HMARA Privacy Policy
1. Who We Are
HMARA is an AI-enabled wellbeing and self-reflection application that provides conversational support, educational courses, exercises, assessments, personalized insights, and related features (the “Service”).
The entity responsible for deciding how and why personal information is processed through the Service (the “Controller,” “HMARA,” “we,” “us,” or “our”) is:
- Legal name: Individual Entrepreneur Oleksii Khudenko
- Trading name: HMARA
- Contact location: Anny Akhmatovoi Street, Kyiv, Ukraine
- Country of establishment: Ukraine
- App-store publisher: Oleksii Khudenko
- Privacy email: oleksiikhudenko61@gmail.com
- Support email: oleksiikhudenko61@gmail.com
- Security email: oleksiikhudenko61@gmail.com
- Data Protection Officer: Not appointed
This Privacy Policy explains what personal information we collect, how we use it, the circumstances in which we disclose it, how long we retain it, the choices and rights available to you, and how to contact us.
2. Scope
This Privacy Policy applies to personal information processed through:
- the HMARA mobile application;
- HMARA websites, including https://www.hmara.care/ and the website on which this Privacy Policy is published;
- HMARA accounts, subscriptions, courses, assessments, chat, voice, notification, advertising, and support features; and
- communications between you and HMARA.
HMARA intends to make the Service available worldwide except in Russia, subject to applicable law and availability through Apple, Google, advertising, payment, and subscription providers. Subscriptions and advertising are intended to be available in every supported launch country.
This Privacy Policy does not apply to third-party services that you access independently, even if HMARA links to them. Those third parties process information under their own privacy notices.
Where a supplemental notice is presented for a particular feature, promotion, jurisdiction, or type of information, that supplemental notice applies together with this Privacy Policy. If there is a conflict, the supplemental notice controls for the relevant processing.
3. Important Information About HMARA
3.1 HMARA is not emergency or medical care
HMARA is intended for general wellbeing, education, and self-reflection. It is not a hospital, healthcare provider, emergency service, crisis-response service, or substitute for a qualified physician, psychologist, psychotherapist, or other licensed professional. The Service is not designed to diagnose, prevent, monitor, predict, prognose, treat, or cure a disease or medical condition.
Do not use HMARA for emergencies. If you believe that you or another person is in immediate danger, contact the emergency services or an appropriate crisis service where you are located.
3.2 HMARA uses artificial intelligence
When you use AI chat or personalized insight features, you are interacting with an automated system. Your messages and relevant contextual information may be submitted to an AI service provider to generate a response. AI responses can be incomplete, inaccurate, or inappropriate and should not be treated as professional advice.
3.3 Some information may be sensitive
Your conversations, assessments, wellbeing goals, emotional state, and other information you choose to provide may reveal information about your physical or mental health, sex life or sexual orientation, religion, racial or ethnic origin, political opinions, disability, or other highly personal matters. Depending on the jurisdiction, this may be called sensitive personal information, special-category data, or consumer health data.
We apply additional protections to this information. We do not sell consumer health data. We do not use the content of your HMARA conversations, assessments, or psychological profile to target advertising.
4. Personal Information We Collect
The exact information collected depends on how you use the Service, your device permissions, your choices, and the features available in your country.
4.1 Account and identity information
We may collect:
- name, nickname, or display name;
- email address;
- internal user and account identifiers;
- authentication provider and authentication tokens or related technical records;
- profile image, if you choose to provide one;
- age or age range, where used for eligibility or safety;
- language, country, time zone, and communication preferences;
- account-creation date, account status, and login history; and
- information provided through Sign in with Apple, Google Sign-In, or another authentication provider, according to the permissions you approve.
HMARA does not receive your Apple ID or Google password.
4.2 Conversation and journal information
When you use chat, journaling, reflection, or similar features, we may process:
- the text you submit;
- AI-generated responses;
- conversation history and timestamps;
- saved reflections, notes, goals, or exercises;
- feedback on an AI response;
- context selected from prior conversations or your profile to personalize a response.
HMARA does not currently allow users to attach photographs, documents, or other files to a conversation.
Please do not include information about another person unless you have a lawful reason and their permission to do so. Do not submit government identification numbers, financial-account credentials, passwords, or information that is not needed to use the Service.
4.3 Voice and audio information
If you use a voice feature and grant microphone permission, we may process:
- audio captured while the microphone feature is active;
- a transcript created from that audio;
- technical information needed to operate the recording and transcription feature; and
- your language or speech-recognition settings.
HMARA does not retain the original voice recording after transcription. Raw audio is processed only for the time needed to create the transcript and is then deleted. HMARA retains the resulting transcript as part of the conversation history.
You can deny or revoke microphone permission through your device settings. You may still use text-based features when microphone access is disabled.
4.4 Wellbeing, assessment, and consumer health information
We may process information you choose to provide or generate through the Service, including:
- mood, emotions, stress, sleep, energy, motivation, or wellbeing;
- symptoms, concerns, life events, relationships, habits, or coping strategies;
- answers to questionnaires, check-ins, exercises, or psychological assessments;
- wellbeing goals, course choices, lesson progress, completed exercises, and preferences;
- information about trauma, safety, self-harm, substance use, or other sensitive experiences if you choose to discuss them;
- information that may reveal health conditions, disability, sex life or sexual orientation, religious beliefs, racial or ethnic origin, or other sensitive characteristics; and
- insights inferred by HMARA from your use of the Service, such as themes, preferences, communication patterns, wellbeing trends, or a personalized psychological or conversational profile.
