Here's the short version of how Amaina handles your data. The rest of this policy fills in the details.

If you want the full details, read on.

1.Who we are

Amaina is operated by Smart IT US Inc., a corporation incorporated in Wyoming, United States.

Our mailing address is: 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA

For any privacy question, request, or concern, reach us at legal@smart-it.io. For product help, use support@smart-it.io.

In this Privacy Policy, "we," "us," and "our" mean Smart IT US Inc. doing business as Amaina. "You" means anyone who uses the Amaina iOS app or visits amaina.health.

This policy covers both the Amaina iOS app and the amaina.health website. The website presents marketing/legal information and an optional onboarding questionnaire — a few migraine-related (health) questions we collect only with your opt-in consent, governed by a separate, consent-first Health Questionnaire Privacy Notice (which controls for the questionnaire) — plus an optional step to give your name/email to save your personalized summary. The website links to the App Store; you subscribe inside the app through Apple, not on the website.

2.What we collect

We collect the following categories of information. Some are needed to run the core app; anything beyond that is collected only with your permission.

Account information

You sign in using Sign in with Apple, Sign in with Google, or email, handled by Firebase Authentication.

Health data you log

When you use the app, you create a personal migraine log. This can include:

This is sensitive health information. Depending on where you live it is treated as "consumer health data," "sensitive personal information," and/or "special category data" under the relevant laws (see Section 5 and the Regional Addenda). We collect it to provide the app to you, and we never use it for advertising.

Health data read from Apple Health (Google Health Connect on a future Android release)

Amaina v1 ships on iOS only. Google Health Connect exists in our codebase but is a planned later Android release; the description below applies to Apple Health today and to Health Connect where available on a future Android release.

If you grant permission — always granular, feature by feature — the app can:

Raw health readings (Apple Health today; Health Connect where available on a future Android release) are processed on your device and are not retained by us beyond what's needed to compute a result; the attack log you save (including any recorded barometric pressure) is stored in your account. We follow Apple's HealthKit rules: HealthKit data is never used for advertising, marketing, or data-mining and is never shared with third parties for those purposes. See HealthKit Data Use for the details.

Voice input — text only, never audio

When you log by voice, the app uses your device's built-in speech feature (Apple Speech) to turn your speech into text. Depending on your device, language, and settings, Apple may transcribe on-device or on Apple's servers — that step happens between you and Apple.

We (and our AI subprocessor) only ever receive the resulting text — never the audio recording. The free text you dictate or type is what gets structured into fields (with your consent — see Section 4). A structured tap-to-log form is always available as an alternative and works with no AI at all. See Section 4 and the AI Processing Disclosure.

Location and weather

If you enable the weather feature, the app uses your location while you are using the app ("when-in-use") to fetch barometric pressure and a short forecast from OpenWeatherMap. Amaina reads local barometric pressure and a 5-day forecast (in 3-hour steps). Two things are shown from it. On the home screen, when a fall of about 6 hPa or more is forecast for the next ~24 hours, you see a "Pressure dropping today" note. In the weather view, the pressure chart is colour-coded by how fast pressure is forecast to fall — green "Steady", amber "Falling", red "Falling fast" (about 3 hPa and about 6 hPa over 24 hours, following Kimoto et al., 2011, which is cited in the app). Humidity and temperature are charted without any colour classification, because we have no cited thresholds for them. All of this is a general weather signal on a one-size-for-everyone threshold — not personalized to your health history and not a prediction of your personal risk. The "your history" figure (share of your logged attacks at low pressure) is a descriptive look-back.

Your coordinates are not stored on our servers, are not used for tracking or advertising, and are shared with OpenWeatherMap only to fetch that weather data. The barometric pressure value can be saved with the relevant attack in your log, and the app also keeps a short rolling record of the daily pressure, temperature and humidity where you are (about two weeks) — weather readings only, never your coordinates — so an attack you log after the fact can still show the weather for the day it happened, and so you can see the days leading up to it.

Payment and subscription information

You buy your subscription inside the app as an Apple In-App Purchase, using StoreKit and managed with RevenueCat. Apple processes the transaction and handles your card — we never see or store your card number. Our subprocessor RevenueCat receives the purchase receipt, an app-assigned user identifier, and your subscription/entitlement status (no card data, no health data) so we can validate the purchase and unlock the paid features for your account. RevenueCat also forwards subscription-lifecycle events (trial started, purchase, renewal, cancellation) to our analytics processor Amplitude through a server-side integration, keyed to the same anonymous identifier, as billing/contractual data (no card data, no health data). This flow is not controlled by the Usage-analytics toggle.

