Privacy policy

The information stored, how it is used, and your choices.

Effective date: 07.10.2026

Introduction and data controller

This policy describes information processing for the Healthy+ website and app, a consumer personal health journal. The operator is Eden Weiss / System for Success (סיסטם להצלחה), the controller of personal information processed on the operator’s behalf for the service. For privacy inquiries and rights requests: info@edenweiss.co.il. Read this policy with the terms of use.

The policy addresses Israel’s Privacy Protection Law, 5741–1981, including Amendment 13, and applicable regulations. Where the EU General Data Protection Regulation (GDPR) applies to particular processing, the protections and rights below also apply. This is not a claim of certification or regulatory approval.

There is no user account, password login, community or syncing of your health journal to our server. We have no interface for viewing your local journal. However, some actions send information to providers outside your device, as explained below.

Information stored on your device

Depending on the features you use, the app stores a name for greetings, age, sex, height, weight, waist circumference, goals and preferences; food and water records; dishes and recipes; menus and shopping lists; workouts, exercises and sets; sleep and steps; allergies and dietary restrictions. You can also store progress photos and notes, and, in the cycle feature, dates, bleeding, symptoms and an estimate of your next period.

This information may reveal your health, habits and intimate information. It is stored in the app’s database and files. Turning off a feature hides it and keeps its records. Cycle predictions are calculated on your device and are not used to personalize nutrition or advertising.

Providing information is your choice and is not required by law for ordinary use. You can skip some profile details and enter records manually; missing information or permissions may limit features that depend on them. Do not enter other people’s personal information without appropriate permission.

Health, allergy, cycle and physical-condition information may be “information of special sensitivity” under Israeli privacy law and special-category data under the GDPR. Its sensitivity requires data minimization, purpose limits and appropriate permissions; providing it does not make it public.

Purposes and legal bases

Information is used to display the journal, perform calculations and selected features, fulfill recognition requests, manage subscription eligibility, answer inquiries, secure the service and meet legal obligations. There is no blanket permission for unrelated additional uses.

Where the GDPR applies, processing necessary for your requested service relies on performance of a contract (Article 6(1)(b)); legally required processing on a legal obligation (Article 6(1)(c)); and proportionate technical security and abuse prevention on legitimate interests balanced against your rights (Article 6(1)(f)). Optional consent-based processing relies on Article 6(1)(a); consent-based health-data processing additionally requires explicit consent under Article 9(2)(a). Legitimate interests alone do not authorize health-data processing.

Providing information for ordinary use is voluntary. Refusing permission or consent for an optional feature limits that feature, not manual logging. You can withdraw consent through feature settings, revoke system permissions or contact us. Withdrawal does not affect the lawfulness of earlier processing. We do not make solely automated decisions producing legal or similarly significant effects on you; AI estimates are available for review and correction.

Smart food and image recognition

Recognition is optional. Before transfer, separate explicit consent is required to process the content, which may include sensitive health information, through the operator’s Cloudflare Worker and Google Gemini. Camera permission or acceptance of terms does not replace this consent. You can use manual logging and withdraw consent for future processing.

When you submit text for recognition, the entire text is sent to the operator’s Cloudflare Worker, even if part of it can be recognized on your device. When you photograph a plate or label, a reduced-size image is sent for processing. The server forwards the content to Google Gemini to obtain an estimate of the food and its nutritional values. This process does not automatically send your entire journal, profile or progress photo collection.

The text and image themselves may contain identifying or sensitive information. Photograph only the food or label, without faces, documents or unnecessary details. Cloudflare and communications providers may also process technical data, such as your IP address and the time of the request. Recognition results are shown for review before they are saved in your journal.

The processing server does not store request content in its activity log. This is not a promise that service providers retain nothing. Gemini’s terms distinguish between paid and unpaid services, and a paid service does not guarantee zero retention for abuse prevention. Google’s policy describes retention for 55 days under this mechanism, subject to the relevant terms and exceptions. Gemini terms, abuse monitoring policy.

Personal, health or confidential information must not be sent through a Gemini service tier that does not permit it. Unpaid-service terms prohibit sensitive or personal submissions and allow product-improvement uses; user consent does not override these terms. The operator does not use your journal to train models. The provider tier and data-use terms must match the disclosure and consent before transfer.

Other services and permissions

You can change permissions in your operating-system settings. Revoking a permission stops future access covered by that permission; it does not delete information already stored or transferred.

Apple Health and Health Connect

Apple Health integration is optional; Health Connect for Android is planned, subject to availability. A connection permits reading or writing only authorized data types for your selected health features, such as steps, sleep, activity and measurements. Permission for one data type is not permission for all information.

Health-service data is not sold or used for advertising, advertising tracking or marketing profiles. It is not automatically sent to Gemini through food recognition. You can disconnect and revoke permissions in Apple Health, Health Connect or operating-system settings. Revoking access does not delete the original held by Apple or Google or a record already saved in your journal; manage each copy separately.

Support inquiries and purchase information

When you email us, your sender address, message and attachments you choose to include are processed through the email provider to respond and handle your request. You need not include a complete journal, identity document or unnecessary medical details. If more information is needed to exercise a right, we will request only what is necessary for proportionate verification.

Apple or Google handles subscriptions, including a 3-day trial for eligible users, depending on the store. Transaction information, purchase identifiers and entitlement status may be provided to verify a subscription, restore a purchase or resolve an issue. We do not receive full card details, and a purchase does not give the store access to your local health journal through us. Each store has its own privacy policy.

