1.Who we are
Amaina is operated by Smart IT US Inc., a corporation incorporated in Wyoming, United States.
Our mailing address is: 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
For any privacy question, request, or concern, reach us at legal@smart-it.io. For product help, use support@smart-it.io.
In this Privacy Policy, "we," "us," and "our" mean Smart IT US Inc. doing business as Amaina. "You" means anyone who uses the Amaina iOS app or visits amaina.health.
This policy covers both the Amaina iOS app and the amaina.health website. The website presents marketing/legal information and an optional onboarding questionnaire — a few migraine-related (health) questions we collect only with your opt-in consent, governed by a separate, consent-first Health Questionnaire Privacy Notice (which controls for the questionnaire) — plus an optional step to give your name/email to save your personalized summary. The website links to the App Store; you subscribe inside the app through Apple, not on the website.
2.What we collect
We collect the following categories of information. Some are needed to run the core app; anything beyond that is collected only with your permission.
Account information
- First name — how the app addresses you.
- Email address — for your login, account recovery, and service messages.
- Date of birth (optional) — used only to give age context to your Insights. Confirming you are 18+ is done by a separate age-attestation checkbox at sign-up, not by your date of birth. We treat it as sensitive personal information and do not share it with advertising platforms. It is account information, not health data — in Apple's App Privacy labels it is mapped under Contact Info, not Health & Fitness — and it is not used to build any advertising profile.
- Sex (optional — Female / Male / Other / Prefer-not-to-say) — used only for in-app and doctor-report context. It is stored in your account, kept first-party only, and is never sent to analytics or any third party. We treat it as sensitive-adjacent personal information and do not use it for advertising.
You sign in using Sign in with Apple, Sign in with Google, or email, handled by Firebase Authentication.
Health data you log
When you use the app, you create a personal migraine log. This can include:
- Attack details — date and time, intensity (1–10), duration, symptoms, aura, and location of pain.
- Medications and doses you enter — the acute or preventive medications you take and the doses you record, and whether they helped (a self-rated effectiveness scale).
- Self-reported factors — triggers, sleep, stress, food, activity, and other context you choose to log.
- Daily wellbeing check-in (optional) — a once-a-day rating of how your day felt, on a simple 1–5 scale. It is stored in your account with the rest of your log and used only inside the app, to show patterns over time.
- Local weather readings — barometric pressure recorded with an attack, plus a short rolling daily record of pressure, temperature and humidity (about two weeks) so that an attack you log later can still show the weather for the day it actually happened, and so the app can show you the days leading up to an attack. See "Location and weather" below.
This is sensitive health information. Depending on where you live it is treated as "consumer health data," "sensitive personal information," and/or "special category data" under the relevant laws (see Section 5 and the Regional Addenda). We collect it to provide the app to you, and we never use it for advertising.
Health data read from Apple Health (Google Health Connect on a future Android release)
Amaina v1 ships on iOS only. Google Health Connect exists in our codebase but is a planned later Android release; the description below applies to Apple Health today and to Health Connect where available on a future Android release.
If you grant permission — always granular, feature by feature — the app can:
- Read sleep, menstrual cycle, and workout data from Apple Health (HealthKit) — or Google Health Connect on a future Android release — so your Insights can show associations you might otherwise miss; and
- Write your headache episodes back to Apple Health (Health Connect where available on a future Android release), so your health record stays in one place.
Raw health readings (Apple Health today; Health Connect where available on a future Android release) are processed on your device and are not retained by us beyond what's needed to compute a result; the attack log you save (including any recorded barometric pressure) is stored in your account. We follow Apple's HealthKit rules: HealthKit data is never used for advertising, marketing, or data-mining and is never shared with third parties for those purposes. See HealthKit Data Use for the details.
Voice input — text only, never audio
When you log by voice, the app uses your device's built-in speech feature (Apple Speech) to turn your speech into text. Depending on your device, language, and settings, Apple may transcribe on-device or on Apple's servers — that step happens between you and Apple.
We (and our AI subprocessor) only ever receive the resulting text — never the audio recording. The free text you dictate or type is what gets structured into fields (with your consent — see Section 4). A structured tap-to-log form is always available as an alternative and works with no AI at all. See Section 4 and the AI Processing Disclosure.
Location and weather
If you enable the weather feature, the app uses your location while you are using the app ("when-in-use") to fetch barometric pressure and a short forecast from OpenWeatherMap. Amaina reads local barometric pressure and a 5-day forecast (in 3-hour steps). Two things are shown from it. On the home screen, when a fall of about 6 hPa or more is forecast for the next ~24 hours, you see a "Pressure dropping today" note. In the weather view, the pressure chart is colour-coded by how fast pressure is forecast to fall — green "Steady", amber "Falling", red "Falling fast" (about 3 hPa and about 6 hPa over 24 hours, following Kimoto et al., 2011, which is cited in the app). Humidity and temperature are charted without any colour classification, because we have no cited thresholds for them. All of this is a general weather signal on a one-size-for-everyone threshold — not personalized to your health history and not a prediction of your personal risk. The "your history" figure (share of your logged attacks at low pressure) is a descriptive look-back.
