Legal
Privacy Policy
Eira holds some of the most sensitive data there is, so this is written in the same detail we would want if it were ours. The sections that answer most questions are 6 (what the AI sees), 8 (who else touches your data), 10 (how long it is kept, and what deleting your account actually does) and 12 (your rights). Last updated 2 August 2026.
1. Who we are
1.1 The controller
Codes L.L.C., a limited liability company registered in the Republic of Kosovo at Kodra e Diellit, H 1/2, Nr. 22, Prishtinë, company number 810858003 (“Eira”, “we”, “us”, “our”), is the controller of the personal data described in this policy. That means we decide what data is collected and why.
1.2 How to reach us about privacy
Privacy questions, data-subject requests and complaints reach us through the contact form, or at legal@eira.coach. A person reads both.
1.3 Representative in the European Union
Our representative in the European Union for the purposes of Article 27 of the GDPR is
[EU REPRESENTATIVE — Art. 27].
1.4 What this policy is not
Eira provides wellness guidance, not medical advice. Eira is not a healthcare provider, and this policy is not a HIPAA notice — Eira is not a HIPAA covered entity or business associate. Health information you give a wellness app is generally outside HIPAA and inside consumer privacy law, which is what this policy addresses.
2. Scope
2.1 The app
This policy covers the Eira iPhone app, its Apple Watch companion, its widgets, complications and Siri/App Intents surfaces, and the backend service behind them.
2.2 The website
It also covers eira.coach. The website is a marketing and legal surface only: you cannot create an account or log food on it.
2.3 What it does not cover
- Apple. Your App Store account, your payment method and your Apple Health data on your device are governed by Apple’s privacy policy. We never see your Apple ID password or your card details.
- Third-party sites linked from ours or from the app (for example, a crisis helpline’s own website).
3. What personal data we collect
Categories marked [Art. 9] are special-category health data under the GDPR and UK GDPR, sensitive personal information under CCPA/CPRA, sensitive data under the Virginia-model state laws, and consumer health data under Washington’s My Health My Data Act. They carry the strictest handling rules in this policy.
3.1 Account and identity
- A user identifier issued by our authentication provider when you use Sign in with Apple. This identifier is your account key — we hold no separate mapping.
- The email address Apple relays to us. If you chose Apple’s Hide My Email, this is a private relay address and we never see your real one. Your email is display-and-export only; we never use it to look up your account.
- Your time zone, the hour at which your day starts, and account timestamps (created, onboarded, trial start).
We never receive or store a password.
3.2 Your food record [Art. 9]
- Meals and their times, meal slot, and how each was logged (photo, voice, barcode, search, manual, repeat, Watch, widget, Siri).
- Per item: the food’s name, the nutrition database it was matched to, portion in grams, and the resulting calories, protein, carbohydrate, fat and fibre, plus eight micronutrients (sodium, potassium, calcium, iron, magnesium, vitamin D, vitamin C, B12).
- Meal photos you take, and label photos when you teach Eira a product.
- The structured output of the AI analysis of a photo (what the model identified, its portion estimate, its confidence, its stated assumptions).
- Your corrections — what the model said, what you changed it to, and how you changed it. We keep these because correcting the estimate is how Eira gets better at your food. See §6.5.
- Recipes you build, and their ingredients.
- Water you log, and your water quick-add presets.
3.3 Mood and context of eating [Art. 9 — the most sensitive field in the product]
Entirely optional, off by default, and offered on one screen. If you turn it on you can tag a meal with one or more of eight fixed words (hungry, stressed/anxious, tired, bored, sad, social, celebrating, craving) and add a short free-text note.
Two things are true of the free-text note and are worth stating plainly:
- Nothing reads it. It is excluded from every aggregate, every AI prompt and every log line by design. The only place it is ever returned is your own data export.
- It is never stored on your device. It lives only on the server, so that the deletion controls that reach the server reach it too.
3.4 Weight and body measurements [Art. 9]
- Your weight over time, entered manually or read from Apple Health with your permission.
- Optionally, sex, height and year of birth — collected only because the calorie-estimation formula needs them. We store a year, not a full date of birth, because a full date of birth is a stronger identifier collected for no gain. These three are never written to a log line and are never cached on your device, and you can withdraw all three at once without deleting your account (§12.1).
3.5 Medication mode [Art. 9 — special-category, medication data]
If you turn on GLP-1 mode, we store the fact that the mode is on and, if you choose to tell us, which generic molecule you take (one of five: semaglutide, tirzepatide, liraglutide, dulaglutide, or “other”).
Deliberate limits, because this is the sharpest data in the product:
- We store the generic molecule, never the brand — brand names would reveal the indication (diabetes versus weight management), which is a second and sharper piece of health data we do not need.
- Nothing currently reads the molecule. No target, no prompt and no route branches on it. It is stored because the mode’s setup asks the question and the answer belongs in the record you can export.
- It is never sent to an AI provider. The coaching model is told the mode is on; it is never told which drug.
- Turning the mode off erases the molecule, because a medication name held for a mode nobody is in is health data kept for no purpose.
3.6 Goals, targets and settings
Goal direction and pace; calorie targets Eira has proposed and whether you accepted or dismissed them, with the arithmetic basis for each; and your display preferences (gentle mode, net carbs, measurement region, pinned nutrient, coaching hour and whether coaching is on).
3.7 Fasting and eating window [Art. 9]
Your chosen protocol and target hours, and each timer you run: when it started, when and why it ended, and which meal ended it if a meal did.
3.8 What Eira remembers about you [Art. 9 — derived]
This is the product’s core, so it deserves its own line rather than a footnote. From everything above, Eira derives and stores:
- Extracted facts — effective-dated statements about your habits, preferences, constraints and life context, each with its confidence and the conversation or log it came from. Facts are superseded, never overwritten, so the history is auditable. Facts touching allergies or medical constraints are flagged as health-sensitive and are never auto-changed by the AI — Eira asks you.
- Profile facts — structured, effective-dated profile values.
- Weekly profile summaries — deterministic statistics computed in the database, plus a short narrative paragraph written by an AI model from those statistics.
- Semantic embeddings — numerical vector representations of session summaries, notes and facts, used to retrieve the right memory at the right moment. An embedding derived from health data is still personal health data, and we treat it as such.
All of it is visible to you on one screen (“What Eira knows about you”), and editable and deletable line by line.
3.9 Coaching conversations [Art. 9]
The daily message Eira writes you (and whether it was sent and opened), your chat messages and Eira’s replies, and derived session summaries.
3.10 Subscription and entitlement state
Which product you bought, its status (trial, active, grace, billing retry, expired, revoked), when it was purchased, when the entitlement runs to, and whether auto-renew is on.
Apple processes the payment. We never receive or store your card number, billing address or any payment credential.
3.11 Device and technical data
- Push tokens — an Apple Push Notification token per device, with the platform (iPhone or Watch) and environment. Push payloads carry static text and record identifiers only, never health content, so a notification sitting on your lock screen says nothing about what you ate.
- Request metadata — a request identifier and rate-limit counters keyed to your account, kept so the service can be operated and abuse prevented.
- Error events — when something crashes or errors, a scrubbed diagnostic event. Local variables from the failing code are stripped before the event leaves the server, specifically so that a stack trace cannot carry your diary out with it.
- AI request traces — see §6.4.
3.12 Products you teach Eira
When you scan a barcode Eira does not know and teach it the product (name, brand, nutrition per 100 g, and optionally a photo of the label), that product row is added to a shared catalogue so the next person who scans the same barcode gets an answer.
⚠️ One thing you contribute outlives your account.
When you delete your account, your link to a product you taught Eira is removed, but the product row itself is kept, unlinked from you. This is deliberate: the shared catalogue is how Eira covers regional products no commercial database has. It is the only place in the product where something survives your deletion, and you should know about it before you teach Eira anything.
