Privacy Policy — Evity Club
Evity Club

Privacy Policy

Effective date: 2 July 2026

1. Who we are

Evity Club AB is the data controller for all personal data processed through the Evity Club iOS application and the website at evityclub.com.

Evity Club AB

Organisation number: 559355-0766

Sweden

Email: [email protected]

2. Data we collect and why

Account data

When you create an account we collect your email address and, optionally, your first name and organisation name. This data is used to authenticate you and provide the service.

Health and biometric data

We collect sleep, heart rate variability, and resting heart rate data from your connected wearable device. This data is used solely to calculate your Decision Readiness score and to generate usage patterns within the app. Providing this data is required to use the core features of the app. We collect it only with your explicit consent, which you provide during onboarding. You can withdraw this consent at any time in Settings, though doing so will prevent the app from calculating your score.

Health values are never included in error reports, analytics events, or any external service. Raw biometric values are never shared with third parties for advertising or any purpose other than providing the service.

Profiling

Evity Club uses your health data to calculate a personalised Decision Readiness score. This is a form of automated profiling. It does not produce any legal effect or similarly significant consequence. It is a personal wellness indicator intended to help you make more informed decisions about your day.

Journal and decision entries

Your reflection journal entries and decision log entries are encrypted on your device before being sent to our servers. The encryption key is stored only in your device's secure keychain. Evity Club cannot read the content of your entries. We store only the encrypted data, the date of each entry, and a snapshot of your score for that day.

Weekly planning entries

Notes you write during your weekly planning session are stored on our servers. They are not end-to-end encrypted.

Usage and analytics data

We collect pseudonymised usage data to understand how the app is used and to improve it. Examples include which features you open and whether you complete your weekly planning. No health values are ever included. You are identified only by a random identifier that cannot be directly linked to your name or email. You can opt out of analytics collection at any time in Settings.

Technical and error data

Our error monitoring service captures crash reports. All reports are scrubbed to remove health-related values before they leave your device. We do not send personally identifiable information in error reports.

3. Legal basis for processing

We process your data under the following legal bases:

  • Explicit consent (GDPR Article 9(2)(a)): health and biometric data. You can withdraw consent at any time in Settings without affecting prior processing.
  • Performance of a contract (GDPR Article 6(1)(b)): account data and subscription management, necessary to provide the service you signed up for.
  • Legitimate interests (GDPR Article 6(1)(f)): pseudonymised usage analytics and error monitoring, for the purpose of maintaining service reliability and improving the app. We have assessed that these interests are not overridden by your rights and freedoms. You have the right to object to this processing at any time via the opt-out in Settings.
  • Legal obligation (GDPR Article 6(1)(c)): data we are required to retain for accounting, tax, or other legal purposes.

4. Wearable integrations

WHOOP

When you connect a WHOOP device, you authorise Evity Club to read sleep, heart rate variability, and resting heart rate data from the WHOOP API. Your WHOOP credentials are never stored by Evity Club. We store only an access token in your device's secure keychain. If you disconnect your WHOOP or delete your account, we delete all daily metrics data sourced from WHOOP from our servers within 30 days. WHOOP's own privacy policy governs how WHOOP collects and processes data from your device: whoop.com/privacy. Evity Club is not affiliated with or endorsed by WHOOP.

Oura Ring

When you connect an Oura Ring, you authorise Evity Club to read sleep, heart rate variability, and resting heart rate data from the Oura API. Your Oura credentials are never stored by Evity Club. We store only an access token in your device's secure keychain. If you disconnect your Oura Ring or delete your account, we delete all daily metrics data sourced from Oura from our servers within 30 days. Oura's own privacy policy governs how Oura collects and processes data from your device: ouraring.com/privacy-policy. Evity Club is not affiliated with or endorsed by Oura.

Apple Watch (HealthKit)

When you connect Apple Watch, you grant Evity Club permission to read sleep and heart rate data from Apple HealthKit on your device. HealthKit data is never used for advertising and is never sold. Apple's own privacy policy governs how HealthKit data is managed on your device: apple.com/legal/privacy. Evity Club is not affiliated with or endorsed by Apple.

5. Data processors and third parties

We do not sell your personal data. We share it only with the following service providers, each bound by a data processing agreement:

  • Supabase: database and backend infrastructure. Supabase is a US-based company. Your data is stored on servers in Frankfurt, Germany (EU). Data transfers to Supabase are governed by Standard Contractual Clauses.
  • RevenueCat: subscription and purchase management. Location: United States. Transfer mechanism: EU-US Data Privacy Framework or Standard Contractual Clauses.
  • Stripe: payment processing. Location: United States and EU. Transfer mechanism: EU-US Data Privacy Framework or Standard Contractual Clauses.
  • PostHog: product analytics. Pseudonymised usage events only, no health values. Location: Frankfurt, Germany (EU).
  • Sentry: error monitoring. Crash reports only, health values scrubbed before transmission. Location: United States. Transfer mechanism: EU-US Data Privacy Framework or Standard Contractual Clauses.

We may also disclose personal data if required by law, court order, or to protect the legal rights and safety of Evity Club or its users.

6. International data transfers

Our primary database is hosted in Frankfurt, Germany, within the EU. Some third-party processors are based in the United States. Where we transfer data outside the EU we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) approved by the European Commission, depending on which safeguard the processor participates in, to ensure adequate protection of your data.

7. Data retention

We retain your data for as long as your account is active. On account deletion:

  • Health and biometric data is deleted within 30 days.
  • Journal and decision entries (encrypted) are deleted within 30 days.
  • WHOOP and Oura Ring data is deleted within 30 days of disconnection or account deletion.
  • Account data is deleted within 30 days.
  • Pseudonymised analytics data may be retained for up to 12 months.

Some data may be retained longer where we have a legal obligation to do so, for example for accounting or tax purposes.

You can delete your account at any time from Settings, or by emailing [email protected].

8. Your rights

Under GDPR you have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data.
  • Right to restriction: ask us to limit processing of your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests, including analytics. You can do this at any time via the opt-out in Settings or by contacting us.
  • Right to withdraw consent: withdraw your health data consent at any time in Settings. Withdrawal does not affect prior processing.
  • Right to lodge a complaint: you can contact the Swedish Authority for Privacy Protection (IMY) at imy.se, or the supervisory authority in the EU member state where you live or work.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

9. Children

Evity Club is not intended for anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has created an account, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you by email or by a notice inside the app before the changes take effect. If any changes require your explicit consent under data protection law, for example changes to how we process your health data, we will ask for your consent at that time rather than relying on prior acceptance.

11. Contact

Evity Club AB

Organisation number: 559355-0766

Sweden

Email: [email protected]