Your coordinates are not stored on our servers, are not used for tracking or advertising, and are shared with OpenWeatherMap only to fetch that weather data. The barometric pressure value can be saved with the relevant attack in your log, and the app also keeps a short rolling record of the daily pressure, temperature and humidity where you are (about two weeks) — weather readings only, never your coordinates — so an attack you log after the fact can still show the weather for the day it happened, and so you can see the days leading up to it.
Payment and subscription information
You buy your subscription inside the app as an Apple In-App Purchase, using StoreKit and managed with RevenueCat. Apple processes the transaction and handles your card — we never see or store your card number. Our subprocessor RevenueCat receives the purchase receipt, an app-assigned user identifier, and your subscription/entitlement status (no card data, no health data) so we can validate the purchase and unlock the paid features for your account. RevenueCat also forwards subscription-lifecycle events (trial started, purchase, renewal, cancellation) to our analytics processor Amplitude through a server-side integration, keyed to the same anonymous identifier, as billing/contractual data (no card data, no health data). This flow is not controlled by the Usage-analytics toggle.
Your subscription automatically renews at the then-current price unless auto-renew is turned off at least 24 hours before the end of the current period; payment is charged to your Apple ID at confirmation of purchase. You manage or cancel in Settings → your Apple ID → Subscriptions (or App Store → your account → Subscriptions). Refunds are handled by Apple (Report a Problem / Apple Support) — we cannot directly refund an App Store purchase.
In-app usage analytics and crash diagnostics
The app includes two in-app SDKs that collect non-health technical data. Neither ever receives raw or derived health data, log content, or AI output, and neither is used for advertising:
- Usage analytics (Amplitude). Amplitude (product analytics). Anonymous behaviour/usage events only — app screens and funnel steps, onboarding/activation steps, log input method (voice vs tap), whether the pain head-map was used (the fact only, never a location value), report generated/shared, paywall shown, and a weather-alert-shown flag with a coarse pressure-change bucket; health-adjacent facts appear only as privacy-safe proxies (severity as a coarse bucket, medication as a yes/no, triggers as a count) — never raw or derived health data, log content, AI output, med/trigger names, dates, or pain-location values. The authoritative, always-current event list is ANALYTICS_EVENTS.md. Identified only by an anonymous internal user id (your Firebase UID), never your name or email. US data region. Behaviour/usage events are collected only when "Usage analytics" is on (off by default). Separately, subscription-lifecycle events (trial start, purchase, renewal, cancellation) are forwarded to Amplitude by our payment processor RevenueCat through a server-side integration, keyed to the same anonymous Firebase identifier. Because these are billing/contractual records, they are sent regardless of the "Usage analytics" toggle; they contain no card data, no health data, no log content, and no AI output. No Session Replay; no advertising or cross-app tracking (no IDFA / no ATT). IP address, geo (country/region/city/DMA/latitude-longitude), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions), build 18 — so no IP address or location is collected, and "Tracking = No" does not depend on a console setting.
- Crash diagnostics (Firebase Crashlytics). Google — Firebase Crashlytics (crash diagnostics). Anonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent.
Web device, usage, and cookie data
When you visit amaina.health we automatically collect standard technical data:
- Device and browser information — IP address, browser type and version, operating system, screen size, language.
- Usage information — pages viewed, links clicked, time on page, referring website.
- Cookie and tracker data — see Section 7 and our Cookie Policy.
We use this to run and improve the site, measure marketing, and prevent fraud and abuse.
3.How we use your information
We use your information to:
- Run the core app — save your logs, build your timeline, and compute your in-app Insights.
- Structure the free text you dictate or type — and draft your doctor summary — see Section 4. The structured tap-to-log form never uses AI.
- Show you associations and observations from your own data — patterns, trends, and Insight cards drawn from what you logged. These are observations, not diagnoses, predictions, risk scores, or treatment recommendations (see the Medical Disclaimer).
- Communicate with you — service messages (account, security, subscription), and — only if you opted in — product updates. If you turn on the optional Monthly report reminder, your device shows a local reminder on the 1st of each month to review your report — scheduled on-device with no push tokens, no server, and no data leaving your device.
- Process your subscription — via Apple In-App Purchase (StoreKit), managed with RevenueCat.
- Keep the service secure — detect fraud and abuse, debug, and protect our users and our business.
- Understand product usage and fix crashes — anonymous in-app behaviour events via Amplitude (only if you turn on "Usage analytics", off by default; subscription-lifecycle billing events reach Amplitude regardless — see Section 2) and anonymous crash reports via Firebase Crashlytics (on by default; opt out under "Crash diagnostics"). Behaviour and crash telemetry only — never health data. See Section 2 and Section 8.
- Measure our web marketing in aggregate — see Section 7.