We do not require you to provide more sensitive information than is necessary for the feature you choose to use. You may choose not to answer an optional question.
4.5 Courses, content, and product-use information
We may collect:
- courses, lessons, exercises, and screens viewed;
- completion status, streaks, progress, saved items, and feature interactions;
- search terms, button taps, session duration, referral screens, and navigation paths;
- dates and times of use;
- experiments, feature flags, and onboarding choices; and
- feedback, ratings, survey responses, and feature requests.
The translations, course materials, interface text, and other static content delivered from Supabase are not personal information by themselves. Requests for that content may nevertheless create technical logs such as an IP address, timestamp, or device information.
4.6 Device, network, and technical information
We may automatically collect:
- device type, manufacturer, model, operating system, and application version;
- device language, country, time zone, and approximate region derived from IP address;
- IP address and network information;
- application instance, installation, session, and device identifiers;
- advertising identifier, where available and permitted;
- crash reports, diagnostic logs, performance information, error traces, and security events;
- authentication, session, and access logs; and
- consent status and privacy-choice records.
HMARA does not request or collect precise geolocation. We and our providers may infer an approximate country or region from an IP address for security, localization, legal compliance, subscription, and contextual advertising purposes.
4.7 Subscription and transaction information
If you purchase a subscription or other digital product, the relevant app store processes your payment. HMARA and RevenueCat may receive:
- product and subscription identifiers;
- purchase date, renewal date, expiration date, and subscription status;
- app-store transaction and original transaction identifiers;
- trial, cancellation, refund, and billing-status information;
- country, currency, and storefront information; and
- limited technical information used to validate a purchase and maintain access.
HMARA does not receive your full payment-card number from Apple or Google.
4.8 Advertising information
If HMARA displays a banner or interstitial advertisement through Google AdMob, Google and its advertising partners may process:
- IP address;
- device, app, and advertising identifiers;
- device and operating-system information;
- advertisement views, clicks, and other interaction information;
- diagnostic and fraud-prevention information;
- consent choices and, where permitted, approximate location; and
- information used to select, deliver, measure, secure, and limit advertising.
HMARA requests only contextual, non-personalized, or age-restricted advertising. We do not authorize AdMob to personalize advertisements from HMARA activity or from conversation, course, assessment, mood, or psychological-profile data. Advertising treatment may be further restricted based on a user’s age, location, consent status, and device settings.
- HMARA commitment: we do not send the text of your conversations, assessment answers, wellbeing profile, inferred psychological attributes, course choices that reveal health information, or other consumer health data to AdMob or an advertising partner. We do not build advertising audiences from that information.
Google may use its own service providers and subprocessors to operate AdMob. Those parties process data under Google’s terms and privacy disclosures. HMARA does not provide them with conversation, assessment, mood, course, or psychological-profile information.
4.9 Push-notification information
If you enable notifications, we may process:
- a device push token;
- notification preferences;
- notification delivery, opening, and error information; and
- the content and timing of notifications.
Push notifications may be routed through Expo, Apple Push Notification service, or Firebase Cloud Messaging. Notification previews may appear on a locked device. We design notification text to avoid exposing sensitive conversation or health details, but you should also configure notification previews through your device settings.
4.10 Support and communications
If you contact us, we may collect:
- your contact details;
- the content of your request and any attachments;
- support history and internal notes;
- information needed to verify your identity or account;
- marketing preferences, if we offer optional marketing communications; and
- records of privacy requests, consent withdrawal, complaints, and our response.
4.11 Website information
When you visit an HMARA website, we and our hosting provider may process IP address, browser type, device information, requested pages, referral URL, timestamps, security logs, and cookie or similar-technology information.
HMARA uses PostHog, a product-analytics tool, to understand how the app is used — for example which screens you open, which features you use, and how long your sessions last. We send PostHog only anonymized in-app usage events, and PostHog is hosted in the European Union. We do not enable autocapture or session replay. We never send your conversation content, assessment questions or answers, psychological-profile information, or personal identifiers such as your name, email address, or phone number to PostHog.
5. Sources of Personal Information
We obtain personal information:
- directly from you, when you create an account, communicate with HMARA, answer questions, complete an assessment, use chat or voice, or make a privacy choice;
- automatically from your device and use of the Service, through application code, logs, SDKs, cookies, and similar technologies;
- from authentication providers, such as Apple or Google, according to the sign-in permissions you grant;
- from app stores and subscription infrastructure, such as Apple App Store, Google Play, and RevenueCat;
- from advertising and technology providers, such as AdMob, Sentry, Expo, and hosting or security providers;
- from inferences generated by HMARA, such as a personalized profile, themes, progress, preferences, or safety-related signals; and
- from another person, only where they lawfully provide information to us, such as an authorized agent making a request on your behalf.
6. How We Use Personal Information
We use personal information for the following purposes.