3.13 Marketing emails
If you join the early-access list on eira.coach, we store your first name, your last name if you gave one, your email address, and the record of your consent — the exact wording you agreed to, the version of that wording, and the moment you agreed. We keep the wording rather than a tick, because consent you cannot evidence is not consent.
That is the whole record. It is not joined to an Eira account, it says nothing about your health, and it exists for one purpose: to tell you when Eira opens, and after that to send only what you ticked the box for. It is never sold, never shared, and never handed to an advertiser.
We send one note asking you to confirm the address. If you never confirm it, we never write again. Every email after that carries a one-click unsubscribe, and unsubscribing deletes the record — your name and address come out of the list rather than being marked inactive in it. You can also ask us to remove it at any time through the contact form or at legal@eira.coach.
The list is held and the mail is sent by Brevo, which is a processor for this and for nothing else — it never receives anything from the app, and none of your health data is in it (§8.1).
The lawful basis is your consent, which you can withdraw whenever you like and without giving a reason.
3.14 What we do not collect
- No precise location. We never request location permission, and GPS metadata is stripped from every photo before it is stored (§11.2).
- No audio. Voice logging is transcribed on your device; the recording never leaves it (§7.3).
- No contacts, no photo library scanning, no advertising identifier, no device fingerprinting.
- No payment credentials.
- No special-category data other than health data — we do not collect race, religion, political opinions, trade-union membership, genetic data, biometric identifiers or data about your sex life or sexual orientation.
4. How we collect it
From you directly — everything you type, photograph, speak, scan, tag or choose.
From your device with your permission:
- Apple Health, per feature, at the moment the feature is first used — never as a wall of prompts at the start. See §7.
- Camera — for photo logging and barcode scanning.
- Microphone and speech recognition — for voice logging, processed on-device (§7.3).
- Notifications — if you allow them.
You can decline every one of these and keep using Eira with less to go on.
Automatically — the technical and diagnostic data in §3.11, generated by the act of using the service.
From Apple — your Sign in with Apple identifier and relayed email; and subscription status signals when your subscription renews, lapses, is refunded or is revoked.
We do not buy personal data, and we do not enrich your record from data brokers or third-party sources.
5. Why we use your data, and our legal bases
| What we do | Why | GDPR Art. 6 basis | Art. 9 condition (health data) |
|---|---|---|---|
| Create and run your account; authenticate you | You asked for the service | Art. 6(1)(b) contract | Not health data |
| Store your food, water, weight, fasting and mood record and show it back to you | It is the service | Art. 6(1)(b) contract | Art. 9(2)(a) explicit consent |
| Estimate nutrition from a photo, voice note or barcode by sending it to an AI processor | The feature you invoked | Art. 6(1)(b) contract | Art. 9(2)(a) explicit consent |
| Build and maintain the memory: extract facts, summarise, embed | Longitudinal coaching is the product | Art. 6(1)(b) contract | Art. 9(2)(a) explicit consent |
| Write daily messages and answer coaching chat | The feature you invoked | Art. 6(1)(b) contract | Art. 9(2)(a) explicit consent |
| Read weight and water from Apple Health; write your nutrition back | You granted the permission | Art. 6(1)(b) contract | Art. 9(2)(a) explicit consent, given through Apple’s own permission prompt and our own consent step |
| Learn from your corrections to improve your future estimates and our own evaluation set | Service quality | Art. 6(1)(f) legitimate interests | Art. 9(2)(a) explicit consent — see §6.5 |
| Safety filtering: detect and route crisis and eating-disorder signals, enforce calorie floors | Protecting you from foreseeable harm from an AI health product | Art. 6(1)(f) legitimate interests | Art. 9(2)(a) explicit consent |
| Manage subscriptions and entitlements | To bill you correctly and honestly | Art. 6(1)(b) contract | Not health data |
| Send push notifications you asked for | The feature you enabled | Art. 6(1)(a) consent (device permission) | Not health data — payloads carry no health content |
| Email you about the launch and about Eira, if you asked us to | You ticked the box | Art. 6(1)(a) consent | Not health data — see §3.13 |
| Keep the service secure; rate-limit; prevent abuse | Security is a legal duty and a product duty | Art. 6(1)(f) legitimate interests | Not health data — no health values in these records |
| Diagnose errors and crashes | To fix what broke | Art. 6(1)(f) legitimate interests | Not health data — health values are excluded by design (§11.3) |
| Comply with legal obligations; respond to lawful requests | We have to | Art. 6(1)(c) legal obligation | Art. 9(2)(f) where applicable |
5.1 How consent is given
Explicit consent under Art. 9 is a higher bar than ordinary consent: it needs a clear affirmative act that names the sensitive data and its purposes, separately from a general acceptance of terms. Bundling it into “I agree to the Terms and Privacy Policy” does not meet the standard.