We do not use your information for automated decisions that produce legal or similarly significant effects about you. We do not use your health data, Apple Health data, structured logs, or AI outputs to build advertising audiences, and we do not sell them.
A note on what Amaina's outputs are. Everything Amaina shows you — Insight cards, patterns, your own medication-days count, the weather view, medication-effectiveness views, and the doctor summary — reflects your own logged data. Your report keeps a count of your own acute-medication days drawn from what you logged — a descriptive record of your own data. Separately, a general educational note references the guidance that using acute medication on roughly 10–15 or more days a month is worth discussing with your doctor — presented as a neutral, general educational note, not juxtaposed with your personal count and not attached to it as a "medication-overuse-headache risk" label. It is a descriptive record plus separate general education — not a personalized calculation, not a risk assessment, and not dosing advice. The weather view includes a forward-looking, general element: a 5-day pressure chart colour-coded by how fast pressure is forecast to fall (green "Steady" / amber "Falling" / red "Falling fast", at about 3 and about 6 hPa over 24 hours), plus a home-screen "Pressure dropping today" note on a forecast fall of about 6 hPa or more. Colours describe the weather, not you — the thresholds are the same for everyone, so this is not personalized to your history and not a prediction of your personal risk; humidity and temperature carry no colour coding at all. It sits alongside a separate descriptive "your history" look-back at pressure and your attacks. Medication-effectiveness views are retrospective displays only and never influence your dose or drug choice. Your doctor interprets what any of it means.
4.How we use AI
Some features use a third-party AI service:
- Structuring the free text you dictate or type. When you describe an attack in your own words — the text your device produced from your speech, or free text you type — that text is sent from the app to our own backend server, which forwards it to Anthropic's Claude (Messages API) to organize it into fields (time, intensity, duration, symptoms, aura, medication, triggers). This happens only after you consent. If you decline (or turn AI off), you log with the structured tap-to-log form instead — you pick times, intensity, symptoms, and medications from the app's own controls, which are saved directly with no AI.
- The doctor summary. When you generate a summary for your doctor, we send your own logged record — the number of attacks in the period, your average severity, your ranked triggers (with Apple Health-derived ones such as sleep-under-6h and menstrual-window stripped out before sending), and your medications with how well they helped — and Claude drafts a descriptive narrative from it (frequency, clustering, severity trend, changes in what you've recorded). This is a live, consent-gated Claude call site; the report also has a static, no-AI fallback. It is descriptive only — never a diagnosis, prognosis, or treatment recommendation.
In build 1.0.0(22) there are exactly two Claude call sites, both live and both gated on your AI consent: (1) structuring your voice/typed log into fields, and (2) drafting the doctor-visit summary narrative (with a static, no-AI fallback for the report). The tap / manual path never uses AI. The AI Processing Disclosure is the authoritative, feature-by-feature description; this policy, the disclosure, the in-app consent screen, and the App Privacy labels are all kept in sync with what ships.
In-app Insights (Frequency, Sleep, Cycle, Activity, Profile) are computed on your device by rule-based logic — they do NOT use AI. The structured tap-to-log form does not use AI either, so you can log fully without it.
Key safeguards for the AI processing:
- Anthropic is a subprocessor under a Data Processing Agreement (with Standard Contractual Clauses) that is in force for our commercial API organization (Smart IT US Inc.).
- Equal protection. Anthropic is contractually required, under our Data Processing Agreement and Standard Contractual Clauses, to protect this data to the same standard described in this policy — including no training on your data, deletion of AI request text within 30 days, and no use of your data for advertising or its own purposes.
- No training on your data by default — Anthropic does not train its models on what we send.
- Automatic 30-day deletion. Anthropic automatically deletes the text of AI requests within 30 days — keeping it longer only if content is flagged for a safety/policy review. We asked Anthropic for Zero Data Retention, which would remove even that short window, but it is currently offered only to large enterprise accounts, so we rely on this standard 30-day-deletion policy together with our data-processing agreement and our own data minimization. We use a standard Claude model.
- Text only — we never send the audio; and we do not put health identifiers into the AI field names.
- Backend only — the AI is called only from our server, never from your browser.
- Your consent first. Because this shares your data with a third-party AI, we ask for your explicit, separate consent before any transmission, in line with Apple's App Store rules. You can use the tap / manual-entry option without AI.
Full detail — including exactly what is sent, what isn't, and how to opt out — is in the AI Processing Disclosure.
5.How we handle health data
Your migraine logs, symptoms, and the medications you enter are health data, and we treat them accordingly. Separately, the amaina.health onboarding questionnaire collects a few migraine-related answers only with your opt-in consent (an unchecked box before the first health question), under a dedicated, consent-first Health Questionnaire Privacy Notice that controls for the questionnaire.
- Consent-first. We collect health data to provide the app to you, and we ask for granular, separated consent for anything beyond the core function — especially AI processing (Section 4), Apple Health access (Health Connect on a future Android release) (HealthKit Data Use), and any research use (we do not use your data for research without a separate, clearly-worded opt-in).
