Privacy Policy

Last updated 24 August 2026

01Who We Are

LeWell is operated by LEWELL Co., Ltd., Bangkok, Thailand. We are the data controller for personal data we decide how and why to process across lewell.app and the LeWell web and mobile apps. Contact privacy@lewell.app with privacy questions or requests.

LeWell is intended only for people aged 18 or older.

02Information We Process

Waitlist: If you join the waitlist, we collect your email address and signup source to send requested launch updates. You can unsubscribe at any time.

Account and legal records: We collect email, username, a password hash where applicable, and identifiers supplied by Google or Apple for social sign-in. We record the legal-document versions and time accepted, plus your latest usage-data choice.

Guest onboarding draft: Before account creation, the device stores the goals, optional profile answers, units, learning schedule, reminder choice, and progress needed to resume onboarding. The draft expires after seven days. Credentials and tokens are excluded. We do not record or buffer guest analytics interactions before consent.

Profile and personalization: We process goals, schedule, reminder preferences, units, timezone, onboarding version, onboarding progress, and welcome-offer stage to resume and personalize the experience.

Health and wellness information: You may provide date of birth, biological sex, height, weight, mood and affect ratings, activity and intake logs, and health readings such as resting heart rate, heart rate variability, blood glucose, blood lipids, and sleep. Optional onboarding health questions can be skipped.

With separate device permission, LeWell can read steps, active energy, exercise minutes, resting heart rate, heart rate variability, and sleep duration from Apple Health or Health Connect where supported. Access is read-only. Revoking permission stops future reads but does not automatically delete readings already copied to LeWell. You can delete individual readings or your account.

Learning and social activity: We process lesson and practice progress, quiz answers and scores, XP, gold, gems, streaks, challenges, follows, connections, reactions, and related actions needed to provide the service.

Practice responses and AI feedback:Some reflections are sent to Anthropic's commercial Claude API for feedback you request. Commercial API inputs and outputs are not used to train Anthropic models by default and are normally retained for up to 30 days, with stated safety, abuse-prevention, and legal exceptions.

Optional product analytics: If you opt in to Share usage data, PostHog receives selected events about onboarding, feature use, engagement, time spent, purchases, trials, and retention. PostHog starts only after authentication and recorded consent. The profile uses an internal account ID and coarse product properties such as level and Premium status. We exclude email, username, raw health answers, health-reading values, and practice text. PostHog data is hosted in the EU.

Crash diagnostics: Sentry receives technical crash context such as device, operating-system and app versions, and the code path involved. Sentry is used for security and reliability independently of optional product analytics. Known sensitive fields are redacted.

Purchases and communications: Apple or Google processes mobile payments and RevenueCat validates receipts and entitlements. We receive transaction and lifecycle information, not card or bank details. We also process push tokens, preferences, delivery records, and transactional email data.

03Cookies and Device Storage

LeWell does not use advertising cookies or cross-app tracking. Device storage includes browser cookies, local and session storage, and native app preferences.

  • Web refresh cookie: Essential HTTP-only authentication, up to 365 days.
  • App session storage: Essential sign-in state until sign-out, deletion, clearing, or uninstall.
  • Guest draft: Resumable onboarding for up to seven days.
  • Analytics preference and identifier: Used only after opt-in and reset on opt-out, sign-out, or deletion.
  • Timers, drafts, and preferences: Resume requested features and remember interface choices.

Blocking essential storage may prevent sign-in or resumable features from working.

04Purposes and Legal Bases

We process information to provide and secure accounts, learning, social, health, purchase, communication, support, fraud-prevention, and diagnostic functions. Depending on the activity and your location, we rely on contract performance, consent, legal obligations, or legitimate interests balanced against your rights. You can withdraw consent at any time without affecting earlier lawful processing.

05Sharing and Service Providers

We do not sell personal data. We use these providers for the stated purposes:

  • Anthropic: Requested AI feedback.
  • PostHog: Optional EU-hosted product analytics.
  • Sentry: Crash and diagnostic reporting.
  • Render: Application and database hosting.
  • Cloudflare: DNS, website hosting, and email routing.
  • Resend: Transactional email.
  • Google: Sign-in, Android push, Health Connect, and Google Play payments.
  • Apple: Sign-in, iOS push, Apple Health, and App Store payments.
  • RevenueCat: Receipt, purchase, subscription, and entitlement management.

Providers may process information outside Thailand, including in the EU, US, or UK, under contractual protections and applicable transfer safeguards. We may disclose information where legally required, to protect rights and safety, or in a corporate transaction with appropriate safeguards.

06Security

We use HTTPS, salted password hashing, short-lived access tokens, restricted database access, authenticated purchase webhooks, field redaction, and other reasonable safeguards. Web refresh tokens use an HTTP-only cookie. Native refresh tokens use app-controlled local storage and native preferences. No system is completely secure.

07Retention and Deletion

  • Guest onboarding drafts: up to seven days.
  • Active-account profile, health, learning, and social data: while the account is active.
  • Optional PostHog analytics: up to 24 months under the project setting.
  • Sentry diagnostics: up to 90 days under the project setting.
  • Routine application and security logs: normally up to 30 days.
  • Anthropic commercial API data: normally up to 30 days, subject to stated exceptions.
  • Required transaction, consent, fraud, tax, and legal records: for the applicable obligation, potentially up to seven years.
  • Backups: until overwritten through the restricted hosting backup cycle.

Delete your account in Settings or use the account-deletion page. LeWell requests deletion of account-linked PostHog and RevenueCat customer data before local account deletion where applicable. Provider processing may finish asynchronously. Deletion does not cancel an Apple or Google subscription.

08Your Rights

Depending on where you live, including under Thailand's PDPA and the EU or UK GDPR, you may have rights to access, correct, delete, restrict, object, obtain a portable copy, withdraw consent, and complain to a data-protection authority. Use available app controls or contact privacy@lewell.app. We may need to verify your identity.

09Changes and Contact

We will update the date and provide appropriate notice for material changes. Contactprivacy@lewell.app. Data Controller: LEWELL Co., Ltd., Bangkok, Thailand.