Data Controller
Andningsappen Varberg AB (trading as "WeHale", "we", "us", "our") is the data controller responsible for the processing of your personal data as described in this privacy policy.
Andningsappen Varberg AB
Organisation number: 559496-1491
Boråsgatan 12 B, 432 45 Varberg, Sweden
Email: support@wehale.io
We care about your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Swedish law. This privacy policy explains what personal data we collect when you use the WeHale mobile app and related services, why we collect it, how we use it, and your rights in relation to your data.
As a smaller organisation, Andningsappen Varberg AB is not required to appoint a Data Protection Officer (DPO) under GDPR Article 37. For any data protection queries, please contact us at support@wehale.io.
1. Data We Collect
We collect the following categories of personal data, each with a specified legal basis under GDPR Article 6. When we refer to "personal data" in this policy, we mean any information that can directly or indirectly identify you as an individual under GDPR. Data that has been irreversibly anonymised so that you are no longer identifiable is not considered personal data.
1.1 Account information
Data: Email address and display name when you create an account.
Purpose: To create and manage your account, identify you as a user, and send transactional emails such as password resets and account-related notifications.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)): necessary to provide you with the WeHale service under our terms of use.
1.2 Session activity
Data: Which sessions you complete, session ratings, and breath-hold durations.
Purpose: To track your progress, provide weekly progress tracking, and offer personalised session recommendations.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)): necessary to deliver core app functionality and personalisation.
1.3 Check-in and wellness data
Data: Self-reported stress level (numerical scale) before sessions and self-reported emotional or mental state (e.g. "Calm", "Clear") after sessions.
Purpose: To personalise your experience through AI-powered session recommendations (see section 2.1), track changes in your self-reported wellbeing over time, and generate aggregated, anonymised insights for product improvement and, in the future, evidence-based reporting (e.g. for workplace wellness programmes). We do not use this data to diagnose, treat, or prevent any medical condition.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)): necessary to deliver the personalised breathwork experience that forms a core part of the WeHale service.
Note on health data: Self-reported mood and stress ratings on a simple scale are generally not considered "special category data" (health data) under GDPR Article 9, as they reflect subjective self-assessments rather than medical information. We do not infer health conditions from this data. We periodically review our classification of this data in light of regulatory guidance and any changes to how we process it. Should our processing change in a way that would bring this data within the scope of Article 9, we will update this policy and, where required, obtain your explicit consent.
1.4 Device information
Data: Device model, operating system version, and app version.
Purpose: Diagnostics, troubleshooting, and improving app stability and security.
Legal basis: Legitimate interest (GDPR Art. 6(1)(f)): our legitimate interest in maintaining a secure, well-functioning application. We have carried out a legitimate interest assessment to ensure that our interests do not override your fundamental rights and freedoms. A summary of this assessment is available on request.
1.5 Analytics and attribution data
Data: Usage events such as screens viewed, session starts, and feature interactions, collected via Mixpanel and similar tools. This data is processed in pseudonymised form and we take steps to avoid collecting information that directly identifies you. We also collect attribution data such as install source, campaign identifiers (e.g. UTM parameters), locale, and timezone to understand how users discover WeHale.
Purpose: To understand how users interact with the app and improve the overall experience, including product decisions, feature development, and marketing effectiveness analysis.
Legal basis: Legitimate interest (GDPR Art. 6(1)(f)): our interest in improving our service through analytics data and understanding marketing channel effectiveness. We have carried out a legitimate interest assessment and take measures to minimise privacy impact. A summary is available on request.
Pseudonymised vs. anonymised: Analytics data that we collect is pseudonymised, meaning it could in principle be linked back to you through additional information that we keep separately and securely. Where we use data for aggregate reporting or statistical analysis, we take further steps to anonymise it. Anonymised data is no longer personal data under GDPR.
1.6 Authentication and subscription data
Apple Sign-In
Data: Email address and technical authentication information from Apple Sign-In. We never receive your Apple ID password.
Purpose: To authenticate you securely and allow sign-in to your account.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)): necessary to provide login and account access.
Subscription and purchase data (RevenueCat)
Data: Subscription status, product identifiers, purchase history (e.g. active subscription, renewal information, platform purchase receipts).
Purpose: To manage your subscription, verify entitlements, and handle upgrades, downgrades, and cancellations.
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)): necessary to provide paid features and manage your subscription; and, where applicable, compliance with legal obligations (e.g. bookkeeping) (GDPR Art. 6(1)(c)).
1.7 Push notification and reminder preferences
Data: Your push notification opt-in status and reminder schedule preferences.
