Data controller for the HAVYT service:
Daniel Denis Golaszewski (operating as "HAVYT"), self-employed professional (autónomo) established in Spain.
NIF: Z3964150J · VAT/NIF-IVA (ROI): ESZ3964150J
Address: Avinguda d'Alexandre Rosselló 15, 6 D, 07002 Palma de Mallorca, Illes Balears, Spain.
Email: support@havyt.app
This policy supplements our Privacy Policy (which describes all processing, legal bases and your other GDPR rights) and the Terms & Conditions.
2.1 Delete Account (destructive). Permanently erases your account and your data (Section 3). This is the option that satisfies your GDPR Article 17 right to erasure.
2.2 Restart Onboarding (non-destructive). A separate in-app reset that clears your profile setup, goals, preferences and plan so you can set HAVYT up again from scratch — your history (workouts, check-ins, symptom logs, photos) is kept. Use this if you want a fresh start, not a departure. Nothing in this option deletes data.
Both are available in the app: Settings → Account.
3.1 How it works. Deletion requires re-authentication (you must confirm your password) so nobody can wipe your account from an unlocked phone. It then runs a catalog-driven hard-delete server-side, followed by an automated verification step that checks no user rows remain.
3.2 What is erased — everything, including:
The deletion catalog covers all user tables in our database (currently about 200) and all storage buckets, and is maintained so that new features are automatically included.
3.3 Cycle and pregnancy-related data is included in the hard delete like all other health data — we specifically confirm that menstrual-cycle and pregnancy/postpartum logs are permanently erased and are never retained in any identifiable form after deletion.
3.4 Wearable connections. HAVYT no longer offers a direct Oura, WHOOP or Huawei Health connection. If you made one in an earlier version, deletion removes any access token we still hold, which cuts off our access. We recommend you also revoke HAVYT's access inside the provider's own app or account settings (and in iOS Settings → Health → Data Access & Devices for Apple Health) — that revocation happens on their side and only you can do it.
We keep the minimum set of records that the law requires or that a legitimate, documented interest justifies (GDPR Art. 17(3)):
| What | Why | How long |
|---|---|---|
| Legal-acceptance records (which document versions you accepted, when, how — no health data) | Proof of consent/acceptance — defense of legal claims (Art. 17(3)(e)) | For the applicable statutory limitation periods under Spanish law |
| Admin audit log (a record that a deletion was requested and executed, and security-relevant admin actions) | Security, accountability, proof of erasure | For the applicable statutory limitation periods under Spanish law |
| Tax and billing records (AI-credit purchase/revenue events; Apple holds the actual payment records) | Legal obligation — Spanish tax and commercial retention | The statutory retention periods under Spanish tax and commercial law |
| Anonymized references — your invite codes are dissociated, your contributions to the shared food database (e.g. products you added) are kept with authorship nulled, support email thread subjects may be kept with your identifiers removed | Keeping shared/aggregate systems consistent without identifying you | Indefinite (no longer personal data once anonymized) |
Nothing in the retained set includes your health logs, photos, chat content or metrics.
Deleted data may persist for a limited time in encrypted backups used for disaster recovery. Backups are not accessible for normal operations and are purged on a rolling basis; deleted data disappears from all backups normally within 30 days. If we ever had to restore from a backup, we would re-apply deletions recorded in the audit log.
Be aware of the limits — deletion removes data from our systems:
If you can't use the in-app flow (lost device, can't sign in), email support@havyt.app from your registered address, or provide enough information for us to verify you are the account holder. We will verify identity, then perform the same deletion, and confirm to you when it is done — at the latest within one month (GDPR Art. 12(3)).
Deletion is one of several GDPR rights (access, rectification, restriction, portability, objection, withdrawal of consent). These, and your right to complain to the Agencia Española de Protección de Datos (AEPD, www.aepd.es) or your local supervisory authority, are described in our Privacy Policy.
We may update this policy as the product or the law changes. Material changes are notified in-app and versioned through our legal-acceptance system (see the Terms & Conditions, Section 4).
HAVYT — Daniel Denis Golaszewski (autónomo, Spain)
NIF: Z3964150J · VAT/NIF-IVA (ROI): ESZ3964150J
Address: Avinguda d'Alexandre Rosselló 15, 6 D, 07002 Palma de Mallorca, Illes Balears, Spain.
Email: support@havyt.app