1.Who this covers and who we are
Amaina is a voice-first migraine pattern tracker and doctor-visit-prep app operated by Smart IT US Inc., a company incorporated in Wyoming, United States.
- Mailing address: 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
- Privacy/legal contact: legal@smart-it.io
- Support: support@smart-it.io
- Product domain: amaina.health
In this document, "we," "us," and "our" mean Smart IT US Inc. doing business as Amaina. "Health app data" means data we read from or write to Apple HealthKit (on iOS) or Google Health Connect (on Android).
Platform scope. Amaina v1 ships on iOS only. Google Health Connect (Android) support exists in the codebase but is a planned later release. Throughout this notice, references to Health Connect / Android describe how the feature will behave on a future Android release, where available — they are not live v1 features.
Amaina is intended for adults 18 or older.
Amaina is a wellness tracker, not a medical device. It logs and organizes your own data to help you prepare for a doctor visit. Anything it shows you is an observation from your own data — never a diagnosis, prediction, risk score, or treatment recommendation. Your doctor draws the conclusions. See our Medical Disclaimer.
2.What health app data we READ
Only if you grant permission, and only for the categories you approve, Amaina reads the following from Apple HealthKit / Google Health Connect:
| Category | Why we read it |
|---|---|
| Sleep | To show retrospective correlations and Insights between your sleep and the headache episodes you have logged (for example, an observation that shorter sleep appeared before some of your logged episodes). |
| Menstrual cycle | To show cycle-linked correlations and Insights, since cycle phase is a commonly discussed factor to raise with a doctor. This is tracking a physiological factor — it is not a diagnosis. |
| Workouts / activity | To show retrospective activity-related correlations and Insights alongside your logged episodes. |
How we handle these readings:
- We request each category separately (granular permissions). You can grant sleep but not cycle, cycle but not workouts, or none at all.
- Raw readings are read transiently and processed on your device where possible. We do not store your raw HealthKit / Health Connect readings on our servers. When a correlation is saved so you can see it across devices, what we keep is tied to your headache episode log (for example, an episode with a linked factor) — not the raw sleep, cycle, or workout data from your health app.
- These features are optional. Amaina's core headache logging (by voice or by manual tap entry) works with no health app permissions at all.
3.What health app data we WRITE
Only if you grant write permission, Amaina writes the following to Apple HealthKit / Google Health Connect:
- Headache / migraine episodes you have logged in Amaina — so your health app holds a complete record and other apps you use can see your episodes if you allow them.
We only write the episode data you created in Amaina. We do not write anything else, and writing is optional and separately controllable.
4.What we use health app data for — and only for
We use HealthKit / Health Connect data only to provide features inside Amaina to you:
- Correlations — retrospective, descriptive views associating your logged episodes with factors like sleep, cycle phase, or activity. These are associations from your own data, not diagnoses, predictions, or recommendations.
- In-app Insights — the FREQUENCY / SLEEP / CYCLE / ACTIVITY / PROFILE cards. These are computed in the app by rule-based logic (not by any AI service) and are descriptive only.
The doctor summary may include HealthKit-derived content — but that content is never sent to our AI. The descriptive summary you can generate for your doctor is built from your own logged data and may include an Apple Health block and sleep / cycle / low-pressure correlations derived from that data. The important distinction is between what appears in the summary and what is sent to the AI: HealthKit-derived factors (for example, sleep-under-6h and menstrual-window triggers) are stripped from the AI request before any text is sent to Anthropic, so the AI never receives HealthKit / Health Connect data, raw or derived. You can generate a doctor summary from your logs and export or share it as a PDF (amaina-migraine-report.pdf), built on your device with no AI — or share it as text. That summary is a patient-generated health record — a communication tool for your appointment, not a clinical report, diagnosis, or prognosis.
We do not use HealthKit / Health Connect data for any purpose beyond delivering the in-app features above to you.
Important — how AI fits in. Amaina has two AI call sites, both to Anthropic (Claude) and both gated on your AI-logging consent: structuring your voice log into fields, and drafting the narrative for the doctor summary. Only the text of your logs is sent, and only if you turn on AI logging. We never send audio, your name, email, date of birth, or any HealthKit / Health Connect data — raw OR derived (sleep-under-6h and menstrual-window triggers are stripped from the AI request; only the transcript plus non-health context such as weather is sent). The tap / manual-entry path never uses AI, and the doctor summary has a static no-AI fallback. See the Privacy Policy and AI Processing Disclosure for details.
5.What we NEVER do with health app data (Apple 5.1.3)
This section mirrors Apple App Store Guideline 5.1.3. Health app data obtained through HealthKit or Health Connect is:
- (a) NEVER used for advertising or marketing. We do not use it for advertising or marketing purposes of any kind — ours or anyone else's — and it is never used for data-mining.
- (b) NEVER shared with or sold to third parties for advertising, marketing, or data-mining. We do not sell it and do not share it with any third party — including data brokers, advertising networks, or data-mining or analytics firms — for advertising, marketing, or data-mining. It is never disclosed to Meta, Google's advertising products, or any other ad platform.
- (c) NEVER used to build audiences. It is never used to create or enrich custom audiences, lookalike audiences, health-interest audiences, or any advertising or marketing segment.
In addition:
- We request only the permissions we actually use for the features described above, and each is granular.
- We do not use HealthKit / Health Connect data to make automated decisions that produce legal or similarly significant effects on you.
