Privacy Policy

Last updated: September 2026

This policy is written in plain English so you can actually read it. It describes what data Fundamental collects, where that data goes, and how you can take it back. We are still in private beta and recommend you have a lawyer review this document before relying on it for any regulated use case.

About this app

Fundamental is a seasonal wellness companion based in the science of Ayurveda. It helps you organise daily self-care practices, plan seasonal meals, log what you eat, and optionally share that information with a practitioner you are working with. It is not a medical application and does not provide medical advice or diagnosis.

What we collect

Account-required service

An account and sign-in are required to use Fundamental. We store the following through the service so it is available on devices where you sign in and to support optional practitioner sharing:

Your account content is server-authoritative: the authenticated service is the source of truth for your saved app data.

Technical state on your device

We keep only the technical local state needed to operate securely and reliably, such as encrypted sign-in tokens, session-lock settings, cached content, notification schedules, and temporary files. This state may be cleared when you sign out, delete your account, or uninstall the app.

If you join the public waitlist

If you sign up on our landing page, we store your name, email address, and the source you came from, so we can write to you when beta access is available. You can ask us to remove your waitlist entry at any time.

What we send to third parties

AI meal and recipe analysis (OpenAI)

When you use the camera or recipe analyser to evaluate a meal, the photograph or recipe text you submit is sent to OpenAI for processing. We send only the image or text you choose to analyse plus the season and climate context needed for the analysis. We do not send your name, email address, location coordinates, journal history, or account identifier to OpenAI.

OpenAI processes the request and returns the analysis, which is shown only to you and stored with your account. OpenAI's own data handling is governed by their API data policy, which states that data submitted via the API is not used to train their models by default.

If you do not use the meal or recipe analyser, no images or recipes are sent to any third party.

Practitioner sharing (opt-in, per category)

If you enter a practitioner sharing code and turn on sharing, the practitioner who issued the code can read the categories of data you have explicitly enabled. Today these categories are meal journal entries, morning notes, and cycle (menses) entries. Each category is off by default.

Turning sharing off, or revoking your sharing code from the Profile screen, immediately stops your practitioner from receiving any new data. Data the practitioner has already received is not automatically deleted from their copy of the app.

Location lookup

If you tap "Use my location," we ask the operating system for your coordinates and send them to OpenStreetMap's Nominatim service to look up the corresponding city name. Nominatim returns a city, state, and country and does not retain personal information about the request beyond standard server logs. Your coordinates are rounded to approximately 11 km precision before storage with your account so the app can serve the right seasonal guidance on every device. Full GPS precision is never retained.

Push notifications

Practice reminders, holiday alerts, and shopping reminders are scheduled as local notifications on your device. The app does not send notifications through our servers.

White-Label early access

White-Label early access is currently paused. If you register interest on our landing page, we store your email address, whether you selected Solo or Clinic, whether you would consider a pilot, the source you came from, and any optional practice size, approximate client count, desired capabilities, launch timeframe, or budget range you choose to provide. This records demand only; it does not start a purchase, create an entitlement, or guarantee pilot access. Please do not include health information. We never send your email or free-text answers to analytics, and you can ask us to remove the record at any time.

Email delivery (Resend)

If you request a password reset, we send the reset code to your email address through Resend, our email delivery provider. We send only your email address and the reset code. Resend processes the email solely to deliver it and is bound by their own data handling policy.

If you make a purchase (a paid subscription or an AI credit pack), we also send transactional emails about it through Resend: a decision on a refund you requested, and a notice when a refund issued by the App Store ends your paid access or removes purchased credits. These are service notices, not marketing — we do not send marketing email.

Product analytics (PostHog)

We use PostHog, a privacy-focused analytics provider, to understand how the landing page and the app are used so we can fix problems and prioritise improvements. We send a small, fixed list of named events (for example: landing page viewed, waitlist signup, White-Label early-access submission, account created, onboarding completed, weekly plan saved, meal logged) along with a random anonymous identifier and basic technical metadata. The White-Label event may include only the Solo/Clinic choice and whether pilot interest was selected — never the email or optional practice answers. Once you sign in, that anonymous identifier is linked to your account user id so we can count unique users, but never to your name, email, location, or anything you have logged.

We never send the contents of meals, photos, journal entries, cycle data, recipes, plans, or any free-text you write. If you would prefer to opt out of analytics entirely, open Profile in the app and turn off the "Share product analytics" toggle — the choice is honoured immediately on this device, both in the app and on this landing page. You can also email us at support@fundamental.lifestyle and we will exclude your account from future event ingestion as a fallback.

Payments

Paid subscriptions are billed through the platform's standard payment processor (Apple In-App Purchase on iOS), with RevenueCat acting on our behalf to manage subscription state. We receive only the subscription status and a store transaction/receipt identifier, never your card details. We keep a purchase audit trail (transaction identifiers and the credits or access they granted) so store refunds can be applied correctly.

Health information

Some of what you log in Fundamental, including meal photos, journal entries, and cycle data, is personal health information. We treat it accordingly:

How long we keep your data

Your choices

Children

You must be at least 16 years old to use Fundamental. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has created an account, please contact us and we will remove it.

Security

We use industry-standard transport encryption (HTTPS) for all communication between the app and our servers. Account passwords are stored only as bcrypt hashes. Two-step verification is available from the Profile screen. No system is perfectly secure, so please use a strong, unique password and enable two-step verification if you are sharing data with a practitioner.

Changes to this policy

We will update this policy as the app evolves. Material changes will be communicated through the app and on this page. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact

If you have any questions about this policy or how your data is handled, please write to support@fundamental.lifestyle.