Privacy Policy
bunlo needs an account, which holds your email address, your name and, if you add one, a profile photo. Your health data is read from Apple Health on your iPhone, only after you allow it, and your scores are worked out on the iPhone. Health data leaves the iPhone only if you give explicit consent to AI chat, or to keeping health data on our server for cloud backup and device connections. Usage statistics and crash reports are sent only if you agree to share usage data. bunlo shows no ads, does not track you across apps, never sells your data, and you can delete your account and its data from inside the app.
1. Who is responsible
JRS Content Solutions UG (haftungsbeschränkt)
c/o Robin Sadeghpour Faraj
Bernauer Straße 65
13507 Berlin
Germany
Email: robin.faraj@11x.agency
This is the controller under the GDPR. See also the legal notice (Impressum).
2. Overview
| Purpose | Data | Legal basis | Recipients | Kept until |
|---|---|---|---|---|
| Showing your health data, scores, garden, journal and training | Apple Health data and what you enter in the app | Processed only on your iPhone; not sent to us | None | You delete it or the app |
| Your account | Email address, account ID, sign-in method, name, profile photo if you add one | Art. 6(1)(b) GDPR (contract) | Supabase; Apple or Google if you sign in with them; Resend for account emails | You delete your account |
| AI chat and the daily challenge line (optional) | The health data categories you allow (last 7 days), your questions, notes, photos and the screen you're on | Art. 9(2)(a) and Art. 6(1)(a) GDPR: explicit consent | Supabase, OpenRouter, Anthropic via Amazon Bedrock | Saved questions and answers: 90 days after each was created, or sooner if you delete them |
| Cloud backup and device connections (optional) | Journal, daily scores and the settings that shape them; health data from the wearable account you connect, and the access it grants | Art. 9(2)(a) and Art. 6(1)(a) GDPR: explicit consent | Supabase; the provider you connect | You turn backup off, disconnect and choose delete, or delete your account; device data at the latest 400 days after the moment it describes |
| Notifications from connected devices | Your iPhone's push token, its push environment and your time zone | Art. 6(1)(b) GDPR (contract) | Supabase; Apple (Apple Push Notification service) | You sign out or delete your account |
| Subscriptions and the paywall | Account ID, purchase records, device and app information, IP address | Art. 6(1)(b) GDPR; § 25(2) no. 2 TDDDG | Apple, RevenueCat, Superwall | You delete your account (RevenueCat); see section 9 for Superwall |
| Usage statistics, crash reports and paywall statistics (optional) | App events linked to your account, a random identifier, device and app information, crash reports with a masked replay | Art. 6(1)(a) GDPR and § 25(1) TDDDG: consent | PostHog (EU), Sentry (EU), Superwall | See section 10 |
| Support and privacy requests | Your email address and message | Art. 6(1)(b) or (c) GDPR; Art. 6(1)(f) GDPR, our interest in answering you | Google (email hosting) | As long as your request needs, then deleted unless a statutory retention duty applies |
| This website | IP address, browser and request details in server logs | Art. 6(1)(f) GDPR, our interest in a secure, working website | Vercel | Briefly, under Vercel's log retention |
You have to provide an email address (or sign in with Apple or Google) to use bunlo, because the app runs through your account. Everything based on consent is optional: bunlo works without it, only without the feature that needs it.
3. Apple Health
When you connect Apple Health, iOS asks which data bunlo may read: sleep, activity and workouts, heart rate, resting heart rate and heart rate variability, breathing rate, blood oxygen, wrist temperature, body measurements and cycle tracking. You choose each type in the iOS permission sheet and can change it any time in Settings → Health → Data Access & Devices → bunlo.
- The data is read on your iPhone. bunlo keeps a working copy in its own private storage on the iPhone so it can calculate your recovery, sleep, strain and stress scores and your history. The scores are worked out on the iPhone.
- bunlo writes to Apple Health only the types you switch on in the app, such as mood, weight or a strength workout you logged. Each is off until you turn it on, and iOS asks your permission for it. Turning one off stops new writes and deletes nothing already saved in Apple Health.
- Apple Health samples leave your iPhone only for AI chat (section 5), and only the categories you allowed. They are not part of cloud backup.
- They are never sent to analytics or crash reporting, never used for advertising or marketing, never sold, and never stored in iCloud by bunlo.
bunlo is a wellness companion, not a medical device. Its scores are estimates, and it does not diagnose, treat or prevent any condition.
4. What you enter in the app
Your date of birth, sex and height, your focus from setup, your garden, journal entries, training sessions, body measurements, blood test values you type in, cycle logs and settings are stored on your iPhone. We do not receive them unless you turn on cloud backup (section 6) or include them in AI chat (section 5). They are removed when you delete the app. Like any app data, they can be part of an iPhone backup you enable in iOS.
