Welluna Health TM
Home Contact Privacy Terms
Privacy Policy

Privacy Policy

Effective date: August 23, 2026

Intervaya information added: September 3, 2026

Welluna HealthTM respects the personal nature of health and wellbeing information. This policy explains the practices that apply across wellunahealth.com and our apps, followed by product-specific details for AquellaTM and the Welluna HealthTM App, with an additional section for IntervayaTM.

Choose a section:

  • All Welluna Health apps and services
  • AquellaTM
  • Welluna HealthTM App
  • IntervayaTM interval timer
  • Your choices and contact information

All Welluna Health apps and services

The information a Welluna Health product handles depends on the product and the features you choose. We collect or process only information reasonably needed to provide, secure, support, and improve the applicable service. Aquella is a local-only product and is specifically described below; connected products and our website may process information on Welluna Health systems or through service providers that help us operate them.

Information that may be processed

  • Account information such as your name, email address, password hash, and sign-in preferences when a service offers accounts.
  • Security data such as verification requests, trusted-device records, session activity, login timestamps, and abuse-prevention records.
  • Health and lifestyle entries you choose to log, depending on the features available in the product.
  • Settings and preferences such as units, targets, profile choices, and feature defaults.
  • Support and contact information when you communicate with us.
  • Basic technical data such as browser or device type, approximate request times, and server logs for connected services and our website.

How information may be used

  • To provide the features you request and display your saved records, goals, trends, and preferences.
  • To create, maintain, and authenticate accounts where accounts are offered.
  • To protect accounts and services, prevent abuse, and maintain reliability.
  • To respond to support, privacy, and product questions.
  • To improve service performance and feature quality.

Sharing and service providers

We do not sell personal information. For connected products and website features, we may share limited information with providers that help us operate hosting, email delivery, security, infrastructure, or requested data lookups. We disclose product-specific provider uses below. We may also disclose information when required by law or when reasonably necessary to protect users, our services, or legal rights.

Cookies and local storage

Our website and connected products may use cookies or similar device storage to maintain sessions, remember trusted devices, preserve preferences, prevent abuse, and support basic usability. Aquella does not use account or advertising cookies.

Retention and security

For connected products and website interactions, information is kept for as long as reasonably needed to operate the service, maintain records and security, meet legal obligations, and resolve disputes. Retention varies by data type and is also subject to the product-specific provisions below. We use reasonable administrative and technical safeguards appropriate to the information and service involved, but no storage or transmission method can be guaranteed completely secure.

AquellaTM

Aquella is a local-only hydration tracker. It does not require or create an account, connect to a Welluna Health database, include advertising or analytics services, or request internet access. Welluna Health does not receive the hydration entries, reminder schedules, custom reminder messages, or settings you save in Aquella.

  • Hydration entries, goals, drink settings, personalized drink names, reminders, and app preferences are stored in Aquella's private storage on your device.
  • Home-screen widgets use the same local data and do not transmit it to Welluna Health.
  • If you enable reminders, Aquella uses Android's notification permission only to display the local reminders you configure.
  • Cloud backup is disabled for Aquella.
  • Where Android permits it, Android may transfer Aquella's local database and preferences directly to a new device during device setup. That transfer is controlled by Android and your device or platform provider, not by Welluna Health.
  • You may manually export or import an Aquella JSON or CSV file. You choose where an exported file is saved or shared. Once it leaves Aquella's private storage, it is protected by the storage location and services you choose.

Aquella retention and deletion

Aquella keeps local entries and preferences until you edit or delete them, clear the app's storage through Android, or uninstall the app. Uninstalling or clearing storage removes Aquella's private local data from that device, but it does not remove copies you previously exported or data already transferred to another device. Because Welluna Health does not receive Aquella's local records, there is no Aquella account or server-side hydration record for Welluna Health to delete.

Welluna HealthTM App

The Welluna Health App is a connected, account-based wellbeing service. Unlike Aquella, information entered in the Welluna Health App is sent to and stored on systems operated for Welluna Health so users can sign in, retrieve records, and use account features across supported devices.

