Traverse — Privacy Policy
Effective: 30 June 2026 Last updated: 18 June 2026 Version: 2.1
Published by: Adfinium (trading name of George Hales, sole trader, United Kingdom) Postal / service address: 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY Data-protection contact: contact@adfinium.co.uk ICO registration: application submitted; registration in progress (reference published here on completion).
This policy explains what Traverse does with your data, what it does not do, and the rights you have. It is written to be read by a human, and to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and equivalent law in the other markets Traverse launches in.
Traverse is built on a single principle: your raw health data never leaves your device in identifiable form. Everything below follows from that principle, and the app's architecture is designed to enforce it.
The short version.
- Raw HealthKit data stays on your device. Heart rate, blood pressure, sleep, weight and the rest are never transmitted to us or to any third party as raw, identifiable readings.
- We do not sell, rent, share or monetise your health data. There is no mechanism in the app to do so.
- We use no third-party analytics or advertising SDKs. No Mixpanel, Amplitude, Segment, Firebase Analytics, Google Ads or Facebook SDK. None.
- Everything we do transmit is enumerated below, together with the lawful basis for it, where it goes, and how long it is kept.
1. Who we are (data controller)
Traverse is published under the trading name Adfinium by George Hales, a sole trader based in the United Kingdom. George Hales, trading as Adfinium, is the data controller for the purposes of UK GDPR, EU GDPR and equivalent regulations.
Because we process UK residents' personal data, we have applied to register with the UK Information Commissioner's Office (ICO) and to pay the data protection fee; the registration is in progress and its reference will be published here on completion. Our service address is 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY.
For data-protection matters contact contact@adfinium.co.uk; for general support contact support@adfinium.co.uk.
2. The data Traverse touches, and our lawful basis for each
For every processing activity we identify: what the data is, where it is stored, whether it is transmitted, our lawful basis under UK GDPR Article 6, and — for health data — the special-category condition under Article 9.
Why lawful basis matters. Health data is "special-category" data under Article 9. We may only process it where both an Article 6 basis and an Article 9 condition apply. The table at the end of this section summarises the full mapping; the detail follows.
2.1 Health data read from Apple HealthKit
- What: Heart rate, heart-rate variability, blood-oxygen saturation, blood pressure, body weight, steps, sleep, respiratory rate, VO₂ max, exercise minutes, workouts, and any other metric you grant Traverse permission to read.
- Where stored: On your device only, in a local SwiftData store that mirrors Apple HealthKit.
- Transmitted? No. Raw readings are never sent to us or any third party in identifiable form.
- Lawful basis: Article 6(1)(a) consent, and Article 9(2)(a) explicit consent (given through the iOS HealthKit permission sheet and in-app onboarding).
- Retention: Until you delete the app or revoke HealthKit permission.
2.2 Health data you enter manually
- What: Values you type in (home blood-pressure readings, weight, fasting glucose/insulin, CPAP hours, lab values such as LVEF, NT-proBNP, FEV1, ACT/ACQ, FSH, oestradiol, thyroid panel, iron studies, INR, and structured event logs).
- Where stored: On your device, in the same local store; optionally written back to Apple HealthKit at your request.
- Transmitted? No raw manual entries are transmitted.
- Lawful basis: Article 6(1)(a) consent and Article 9(2)(a) explicit consent.
- Retention: Until you delete the entry, the app, or revoke permission.
2.3 Your declared profile
- What: The conditions you tell us you live with, the medication classes you declare, and the demographic context (age, biological sex, height) used to calibrate interpretation.
- Where stored: On your device.
- Transmitted? To retrieve the correct clinical reference ranges, Traverse sends a pseudonymised query to our threshold library (hosted at Supabase) containing hashed condition identifiers and the condition category only. This query carries no direct identifiers — no name, email, account ID or device ID. It remains personal data in pseudonymised form (see the note below).
- Lawful basis: Article 6(1)(b) performance of the contract (delivering the calibrated interpretation you asked for) and Article 9(2)(a) explicit consent.
- Retention: Until you change your declaration or delete the app.
2.4 Account credentials
- What: A stable, app-specific identifier issued by Sign in with Apple. We do not receive your Apple ID email unless you choose to share it (Apple's private-relay is on by default). We do not collect your name.
- Where stored: Apple's infrastructure and Supabase Auth (encrypted at rest; EU or US region per your account location).
- Transmitted? The identifier is sent to Supabase for authentication. No health data is attached to this record.
- Lawful basis: Article 6(1)(b) performance of the contract (you cannot have an account without it).
- Retention: Until you delete your account (Settings → Account → Delete Account, completable in under three taps).
2.5 Subscription state
- What: Whether you hold an active Intelligence subscription, the plan tier, and renewal status. Purchase events flow through RevenueCat.
- Where stored: RevenueCat, our Supabase backend (a
founders_purchasesrecord for Founders participants), and Apple's App Store records. - Transmitted? Yes — subscription state is verified server-side to gate Intelligence features.