Providers, disclosures and international transfers

Information is disclosed to providers named in this policy according to your selected feature and only as needed for its purpose: Cloudflare for traffic and request processing, Google Gemini for requested recognition, stores for subscriptions, health services and other providers described above. This does not authorize sending the entire journal to every provider. Providers processing on our behalf are subject to appropriate arrangements; independent controllers are also responsible under their own policies.

Information may also be disclosed when required by a legal obligation or valid order, or where proportionately necessary to protect rights, prevent fraud or address a security incident, always subject to law. An allegation of a terms violation does not provide blanket permission to disclose sensitive information.

Providers may process information outside Israel or the European Economic Area. Transfers must comply with applicable Israeli overseas-transfer regulations; where the GDPR applies, an appropriate Chapter V mechanism is required, such as an adequacy decision or standard contractual clauses with supplementary safeguards as needed. AI consent does not waive these protections. Contact us for details of the relevant arrangements.

Backups, export and security

Internal weekly backup is enabled by default and stored in the app’s folder. It includes records, settings and cycle data. Up to four weekly backups are retained; safety copies made before restoring or resetting settings are stored separately and currently have no automatic age-based deletion.

You can export a comprehensive JSON file and choose whether to include progress photos. A CSV file is a partial report and does not include every type of information. You can export a password-encrypted backup. An unencrypted export can be read by anyone who receives it. Saving it in another app, sending it or uploading it to the cloud creates a copy outside the app’s control.

The app’s data and images may also be included in operating-system backups, depending on your device settings. Cloud backup protection depends on the service and its settings; this is not a guarantee of end-to-end encryption. You can enable an app lock and hide information in the recent-apps preview. Operating-system protection does not eliminate the risk of an unlocked device or a copied file.

The operator applies reasonable technical and organizational security measures proportionate to the information under its control, applicable law and risks. Absolute protection cannot be guaranteed; this does not waive security duties or required notifications to authorities and affected people. Lock your device and protect exported files and backup passwords.

Future encrypted syncing

Optional encrypted syncing between devices is planned and is not currently active. Ordinary use of the journal or acceptance of this policy alone will not activate it. Before activation, we will explain what data is transferred, to whom, where and for how long it is stored, who can decrypt it and how copies are deleted, and request separate consent.

“Encrypted” does not promise end-to-end encryption for the future service or that the operator can never access keys. Those details will be determined and disclosed before activation. This future syncing is separate from encrypted backup exports and operating-system backups described above.

Retention, deletion and rights

Local records are kept until you delete them; there is no automatic deletion based on a record’s age. You can correct records in the relevant screens. “Start over” resets settings and the questionnaire while keeping your data. “Delete all data” deletes user records and the photos and backups managed by the app, after two confirmations.

Local deletion does not delete exported copies, earlier device backups or information retained by providers under their terms. There is no guarantee of forensic erasure from all device storage.

Support inquiries, entitlement information and technical records under our control are kept only as needed for responses, security, disputes or legal obligations, then deleted or anonymized. Provider retention periods may differ as described above; legal holds or statutory exceptions are limited to the necessary information and duration.

Access, correction, deletion, export and requests

You can view your journal, correct records, export and delete through the app. For personal information controlled by the operator, contact info@edenweiss.co.il to exercise access and correction rights under Israeli privacy law and request deletion where applicable. In-app deletion and export do not depend on GDPR applicability.

Where the GDPR applies, subject to its conditions and exceptions, you also have rights to erasure, restriction, objection and portability in a structured machine-readable format, and to withdraw consent. We respond without undue delay, normally within one month; any permitted extension will be explained within the first month. Israeli-law requests are handled within the periods required by that law. If we cannot fulfill a request, we will explain why and the options available.

We have no routine access to your local journal and cannot locate it by name alone. We request as little information as necessary to investigate and verify a request; do not send your whole journal to start an inquiry. For a copy held by an independent provider or your chosen recipient, you may also need to contact them. You may complain to the Israeli Privacy Protection Authority or, where the GDPR applies, the competent supervisory authority in your country of residence, work or the alleged infringement.

Children and teenagers

The service is for people aged 16 and over. We do not knowingly collect information from children under 16. Users aged 16–17 are subject to applicable consent requirements described in the terms. AI recognition using Gemini is intended for adults aged 18 and over, subject to provider terms.

If you learn that information about a child under 16 has been sent to us, contact us so we can investigate, stop processing and delete information under our control as permitted by law. Information stored only on a device must be handled through the device’s deletion options; you do not need to send it to us to report a concern.

No data sales, advertising tracking or website cookies

We do not sell personal or health information. The app has no ads or third-party advertising trackers, and health and cycle data are not used for advertising targeting. Limited disclosure for a requested feature, as explained in this policy, does not authorize marketing use.

The website uses no cookies, analytics tools or advertising tracking. Display and accessibility preferences use local browser storage, which is not a cookie. The hosting provider processes ordinary connection data, such as IP addresses and request times, to deliver and secure the website. External links are subject to the destination’s policy.

Policy changes and contact

Changes will be published with an effective date. Material changes to purposes, providers or processing will receive appropriate advance notice; where fresh consent is required, it will be requested before the new processing. Continuing to use the website does not consent to health-data transfers or future syncing.

Contact: Eden Weiss / System for Success (סיסטם להצלחה), info@edenweiss.co.il.

info@edenweiss.co.il