The Welluna Health App may process:

  • Account information, including your name, email address, password hash, role, unit preferences, goals, and profile settings.
  • Account-security information, including session records, password-reset records, hashed verification and trusted-device tokens, device or browser identification information, and security timestamps.
  • Wellness information you choose to enter, including hydration, food and nutrition, movement, mood, energy, stress, gratitude, intentions, notes, reflections, cycle information, and daily routines.
  • Optional content you choose to upload, such as meal photos.
  • Food names, search terms, and barcode numbers used to search or contribute food information.
  • Technical and security information such as browser or device type, approximate request times, and server or rate-limiting records.

We use this information to create and secure accounts, provide requested tracking features, display saved records and trends, remember preferences, perform food lookups, respond to support requests, prevent abuse, and maintain service reliability.

When you request a food or barcode lookup, the lookup value or search terms may be sent to food-data providers such as Open Food Facts or the U.S. Department of Agriculture FoodData Central. Welluna Health does not intentionally send account credentials or personal journal entries to those providers. Barcode-camera images are used to recognize a code and are not intentionally retained as meal photos unless you separately choose to upload an image.

Personal logs and personal food items remain associated with your account. Food or barcode information is considered for a shared catalog only when you deliberately use a submission or sharing feature. Shared submissions may be reviewed, corrected, approved, declined, or incorporated into a catalog available to other users. Contributor and review records may be retained internally for integrity and abuse prevention.

Welluna Health App retention and account deletion

Account information and connected wellness records are generally retained while your account remains active. You may delete individual records where the service provides that control or contact us to request an account export or deletion. A verified deletion request will delete or de-identify account-associated personal records, subject to limited retention reasonably required for security, fraud prevention, legal compliance, dispute resolution, or backup rotation. Public or shared catalog facts that do not identify you may remain.

Before an account-creating mobile version is publicly released, it will provide an in-app account-deletion path and a public web method for initiating deletion. Until then, privacy and deletion requests may be submitted through our contact form.

IntervayaTM interval timer

Intervaya is Welluna Health's customizable interval timer for exercise and other timed routines. This section applies to the Intervaya Android app (com.wellunahealth.intervaya) and its connected web service at intervaya.wellunahealth.com. It supplements the general provisions above and does not change the separate practices described for Aquella or the Welluna Health App.

Local use and optional connected features

You can use Intervaya Lite's local timer and one routine without creating an account. Local routines and settings are stored on your device. Basic adds local features such as additional routines, history, reminders, and file import/export. Purchases require an Intervaya account, even when the unlocked timer features are used locally. Account and purchase verification sends information to our service; it does not by itself enable cloud synchronization of your routines and history.

When you use Pro cloud synchronization, Intervaya uploads and stores your routines, exercise details, workout history, in-progress sessions, settings, and reminder schedules so they can be retrieved and synchronized across supported signed-in devices and the web app. Synchronization can run automatically while the app is in use. Canceling Pro does not end access before the paid period expires, and downgrading to Basic does not remove routines or history already stored on your device. Basic does not include ongoing cloud upload or synchronization.

When eligible Pro access actually ends and your account remains on Basic, we provide a download-only cloud recovery window for previously synchronized routines, history, in-progress sessions, and settings. We email the account address when that window starts and show the exact expiration time in the recovery screen. The window lasts at least 30 days after successful initial notice. We send another warning at least three days before removal; if that warning is delayed, removal is delayed to preserve the full warning period. Downloading does not extend the deadline. If eligible Pro access resumes before removal, expiry for that ended-Pro period is not performed and ordinary synchronization can resume. After the displayed deadline, the active synchronized records and their synchronization change history are removed. Your Basic account, purchase records, local device data, and files you exported are not removed by this cloud cleanup. Existing cloud data first covered by this practice receives a prospective notice period rather than a retroactive deadline.

Information Intervaya processes and why

  • Account information: your email address, account ID, password hash, and account timestamps, used to create and manage your account, authenticate you, and provide account recovery.
  • Security and device information: an app-generated installation ID, device name or model, platform/app version, authentication and trusted-device records, and sign-in or synchronization timestamps, used to manage sessions, recognize devices, and protect access. The installation ID is not an advertising ID.
  • Purchase history: product identifiers, purchase tokens, order references, subscription status and expiry, and purchase-verification records, used to confirm ownership, provide Basic or Pro access, restore eligible purchases, and prevent purchase fraud.
  • Fitness information and other content you enter: routine and exercise names, work/rest durations, rounds, schedules, completion records, and in-progress sessions, used to run your routines and provide history and synchronization where enabled. Custom text can also describe activities other than exercise.
  • App interactions and preferences: saved changes, activity timestamps, theme and timer colors, voice/audio choices, and reminder settings, used to operate the app, maintain your account and synchronized state, and personalize your experience.
  • Technical and support information: network addresses and request/error information in server logs when you connect to our service, and information you voluntarily provide when contacting support, used to troubleshoot, secure, and support the service.

