Traverse

Traverse — Privacy Policy

Effective: 30 June 2026 Last updated: 18 June 2026 Version: 2.1

Published by: Adfinium (trading name of George Hales, sole trader, United Kingdom) Postal / service address: 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY Data-protection contact: contact@adfinium.co.uk ICO registration: application submitted; registration in progress (reference published here on completion).

This policy explains what Traverse does with your data, what it does not do, and the rights you have. It is written to be read by a human, and to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and equivalent law in the other markets Traverse launches in.

Traverse is built on a single principle: your raw health data never leaves your device in identifiable form. Everything below follows from that principle, and the app's architecture is designed to enforce it.

The short version.

  1. Raw HealthKit data stays on your device. Heart rate, blood pressure, sleep, weight and the rest are never transmitted to us or to any third party as raw, identifiable readings.
  2. We do not sell, rent, share or monetise your health data. There is no mechanism in the app to do so.
  3. We use no third-party analytics or advertising SDKs. No Mixpanel, Amplitude, Segment, Firebase Analytics, Google Ads or Facebook SDK. None.
  4. Everything we do transmit is enumerated below, together with the lawful basis for it, where it goes, and how long it is kept.

1. Who we are (data controller)

Traverse is published under the trading name Adfinium by George Hales, a sole trader based in the United Kingdom. George Hales, trading as Adfinium, is the data controller for the purposes of UK GDPR, EU GDPR and equivalent regulations.

Because we process UK residents' personal data, we have applied to register with the UK Information Commissioner's Office (ICO) and to pay the data protection fee; the registration is in progress and its reference will be published here on completion. Our service address is 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY.

For data-protection matters contact contact@adfinium.co.uk; for general support contact support@adfinium.co.uk.

2. The data Traverse touches, and our lawful basis for each

For every processing activity we identify: what the data is, where it is stored, whether it is transmitted, our lawful basis under UK GDPR Article 6, and — for health data — the special-category condition under Article 9.

Why lawful basis matters. Health data is "special-category" data under Article 9. We may only process it where both an Article 6 basis and an Article 9 condition apply. The table at the end of this section summarises the full mapping; the detail follows.

2.1 Health data read from Apple HealthKit

2.2 Health data you enter manually

2.3 Your declared profile

2.4 Account credentials

2.5 Subscription state

2.6 Report generation and delivery (Claude API + delivery buffer)

2.7 Closed-taxonomy app analytics

2.8 On-device diagnostics (MetricKit)

Lawful-basis summary

Activity Art 6 basis Art 9 condition (health data) Opt-out
HealthKit data (2.1) 6(1)(a) consent 9(2)(a) explicit consent Revoke in iOS Health
Manual entries (2.2) 6(1)(a) consent 9(2)(a) explicit consent Delete entries
Declared profile / threshold query (2.3) 6(1)(b) contract 9(2)(a) explicit consent Change declaration
Account (2.4) 6(1)(b) contract Delete account
Subscription (2.5) 6(1)(b) contract; 6(1)(c) legal obligation — (statutory retention)
Report generation and delivery (2.6) 6(1)(b) contract 9(2)(a) explicit consent Don't subscribe / cancel
App analytics (2.7) 6(1)(f) legitimate interests — (no health data) Settings → Privacy → Analytics
Diagnostics (2.8) 6(1)(f) legitimate interests — (no health data)

3. What Traverse does not do

4. Sub-processors

We use the following sub-processors. Each performs a defined function under a written data-processing agreement (Article 28 UK GDPR) and the safeguards in §8.

Sub-processor Function Data category Location
Apple Inc. App Store distribution, In-App Purchase, Sign in with Apple, HealthKit framework, device backup Subscription records, account identifier United States / global
Supabase Inc. Authentication, threshold-library hosting, app-analytics storage, Founders records, transient report delivery buffer Account identifier, hashed condition identifiers, closed-taxonomy analytics, transient generated reports (derived figures + narrative, account-linked, deleted on delivery) EU or US region (per account); the report delivery buffer is hosted in the EU/UK region
Anthropic PBC Claude API narrative generation Pseudonymised narrative payload (§2.6) — no raw readings, no direct identifiers United States
RevenueCat Inc. Subscription-state verification, purchase-event processing Subscription identifier, purchase events United States

The table above is our current sub-processor list. We will publish any change here and give notice of new sub-processors before they begin processing, with an opportunity to object (see §10).

5. Your rights

Under UK GDPR, EU GDPR and equivalent law you have the rights below. Most are exercisable directly in-app; otherwise email contact@adfinium.co.uk with "Data Protection Request" in the subject. We acknowledge within 24 hours and respond within one month (the statutory period), extendable by two further months for complex requests, in which case we will tell you within the first month.

6. International data transfers

Some sub-processors are US-based (Apple, Anthropic, RevenueCat). For UK and EU users:

7. Security

If a personal-data breach affects your rights, we will notify the ICO within 72 hours (UK GDPR Article 33) and tell affected users without undue delay where the risk is high (Article 34).

8. Retention

See the per-activity retention above. In short: on-device data persists until you delete it; account data until account deletion; analytics on a 90-day rolling basis; tax-relevant subscription records for six years; the Claude payload is not retained by us, and a copy of a generated report held in our delivery buffer is kept only until your device confirms receipt (24 hours by default, 72 hours at most), then deleted — we keep no report history.

9. Children

Traverse is not for under-18s. We do not knowingly process data from anyone under 18, and the Terms require users to be 18 or older. If you believe a child has used Traverse, contact contact@adfinium.co.uk and we will delete the account and data.

10. Changes

For material changes (what we collect, who receives it, or how we use it) we will notify you in-app and by email if provided, and obtain any consent the change requires before it takes effect. For non-material changes we update the "Last updated" date. Previous versions remain available for a reasonable period.

11. Contact

Data protection / GDPR / CCPA: contact@adfinium.co.uk (acknowledged within 24 hours; resolved within one month). General support: support@adfinium.co.uk. Service address: 1 Exchange Court, Cottingham Road, Corby, Northamptonshire, NN17 1TY. Data controller: George Hales, trading as Adfinium, United Kingdom.