So we ask for it as its own step in onboarding — separate from accepting the Terms, specific about what it covers, never pre-ticked — covering both the processing of health data to provide the service and the sending of it to named AI processors under no-training terms. We record when you gave it, which version of the consent it was, and the exact wording you saw.
5.2 How consent is withdrawn
Withdrawal must be as easy as giving it, and it is not all-or-nothing:
| What you want to stop | How |
|---|---|
| Apple Health reading or writing | Revoke it in Apple’s Health app, any time. Eira keeps working with less to go on. |
| Your body measurements being held | Settings → About you → “Remove your biometric data”. Clears sex, height and birth year together, immediately, without deleting anything else. |
| Medication data being held | Turn GLP-1 mode off. The molecule is erased when you do. |
| A mood tag or note on a meal | Clear it on that meal. |
| A remembered fact | Delete it on the “What Eira knows about you” screen. |
| A single meal, weight or water entry | Delete it in the app. |
| Everything | Delete your account (§12.1). |
Withdrawing consent stops future processing. It does not make unlawful the processing that happened lawfully before you withdrew.
6. AI processing
This is the section that deserves the most plain language, so it gets it.
6.1 What is sent, and when
| Feature | What leaves our servers | To whom |
|---|---|---|
| Photo meal logging | The downscaled, metadata-stripped meal photo | AI vision provider |
| Label and barcode teaching | The label photo, for text recognition | AI vision provider |
| Voice logging | The text transcript only — never audio (§7.3) | AI provider |
| Daily coaching message | A compact, de-identified context block: your profile summary, recent trends and targets | AI provider |
| Coaching chat | Your message plus the same kind of context block | AI provider |
| Memory extraction | The session text being extracted from | AI provider |
| History questions | Your question and a computed, grounded answer block | AI provider |
| Semantic search | The text being embedded | Embeddings provider |
Your name, email and account identifier are never sent. Prompts refer to you as “the user”. Context blocks carry only the fields a given task needs, never raw database rows.
6.2 Who processes it
All AI providers act as our processors — they process your data on our instructions and for no purpose of their own.
| Provider | What it does for us |
|---|---|
| Photo and label vision, coaching, daily messages, narrative summaries and memory extraction | |
| OpenAI | Embeddings for semantic memory; a fallback for every task if Google is unavailable; and the primary model for a safety-escalation reply — the one turn we deliberately route elsewhere |
No other AI provider receives your data. A fallback is triggered only by a transport failure, timeout, rate limit, server error, repeated schema failure or an open circuit breaker — never by what you said, and never by a low-confidence result. Every call records which provider actually served it, and a provider is never switched on before its data-processing agreement is signed and its configuration verified.
6.3 Training and retention
Every AI call we make runs under API terms that prohibit the provider from training on your data and that require it not to be retained beyond what is needed to serve the request. No processor receives health data before its data-processing agreement is signed and its configuration verified.
6.4 Observability of AI calls
We record traces of AI requests to diagnose failures and control cost, in an EU-hosted tracing service. Traces are minimised: prompts carry no identifiers, an automatic mask scrubs email- and phone-shaped strings, and photos are never sent to the tracing service — a trace references the storage key, not the image.