6.1 Provide and personalize the Service
We use information to:
- create, authenticate, and maintain your account;
- provide chat, voice transcription, courses, assessments, exercises, and personalized insights;
- maintain conversation history and continuity;
- adapt language, content, tone, recommendations, and exercises to your selections and prior use;
- save progress, preferences, and settings;
- validate subscriptions and provide paid features;
- display banner and interstitial advertising; and
- deliver requested support.
6.2 Operate AI features
We use conversation content and relevant context to:
- generate an AI response;
- preserve continuity across a conversation;
- generate summaries, themes, suggested exercises, or profile updates;
- help identify content that may require a safety-oriented response;
- evaluate response quality and investigate reported errors; and
- improve HMARA’s prompts, product design, safeguards, and user experience.
We do not use your private conversation content to train a general-purpose HMARA model. If this practice changes, we will first provide a separate explanation, update this Policy, and obtain any consent required by law.
6.3 Maintain safety, security, and integrity
We use information to:
- authenticate users and protect accounts;
- detect spam, fraud, abuse, unauthorized access, and violations of our terms;
- debug errors, monitor reliability, and prevent service disruption;
- investigate security incidents and maintain audit records;
- enforce legal terms and protect the rights, safety, and property of HMARA, users, and others; and
- comply with lawful requests and applicable legal obligations.
6.4 Communicate with you
We use contact and notification information to:
- send service, security, account, and subscription notices;
- send reminders and wellbeing prompts you request;
- respond to questions and privacy requests;
- explain material changes to the Service or this Policy; and
- send optional promotional messages where permitted and with any required consent.
You can opt out of marketing communications without opting out of essential service messages.
6.5 Analyze and improve HMARA
We may use appropriately limited product-use and diagnostic information to:
- understand which features work and how they are used;
- improve accessibility, performance, localization, and navigation;
- measure course completion and feature effectiveness;
- conduct aggregate reporting and product planning;
- test new features; and
- identify and correct technical issues.
Where feasible, we aggregate or de-identify this information. We do not intentionally send conversation content, assessment answers, psychological profiles, or other consumer health data to Sentry or another diagnostics provider. Diagnostic events may contain limited device, application, network, account, and error context needed to investigate a technical problem.
6.6 Advertising
We use limited device and advertising information to display, measure, secure, frequency-cap, and account for contextual/non-personalized advertisements. We do not use consumer health data to select advertisements.
6.7 Meet legal and compliance obligations
We may use and preserve information where reasonably necessary to:
- comply with tax, accounting, consumer-protection, privacy, and other laws;
- respond to binding legal process;
- establish, exercise, or defend legal claims;
- maintain consent, privacy-request, and transaction records; and
- notify individuals and regulators about a qualifying security incident.
7. Legal Bases for Processing in the EEA, United Kingdom, and Switzerland
Where European data-protection law applies, HMARA relies on the following legal bases. More than one basis may apply to a processing activity.
- Create an account and provide requested core features — Personal information: Account, conversation, course, preference, and subscription information — Legal basis: Performance of a contract or steps requested before entering a contract
- Process health-related or other special-category information for personalization — Personal information: Conversation, assessment, wellbeing, and inferred profile information — Legal basis: Your explicit consent, together with consent or contract as the applicable Article 6 basis
- Optional microphone, notifications, non-essential analytics, or advertising technologies — Personal information: Audio, push token, device, analytics, and advertising information — Legal basis: Consent, where required
- Secure, debug, and protect the Service — Personal information: Limited account, device, log, fraud, and diagnostic information — Legal basis: Our legitimate interests in security, reliability, abuse prevention, and legal protection, balanced against your rights
- Respond to support and privacy requests — Personal information: Contact, account, request, and verification information — Legal basis: Contract, legal obligation, and legitimate interests
- Comply with law and protect legal rights — Personal information: Relevant records — Legal basis: Legal obligation, legitimate interests, or, in exceptional circumstances, protection of vital interests
Consent is not a condition for processing that is not necessary to provide the requested Service. You may withdraw consent at any time through available in-app controls or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal.
Where HMARA relies on consent to process mental-health or other special-category information, the consent request is presented separately from general acceptance of the Terms. You may withdraw consent by using an available in-app control or by contacting us. Withdrawal may require us to disable the affected personalized feature or delete the information that depended on consent.
8. AI Processing, Personalization, and Profiling
8.1 How AI processing works
When you submit a message, HMARA may combine it with system instructions, selected conversation history, profile information, language, safety instructions, and feature context. That information is transmitted securely to an AI service provider, currently OpenAI, which returns generated content to HMARA.
HMARA may also use automated processing to generate:
- conversation summaries;
- topics or themes;
- wellbeing patterns and trends;
- suggested courses, exercises, or prompts;
- language and style preferences;
- risk or safety-related signals; and
- a personalized profile used to improve continuity and relevance.
These outputs are probabilistic inferences, not verified clinical findings.
8.2 Human review
HMARA administrators have technical access to user records, including conversations, but HMARA does not routinely read private conversations. Authorized personnel may access only the information reasonably necessary to respond to a user-requested support issue, investigate a security incident or abuse report, address a specifically reported AI response, comply with a binding legal request, or protect a person from serious harm where permitted by law. Routine or unrestricted staff review of private conversations is not part of HMARA’s operations.
