AIyurveda

Privacy notice

Version 1 · Last updated 10 October 2026

The short version

1. Who is responsible for your data

AIyurveda is made by Ori Iscovici, an independent developer based in Israel. Ori is the controller of your personal data: the person who decides how it is used and is responsible for it. In this notice, "we" means Ori.

Contact for anything about your data: privacy@aiyurveda.app. For everything else: support@aiyurveda.app.

If you live in the EU or the UK: the law asks a developer outside the EU and UK to name a representative there. We have not appointed one yet, and we will name them here before anyone in the EU or UK is invited to the test.

2. What we collect

What Details
Your account Your email address and password (stored only as a secure hash by our sign-in provider), when you signed up, and sign-in records.
Your age confirmation That you confirmed you are 18 or over, and when. The app checks your date of birth on your phone. We do not store it.
Your time zone Sent by your phone, so your day starts and ends at the right time.
Your assessment Your answers in the opening conversation, including short quotes in your own words, and the constitution reading worked out from them.
Your check-ins How you rate your energy, digestion, sleep and mood.
Your conversations Every message you send the guide, and every reply.
Your daily plans The plans written for you, and which items you mark done.
What the guide remembers Short notes it takes from your conversations and check-ins, such as "prefers warm breakfasts" or "sleeps badly before deadlines", and a written summary of your profile.
Safety notes See section 3.
Reports If you report a guide reply: the reason you choose and any note you add.
Consent records Which consents you gave or withdrew and when, the version of the text you saw, and the app version, platform and language at the time.
Technical data Your IP address, which our servers use for a few minutes to limit abuse and, on a chat turn, to work out which country's crisis lines to show. We do not store it. Our server logs record your account's random ID, the kind of event and how long it took, never what you wrote.

No law requires you to give us any of this. Without the two consents in the app, the guide cannot work, and you can still delete the account at any time.

We do not collect your name (unless you type it into a message), contacts, photos, precise location, advertising ID or payment details.

Your messages are sent to the AI exactly as you type them. If you write your name, email or phone number in a message, it is sent too. Your account's email address is never sent to the AI.

3. What the app works out about you

Memory. After each conversation, an AI model notes facts you shared, so the guide does not have to ask again. You can ask it to forget any of them (section 8).

Safety notes. To keep its suggestions safe, the app records some things about your health:

A safety note is set when you say something about yourself ("I'm pregnant", "I take warfarin"), or when the AI picks it up from a conversation; when it is unsure, it asks you first. While a note is active, the guide does not suggest herbs, does not change food advice, or shows crisis lines, as the note requires.

Safety check on every message. Each message you send the guide, together with up to six earlier messages, is checked by an AI model at Anthropic for signs of crisis, eating-disorder risk, medical questions and attempts to misuse the guide. Messages our own rules answer first (for example an explicit crisis) are not sent anywhere.

None of this makes decisions with legal or similarly significant effects on you. It only changes what the guide says to you.

You can clear a safety note yourself, except food-guidance care mode, which ends on its own 90 days after the last message that set it. If you think it was set by mistake, write to us and we will review it.

4. Why we use it, and our legal basis

The legal bases below are those of the UK and EU GDPR.

Purpose Data Legal basis
Running your account Account, age confirmation, time zone Providing the service you signed up for (Art. 6(1)(b))
The guide, your plans and its memory of you Assessment, check-ins, conversations, plans, memory, safety notes Your explicit consent (Art. 6(1)(a) and 9(2)(a)), given on the "Before we begin" screen: one consent to store your health information, one to send it to Anthropic
Keeping you safe Messages, safety notes, the country your connection comes from Your explicit consent, as above. A crisis message sent before you have given consent is answered with crisis lines to protect your vital interests (Art. 6(1)(d) and 9(2)(c)), and nothing of it is stored.
Security and preventing abuse IP address, account ID, server logs Our legitimate interest in keeping the service safe and working (Art. 6(1)(f))
Proving we honoured your choices Consent records, deletion records Our legal obligation to be able to show consent and erasure (Art. 6(1)(c))

We never sell your data, use it for advertising, share it with data brokers, use it to train AI models (ours or anyone's), or send you marketing.

