PRIVACY POLICY
This Privacy Policy explains what Alure (“Alure,” “we,” “us”) collects when you use the Alure mobile app or website, how we use it, and the choices you have. If anything here is unclear, email support@alure.health.
The short version
- We collect what you put in: profile details, meal photos and their nutrition, symptom journal entries, cycle logs, and optional Apple Health data.
- Meal photos are sent to Google (Gemini) to identify the foods and estimate their nutrition. Nothing else is sent to third party AI providers.
- Apple Health data is used solely to power what you see inside the app. It is never used for advertising, never sold, never shared with data brokers, and never used for research.
- We measure how the app is used with product analytics (PostHog): anonymous events like “a meal was scanned,” tied to a random identifier, never your name, email, or the contents of your logs. Session recording is off.
- You can delete your account from inside the app at any time. Deletion removes your data from our servers and cannot be undone.
- We don’t sell your personal information.
What we collect
Waitlist (website, pre-launch)
If you joined the waitlist on our website before Alure launched, we collected the email address you submitted and the date you joined. We use it only to email you about Alure, and we store it with our database provider, Supabase. We never sell it and never use it for advertising. Email support@alure.health to be removed at any time.
Account information
When you sign in with Apple or Google, we receive an email address and a stable user identifier. We do not receive your social contacts, calendar, or other data from those providers.
Profile you create
Name, age, height, weight, PMOS type, and goals you provide. This information stays tied to your account and is used to personalize your experience inside the app.
Shipping details
During setup we ask for your address, and you can add a phone number later if you like. Alure is free and this is not a billing form. We use your address to localize the app (for example, regional grocery prices in the savings calculator and seasonal food suggestions) and to prefill checkout in the PMOS Labs store if you ever choose to order there. While you type your street address, the text in that field is sent to the Photon geocoding service to offer completions (see providers below). You can edit or remove your shipping details at any time in Profile → Shipping details, and they are deleted with your account.
Meal logs
Photos you capture of meals are stored with your account and used to generate nutrition estimates (calories, macros, micronutrients, and a meal score). The photo and a brief prompt are sent to Google’s Gemini API to identify the foods and portions and estimate their nutrition. The analysis response is stored against the meal record. No user identifier is sent to Google with the photo.
Symptom journal
Symptoms you log (category, severity, time of day) are stored with your account. We use these entries to generate your personal insights and to surface patterns alongside your meal data.
Cycle tracking
Period and cycle entries you log (flow, dates, and optional body signs) are stored with your account and used to show your cycle view and connect cycle phase to your other patterns. If you connect Apple Health, cycle data can sync in both directions as described below.
Other logs
Water, supplement, and saved-meal entries you create are stored with your account and shown back to you in the app.
Apple Health (optional)
If you grant permission, Alure reads the following from Apple HealthKit to power what you see in the app:
- Body mass (weight)
- Step count
- Active energy burned
- Workouts
- Sleep analysis
- Heart rate and resting heart rate
- Heart rate variability
- Blood glucose (if you use a connected meter or CGM)
- Cycle data: menstrual flow, basal body temperature, ovulation test results, and cervical mucus quality
You choose which of these to grant, and the app works without any of them. When you log a weight inside Alure, we write a body mass sample back to HealthKit; when you log a period or cervical mucus entry in the cycle tracker, we write those back too, so the Health app’s history stays complete. You can revoke any of these permissions at any time in the Apple Settings app under Privacy & Security → Health.
Device and diagnostic information
The app records anonymous device side rate limit counters (e.g., daily meal scan limit) and may log crash diagnostics. We do not collect precise location.
How we use your information
- Provide and improve the Alure experience.
- Generate AI insights from summarized statistics of your recent weeks. Only aggregated metrics are sent to Google’s Gemini for this, never your raw logs or photos.
- Understand which features are used, through anonymous product analytics, so we can improve them.
- Schedule local meal reminders if you turn them on.
- Respond when you contact support.
- Detect and prevent abuse (e.g., rate limits on meal scans).
- Localize the app to your region, for example grocery prices in the savings calculator and seasonal food suggestions.
- Sign you into the PMOS Labs store and prefill checkout when you choose to open it from the app.
How we share your information
We do not sell or rent personal information. We share data only with service providers acting on our behalf:
- Supabase, Inc.: managed PostgreSQL, authentication, and Edge Functions hosting (US East).
- PowerSync, Inc.: sync engine between the device and our database.
- Apple Inc.: Sign in with Apple; App Store distribution; HealthKit (on device, never leaves your device through us).
- PostHog, Inc.: product analytics, hosted in the US. Receives anonymous usage events (screens viewed, features used, for example that a meal was scanned) tied to a random identifier. It never receives your name, email, photos, or the contents of your meals, symptoms, or cycle logs, and session recording is off.
- Google LLC: Gemini API for meal photo analysis and insight generation; Google sign in (if you choose it).
- Komoot Photon (OpenStreetMap): address autocomplete. As you type in the street address field, that text is sent to the Photon geocoding service to suggest completions. No name, email, or account identifier goes with it.
- PMOS Labs (pmoslabs.com): our companion store. Only when you tap a store link inside the app, we pass your email, name, and saved shipping details (if any) through a signed one time link so the store can sign you in and prefill checkout. The link expires within minutes and works once. Nothing is shared with the store until you choose to open it, and your health data (meals, symptoms, cycle, Apple Health) is never shared with the store.
Each provider acts on our written instructions and is permitted to use the data only to provide their service to us. We may disclose information if required by law.
Where data is stored
Account and profile data, meals, symptom logs, cycle logs, and weights are stored in encrypted PostgreSQL databases operated by Supabase in AWS US East. On your device, session tokens are stored in the iOS Keychain. Recent data is cached in an encrypted local SQLite database for offline use.
Retention
We retain your data for as long as your account is active. When you delete your account, we delete your profile, meal records, symptom logs, cycle logs, and weights from our active databases. Limited operational backups roll off within 30 days.
Your rights
- Access & correction: view and edit your profile from the Profile tab.
- Deletion: Profile → Delete Account removes your data from our servers.
- Apple Health control: revoke read or write permissions at any time in Apple’s Settings app.
- Notifications: turn meal reminders on or off in Profile → Settings.
Depending on your jurisdiction (e.g., California, EEA, UK) you may have additional rights to access, correct, port, or restrict processing of your data. Email support@alure.health to exercise those rights.
Children
Alure is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have, we will delete it.
Security
We use TLS for data in transit and encryption at rest with our database provider. No system is perfectly secure, but we take reasonable steps to protect your information.
Changes
If we materially change this Policy, we will update the effective date and, where appropriate, notify you in the app. Continued use after changes means you accept them.
Contact
17258526 Canada Ltd. Questions, requests, or complaints: support@alure.health.