8.3 OpenAI data handling
OpenAI processes API data on HMARA’s behalf under applicable contractual terms. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer affirmatively opts in. OpenAI may retain certain abuse-monitoring logs containing prompts, responses, or related metadata for up to 30 days by default, unless a longer period is required by law or reasonably necessary to protect its services or third parties. Some API features may retain application state. HMARA does not represent that Zero Data Retention or Modified Abuse Monitoring is currently enabled.
HMARA does not opt in to OpenAI model training with user content. For a child below 13 or the applicable age of digital consent, HMARA will make an AI feature that sends personal data to OpenAI available only after required parental authorization has been obtained and any provider safeguard required for processing a child’s data, including Zero Data Retention where applicable, is active. If those conditions are not met, that AI feature is not available to the child.
8.4 No solely automated decisions with legal or similarly significant effects
HMARA does not use AI or profiling to make decisions that produce legal effects or similarly significant effects concerning you, such as decisions about employment, credit, insurance, housing, education admission, or access to essential services.
You can contact us to ask about personalization, correct information used in your profile, or request deletion of your profile and conversation history.
9. Advertising and Privacy Choices
HMARA may display banner and interstitial advertisements. Advertising is provided by Google AdMob. Advertisements are intended to be available in every supported launch country.
9.1 Information used for ads
AdMob may automatically process IP address, device and app identifiers, user interaction with ads, diagnostic information, and other information described in Section 4.8. Google’s processing is also governed by its own privacy disclosures where it acts independently.
9.2 Contextual, non-personalized, and age-restricted ads
HMARA requests contextual, non-personalized, or age-restricted ads rather than ads personalized from a user’s HMARA activity. In the EEA, United Kingdom, Switzerland, and other regions requiring consent, HMARA will request any required privacy choice through a consent-management interface before initializing non-essential advertising technology or accessing an advertising identifier.
HMARA does not use HMARA conversation, assessment, wellbeing, course, or psychological-profile information for tracking or cross-context behavioral advertising. Where device-platform rules or applicable law require permission before accessing an advertising identifier or other non-essential ad technology, HMARA requests that permission and respects the user’s choice.
For users known to be children or below the applicable age of digital consent, HMARA requests child-directed or age-restricted treatment, does not request personalized advertising, and limits advertising identifiers and other non-essential ad data as required by law and app-store rules.
9.3 Changing your choice
Privacy and advertising controls will be available at Settings → Privacy. You can also limit advertising tracking through your device settings or contact oleksiikhudenko61@gmail.com.
HMARA does not sell personal information or authorize cross-context behavioral advertising. California and other U.S. residents may submit an opt-out or privacy request at oleksiikhudenko61@gmail.com.
9.4 No advertising based on consumer health data
HMARA does not disclose consumer health data to an advertising network for advertising, does not create advertising segments based on HMARA conversations or assessments, and does not permit an advertising SDK to access those fields.
10. When We Disclose Personal Information
We disclose personal information only as described below.
10.1 Service providers and processors
We use vendors to operate the Service. They may process information only for contracted purposes and subject to appropriate confidentiality, security, and data-protection obligations.
- Supabase — Purpose: Authentication, database, storage, and delivery of application content and translations — Information involved: Account, profile, conversations, assessments, course progress, preferences, and technical logs — Provider role and location: Processor; the HMARA project is hosted in the European Union, in Germany.
- OpenAI — Purpose: Generate AI responses, summaries, and related AI functionality — Information involved: Prompt, selected conversation context, profile context, safety instructions, and generated output — Provider role and location: Processor/service provider; processing may occur in the United States and other documented locations.
- RevenueCat — Purpose: Validate and manage subscriptions and entitlements — Information involved: App user ID, product, transaction, subscription, and device information — Provider role and location: Processor/service provider; processing may occur outside your country.
- Apple and Google — Purpose: Authentication, app distribution, purchases, push delivery, platform security, and device services — Information involved: Account identifiers, transaction records, push token and payload, device and technical information — Provider role and location: May act as independent controllers and/or service providers under their terms.
- Google AdMob — Purpose: Deliver, secure, measure, and account for contextual/non-personalized advertising — Information involved: IP address, limited device/app/ad identifiers, ad interactions, consent and age-treatment signals, diagnostics, and approximate region — Provider role and location: May act as an independent controller and/or service provider. No HMARA conversation or health-profile data is provided.
- Sentry — Purpose: Error monitoring, crash diagnostics, and performance — Information involved: Limited diagnostic, device, app, network, account, and error information — Provider role and location: Processor/service provider. HMARA does not intentionally send conversation or consumer health data to Sentry.
- Expo — Purpose: Route push notifications and support application infrastructure — Information involved: Push token, notification payload, delivery information, and technical logs — Provider role and location: Processor/service provider; payload then passes to Apple or Google push services.
- Vercel — Purpose: Host and secure the HMARA website — Information involved: IP address, request, browser, device, security, and website log information — Provider role and location: Processor/service provider.
- Professional advisers — Purpose: Legal, accounting, audit, insurance, and compliance — Information involved: Information reasonably necessary for the engagement — Provider role and location: Independent controller or processor, depending on the service.
Provider details, subprocessors, and processing locations can change. We require providers to apply protections appropriate to the information and service they provide.