Your subscription automatically renews at the then-current price unless auto-renew is turned off at least 24 hours before the end of the current period; payment is charged to your Apple ID at confirmation of purchase. You manage or cancel in Settings → your Apple ID → Subscriptions (or App Store → your account → Subscriptions). Refunds are handled by Apple (Report a Problem / Apple Support) — we cannot directly refund an App Store purchase.

In-app usage analytics and crash diagnostics

The app includes two in-app SDKs that collect non-health technical data. Neither ever receives raw or derived health data, log content, or AI output, and neither is used for advertising:

Web device, usage, and cookie data

When you visit amaina.health we automatically collect standard technical data:

We use this to run and improve the site, measure marketing, and prevent fraud and abuse.

3.How we use your information

We use your information to:

We do not use your information for automated decisions that produce legal or similarly significant effects about you. We do not use your health data, Apple Health data, structured logs, or AI outputs to build advertising audiences, and we do not sell them.

A note on what Amaina's outputs are. Everything Amaina shows you — Insight cards, patterns, your own medication-days count, the weather view, medication-effectiveness views, and the doctor summary — reflects your own logged data. Your report keeps a count of your own acute-medication days drawn from what you logged — a descriptive record of your own data. Separately, a general educational note references the guidance that using acute medication on roughly 10–15 or more days a month is worth discussing with your doctor — presented as a neutral, general educational note, not juxtaposed with your personal count and not attached to it as a "medication-overuse-headache risk" label. It is a descriptive record plus separate general education — not a personalized calculation, not a risk assessment, and not dosing advice. The weather view includes a forward-looking, general element: a 5-day pressure chart colour-coded by how fast pressure is forecast to fall (green "Steady" / amber "Falling" / red "Falling fast", at about 3 and about 6 hPa over 24 hours), plus a home-screen "Pressure dropping today" note on a forecast fall of about 6 hPa or more. Colours describe the weather, not you — the thresholds are the same for everyone, so this is not personalized to your history and not a prediction of your personal risk; humidity and temperature carry no colour coding at all. It sits alongside a separate descriptive "your history" look-back at pressure and your attacks. Medication-effectiveness views are retrospective displays only and never influence your dose or drug choice. Your doctor interprets what any of it means.

4.How we use AI

Some features use a third-party AI service:

  1. Structuring the free text you dictate or type. When you describe an attack in your own words — the text your device produced from your speech, or free text you type — that text is sent from the app to our own backend server, which forwards it to Anthropic's Claude (Messages API) to organize it into fields (time, intensity, duration, symptoms, aura, medication, triggers). This happens only after you consent. If you decline (or turn AI off), you log with the structured tap-to-log form instead — you pick times, intensity, symptoms, and medications from the app's own controls, which are saved directly with no AI.
  2. The doctor summary. When you generate a summary for your doctor, we send your own logged record — the number of attacks in the period, your average severity, your ranked triggers (with Apple Health-derived ones such as sleep-under-6h and menstrual-window stripped out before sending), and your medications with how well they helped — and Claude drafts a descriptive narrative from it (frequency, clustering, severity trend, changes in what you've recorded). This is a live, consent-gated Claude call site; the report also has a static, no-AI fallback. It is descriptive only — never a diagnosis, prognosis, or treatment recommendation.

In build 1.0.0(22) there are exactly two Claude call sites, both live and both gated on your AI consent: (1) structuring your voice/typed log into fields, and (2) drafting the doctor-visit summary narrative (with a static, no-AI fallback for the report). The tap / manual path never uses AI. The AI Processing Disclosure is the authoritative, feature-by-feature description; this policy, the disclosure, the in-app consent screen, and the App Privacy labels are all kept in sync with what ships.

In-app Insights (Frequency, Sleep, Cycle, Activity, Profile) are computed on your device by rule-based logic — they do NOT use AI. The structured tap-to-log form does not use AI either, so you can log fully without it.

Key safeguards for the AI processing:

Full detail — including exactly what is sent, what isn't, and how to opt out — is in the AI Processing Disclosure.

5.How we handle health data

Your migraine logs, symptoms, and the medications you enter are health data, and we treat them accordingly. Separately, the amaina.health onboarding questionnaire collects a few migraine-related answers only with your opt-in consent (an unchecked box before the first health question), under a dedicated, consent-first Health Questionnaire Privacy Notice that controls for the questionnaire.

