Privacy Policy
This policy explains how we process personal data for wellcell.app and the WellCell iOS app. Draft — obtain legal review before relying on it commercially.
Last updated: 7 May 2026. Version: 1.1
1. Scope
This policy describes personal data practices for the WellCell iOS app and the informational website at wellcell.app.
Links inside the app should point to policies on the same host; keep URLs aligned with App Store Connect fields.
2. Data controller
For identity verification on privacy requests, email us preferably from the address associated with your WellCell account.
3. Categories of data
Account and authentication: email, name; optional coach contact fields; identifiers and session artefacts from Sign in with Apple or Google Sign-In where used.
Fitness and wellness: measurements, photos you upload, workouts and nutrition entries, onboarding answers — may be sensitive in some jurisdictions.
Device, logs and reliability: OS/app versions; automated crash/error reporting if enabled (must match your App Privacy disclosures).
Payments: Coach subscriptions are billed through the App Store; card data is not stored on WellCell servers. Apple is responsible for storefront billing data.
Optional marketing operates only with consent where required. If you do not run marketing emails, disclosures stay consistent with that posture.
4. Consistency with App Store privacy labels
App Privacy answers in App Store Connect (data collected, linked to identity, tracking, purposes, third parties) must align with real behavior and this policy.
Whenever you ship analytics, crashes, Health features, etc., declare exactly what runs in production.
5. Purposes and legal bases (summary)
Depending on jurisdiction, processing usually maps roughly as follows:
- Delivering accounts, subscriptions and features (performance of contract).
- Security and abuse prevention, integrity of the platform (legitimate interests or legal duty, proportionate).
- Product diagnostics and improvements (privacy-preserving aggregates where possible; disclosed if identifiable).
- Legal compliance and claims defense.
- Sensitive wellness data where expressly permitted and justified (including consent where applicable).
If you introduce marketing communications, configure separate consent channels and lawful bases.
6. Recipients and processors
We rely on vendors in roles such as:
- Hosted infrastructure, databases and backups.
- Edge delivery/security layers (CDN, mitigation).
- Authentication tooling and transactional email transport.
Apple: distribution, IAP subscriptions — subject to Apple's policies for data they process.
Google: only if Google Sign-In (or adjacent features) are enabled.
Marketing site hosting may generate technical logs linked in the Cookies policy.
Optional third-party content modules may evolve; impacts are surfaced in release notes or supplemental notices.
7. Retention and deletion
Retention is proportionate to service delivery, backups, audits and lawful obligations; restoration windows may extend removal slightly.
Account deletion / erasure requests
Email hi@wellcell.app with suggested subject line: “Data deletion request”.
- Include the WellCell-associated email address and roles (coach / student).
- List separate accounts distinctly if applicable.
- We may throttle access while validating complex requests.
Typical acknowledgement mirrors our /contact guidelines (~2–5 business days) unless verification is unusually heavy.
8. Your rights
You may pursue access, correction, deletion, restriction, objection, portability and complaints compatible with GDPR / KVKK frameworks.
Regional specifics apply; we cooperate with supervisory authorities.
9. Children
WellCell targets adult coaches/clients and is not aimed at knowingly collecting information from children under 13 (or higher age where storefront rules dictate). Requirements appear in onboarding and storefront metadata.
10. International transfers
Hosting may reside outside Türkiye; we use appropriate safeguards (SCCs, vendor safeguards) where mandated.
11. Security
We apply layered access controls, encryption in transit, segmentation and monitored incident workflows.
12. Policy updates
We revise this notice from time to time; the revision date reflects changes. Material shifts may prompt in-product notice.
13. Contact
Questions: hi@wellcell.app.
Related documents: