Blog
🔒

Health and Wellness App Privacy: What Apps Collect and How to Stay Protected

A wellness app accumulates a record that is more revealing than almost anything else on your phone: when you sleep, how you feel, what you eat, when your mood drops and what you wrote about it. Most people agree to that record in a two-second tap on a consent screen. This is a practical guide to what these apps collect, what GDPR actually entitles you to in Europe, the specific clauses worth finding in a privacy policy before you commit, and how to reduce your exposure without giving up the tools.

2026-08-22
8 min

Why wellness data is more sensitive than it looks

Individually, the data points look trivial — a mood value, a step count, a completed habit. In aggregate over months they are not. A mood log with timestamps reveals patterns about your mental health; a cycle tracker reveals pregnancy and its outcomes; a sleep log reveals shift work, insomnia and drinking patterns; location-tagged workouts reveal your home address, your gym and your routine. This is why regulators treat it as a special category rather than ordinary personal data. It is also unusually durable: an email address can be changed, but a five-year emotional record cannot be un-disclosed, and it can be re-identified from surprisingly little. Investigations by regulators and journalists over recent years have repeatedly found health and cycle-tracking apps sharing data with advertising and analytics networks in ways users did not expect and policies did not clearly disclose. The point is not that every app does this. It is that the category has a track record, so the burden of proof belongs on the app.

What GDPR actually gives you

If you are in the EU or EEA, health data falls under Article 9 as a special category, which means processing it generally requires your explicit, specific, freely given consent — not consent bundled into a general terms acceptance, and not consent you cannot withdraw as easily as you gave it. Beyond that you have concrete, enforceable rights: access, to obtain a copy of everything held about you; portability, to receive it in a machine-readable format; rectification; erasure, the so-called right to be forgotten; and the right to object to processing. Any provider offering a service in the EU must identify a data controller and, in most cases, a data protection officer, and must disclose transfers outside the EEA and the safeguard relied on. The practical test is simple: can you exercise these rights in the app in a few taps, or does it require emailing an address that does not reply? A provider that has built export and delete buttons has made a design decision about your data; one that has not has also made a decision.

Create your free account

No credit card. 13 languages. Privacy-first.

Start free

Reading a privacy policy in five minutes

You do not need to read the whole document. Search it for six things. First, "third part" — who receives your data and for what; a long list of advertising and analytics partners tells you most of what you need. Second, "train" or "improve our models" — whether your content is used for AI training, and whether there is an opt-out. Third, "retention" — how long data is kept after you stop using the service and after you delete your account. Fourth, "transfer" — whether data leaves the EEA and under what mechanism. Fifth, "sell" — noting that some policies deny selling while permitting "sharing for business purposes", which can be the same thing. Sixth, "aggregate" or "de-identified" — a common carve-out that exempts a large amount of processing from every other promise in the document. If the answers to those six are vague, that vagueness is the finding.

What Aura does with your data

Stated plainly so you can hold us to it. Your data is encrypted, is not sold, and is not shared with advertising networks. Conversations with the AI features, journal entries and mood logs are yours: there is a full export endpoint and a full deletion endpoint, both reachable from settings, and deletion removes the account and its associated records rather than flagging them as hidden. Sensitive imagery is handled with deliberately short lifetimes rather than indefinite storage — bill photos in AURA Home are discarded immediately after the data is extracted, and face photos in AURA Mirror carry a 24-hour lifetime, with only the stylised avatar retained. Where a feature needs location, it is opt-in and stored at reduced precision, rounded to roughly a kilometre for weather. None of that is a reason to skip reading the policy yourself; it is what you should expect to find when you do.

Reducing your exposure without giving up the app

Several habits materially lower risk regardless of provider. Grant permissions individually and only when a feature needs them, rather than accepting a bundle at install; location, contacts and photo-library access are the ones worth refusing by default and enabling only for a specific action. Keep identifying details out of free-text fields — journal entries and AI chats are the highest-value data you produce, and they do not need full names, employers or addresses to be useful to you. Turn off any data-sharing or personalisation toggle you do not actively want, since these frequently default to on. Export your data once so you know what is actually held rather than what you assume. And if you stop using an app, delete the account rather than the app: removing the icon from your phone changes nothing about what the server keeps.

Questions to ask before you commit to any wellness app

Five questions decide most of it. Is my content used to train AI models, and can I opt out without losing the feature? Can I export everything in a usable format, today, without contacting support? Can I permanently delete my account and data myself, and how long until backups are purged? Who is the data controller, where are they established, and is there a named contact? And what happens to my data if the company is acquired or shuts down — a clause that is easy to skip and matters enormously, since user databases are assets in an acquisition. An app that answers all five clearly in its own documentation has thought about this. One that answers none of them has also told you something, and it is worth listening to before you start typing the contents of your head into it.

Reviewed by the AURA Team

This article was checked by our editorial team for accuracy and for adherence to our quality policies.

FAQ

Is mood and journal data considered health data under GDPR?

Data concerning mental health falls under the Article 9 special categories, which requires explicit consent and stricter safeguards than ordinary personal data.

Are my conversations with Aura's AI features private?

Yes. They are encrypted, not sold, and not shared with advertising networks, and you can export or delete them at any time from settings.

Can I delete everything permanently?

Yes. Aura provides full export and full account deletion from settings, and deletion removes the records rather than hiding them.

Does Aura sell data to advertisers?

No. Data is not sold and is not shared with advertising networks.

What is the fastest way to check any app's policy?

Search the document for "third part", "train", "retention", "transfer", "sell" and "aggregate". Those six terms surface almost everything that matters.

Should I delete the app or the account?

The account. Removing the app from your phone does not affect anything the provider holds on its servers.

✨

Create your free account

No credit card. 13 languages. Privacy-first.

Start free