Privacy Policy

Halera collects your account email, the health data you choose to log, and seven named analytics events. It never sells data, never shows ads, and never sends anything you log to its analytics provider. You can export or delete everything from inside the app at any time.

This Privacy Policy explains how Halera ("Halera", "we", "us"), operated by Lee Crowe Software Solutions LLC, collects, uses, stores, and protects your information when you use the Halera mobile app and this website (together, the "Service"). Halera is a personal wellness-tracking tool. It is not a medical device and does not provide medical advice.

1. What information does Halera collect?

Account information

When you create an account we collect your email address and a securely hashed password (handled by our authentication provider — we never see your plaintext password).

Health & wellness data

Halera stores only what you choose to log, which may include: food and drink entries (calories, protein, carbohydrates, sodium, fluids), hydration, intermittent-fasting windows, body weight, blood-pressure readings, mood, symptoms, bowel-movement logs, and profile details you provide (such as height, age, sex, activity level, and personal goals).

If you connect Apple Health or Health Connect, Halera also receives the workout, weight and height data you approve there. This is optional and off unless you turn it on. The Consumer Health Data Privacy Policy describes exactly what is requested and how to disconnect.

Sensitive data & your consent

The health and wellness data described above is sensitive personal data under applicable state privacy laws. By creating a Halera account and choosing to enter this data, you consent to our processing it as described in this policy. You can withdraw that consent at any time by deleting your account and data (Profile & goals → "Delete account & all data"), which stops all further processing and removes what we hold.

Product analytics — exactly what we collect

We use one third-party product-analytics tool, PostHog (PostHog, Inc., US Cloud), acting as our processor under its Data Processing Addendum, to understand how people find Halera and where they get stuck. We have deliberately kept it away from anything you log. Here is precisely what it does and does not receive.

Inside the Halera app, we send only these named events:

first_entry_logged and returned_second_day were added on and reach users with the next app release; versions before that send the other five only. Both are counts that something happened once. Neither carries what was logged, when, or how much.

That is the complete list. Alongside an event we send a random account identifier and standard technical information (device and OS type, app version, screen size, language, time zone). Our analytics provider is configured to discard your IP address and not derive any location from it.

Halera never asks for location permission and never reads your device's location.

App versions before the PostHog switch send the same seven events to HeyCatch, our previous provider. HeyCatch deletes Halera's data within two months of our subscription ending.

What is never sent from the app: nothing you log. Not food or drink entries, calories, macros, weight, blood-pressure readings, fasting windows, hydration, sleep, mood, symptoms, bowel movements, caffeine, alcohol, photos, or anything in your profile such as height, age, sex or goals. Your name and email address are not sent either.

We enforce this in the app's code, not by policy alone: the entire signed-in area of the app is marked so the analytics tool cannot automatically record taps, screens or on-screen text inside it. The only analytics data that leaves the app is the short list of events above, which we write by hand.

This website

On gethalera.com we count page visits, the page or site that referred you, any campaign tag in the link (such as ct= or utm_), device and browser type, and taps on the App Store and Google Play buttons. The website sets no analytics cookies and stores nothing in your browser. Visitors are counted with a one-way hash that our analytics provider rotates daily and cannot reverse. Your IP address is not stored and is not used to work out your location. This is ordinary website analytics and is separate from the app. It has no access to your account and never sees any health or wellness data.

Cookies and local storage

The website uses no analytics cookies and stores nothing in your browser for analytics. In the app, analytics keeps a random identifier in on-device storage so that opt-in events can be linked across sessions; that identifier is cleared on sign-out or when you turn analytics off. We use no advertising cookies and no cross-site tracking.

We do not sell your data — and we never will

We do not sell your personal information, your health data, or your analytics data to anyone, for any price. We do not share it with advertisers, data brokers or marketing networks, and we do not use it to build advertising profiles. Halera shows no ads at all.