6.5 Learning from your corrections
When you correct an estimate, we keep the before-and-after. It is used two ways: to build your own priors, so Eira gets better at your food specifically, and as our internal evaluation set, so a prompt or model change can be tested before it ships.
This is our own improvement loop. Corrections are not sent to AI providers as training data, and no AI provider trains on your data. The distinction matters and we state it plainly rather than hiding behind “we may use your data to improve our services”.
6.6 The estimate is an estimate
The AI identifies foods and portions. It never produces the calorie or macronutrient numbers — those are looked up in nutrition databases and computed arithmetically. Where the model’s own estimate diverges sharply from the database, confidence is lowered and Eira asks you rather than guessing.
The same discipline governs coaching: targets, floors and bands are computed deterministically in code; a model may restate a figure it was given, never originate one. Every user-facing AI output passes a safety filter before it reaches you.
6.7 We never use your data to advertise
Nothing in this pipeline feeds advertising, ad targeting, look-alike audiences or profiling for any third party. There is no advertising SDK in the app.
7. Apple Health and device data
7.1 What Eira reads and writes
Eira asks for Health permissions one feature at a time, at the moment that feature is first used.
- Eira reads: body mass (weight) and dietary water.
- Eira writes: dietary water, dietary energy, protein, carbohydrates, total fat and fibre.
That is the whole scope. If we ever add a type, this section and the App Store privacy label are updated in the same release.
7.2 The rules that ride with Health data
Data read from Apple Health, and data derived from it:
- is used only to run features you asked for;
- is never used for advertising or marketing;
- is never sold, and is never disclosed to a data broker;
- is never used for use-based data mining;
- is never sent to any analytics SDK, and never written to a log line;
- is never stored in our iCloud containers — Eira uses no CloudKit for health data at all.
You can revoke any Health permission in Apple’s Health app at any time. Eira keeps working with less to go on.
Only your iPhone writes to Apple Health. A meal logged on your Watch is sent to our backend and mirrored into Health by the phone, so nothing is double-counted.
7.3 Voice
Speech is transcribed on your device, with on-device recognition required. The audio recording never leaves your iPhone or Watch and is never uploaded to us or to anyone else. Only the resulting text transcript is sent to our server to be parsed into a food entry.
7.4 Photos
A meal photo is uploaded directly to our private storage under a key scoped to your account. Before anything else happens to it, our server:
- verifies it really is an image, by inspecting the file’s bytes rather than trusting its name;
- strips all metadata, including GPS coordinates — a meal photo’s location is health-adjacent location data, and there is no code path that keeps an unstripped photo past processing;
- re-encodes and downscales it, and deletes the original.
Only the stripped, resized image is retained. Photos are served back to you through short-lived, per-request links; the storage bucket is fully private, with no public access and no listing.
7.5 Crisis resources and region
If you use coaching chat, your app may send a region hint so that the crisis and eating-disorder helplines shown to you are the ones in your country. That hint is never stored and never logged — it is used to render the block on that one reply and then discarded. If we cannot tell your region, you get the international resources instead; you are never shown nothing.
8. How we share your data
We do not sell your personal data. We do not share it for cross-context behavioural advertising. We show no ads. There are no advertising, marketing or data-broker recipients, and we have never had any. These are statements about the architecture, not aspirations: there is no advertising SDK, no analytics SDK and no marketing pixel anywhere in the app.
8.1 Sub-processors
We use a deliberately short list of processors, each under a data-processing agreement, each present because a feature needs it.
| Recipient | What it receives | Where |
|---|---|---|
| Hetzner | Hosting for the application and the database — all primary data | Germany |
| Cloudflare R2 | Meal and label photos, export bundles, encrypted backups | Bucket jurisdiction set to the EU; US parent company |
| Supabase | Authentication only — your identity, no health data | EU project |
| Backblaze B2 | A second, client-side-encrypted copy of backups | EU region bucket |
| AI processing (§6) | US company | |
| OpenAI | AI processing and embeddings (§6) | US company |
| Sentry | Scrubbed error events — no health data | US company |
| Langfuse | Minimised AI traces — no photos, no identifiers | EU region |
| Brevo | The early-access mailing list: name, email and the consent record (§3.13). No health data, and nothing from the app. | EU company |
| Apple | Push notification delivery (a token, and a payload with no health content); App Store billing | Apple’s infrastructure |
| FatSecret, USDA FoodData Central, Open Food Facts | A food name or a barcode. No account identifier, and nothing about you, is sent to a nutrition database. | Respective providers |
8.2 Other disclosures
We may disclose personal data:
- To comply with law — a valid court order, subpoena or regulatory demand. We will tell you unless we are legally prohibited from doing so.