Purpose: To send you session reminders and other notifications you have opted in to receive.
Legal basis: Consent (GDPR Art. 6(1)(a)): you can enable or disable push notifications at any time through your device settings or in-app preferences.
1.8 Health data from Apple Health (HealthKit) and Google Health Connect
Data: Heart rate variability (HRV) and heart rate data read from Apple Health (HealthKit) or Google Health Connect after a completed breathwork session. WeHale reads this data passively; we do not write data to Apple Health or Google Health Connect. This data is stored server-side in our database (hosted by Supabase) to enable trend calculations, weekly progress tracking, and post-session biometric feedback. It is encrypted in transit (HTTPS) and deleted upon account deletion.
Purpose: To display post-session biometric feedback ("Afterglow") that shows how the breathwork session affected your heart rate variability and heart rate, helping you understand the physiological impact of your practice over time. This data is not used to diagnose, treat, or prevent any medical condition.
Legal basis: Explicit consent (GDPR Art. 9(2)(a)). HRV and heart rate data constitute health data under GDPR Article 9 and are classified as special category data. We will only access this data after you have granted explicit permission through the iOS HealthKit permission prompt or the Android Health Connect permission prompt. You may revoke access at any time via your device's settings (iOS: Settings → Privacy & Security → Health → WeHale; Android: Settings → Health Connect → App permissions → WeHale). Revoking access will not affect the lawfulness of processing carried out prior to revocation, but WeHale will no longer be able to display biometric feedback for future sessions.
Platform health data compliance: In accordance with Apple's HealthKit guidelines and Google's Health Connect policies, data obtained through these platforms is not used for advertising, marketing, or sale to data brokers or information resellers. Health data is not shared with third parties without your explicit consent, except as required to provide the core functionality described above. We do not use health data to serve advertising or to build user profiles for purposes unrelated to health or fitness.
2. How We Use Your Data
We use the data collected for the following purposes:
- Provide and personalise the WeHale service (weekly progress tracking, session recommendations, check-in tracking, user account management).
- Power our AI-based session recommendation engine (see section 2.1 below).
- Authenticate you and provide secure access to your account.
- Manage subscriptions and payments via our third-party providers.
- Send transactional emails (password resets, account confirmations, important service notifications) and, where opted in, push notification reminders.
- Improve app quality and user experience through pseudonymised and aggregated analytics.
- Analyse marketing attribution data to understand how users discover WeHale and to measure the effectiveness of marketing channels.
- Respond to support requests and communicate with you regarding issues or feedback.
- Maintain the security and integrity of our systems and prevent abuse.
- Generate aggregated, anonymised insights about the effectiveness of breathwork sessions for product development and, in future, evidence-based B2B reporting.
- Display post-session biometric feedback using heart rate variability (HRV) and heart rate data read from Apple Health (HealthKit) or Google Health Connect, where you have granted access (see section 1.8).
We do not use your personal data for advertising purposes or sell your personal data to any third party.
2.1 Automated session recommendations
WeHale uses an AI-powered recommendation engine to suggest breathwork sessions tailored to you. This engine processes your check-in data (stress level, post-session mood or emotional state), time of day, and session history. Your check-in data is sent to Anthropic's Claude API (see section 4) to generate personalised session recommendations. Biometric data (heart rate, HRV) is never sent to Anthropic or any other AI service; it is only used locally and server-side for trend calculations and post-session feedback. The recommendations do not produce legal or similarly significant effects.
Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our recommendations are suggestions only and do not restrict your access to any content: you can always browse and choose any session manually. If you have concerns about how recommendations work, please contact us at support@wehale.io.
3. Data Storage and Security
Your personal data is stored in Supabase-hosted PostgreSQL databases located within the European Union (EU). We apply the following technical and organisational security measures:
- TLS encryption for all data in transit.
- Encryption at rest for stored data, where supported by our infrastructure providers.
- Access to production systems restricted to authorised personnel only and based on the need-to-know principle.
- Regular review of access controls, security practices, and third-party security measures.
We aim to store only the minimum amount of personal data necessary for the stated purposes and to limit access to that data as far as possible.
4. Third-Party Services
We share data with the following processors who provide services on our behalf. These providers process personal data only in accordance with our instructions and for the purposes described below.
- Supabase: database and file storage (EU-hosted). Used to store account, session, check-in, and related app data.
- Mixpanel: product analytics. We configure Mixpanel to process pseudonymised usage and attribution data to understand app usage and improve our service. Mixpanel is a US-based service. Transfers to the US are safeguarded through Standard Contractual Clauses (SCCs) in accordance with GDPR Chapter V, and we implement additional technical and organisational measures (such as limiting the categories of data shared) to protect your privacy.