10.2 Legal, safety, and rights-protection disclosures
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with a law, regulation, court order, subpoena, or other binding legal process;
- respond to a lawful request from a competent authority;
- establish, exercise, or defend legal claims;
- investigate fraud, abuse, unauthorized access, or a security incident;
- enforce our agreements and policies; or
- protect the vital interests, rights, safety, and property of a person, HMARA, or the public, where permitted by law.
We review government and law-enforcement requests for legal validity and seek to narrow or challenge overbroad requests where appropriate.
10.3 Corporate transactions
If HMARA is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be disclosed to advisers and transaction participants subject to appropriate safeguards. We will provide notice where required before personal information becomes subject to a materially different privacy policy.
10.4 At your direction
We may disclose information when you direct us to do so, such as when you choose to share content or connect a third-party service. We will explain what information is involved at the time where the disclosure is not already clear.
10.5 Aggregate or de-identified information
We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably be linked to an individual. We maintain de-identified information in de-identified form and do not attempt to re-identify it except to test the effectiveness of our de-identification methods or as permitted by law.
11. Sale, Sharing, and Targeted Advertising
HMARA does not sell personal information for money. HMARA does not sell consumer health data.
Some privacy laws define “sale,” “sharing,” or “targeted advertising” broadly enough to include disclosing device or online-activity information to an advertising network in order to select or measure an advertisement. HMARA does not authorize AdMob to use HMARA activity for personalized or cross-context behavioral advertising and does not receive money for personal information.
HMARA may disclose an IP address, limited device or app information, consent or age-treatment signals, and ad-interaction information to Google AdMob to deliver, measure, secure, and frequency-cap contextual/non-personalized advertising, subject to the user’s region, age, consent status, device settings, and HMARA’s configuration. HMARA does not knowingly sell or share the personal information of consumers under 16 and does not disclose HMARA consumer health data for targeted advertising.
You may submit an opt-out request by emailing oleksiikhudenko61@gmail.com, through applicable device settings, or through Settings → Privacy when that in-app control becomes available.
12. International Data Transfers
HMARA and its providers may process personal information in countries other than the country where you live. Those countries may have different data-protection laws.
For transfers of personal information from the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing adequate protection, HMARA will use an approved transfer mechanism as applicable, such as:
- the European Commission’s Standard Contractual Clauses;
- the United Kingdom International Data Transfer Addendum or International Data Transfer Agreement;
- a valid adequacy decision;
- an applicable certification framework; or
- another lawful derogation for a specific transfer.
We also assess transfer risks and apply supplementary safeguards where appropriate, such as encryption in transit and at rest, access restrictions, data minimization, and contractual limits.
You may contact us to request information about the safeguards relevant to your information. Certain confidential commercial or security details may be redacted.
13. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, honoring user choices, meeting legal obligations, resolving disputes, and protecting security.
In applying this rule:
- account, profile, conversation, transcript, assessment, inferred-profile, course-progress, preference, and related user content is retained while the account remains active and is deleted or de-identified when the account is deleted, subject to the limited exceptions below;
- original voice audio is retained only long enough to create a transcript and is then deleted;
- push tokens are retained until notifications are disabled, the token expires, or the account is deleted;
- diagnostic, security, support, consent, advertising-reporting, and privacy-request records are retained only for the period reasonably necessary to operate and secure the Service, investigate an issue, respond to the request, demonstrate compliance, or establish or defend a legal claim;
- subscription and transaction records are retained for the periods required by tax, accounting, consumer-protection, fraud-prevention, and app-store obligations;
- de-identified or aggregate information may be retained where it can no longer reasonably be linked to an individual;
- provider-held information is retained under the applicable provider settings and contractual terms, including OpenAI’s default abuse-monitoring period described in Section 8.3; and
- residual copies may remain in protected backups until those backups are overwritten in the ordinary backup cycle. Backup data is not used for ordinary product purposes.
We may retain limited information longer when required by law, subject to a legal hold, necessary to establish or defend a claim, or needed to investigate fraud or a security incident. When deletion is not immediately possible, we restrict the information from ordinary use until deletion is completed.
14. Security
HMARA uses administrative, technical, and physical safeguards designed to protect personal information. Depending on the system and risk, safeguards may include:
- encryption in transit and at rest;
- least-privilege access and role-based permissions;
- multi-factor authentication for administrative systems;
- separation of production and development environments;
- secrets and key management;
- logging and review of privileged access;
- data minimization and pseudonymous identifiers;
- processor due diligence and contractual safeguards;
- vulnerability management, dependency updates, and secure development practices;
- incident-response and breach-notification procedures; and
- backups and service-recovery controls.
No system is completely secure. You are responsible for maintaining the confidentiality of your device and authentication methods. Contact us immediately at oleksiikhudenko61@gmail.com if you believe your account or information has been compromised.
15. Your Choices and Controls
Depending on your device and location, you can:
- edit account and profile information in the application;
- withdraw sensitive-data consent and request deletion of the related information;
- enable or disable microphone access through device settings;
- enable, disable, or limit notification previews through device settings;
- manage available privacy and advertising choices through Settings → Privacy;
- limit ad tracking through Apple or Android settings;
- unsubscribe from marketing email using the link in the message;
- submit a request to access, correct, export, or delete information; and
- request deletion of your account by emailing oleksiikhudenko61@gmail.com, or by following the HMARA account-deletion page (https://www.hmara.care/delete-account).