You can generate a doctor summary from your logs and export or share it as a PDF (amaina-migraine-report.pdf), built on your device with no AI — or share it as text. (The no-AI static-fallback summary can be exported as this same PDF, so the no-AI path still yields a real doctor PDF.) This is separate from the "Export my data" feature, which now offers a choice: a Doctor report (PDF) built on your device with no AI, or Raw data (JSON) of your profile, medications, and attacks for data portability. The doctor summary is a patient-generated health record — a communication tool to bring to your doctor — not a clinical report or diagnosis.

6.Subprocessors

We share your information with a small set of trusted service providers ("subprocessors") who help us run Amaina. Each is bound by contract to use your data only for the purposes we specify. This table is a summary; the authoritative, always-current list is the Subprocessor List, and the two must match.

SubprocessorUsed forData it can receive
Anthropic (Claude)Structuring your entries; generating the descriptive doctor summaryThe text of your logs (never audio); no health identifiers in field names
OpenWeatherMapBarometric pressure + short forecast for the weather viewApproximate location — reduced accuracy, when-in-use (coordinates, not stored by us)
Google (Firebase Authentication + Firestore + Crashlytics)Login and account/data storage; crash diagnosticsAccount info and your attack logs (Auth + Firestore); Crashlytics is listed separately below
Amplitude (product analytics)Anonymous in-app behaviour/usage analyticsAnonymous behaviour/usage events (the authoritative, always-current list is ANALYTICS_EVENTS.md) — never raw or derived health data, log content, or AI output. Identified only by an anonymous internal user id (your Firebase UID), never your name or email. US data region. Behaviour/usage events are collected only when "Usage analytics" is on (off by default); no Session Replay; no advertising or cross-app tracking (no IDFA / no ATT). Plus subscription-lifecycle events (trial / purchase / renewal / cancellation) forwarded server-side by RevenueCat, keyed to the same anonymous Firebase UID, sent as billing/contractual data regardless of the Usage-analytics toggle (no card data, no health data)
Google — Firebase Crashlytics (crash diagnostics)Anonymous crash reports to fix bugsAnonymous crash reports (stack traces, device/OS) — never health data, and not linked to your identity. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent
Apple (Speech, HealthKit, App Store, In-App Purchase)On-device/OS speech-to-text; Apple Health read/write; app distribution; subscription paymentSpeech is handled by Apple's OS; HealthKit data per your granular permissions; the payment/card is handled by Apple (we never receive it)
RevenueCatSubscription/entitlement management for the in-app Apple purchasePurchase receipt, app user id, and subscription status — no card data, no health data. RevenueCat also forwards these subscription-lifecycle events to Amplitude (analytics) via a server-side integration, keyed to the same anonymous identifier; not controlled by the Usage-analytics toggle
HubSpot (web only)Email/CRM for waitlist and product communicationsName, email, marketing-engagement data
Google / Meta advertising & analytics pixels (web only)Aggregate conversion measurement and site analyticsWeb usage, IP, device info — never health data (see Section 7)

We may also disclose information if required by law (e.g., subpoena or court order), to protect our rights and safety (fraud, abuse, or harm), or in a business transfer (merger, acquisition, or sale of assets — you'll be notified). We do not sell your personal information for money.

7.Advertising and cookies

Advertising happens only on the web funnel — never inside the app.

On amaina.health we use Meta and Google pixels for aggregate conversion measurement and site analytics, and only when you've consented via our cookie banner. See our Cookie Policy for the full list of cookies and how to manage them.

The app does run two in-app SDKs — Amplitude (product-usage analytics) and Firebase Crashlytics (crash diagnostics) — but these are not advertising: Amplitude is classified as Analytics, not Tracking (no IDFA, no ATT prompt, no cross-app tracking, no Session Replay), and Crashlytics is anonymous crash data. Neither receives health data. See Section 2 for what each collects and how to control it.

We never:

We honor the Global Privacy Control (GPC): if your browser sends a GPC signal, we treat it as a valid opt-out of "sale"/"sharing" for advertising for that browser. See Section 8 and the Regional Addenda.

8.Your US privacy rights

Wherever you live in the US, you can ask us to:

To make a request, email legal@smart-it.io, or use the in-app and in-account controls. We may need to verify your identity first. We do not discriminate against you for exercising these rights.