- Never for advertising. We do not use health data, Apple Health / HealthKit data, structured logs, or AI outputs to target ads, to build advertising audiences (custom, lookalike, or health-interest), or for data-mining. We do not sell them. See Section 7.
- Outputs are observations, not medical conclusions. See the note in Section 3 and the Medical Disclaimer.
- Extra rights. Depending on where you live, health data carries additional rights and consent requirements — see Section 8 and the Regional Addenda.
You can generate a doctor summary from your logs and export or share it as a PDF (amaina-migraine-report.pdf), built on your device with no AI — or share it as text. (The no-AI static-fallback summary can be exported as this same PDF, so the no-AI path still yields a real doctor PDF.) This is separate from the "Export my data" feature, which now offers a choice: a Doctor report (PDF) built on your device with no AI, or Raw data (JSON) of your profile, medications, and attacks for data portability. The doctor summary is a patient-generated health record — a communication tool to bring to your doctor — not a clinical report or diagnosis.
6.Subprocessors
We share your information with a small set of trusted service providers ("subprocessors") who help us run Amaina. Each is bound by contract to use your data only for the purposes we specify. This table is a summary; the authoritative, always-current list is the Subprocessor List, and the two must match.
| Subprocessor | Used for | Data it can receive |
|---|---|---|
| Anthropic (Claude) | Structuring your entries; generating the descriptive doctor summary | The text of your logs (never audio); no health identifiers in field names |
| OpenWeatherMap | Barometric pressure + short forecast for the weather view | Approximate location — reduced accuracy, when-in-use (coordinates, not stored by us) |
| Google (Firebase Authentication + Firestore + Crashlytics) | Login and account/data storage; crash diagnostics | Account info and your attack logs (Auth + Firestore); Crashlytics is listed separately below |
| Amplitude (product analytics) | Anonymous in-app behaviour/usage analytics | Anonymous behaviour/usage events (the authoritative, always-current list is ANALYTICS_EVENTS.md) — never raw or derived health data, log content, or AI output. Identified only by an anonymous internal user id (your Firebase UID), never your name or email. US data region. Behaviour/usage events are collected only when "Usage analytics" is on (off by default); no Session Replay; no advertising or cross-app tracking (no IDFA / no ATT). Plus subscription-lifecycle events (trial / purchase / renewal / cancellation) forwarded server-side by RevenueCat, keyed to the same anonymous Firebase UID, sent as billing/contractual data regardless of the Usage-analytics toggle (no card data, no health data) |
| Google — Firebase Crashlytics (crash diagnostics) | Anonymous crash reports to fix bugs | Anonymous crash reports (stack traces, device/OS) — never health data, and not linked to your identity. On by default; turn it off under "Crash diagnostics" in Settings → Privacy & consent |
| Apple (Speech, HealthKit, App Store, In-App Purchase) | On-device/OS speech-to-text; Apple Health read/write; app distribution; subscription payment | Speech is handled by Apple's OS; HealthKit data per your granular permissions; the payment/card is handled by Apple (we never receive it) |
| RevenueCat | Subscription/entitlement management for the in-app Apple purchase | Purchase receipt, app user id, and subscription status — no card data, no health data. RevenueCat also forwards these subscription-lifecycle events to Amplitude (analytics) via a server-side integration, keyed to the same anonymous identifier; not controlled by the Usage-analytics toggle |
| HubSpot (web only) | Email/CRM for waitlist and product communications | Name, email, marketing-engagement data |
| Google / Meta advertising & analytics pixels (web only) | Aggregate conversion measurement and site analytics | Web usage, IP, device info — never health data (see Section 7) |
We may also disclose information if required by law (e.g., subpoena or court order), to protect our rights and safety (fraud, abuse, or harm), or in a business transfer (merger, acquisition, or sale of assets — you'll be notified). We do not sell your personal information for money.
8.Your US privacy rights
Wherever you live in the US, you can ask us to:
- Access the personal information we hold about you;
- Correct information that's inaccurate;
- Delete your information (see Section 9);
- Limit the use of your sensitive/health information to what's necessary;
- Opt out of any "sale" or "sharing" for cross-context advertising. This control (and the Global Privacy Control signal) applies to our web funnel, where the only ad/analytics pixels run. The app itself runs no ad pixels and performs no "sale" or cross-context "sharing," so there is nothing to opt out of in-app — and we never share health data for ads anywhere.
To make a request, email legal@smart-it.io, or use the in-app and in-account controls. We may need to verify your identity first. We do not discriminate against you for exercising these rights.
