This Privacy Policy applies to the Hues Within mobile app, website, account services, exports, share images, and support.
1. Where your information is kept
Hues Within keeps its working records in the app database on your device. If you use the app without an account, your check-ins remain device-local. When you sign in, completed manual check-ins and basic profile details are also backed up to your private Hues Within account so they can be restored on another device where you sign in to the same account.
Prescription history, cycle records outside completed check-ins, custom questions, reminders, most preferences, and generated insights remain on your device unless a feature you choose explicitly sends information elsewhere. A completed check-in backup includes every answer saved in that check-in, which may include medication, symptom, note, and period information. Supabase processes account authentication and the signed-in check-in and basic-profile backups.
2. Information you choose to record
- daily check-ins, including mood, energy, interest, irritability, everyday manageability, sleep duration and need for sleep, medications taken, symptoms, changes from usual, emotions, movement, activities, notes, custom answers, and timestamps;
- current and past medication names, doses, units, prescription snapshots, dates, and what you report taking on a particular day;
- optional period and menstrual-cycle records and settings;
- display name, age, country, gender identity, reminders, custom tags, custom questions, insight preferences, and other settings; and
- PDF or spreadsheet reports, and chart or calendar images, you intentionally generate.
These records can reveal sensitive health information. Reports and share images are generated only when you request them; Hues Within does not automatically send them to a clinician, family member, employer, insurer, or anyone else.
3. Account and sign-in information
If you create an account, Supabase Authentication processes your account identifier, email, sign-in provider, and session information. Apple sign-in provides the basic account details Apple releases for authentication, such as a provider identifier and, when available, an email. Apple sign-in does not give Hues Within access to iCloud files. For native Sign in with Apple, Hues Within may securely store an Apple-issued revocation credential in the account backend solely to disconnect the sign-in relationship when the account is deleted. If Apple does not accept the revocation at that time, the credential is moved to a restricted, server-only retry queue so account deletion can still finish. The queue is reviewed through a manual operator process; the credential is removed when revocation succeeds or on the first later retry run after it has been pending for 14 days. Email sign-in may use a password, a one-time code, or a password-reset link. You may use the app without an account where guest access is offered. Signed-in backup contains completed check-in answers and dates, plus the display name, age, country, and gender identity you save in your profile. Edits replace the backed-up version for that date, and deletion markers prevent a deleted check-in from silently reappearing on another signed-in device.
To verify and restore an App Store purchase, Hues Within keeps a restricted, server-only purchase ledger containing the Apple original transaction identifier, product and plan, the latest transaction signed date, verification timestamps, and—while the purchase is attached to an active account—the Hues Within account identifier. The ledger does not contain journal entries, profile details, or an account email. When that account is deleted, its identifier is cleared from the ledger, while the remaining purchase record is retained so the same Apple purchase can be restored safely and duplicate or conflicting claims can be prevented. A separate server-only replay log keeps an App Store notification identifier and the time received so the same notification is not applied twice; it does not contain journal, profile, or account-email information.
4. Technical and support information
Service providers may process limited technical information such as IP address, request time, browser or device information, authentication events, and error details to deliver and secure the service. If you contact support, Hues Within processes your email address, message, and anything you choose to include. Please do not email sensitive health details unless they are necessary for your request.
5. How information is used
Hues Within uses information only to:
- save and display the records, preferences, history, reports, and share images you request;
- back up and restore completed check-ins and basic profile details when you sign in;
- show descriptive patterns and context from recorded dates without diagnosing, predicting, or determining cause;
- authenticate accounts and maintain secure sessions;
- respond to support, privacy, security, and deletion requests; and
- prevent abuse, diagnose service failures, and protect the service.
Health information is used only to provide the features you choose. Hues Within does not sell personal or health information, use it for advertising, share it with data brokers, provide it to insurers or employers, or use private records to train, fine-tune, evaluate, prompt, or otherwise supply an artificial-intelligence model.
6. Service providers and disclosures
- Supabase provides authentication, private signed-in check-in and basic-profile backups, Plus entitlement and purchase-restoration records, the restricted Apple-revocation retry queue, database security, and server functions.
- Apple processes Apple sign-in when you choose it and App Store purchases, restoration, billing, and subscription management. Hues Within receives transaction and entitlement information needed to verify and provide Plus, not your full payment-card details.
- Google Workspace provides the support and privacy-request mailbox. If you email Hues Within, Google processes the message, sender and recipient information, attachments, and related security and delivery metadata to provide and protect the email service.
- OpenAI Sites and its hosting infrastructure deliver the public website and may keep limited request, security, and reliability logs.
- Authorities or professional advisers may receive information when reasonably necessary to comply with law, protect rights and safety, or investigate a security incident.
These providers may process information in countries where they operate. Hues Within uses safeguards required by applicable law for international transfers.
7. Retention and deletion
- Device-local records remain until you delete an available record, use the guest data-erasure control, delete your account successfully, or delete the app and its data. Guest erasure also clears Hues Within reminders and attempts to clear cached reports or share images that the app can access, but intentionally keeps the device's language choice and app-lock setting.
