Privacy Policy

Effective date: September 15, 2026
Operator: Welta Labs LLC
Contact: support@welta.co

Welta: AI Wellness Insights is a general-wellness app. This policy explains the information Welta processes, why it is processed, where it may be processed, and the controls available to you.

Information We Process

How We Use Information

Apple Health

Welta accesses Apple Health data only with your permission. Health data is used for app functionality and wellness insights. Welta does not sell Health data or use it for advertising. You can change or revoke Apple Health permissions in iOS Settings.

Workout routes and location traces obtained from HealthKit are used only for local workout maps in the current release. Route coordinates, route polylines, and route-derived fingerprints are not sent to Welta’s backend, AI processors, Product Analytics, or support systems.

Optional AI Processing

Cloud AI requires both Enable AI Features and your acceptance of the current in-app Cloud AI data-sharing agreement. Before Welta sends data to Cloud AI, the app identifies the recipient, the data categories, the purpose, and a link to this policy. Welta sends disclosed requests to Cloudflare, Inc. through Cloudflare Workers for secure backend request processing and routing; short voice recordings go to Cloudflare Workers AI for transcription. Welta sends AI insights, Welta AI chat, nutrition estimation, and photo analysis to Fireworks.ai, Inc. (Fireworks AI) for AI inference. Welta stores only a pseudonymous record that you accepted the current disclosure ID and digest; it does not store AI content in that record. Turning off Cloud AI stops future Cloud AI requests covered by that agreement.

When enabled, Welta may send minimized, structured wellness context for AI insights. This may include summarized sleep, activity, nutrition and hydration observations, supplied trends or comparisons, logging state, goal ratios, a selected Time Machine scenario identifier or label (a user-selected scenario) with an optional overlay relative to a recent baseline, and bounded coded continuity markers. Welta does not send raw HealthKit records, full HealthKit history, raw goals, birth date, height, weight, workout-route coordinates, prior insight text, or advertising identifiers in AI insight payloads.

Welta AI may process your current message and a bounded nearby conversation context. If you enable Automatic Memory, it may also process selected thread notes and their source fragments; selected cross-thread notes are included only when Global Memory is enabled. Full chat history, unselected memory, Today’s plans, and action records remain local to the app and are not synced through Welta cloud services in this release.

Automatically assembled wellness evidence is limited to allowlisted typed observations, such as HRV or VO2 max, together with units and observation windows. Welta does not automatically send birth date, height, weight, or the local result-card body as Welta AI context. This automatic-evidence exclusion is separate from your current message: if you choose to type sensitive information in a message, that message is processed under your Cloud AI consent. Welta does not claim to identify or redact every sensitive fact in free-form text. Today’s plans and logging actions use draft, review, and explicit confirmation before any supported change is saved.

Search Food and user-initiated text nutrition tools send food or drink text and limited serving context through the Welta Cloudflare Worker to Fireworks AI to produce a complete nutrition estimate. Search Food does not send HealthKit information, a health profile, saved meals, Welta AI chat history, or other chat context. Results are approximate, editable AI estimates and are saved as a complete local nutrition record only after you review and confirm them.

Photo-based food analysis is a separate user-initiated feature. The selected image is sent through the Welta Cloudflare Worker to Fireworks AI only after you choose to analyze it, to extract visible food, portion, package, and readable nutrition-label evidence and prepare a nutrition estimate. Food photos are not sent to Product Analytics. Voice recordings are sent to Cloudflare Workers AI only after you choose to send them for transcription.

Service Providers

Welta shares Cloud AI data only with the processors named above and only for the purposes described in the current in-app agreement. Welta requires those processors to provide privacy and security protections that are the same as or equal to those described in this policy. Fireworks states that it does not use prompts, API inputs, or training data to train or improve its AI models without explicit opt-in. Welta does not sell personal information and does not use these providers for cross-context behavioral advertising.

Storage And Retention

Core health and wellness records are local-first. Local app data remains on your device until it is replaced, deleted through available app or system controls, or removed when the app is uninstalled. Selected app-state records may be stored in your private iCloud account when iCloud is enabled.

Welta AI chats, local memory, summaries, action records, and Today’s plans are stored in the app’s local-projection database and do not use CloudKit sync in this release. The separate local search index is excluded from device backup and can be rebuilt from those records. The complete local-projection database and locally stored chat attachments are not currently marked by the app as excluded from Apple device backup. Their backup and restoration are therefore governed by the user’s Apple device-backup settings. This is separate from Welta cloud services and CloudKit sync.

The Welta backend does not maintain a long-term account database of AI prompts or AI chat history. It uses limited temporary Cloudflare storage for content-free action-deduplication markers for no more than approximately 300 seconds, security quota counters for approximately 24 hours, and pseudonymous App Attest security records for approximately 90 days after the last successful authentication. Action markers contain status, lease/expiry timing, version, and a random owner nonce, but no request or response body. Welta does not provide a server response cache or server replay/resume store, and it does not log or cache raw food queries, images, prompts, or model responses in the backend.

Cloud AI content is used only for transient request processing. Welta does not log or cache raw food queries, images, prompts, or model responses in its backend. Cloudflare and Fireworks may perform transient processing and retain limited technical, security, or infrastructure records under their applicable terms.

International Processing

Cloudflare, Fireworks, and their approved subprocessors may process information in the United States and other locations used to provide the service. Where required, Welta uses applicable contractual transfer safeguards with its processors. Optional Product Analytics is sent only to Amplitude's EU ingestion endpoint.

Your Controls And Rights

Disabling a feature stops future processing for that feature but does not retroactively remove information that a platform provider must retain for security, legal, or contractual reasons. Temporary content-free Welta backend markers expire automatically and are handled under documented deletion procedures.

Children

Welta is not directed to children under 13.

Changes

Welta may update this policy as the product, providers, or legal requirements change. The effective date above identifies the current version.