- Apple Sign-In: authentication. We receive only the email address associated with your Apple account (if you choose to share it) and technical tokens needed for sign-in. We never receive your Apple ID password.
- RevenueCat: subscription management. RevenueCat processes information about your subscription status and purchase history on our behalf, to enable and manage your paid access to WeHale features.
- Railway: application hosting and backend infrastructure. Railway hosts the WeHale backend services through which all personal data passes during normal use of the app (including account data, session data, check-in data, and API requests). Railway is a US-based service; transfers are safeguarded through Standard Contractual Clauses (SCCs) and technical measures including encryption in transit and at rest.
- Anthropic (Claude API): AI-powered session recommendations. When you complete a pre-session check-in, your self-reported stress level and mood data are sent to Anthropic's Claude API to generate a personalised session recommendation. Anthropic does not use this data to train its models when accessed via the API. Anthropic is a US-based service; transfers are safeguarded through Standard Contractual Clauses (SCCs) and Anthropic's data processing addendum.
- Loops (Astrodon Inc.): email delivery service. Loops processes your email address on our behalf to deliver marketing communications and transactional emails (such as password resets and account notifications). Email delivery infrastructure is provided by Amazon Simple Email Service (Amazon SES). Loops (Astrodon Inc.) is a US-based service; transfers are safeguarded through Standard Contractual Clauses (SCCs) and Loops' data processing agreement (available at loops.so/dpa).
We do not sell your personal data to any third party, and we do not share your personal data with third parties for their own direct marketing.
5. Disclosure of Personal Data
In addition to sharing data with the processors listed in section 4, we may disclose your personal data in the following circumstances:
- Legal obligations and law enforcement: Where we are required to do so by applicable law, court order, or a binding request from a competent authority (GDPR Art. 6(1)(c)). We may also disclose data where reasonably necessary to protect our legal rights, enforce our terms of use, or protect the safety of our users or the public (GDPR Art. 6(1)(f)).
- Business transfers: In connection with a merger, acquisition, restructuring, sale of assets, or similar corporate transaction involving all or part of Andningsappen Varberg AB. In such cases, your personal data may be transferred to the acquiring party. We will notify you before your data becomes subject to a different privacy policy.
- Professional advisors: To accountants, auditors, lawyers, and other professional advisors, subject to appropriate confidentiality obligations.
6. Cookies and Tracking Technologies
Our websites (wehale.io and wehale.io/business) may use cookies and similar tracking technologies to provide functionality, remember your preferences, and collect analytics data.
- Strictly necessary cookies: Required for the website to function properly (e.g. session management). These do not require your consent under the ePrivacy Directive.
- Analytics cookies: Used to understand how visitors interact with our websites (e.g. via Mixpanel or similar tools). These cookies are only placed with your consent, which you can manage through our cookie banner or by contacting us at support@wehale.io.
We do not use cookies for advertising purposes or share cookie data with advertising networks. For more information about cookies and how to manage them in your browser, visit www.allaboutcookies.org.
7. Marketing Communications
We may send you marketing emails about new features, subscription offers, tips, and other content related to the WeHale service that we believe may be of interest to you. We only market our own products and services and never share your contact details with third parties for their marketing purposes.
Legal basis: The legal basis for marketing communications depends on your relationship with WeHale:
- Users with an existing customer relationship (free trial or paid subscription): Legitimate interest (GDPR Art. 6(1)(f)) in combination with the "soft opt-in" exception under the Swedish Electronic Communications Act (6 kap. 4 § LEK), implementing Article 13(2) of the ePrivacy Directive. This means we may send you marketing emails about WeHale's own similar products and services without separate opt-in consent, provided that you were given the opportunity to opt out when you signed up and that every email includes an easy way to unsubscribe. If you started a free trial or purchased a subscription, you have an existing customer relationship with us.
- Users without an existing customer relationship (free account without trial or subscription): Consent (GDPR Art. 6(1)(a)). We will only send you marketing emails if you have actively opted in. You will not be subscribed to marketing emails by default.
Opt-out: Regardless of which legal basis applies to you, you may unsubscribe from marketing emails at any time by clicking the "unsubscribe" link included in every marketing email, by adjusting your preferences in the app under Settings, or by contacting us at support@wehale.io. We will process your opt-out request without delay. Opting out of marketing emails does not affect transactional emails (such as password resets, account confirmations, and important service notifications), which we will continue to send as necessary to operate your account.
