no price differences based on your health data. The only "profile" is the one the app shows you, to help you understand yourself. You can delete it at any time.
AI model training. We do not use your data to train AI models, and our AI provider is contractually committed not to train on it either (see §8).
We share data only with processors acting on our instructions — never with advertisers or data brokers. The always-current list, with details, lives in our sub-processor list. Summary:
International transfers. Our primary data store and our AI provider are located in the United States. Where EU/UK personal data is transferred to the USA, we rely on Standard Contractual Clauses (SCCs) and, where the recipient is certified, the EU–US Data Privacy Framework, plus supplementary measures (TLS in transit, encryption at rest, prompt minimization).
We keep your check-ins, reads, and memory while your account is active — that is what lets Feelon show your pattern over time. Service metadata and diagnostic logs live on short rolling windows. The full schedule per data type is available on request via support@feelon.io.
When you delete your account (in-app, one tap), we permanently delete your data from our live systems — every Feelon table, your stored device connections (asking the wearable provider to revoke our access), and the account itself. Deleted data may persist in our encrypted backups for up to 7 days before those backups expire; backups are never used for live processing. Data previously sent to Anthropic is deleted on their side within 30 days under their own terms — it is not our storage.
Anonymous accounts that never return may be purged after 12 months of inactivity.
Wherever you are — and in full for EU/UK/EEA users — you can:
For anything not available as an in-app button, contact support@feelon.io. We respond within 30 days (extendable once where the law allows for complex requests — we will tell you if so). We verify that a request comes from the account holder and never ask for more data than needed to verify.
California and other US states. We do not "sell" or "share" personal information as defined by the CCPA/CPRA, and we do not process it for cross-context behavioral advertising. California residents have rights of access, deletion, correction, and non-discrimination; the in-app tools above satisfy them.
Consumer health data (Washington, Nevada, and similar US state laws). Your check-ins, memory, and wearable signals are "consumer health data" under laws such as the Washington My Health My Data Act and Nevada SB 370. This policy serves as our consumer health data privacy policy: we collect and share such data only as described here, only with the processors in §8, and only to provide the service you asked for. We do not sell consumer health data, and we would never do so without the separate, explicit authorization those laws require. You can exercise access and deletion through the in-app tools above; if we refuse a request, you may appeal by replying to our response, and Washington/Nevada residents may also contact their state Attorney General.
Feelon is not for anyone under 16. We do not knowingly collect data from children under 16, and the App Store age rating reflects this. If you believe a child has used Feelon, contact support@feelon.io and we will delete the data.
Data is encrypted in transit (TLS) and at rest. Access to your rows is restricted to your account (row-level security enforced by the database). Server credentials never ship inside the app. We minimize what leaves your device and what reaches the AI (no identifiers — §8), and we cap per-account usage to limit abuse. No system is perfectly secure; we maintain a breach-response process and will notify affected users and regulators where required by law (GDPR Art. 33/34).
If we make material changes — especially to how we use health data or to the list of processors that receive it — we will update the version, notify you in-app, and where required ask for your consent again before the new processing applies to you. The version you consented to is recorded with your consent. Continued use after a non-material update means you accept it.
Sixtyfive Security Systems Ltd · support@feelon.io · https://feelon.io