Like every modern app, HAVYT relies on specialist providers for infrastructure, AI, email and payments. Providers that process personal data on our behalf do so only on our instructions, under a data processing agreement (Art. 28 GDPR). OpenAI receives account health context only after you enable AI features. If you send a support request, the content you choose to include may also be processed by OpenAI to help authorised staff classify, summarise and draft a response; a person remains responsible for the response.
Some services (like Apple Health or your wearable) are ones you connect and authorize; they remain independently responsible for the data they hold about you under their own privacy policies.
| Provider | What they do for HAVYT | Data involved | Location / safeguards |
|---|---|---|---|
| Supabase | Core infrastructure: database, sign-in, file storage and server functions | All app data, including your health logs | Engaged under a GDPR data processing agreement; any processing outside the EU/EEA is covered by an adequacy decision and/or Standard Contractual Clauses |
| OpenAI | Powers the Emelie AI coach: chat, voice calls, photo analysis, plan generation and report summaries when you enable AI; it may also assist authorised staff with support-ticket summaries and draft replies | Your messages plus relevant health context; voice audio (we keep only transcripts, never the audio); photos you submit for analysis; and support content you choose to send | USA — EU–US Data Privacy Framework and/or Standard Contractual Clauses via OpenAI's DPA; API data is not used to train OpenAI's models by default |
| RevenueCat | Validates and reports one-time AI-credit purchases and fulfilment events | App user ID, product identifier, purchase/entitlement event and revenue amount — no health data or card details | USA — DPA + Standard Contractual Clauses |
| Apple | App Store payments and push notification delivery (APNs) | Payment and billing data stay entirely with Apple — we never see your card details. Push tokens and notification payloads (payloads contain no health data) | Apple platform terms; Apple is independently responsible for payments |
| Resend | Sends our emails (waitlist confirmation, support replies) | Email address, name, message content | USA — DPA + Standard Contractual Clauses |
| Vercel | Hosts the app and the website (hosting + CDN) | IP addresses and technical request logs — no health data | USA/global edge — DPA + Standard Contractual Clauses |
| Bunny.net | Delivers exercise GIFs and thumbnails (media.havyt.app) | Requester IP only — no user content | EU |
| Google Analytics 4 (Google Ireland Ltd) | Optional website audience measurement; never loaded before Analytics consent | Page views, signup events, approximate location from IP, device and browser — no health data | EU (Ireland), with safeguarded onward transfer to the US |
| Google Ads (Google Ireland Ltd) | Optional website conversion measurement; used only after Marketing consent and only if configured | Whether an advertising interaction led to a signup — no health data | EU (Ireland), with safeguarded onward transfer to the US |
These services only come into play when you connect them or use a feature that calls them. The wearable providers are independent controllers of the data they hold about you.
| Provider | What they do for HAVYT | Data involved | Location / safeguards |
|---|---|---|---|
| Apple Health | Health data source, read on your device with iOS permissions you control | Steps, workouts, heart rate, HRV, sleep and other categories you allow | On-device; you manage access in iOS Settings → Health → Data Access & Devices |
| Open-Meteo | Local weather for weather-aware features | Approximate location only (city-level rounding) and IP — no account identifier | EU non-profit |
| Open Food Facts | Looks up products when you scan a food barcode | The scanned barcode and IP — no account identifier | EU non-profit |
| OpenFreeMap | Provides map tiles when you view GPS activity routes | IP address and the map-tile coordinates requested by your device; no HAVYT account identifier is sent | Third-party map service; its own privacy and service terms apply |
Where a provider processes data outside the EU/EEA, the transfer relies on GDPR safeguards: an adequacy decision — including the EU–US Data Privacy Framework where the provider is certified — and/or the EU Standard Contractual Clauses built into the provider's data processing agreement, with supplementary measures where required. You can request a copy of the relevant safeguards at support@havyt.app.
The full legal detail — legal bases, retention periods, and your GDPR rights (access, erasure, portability and more) — is in the HAVYT Privacy Policy. To exercise any right or ask about a provider, email support@havyt.app; we answer within one month.
Related documents: Privacy Policy · Cookie Policy · Terms of Service · Data Deletion · Aviso Legal / Legal Notice