Privacy policy · WellFirst
WellFirst

Privacy policy

Last updated: 3 September 2026

The short version

This policy covers two distinct things: the wellfirst.app website and the WellFirst mobile app. In short:
  • the website uses no cookies and no advertising trackers; its audience measurement is anonymous and cookie-free; the only personal data it collects is the email address you choose to leave;
  • the app requires an account (email and password) and stores your daily Check-in answers;
  • you are never required to use your real name — a pseudonym is fine;
  • if a coach is linked to you, they can see your answers and your Score;
  • you can delete your account and all your data from inside the app, in two taps, without writing to us.

Each point is detailed below. This is the page referenced by the App Store and the Google Play Store.

Data controller

The controller of your personal data is WellFirst, [company name and address, to be completed — see the legal notice].

For any question about your personal data, write to us at hello@wellfirst.app. We answer within one month.

The wellfirst.app website

The only personal data collected on the website is the email address you voluntarily provide when joining the waitlist. It is used solely to:
  • let you know when the app launches, or share product news,
  • reply to you if you get in touch.

Legal basis: your consent (art. 6.1.a GDPR), given by submitting the form.

The website uses no cookies and no advertising trackers. No consent banner is therefore required. It does use two measurement tools provided by our host:

  • Vercel Web Analytics — visit counts and pages viewed. It works without cookies and without a persistent identifier: it cannot recognise you from one visit to the next, nor follow you across other sites.
  • Vercel Speed Insights — page load times, to catch slowdowns.

Neither serves any advertising purpose and neither collects health data. Legal basis: our legitimate interest (art. 6.1.f GDPR) in measuring the audience and performance of the site.

Your account in the app

The app can only be used with an account. Creating one asks for three things:
  • an email address — it is your login identifier and how we reach you;
  • a password — handled by Supabase Auth, our authentication provider: we never see it and it is never stored in clear text, only as a hash;
  • a display name — this is what your coach sees. You are under no obligation to use your real identity: a first name, initials or a pseudonym work perfectly well.

There is no social login, and we collect no phone number, no postal address, no date of birth and no payment card details.

Your Check-in answers

Each day you can complete a Check-in: eight multiple-choice questions, a few follow-ups, and two free-text fields. What is stored is your answers (sleep duration and how you felt on waking, physical activity and perceived intensity, discomfort or pain and the body areas involved, hydration, nutrition, anything that disrupted your habits, your mood for the day), the Check-in date, and the Score computed from those answers.

Two points deserve to be stated plainly:

  • These answers are health data under article 9 GDPR. Simple questions or not, information about your sleep or your pain is health data, and we treat it as such. Legal basis: your explicit consent (art. 9.2.a), given when you create your account and withdrawable at any time by deleting it.
  • These answers are pseudonymised, not anonymised. They are stored under your account's technical identifier, without your name, but that identifier remains tied to your email. It is exactly that link which lets us show you your history and guarantee your right to erasure: truly anonymous data could neither be given back to you nor deleted on request.

The two free-text fields are capped at 200 characters and are yours: write only what you are willing to share with your coach, and avoid precise medical information, contact details, or anything concerning someone else.

Your answers are never used for advertising, never sold, never passed to a data broker, an insurer or an employer, and are not used to train any artificial intelligence model.

What your coach can see

WellFirst can link a Client to a coach. That link only exists because you created it yourself by accepting an invitation from that coach: nobody can attach themselves to your account without that action.

While the link exists, your coach can see:

  • your display name and email address,
  • every one of your Check-in answers, including pain areas and free-text fields,
  • your Score and how it changes over time,
  • your Check-ins from before the link was created, if any — the history is not truncated at the linking date,
  • a notification when you complete a Check-in, if they enabled it.

Your coach can neither edit nor delete your answers, and has no access to any Client other than their own: that separation is enforced by the database itself, not by the app.

If the link is broken, that coach loses access immediately going forward. We can do nothing, however, about anything they may have noted or copied elsewhere during the coaching period.

Notifications

If you allow them, the app stores a notification token specific to your device, along with your time zone, your language and the reminder time you choose. This is used only to send the Check-in reminder at the right local time. It is deleted when you turn notifications off or delete your account. Delivery goes through Apple (APNs) and Google (FCM), as well as Expo.

