Privacy Policy
Last updated: September 2026
This policy is written in plain English so you can actually read it. It describes what data Fundamental collects, where that data goes, and how you can take it back. We are still in private beta and recommend you have a lawyer review this document before relying on it for any regulated use case.
About this app
Fundamental is a seasonal wellness companion based in the science of Ayurveda. It helps you organise daily self-care practices, plan seasonal meals, log what you eat, and optionally share that information with a practitioner you are working with. It is not a medical application and does not provide medical advice or diagnosis.
What we collect
Account-required service
An account and sign-in are required to use Fundamental. We store the following through the service so it is available on devices where you sign in and to support optional practitioner sharing:
- Your email address (used for sign-in and account recovery)
- Your date of birth (used only to verify you meet the minimum age requirement)
- A securely hashed version of your password (we never store the password itself)
- Your first name and basic profile preferences (latitude, climate zone, terminology mode, account type)
- If you enable two-step verification, the secret used to verify your codes (stored on our server, access-controlled)
- Your in-app data — including practices, plans, recipes, grocery lists, meal journal, morning notes, daily health logs, cycle entries, and meal photos. This data is readable only by your account unless you explicitly enable practitioner sharing, and is deleted when you delete your account.
Your account content is server-authoritative: the authenticated service is the source of truth for your saved app data.
Technical state on your device
We keep only the technical local state needed to operate securely and reliably, such as encrypted sign-in tokens, session-lock settings, cached content, notification schedules, and temporary files. This state may be cleared when you sign out, delete your account, or uninstall the app.
If you join the public waitlist
If you sign up on our landing page, we store your name, email address, and the source you came from, so we can write to you when beta access is available. You can ask us to remove your waitlist entry at any time.
What we send to third parties
AI meal and recipe analysis (OpenAI)
When you use the camera or recipe analyser to evaluate a meal, the photograph or recipe text you submit is sent to OpenAI for processing. We send only the image or text you choose to analyse plus the season and climate context needed for the analysis. We do not send your name, email address, location coordinates, journal history, or account identifier to OpenAI.
OpenAI processes the request and returns the analysis, which is shown only to you and stored with your account. OpenAI's own data handling is governed by their API data policy, which states that data submitted via the API is not used to train their models by default.
If you do not use the meal or recipe analyser, no images or recipes are sent to any third party.
Practitioner sharing (opt-in, per category)
If you enter a practitioner sharing code and turn on sharing, the practitioner who issued the code can read the categories of data you have explicitly enabled. Today these categories are meal journal entries, morning notes, and cycle (menses) entries. Each category is off by default.
Turning sharing off, or revoking your sharing code from the Profile screen, immediately stops your practitioner from receiving any new data. Data the practitioner has already received is not automatically deleted from their copy of the app.
Location lookup
If you tap "Use my location," we ask the operating system for your coordinates and send them to OpenStreetMap's Nominatim service to look up the corresponding city name. Nominatim returns a city, state, and country and does not retain personal information about the request beyond standard server logs. Your coordinates are rounded to approximately 11 km precision before storage with your account so the app can serve the right seasonal guidance on every device. Full GPS precision is never retained.
Push notifications
Practice reminders, holiday alerts, and shopping reminders are scheduled as local notifications on your device. The app does not send notifications through our servers.
White-Label early access
White-Label early access is currently paused. If you register interest on our landing page, we store your email address, whether you selected Solo or Clinic, whether you would consider a pilot, the source you came from, and any optional practice size, approximate client count, desired capabilities, launch timeframe, or budget range you choose to provide. This records demand only; it does not start a purchase, create an entitlement, or guarantee pilot access. Please do not include health information. We never send your email or free-text answers to analytics, and you can ask us to remove the record at any time.
Email delivery (Resend)
If you request a password reset, we send the reset code to your email address through Resend, our email delivery provider. We send only your email address and the reset code. Resend processes the email solely to deliver it and is bound by their own data handling policy.
If you make a purchase (a paid subscription or an AI credit pack), we also send transactional emails about it through Resend: a decision on a refund you requested, and a notice when a refund issued by the App Store ends your paid access or removes purchased credits. These are service notices, not marketing — we do not send marketing email.