Your in-app consent controls. Two consents are mandatory to use the app — confirming you are 18 or older and consenting to health-data processing. The rest are optional and each is recorded as an audit event: AI logging (opt-in, asked once before any AI use), Product emails (opt-in, off by default), Usage analytics (opt-in, off by default — gates the Amplitude behaviour/usage events; note that subscription-lifecycle billing events still reach Amplitude via a server-side RevenueCat integration, which this toggle does not control), and Crash diagnostics (on by default / opt-out — gates Firebase Crashlytics). You can change or withdraw these last four anytime in Settings → "Privacy & consent", which has four toggles: AI logging · Product emails · Usage analytics · Crash diagnostics.

Some states give you extra protections. In particular:

Full state-by-state detail — including the California notice-at-collection and the Washington consumer-health-data section — is in the Regional Addenda.

HIPAA note. Amaina is a direct-to-consumer wellness app, not a HIPAA covered entity or business associate. We do not claim HIPAA compliance and HIPAA does not apply. Separately, we comply with the FTC Health Breach Notification Rule — see Section 12.

9.Account and data deletion

You can delete your Amaina account and associated data:

When you delete your account, we remove your personal data from our active systems, and instruct our subprocessors to do the same, within 30 days, except where we must keep certain records to meet a legal obligation. Note that headache episodes the app wrote to your Apple Health (or Health Connect on a future Android release) stay in your device's health store until you remove them there. Deleting your Amaina account does not cancel your App Store subscription — you must cancel that separately in Settings → your Apple ID → Subscriptions. For the full walkthrough, see Account & Data Deletion.

10.How long we keep your information

We keep information only as long as we need it for the purposes above:

11.Adults only (18+)

Amaina is intended for adults 18 years of age or older. We do not knowingly collect information from anyone under 18. By using Amaina you confirm you are 18 or older. If you believe someone under 18 has given us their information, email legal@smart-it.io and we'll delete it.

12.Security and breach notification

We protect your information with industry-standard safeguards — encryption in transit (HTTPS/TLS) and at rest where applicable, authenticated access, least-privilege internal access, and security reviews of our subprocessors. No system is 100% secure, but we work to keep your data as safe as reasonably possible.

If a breach of your health data occurs, we comply with the FTC Health Breach Notification Rule: we will notify affected users and the FTC within 60 days, and provide media notice if 500 or more residents of a state are affected.

13.International transfers

We are based in the United States (Wyoming), and we process your data in the United States. Our subprocessors may process data in the United States and, in some cases, other countries; where they do, appropriate safeguards apply.

EEA/UK (secondary). We do not currently target the EEA or the UK, and Amaina is offered to US users at launch. If that changes, the following would apply: for transfers involving EEA or UK residents, we would rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), and health data would be handled as special category data under GDPR Article 9 (explicit consent). See the Regional Addenda. Copies of safeguards are available at legal@smart-it.io.

14.Changes to this policy

We may update this Privacy Policy from time to time. When we do, we'll change the Effective Date above and, for material changes, notify you in the app or by email. The current version is always available at amaina.health/privacy and in the app.

15.Contact us

For any privacy question, request, or concern:

Email: legal@smart-it.io Support: support@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA

Regional privacy addenda (US)

  • US law is primary. Amaina launches US-only. We call out California, Washington, and Nevada rights below. EU/UK is included only as clearly-flagged secondary — we do not currently target the EEA/UK.
  • Your health data is treated as sensitive everywhere. Your migraine logs, symptoms, medications, and related answers get the strongest protection we offer, in every state.
  • We do not sell your personal information, and we never share your health data for cross-context advertising. Health data, HealthKit/Health Connect data, structured logs, and AI outputs are never sent to ad platforms or used to build ad audiences.
  • California: rights to know, access, delete, correct, limit use of sensitive PI, and opt out — we honor Global Privacy Control (GPC). 45-day response.
  • Washington (MHMDA): we get your opt-in consent to collect your consumer health data and a separate opt-in consent to share it; no sale without your written authorization. Applies to any Washington resident.
  • Nevada (SB 370): similar consumer-health-data protections; same request path.
  • If a breach of your health data occurs, we follow the FTC Health Breach Notification Rule (see Privacy Policy §12): notice to affected users and the FTC within 60 days, and media notice if 500 or more residents of a state are affected.
  • How to make a request (any state): email legal@smart-it.io, or delete your account in-app (Settings → Delete Account). We verify it's you before acting.

