Legal
Effective date: September 13, 2026
Version: 2.1
What changed in Version 2.1: we corrected the description of how document files are stored (they are not included in device backups; §2.5, §2.9, §6.2), corrected the list of device permissions Gavia does not use (§3), and added Resend to the list of providers in §5, because Resend began delivering our sign-in code emails on September 13, 2026. Section 13 promises 30 days' notice before a change like the Resend addition; we did not meet that for this change, and we have changed our process so that new providers are disclosed here before they go live. This version took effect on posting so that it describes our actual practice. We notified account holders by email and in the app the same day. Continued use will be treated as acceptance of this version from October 13, 2026; until then you may export your data and delete your account without being bound by it.
Gavia Health LLC ("Gavia," "we," "us," or "our") makes the Gavia iOS application and operates the website at gaviahealth.com (together, the "Services"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
We wrote this in plain English because you should be able to read it. Where we have to be precise, we are. If anything is unclear, email privacy@gaviahealth.com and we will answer you and, if we can, improve the sentence.
Gavia Health LLC is a limited liability company organized in Virginia, United States. We are the data controller for the personal information described in this Policy.
This is the heart of the product and the most sensitive information we hold. Depending on what you choose to track, it may include:
Gavia includes self-monitoring tools for mental wellbeing:
Your answers are stored with the same encryption as all other health data, in their own table. Section 8 explains how this information is handled differently from the rest of your data, including that it is never sent to our AI provider.
If you choose to connect Apple Health, Gavia requests read-only access to five types of data: step count, active energy, exercise minutes, sleep analysis, and weight. Readings are saved into your Gavia log, labeled as Apple Health entries, and then treated exactly like data you log manually: same encryption, same sync, same export and deletion rights. Gavia never writes to Apple Health. We do not use Apple Health data for advertising or marketing (we have neither), and we do not sell it or share it with anyone except the processors in Section 5 that store your data on your behalf.
You may add documents to Gavia, such as lab results, doctor notes, or insurance cards, and organize them in folders. The document files themselves stay on your device only. They are not uploaded to our servers. Document names, folders, dates, and links to timeline events are synced to your account. Document files are stored only on your device and are not included in device backups. If you delete the app or lose your phone, they cannot be recovered, so keep your own copies of anything important. Section 6.2 explains how files on your device are protected.
Your subscription status: which plan you have, whether you are in a trial, grace period, active, or lapsed, and the relevant dates. This comes to us through Apple via our subscription-management provider, RevenueCat. We never receive your payment card number, billing address, or bank details. Apple handles payment entirely.
If the app crashes or hits an error, a report is sent to our crash-reporting provider, Sentry. Before it leaves your device, we strip it: names, emails, medication names, diagnoses, notes, tokens, and other personal values are removed or replaced. What remains is the error type, the screen you were on, the app version, and device and OS information, plus your internal user ID so we can tell whether one person or many hit the same bug. Crash reporting is disabled entirely in development builds.
When you use an AI feature, our server records the event (which feature, whether it succeeded, and related technical details) against a pseudonymous version of your user ID. We keep this to enforce daily limits, detect abuse, and account for cost. It contains no health content or message text. Because the pseudonym is derived from your ID, we treat these records as personal data and delete them when your account is deleted.
Some information never leaves your phone: custom foods, favorite foods, saved Learn articles, and unit preferences, which are not backed up to your Gavia account and will be lost if you delete the app or switch phones without an iOS backup; and document files (Section 2.5), which are excluded from device backups entirely and will be lost if you delete the app or lose your phone. GutGuide chats are not stored at all, on your phone or anywhere else; they exist only while the chat screen is open (Section 4.4).
gaviahealth.com is a static site. It sets only essential cookies and runs no analytics. If you join the Android waitlist, we collect the email address you provide for that purpose only.
We have no advertising, analytics, attribution, or A/B-testing software in the app. The only third-party software that communicates from the app is our crash reporter and our subscription-management SDK, each scoped as described in Section 5.
| We use | To |
|---|---|
| Account information | Create and secure your account, verify age, record consent, and communicate with you about the Services. |
| Health, mental health, and Apple Health data | Show you your own dashboards, charts, trends, reminders, and reports; power the AI features when you invoke them; keep your history safe across devices. Nothing else. |
| Subscription information | Grant and manage access to Gavia Pro. |
| Diagnostic information | Find and fix bugs. |
| AI usage records | Enforce usage limits, prevent abuse, and account for costs. |
We do not use your information for advertising, profiling, marketing to you based on your health, or any purpose not listed here. If we ever want to, we will change this Policy first and notify you under Section 13.