Reminders and check-ins are scheduled on your iPhone. If you allow notifications, bunlo stores your iPhone's push token (an identifier Apple issues so this app can be reached) and your time zone in your account. Our server uses it only to wake the app with a silent push when a device you connected, such as a Fitbit through Google Health, Oura or WHOOP, has a new night or workout. The push carries no content and no health data; the app then decides on your iPhone whether to show a notification. Signing out removes the token, and deleting your account deletes it. bunlo's Home Screen and Lock Screen widgets read a small summary that stays on the iPhone.
5. AI chat
bunlo can chat about your recent health data: explaining it in plain language, answering your questions, and writing one short line a day above your challenges. This needs a server, so AI chat is off until you allow it, category by category. Without bunlo Pro, an account can ask 5 questions a month. AI chat is not medical advice: it does not diagnose, treat or prevent any condition, and it says so when asked to.
Consent
- Nothing is sent until you give explicit consent in Settings → Chat → Data sharing and choose which categories may be sent (sleep, steps, resting heart rate). This consent covers data concerning health, a special category under Art. 9(2)(a) GDPR. Reproductive health has its own separate switch and is never included unless you turn that on too.
- You can stop at any time on the same screen (Stop sharing), and nothing is sent afterwards. Stopping does not affect processing before it (Art. 7(3) GDPR). The app checks your choice each time, right before sending.
What is sent
For the categories you allowed only: up to the last 7 days of values with their date and unit, the app or device that recorded them, how many days have data and when they last synced. Days without data are sent as missing, never as zero. When bunlo has them, it also sends a status you set (sick, injured or on a break) and its score estimates for those days. Your typed question goes with it, and so does anything you attach to it: a note you wrote for the AI, or a photo. If you open the chat from a particular screen in bunlo, that screen and the values it was showing you go with it too. For the daily challenge line, bunlo sends the challenge on offer, a short plain-language summary of your recent days, your focus, the time of day and how long you have used bunlo.
What is never sent
Your name, email address, account ID and other account identifiers, your journal and reflections, your garden, your water log, and any category you left switched off.
Cycle data
Reproductive health has its own switch on the same screen, separate from the categories above and off by default. Nothing about your cycle is sent unless you turn it on. When it is on, for the same 7 days: your logged flow (including no flow or not logged) and the symptoms you logged with their severity, whether you track a natural cycle or use hormonal contraception, whether your contraception is hormonal, non-hormonal or none, your last logged period's dates and length, the day of your cycle, and up to 6 past cycle lengths. Never sent: the name of your contraception method, which app wrote your cycle data, your cycle settings, or any estimate — bunlo does not estimate periods, fertility or ovulation, and none of this is contraception or medical advice.
Where it goes
- Our server, hosted by Supabase in the EU (Ireland), checks your account and plan and forwards the request.
- OpenRouter, Inc. (USA) routes the request to the model. We only allow routes where the provider keeps nothing once the answer is written (zero data retention), and OpenRouter does not keep it either.
- Anthropic's Claude model, run on Amazon Bedrock (Amazon Web Services), writes the answer. The region where this happens is not fixed and can be outside the EU, including the USA.
What it's for
Explaining your recent health data in plain language, answering your questions about it, and the daily challenge line. Not diagnosis, not advertising, and your data is never sold.
Storage and deletion
- Your questions and bunlo's answers, and photos you attach, are saved in your account so you can read them again. The health data sent with a question is not saved, though an answer can mention values from it. The daily challenge line is not stored on our server; only the fact that one was written on a given day, kept for 14 days to limit use.
- Each question and answer is deleted automatically 90 days after it was created.
- You can delete all saved questions and answers sooner in Settings → Chat → Data sharing. Deleting your account deletes all of them.
- To apply plan limits we count how many free questions an account used in a month, kept for three months, and keep short-lived request records for abuse protection, deleted after one day. These contain no health data, questions or answers.
AI transparency
AI chat's explanations, answers to your questions and the daily challenge line are written by an AI system: Anthropic's Claude, through OpenRouter. The app labels explanations and answers as written by AI, and our server marks each AI-written response as AI-generated in a machine-readable way (Art. 50 EU AI Act). Short fallback texts that bunlo writes itself are not marked. AI answers can be wrong. They are not medical advice, do not diagnose, and are told to refuse diagnoses and assessments of photos. They do not produce decisions with legal or similarly significant effects on you (Art. 22 GDPR). We do not use your data to train AI models, and our AI providers keep nothing once the answer is written.
6. Cloud backup and device connections
Both features keep health data on our server, so both rest on one consent: allowing bunlo to keep health data on its server (Art. 9(2)(a) GDPR). You give it when you turn on Settings → Cloud backup or when you connect a device. Because it is one consent, connecting a device also turns on cloud backup of your journal and scores.