HMARA does not currently provide a control for deleting one individual conversation while retaining the rest of the account. You may request deletion of the complete account and all user-linked information, subject to the limited legal-retention exceptions described in Section 13.
Some choices affect functionality. For example, withdrawing consent to process sensitive wellbeing information may require HMARA to delete your profile or disable personalized wellbeing features.
16. Your Privacy Rights
Privacy rights vary by location. Subject to applicable law and exceptions, you may have the right to:
- know whether we process your personal information;
- access personal information and receive a copy;
- correct inaccurate personal information;
- delete personal information;
- receive certain information in a portable format;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit certain uses or disclosures of sensitive personal information;
- obtain information about categories and specific third parties to which information was disclosed;
- appeal our refusal to act on a request;
- lodge a complaint with a data-protection authority; and
- not be discriminated against for exercising a privacy right.
16.1 How to submit a request
Submit a request through:
- In-app: Settings → Privacy, when this planned control is released
- Email: oleksiikhudenko61@gmail.com
Describe the right you wish to exercise and the account involved. Do not send a password or unnecessary sensitive information.
16.2 Verification
We may need to verify your identity before completing a request. We will request only information reasonably necessary for verification. If we cannot verify a request, we will explain why and may ask for additional information.
An authorized agent may submit a request where permitted by law. We may require proof that the agent has authority and may ask you to confirm the request directly.
16.3 Response and appeal
We respond within the period required by applicable law. If we need an extension, we will explain the reason where required. We may deny or limit a request when an exception applies, such as where information is needed for security, legal compliance, another person’s rights, or a legal claim.
If we deny your request, you may appeal by emailing oleksiikhudenko61@gmail.com with the subject “Privacy Appeal.” We will explain the result and, where applicable, how to contact your state attorney general or supervisory authority.
17. Account Deletion
Users who can create an HMARA account can initiate deletion:
- by emailing a deletion request to oleksiikhudenko61@gmail.com; or
- by following the instructions on the HMARA account-deletion page (https://www.hmara.care/delete-account).
Account deletion deletes or de-identifies the account and all information linked to that user in HMARA’s active systems, including profile and authentication records, conversations and transcripts, assessments and answers, inferred psychological or conversational profiles, wellbeing and safety signals, course progress, preferences, notification tokens, and other user-linked application data. Limited transaction, security, consent, or request records may be retained only where required by law or reasonably necessary for fraud prevention, security, dispute resolution, or proof of compliance, as described in Section 13. Deleting the application from your device does not delete your account.
Deleting an HMARA account does not automatically cancel an Apple App Store or Google Play subscription. You must manage cancellation through the applicable store. Account deletion also does not require HMARA to delete transaction records that it must retain for legal, accounting, fraud-prevention, or dispute purposes.
We will communicate completion or any applicable exception. Residual copies may remain temporarily in protected backups until rotation, but they will not be used for ordinary purposes.
18. Children and Teenagers
The minimum age for HMARA is 4 years. A child may use HMARA only with the involvement, supervision, and authorization of a parent or legal guardian whenever the child is not legally able to consent to the relevant processing independently.
HMARA may collect personal information from a child below the applicable age of digital consent only after providing any required direct notice to the parent or legal guardian and obtaining verifiable parental consent. In the United States, this generally applies to children under 13 under COPPA. In the EEA, the age at which a child may consent to an information-society service varies by Member State from 13 to 16. HMARA applies the rule required in the child’s country and may require parental authorization at a higher age because the Service can process sensitive wellbeing information.
Where required parental authorization or child-specific safeguards are not available, a child may not create an account, submit personal information, or use an interactive feature that processes personal information. The additional restriction for AI features that transmit data to OpenAI is described in Section 8.3.
A parent or legal guardian may contact oleksiikhudenko61@gmail.com to ask what information HMARA holds about a child, review it, withdraw consent, request correction, or request deletion of the child’s account and user-linked information.
HMARA does not use a child’s conversations, course activity, assessments, mood, wellbeing information, or psychological profile for advertising. Advertising shown to a known child is contextual/non-personalized and configured for child-directed or age-restricted treatment. Advertising identifiers and other non-essential data are limited where required. HMARA will not use PostHog or another non-essential product-analytics tool for known child users unless that processing is lawful, age-appropriate, disclosed in this Policy, and subject to any required parental authorization.
If HMARA learns that personal information was collected from a child without required parental authorization, HMARA will suspend the child’s access, stop further non-essential processing, and delete the information unless a limited legal exception permits retention.
19. Region-Specific Disclosures
19.1 European Economic Area, United Kingdom, and Switzerland
The Controller and contact details are in Section 1. The purposes, categories, legal bases, recipients, transfers, and retention periods are described in Sections 4–13.
You may have rights of access, correction, deletion, restriction, portability, objection, and withdrawal of consent. You also have the right to complain to the supervisory authority where you live, work, or believe an infringement occurred. EEA supervisory authorities are listed by the European Data Protection Board. United Kingdom users may complain to the Information Commissioner’s Office. Swiss users may contact the Federal Data Protection and Information Commissioner.
