WAS — Privacy Policy

Effective date: June 28, 2026 · Last updated: June 28, 2026

WAS (“WAS,” “the app,” “we,” “us”) is a consumer health and lifestyle transformation app built and owned by AEVUM LLC(“AEVUM”). This Privacy Policy explains what information the app collects, how we use it, who we share it with, and the choices and rights you have over your data. By creating an account or using WAS you agree to this Policy. If you do not agree, do not use the app.

WAS is not a medical device and does not provide medical advice. Plans, coaching messages, and any nutrition, training, glucose, or lab-related content are for general informational and educational purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider.

1. Who we are

AEVUM LLC is the data controller for information processed through WAS.

  • Company: AEVUM LLC
  • App: WAS (iOS / Android), bundle ID com.aevum.was
  • Privacy contact: dev@aevumos.io

2. Information we collect

We collect only what the app needs to deliver your transformation plan, log your food and training, and operate your account. You provide most of it directly; some is generated as you use the app.

2.1 Account information

  • Email address (used for authentication and account recovery).
  • Authentication identifiers managed by our auth provider.

2.2 Profile and onboarding

  • Body metrics you enter: height, age, sex, activity level, starting and current weight, goals.
  • Plan data we generate for you: calorie and macro targets, maintenance estimate, plan phase.
  • App settings and preferences, including notification settings, quiet hours, and timezone.

2.3 Health, fitness, and nutrition data you log

  • Food logs and saved meals (including items recognized from food photos and barcodes).
  • Workout routines and workout sessions (exercises, sets, reps, weights, progression).
  • Body metrics over time (weight and related measurements).
  • Progress photos you choose to upload.
  • Glucose readings and lab results, where you choose to enter them.
  • Refeed days, fasts, and carb-cycling schedules.

2.4 AI coach interactions

  • Messages exchanged with the in-app AI coach, and the plan/coaching content generated for you.

2.5 Photos and voice

  • Food and progress photos you capture or select. Food photos are sent to our AI vision provider to estimate nutrition; progress photos are stored privately for your own tracking.
  • Voice input (optional) is streamed to a speech-to-text provider to transcribe what you say.

2.6 Device and technical data

  • A push-notification token (so we can send the reminders and coach nudges you enable).
  • Standard technical data needed to operate and secure the service (e.g., app version, request logs, and error diagnostics).

2.7 Wearable / health-platform data (optional)

If you connect a wearable or health platform (e.g., Apple Health), we may import data such as weight, steps, or sleep. We only access what you authorize, and your manually entered data always takes precedence over imported data. You can disconnect at any time.

2.8 Subscription data

If you purchase a subscription, our payments/subscriptions provider processes your purchase and entitlement status. We never receive or store your full payment card details — those are handled by the app store and the payments provider.

We do not sell your personal information, and we do not use your health data for advertising.

3. How we use your information

  • Create and maintain your account.
  • Generate your personalized transformation plan and recompute targets as you progress.
  • Recognize food from photos and barcodes and estimate nutrition.
  • Log and display your food, workouts, body metrics, glucose, labs, and progress.
  • Power the AI coach and send the reminders and nudges you enable.
  • Operate, secure, debug, and improve the service.
  • Process subscriptions and manage premium access.
  • Comply with legal obligations.

Legal bases (where GDPR applies): performance of our contract with you (operating the app), your consent (e.g., optional wearable connections, voice input, and health data you choose to provide), our legitimate interests (security, debugging, product improvement), and compliance with legal obligations.

4. How your information is shared

We share data only with service providers (“subprocessors”) that help us run the app, and only to the extent needed to provide their function. These providers are bound to protect your data and to use it only on our instructions.

ProviderPurposeData shared
SupabaseDatabase, authentication, and file storageAccount, profile, and all logged app data (at rest); progress photos in a private bucket
RailwayAPI server hostingData in transit through our backend
OpenAIFood-photo nutrition recognition (vision)Food photos and barcode/label images you submit for analysis
Anthropic (Claude)AI coach, plan generation, food data reconciliationCoach messages and the plan/food context needed to respond
DeepgramVoice-to-text (only if you use voice input)Audio you speak into the app
RevenueCatSubscription managementPurchase and entitlement data
ExpoPush notificationsYour push token and notification content
Open Food Facts / USDA FoodData CentralPublic food-database lookupsBarcode numbers only — no personal data
Apple Health / wearables (optional)Importing health metrics you authorizeOnly the metrics you authorize

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users or AEVUM. If AEVUM is involved in a merger, acquisition, or asset sale, your information may be transferred subject to this Policy.

5. Data storage and security

  • Your data is stored in managed cloud infrastructure with access controls and row-level security so that you can only access your own records.
  • Progress photos are stored in a private bucket and served only via short-lived signed URLs — they are not publicly accessible.
  • All API keys and credentials are held server-side; the mobile app never holds privileged keys.
  • Data is encrypted in transit (HTTPS/TLS) and at rest by our infrastructure providers.

No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.

6. Data retention

We keep your information for as long as your account is active or as needed to provide the service. When you delete your account, we delete your personal data and stored files, except where we are required to retain certain records to comply with legal obligations. See Section 7.

7. Your rights and choices

You are in control of your data:

  • Access / export.You can export all of your data from within the app (Settings → Privacy & Data → Export My Data), which produces a complete copy of your records.
  • Deletion.You can delete your account and all associated data from within the app (Settings → Privacy & Data → Delete Account). This permanently removes your records and stored files, including progress photos.
  • Correction. You can edit your profile, logs, and settings directly in the app.
  • Notifications. You can turn reminders and coach nudges on or off, and set quiet hours, in Settings.
  • Wearable connections. You can connect or disconnect optional health-platform integrations at any time.

Depending on where you live, you may have additional rights under laws such as the GDPR (EU/UK) or CCPA/CPRA (California) — including the right to access, correct, delete, port, or restrict processing of your data, and to object to certain processing. We honor these rights for all users through the in-app export and deletion tools above. To make any other request, contact us at dev@aevumos.io. We will not discriminate against you for exercising your rights.

8. Children’s privacy

WAS is intended for adults (18+) and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at dev@aevumos.io and we will delete it.

9. International users

WAS is operated from the United States, and your information may be processed in the United States and other countries where our service providers operate. These countries may have data protection laws different from those in your country. Where required, we rely on appropriate safeguards for international transfers.

10. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app. Your continued use of WAS after changes take effect constitutes acceptance of the updated Policy.

11. Contact us

Questions, requests, or concerns about this Policy or your data:

AEVUM LLC
Email: dev@aevumos.io