Your in-app consent controls. Two consents are mandatory to use the app — confirming you are 18 or older and consenting to health-data processing. The rest are optional and each is recorded as an audit event: AI logging (opt-in, asked once before any AI use), Product emails (opt-in, off by default), Usage analytics (opt-in, off by default — gates the Amplitude behaviour/usage events; note that subscription-lifecycle billing events still reach Amplitude via a server-side RevenueCat integration, which this toggle does not control), and Crash diagnostics (on by default / opt-out — gates Firebase Crashlytics). You can change or withdraw these last four anytime in Settings → "Privacy & consent", which has four toggles: AI logging · Product emails · Usage analytics · Crash diagnostics.
Some states give you extra protections. In particular:
- California (CPRA). Health data is "sensitive personal information" with a right to limit its use; we honor GPC; and we provide an opt-out for cross-context advertising ("sharing"). We do not share health data for ads.
- Washington (My Health My Data Act). Your "consumer health data" here means your migraine symptoms and attack logs, aura, medications and their effectiveness, triggers, and any Apple Health readings you let us read (sleep, cycle, workouts) — Health Connect where available on a future Android release. We obtain opt-in consent to collect it and a separate opt-in consent to share it, and we will not sell it without your signed VALID AUTHORIZATION (the specific document MHMDA requires — separate from, and stricter than, consent) — which we do not seek. These protections apply to any Washington user; the Regional Addenda is authoritative on the full category list, your appeal right, and our non-discrimination guarantee.
- Nevada (SB 370). Similar consumer-health-data protections apply to Nevada users.
Full state-by-state detail — including the California notice-at-collection and the Washington consumer-health-data section — is in the Regional Addenda.
HIPAA note. Amaina is a direct-to-consumer wellness app, not a HIPAA covered entity or business associate. We do not claim HIPAA compliance and HIPAA does not apply. Separately, we comply with the FTC Health Breach Notification Rule — see Section 12.
9.Account and data deletion
You can delete your Amaina account and associated data:
- In the app — account deletion is available directly in the app (as Apple requires), not only by email; and
- By email — write to legal@smart-it.io.
When you delete your account, we remove your personal data from our active systems, and instruct our subprocessors to do the same, within 30 days, except where we must keep certain records to meet a legal obligation. Note that headache episodes the app wrote to your Apple Health (or Health Connect on a future Android release) stay in your device's health store until you remove them there. Deleting your Amaina account does not cancel your App Store subscription — you must cancel that separately in Settings → your Apple ID → Subscriptions. For the full walkthrough, see Account & Data Deletion.
10.How long we keep your information
We keep information only as long as we need it for the purposes above:
- Account and health logs — for as long as your account is active. If you delete your account, we delete this data within 30 days (see Section 9).
- Raw Apple Health readings (Health Connect on a future Android release) — processed on-device and not retained by us beyond what's needed to compute a result; only the attack log you save is kept.
- Voice audio — never received by us, so never stored by us.
- AI processing content — the text of AI requests is automatically deleted by Anthropic within 30 days, kept longer only if flagged for a safety/policy review. (We asked Anthropic for Zero Data Retention, which would remove even that short window, but it is currently offered only to large enterprise accounts, so we rely on this standard 30-day-deletion policy together with our data-processing agreement and our own data minimization.) See the AI Processing Disclosure.
- In-app usage analytics (Amplitude) — Behaviour/usage events are collected only while "Usage analytics" is on; turning the toggle off stops that collection. Subscription-lifecycle (billing) events continue to flow to Amplitude via the server-side RevenueCat integration even with the toggle off, keyed to your anonymous Firebase UID. Deleting your account severs the UID-linked analytics identity.
- In-app crash diagnostics (Firebase Crashlytics) — anonymous crash reports, not linked to your identity; retained per Crashlytics' standard diagnostic retention. No user-identified crash data is kept.
- Web email and name (waitlist/CRM) — until you unsubscribe or ask us to delete it, or up to 3 years after your last interaction, whichever comes first.
- Web technical/usage data — up to 26 months (standard analytics retention).
- Payment records — the card transaction is handled by Apple (we never receive card data); RevenueCat and we retain subscription/entitlement records (receipt, app user id, subscription status) as needed for tax, accounting, and legal obligations.
11.Adults only (18+)
Amaina is intended for adults 18 years of age or older. We do not knowingly collect information from anyone under 18. By using Amaina you confirm you are 18 or older. If you believe someone under 18 has given us their information, email legal@smart-it.io and we'll delete it.
12.Security and breach notification
We protect your information with industry-standard safeguards — encryption in transit (HTTPS/TLS) and at rest where applicable, authenticated access, least-privilege internal access, and security reviews of our subprocessors. No system is 100% secure, but we work to keep your data as safe as reasonably possible.
If a breach of your health data occurs, we comply with the FTC Health Breach Notification Rule: we will notify affected users and the FTC within 60 days, and provide media notice if 500 or more residents of a state are affected.
13.International transfers
We are based in the United States (Wyoming), and we process your data in the United States. Our subprocessors may process data in the United States and, in some cases, other countries; where they do, appropriate safeguards apply.