Analytics data exists for one reason: to make Halera better. The events show which parts of the app confuse people, where new users give up before getting any value, and whether a change actually helped.

There is no second purpose. Before using analytics data for anything beyond product improvement, Halera would update this policy and say so in the app first.

Other automatically collected information

Our hosting providers may process limited technical information (such as IP address and request metadata) as needed to operate and secure the Service.

2. How does Halera use your information?

We do not sell your personal or health information, and we do not use it for advertising.

3. What happens when Halera estimates a food?

When you ask Halera to estimate nutrition or calories, the text you enter (for example, "grande latte" or "30 minute walk") is sent to our server, which queries the U.S. Department of Agriculture (USDA) FoodData Central database and/or Microsoft Azure OpenAI Service to generate an estimate. These lookups are used only to return your estimate. We do not send your identity, email, or your broader health log to these lookups beyond the specific text needed for the estimate.

If you use the photo-estimate feature, the meal or nutrition-label photo you submit is sent to Microsoft Azure OpenAI Service to generate the estimate, then discarded — we don't retain the photo itself, only the resulting estimate you choose to save. Per Microsoft's Azure OpenAI terms, this content is not used to train their models.

4. Who does Halera share your data with?

Where Halera's data goes Your log is stored in Halera's Microsoft Azure environment in the United States. Photos and typed descriptions go to Azure OpenAI to produce an estimate and are then discarded. Analytics receives only event names and a random identifier, never anything you log. Nothing goes to advertisers or data brokers. Your phone Food, weight, BP, fasting, symptoms HTTPS Your account Microsoft Azure, US Encrypted in transit Sign-in required Azure OpenAI Photo or description in, estimate out, then discarded — not stored Analytics (PostHog) Seven event names and a random ID. No name, no email, nothing you log. Advertisers, data brokers, ad networks — never
Where your data actually goes. Your log lives in Halera's Azure environment in the United States. A photo or description sent for an AI estimate is used to produce that estimate and then discarded. Analytics never receives anything you log. Nothing is sold, and nothing goes to advertisers or data brokers.

We share information only with vendors that help us run the Service, under their respective terms:

We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the Service.

5. Where is your data stored, and how is it protected?

Your health log is stored in our Microsoft Azure environment, currently in the United States. Data is transmitted over encrypted connections (HTTPS/TLS) and access to your data requires a verified sign-in to your account. While no system is perfectly secure, we take reasonable measures to protect your information.

If a breach of security compromises your unsecured health information, we will notify you and, where required, the Federal Trade Commission, in accordance with the FTC Health Breach Notification Rule.

6. How long is your data kept, and how do you delete it?

We keep your data while your account is active.

You can delete your account and all associated data at any time from within the app (Profile & goals → "Delete account & all data"). You can also export your log as a spreadsheet at any time.

7. What rights do you have over your data?

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Halera is built so you can do these yourself in-app; for anything else, contact us and we will help. This may include rights under laws governing consumer health data, such as the FTC Health Breach Notification Rule, the Washington My Health My Data Act, the California Confidentiality of Medical Information Act, and the Kentucky Consumer Data Protection Act (KCDPA), as applicable.

Appeal process

If we deny a request you've made to exercise one of these rights, we will explain why and tell you how to appeal by replying to our decision or emailing privacy@gethalera.com with "Appeal" in the subject line. We will respond to your appeal within 60 days with a written explanation of our decision. If we deny your appeal, we will provide you with a way to submit a complaint to the Kentucky Attorney General's Office.

8. Can children use Halera?

Halera is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

9. How will you be told if this policy changes?

We may update this policy from time to time.

We will reflect any changes by updating the "Last updated" date above. For material changes — those that expand the categories of data we collect or how we share it — we will also notify you in-app or by email before the change takes effect.

10. How do you contact Halera about privacy?

Questions about privacy? Email privacy@gethalera.com. Governing law: the Commonwealth of Kentucky.