Skip to legal content

Enphana Privacy Policy

Effective date: August 17, 2026 Last updated: August 17, 2026

Enphana is a local-first wellness tracking app operated by Colyden LLC ("Enphana," "we," "us," or "our"). This Privacy Policy explains how we handle information when you use the Enphana mobile app (the "App").

Privacy contact: privacy@colyden.com

1. The short version

Your wellness entries are designed to remain on your device. The App may offer an optional Enphana account for Premium identity and cross-device subscription restoration, but it does not upload or sync your wellness entries to an Enphana cloud service in the current release.

We do not sell health or wellness information, use it for advertising, or share it for cross-context behavioral advertising. Optional health-platform imports occur only after you choose to connect Apple Health or Health Connect and grant the applicable read permission. Purchases are administered by the applicable app store and RevenueCat.

For details about health-data handling and rights, read the separate Consumer Health Data Privacy Policy.

2. Information the App handles

Information you enter or create

Depending on how you use the App, this can include:

This information may reveal health, fitness, dietary, or other sensitive information. Treat it carefully.

Optional connected-health information

If you choose to connect Apple Health (iOS) or Health Connect (Android) and grant the relevant read permissions, the App can import:

The current App imports this information into local storage on your device. It does not write information to Apple Health or Health Connect, and it does not upload imported health information to Supabase, RevenueCat, Apple, Google, or an Enphana cloud service. You can decline, revoke, or manage these permissions through your device settings and the connected-app settings in Enphana.

Apple and Google independently operate their health platforms. Their handling of information is governed by their own terms and privacy policies.

Optional Enphana account

If you choose to start Premium, the App may ask for your email address and send a one-time verification code through Supabase Auth. Supabase processes the account identity, email address, authentication/session data, and security metadata needed to sign you in. The App uses the resulting account identifier with RevenueCat to associate subscription entitlements across supported platforms. The App does not upload your local wellness entries, health imports, or free-text notes to Supabase.

Camera, meal photos, and gallery selection

You may allow camera access to scan a food barcode or take an optional photo for a meal or recipe. You may also choose an existing photo from your device's photo library. Enphana stores or references the selected photo locally on your device with the associated meal or recipe; it does not upload those photos to an Enphana cloud service in the current release. Removing a photo from a meal or recipe removes Enphana's local reference to it, but does not delete the original from your device's photo library. Manage camera and photo-library access through your device settings.

Subscription and purchase information

Apple App Store or Google Play processes purchases, not Enphana. The App uses RevenueCat to obtain subscription entitlement and offering information. We do not receive your full payment-card number. RevenueCat and the applicable app store may process device, transaction, subscription-status, and technical information under their own privacy terms.

Information we do not intentionally collect through the current App

The App does not require an account for ordinary local use. It does not include third-party advertising SDKs or third-party behavioral analytics in the current release. It does not send your meal entries, reflections, health imports, or free-text notes to an Enphana cloud service.

3. Where information is stored and how long it remains

Your App content is stored locally on your device, primarily in the App's local database and local app storage. It remains there until you edit or delete it, reset local data, uninstall the App, or your device/platform removes it.

The App may create local recovery backups before certain resets, restores, or database migrations. It keeps recent automatic recovery backups locally and lets you create and delete manual backups. Resetting active local data can create a recovery backup; to remove that copy, use Settings → Local Backups and delete it. A data export is a JSON file stored locally and may be shared only when you choose to do so. Enphana does not add its own encryption to exports or local backups, so protect them carefully.

Optional account identity and authentication data remain in Supabase while your account is active. When you delete an account, we delete the account identity and authentication data that we control, unless a limited record must be kept to meet a legal obligation, resolve a security issue, or enforce our rights. Apple, Google, and RevenueCat maintain their own purchase or entitlement records under their respective policies. See the Data Deletion Policy for practical instructions.

Deleting a discovery topic may first place it in a recoverable state for up to 30 days. Other delete or reset actions may be permanent, subject to the local recovery-backup behavior described above.

4. How we use information

The App uses your information to:

We do not use health or wellness information for advertising, marketing profiling, or sale to data brokers.

5. When information is disclosed

We do not disclose your locally stored health and wellness entries to an Enphana server in the current App. Information can leave your device only in these limited situations:

6. Your choices and privacy rights

You can choose whether to grant camera, Apple Health, or Health Connect permissions; manage or revoke permissions in device settings; export selected App content from Settings → Export Data; delete active App content from Settings → Reset Local Data; delete local recovery backups from Settings → Local Backups; and manage or cancel a subscription through the applicable app store.

You can create, use, sign out of, or delete an optional Enphana account from the App. Account deletion does not cancel an App Store or Google Play subscription; use the store's subscription controls separately.

Because Enphana does not maintain a cloud copy of App content in the current release, we generally cannot retrieve, correct, export, or delete your on-device entries for you. You control those entries directly through the App. If an applicable privacy law gives you rights to access, delete, correct, limit, or object to processing of information we control, email privacy@colyden.com. We may need to verify your request. We aim to respond within 45 days; if we need an extension permitted by law, we will notify you and explain why.

If we deny a privacy request, you may appeal by replying to our decision with the subject line Privacy Appeal. We will review the appeal and explain our decision. This Policy does not limit rights that cannot be waived under applicable law.

7. Security

We design the App to minimize data transfer by storing core content locally. No method of electronic storage or transmission is completely secure. Keep your device protected with a passcode or biometric lock, use care when exporting or sharing data, and delete exports and backups you no longer need.

If you believe there is a vulnerability or unauthorized access involving Enphana, contact privacy@colyden.com promptly. Do not include passwords, one-time codes, payment-card numbers, or sensitive health entries in an initial report.

8. Children

Enphana is a general-audience app and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information through the App, we will delete it. If you believe this has happened, contact privacy@colyden.com.

9. Changes to this Policy

We may update this Policy to reflect changes to the App, law, or our practices. We will post the revised Policy with a new effective date and provide additional notice when required by law. If Enphana adds cloud sync, analytics, advertising, new integrations, a new category of health data, or a new use of health data, we will update this Policy and, where required, provide notice or obtain consent before the change.