Privacy Policy

Effective Date: April 11, 2026  |  Last Updated: April 11, 2026

🔒 Privacy at a Glance

Table of Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. AI and Machine Learning (NOVA)
  5. Health Data and Apple HealthKit
  6. How We Share Information
  7. Third-Party Services
  8. Data Retention
  9. Data Security
  10. Your California Privacy Rights (CCPA/CPRA)
  11. International Privacy Rights (GDPR-Aligned)
  12. Do Not Sell or Share My Personal Information
  13. Children's Privacy (COPPA)
  14. Email Marketing (CAN-SPAM)
  15. Push Notifications (TCPA)
  16. Cookies and Tracking Technologies
  17. Do Not Track Signals
  18. International Data Transfers
  19. Data Breach Notification
  20. Your Right to Delete
  21. California Shine the Light
  22. Changes to This Policy
  23. Contact Us

1. Who We Are

Flexwell is owned and operated by Micawber Media LLC, a Texas limited liability company.

Address: 1885 FM 2673, Suite H31, Canyon Lake, TX 78132
Email: hello@flexwell.com
Website: flexwell.com

This Privacy Policy applies to the Flexwell mobile application, the Flexwell website (flexwell.com), and all related services (collectively, the "Service").

2. Information We Collect

Information You Provide

Data TypeWhat We CollectWhy
Account DataEmail address, name (optional), password (stored as bcrypt hash)Account creation and authentication
Supplement StackSupplements you track, dosages, timing preferences, custom entriesCore tracking functionality
Daily LogsWhich supplements you take or skip each day, timestampsConsistency tracking and streaks
NOVA ConversationsMessages you send to NOVA, AI responsesPersonalized AI supplement guidance
Barcode ScansBarcodes and FNSKUs you scanSupplement identification and lookup

Information from Connected Services (Your Choice)

Data TypeWhat We CollectWhy
Apple HealthKit DataHeart rate, sleep duration, steps, HRV, blood oxygen (Premium feature, opt-in only)Health-contextualized NOVA advice and insights

Information Collected Automatically

Data TypeWhat We CollectWhy
Device InfoDevice type, operating system, app versionBug fixes and compatibility
Usage DataApp opens, feature usage, screen viewsImproving the app experience

Information We Never Collect

3. How We Use Your Information

We use your information for the following purposes:

We never use your data for advertising. We never sell your data. We never share your health data with third parties for their own purposes.

4. AI and Machine Learning (NOVA)

NOVA is Flexwell's AI-powered supplement advisor. Here is exactly how your data is used:

Important: NOVA provides informational guidance only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider before making changes to your supplement regimen.

5. Health Data and Apple HealthKit

If you choose to connect Apple HealthKit (a Premium feature), we access health metrics you explicitly authorize, such as heart rate, sleep, steps, HRV, and blood oxygen.

Apple HealthKit Commitments (Required by Apple):

We store health data in our secure database with source attribution (e.g., "apple_health") to provide trends and power NOVA's health-aware insights. This data is encrypted in transit and at rest.

Flexwell is not a HIPAA-covered entity. However, we treat all health data with the highest level of care and apply security standards consistent with sensitive health information.

6. How We Share Information

We do not sell your personal information. We share data only in these limited circumstances:

7. Third-Party Services

Flexwell integrates with the following third-party services:

ServicePurposeData Shared
OpenAIPowers NOVA AI advisorSupplement stack, health data, conversation messages
Apple HealthKitHealth data syncRead-only access to authorized metrics
RevenueCatSubscription managementPurchase receipts, subscription status
Apple App StorePayment processingPayment handled entirely by Apple
RailwayCloud hostingAll app data (encrypted)
MailchimpEmail marketing (opt-in)Email address only

Each service operates under its own privacy policy. We encourage you to review them.

8. Data Retention

9. Data Security

We implement industry-standard security measures to protect your data:

No system is 100% secure. While we take extensive precautions, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at hello@flexwell.com.

10. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of Personal Information Collected (Last 12 Months)

CategoryCollectedSoldShared for Advertising
Identifiers (email, name)YesNoNo
Health informationYes (opt-in)NoNo
Commercial info (subscriptions)YesNoNo
Internet activity (usage data)YesNoNo
Inferences (AI-generated insights)YesNoNo

Submitting a Verifiable Consumer Request

To exercise your rights, email hello@flexwell.com with the subject line "CCPA Request." We will verify your identity using the email associated with your account and respond within 45 days (extendable by 45 days with notice).

You may designate an authorized agent to submit a request on your behalf. We may require proof of authorization.

11. International Privacy Rights (GDPR-Aligned)

While Flexwell is currently US-based, we extend the following rights to all users in preparation for international availability:

Our lawful bases for processing include: (a) your consent, (b) performance of a contract (providing the Service), and (c) our legitimate interests (improving the Service, ensuring security).

To exercise these rights, email hello@flexwell.com.

12. Do Not Sell or Share My Personal Information

We do not sell your personal information. We have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.

Because we do not sell or share your information for advertising, there is no need to opt out. However, if you have questions, contact hello@flexwell.com.

13. Children's Privacy (COPPA)

Flexwell is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. Health tracking features (Apple HealthKit integration) require users to be at least 16 years old.

If we discover that we have collected personal information from a child under 13, we will delete it immediately. If you believe a child under 13 has provided us with personal information, contact us at hello@flexwell.com.

14. Email Marketing (CAN-SPAM)

We comply with the CAN-SPAM Act. If you opt in to our email list:

Transactional emails (password resets, account notifications) are not marketing and may be sent without opt-in.

15. Push Notifications (TCPA)

Flexwell may send push notifications (e.g., supplement reminders). We comply with the Telephone Consumer Protection Act (TCPA):

16. Cookies and Tracking Technologies

Mobile App: The Flexwell app does not use cookies. We do not use third-party advertising trackers or analytics SDKs that create advertising profiles.

Website (flexwell.com): Our website may use essential cookies for basic functionality. We do not use advertising cookies, retargeting pixels, or third-party tracking scripts.

17. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. Because there is no industry standard for DNT compliance, we do not currently respond to DNT signals. However, we do not engage in cross-site tracking, so the practical effect is the same: your browsing activity is not tracked across websites by Flexwell.

18. International Data Transfers

Flexwell's servers are located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States.

By using Flexwell, you consent to the transfer of your data to the US. We apply the same privacy protections to all users regardless of location.

19. Data Breach Notification

In the event of a data breach that affects your personal information:

20. Your Right to Delete

You may request complete deletion of your account and all associated data at any time:

  1. Email hello@flexwell.com with the subject "Delete My Account."
  2. We will verify your identity using your account email.
  3. Within 30 days, we will permanently delete: your account, supplement stack, daily logs, NOVA conversation history, health data, and all other personal information.
  4. Anonymized aggregated data (that cannot identify you) may be retained.
  5. Data in encrypted backups will be purged within 90 days.

Account deletion is irreversible. Cancelled subscriptions must be managed through the Apple App Store.

21. California Shine the Light

Under California Civil Code Section 1798.83, California residents may request information about our disclosure of personal information to third parties for direct marketing purposes. Because we do not disclose personal information to third parties for their direct marketing purposes, no such disclosure list is required. For questions, contact hello@flexwell.com.

22. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

23. Contact Us

For questions, concerns, or requests related to this Privacy Policy or your personal data:

Micawber Media LLC
1885 FM 2673, Suite H31
Canyon Lake, TX 78132
Email: hello@flexwell.com
Website: flexwell.com

We aim to respond to all privacy inquiries within 30 days.