HMARA is established in Ukraine. Until HMARA publishes a local representative contact for a jurisdiction, users may contact the Controller directly using the email address in Section 1. If HMARA appoints an EEA or UK representative or a Data Protection Officer, the relevant contact details will be added to this Policy.
19.2 California Privacy Notice
This subsection supplements the rest of the Privacy Policy for California residents and uses terms defined by the California Consumer Privacy Act, as amended.
Categories collected
During the preceding 12 months, HMARA may have collected the following categories:
- Identifiers: name, email, account ID, IP address, device ID, advertising ID, transaction ID, and push token.
- Customer-record information: contact, account, subscription, and support information.
- Protected classifications: age range or sensitive characteristics you choose to disclose in a conversation or assessment.
- Commercial information: subscription product, purchase, renewal, cancellation, refund, entitlement, and advertising interaction information.
- Internet or electronic network activity: app interactions, content viewed, session, referral, ad interaction, crash, diagnostic, and security logs.
- Geolocation: approximate location derived from IP address; precise location is not intended to be collected.
- Audio information: voice submitted for transcription, if the voice feature is used.
- Sensitive personal information: account credentials, precise geolocation if unexpectedly received, message contents when HMARA is not the intended recipient under applicable definitions, and information concerning health, sex life, sexual orientation, racial or ethnic origin, religion, or similar characteristics that you choose to provide.
- Inferences: themes, preferences, wellbeing trends, profile attributes, recommended content, and safety-related signals.
The sources are listed in Section 5. Business and commercial purposes are listed in Section 6. Categories of recipients are listed in Section 10.
Sale and sharing
HMARA does not sell personal information for money, does not sell consumer health data, and does not authorize AdMob to use HMARA activity for cross-context behavioral advertising. HMARA may disclose limited device, IP-address, consent, age-treatment, and ad-interaction information to AdMob to provide contextual/non-personalized advertising. HMARA does not disclose conversation content, assessments, or psychological-profile information for advertising.
You can submit an opt-out or privacy request through Settings → Privacy when that control becomes available or at oleksiikhudenko61@gmail.com. HMARA does not knowingly sell or share personal information of consumers under 16.
Sensitive personal information
HMARA uses sensitive personal information to provide requested wellbeing features, secure the Service, and perform other purposes described in this Policy. HMARA does not use or disclose sensitive personal information to infer characteristics for advertising. If HMARA begins using sensitive personal information beyond legally permitted purposes, we will provide a right to limit that use.
California rights
Subject to exceptions, California residents may request to know, access, correct, or delete personal information; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing after exercising a right. California residents may use an authorized agent.
California’s “Shine the Light” law may provide additional rights concerning disclosure of personal information for third parties’ own direct marketing. HMARA does not disclose HMARA conversation or profile information to third parties for their own direct marketing.
Metrics and financial incentives
HMARA does not currently offer a financial incentive in exchange for personal information. If we introduce a program covered by California financial-incentive rules, we will provide a separate notice.
19.3 U.S. Consumer Health Data Privacy Notice
This subsection is HMARA’s Consumer Health Data Privacy Notice for residents covered by U.S. consumer health data laws, including Washington’s My Health My Data Act and Nevada’s consumer health data law. It applies to personal information that is linked or reasonably linkable to a consumer and identifies or permits an inference about the consumer’s past, present, or future physical or mental health.
Categories of consumer health data
Depending on how you use HMARA, we may collect:
- mental or physical health conditions, symptoms, concerns, or status that you choose to discuss;
- mood, stress, sleep, energy, motivation, and wellbeing information;
- assessment, questionnaire, exercise, journal, and check-in responses;
- information about diagnoses, treatments, medications, healthcare providers, or health services that you choose to mention;
- information relating to gender-affirming care, reproductive or sexual health, if you choose to provide it;
- biometric or voice information only to the extent it is processed to identify or infer health status; HMARA does not use voice for identity recognition;
- precise location only if unexpectedly received; HMARA does not intend to collect precise location for health purposes;
- course selections, searches, interactions, or purchases that reveal or permit an inference about health;
- conversation content and transcripts that reveal or permit an inference about health;
- inferred themes, patterns, risk signals, preferences, or a personalized psychological profile; and
- identifiers linked to any of the above.
Sources
We collect consumer health data directly from you, from your use of HMARA, from your device where you grant permission, and from inferences generated by HMARA. We may receive limited subscription, authentication, or technical information from Apple, Google, RevenueCat, and other providers, but those providers do not supply HMARA with independent medical records.
Purposes
We collect and use consumer health data to provide the wellbeing feature you request, generate AI responses and personalized insights, maintain conversation continuity, save progress, recommend HMARA content, respond to support, maintain safety and security, comply with law, and honor privacy requests. We do not use consumer health data to determine eligibility for employment, housing, credit, insurance, education, or essential services.
If HMARA wants to collect a new category of consumer health data or use existing consumer health data for a materially different purpose not described here, we will provide any notice and obtain any consent required by law before doing so.
Categories of consumer health data shared
HMARA may share the following consumer health data only as necessary to provide a feature you request:
- account, conversation, assessment, profile, and course data with Supabase for hosting and storage;
- a prompt, selected conversation context, and related profile context with OpenAI to generate an AI output;
- relevant information with professional advisers or authorities when legally required or necessary to establish or defend a claim; and
- information with another party at your direction.