California — CPRA / CCPA

If you live in California, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you rights about your personal information. This section covers the Amaina iOS app and your account. Advertising and analytics on our marketing website are covered in our website Cookie Policy.

1.1 Categories of personal information we collect for the app

Amaina is pre-launch, so this describes the categories we collect when you use Amaina (not a past 12-month collection history):

CategoryExamplesSourcePurposeDisclosed to
IdentifiersFirst name, email address, internal account/user ID (we do not collect the IDFA advertising identifier)Directly from you; created at sign-up (Firebase Auth via Sign in with Apple / Google / email)Create and secure your account, sign you in, contact you about the serviceGoogle (Firebase Auth + Firestore)
Health / sensitive personal informationMigraine logs (time, intensity, duration, symptoms, aura), medications and effectiveness, triggers, date of birth (for age-context insights), and — only with your granular permission — sleep, menstrual-cycle, and workout data read from Apple Health (and, on a future Android release, Google Health Connect), plus barometric pressure recorded with your attack logDirectly from you (voice or manual entry); read from Apple Health (Health Connect on a future Android release) with your permissionLog and organize your own data; generate a descriptive, patient-generated summary you can share with your doctor (not a clinical report or diagnosis); power in-app Insights; save your attack log to your accountAnthropic (Claude — text transcript structuring and doctor summary); Apple (on-device Speech; HealthKit); Google (Firestore storage); OpenWeatherMap (barometric pressure only — no health data)
Characteristics of protected classificationsAn optional Sex field (Female / Male / Other / Prefer-not-to-say) that you may leave blankDirectly from you (Settings → profile; optional)In-app and doctor-report context onlyGoogle (Firestore storage) — not sent to Amplitude, Anthropic, or any other third party
Commercial / purchase informationSubscription status, entitlement, plan, purchase history (we do not store card numbers)From your App Store purchase (Apple In-App Purchase)Provide and manage your subscription; unlock paid features; and measure and improve the product (product analytics)Apple (App Store / In-App Purchase); RevenueCat (subscription/entitlement management — receipt + app user ID + subscription status; no card data — RevenueCat also forwards subscription-lifecycle events to Amplitude, see the note below the table); Amplitude (subscription-lifecycle events — trial started / purchased / renewed / canceled — sent server-side from RevenueCat, keyed to your anonymous internal user id; no card data)
Usage / internet activityIn-app product-usage events — screens and funnel steps, report generation and sharing, paywall views, an elevated-pressure weather banner being shown, and the fact that the pain head-map was used (never the pain location itself); attack severity as a coarse bucket (low/moderate/high), medication as a yes/no, triggers as a count — never raw or derived health data (full list: docs/ANALYTICS_EVENTS.md)Behaviour/usage events are collected only when 'Usage analytics' is on (off by default). Subscription/billing events (see the Commercial / purchase row) are sent to Amplitude server-side and are not controlled by this toggle.Understand product usage and improve the productAmplitude (product analytics; US data region; identified only by an anonymous internal user id — your Firebase UID — never your name or email; no Session Replay; no advertising or cross-app tracking; IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions, build 18) — so no IP or location is collected and Tracking = No does not depend on a console setting)
Diagnostics / crash dataAnonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identityCollected automatically to fix bugs; on by default, opt-out under 'Crash diagnostics' in Settings → Privacy & consentDiagnose and fix crashesGoogle — Firebase Crashlytics (crash diagnostics; anonymous, not linked to your identity)
Approximate location — reduced accuracy, when-in-use (transient)When-in-use coordinates used once to fetch barometric pressure + short forecastFrom your device, with permissionShow you weather/barometric context alongside your logsOpenWeatherMap (coordinates are not stored and not used for tracking or ads)

Separately, subscription-lifecycle events (trial start, purchase, renewal, cancellation) are forwarded to Amplitude by our payment processor RevenueCat through a server-side integration, keyed to the same anonymous Firebase identifier. Because these are billing/contractual records, they are sent regardless of the "Usage analytics" toggle; they contain no card data, no health data, no log content, and no AI output.

We do not collect government identifiers (SSN, driver's license), biometric identifiers, or financial account numbers in the app. Voice audio never reaches us — speech-to-text is handled by Apple's Speech framework (which may process some audio on Apple's servers rather than strictly on-device); either way, the audio is never uploaded to us or to the AI, and we receive only the resulting text.

