TALLAWA · SMALL BUT MIGHTY

Privacy Policy

How Tallawa handles personal and sensitive whole-person wellness data, plus the controls that remain yours.

Version 2026.08.26 · Effective August 26, 2026

Data you choose to provide

Tallawa stores account and profile details, body measurements, goals, meals, workouts, weight, fasting records, routines, supplements or medication schedules, mood check-ins, optional reflections, and any spiritual path or practice you explicitly enable.

Photos and AI conversations may contain health information. Private media is stored in owner-only storage and delivered with short-lived signed links.

If you connect Apple Health or Health Connect, Tallawa stores only the categories you select, normalized values, time range, source app or device, provider revision, and sync cursor. Tallawa does not retain raw provider payloads or routes and does not write records back to your health store.

How Tallawa uses data

We use your data to provide tracking, schedules, progress summaries, reminders, subscriptions, support, security, and the recommendations you request. Deterministic safety rules run before optional AI features.

Tallawa records a limited vocabulary of product outcomes such as onboarding completion, paywall readiness, restore result, Today viewed, and export started. These events may include only short allowlisted fields such as outcome, source, app version, and platform. Raw medication, mood, journal, prayer, reflection, image, AI prompt, and other user-authored content is blocked from this ledger and is not used for advertising audiences.

AI and service providers

Supabase provides authentication, database, storage, server functions, and the private product-outcome ledger. RevenueCat processes subscription identifiers and purchase state. OpenAI processes only the minimum authorized context needed when you invoke an AI feature. Apple or Google process app-store purchases and provide optional on-device health stores when you connect them.

AI output can be wrong and is not medical, diagnostic, prescribing, crisis, or religious authority. Core meal, workout, routine, fasting, and reflection logging remains available without AI.

Sensitive wellness and spiritual choices

Medication, fasting, mood, journal, faith identity, prayer, and reflection records are treated as sensitive. Spirituality is opt-in, “none” is a full choice, and Tallawa never infers religion from identity, location, food, or behavior.

You can disable optional modules without losing unrelated fitness or nutrition data. Private notification wording is available for sensitive routines.

Your controls

The Data & Privacy center creates a versioned, portable export including your records, connected-health imports and cursors, product-outcome events, and private media. Connected Health also provides pause, disconnect, and delete-imported-data controls. Account deletion removes your authentication identity, database records, private media, and RevenueCat customer data. Store subscriptions must be cancelled separately through Apple or Google.

Contact privacy@tallawa.com for access, correction, portability, objection, restriction, or deletion questions. Applicable legal retention may require us to preserve a limited record, which we will disclose when relevant.

Security, retention, and changes

Tallawa uses authenticated access, row-level ownership rules, private storage, server-side subscription checks, input limits, and credential separation. No internet service can guarantee absolute security.

We keep account data while you use Tallawa and only as long as needed for the purposes above or applicable law. Material policy changes receive a new version and an in-app notice before new sensitive processing where required.

Questions or requests?

Privacy requests: privacy@tallawa.com

Support and legal questions: support@tallawa.com