HAVYT

Data Processing

Last Updated: August 14, 2026 Version 2.2
Who processes your data and where. HAVYT runs on a small, carefully chosen set of service providers. This page lists every company that touches your data, what it does for HAVYT, and where it processes data. We never sell your data, and there are no advertising trackers in HAVYT — no ad networks, no third-party analytics SDKs, no pixels. For the full legal detail, see the Privacy Policy.

Table of Contents

  1. How HAVYT works with providers
  2. Service providers acting on our instructions
  3. Services you connect or use directly
  4. Where your data goes (transfers and safeguards)
  5. What we never do
  6. Questions and your rights

1. How HAVYT works with providers

Like every modern app, HAVYT relies on specialist providers for infrastructure, AI, email and payments. Providers that process personal data on our behalf do so only on our instructions, under a data processing agreement (Art. 28 GDPR). OpenAI receives account health context only after you enable AI features. If you send a support request, the content you choose to include may also be processed by OpenAI to help authorised staff classify, summarise and draft a response; a person remains responsible for the response.

Some services (like Apple Health or your wearable) are ones you connect and authorize; they remain independently responsible for the data they hold about you under their own privacy policies.

2. Service providers acting on our instructions

Provider What they do for HAVYT Data involved Location / safeguards
Supabase Core infrastructure: database, sign-in, file storage and server functions All app data, including your health logs Engaged under a GDPR data processing agreement; any processing outside the EU/EEA is covered by an adequacy decision and/or Standard Contractual Clauses
OpenAI Powers the Emelie AI coach: chat, voice calls, photo analysis, plan generation and report summaries when you enable AI; it may also assist authorised staff with support-ticket summaries and draft replies Your messages plus relevant health context; voice audio (we keep only transcripts, never the audio); photos you submit for analysis; and support content you choose to send USA — EU–US Data Privacy Framework and/or Standard Contractual Clauses via OpenAI's DPA; API data is not used to train OpenAI's models by default
RevenueCat Validates and reports one-time AI-credit purchases and fulfilment events App user ID, product identifier, purchase/entitlement event and revenue amount — no health data or card details USA — DPA + Standard Contractual Clauses
Apple App Store payments and push notification delivery (APNs) Payment and billing data stay entirely with Apple — we never see your card details. Push tokens and notification payloads (payloads contain no health data) Apple platform terms; Apple is independently responsible for payments
Resend Sends our emails (waitlist confirmation, support replies) Email address, name, message content USA — DPA + Standard Contractual Clauses
Vercel Hosts the app and the website (hosting + CDN) IP addresses and technical request logs — no health data USA/global edge — DPA + Standard Contractual Clauses
Bunny.net Delivers exercise GIFs and thumbnails (media.havyt.app) Requester IP only — no user content EU
Google Analytics 4 (Google Ireland Ltd) Optional website audience measurement; never loaded before Analytics consent Page views, signup events, approximate location from IP, device and browser — no health data EU (Ireland), with safeguarded onward transfer to the US
Google Ads (Google Ireland Ltd) Optional website conversion measurement; used only after Marketing consent and only if configured Whether an advertising interaction led to a signup — no health data EU (Ireland), with safeguarded onward transfer to the US

3. Services you connect or use directly

These services only come into play when you connect them or use a feature that calls them. The wearable providers are independent controllers of the data they hold about you.

Provider What they do for HAVYT Data involved Location / safeguards
Apple Health Health data source, read on your device with iOS permissions you control Steps, workouts, heart rate, HRV, sleep and other categories you allow On-device; you manage access in iOS Settings → Health → Data Access & Devices
Open-Meteo Local weather for weather-aware features Approximate location only (city-level rounding) and IP — no account identifier EU non-profit
Open Food Facts Looks up products when you scan a food barcode The scanned barcode and IP — no account identifier EU non-profit
OpenFreeMap Provides map tiles when you view GPS activity routes IP address and the map-tile coordinates requested by your device; no HAVYT account identifier is sent Third-party map service; its own privacy and service terms apply

4. Where your data goes (transfers and safeguards)

Where a provider processes data outside the EU/EEA, the transfer relies on GDPR safeguards: an adequacy decision — including the EU–US Data Privacy Framework where the provider is certified — and/or the EU Standard Contractual Clauses built into the provider's data processing agreement, with supplementary measures where required. You can request a copy of the relevant safeguards at support@havyt.app.

5. What we never do

6. Questions and your rights

The full legal detail — legal bases, retention periods, and your GDPR rights (access, erasure, portability and more) — is in the HAVYT Privacy Policy. To exercise any right or ask about a provider, email support@havyt.app; we answer within one month.

Related documents: Privacy Policy · Cookie Policy · Terms of Service · Data Deletion · Aviso Legal / Legal Notice