WELLDUEL PRIVACY POLICY

Effective Date: 12/1/25

WellDuel (“WellDuel,” “we,” “us,” or “our”) is a health-competition platform that empowers you to improve your wellbeing through challenges, insights, and our Personalized Baseline Handicap System. We respect your privacy and are committed to protecting your data.
This Privacy Policy explains how we collect, use, share, and protect your information when you use our app, website, and all related services (collectively, the “Services”).

By using WellDuel, you agree to this Privacy Policy.

1. Information We Collect

We collect information to power competitions, calculate baselines, create fair rankings, deliver insights, and improve your experience.

1.1 Account Information

When you create an account, we collect:

  • Name, username, email, password
  • Date of birth
  • Height and weight (used for Handicap scoring if provided)
  • Gender
  • Profile photo (optional)
  • Country and time zone

1.2 Device & Health Data

With your permission, we collect data from apps and devices such as:

  • Apple Health
  • Google Fit
  • Oura
  • WHOOP
  • Garmin
  • Fitbit
  • Polar
  • Etc

Examples of data we may receive:

  • Steps, distance, calories
  • Heart rate, HRV, SpO2
  • Sleep stages (REM, deep, total)
  • Stress, readiness, and recovery metrics
  • Workouts and activity logs
  • Device metadata (model, version, timezone, sampling intervals)
  • Baseline data used by our Handicap System

Sensitive Data

Health data is considered “sensitive.”
We only collect it:

  • With your explicit consent, and
  • To power WellDuel features (never for advertising).

1.3 Usage Information

We collect data about how you use WellDuel:

  • In-app actions (creating/joining challenges, settings, sharing)
  • Interactions with notifications
  • App diagnostics (crash logs)
  • Device details (IP address, OS version, app version)

1.4 Location Data

  • We do not collect GPS data.
  • We may infer general location (city/region) from IP for:
    • Timezone accuracy
    • Localization
    • Fair leaderboard logic

1.5 Communications

If you contact us or receive updates, we may store:

  • Emails and messages
  • Feedback, surveys, bug reports

2. How We Use Your Information

2.1 To Provide and Improve the Services

We use your data to:

  • Sync health/device data
  • Calculate rolling 30-day baselines
  • Apply the Health Handicap scoring system
  • Power competitions and leaderboards
  • Deliver personalized insights
  • Customize your dashboard
  • Build new features

2.2 To Maintain Fair Competition

We analyze data to:

  • Ensure fair handicaps
  • Apply demographic/device adjustments (if enabled)
  • Detect cheating or abnormal data
  • Validate scores and rankings

2.3 For Analytics (Aggregated & Anonymized)

We study anonymized trends to:

  • Improve performance
  • Understand feature usage
  • Build new scoring models
  • Enhance user experience

All analytics is non-identifiable.

2.4 For Security & Fraud Prevention

We process data to:

  • Prevent misuse
  • Detect suspicious behavior
  • Protect the integrity of paid competitions

2.5 Communications

We may send:

  • Feature updates
  • Competition updates
  • Account alerts
  • Billing notifications
  • Support responses

You may opt out of non-essential messages.

3. How We Share Your Information

We do not sell your personal data.

We share information only in limited ways:

3.1 With Your Consent

Examples:

  • Posting on leaderboards
  • Sharing results
  • Joining group competitions
  • Displaying profile information

3.2 With Service Providers

We use trusted partners to operate WellDuel, including:

  • Cloud hosting (e.g., AWS, Vercel)
  • Device/health sync infrastructure (e.g., Terra)
  • Analytics tools
  • Payment processors
  • Email/notification services
  • Fraud detection tools

They may only use your data to perform services on our behalf.

3.3 Aggregated or Anonymized Data

We may share grouped insights, such as:

  • Challenge trends
  • Average improvements
  • Wellness statistics

Never personally identifiable.

3.4 Legal Requirements

We may disclose data if required for:

  • Law enforcement
  • Valid legal process
  • Protection from harm
  • Fraud prevention

4. Your Privacy Controls

You choose what you share and how your data is used.

4.1 Manage Health Connections

You can connect or disconnect:

  • Apple Health
  • Google Fit
  • Wearables
  • Other integrations

Disconnecting stops future syncing.

4.2 Export Your Data

You may request an export of your data at any time.

4.3 Delete Your Account

When deleted:

  • Personal data is permanently removed
  • Remaining data is fully anonymized

Deletion usually occurs within 30 days.

4.4 Manage Visibility

You control:

  • What shows on leaderboards
  • What’s visible to others
  • Notification settings

5. Apple Health & Wearable Data Requirements

Apple Health and wearable data is treated with the highest level of privacy.

We do NOT:

  • Use Apple Health or wearable data for advertising
  • Share it with third parties for marketing
  • Sell or broker your data
  • Use it for tracking

We ONLY use this data to:

  • Power core WellDuel functionality
  • Calculate baselines
  • Run competitions
  • Generate insights

This is required for App Store compliance.

6. Cookies & Tracking Technologies

We use limited tracking technologies to improve the Services.

We may use:

  • Cookies
  • Session tokens
  • SDKs for analytics
  • Crash reporting tools
  • Device identifiers

We do NOT:

  • Use cookies to sell personal information
  • Use third-party advertising trackers

You can disable cookies in your browser settings.

7. AI & Automated Processing

WellDuel uses AI and automated scoring to:

  • Generate insights
  • Detect anomalies
  • Calculate handicaps
  • Personalize your experience

Model Training

We may use aggregated, anonymized data to improve algorithms.
We do not use identifiable health data to train models.

8. Data Retention

We retain data only as long as necessary.

Account Data: kept until account deletion

Health & Device Data: kept to power baselines + features

Competition Records: anonymized after deletion

Logs & Diagnostics: retained for security, then purged

Backups: deleted automatically on rotating schedules

You may request deletion at any time.

9. Security

We use industry-standard security measures, including:

  • Encryption at rest and in transit
  • Secure API authentication
  • Access controls and audit logs
  • Anomaly and fraud monitoring
  • Regular security reviews

No system is 100% secure, but we take all reasonable steps to protect your data.

10. Your Rights

Depending on your location, you may have:

  • Right to access your data
  • Right to correct inaccurate data
  • Right to delete personal data
  • Right to restrict processing
  • Right to opt-out of data sharing (even though we don’t sell data)
  • Right to portability (data export)

To exercise rights, contact us at support@wellduel.com.

11. Children’s Privacy

WellDuel is not intended for children under 16.
We do not knowingly collect data from children.

If a child’s account is discovered, we will delete it.

12. International Data Transfers

We may process data in:

  • The United States
  • The EU
  • Other regions where providers operate

We use appropriate safeguards, including Standard Contractual Clauses (SCCs).

13. Changes to This Policy

We may update this Privacy Policy occasionally.
If changes are significant, we will notify you by email or in-app alerts.

14. Contact Us

If you have questions about your privacy or this policy, contact:

WellDuel, Inc.
Email: support@wellduel.com
Website: wellduel.com