Our advertising pixels (Meta and Google) run only on the web funnel at amaina.health, are consent-gated, and measure aggregate conversions. Separately, the app itself includes a consent-gated product-analytics SDK (Amplitude) and crash diagnostics (Firebase Crashlytics) — see Section 8. No HealthKit data, no Health Connect data, no structured headache logs, and no AI outputs are ever sent to the web pixels, to Amplitude, to Crashlytics, or to any ad platform.
6.Your controls — granular and revocable
- Grant per category. iOS and Android show you each data type separately when Amaina first asks. You choose what to allow.
- Revoke any time. You can change or fully revoke Amaina's read/write access at any time:
- iOS: Settings › Health › Data Access & Devices › Amaina (or the Health app › Sharing).
- Android: Health Connect › App permissions › Amaina.
- Turning it off is safe. If you revoke access, the related correlations and Insights simply stop updating with new health app data. Core headache logging keeps working — Amaina never requires HealthKit or Health Connect to function.
- Delete on request. In-app account deletion is built in and available directly inside the app (Settings → Delete Account) — you never have to email us; see Account & Data Deletion. To delete data we hold in your Amaina account, use that in-app option, or email legal@smart-it.io if you prefer. (Revoking a permission in iOS/Android does not, by itself, delete data already saved to your Amaina account.)
7.Storage and retention
- Raw HealthKit / Health Connect readings are read transiently and processed on your device where possible. We do not store your raw sleep, cycle, or workout readings on our servers.
- Your headache episode log (including any barometric pressure recorded with an episode, and any factor linked to an episode) is saved to your Amaina account in Google Firebase / Firestore so you can see your history and correlations across sessions and devices. This is your own logged data — not the raw readings from your health app.
- We keep account data only as long as needed to provide the service or as required by law. When you delete your account, we delete or de-identify associated data within 30 days, except where we must keep something to meet a legal obligation.
Full retention details for all data categories are in the Privacy Policy.
8.Who can touch this data (subprocessors)
Health app data used to power your features is handled only by the service providers we rely on to run Amaina, each bound by contract to use data only as we instruct. Our subprocessors are: Anthropic (Claude), OpenWeatherMap, Google (Firebase Auth + Firestore + Crashlytics), Apple (Speech / HealthKit / App Store / In-App Purchase — Apple processes the subscription payment and your card; we never see or store card data), RevenueCat (subscription/entitlement management — receives only the purchase receipt, an app-assigned user id, and subscription status; no card data, no health data; RevenueCat also forwards these subscription-lifecycle events to Amplitude via a server-side integration keyed to the same anonymous Firebase UID, independent of the 'Usage analytics' opt-in — still carrying no card data and no health data), Amplitude (product analytics), Google — Firebase Crashlytics (crash diagnostics), and — on the web funnel only — HubSpot and Google/Meta advertising and analytics pixels.
- Amplitude (product analytics). Anonymous product-usage events only — screens and funnel steps (onboarding/activation, attack logging, report generation and sharing, paywall views); attack severity as a coarse bucket (low/moderate/high), medication as a yes/no, triggers as a count; use of the pain-location head-map recorded only as the input method (never a location value); and an elevated-weather banner recorded only as a pressure-change bucket — never raw or derived health data, log content, or AI output. Identified only by an anonymous internal user id (your Firebase UID), never your name or email. US data region. Behavioural product-usage events are collected only when you turn on 'Usage analytics' (off by default). Separately, subscription-lifecycle events (trial start, purchase, renewal, cancellation) are forwarded to Amplitude by our payment processor RevenueCat through a server-side integration, keyed to the same anonymous Firebase identifier. Because these are billing/contractual records, they are sent regardless of the 'Usage analytics' toggle; they contain no card data, no health data, no log content, and no AI output. No Session Replay; no advertising or cross-app tracking (no IDFA / no ATT). IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions), build 18 — so no IP or location is collected and Tracking = No does not depend on a console setting.
- Google — Firebase Crashlytics (crash diagnostics). Anonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity. On by default; turn it off under 'Crash diagnostics' in Settings → Privacy & consent.
To be explicit: no HealthKit or Health Connect data — raw or derived — is ever sent to Amplitude, Firebase Crashlytics, or the web-only advertising and analytics pixels. Amplitude receives behavioural telemetry plus the RevenueCat subscription-lifecycle events described above, and Crashlytics receives crash telemetry — in every case with no HealthKit / Health Connect data (raw or derived), no structured headache logs, and no AI output; that health app data supports only the in-app features described in Section 4.
9.Regional note — EEA / UK (secondary)
We do not currently target the EEA or UK; Amaina launches in the United States, and US law is primary. If that changes, the following would also apply:
- Health app data is special category data under the GDPR/UK GDPR. Our legal basis for using it would be your explicit consent (Article 9(2)(a)), asked for separately, and withdrawable at any time.
- Where a provider processes data outside the EEA/UK, we would rely on appropriate safeguards (for example, Standard Contractual Clauses).
For US residents, our handling of symptoms, medications, and related health data as consumer health data (Washington My Health My Data Act, Nevada SB 370) and as sensitive personal information (California CPRA), including opt-in consent and your rights, is covered in the Privacy Policy and Consumer Health Data notice.
10.Changes to this notice
If we change how we use HealthKit or Health Connect data, we'll update this notice, change the Effective Date above, keep it consistent with our Privacy Policy and App Store privacy answers, and — for material changes affecting how your health data is used — ask for your consent again where required.
11.Contact us
For any question about how Amaina uses your health app data:
- Email: legal@smart-it.io
- Support: support@smart-it.io
- Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
Written in plain English. If anything is unclear, email us at legal@smart-it.io and we'll explain.