Intervaya does not display advertisements, use the Android advertising ID, or include third-party advertising or analytics SDKs in its Android app. We do not sell your Intervaya personal information or use your workout records for targeted advertising. The Android app does not request access to your location, contacts, device calendar, camera, or microphone.

Purchases, service providers, and communications

Google Play processes Android purchases and subscription payments. Intervaya sends product and purchase-verification information, including an obfuscated account identifier for purchase association, and receives purchase and subscription updates. We do not receive or store your full payment-card or bank-account details through Google Play Billing. Google handles its own account, payment, transaction, and retention practices under its policies.

Our hosting and infrastructure providers process connected account data on our behalf. Email-delivery services process your email address and message contents to deliver sign-in verification and password-recovery messages. Routine names or workout history are not needed in these authentication emails. Our staff may access relevant records when necessary to provide support, investigate security issues, or administer the service.

Device voices and premium speech

Device voices use the text-to-speech engine installed on your device. Its available voices, offline capability, and any network processing depend on the engine and voice you choose and that provider's settings and policies.

If you choose a Pro premium voice, text to be spoken, such as exercise names, countdowns, and timer announcements, is sent to our server. When audio is not already cached, we send that text and the selected voice to Microsoft Azure AI Speech to generate the requested audio. We do not include your account email or password in the speech-synthesis request to Microsoft. Custom spoken text may itself contain personal information, so avoid putting sensitive information into exercise names you choose to have spoken. This feature generates speech from text; it does not record or clone your voice.

Generated audio is cached on our server and may also be cached on your device to avoid repeatedly generating the same speech. Custom server audio is stored separately for each account, with filenames derived from the text and selected voice. The audio can still contain the words you supplied. Custom clips expire after 15 days without a successful server request for that clip; requesting a cached clip from the server refreshes this period. Expired clips are regenerated when requested. An hourly cleanup normally removes inactive clips within one hour after the 15-day threshold while the service is running.

A fixed set of generic app cues (Begin, Rest, Round rest, Get ready, Workout complete, Halfway there, and the countdown numbers 3, 2, and 1) is shared across accounts, with a separate audio version for each premium voice. These generic clips do not contain custom routine text and are kept without an inactivity expiry so they can be reused. Other custom speech does not enter this shared cache. These server-cache practices were updated on September 4, 2026.

The 15-day period applies to our active server cache, not to device copies or server backups. Playing audio already cached on your phone does not contact the server and does not refresh the server's inactivity period. Clearing the relevant app or browser storage removes local cached copies on that device; deleting an account does not remotely erase every device copy.

Reminders, local storage, and files

Android notification permission is used for the local routine reminders you enable. If you enable browser push reminders in the web app, we store the browser's push subscription and reminder-delivery information and use the browser provider's push service to deliver notifications. Reminder notifications can display a routine name; you can manage permission and lock-screen visibility in your device or browser settings.

Intervaya uses app or browser storage for routines, settings, history, session credentials, and cached content as applicable. Android credentials are protected using Android Keystore-backed storage. Android automatic app backup is disabled; Intervaya's optional Pro synchronization and your manual file exports are separate features.

Import/export tools let you select JSON or CSV files and choose where exports are saved. Importing a file reads its contents on your device; imported routines or records may subsequently be uploaded if you use cloud synchronization. Exported files and copies you share are controlled by you and the storage services or recipients you choose. They are not removed by deleting your Intervaya account.

Intervaya retention and account deletion

Local data remains in app or browser storage until it is removed through available app controls or by clearing the relevant app/site storage or uninstalling the Android app. Signing out is not the same as deleting local data. Other devices and files you previously exported may retain their own copies.