- To protect rights and safety — where necessary to investigate fraud, abuse or a threat to someone’s safety.
- In a corporate transaction — if Eira is acquired or merged, your data may transfer to the acquirer. We will notify you before any such transfer, and your health data will remain subject to this policy or to one no less protective of you.
9. International transfers
Stated as compliance facts, plainly.
- Your account, your record and your photos are hosted in the European Union — the application, database and object storage all sit in EU jurisdictions. Encrypted backups are held in the EU.
- Eira is offered internationally, including in the United States. If you use Eira from outside the EU, your data is transferred to and stored on EU infrastructure.
- Some processing happens with US-based providers. In particular, the AI providers that analyse a photo or write a coaching reply, and our error-reporting provider, are US corporations. That is a transfer out of the European Economic Area even where the service itself runs in an EU region.
- Every such transfer runs under an approved safeguard — Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified under it.
A copy of the safeguards we rely on is available on request — ask through the contact form.
10. How long we keep it
| Data | Retention |
|---|---|
| Your record — food, water, weight, fasting, mood, memory, coaching | For as long as your account exists. A companion with a memory is the product. You can delete any individual item at any time. |
| Raw, unprocessed photo uploads | Deleted immediately after processing, with a storage lifecycle rule removing any remainder within 24 hours |
| Processed meal photos | While the meal exists; deleted when you delete the meal or the account |
| AI request traces | 90 days |
| Error events | 90 days |
| Encrypted backups | Rotated daily for 7 days, weekly for 4 weeks, monthly for 6 months — so a deleted account can persist in an encrypted backup for up to about six months |
| Deleted-account marker | An account identifier and a deletion timestamp only — no personal data — kept indefinitely, so that a restored backup can be re-deleted and a deleted identity cannot be silently re-created |
| Products you taught Eira | Kept in the shared catalogue, unlinked from you — see §3.12 |
| Messages you send through the contact form | 24 months, then deleted |
| Your early-access list entry | Until you unsubscribe or ask us to remove it, and then deleted |
10.1 What happens when you delete your account
- Your record is erased from the live database in a single cascading delete — every table, including the semantic embeddings, by hard delete, never a soft flag.
- Your photos, label images and export bundles are deleted from object storage.
- Your identity is deleted at the authentication provider, which removes every linked sign-in.
- Your push tokens are purged.
- The job ends by counting the remaining rows and storage objects for your account and asserting the answer is zero — the deletion is verified, not assumed.
- The semantic index is rebuilt on a monthly schedule, because a vector index can retain traces of a deleted entry in its internal structure. Your embeddings are therefore provably gone from the index within 31 days of deletion.
- Backups are handled as set out in the table above.
11. Security
Security is treated as product spend here, not overhead, because the product’s premise is trust.
11.1 Access and isolation
- Encryption in transit (HTTPS only, with HSTS) and at rest.
- Exactly one authorisation rule: you can access only your own rows. Your account identifier comes only from your verified session token — never from a URL, a query parameter or a request body — and every query on your data is filtered by it. Asking for someone else’s record returns “not found”, indistinguishable from a record that does not exist. This is enforced by a test suite that, for every endpoint, asserts one user cannot reach another’s data.
- Object identifiers are non-sequential and non-enumerable.
- Access tokens are short-lived (one hour) with rotating refresh tokens and replay detection. Tokens are stored in the iOS Keychain, device-only, never in plain preferences.