Subscriptions and payments

The coach subscription is handled by RevenueCat and billed directly by Apple's App Store or the Google Play Store depending on your device. RevenueCat tells us your subscription status (active, expired, end date) and a technical identifier. WellFirst neither collects nor stores any payment card data: your payment method is known only to the platform you subscribed through.

Technical measurement and error reporting

The app uses two technical tools, and no advertising tool at all:
  • TelemetryDeck — aggregate usage measurement (for example: how many Check-ins are completed). Signals are sent without a user identifier and contain no Check-in answers.
  • Sentry — technical error and crash reporting, so we can fix them. No health or payment data is sent to it.

The website uses neither; its own audience measurement is described above.

Processors

We rely on the following providers, each acting as a processor under a data processing agreement:
  • Supabase — the app's database, authentication and server functions, plus storage of waitlist email addresses,
  • Vercel — website hosting and delivery, cookie-free audience measurement and performance measurement,
  • Expo, Apple (APNs) and Google (FCM) — push notification delivery,
  • RevenueCat, Apple and Google — subscription management and billing,
  • Sentry — technical error reporting,
  • TelemetryDeck — anonymous usage measurement.

Hosting and transfers outside the European Union

Application data — your account, your Check-ins and your Scores — is hosted by Supabase in a data centre located in Ireland, within the European Union. It does not leave it in the normal course of running the service.

Some of our providers are, however, established outside the European Union, or belong to companies that are: this is the case for Supabase Inc. itself, Vercel, Apple, Google, Expo, RevenueCat and Sentry, insofar as their technical support may access those systems. Such transfers are covered by the European Commission's standard contractual clauses, alongside the security measures described below.

Retention periods

  • Waitlist email address — until you unsubscribe or it no longer serves a purpose.
  • Account and Check-in answers — for as long as your account exists. The history is the point of the service: there is no automatic deletion after a set period, it is your call.
  • Notification tokens — until notifications are turned off or the account is deleted.
  • Subscription billing data — kept by Apple, Google and RevenueCat under their own policies; on our side the status is deleted with the account.
  • Technical errors (Sentry) — 90 days.
  • Website audience measurement — aggregate data, kept with no way to tie it back to you.

Deleting your account

You can delete your account directly from the app: Settings → Danger zone → Delete my account. No request to us, no justification, no imposed waiting period.

Deletion erases your profile, all of your Check-ins and Scores, your notification tokens and, where applicable, the link with your coach — who loses all access immediately. The operation is immediate and irreversible.

Encrypted database backups may hold a residual copy for at most 30 days, after which it disappears through rotation. Those backups are only ever used for disaster recovery.

If you can no longer access the app, write to us at hello@wellfirst.app from your account email address: see the Deleting your account page.

Your rights

Under the GDPR you have the following rights:
  • Access — obtain a copy of your data,
  • Rectification — correct inaccurate data,
  • Erasure — delete your data, directly from the app,
  • Portability — receive your data in a structured, machine-readable format,
  • Restriction and objection — limit or contest a processing operation,
  • Withdrawal of consent — at any time, without affecting the lawfulness of processing already carried out.

To exercise these rights, write to us at hello@wellfirst.app.

You also have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the French supervisory authority: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr. If you live in another EU country, you may also complain to your own supervisory authority.

Automated decision-making

The Score shown in the app is computed automatically from your answers. It is a trend indicator with no legal or similarly significant effect: it gates access to nothing, produces no decision taken without human involvement, and is in no way a medical diagnosis. The method is published on the Understanding the Score page.

Security

The following measures protect your data:
  • encryption in transit (HTTPS/TLS) on both the website and the app, and encryption at rest for the database,
  • passwords stored only as hashes by Supabase Auth,
  • access separation enforced at the database level (Row Level Security): a Client can only read their own data, a coach only that of the Clients linked to them,
  • administrative access limited to those who need it, and established providers applying their own technical and organisational measures.

No system is infallible. In the event of a data breach likely to result in a high risk to your rights, we will inform you and the CNIL within the timeframes set by the GDPR.

Minimum age

The app is intended for people aged 16 or over. We do not knowingly collect data from a child under 16; if you become aware of such an account, write to us at hello@wellfirst.app and we will delete it.

Changes to this policy

This policy may change. For any substantial change — a new purpose, a new processor receiving health data — you will be informed by email or by an in-app notification before it takes effect. The last updated date is shown at the top of this page.