8. International Data Transfers
Personal data may be transferred to and processed in countries outside the EU/EEA, including the United States, where some of our service providers are located.
Where our processors or sub-processors are located outside the EU/EEA (for example, Mixpanel, Railway, Anthropic, and Loops in the United States), we ensure that appropriate safeguards are in place for international transfers of personal data, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Technical and organisational measures, such as encryption, access controls, and data minimisation.
You can contact us if you would like more information about our international transfer safeguards.
9. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected or as required by law. Retention periods are determined based on the purpose and applicable legal requirements for each category of data.
- Account data: We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days of your request, unless we are required by law to retain certain information for a longer period (e.g. for bookkeeping or legal claims).
- Check-in and wellness data: Retained for as long as your account is active and deleted or anonymised upon account deletion, subject to the same 30-day processing period.
- Health data (HRV, heart rate): Retained for as long as your account is active and deleted or anonymised upon account deletion, subject to the same 30-day processing period. If you revoke health data access, no new data will be read, but previously collected data will be retained until account deletion unless you request earlier erasure.
- Subscription and payment-related data: May be retained for longer periods where required by applicable accounting and tax laws.
- Support communications: Retained for a reasonable period to handle your request and maintain a history of issues.
- Analytics data: Pseudonymised analytics data is retained for as long as reasonably necessary for analysis purposes. Fully anonymised analytics data, which cannot be linked back to you, may be retained indefinitely for statistical and product development purposes.
10. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right to access: You may request a copy of the personal data we hold about you, along with information on how it is processed. We will respond within 30 days, free of charge, unless requests are manifestly unfounded or excessive.
- Right to rectification: You may request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure ("right to be forgotten"): You may request that we delete your personal data where it is no longer necessary for the purposes it was collected, where you have withdrawn consent (if applicable), or where processing is unlawful. Requests will be fulfilled within 30 days, subject to legal retention obligations.
- Right to restriction of processing: You may request that we restrict the processing of your data, for example while we verify the accuracy of data you have disputed or pending the outcome of an objection.
- Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible and where the processing is based on consent or contract and carried out by automated means.
- Right to object: You have the right to object to the processing of your personal data where we rely on legitimate interest as our legal basis. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
- Right to withdraw consent: Where processing is based on your consent (e.g. push notifications), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- Right related to automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our AI recommendations do not produce such effects (see section 2.1), but you may contact us if you have concerns.
To exercise any of these rights, please email us at support@wehale.io. We will respond within 30 days of receiving your request.
If we offer in-app features such as "Delete account" or "Export data", you may also use those features to exercise your rights directly in the app. In such cases, the technical actions will normally be carried out immediately, while some backend deletions may take up to 30 days.
11. Right to Lodge a Complaint
You have the right to lodge a complaint with the Swedish data protection supervisory authority if you believe we have processed your personal data in a manner that does not comply with applicable law:
Integritetsskyddsmyndigheten (IMY)
Website: www.imy.se
Email: imy@imy.se
You may also lodge a complaint with your local supervisory authority within the EU/EEA. However, we would appreciate the opportunity to address your concerns directly before you contact a supervisory authority. Please reach out to us at support@wehale.io.
12. Children's Privacy
WeHale is not intended for individuals under the age of 16. We do not offer the Service directly to children within the meaning of Article 8 GDPR. We do not knowingly collect personal data from children under 16, and we do not design or market our service specifically to children.
In Sweden and most EU member states, the minimum age for consent to data processing for information society services is between 13 and 16 years under GDPR Article 8. We have chosen to make WeHale a service intended for users aged 16 and above, and we expect that only individuals who are at least 16 years old create an account and use the app.
If you believe a child under 16 has provided us with personal data, please contact us at support@wehale.io and we will delete the data and, if applicable, the account promptly.
13. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technologies, or legal obligations. The updated policy will be posted on this page with a revised effective date.
For material changes (for example, changes to the types of data we collect, the purposes for which we use it, or our sharing practices), we will notify you in advance via email or through an in-app notification. Where such changes involve new processing activities that require a different legal basis (e.g. consent), we will obtain the appropriate authorisation before commencing the new processing. Your continued use of WeHale after notification constitutes acceptance of changes that do not require separate authorisation.
14. Contact
If you have any questions, concerns, or requests relating to this privacy policy or how we handle your personal data, please contact us:
Andningsappen Varberg AB (WeHale)
Boråsgatan 12 B, 432 45 Varberg, Sweden
Organisation number: 559496-1491
Email: support@wehale.io