5. Who else handles your data

These companies process data for us. Each, except Google for our inbox, does so under a data processing agreement that limits it to our instructions and stops it using your data for its own purposes.

Company What it does for us What it handles Where
Supabase (Supabase Pte. Ltd., with Supabase, Inc.) Our database, sign-in and backups Everything we store, and sign-in records with your IP address and device type Frankfurt, Germany. Support and service logs may be handled from Singapore and the US.
Vercel Inc. Hosts our servers and this website. Its AI Gateway passes requests on to Anthropic. Everything that passes through our servers, and logs with your account ID and IP address Our servers run in Frankfurt, Germany (until mid-October 2026, in Washington, DC). Vercel is a US company and handles some data in the US.
Anthropic, PBC The Claude AI model behind the guide, its memory and the safety check Your messages, recent conversation, profile summary and the notes needed for each request United States
Upstash, Inc. Abuse-prevention counters and short-lived caches Your account ID and IP address, for minutes to two days. No health data. Frankfurt, Germany
Expo (650 Industries, Inc.) Delivers app updates App and device information, and your IP address, when the app checks for an update United States
Cloudflare, Inc. Forwards email sent to our @aiyurveda.app addresses Emails you send us. It keeps the sender, recipient and subject for 31 days, not the message. Global network
Google LLC Our email inbox Emails you send us United States

Every AI request goes to Anthropic and to no other AI company. If a request through our own Anthropic account fails, Vercel may resend it to Anthropic under Vercel's own account.

Google Play distributes the app. Google acts under its own privacy policy as an independent controller for your Play account, downloads and reviews. We receive no personal data from Google about you.

6. International transfers

We are based in Israel, which the EU and the UK recognise as protecting personal data adequately. Your data is stored in the EU, in Frankfurt.

Some providers handle data in the United States: Anthropic, Vercel, Expo and Google. Supabase supports its service from Singapore and the US. Where a provider is certified under the EU-US Data Privacy Framework and its UK Extension (Vercel, Upstash, Expo, Cloudflare and Google), we rely on that. For Anthropic and Supabase, which are not certified, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum in their data processing agreements. Write to us for a copy of the safeguards.

7. How long we keep it

Data How long
Your account, assessment, conversations, check-ins, plans, memory and safety notes Until you delete your account
A memory note you ask the guide to forget Hidden from the AI at once, and deleted after 24 hours. The messages where you said it stay in your conversation history, which only you see, but the AI no longer reads them.
A safety note you clear Deleted, if the app set it. If you added it yourself, we keep a record that it was cleared, without its label.
Food-guidance care mode Ends 90 days after the last message that set it; a record that it ended is kept
Working copies used to update the guide's memory Up to 30 days after the task finishes
Abuse-prevention counters (account ID or IP address) From a few minutes to two days
Server logs (account ID, event, timing; IP addresses in request logs) Hosting logs: 1 day, or up to 30 days when extended monitoring is on. Database and sign-in logs: 7 days.
Database backups 7 days, then overwritten
Copies held by Anthropic Up to 30 days, then deleted by Anthropic. Content Anthropic flags as breaking its usage policy can be kept for up to 2 years.
Consent records and a record that your account was deleted Kept after you delete your account, with your account ID replaced by a protected code, so we can show we did what you asked

8. Your rights, and how to use them

You can do the following at any time. Write to privacy@aiyurveda.app from the email address on your account. To check it is you, we reply with a one-time code to that address; we never act on a reply to someone else's message. We answer within one month.

The closed-test version of the app is gaining these controls in Settings: delete your account, withdraw consent, see what the guide remembers and forget it, and clear safety notes. If your version does not have one yet, email us and we will do it for you.

If you are unhappy with how we handle your data, please tell us first at privacy@aiyurveda.app; we will answer within one month. You can also complain to a data protection authority:

9. How we protect it

10. Adults only

AIyurveda is for people aged 18 and over. If we learn that someone under 18 has an account, we delete it.

11. Changes to this notice

If we change this notice, we update this page and the date at the top. If a change affects what you agreed to, we tell you in the app and ask for your consent again.

12. If you live in the United States

Washington, Nevada and some other states have their own consumer health data laws. Our Consumer Health Data Privacy Policy covers them.