EEA/UK (secondary). We do not currently target the EEA or the UK, and Amaina is offered to US users at launch. If that changes, the following would apply: for transfers involving EEA or UK residents, we would rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), and health data would be handled as special category data under GDPR Article 9 (explicit consent). See the Regional Addenda. Copies of safeguards are available at legal@smart-it.io.
14.Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll change the Effective Date above and, for material changes, notify you in the app or by email. The current version is always available at amaina.health/privacy and in the app.
15.Contact us
For any privacy question, request, or concern:
Email: legal@smart-it.io Support: support@smart-it.io Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA
Regional privacy addenda (US)
- US law is primary. Amaina launches US-only. We call out California, Washington, and Nevada rights below. EU/UK is included only as clearly-flagged secondary — we do not currently target the EEA/UK.
- Your health data is treated as sensitive everywhere. Your migraine logs, symptoms, medications, and related answers get the strongest protection we offer, in every state.
- We do not sell your personal information, and we never share your health data for cross-context advertising. Health data, HealthKit/Health Connect data, structured logs, and AI outputs are never sent to ad platforms or used to build ad audiences.
- California: rights to know, access, delete, correct, limit use of sensitive PI, and opt out — we honor Global Privacy Control (GPC). 45-day response.
- Washington (MHMDA): we get your opt-in consent to collect your consumer health data and a separate opt-in consent to share it; no sale without your written authorization. Applies to any Washington resident.
- Nevada (SB 370): similar consumer-health-data protections; same request path.
- If a breach of your health data occurs, we follow the FTC Health Breach Notification Rule (see Privacy Policy §12): notice to affected users and the FTC within 60 days, and media notice if 500 or more residents of a state are affected.
- How to make a request (any state): email legal@smart-it.io, or delete your account in-app (Settings → Delete Account). We verify it's you before acting.
California — CPRA / CCPA
If you live in California, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you rights about your personal information. This section covers the Amaina iOS app and your account. Advertising and analytics on our marketing website are covered in our website Cookie Policy.
1.1 Categories of personal information we collect for the app
Amaina is pre-launch, so this describes the categories we collect when you use Amaina (not a past 12-month collection history):
| Category | Examples | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | First name, email address, internal account/user ID (we do not collect the IDFA advertising identifier) | Directly from you; created at sign-up (Firebase Auth via Sign in with Apple / Google / email) | Create and secure your account, sign you in, contact you about the service | Google (Firebase Auth + Firestore) |
| Health / sensitive personal information | Migraine logs (time, intensity, duration, symptoms, aura), medications and effectiveness, triggers, date of birth (for age-context insights), and — only with your granular permission — sleep, menstrual-cycle, and workout data read from Apple Health (and, on a future Android release, Google Health Connect), plus barometric pressure recorded with your attack log | Directly from you (voice or manual entry); read from Apple Health (Health Connect on a future Android release) with your permission | Log and organize your own data; generate a descriptive, patient-generated summary you can share with your doctor (not a clinical report or diagnosis); power in-app Insights; save your attack log to your account | Anthropic (Claude — text transcript structuring and doctor summary); Apple (on-device Speech; HealthKit); Google (Firestore storage); OpenWeatherMap (barometric pressure only — no health data) |
| Characteristics of protected classifications | An optional Sex field (Female / Male / Other / Prefer-not-to-say) that you may leave blank | Directly from you (Settings → profile; optional) | In-app and doctor-report context only | Google (Firestore storage) — not sent to Amplitude, Anthropic, or any other third party |
| Commercial / purchase information | Subscription status, entitlement, plan, purchase history (we do not store card numbers) | From your App Store purchase (Apple In-App Purchase) | Provide and manage your subscription; unlock paid features; and measure and improve the product (product analytics) | Apple (App Store / In-App Purchase); RevenueCat (subscription/entitlement management — receipt + app user ID + subscription status; no card data — RevenueCat also forwards subscription-lifecycle events to Amplitude, see the note below the table); Amplitude (subscription-lifecycle events — trial started / purchased / renewed / canceled — sent server-side from RevenueCat, keyed to your anonymous internal user id; no card data) |
| Usage / internet activity | In-app product-usage events — screens and funnel steps, report generation and sharing, paywall views, an elevated-pressure weather banner being shown, and the fact that the pain head-map was used (never the pain location itself); attack severity as a coarse bucket (low/moderate/high), medication as a yes/no, triggers as a count — never raw or derived health data (full list: docs/ANALYTICS_EVENTS.md) | Behaviour/usage events are collected only when 'Usage analytics' is on (off by default). Subscription/billing events (see the Commercial / purchase row) are sent to Amplitude server-side and are not controlled by this toggle. | Understand product usage and improve the product | Amplitude (product analytics; US data region; identified only by an anonymous internal user id — your Firebase UID — never your name or email; no Session Replay; no advertising or cross-app tracking; IP address, geo (country/region/city/DMA/lat-lng), carrier, and advertising id capture are disabled in the Amplitude SDK (TrackingOptions, build 18) — so no IP or location is collected and Tracking = No does not depend on a console setting) |
| Diagnostics / crash data | Anonymous crash reports (stack traces, device/OS) to fix bugs — never health data, and not linked to your identity | Collected automatically to fix bugs; on by default, opt-out under 'Crash diagnostics' in Settings → Privacy & consent | Diagnose and fix crashes | Google — Firebase Crashlytics (crash diagnostics; anonymous, not linked to your identity) |
| Approximate location — reduced accuracy, when-in-use (transient) | When-in-use coordinates used once to fetch barometric pressure + short forecast | From your device, with permission | Show you weather/barometric context alongside your logs | OpenWeatherMap (coordinates are not stored and not used for tracking or ads) |
Separately, subscription-lifecycle events (trial start, purchase, renewal, cancellation) are forwarded to Amplitude by our payment processor RevenueCat through a server-side integration, keyed to the same anonymous Firebase identifier. Because these are billing/contractual records, they are sent regardless of the "Usage analytics" toggle; they contain no card data, no health data, no log content, and no AI output.