- Lawful basis: Article 6(1)(b) performance of the contract; and Article 6(1)(c) legal obligation for the tax/accounting records we must keep.
- Retention: Per RevenueCat and Apple policies; tax-relevant records retained for six years (UK statutory).
2.6 Report generation and delivery (Claude API + delivery buffer)
- What: When you hold an active Intelligence subscription and Traverse generates a daily report, an aggregated summary is sent to the Claude API (operated by Anthropic) to produce the natural-language narration. The payload contains computed deltas, locally-computed trend vectors, categorical "within / outside expected range" labels, your declared condition names, and your declared medication classes.
- The payload sent to Anthropic does not contain: raw HealthKit readings; timestamps on individual readings; your name, email, account identifier or device identifier; any free-text (Traverse has no free-text inputs); geographic location.
- Nature of this data: This is special-category data — it describes your declared conditions and your deltas, so it remains personal data relating to you, and is health data. We treat it accordingly. We do not describe it as anonymous.
- Generation (Anthropic): the summary is sent over HTTPS to Anthropic's API. Under Anthropic's Commercial Terms, API inputs and outputs are not used to train models. We do not operate a Zero-Data-Retention agreement; Anthropic may retain the payload for a limited period to operate the service and enforce its Usage Policy, after which it is deleted. The payload sent to Anthropic carries no account identifier.
- Delivery (transient server-side hold): so the report you paid for reliably reaches your device — even if your connection drops or your device is offline when the report is ready — a copy of the generated report (the same derived figures and narrative above; never raw readings) may be held briefly on our server (Supabase) as a delivery buffer. This held copy is linked to your account so that only you can retrieve it and so it can be deleted once delivered; it is therefore personal, account-linked health data, which we protect accordingly: encrypted at rest, isolated by row-level security so only you can read it, hosted in the EU/UK region, and deleted the moment your device confirms receipt (and in any case within 24 hours by default, 72 hours at most). It is a delivery buffer, not an archive — we keep no history of your past reports.
- Lawful basis: Article 6(1)(b) performance of the contract (you subscribed for this narration and its delivery) and Article 9(2)(a) explicit consent (obtained at subscription, before payment).
2.7 Closed-taxonomy app analytics
- What: A small, closed set of feature-usage events captured by our own backend (paywall views, purchase events, error counts, feature-flag exposure). Every event type is enumerated in our code and reviewed before deployment. No event carries health data.
- Where stored: A dedicated
app_analyticstable in Supabase. No third-party analytics service receives this data. - Transmitted? Yes — to Supabase over HTTPS.
- Lawful basis: Article 6(1)(f) legitimate interests (understanding feature usage and stability to run the service), balanced against your interests; you may opt out at Settings → Privacy → Analytics.
- Retention: Rolling 90 days, then aggregated to counts and per-event records deleted.
2.8 On-device diagnostics (MetricKit)
- What: iOS-supplied data about crashes, hangs, memory pressure and performance.
- Where stored: On your device; aggregated counts (no health data, no direct identifiers) reported to us for stability monitoring.
- Lawful basis: Article 6(1)(f) legitimate interests (keeping the app stable).
- Retention: Standard iOS retention plus 90-day rolling aggregation on our side.
Lawful-basis summary
| Activity | Art 6 basis | Art 9 condition (health data) | Opt-out |
|---|---|---|---|
| HealthKit data (2.1) | 6(1)(a) consent | 9(2)(a) explicit consent | Revoke in iOS Health |
| Manual entries (2.2) | 6(1)(a) consent | 9(2)(a) explicit consent | Delete entries |
| Declared profile / threshold query (2.3) | 6(1)(b) contract | 9(2)(a) explicit consent | Change declaration |
| Account (2.4) | 6(1)(b) contract | — | Delete account |
| Subscription (2.5) | 6(1)(b) contract; 6(1)(c) legal obligation | — | — (statutory retention) |
| Report generation and delivery (2.6) | 6(1)(b) contract | 9(2)(a) explicit consent | Don't subscribe / cancel |
| App analytics (2.7) | 6(1)(f) legitimate interests | — (no health data) | Settings → Privacy → Analytics |
| Diagnostics (2.8) | 6(1)(f) legitimate interests | — (no health data) | — |
3. What Traverse does not do
- No third-party analytics SDKs. No advertising SDKs, ever. No ads.
- No cross-app or cross-website tracking; our App Tracking Transparency declaration is and will remain "Does Not Track."
- No device or behavioural fingerprinting.
- No sale, rental, sharing or monetisation of your health data — architecturally, not merely as policy.
- No use of your health data to train AI models (the Claude payload is sent under terms that exclude training).
- No sharing with insurers, employers, marketing partners or data brokers, beyond the sub-processors in §4, each performing a defined operational function under data-processing terms.