- Signed-in check-in backups remain while your account is active. Editing a check-in replaces the backed-up version for that date. Deleting a check-in removes its backed-up answers and keeps a deletion marker so an older device does not restore them.
- Signed-in basic-profile backups remain while your account is active and are updated when you edit the backed-up profile fields.
- Account information, the active Plus entitlement, and signed-in backups remain while the account is active. When Delete account completes successfully, it removes the authentication account and those Hues Within records from active cloud systems. Limited copies may remain temporarily in provider infrastructure backups, or for security, legal compliance, fraud prevention, or dispute resolution, until the applicable retention period ends.
- The minimal purchase ledger and notification replay log described above remain after account deletion, but the ledger’s Hues Within account link is cleared. Hues Within retains these limited records while reasonably needed to restore the purchase, prevent duplicate or conflicting claims, administer transaction changes, protect against fraud, resolve disputes, or meet legal obligations. Apple may retain its independent purchase records under its own terms.
- If an Apple sign-in revocation initially fails, its credential remains only in the restricted retry queue described above. Because retry runs are manual, it may remain longer than 14 calendar days; it is removed when revocation succeeds or on the first retry run after it has reached 14 days.
- Support and privacy correspondence remains only as long as reasonably needed to respond, document compliance, or resolve a dispute.
See the Data deletion page for the available steps and scope.
8. Security
Hues Within uses HTTPS, restricted database access, row-level security, and device-secured authentication storage. The optional app lock uses the device's own Face ID, Touch ID, or passcode check; Hues Within does not receive or store biometric templates. Access is limited to what is needed to operate the service. No system can guarantee absolute security. If a breach creates legally reportable risk, affected users and authorities are notified as required.
9. Your choices and rights
You can use guest mode, skip unanswered questions, disable optional medication or period tracking, choose whether to use the app lock, export reports or share images, delete individual check-ins, clear guest data, and permanently delete your signed-in account from Settings. Depending on where you live, you may also have rights to access, correct, delete or cancel, restrict or oppose processing, withdraw consent, receive portable data, and complain to a privacy authority. Mexico residents may exercise applicable ARCO rights. Hues Within does not discriminate against anyone for exercising a privacy right.
Regional privacy notices
- Mexico Privacy Notice and ARCO procedure
- Canada and Québec Privacy Notice
- Washington Consumer Health Data Privacy Policy
- U.S. Consumer Health Data Privacy Policy and rights process
Exercising ARCO rights in Mexico
ARCO means access to your personal data, rectification of inaccurate or incomplete data, cancellation when you want data deleted, and opposition when you object to a particular use. To make a request, email hello@hueswithinapp.com with the subject “ARCO privacy request.” Include your name, the email used for your Hues Within account, the right you want to exercise, a clear description of your request, and the email where you want to receive the response. If someone is acting for you, include enough information to confirm their authority. Please do not send journal entries, health details, passwords, or other unnecessary sensitive information.
Hues Within may use the account email or another proportionate authentication step to verify identity or account ownership. If information needed to process the request is missing, Hues Within may ask you to complete it. Hues Within will communicate its decision within 20 days after receiving a complete request. If the request is granted, it will be carried out within the following 15 days. When justified and permitted by law, either period may be extended once for the same length, and Hues Within will tell you why.
Exercising ARCO rights is free. You are responsible only for reproduction or delivery costs allowed by law, if any; electronic access will be provided when practical. Cancellation may be limited where Hues Within must retain or block data for legal, security, or dispute-resolution reasons. If you disagree with the response, you may contact Mexico’s Secretaría Anticorrupción y Buen Gobierno or another competent data-protection authority.
10. Legal bases where applicable
Where applicable law requires a specific legal basis, Hues Within relies on your request to provide a feature, consent where required and validly obtained, compliance with a legal obligation, or another basis that the applicable law permits and that Hues Within discloses when required. When Hues Within relies on consent for a purpose, you may withdraw it using the available consent control or by contacting Hues Within. Withdrawal does not make earlier lawful processing unlawful and is separate from deletion.
11. Age eligibility
Hues Within is intended only for adults age 18 or older. People under 18 may not create an account, use guest access, or otherwise use Hues Within. Contact Hues Within if you believe a person under 18 has provided information so the situation can be reviewed and appropriate action taken, including deletion where required.
12. Website cookies and logs
The public information pages do not set advertising cookies. The hosting provider may keep limited request logs for security and reliability.
13. Changes to this policy
Changes are posted here with an updated date. Hues Within provides additional notice or seeks renewed consent when required, including before materially expanding how sensitive information is used.
14. Third-party policies
15. Controller and contact
Cynthia Salinas Treviño is the Privacy Lead and the operator and controller of Hues Within. Her legal domicile as controller is Manuel Alanis 6, Col. Lomas del Hipico, 64989 Monterrey, Nuevo León, Mexico. For privacy questions or requests, contact hello@hueswithinapp.com.