Skip to content

Personal health companion · Public documents

Linnea
PrivacyHealth dataAI noticesTermsSupport

Version 1.2 · Effective 19 July 2026

Privacy policy

Linnea is a personal wellness companion. This policy explains what information the app handles, why it is needed, where it goes, and how to export or delete it. “Linnea,” “we,” and “us” refer to MINGJUN SUN, the individual developer identified as the seller on Linnea’s App Store product page.

Information we handle

Account information. Email address, or the identifier provided by Apple or Google sign-in, authentication tokens, internal user ID, device push token, app version, locale, and time zone. We do not receive the password for a third-party sign-in account.

Profile and wellness information. Date of birth, sex, height, weight entries, goals, medication and supplement names and schedules entered by the user, reminder preferences, and onboarding choices.

Logs and user content. Food, water, medication, supplement, exercise, sleep, and wellbeing entries; notes; photos submitted for food recognition; and audio submitted for voice logging. Voice audio is sent for transcription and is not persisted by Linnea after that request. The resulting transcript may be stored with the log.

Apple Health summaries. If permission is granted, Linnea reads Apple Health on the device and produces daily aggregates such as sleep totals, steps, workout minutes, active energy, mindful minutes, and weight trend. Raw Apple Health samples never leave the device. The service rejects payloads shaped like raw samples.

Derived information. Today scores and sub-scores, history, trends, generated meal plans, weekly digests, insights, and other AI-assisted results. AI results display a versioned notice that they are general wellness information, not medical advice.

Diagnostics and product analytics. When the production services are enabled, Linnea may send crash, performance, screen-name, and coarse usage events to Sentry and PostHog. A central scrubber removes health fields and contact details before transmission. Analytics and crash reporting can be turned off in You → Analytics.

Purposes

  • Authenticate the account and synchronize the user’s own records.
  • Calculate scores, trends, reminders, exports, and requested AI features.
  • Verify Apple subscription entitlements without receiving payment-card data.
  • Protect the service, enforce rate limits, diagnose failures, and prevent abuse.
  • Answer support, privacy, export, correction, and deletion requests.

AI processing

Requested AI features send only the information needed for that request to OpenAI or Anthropic. Depending on the feature, that can include profile metrics, relevant daily aggregates and logs, a question, a photo, or audio. Linnea does not attach the account email or stored contact name. Personal information placed directly in a note, question, photo, or recording will be part of that request.

Our commercial API arrangements do not permit these providers to train their general models on Linnea API data by default. Provider security and abuse-monitoring logs may be retained for up to 30 days under their standard API terms, unless a shorter approved retention setting applies.

We ask before we send. The app explains in plain language, inside the app, what an AI feature will send and which provider receives it, and asks for your permission before the first such request. Nothing is sent to an AI provider until you agree. You can withdraw that permission at any time in Settings; the AI features then stop sending, and the rest of Linnea — logging, your daily score, trends, reminders, plan editing and export — keeps working.

Equal protection. We share personal information with an AI provider only under written commercial terms that bind the provider to confidentiality, to appropriate technical and organisational security measures, to processing the data solely to return the result of your request, and to protections materially equivalent to those described in this policy. These providers act as processors on our instructions; they are not permitted to use your information for their own purposes.

Processors and disclosures

Supabase hosts authentication, databases, storage, and server functions in the United States. OpenAI and Anthropic process requested AI features. Apple processes subscriptions and provides Apple Health APIs; Google or Apple may provide sign-in when selected. Sentry and PostHog process scrubbed diagnostics when enabled. These providers act for the stated service purposes. We may also disclose information when legally required, to protect users or the service, or as part of a business transfer with notice and applicable safeguards.

Linnea does not sell personal or consumer health data, use it for targeted advertising, or track activity across other companies’ apps or websites.

Storage, security, and international transfers

Account data is stored in the United States. This means information from Canada and other launch regions can be processed under United States law. Database rows are protected by default-deny row-level access controls, and the local device cache is encrypted. No Internet service can promise absolute security; Linnea limits access and data fields instead of making that promise.

Retention

Account records are kept while the account exists. Generated AI artifacts that are no longer referenced are purged after 90 days. Data-export files are deleted after seven days; each download link expires after one hour. Operational caches and rate-limit records expire automatically. When an account deletion is requested, there is a 24-hour cancellation window; after it ends, the account identity and associated application rows are deleted. Residual encrypted backups are isolated from normal use and age out under the hosting provider’s backup cycle.

Choices and rights

The app provides You → Export my data and You → Delete account. Apple Health permissions can be changed in iOS Settings, and analytics can be disabled in the app. Depending on where the user lives, additional rights may include access, correction, portability, objection, withdrawal of consent, restriction, and complaint to a privacy regulator. We will verify a request before acting on it and will not discriminate for exercising a privacy right.

Children

Linnea is not directed to children under 13 and is not available where a higher minimum age for independent digital consent applies unless a parent or guardian provides legally valid consent. Contact support if a child’s account should be removed.

Changes and contact

Material changes will be dated and presented in the app before they take effect where notice is required. The controller and designated Privacy Officer is MINGJUN SUN, 106 Mattingly Way, Ontario K4M 0C6, Canada. Privacy questions, complaints, and rights requests can be sent to mingjun.sun1991@gmail.com. The in-app support route reaches the same monitored address. Washington consumer health requests follow the separate Consumer Health Data Policy.

© 2026 Linnea · Privacy · Consumer health data · AI notices · Terms · Support