- The database is never exposed to the public internet. Administrative access is direct and logged; there is no admin API surface.
11.2 Data-minimisation controls
- GPS and all other metadata stripped from every photo before storage (§7.4).
- Uploads validated by file content, size-capped, and written only under your own account’s key prefix.
- Rate limits on every endpoint, tighter on AI-invoking and authentication-adjacent ones.
11.3 Health data is excluded from logs and analytics by design
This is the rule the rest of the architecture is built around:
- No health value is written to a log line. Body measurements, medication data and mood notes are explicitly excluded.
- No health data reaches an analytics SDK, an advertising network, or a data-mining process. There is currently no product-analytics SDK in the app at all (§14).
- Error reports are scrubbed before they leave the server, including stripping local variables from failing code frames.
- Push notification payloads carry static text and identifiers only.
- No health data is stored in any iCloud container.
11.4 Backups
Backups are encrypted before they leave our infrastructure, held in two EU locations, and restore-tested rather than assumed.
11.5 Honest limits
No system is perfect, and we would rather say so than imply otherwise. Known accepted limits at this stage: we are a small team, we have not yet commissioned an external penetration test, and some supply-chain scanning is run by hand rather than automatically on every change. If a breach affects your data, §16 says what we will do.
12. Your rights
We never charge for a rights request, never require you to create anything extra to make one, and never treat you differently for exercising one.
12.1 Rights you can exercise inside the app, right now
| Right | Where |
|---|---|
| Access and portability — a complete, machine-readable copy of your record | Settings → export. It is generated as structured JSON covering your profile, every food log and item, weights, water, water presets, recipes, fasting sessions, corrections, calorie targets and dismissals, extracted facts, coaching sessions and messages, profile summaries, daily messages, devices and subscriptions. |
| Rectification — correct anything wrong | Edit any meal, item, portion, weight or remembered fact in the app. Corrections take effect immediately, and coaching follows them. |
| Erasure — of one item or of everything | Delete a meal, a weight, a water entry, a remembered fact, a mood tag, or your whole account. Account deletion is in-app, confirmed, and runs the cascade in §10.1. |
| Withdraw consent to hold your body measurements | Settings → About you → “Remove your biometric data” |
| Withdraw consent to hold medication data | Turn GLP-1 mode off |
| Restrict Apple Health access | Apple’s Health app |
12.2 EEA and UK — GDPR rights
If you are in the EEA or the UK you have the rights to access, rectification, erasure, restriction of processing, data portability, objection (including to processing based on legitimate interests), and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
You also have the right to lodge a complaint with a supervisory authority in the country where
you live, work, or where you believe an infringement occurred. Our lead supervisory authority is
[LEAD SUPERVISORY AUTHORITY]. We would much rather you gave us the chance to put it right first,
but that is your choice, not a condition.
We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
12.3 California — CCPA/CPRA rights
Health information collected by a wellness app like Eira is not covered by HIPAA, so it falls squarely within the CCPA/CPRA. As a California resident you have the right to:
- Know what personal information we collect, use and disclose — §3 is that disclosure, by category and by source.
- Delete your personal information — §12.1.
- Correct inaccurate personal information — §12.1.
- Opt out of sale or sharing. We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of and no “Do Not Sell or Share” link is required. We have not sold or shared personal information in the preceding 12 months.
- Limit the use and disclosure of sensitive personal information. Your health data is sensitive personal information. We already use it only for the purposes you asked for — providing the service you requested — and never to infer characteristics about you for any third party, so the right is satisfied by our default behaviour rather than by a toggle.
- Non-discrimination for exercising any of these.
12.4 Other US states
If you live in a state with a comprehensive privacy law — Virginia, Colorado, Connecticut and the growing list that follows their model — you have equivalent rights to access, correct, delete and obtain a portable copy, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do none of those three, so there is nothing to opt out of.
These laws treat health data as sensitive data requiring opt-in consent before processing, which is consistent with the explicit-consent basis in §5.
You may appeal a refused request; if we refuse an appeal, you may complain to your state Attorney General.
