This policy covers the Ardenlyx app (the Vale and Haven experiences). For the website waitlist, see our website privacy policy. This is a pre-launch draft pending final legal review.
Ardenlyx Health Group Ltd ("we", "us", "our") is committed to protecting your personal data. This policy explains what the Ardenlyx app collects, why, where it is stored, and your rights under UK GDPR and the Data Protection Act 2018.
Ardenlyx is a wellbeing app. It provides general wellbeing and lifestyle insights from data your wearable and phone collect. It is not a medical device and does not diagnose, treat, monitor, predict, or prevent any disease or medical condition. Our scores and insights are not a substitute for professional medical advice.
Ardenlyx Health Group Ltd is registered in England & Wales (Companies House number 17227086), registered office Apartment 299 Orion Building, 90 Navigation Street, Birmingham B5 4AE. We are the data controller for the data described here and are registered with the UK Information Commissioner's Office (ICO) under registration number ZC171195. For privacy matters, contact [email protected].
Account & profile: your name, email, age, sex, height, weight and app settings — used to create your account and personalise your scores.
Health & wellbeing data (via Apple HealthKit, with your permission): depending on what you allow and what your device records, this may include heart rate, resting heart rate, heart-rate variability, respiratory rate, blood oxygen (SpO₂), sleep analysis and stages, steps, active energy, exercise minutes, distance, flights climbed, workouts, VO₂max, walking heart rate, wrist temperature, mindfulness minutes, body measurements, menstrual-cycle data, falls recorded by your device, and — only if you choose to import them — lab values such as blood glucose or blood pressure. This is special-category (health) data and receives heightened protection.
Location data (only if you turn it on): your phone's location, used for the Family safe-zone feature and to show where a recorded fall happened. Live location sharing is off by default.
Family-sharing data: the links you create between accounts, your sharing choices, and "Thinking of You" messages.
Technical & usage data: device type, app version and diagnostics needed to run and secure the service.
We do not make automated decisions producing legal or similarly significant effects about you.
Some Premium features — AI coaching and the food and prescription photo scans — send limited information to a trusted AI provider (Google Gemini) to generate a result. This is optional and separate: you switch it on with explicit consent and can switch it off any time in Privacy & data. What is shared: your wellbeing numbers and trends for coaching, and the photo you submit for a food or prescription scan — never your name, email, or account details. The data is processed only to give you a result and is not used to train the AI model. AI output is wellbeing guidance, not medical advice. Safety features (SOS, fall alerts, check-ins, location) never use AI and are unaffected by this choice. Legal basis: your explicit consent (Article 9(2)(a)).
Your data is hosted in the European Union (Ireland) on our infrastructure provider Supabase (acting as our processor). We may access it from the United Kingdom, which the EU recognises as providing adequate protection. Apple processes HealthKit data on your device under its own privacy terms. We do not transfer your health data outside the UK/EU except under a lawful transfer mechanism. Our processors are: Supabase (hosting and database, EU — Ireland); Expo (delivering push notifications, USA); RevenueCat (managing App Store and Play subscriptions, USA); Google (Gemini, for optional AI features only, USA); Resend (account emails, USA); Stripe (Haven payments and delivery). Where a processor is outside the UK/EU, the transfer is covered by a UK International Data Transfer Agreement or equivalent safeguard. Your health data is stored in the European Union.
Pro and Premium are purchased through Apple (App Store) or Google (Play). Haven — which includes the watch and its mobile connection — is arranged directly with us, and payment is handled by our payment provider, Stripe. In every case we never see or store your card details. We receive a record of what you subscribed to and when, and for Haven the delivery address needed to send you the watch.
If a Haven payment fails, the watch keeps working for 14 days while it is resolved — we cover the mobile connection during that period, and we tell you and your family well before anything changes.
We keep your data while your account is active. Day-level location is kept as last-known only (not a continuous trail). If you delete your account, we delete your personal data within 30 days, except limited records we must retain by law. You can ask us to delete specific data at any time.
Under UK/EU GDPR you have the right to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent at any time. Account deletion is built into the app; for anything else, email [email protected]. You may also complain to the UK Information Commissioner's Office (ico.org.uk) or, in Ireland, the Data Protection Commission (dataprotection.ie).
We protect your data with encryption in transit and at rest, strict per-user access controls (you can only access your own data, and a family member only what you've explicitly shared), and access logging.
Ardenlyx is intended for adults (18+). It is not directed at children and we do not knowingly collect data from anyone under 18.
We'll update this policy as the product evolves and will tell you about material changes in the app. The date above reflects the current version.
Questions or requests: [email protected], Ardenlyx Health Group Ltd, Apartment 299 Orion Building, 90 Navigation Street, Birmingham B5 4AE.