Cloud backup
- What is backed up: your journal, your daily scores, and the settings that shape them, such as goals, data sources and zones. It exists so you can get your own writing and results back on a new iPhone.
- What is never backed up: Apple Health itself. Your sleep stages, heart rate, workouts and every other sample stay on the iPhone.
- Where it is kept: on our servers at Supabase in the EU (Ireland), encrypted at rest and readable only by your account.
- Turning it off withdraws the consent: every upload stops and the cloud copies of your journal, scores and settings are deleted. Everything on the iPhone stays as it is. bunlo also stops storing new data from connected devices; to delete what was already read, disconnect the device and choose delete (below).
- The app records when you agreed and which version of this policy you agreed to. If the policy changes in substance, backup pauses until you have read it again.
Device connections
You can connect the account of a wearable that does not write to Apple Health: Google Health (Fitbit and Pixel Watch), Oura, WHOOP, Polar, Withings or Garmin. You choose each one and can disconnect at any time.
- You sign in on the provider's own page in your browser. bunlo never sees your provider password.
- The provider gives bunlo read access to the data types shown on the connection screen, which can include sleep, heart rate, heart rate variability, breathing rate, blood oxygen, skin temperature, steps, energy, workouts, weight and the device's own scores. bunlo reads only; it does not write to your provider account.
- The access the provider grants (its tokens) is stored encrypted in a vault on our server, not on your phone, and is used only to fetch your data for you. What bunlo reads is stored in your account at Supabase in the EU (Ireland) so your iPhone can show it, and is deleted automatically 400 days after the moment it describes.
- When you disconnect, bunlo revokes its access at the provider and deletes the tokens, and you choose whether bunlo keeps or deletes what it already read. Deleting your account deletes it all and revokes bunlo's access.
- bunlo never shares, sells or uses this data for advertising, and never sends it to analytics.
Google user data
bunlo's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data from Google Health is used only to show you your own health data and scores in bunlo; it is not used for advertising, not sold, not used to train AI models, and not read by people except with your consent, for security purposes, or to comply with the law. It is included in AI chat only if you have given the separate consent in section 5.
7. Your account
bunlo needs an account. You sign in with email and password, Sign in with Apple, or Google. We store your email address, an account ID, how you sign in, and your name: the one you enter on your profile, or the one Apple passes on the first time you sign in with Apple. If you add a profile photo, it is stored in a storage area for profile photos that can be opened by anyone who has its exact web address; the address contains your random account ID, and bunlo does not publish or share it. Your date of birth, sex and height stay on your iPhone.
Account emails, such as confirming your address or resetting your password, are sent from mail.bunlo.app through Resend, Inc. (USA). They are sent with a one-time code, never a session.
Delete your account at any time in Settings → Account → Delete account. This deletes the account and everything stored with it on our server, including your name, profile photo, AI chat history, cloud backup and connected device data. It also revokes bunlo's access at connected providers and at Sign in with Apple, and deletes your records at RevenueCat and PostHog. It does not cancel an App Store subscription; cancel that in iOS Settings. If you can no longer open the app, see how to delete your data.
8. Subscriptions
bunlo is free to use. bunlo Pro is an optional weekly or yearly auto-renewing subscription; the price for your country is shown in the app from the App Store. Purchases are processed by Apple with your Apple ID, and we never receive your payment details.
RevenueCat, Inc. (USA) tells the app and our server which subscription is active. It receives your account ID, your App Store purchase records for bunlo, device and app information such as the identifier for vendors (IDFV), and your IP address. No health data is sent to RevenueCat. Legal basis: Art. 6(1)(b) GDPR, and § 25(2) no. 2 TDDDG for what the SDK stores on your iPhone. When you delete your account, we delete your RevenueCat record; Apple keeps its own purchase records under Apple's privacy policy.
9. The paywall (Superwall)
bunlo shows its subscription screen with Superwall, Inc. (USA). To load and show the paywall, the Superwall SDK contacts Superwall at app start and receives your account ID, a device identifier it creates, device and app information and your IP address. This is needed to offer the subscription you ask for: Art. 6(1)(b) GDPR and § 25(2) no. 2 TDDDG. No health data is sent to Superwall.
Only if you agree to share usage data (section 10), Superwall also records its own paywall events, such as when the paywall was shown, closed or led to a purchase, to measure which paywall works. Without that consent the SDK records no such events. A change of your answer applies from the next time you open bunlo.
Superwall keeps this data while you have an account. To have it deleted, email us at robin.faraj@11x.agency and we will ask Superwall to delete your record.
10. Usage data: statistics and crash reports
During setup, bunlo asks whether you want to share usage data. Nothing below is sent, and the tools are not started, unless you say yes. You can change your answer at any time in Settings → Usage data. Legal basis: your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG. Withdrawing does not affect processing before it.