Our two telemetry processors — Amplitude (product analytics) and Firebase Crashlytics (crash diagnostics) — never receive your health-log content: Amplitude gets behaviour-only events — screens and funnel steps, report generation and sharing, paywall views, an elevated-pressure weather banner being shown, and the fact that the pain head-map was used (never the pain location itself) — plus health-adjacent facts only as privacy-safe proxies (attack severity as a coarse bucket, medication as a yes/no, triggers as a count); never raw or derived health data, and never medication or trigger names, dates, or pain-location values. The full, always-current event list is maintained in docs/ANALYTICS_EVENTS.md. (Amplitude separately receives the billing/subscription-lifecycle events forwarded server-side by RevenueCat described above — sent regardless of the "Usage analytics" toggle, with no card data, no health data, no log content, and no AI output.) Crashlytics receives anonymous crash data with no health data in crash keys or logs.

Your health information is "Sensitive Personal Information" (Sensitive PI) under the CPRA. We use it only to provide the service you asked for (logging, your doctor summary, your Insights) — never to infer characteristics for advertising.

1.2 Your California rights

You have the right to:

You may use an authorized agent (include a signed permission letter or power of attorney).

1.3 Sale, sharing, and Global Privacy Control (GPC)

1.4 How to exercise CPRA rights and response time

Washington — My Health My Data Act (MHMDA)

If you are a Washington resident (or your health data is collected while you're in Washington), the My Health My Data Act (MHMDA) applies. MHMDA is extraterritorial — it protects any Washington consumer, regardless of where we are based.

2.1 What counts as consumer health data

Under MHMDA, your "consumer health data" includes information that identifies your past, present, or future physical or mental health. For Amaina that means your migraine symptoms and attack logs, aura, medications and their effectiveness, triggers, and any health readings you let us read from Apple Health (Google Health Connect on a future Android release) (sleep, menstrual cycle, workouts). We treat all of this as consumer health data.

2.2 Consent: collect, then separately to share

2.3 No sale without valid authorization

We do not sell your consumer health data. MHMDA prohibits any sale of consumer health data without your signed VALID AUTHORIZATION — a specific document required by RCW 19.373.110 that is separate from, and stricter than, the consent above (it must name the data, the purpose, the recipient, an expiration, and your right to revoke, and be signed). We do not seek one and do not sell your consumer health data — selling health data is simply not part of our business.

2.4 Your MHMDA rights

You have the right to:

No discrimination. We will not deny you service, charge you a different price, or degrade your experience for exercising your MHMDA rights.

No geofencing. We do not use geofencing around any health-care facility to identify, track, or send messages/ads to consumers about their health data — MHMDA prohibits it.

To exercise these rights, email legal@smart-it.io or delete your account in-app. We honor MHMDA's required timelines (we respond within 45 days, extendable once by 45 days when reasonably necessary, with notice).

Nevada — SB 370

If you are a Nevada resident, Nevada's consumer-health-data law (SB 370, amending NRS Chapter 603A) gives you protections similar to Washington's MHMDA for health information collected about you. In short: we collect your consumer health data only with your consent, we do not sell it, and you may request access to and deletion of it. Use the same request path — email legal@smart-it.io or delete your account in-app — and the protections described in Section 2 apply to you as well.

Other US state privacy laws (brief)

Several other states — including Colorado, Connecticut, Texas, and Virginia — have comprehensive privacy laws granting residents rights to access, correct, delete, and opt out of targeted advertising and the sale of personal data, and requiring consent before processing sensitive data such as health information. Where such a law applies to you, we extend the equivalent rights described above: we treat your health data as sensitive, obtain consent before collecting it, do not sell it, and never use it for targeted advertising. Contact legal@smart-it.io to exercise any right available under your state's law.

EU / UK (secondary — not currently targeted)

We do not currently target the EEA or the UK. Amaina launches US-only (our Apple Developer account is US-only; we operate as a DSA non-trader). This section is carried over as a placeholder. If we begin offering Amaina to individuals in the EEA/UK, the following will apply and we will publish full EU/UK notices before doing so.

If and when we target the EEA/UK, we will:

Until then, individuals in the EEA/UK are not our intended audience, and no EU/UK-specific notice is in force.

How to contact us / make a request

We verify your identity before acting on access, deletion, correction, or consent-withdrawal requests. We do not charge for these requests except as permitted by law, and we will not discriminate against you for making one.