Data controller: STOCKLER X-SOLUCOES LTDA — Brazilian company registry (CNPJ) 47.221.442/0001-21
1. Scope
This Policy explains how we process personal data in the WellUp app and related services (backend, AI processing, and integrations). WellUp is a health, nutrition, and training tracking app — as such, it processes sensitive health data, with the safeguards described below, in compliance with the Brazilian General Data Protection Law (LGPD — Law 13,709/2018) and other applicable data protection laws.
2. Data we collect
2.1 Account and profile data
- Name, e-mail, and profile picture, obtained from your sign-in provider (Google or Apple).
- Technical account identifiers (provider ID, authentication ID, subscription ID).
- Date of birth, biological sex, weight, height, activity level, sleep duration, and goal — used for calculations such as BMR, TDEE, and calorie targets.
- Device platform (iOS/Android), app version, and language.
2.2 Health data (sensitive) — provided by you or by an authorized professional
- Body composition and measurements: weight, body fat percentage, lean/muscle mass, BMI, body circumferences.
- Lab exams: uploaded documents (PDF/image), extracted markers and values, laboratory and requesting physician, calculated indices.
- Posture assessment: body photos (front, back, sides), notes, and generated analyses.
- Protocols: supplements, medications, and other logged substances, with doses, schedules, and adherence.
- Health questionnaires: health history provided in nutrition and training questionnaires (conditions, allergies, injuries, surgeries, habits, sleep, menstrual cycle, among others) and PAR-Q screening.
- Daily metrics: self-reports such as water intake and anxiety level.
2.3 Nutrition and training data
- Logged meals, recipes, meal plans, and macros.
- Workout routines, sessions, sets, loads, and perceived exertion.
- Meal photos uploaded for analysis (optional).
2.4 Apple Health / Health Connect data (optional)
- With your explicit system authorization, we may read from Apple Health (iOS) or Health Connect (Android): steps, distance, active calories, basal metabolic rate, exercise minutes, sleep, weight, height, body fat percentage, heart rate, and resting heart rate — you authorize each data type individually.
- If you enable it, the app can also write exercise sessions performed in WellUp back to Apple Health / Health Connect.
- With the background read permission (Android), the app periodically syncs the day's steps and calories to keep your goals up to date even when the app is closed.
2.5 Subscription data
- Plan status (free/paid), subscribed product, purchase origin, and identifiers needed to manage the subscription through the Apple/Google stores and RevenueCat.
- We do not store full payment card data; payments are processed by the stores.
2.6 Technical and usage data
- Usage and navigation events (analytics) and crash logs.
- Push notification token (when enabled).
- Technical security and integrity data (e.g., app integrity attestation) for API protection and fraud prevention.
2.7 Messages
- Messages exchanged in the chat between you and your connected professional (content, sender, date), stored for delivery and conversation history.
3. Sensitive data and consent
Health data is sensitive personal data. We only process it:
- when you actively provide it (records, uploads, questionnaires) to use the app's features — with your specific consent, expressed through the act of use itself;
- when you authorize a professional to view or edit it (see section 6);
- for health-related purposes limited to operating the service, protecting rights, and complying with legal obligations.
You may choose not to provide any sensitive data — the corresponding features simply will not be available.
4. Purposes of processing
- Operating the app: recording, computing, and displaying your health, nutrition, and training data.
- Running AI features you request (section 5).
- Enabling sharing with professionals you authorize (section 6).
- Authenticating sessions and protecting the API and infrastructure.
- Processing and managing subscriptions.
- Sending push notifications (reminders and app communications, when enabled).
- Monitoring stability, measuring usage, and fixing failures.
- Complying with legal and regulatory obligations and exercising rights in legal proceedings.
5. Artificial intelligence
- Features such as exam extraction (PDF), body composition report reading, meal photo analysis, posture analysis, and diet/workout suggestions use cloud-hosted AI models (Google Vertex AI / Gemini), plus deterministic image processing on our servers (e.g., pose detection).
- Data sent to these features (documents, photos, relevant profile and questionnaire data) is used exclusively to generate the result you requested.
- We use these providers under enterprise terms, in which submitted data is not used to train general-purpose models.
- AI outputs are suggestions subject to error and are only saved after human confirmation.
6. Sharing with professionals
- Connecting with a professional is always initiated by you and requires their acceptance. You define per-module permissions (training, nutrition, health) at none/view/edit levels.
- While the connection is active, the professional accesses only the modules you authorized and may create records identified as authored by them.
- You may change permissions or revoke the connection at any time, with immediate effect. Connection history is preserved for auditing.
- The professional is also responsible under data protection law for how they use the data you granted access to, within your professional relationship.
7. Sharing with processors and third parties
We share data only with processors necessary to operate the service:
| Third party | Purpose |
|---|---|
| Amazon Web Services (AWS) | Infrastructure, database, file storage (photos, PDFs), and processing queues |
| Google Firebase | Authentication, push notifications, chat messages, app integrity, analytics, and crash reporting |
| Google Cloud (Vertex AI / Gemini) | AI processing for the features described in section 5 |
| RevenueCat | Subscription and entitlement management |
| Apple App Store / Google Play | App distribution and payment processing |
We do not sell personal data and we do not share health data for advertising purposes.
8. International data transfers
Because we use global technology providers, data may be processed outside Brazil (e.g., in the United States), subject to appropriate contractual safeguards and security measures, in accordance with articles 33 et seq. of the LGPD.
9. Retention and deletion
- Data is kept while your account is active and for as long as needed for the purposes in this Policy, legal obligations, and the defense of rights.
- When you request account deletion, the account enters a 30-day grace period during which you can reactivate it. After the grace period, account data is permanently erased from our systems, including uploaded files, and the link to your sign-in provider is revoked.
- Records created by a professional for their clients may be preserved on the professional's side with your identification removed (anonymized).
- Records strictly necessary for legal compliance, fraud prevention, and the defense of rights may be retained for the legally required period.
- Documents you delete within the app (e.g., an exam) are also removed from file storage.
10. Your rights
You may request: confirmation of processing, access, correction, anonymization, portability, deletion where applicable, information about sharing, and withdrawal of consent. For health data shared with a professional, you can also revoke access directly in the app at any time.
Privacy channel: contact@fantoy.link
Account deletion: within the app (Profile → Settings → Delete account) or through the WellUp Account Deletion page.
11. Security
We adopt technical and administrative measures to protect data against unauthorized access, loss, alteration, or improper destruction — including encryption in transit, authentication and authorization-based access control, signed and expiring media URLs, app integrity verification, and credential segregation. No system is 100% secure, but we treat health data with the highest level of protection we employ.
12. Children and teenagers
WellUp is not intended for anyone under 18. We do not knowingly collect data from children. If we identify a minor's account without valid guardian consent, it will be deleted.
13. Push notifications
The app may send notifications (reminders, messages from your professional, service communications). You can disable them in your device or app settings.
14. Changes to this Policy
This Policy may be updated periodically. The current version will always show the effective date at the top of the document. Material changes may be communicated in the app.
15. Controller contact
CNPJ: 47.221.442/0001-21
Support e-mail: contact@fantoy.link
Privacy e-mail: contact@fantoy.link