12.5 How to exercise a right we cannot handle in-app
Write to us through the contact form or at legal@eira.coach. We may need to verify that the request comes from you — for an account holder that normally means making the request from the email address on the account, or from within the app while signed in. We will not ask you to justify why.
13. Children
Eira is for adults. You must be at least 18 years old to create an account. A version for teenagers would be a different product, with paediatric references and parental consent, rather than a setting.
We do not knowingly collect personal data from anyone under 18. If we learn that we have, we delete the account and its data. If you believe a child has given us data, tell us through the contact form and we will act on it.
We do not knowingly sell or share the personal information of anyone under 16, and we have no mechanism by which we could.
14. Cookies, tracking and analytics
14.1 In the app
There is no advertising SDK, no attribution SDK, no advertising identifier, no tracking pixel and no cross-app or cross-site tracking. Eira does not present an App Tracking Transparency prompt, because it does not track you.
There is currently no product-analytics SDK in the app either. The only diagnostic collection is the scrubbed error reporting described in §3.11 and §11.3. If that ever changes, this section and the App Store privacy label change with it, in the same release.
14.2 On the website
The website sets no cookies, runs no analytics, and loads nothing from a third party — no font service, no embedded video, no tag manager. There is no consent banner because there is nothing to consent to. Two things leave this site, and both post to our own server on the same domain: the contact form, and the early-access form in §3.13.
15. Automated decision-making and profiling
Eira profiles you in the ordinary sense — it learns your habits and patterns, because that is the product. It does not make automated decisions that produce legal or similarly significant effects on you.
Concretely, and this is a design rule rather than a policy assertion:
- A calorie target is proposed and never applied. Eira estimates and suggests; the number your app actually uses moves only when you press accept. Merely viewing a proposal writes nothing at all. This deliberately replaced an earlier design in which a weekly job adjusted the target automatically, on the reasoning that an auto-decreasing calorie target is the mechanic of a restrictive diet.
- The memory asks rather than assumes. A contradiction touching an allergy or a medical fact is never resolved automatically — Eira asks you.
- Safety routing can change which model answers a coaching message, and can substitute a safe reply carrying crisis resources. That affects the text you receive; it makes no decision about you, grants or withholds nothing, and is subject to human oversight by us.
Nothing here profiles you for advertising, credit, insurance, employment or any third party.
16. Data breaches
If a personal-data breach occurs we will:
- notify the competent supervisory authority within 72 hours of becoming aware of it, where the breach is likely to result in a risk to your rights and freedoms (GDPR Art. 33);
- notify you without undue delay where the breach is likely to result in a high risk to you (GDPR Art. 34). Because Eira holds health data, we will assume a breach of your record is high-risk unless there is a clear reason to conclude otherwise;
- comply with applicable US state breach-notification laws, which may impose their own timelines and content requirements; and
- tell you what actually happened, not a sanitised version of it.
Our incident procedure — containment, credential rotation, forensic snapshot, notification templates and authority contacts — is written down in advance rather than improvised during an incident.
17. Changes to this policy
If we change how we handle your data in a way that matters, we will tell you in the app before the change takes effect. Where a change requires your consent — in particular any new purpose for health data, or any new AI processor — we will ask for it rather than assume it. The “Last updated” date at the top tells you which version you are reading, and we keep prior versions available on request.
18. Contact and complaints
Controller: Codes L.L.C., Kodra e Diellit, H 1/2, Nr. 22, Prishtinë, Republic of Kosovo, company number 810858003
Privacy contact: the contact form, or legal@eira.coach
Representative in the European Union (Art. 27): [EU REPRESENTATIVE — Art. 27]
Lead supervisory authority: [LEAD SUPERVISORY AUTHORITY]
Security reports: legal@eira.coach
EEA and UK: you may lodge a complaint with your local supervisory authority. In the UK, that is the Information Commissioner’s Office.
California: you may contact the California Privacy Protection Agency or the California Attorney General.
Other US states: you may contact your state Attorney General.