We do not collect government identifiers (SSN, driver's license), biometric identifiers, or financial account numbers in the app. Voice audio never reaches us — speech-to-text is handled by Apple's Speech framework (which may process some audio on Apple's servers rather than strictly on-device); either way, the audio is never uploaded to us or to the AI, and we receive only the resulting text.
Our two telemetry processors — Amplitude (product analytics) and Firebase Crashlytics (crash diagnostics) — never receive your health-log content: Amplitude gets behaviour-only events — screens and funnel steps, report generation and sharing, paywall views, an elevated-pressure weather banner being shown, and the fact that the pain head-map was used (never the pain location itself) — plus health-adjacent facts only as privacy-safe proxies (attack severity as a coarse bucket, medication as a yes/no, triggers as a count); never raw or derived health data, and never medication or trigger names, dates, or pain-location values. The full, always-current event list is maintained in docs/ANALYTICS_EVENTS.md. (Amplitude separately receives the billing/subscription-lifecycle events forwarded server-side by RevenueCat described above — sent regardless of the "Usage analytics" toggle, with no card data, no health data, no log content, and no AI output.) Crashlytics receives anonymous crash data with no health data in crash keys or logs.
Your health information is "Sensitive Personal Information" (Sensitive PI) under the CPRA. We use it only to provide the service you asked for (logging, your doctor summary, your Insights) — never to infer characteristics for advertising.
1.2 Your California rights
You have the right to:
- Know / Access — the categories and specific pieces of personal information we've collected, the sources, our purposes, and who we disclosed it to.
- Delete — personal information we collected from you (subject to legal exceptions, e.g. records we must keep).
- Correct — inaccurate personal information.
- Limit use of Sensitive PI — direct us to use your health data only as needed to deliver the service. Because we already use your health data only for the service and never for advertising or profiling, honoring this right does not reduce the app's core function.
- Opt out of "sale"/"sharing" — see 1.3.
- Non-discrimination — we won't deny service, charge more, or give a worse experience for exercising these rights.
You may use an authorized agent (include a signed permission letter or power of attorney).
1.3 Sale, sharing, and Global Privacy Control (GPC)
- We do not sell your personal information.
- We do not share your health data for cross-context behavioral advertising. Health data, HealthKit/Health Connect data, structured logs, and AI outputs are never sent to ad platforms and never used to build custom, lookalike, or health-interest audiences.
- The only advertising-related "sharing" we do is on our marketing website (Meta/Google pixels for aggregate conversion measurement, consent-gated) — never in the app and never with your health data. You can opt out there via "Do Not Sell or Share My Personal Information" / cookie settings.
- We honor the Global Privacy Control (GPC): if your browser sends a GPC signal on our website, we treat it as a valid opt-out of "sale"/"sharing" for that browser.
1.4 How to exercise CPRA rights and response time
- Delete your account: Settings → Delete Account (in-app deletion is always available — Apple 5.1.1(v)). You can also email us.
- Any other request (know, access, correct, limit): email legal@smart-it.io with enough information to verify it's you (typically your account email). We respond within 45 days; if we need more time (up to 45 additional days), we'll tell you why.
Washington — My Health My Data Act (MHMDA)
If you are a Washington resident (or your health data is collected while you're in Washington), the My Health My Data Act (MHMDA) applies. MHMDA is extraterritorial — it protects any Washington consumer, regardless of where we are based.
2.1 What counts as consumer health data
Under MHMDA, your "consumer health data" includes information that identifies your past, present, or future physical or mental health. For Amaina that means your migraine symptoms and attack logs, aura, medications and their effectiveness, triggers, and any health readings you let us read from Apple Health (Google Health Connect on a future Android release) (sleep, menstrual cycle, workouts). We treat all of this as consumer health data.
2.2 Consent: collect, then separately to share
- Opt-in to collect. We ask for your affirmative, opt-in consent before we collect your consumer health data. Consent is specific to the purpose we describe (logging and organizing your own data, generating your descriptive doctor summary, and powering your Insights). A manual, non-AI entry path exists so core logging never requires AI processing consent.