4. Sub-processors
We use the following sub-processors. Each performs a defined function under a written data-processing agreement (Article 28 UK GDPR) and the safeguards in §8.
| Sub-processor | Function | Data category | Location |
|---|---|---|---|
| Apple Inc. | App Store distribution, In-App Purchase, Sign in with Apple, HealthKit framework, device backup | Subscription records, account identifier | United States / global |
| Supabase Inc. | Authentication, threshold-library hosting, app-analytics storage, Founders records, transient report delivery buffer | Account identifier, hashed condition identifiers, closed-taxonomy analytics, transient generated reports (derived figures + narrative, account-linked, deleted on delivery) | EU or US region (per account); the report delivery buffer is hosted in the EU/UK region |
| Anthropic PBC | Claude API narrative generation | Pseudonymised narrative payload (§2.6) — no raw readings, no direct identifiers | United States |
| RevenueCat Inc. | Subscription-state verification, purchase-event processing | Subscription identifier, purchase events | United States |
The table above is our current sub-processor list. We will publish any change here and give notice of new sub-processors before they begin processing, with an opportunity to object (see §10).
5. Your rights
Under UK GDPR, EU GDPR and equivalent law you have the rights below. Most are exercisable directly in-app; otherwise email contact@adfinium.co.uk with "Data Protection Request" in the subject. We acknowledge within 24 hours and respond within one month (the statutory period), extendable by two further months for complex requests, in which case we will tell you within the first month.
- Access — view all data we hold about you: Settings → Data → Export produces a complete machine-readable (JSON) extract.
- Erasure ("right to be forgotten") — Settings → Account → Delete Account removes your Supabase Auth record, your
founders_purchasesrecord (if any) and yourapp_analyticshistory; local deletion clears the on-device store. Apple and RevenueCat purchase records are retained by those services under their own policies and for our statutory tax-record obligations. - Portability — the export in §5 is structured and machine-readable.
- Rectification — correct declared conditions, medications or demographics at Settings → Profile.
- Restriction / objection — you can object to legitimate-interests processing; opt out of analytics at Settings → Privacy → Analytics. Health-data processing is the core function of the app; opting out of it means not using the app.
- Withdraw consent — where we rely on consent (HealthKit, manual entry), withdraw at any time via iOS Health permissions or by deleting your entries. Withdrawal does not affect processing already carried out.
- California residents (CCPA/CPRA), if applicable — rights to know, delete, correct, and to opt out of "sale"/"sharing." Traverse does not sell or share personal information within the meaning of CCPA/CPRA, and does not discriminate against you for exercising any right. (Note: we provide these rights as a matter of policy; applicability depends on statutory thresholds.)
- Complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your member-state authority. We ask that you contact us first so we can put things right.
6. International data transfers
Some sub-processors are US-based (Apple, Anthropic, RevenueCat). For UK and EU users:
- Transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (for UK personal data) and the EU SCCs (for EU personal data), and/or the EU–US / UK–US Data Privacy Framework where the recipient is certified.
- We hold a transfer risk assessment for each US transfer and apply supplementary measures (pseudonymisation, encryption in transit, data minimisation).
- Supabase offers EU-region hosting; EU residents' account data is stored in the EU region.
- We do not transfer personal data to any jurisdiction without an adequacy decision or equivalent safeguards.
7. Security
- On-device storage is protected by iOS data-at-rest encryption (enabled by default with a passcode).
- All network transmissions use HTTPS (TLS 1.2 or higher).
- Sign in with Apple tokens are short-lived and auto-refreshed.
- Claude API credentials are held in the iOS Keychain and provisioned through a Supabase Edge Function gated on subscription state; they are not embedded in the binary.
- Traverse does not write health data to iCloud or CloudKit. Your data is stored locally on the device; if you have iCloud Backup enabled, that local store is included in Apple's standard end-to-end-encrypted device backup, as with any app — we have no access to it.
If a personal-data breach affects your rights, we will notify the ICO within 72 hours (UK GDPR Article 33) and tell affected users without undue delay where the risk is high (Article 34).
8. Retention
See the per-activity retention above. In short: on-device data persists until you delete it; account data until account deletion; analytics on a 90-day rolling basis; tax-relevant subscription records for six years; the Claude payload is not retained by us, and a copy of a generated report held in our delivery buffer is kept only until your device confirms receipt (24 hours by default, 72 hours at most), then deleted — we keep no report history.
9. Children
Traverse is not for under-18s. We do not knowingly process data from anyone under 18, and the Terms require users to be 18 or older. If you believe a child has used Traverse, contact contact@adfinium.co.uk and we will delete the account and data.
10. Changes
For material changes (what we collect, who receives it, or how we use it) we will notify you in-app and by email if provided, and obtain any consent the change requires before it takes effect. For non-material changes we update the "Last updated" date. Previous versions remain available for a reasonable period.
11. Contact
Data protection / GDPR / CCPA: contact@adfinium.co.uk (acknowledged within 24 hours; resolved within one month). General support: support@adfinium.co.uk. Service address: 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY. Data controller: George Hales, trading as Adfinium, United Kingdom.