Where the GDPR or UK GDPR applies, we rely on: your explicit consent (Article 9(2)(a)) for processing health and mental-health data, which you give by accepting this Policy during onboarding and may withdraw at any time by deleting your account or emailing us; performance of our contract with you (Article 6(1)(b)) for account, subscription, and service delivery; and our legitimate interests (Article 6(1)(f)) in keeping the Services secure and functioning, for diagnostic information and AI usage records. Withdrawing consent does not affect processing that happened before withdrawal.
Gavia has four AI features: GutGuide, a chat assistant about your tracked patterns; the AI summary in your Health Insights Report; the GI message drafter, which helps you draft a message to your care team; and appointment prep, which prepares discussion points for an upcoming appointment. All four are available to Gavia Pro subscribers, use the same AI provider, and run only when you invoke them (by sending a message, generating a report, or using a tool). There is no background AI processing.
All AI requests go through our server, which checks that you are signed in, that you have an active subscription, and that you are within your daily limit, before anything is sent to our AI provider, Anthropic.
What is sent to the AI provider for a request:
What is never sent to the AI provider:
Anthropic processes each request solely to generate your response, retains request and response data for up to 30 days, and does not use your data to train its models. We have requested a zero-retention configuration and will update this sentence when it is in effect.
AI-generated content is informational. It is produced under server-side instructions that prohibit diagnosis and treatment directives, and every response carries a disclaimer. It is not reviewed by a clinician. See the Terms of Service, Section 6.
Your GutGuide conversation exists only in the app's memory while the chat screen is open. It is not saved to your device's database and is not synced to your account. When you leave the screen, it is gone. We do not keep a copy on our servers.
We share personal information only with the service providers below, each of which processes it on our behalf, under contract, for a single purpose. We have no other recipients. This table is complete as of the effective date; adding a provider is a material change under Section 13.
| Provider | Purpose | What it receives | What it does not receive |
|---|---|---|---|
| Supabase, Inc. | Hosts our database, authentication, and server functions (Northern Virginia, USA) | Everything in your cloud account, encrypted at rest by the platform | Payment details |
| JourneyApps (PowerSync) | Moves data between your device and your cloud account | Your own records, in transit, scoped to your account | Anything outside your own account |
| Anthropic, PBC | AI provider for GutGuide and report summaries | The de-identified request contents described in Section 4.3 | Your identity, mental-health data, documents, or raw diary |
| RevenueCat, Inc. | Manages subscription state | Your subscription events from Apple, your internal user ID, and standard app and device metadata its SDK collects | Any health data. We do not enable its advertising-identifier collection. |
| Functional Software, Inc. (Sentry) | Crash and error reporting | Scrubbed crash reports (Section 2.7) | Health content, names, emails |
| Apple, Inc. | App distribution, in-app purchase, Sign in with Apple, Apple Health (on-device), local notifications | Your purchase and payment; sign-in identity if you use it | Your health data (Apple Health access is read-only and on-device) |
| Google LLC | Google Sign-In, if you use it | Sign-in identity | Any health data |
| Resend, Inc. | Delivers sign-in code emails on our behalf (United States) | Your email address and the six-digit sign-in code, sent from our server | Any health data; the app never contacts Resend directly |
| Expo (EAS) | Builds the app binary | Nothing about you at runtime | Any user data |
Apple Maps. If you tap a care-team provider's address, the app opens Apple Maps with that address. That address is then handled by Apple under Apple's privacy policy. Nothing else is sent.
We do not sell your personal information and have never done so. We do not share it with advertisers, data brokers, insurers, employers, or researchers. We do not "share" it for cross-context behavioral advertising as that term is defined in California law.
Legal requests. We will disclose information if required by a valid legal order. Where the law allows, we will tell you before we do so, and we will disclose only what is required.
Business transfers. If Gavia is acquired or merges with another company, your information may transfer to the successor. We will notify you before your information becomes subject to a different privacy policy, and you will have the chance to export or delete your data first.
Your Gavia database is encrypted at rest using SQLCipher with a 256-bit key generated on your device. That key is stored in the iOS Keychain with a protection class that prevents it from being copied to any other device, including through iCloud Keychain. The key is never transmitted to us or logged.
Document files (Section 2.5) are stored in the app's private folder on your device, protected by iOS Data Protection, which encrypts them when your device is locked. They are not encrypted by Gavia's own key and are not uploaded to our servers. Document files are stored only on your device and are not included in device backups. If you delete the app or lose your phone, they cannot be recovered.
All communication between the app and our servers, and between our servers and our providers, uses TLS 1.2 or higher. The app does not permit unencrypted connections.