HMARA does not share consumer health data with AdMob or other advertising networks. HMARA does not permit Sentry to receive consumer health data.
Specific entities and affiliates
The specific entities that may receive consumer health data are:
- Supabase, Inc. and its disclosed infrastructure subprocessors;
- OpenAI, L.L.C. and its disclosed subprocessors;
- professional advisers or authorities only where legally necessary, as described in Section 10; and
- HMARA has no affiliates that receive consumer health data.
Contact oleksiikhudenko61@gmail.com to request a current provider and subprocessor list and available contact information for applicable recipients.
Sale and advertising
HMARA does not sell consumer health data. HMARA does not use consumer health data for targeted advertising. If that practice changes, HMARA will first update this Notice and obtain the separate valid authorization or consent required by applicable law.
Geofencing
HMARA does not use a geofence around an entity that provides in-person healthcare services to identify, track, collect data from, or send messages or advertisements to a consumer regarding consumer health data.
Consumer health data rights
Subject to applicable law, you may:
- confirm whether HMARA collects, shares, or sells your consumer health data;
- access that data, including a list of third parties and affiliates with which it was shared or sold and available contact information;
- withdraw consent for collection or sharing;
- delete consumer health data held by HMARA and, where required, have deletion communicated to processors, affiliates, and other recipients;
- correct inaccurate information;
- obtain a portable copy; and
- appeal a refusal to act.
Submit a request using the methods in Section 16. To appeal, email oleksiikhudenko61@gmail.com with the subject “Consumer Health Data Appeal.”
Deletion from archives or backups may take additional time permitted by applicable law. Until deletion, backup data will be isolated from ordinary processing.
19.4 Other U.S. States
Residents of states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects.
HMARA does not conduct profiling for legal or similarly significant decisions. Requests and appeals can be submitted as described in Section 16. If an appeal is denied, we will provide information about contacting the applicable attorney general where required.
19.5 Ukraine
Where Ukrainian data-protection law applies, HMARA processes personal data for the purposes and on the grounds described in this Policy and provides rights of access, correction, objection, withdrawal of consent, and deletion subject to applicable law.
You may contact oleksiikhudenko61@gmail.com with a request or complaint. You may also have the right to complain to the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman).
20. Cookies and Similar Technologies
HMARA’s website and application may use local storage, SDKs, pixels, cookies, and similar technologies to:
- keep you signed in and remember settings;
- secure the Service and prevent abuse;
- understand performance and errors;
- measure use of features; and
- provide and measure advertising.
Strictly necessary technologies operate because they are needed to deliver or secure the Service. Where law requires, we ask for consent before using non-essential analytics, advertising, or tracking technologies.
HMARA does not currently use PostHog or another non-essential product-analytics platform. When the planned privacy controls are released, application choices will be available through Settings → Privacy. Browser and device controls may delete or block cookies or identifiers, but some features may not work. A browser “Do Not Track” setting is not a standardized legal signal in every jurisdiction.
21. Third-Party Links and Services
HMARA may link to websites, app stores, emergency resources, or other services not controlled by HMARA. We are not responsible for their privacy, security, accuracy, or availability. Review their privacy notices before providing information.
Apple, Google, OpenAI, AdMob, and other providers may also process information as independent controllers for their own purposes, such as platform security, fraud prevention, service administration, or legal compliance, as described in their notices.
22. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the Service, technology, providers, law, or our practices. We will update the “Last updated” date and version.
If a change materially affects your rights or how we use sensitive information, we will provide additional notice through the application, email, website, or another appropriate method. We will obtain consent before applying a new practice where consent is required by law.
Earlier versions will be available on request.
23. Contact Us
Questions, requests, or complaints about privacy can be sent to:
Individual Entrepreneur Oleksii Khudenko Anny Akhmatovoi Street, Kyiv, Ukraine oleksiikhudenko61@gmail.com https://www.hmara.care/
If you need help with the Service rather than a privacy request, contact oleksiikhudenko61@gmail.com.
For security reports, contact oleksiikhudenko61@gmail.com.
24. Provider Privacy Information
The following links are provided for transparency. A provider’s notice does not replace HMARA’s responsibility for its own processing.
- Supabase Privacy and Data Processing information: https://supabase.com/privacy and https://supabase.com/legal/dpa
- OpenAI API data controls, Under 18 API Guidance, Enterprise Privacy, and Data Processing Addendum: https://developers.openai.com/api/docs/guides/your-data, https://developers.openai.com/api/docs/guides/safety-checks/under-18-api-guidance, https://openai.com/enterprise-privacy/, and https://openai.com/policies/data-processing-addendum/
- RevenueCat Privacy and Data Processing information: https://www.revenuecat.com/privacy/ and https://www.revenuecat.com/dpa/
- Sentry Privacy and Data Processing information: https://sentry.io/privacy/ and https://sentry.io/legal/dpa/
- Google Privacy Policy and AdMob privacy resources: https://policies.google.com/privacy and https://support.google.com/admob/topic/9756841
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Expo Privacy Policy: https://expo.dev/privacy
- Vercel Privacy Policy: https://vercel.com/legal/privacy-policy