- Separate opt-in to share. We do not share your consumer health data for any secondary purpose. If we ever needed to share it beyond what's necessary to deliver the service you asked for, we would obtain a separate, distinct opt-in consent first (not bundled with the collection consent).
- Processors are not "sharing." Disclosing your data to a service provider strictly to run the service you asked for (for example, Anthropic structuring your voice-log text, or Google storing your account) is a processor relationship under a written contract, not a sale and not the kind of "sharing" that needs separate authorization. Before any log text is sent to Anthropic for structuring, we obtain your explicit in-app consent, and a manual, non-AI entry path is always available — see the AI Processing Disclosure and In-App Consent notice.
2.3 No sale without valid authorization
We do not sell your consumer health data. MHMDA prohibits any sale of consumer health data without your signed VALID AUTHORIZATION — a specific document required by RCW 19.373.110 that is separate from, and stricter than, the consent above (it must name the data, the purpose, the recipient, an expiration, and your right to revoke, and be signed). We do not seek one and do not sell your consumer health data — selling health data is simply not part of our business.
2.4 Your MHMDA rights
You have the right to:
- Confirm and access whether we are collecting, sharing, or selling your consumer health data, and access that data.
- Delete your consumer health data (we will also direct our processors to delete it).
- Withdraw consent to our collection and (if it ever applied) sharing of your consumer health data, at any time.
- Appeal — if we deny your request, we will explain why and give you a way to appeal. If the appeal is denied, you may contact the Washington Attorney General (www.atg.wa.gov/file-complaint).
No discrimination. We will not deny you service, charge you a different price, or degrade your experience for exercising your MHMDA rights.
No geofencing. We do not use geofencing around any health-care facility to identify, track, or send messages/ads to consumers about their health data — MHMDA prohibits it.
To exercise these rights, email legal@smart-it.io or delete your account in-app. We honor MHMDA's required timelines (we respond within 45 days, extendable once by 45 days when reasonably necessary, with notice).
Nevada — SB 370
If you are a Nevada resident, Nevada's consumer-health-data law (SB 370, amending NRS Chapter 603A) gives you protections similar to Washington's MHMDA for health information collected about you. In short: we collect your consumer health data only with your consent, we do not sell it, and you may request access to and deletion of it. Use the same request path — email legal@smart-it.io or delete your account in-app — and the protections described in Section 2 apply to you as well.
Other US state privacy laws (brief)
Several other states — including Colorado, Connecticut, Texas, and Virginia — have comprehensive privacy laws granting residents rights to access, correct, delete, and opt out of targeted advertising and the sale of personal data, and requiring consent before processing sensitive data such as health information. Where such a law applies to you, we extend the equivalent rights described above: we treat your health data as sensitive, obtain consent before collecting it, do not sell it, and never use it for targeted advertising. Contact legal@smart-it.io to exercise any right available under your state's law.
EU / UK (secondary — not currently targeted)
We do not currently target the EEA or the UK. Amaina launches US-only (our Apple Developer account is US-only; we operate as a DSA non-trader). This section is carried over as a placeholder. If we begin offering Amaina to individuals in the EEA/UK, the following will apply and we will publish full EU/UK notices before doing so.
If and when we target the EEA/UK, we will:
- Rely on GDPR Art. 9(2)(a) explicit consent as the legal basis for processing your health data (special-category data), requested clearly before any such processing and withdrawable at any time.
- Put a data processing agreement (DPA) covering special-category data in place with each processor (for example Anthropic, Google, Apple, OpenWeatherMap, RevenueCat, Amplitude, and Firebase Crashlytics) before any health data is sent. Note: Anthropic's commercial DPA (with Standard Contractual Clauses) is already in force for our account; whether the standard DPA is sufficient for special-category health text was self-assessed as adequate for MVP (Anton, 2026-07-24) — not routed to outside counsel (revisit post-MVP).
- Complete a Data Protection Impact Assessment (DPIA) under Art. 35 before any large-scale processing of special-category data.
- Use Standard Contractual Clauses (SCCs) — plus the UK IDTA / UK Addendum for UK transfers — for transfers of EEA/UK data to the United States, alongside safeguards such as encryption and access controls.
- Appoint an Art. 27 representative in the EU (and a UK representative) if we have no establishment there.
Until then, individuals in the EEA/UK are not our intended audience, and no EU/UK-specific notice is in force.
How to contact us / make a request
- Delete your account (all users): in-app, Settings → Delete Account.
- Any privacy request or question: legal@smart-it.io
- Product support: support@smart-it.io
- Mail: Smart IT US Inc., 30 N Gould St Ste R, Sheridan, Wyoming 82801, USA.
We verify your identity before acting on access, deletion, correction, or consent-withdrawal requests. We do not charge for these requests except as permitted by law, and we will not discriminate against you for making one.