Statistics (PostHog)
PostHog (PostHog Inc., processing in its EU cloud in Frankfurt, Germany) receives app events such as “setup completed”, “care moment completed” or “paywall shown”, a random identifier created by the app, your account ID after you sign in (never your email address), device and app information, and your IP address, from which PostHog derives an approximate location (city and country). Events are therefore linked to your account. bunlo does not record screens or taps automatically and does not record sessions.
PostHog never receives health values, scores, the names of your health apps or devices, journal or training content, your questions or answers, or anything else you type. When you withdraw, the app stops sending and forgets the identifier; when you delete your account, or ask us at robin.faraj@11x.agency, we delete your PostHog record and its events.
Crash reports (Sentry)
When the app crashes or hits an error, Sentry (Functional Software, Inc., processing in its EU data region in Germany) receives a technical report: the error message, where in the code it happened, device model, iOS and app version, and an installation identifier. The report carries no account, email address or other user details, and errors that involve health data are reduced to a short code first. A report can include a replay of the few seconds before the error in which every text, image and graphic is masked, so it shows no health values or anything you typed. Sentry deletes reports after its retention period, at most 90 days.
11. This website
bunlo.app sets no cookies and uses no similar storage on your device, so it needs no cookie banner or cookie policy. It runs no analytics and loads no fonts, scripts or images from other companies. Our hosting provider, Vercel Inc. (USA), processes your IP address and request details to deliver the page and keeps them briefly in server logs for security (Art. 6(1)(f) GDPR). If you email us, we use your address and message to answer you; our email is hosted by Google.
12. Recipients and processors
We use the service providers below. Where they process data on our behalf, they act on our instructions under a data processing agreement (Art. 28 GDPR).
| Recipient | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Accounts, profile photos, saved AI chat history, cloud backup, connected device data, our server functions | EU (Ireland); server functions can run at edge locations outside the EU while a request is in flight |
| OpenRouter, Inc. | Routing AI requests, zero data retention | USA |
| Anthropic, PBC, on Amazon Web Services (Amazon Bedrock) | Writing AI answers, zero data retention | Not fixed; EU or USA |
| RevenueCat, Inc. | Subscription status | USA |
| Superwall, Inc. | Showing the paywall; paywall statistics with your consent | USA |
| PostHog Inc. | Usage statistics, with your consent | EU (Germany) |
| Functional Software, Inc. (Sentry) | Crash reports, with your consent | EU (Germany) |
| Resend, Inc. | Account emails | USA |
| Google (Google Workspace) | Our support email | EU / USA |
| Vercel Inc. | Hosting bunlo.app | USA, served from locations worldwide |
| Apple | App Store distribution, purchases, Sign in with Apple. Apple Health runs on your iPhone and Apple does not pass your health data to us. Apple is its own controller. | Ireland / USA |
| Sign in with Google, if you use it. Its own controller. | Ireland / USA | |
| The wearable provider you connect (Google, Oura, WHOOP, Polar, Withings or Garmin) | Gives bunlo read access to your data at your request. Each is its own controller under its own privacy policy. | Varies |
13. Transfers outside the EU/EEA
Some recipients are located in, or may access data from, countries outside the EU/EEA, in particular the USA. We transfer personal data there only on the basis of an adequacy decision, in particular the EU–US Data Privacy Framework for recipients certified under it (Art. 45 GDPR), or of Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can ask us for a copy of the safeguards at robin.faraj@11x.agency.
14. Security
Data between the app and our service providers is encrypted in transit (HTTPS). Data in your account is encrypted at rest, and database rules make each account's data readable only by that account. Access granted by a connected device provider is kept in an encrypted vault on the server.
15. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15),
- rectification (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interests (Art. 21),
- withdraw any consent at any time with effect for the future (Art. 7(3)).
In the app you can stop Apple Health access (in iOS Settings), stop sending data for AI chat, delete saved questions and answers, turn off cloud backup, disconnect a device and delete its data, stop sharing usage data, and delete your account. For a copy of your data, which we send as one machine-readable file, and for everything else, email robin.faraj@11x.agency from the address of your account.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in your country of residence. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (www.datenschutz-berlin.de).
If you live in the United States, see also our Consumer Health Data Privacy Policy.
16. Tracking and advertising
bunlo shows no ads, does not track you across other companies' apps or websites, does not use the advertising identifier (IDFA), and does not sell or share personal data for advertising.
17. Children
bunlo is for people aged 16 and over. It is not directed at younger people, and we do not knowingly process their data. If you believe a younger person has an account, write to robin.faraj@11x.agency and we will delete it.
18. Changes
If we change what bunlo processes or who processes it, we update this page, its version and its effective date before the change reaches the app, and ask for your consent again where it is required.

Questions about any of this?
Write to robin.faraj@11x.agency.