Your data is stored in a PostgreSQL database with row-level security: every table that holds user data carries a database-enforced policy limiting reads and writes to the account that owns the row. Subscription status, report quotas, and AI usage records are writable only by our server, never by the app.
Like any company that operates a database, we have administrative access to it. That access exists for operations, debugging, and support. Today it is limited to our founder. It is used only when operating the Services requires it and never for analytics, profiling, or marketing. We do not have a formal access-control or audit-logging program yet; as we grow, we will add one and update this section. We would rather tell you this than tell you a comforting fiction.
We have designed Gavia to collect as little as possible and to protect what it holds. No system is immune to compromise. We recommend keeping your own copy of records that matter to you; the export feature exists for this.
We keep your data for as long as your account exists. Gavia is a longitudinal record, so we do not automatically purge old entries. You can delete individual entries at any time in the app. Letting your subscription lapse changes nothing about retention: your data stays exactly as it was.
You can delete your account from Settings → Delete Account in the app, without a subscription. When you do:
Two things deletion does not do: it does not cancel your Apple subscription (manage that in iPhone Settings → your name → Subscriptions; see the Terms), and it does not delete the customer record our subscription provider, RevenueCat, holds, which contains your subscription history and internal ID but no health data. Email us if you want that record removed as well.
These rights are available to every user, in every country, whether or not you have a subscription.
We will respond to rights requests within 30 days (45 days where US state law allows and we tell you we need the time). We do not charge for requests and we do not discriminate against anyone for exercising their rights. We may need to verify your identity; the simplest way is to email from your account address.
Residents of California, Virginia, Colorado, Connecticut, Texas, Oregon, and other states with comprehensive privacy laws have rights to access, correct, delete, and port their data, and to opt out of sales, targeted advertising, and profiling. Gavia does not sell data, run targeted advertising, or profile users, so there is nothing to opt out of; the remaining rights are delivered through the app and email as described above. Health data is "sensitive data" under these laws; you consent to its processing by accepting this Policy, and you can withdraw that consent by deleting your account. California residents: we have not sold or shared personal information in the preceding 12 months; we collect the categories listed in Section 2 for the purposes in Section 4; you may designate an authorized agent by emailing us.
If you are a Washington or Nevada resident, our Consumer Health Data Privacy Policy at gaviahealth.com/consumer-health-data sets out the disclosures those states require.
In addition to the rights above, you have the rights to restrict or object to processing and to data portability. Our legal bases are in Section 4.2.
Gavia is not directed to children. You must be at least the minimum age of digital consent in your region to create an account (13 in the United States, United Kingdom, and Canada; 13 to 16 across the EEA, as the app enforces per region; 13 elsewhere by default). The app asks your age before you can use Gavia and does not keep an account or any data for anyone under the minimum. If you believe a child under the applicable age has an account, email privacy@gaviahealth.com and we will delete it.
Gavia's servers are in the United States (Northern Virginia), and all processing, including by the providers in Section 5, takes place in the United States. If you use Gavia from another country, your information is processed in the United States, where privacy laws may differ from those of your country. We apply the protections in this Policy to every user regardless of location. For EEA and UK users: we collect your data directly from you and process it under the safeguards described here; our processors are bound by data-processing agreements; and you may contact us at privacy@gaviahealth.com for any matter relating to your data.
If we discover a security incident affecting your personal information, we will notify you by email without undue delay and within the time required by applicable law, telling you what happened, what information was involved, what we have done, and what you can do. We will also notify regulators where the law requires it.
We will update this Policy when the product or the law changes. For material changes, meaning anything that expands what we collect, how we use it, or who we share it with, we will email the address on your account and show a notice in the app at least 30 days before the change takes effect. Continuing to use Gavia after the effective date means you accept the updated Policy; if you do not, you can export your data and delete your account before then. Clarifications and corrections that do not change our practices take effect when posted, with an updated date.
Gavia Health LLC
Virginia, United States
Privacy and data requests: privacy@gaviahealth.com
Security reports: security@gaviahealth.com
Legal notices: legal@gaviahealth.com
Support: support@gaviahealth.com
French versions of this Policy and the Terms of Service will be published at gaviahealth.com within eight weeks of launch. Until then, the English versions apply.
Medical disclaimer. Gavia is not a medical device. The Services do not diagnose, treat, cure, or prevent any disease or condition. Screening tools in Gavia are self-monitoring instruments, not diagnostic tools. AI-generated content is informational only and does not replace professional medical advice. Always consult your gastroenterologist or another qualified healthcare provider before making decisions about your treatment. If you are in crisis, contact your local emergency number or crisis line.