Product analytics (PostHog)
We use PostHog, a privacy-focused analytics provider, to understand how the landing page and the app are used so we can fix problems and prioritise improvements. We send a small, fixed list of named events (for example: landing page viewed, waitlist signup, White-Label early-access submission, account created, onboarding completed, weekly plan saved, meal logged) along with a random anonymous identifier and basic technical metadata. The White-Label event may include only the Solo/Clinic choice and whether pilot interest was selected — never the email or optional practice answers. Once you sign in, that anonymous identifier is linked to your account user id so we can count unique users, but never to your name, email, location, or anything you have logged.
We never send the contents of meals, photos, journal entries, cycle data, recipes, plans, or any free-text you write. If you would prefer to opt out of analytics entirely, open Profile in the app and turn off the "Share product analytics" toggle — the choice is honoured immediately on this device, both in the app and on this landing page. You can also email us at support@fundamental.lifestyle and we will exclude your account from future event ingestion as a fallback.
Payments
Paid subscriptions are billed through the platform's standard payment processor (Apple In-App Purchase on iOS), with RevenueCat acting on our behalf to manage subscription state. We receive only the subscription status and a store transaction/receipt identifier, never your card details. We keep a purchase audit trail (transaction identifiers and the credits or access they granted) so store refunds can be applied correctly.
Health information
Some of what you log in Fundamental, including meal photos, journal entries, and cycle data, is personal health information. We treat it accordingly:
- It is stored with your account so it is available on devices where you sign in (readable only by your account), unless you explicitly enable practitioner sharing for that category or use the meal analyser, which sends the meal photo or recipe to OpenAI for that one analysis.
- The contents of your health information (meal photos, journal entries, cycle data, free-text notes, location, herbs, recipes) are never sent to our analytics provider, and we do not sell, license, or share your health data with advertisers, data brokers, or insurers.
- The app is not a HIPAA-covered service and should not be used as the sole record for any condition under medical supervision.
How long we keep your data
- Minimal technical state on your device (such as encrypted session tokens and cached content) is kept only as needed to operate the app and may be cleared when you sign out, delete your account, or uninstall.
- Account data (email, hashed password, profile, and your account content) is kept until you delete your account from the Profile screen, after which it is removed from our active servers within 30 days. Backups are rotated out within 90 days. Two narrow records survive deletion: a security audit trail (account id, action, timestamp, and the IP address and browser/device "user agent" metadata recorded with each action — never the content of anything you logged; routine entries are deleted after 12 months, security events after 24 months) and purchase records needed to honour store refunds and meet financial record-keeping obligations.
- If you also operate a practitioner profile, records you authored about your clients and your clinic workspace data are professional records: deleting your personal account removes your name from the practitioner profile and unlinks it from your account, but client records are wound down through the separate practitioner off-boarding process, not personal deletion.
- Practitioner-shared data is retained for as long as you keep sharing enabled. Turning sharing off stops new data from being shared; you can also ask your practitioner to delete their copy.
- Waitlist and White-Label early-access entries are kept until you ask us to remove them or until 12 months after the relevant launch, whichever comes first.
- Meal photos and recipe text sent to OpenAI are not stored on our servers after the analysis returns. Brief diagnostic logs of API responses may be kept for short-term error monitoring and are rotated out of normal logging within days.
Your choices
- Create or sign in to the account required to use the app. The meal analyser sends your photo or recipe text to OpenAI only when you use it, and "Use my location" sends coordinates to OpenStreetMap only when you request a city lookup.
- Delete your account from the Profile screen at any time, which erases your server-side data (except the narrow audit and purchase records described above).
- Delete entries in the app and clear minimal technical local state by signing out or uninstalling.
- Turn off any optional feature (location, notifications, practitioner sharing, AI meal analysis) at any time from your Profile.
- Email us at support@fundamental.lifestyle to request a copy of your account data or to ask any question about how it is handled.
Children
You must be at least 16 years old to use Fundamental. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account, please contact us and we will remove it.
Security
We use industry-standard transport encryption (HTTPS) for all communication between the app and our servers. Account passwords are stored only as bcrypt hashes. Two-step verification is available from the Profile screen. No system is perfectly secure, so please use a strong, unique password and enable two-step verification if you are sharing data with a practitioner.
Changes to this policy
We will update this policy as the app evolves. Material changes will be communicated through the app and on this page. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
If you have any questions about this policy or how your data is handled, please write to support@fundamental.lifestyle.