Connected account and purchase records are generally kept while your account exists. Pro synchronized content follows the download-only downgrade recovery and removal schedule described above. Editing or deleting an individual synchronized routine or history entry can leave synchronization change records until that cloud cleanup or account deletion; it is not equivalent to immediately erasing all server copies. To delete your account and its associated active database records:

  1. In the Android app, sign in and open Settings > Plan & Account > Delete account, or visit Intervaya's account-deletion page without needing the Android app installed.
  2. Sign in if prompted, enter your current password, type DELETE, and confirm the deletion.
  3. If you cannot sign in or need help, use our contact form, identify Intervaya and the account email, and request assistance. Do not send your password or verification codes. We may need to verify account ownership.

When the deletion succeeds, the active database removes your account, synchronized routines, history, sessions, settings, associated devices and authentication records, reminders, and account-linked plan and purchase records. Deletion cannot be undone through the app. It does not delete your Google account or Google's transaction records, cancel your Google Play subscription, or automatically refund purchases. Manage or cancel Pro in Google Play separately to stop future renewals.

Successful account deletion also removes that account's custom audio from our active server cache. If file cleanup fails after the account records are deleted, hourly maintenance retries removal. Shared generic app cues remain because they are not account-specific recordings.

To prevent an older backup from reactivating an account you asked us to delete, we keep a separate, limited deletion record containing the internal account identifier, request time, and integrity-check information. This record does not include your email address, password, fitness history, routine text, or payment details. We retain it as needed to honor deletion requests across retained backups; it is not removed by the 30-day backup-file rotation. These deletion safeguards apply to requests recorded from September 4, 2026 onward and do not reconstruct earlier deletion history.

We use a separate integrity-protected cloud-expiry journal to prevent an older database backup from restoring synchronized content removed after a downgrade recovery deadline. Its minimal records contain internal account and recovery-cycle identifiers, the cleanup cutoff and request time, and integrity-chain information; they do not contain an email address, password, routine text, fitness history, or payment details. Cloud-expiry journal records are retained as needed to enforce the cleanup across backups and are encrypted before incremental off-server backup. Restoring an older database requires operator reconciliation before the service can start. This journal does not represent account deletion and is not used to remove a Basic account or purchase entitlement.

Intervaya-specific deployment and database backup files in our managed backup folders are eligible for removal 30 days after creation. An hourly cleanup normally removes them on the next pass while the server is running. This backup-retention practice was introduced on September 4, 2026. Shared hosting backups, provider snapshots, device copies, and files you export are separate; the 30-day period is not a promise that every copy in every location is erased within 30 days.

Account deletion does not immediately erase every copy outside the active account database and server audio cache. Server backups, device copies, technical/security logs, and pending purchase-notification records may remain and require separate cleanup. Purchase tokens in successfully processed notifications are cleared, but notifications awaiting processing can retain them. Information retained for security, fraud prevention, legal obligations, or dispute resolution is subject to the applicable purpose and retention requirements. Contact us for assistance with information that may remain outside the active account records.

Security and younger users

Intervaya's app and web service use HTTPS to encrypt information sent to our API. Passwords are stored as hashes rather than readable passwords. These safeguards reduce risk but cannot guarantee complete security. Protect your device, exported files, email account, and sign-in credentials.

Intervaya is intended for users aged 13 and older, not children under 13. Where local law requires a parent or guardian's authorization for a younger user's account or connected-data processing, that authorization is required. This age statement does not replace any consent or other protections required in the countries where the service is offered. Contact us through the contact form if you believe a child's information has been provided without appropriate authorization.

Your choices and contact information

  • You can update many settings directly inside the applicable app.
  • You can choose not to use optional uploads, shared submissions, or connected lookup features.
  • You can contact us for account assistance, data export help, correction, or deletion review.

Children's privacy

Our services are intended for general audiences and are not directed to children under 13. Aquella does not transmit personal information to Welluna Health. If you believe a child provided personal information to us through another Welluna Health service without appropriate authorization, contact us and we will review the request promptly.

Medical disclaimer

Welluna HealthTM apps are wellness tools, not medical devices and not substitutes for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional for medical concerns.

Changes to this policy

We may update this policy as our products, practices, or legal obligations change. We will post revisions here and update the effective date. Material changes will be communicated through an appropriate additional notice when required.

Contact us

For privacy questions or requests, use our contact form.

Welluna HealthTM

Health-focused apps designed to help people build softer, steadier routines around hydration, nutrition, mood, and everyday wellbeing.

Privacy Policy Terms & Conditions Welluna HealthTM App Contact Welluna Health