1. Introduction & Scope
This Privacy Policy ("Policy") describes how Mavik Labs LLC, a Delaware limited liability company doing business as Ohga ("Ohga," "we," "us," or "our"), collects, uses, discloses, stores, and protects personal information when you use the Ohga mobile application, the website at ohga.app, and any related products, features, and services that link to this Policy (collectively, the "Services").
Ohga is a wellness intelligence application that helps you track nutrition, fitness, mood, hydration, sleep, and related health metrics; receive AI-powered coaching; and optionally connect with friends and wellness partners. Because we process sensitive health-related information, we have designed this Policy to be comprehensive and transparent about every category of data we handle.
Incorporated Documents
This Policy incorporates by reference the following supplemental notices, which form part of our privacy commitments:
- Consumer Health Data Notice — see Section 14 below (for users in Washington State, Nevada, and other jurisdictions with consumer health data laws).
- Cookie Policy — see Section 12 below (for website visitors at ohga.app).
When This Policy Applies
This Policy applies when you:
- Download, install, or use the Ohga mobile application on iOS or Android;
- Visit or interact with ohga.app or any Ohga-hosted web pages;
- Create or manage an Ohga account;
- Connect third-party health, music, or wearable integrations through Ohga;
- Contact our support or privacy teams regarding the Services;
- Subscribe to Ohga Pro, Max, or other paid tiers through the App Store, Google Play, or related billing flows.
When This Policy Does Not Apply
This Policy does not apply to:
- Third-party websites, apps, or services that you access independently of Ohga (including Apple Health, Google Health Connect, Spotify, Apple Music, wearable providers, and authentication providers), even if linked from or integrated with Ohga — those services are governed by their own privacy policies;
- Information collected by app store platforms (Apple App Store, Google Play) in connection with your device account, payment methods, or store-level analytics, which are governed by Apple or Google;
- Employment or contractor relationships with Mavik Labs LLC, which are covered by separate agreements;
- De-identified or aggregated data that cannot reasonably be used to identify you, as described in Section 2.
By using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices, please do not use the Services.
2. Definitions
The following terms have the meanings set forth below. Capitalized terms not defined here have the meanings given in context or under applicable law.
- Personal Information
- Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This includes identifiers (such as email address and username), commercial information (such as subscription status), internet or network activity (such as in-app events), and inferences drawn from the above to create a profile about you.
- Sensitive Personal Information
- A subset of Personal Information that receives heightened protection under laws such as the California Consumer Privacy Act (CCPA/CPRA), Colorado Privacy Act, and similar statutes. For Ohga, this includes health and wellness data, biometric identifiers where applicable, precise geolocation (which we do not collect), and account log-in credentials in combination with passwords or security codes.
- Health Data
- Information about your physical or mental health, wellness, fitness, nutrition, sleep, vital signs, body composition, mood, energy levels, and related metrics. This includes data you log manually, data synced from Apple HealthKit or Google Health Connect, data derived from wearables, and health-related inferences generated by our AI coaching features.
- Biometric Data
- Data generated from measurements of your biological characteristics. Ohga does not collect biometric authentication data (such as Face ID or fingerprint templates for app unlock). Voice recordings submitted to our voice copilot feature are processed for transcription only and are not used to create biometric identifiers or voiceprints for identification purposes.
- Processing
- Any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
- Controller
- The entity that determines the purposes and means of Processing Personal Information. For the Services described in this Policy, Mavik Labs LLC (dba Ohga) is the Controller, except where we act as a processor on behalf of another entity (which is not the case for consumer use of Ohga).
- AI Features
- Artificial intelligence-powered capabilities within Ohga, including conversational coaching, food photo analysis, meal planning, voice copilot transcription and response, workout generation, nutrition label scanning, and weekly wellness summaries. AI Features are initiated by you and operate through Ohga's backend infrastructure.
- Agent Actions
- Proposed operations that an AI model may suggest on your behalf — such as logging a meal, creating a workout, or updating a goal — which are validated by Ohga's PolicyEngine and, for material actions, require your explicit confirmation before execution.
- De-identified Data
- Information that has been processed so that it cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, and for which we maintain technical and organizational safeguards to prevent re-identification.
3. Information We Collect
We collect information in three primary ways: information you provide directly, information collected automatically when you use the Services, and information received from third-party sources you choose to connect. The categories below reflect our current practices as of the effective date of this Policy.
3a. Information You Provide
Account Registration
When you create an Ohga account, we collect:
- Email address (required for account identification and communication);
- Name (first and last), as provided through WorkOS OAuth sign-in with Google, Apple, or Microsoft;
- Authentication tokens and session identifiers managed by WorkOS and stored securely on your device.
Profile Data
You may optionally provide profile information, including:
- First name, last name, username, and nickname;
- Bio and profile preferences;
- Age and gender;
- Height, weight, and body fat percentage;
- Activity level, fitness goals, and experience level;
- Dietary preferences and restrictions;
- Reported injuries or physical limitations;
- Weekly workout days and training schedule preferences.
Wellness Logs
When you use Ohga's core tracking features, we collect wellness data you enter or generate, including:
- Nutrition entries: foods, meals, portions, calories, macronutrients (protein, carbohydrates, fat), and micronutrients; meal templates, favorite foods, and barcode scan history;
- Water intake: volume and timestamps;
- Workout sessions: exercises, sets, repetitions, weight lifted, duration, and notes; workout programs and program enrollments;
- Mood entries: mood ratings, notes, and tags;
- Weight logs and body composition trends;
- Energy logs throughout the day;
- Focus and meditation sessions: duration and session type;
- Goals, todos, and streaks you create within the app.
Ohga may compute basic sentiment indicators (positive/negative word counts) on mood notes to enhance your mood tracking insights.
AI Coaching Conversations
When you use AI Features, we collect:
- Text messages you send to the AI coach and responses generated for you;
- Voice recordings submitted to the voice copilot feature (processed for transcription);
- Food photos you submit for nutrition analysis and meal logging;
- Meal descriptions and context you provide during AI-assisted logging.
User Memories
Ohga may store explicit preferences and facts you ask the AI to remember for personalization (for example, dietary restrictions, preferred workout times, or coaching tone). You can view, edit, and delete these memories in the app.
Social Features
If you enable social features (which are off by default), we may collect:
- Friend connections and connection requests;
- Reactions and interactions on shared content;
- Challenge participation and leaderboard standings;
- Meal duo partnerships and workout buddy relationships;
- Shared progress metrics according to your privacy settings.
Communications
When you contact us for support, submit feedback, or correspond with our privacy team, we collect the content of your messages, your email address, and any attachments or details you choose to provide.
3b. Information Collected Automatically
When you use the Services, certain information is collected automatically:
Device Information
Via the device_info_plus library and similar mechanisms, we collect:
- Device model and manufacturer;
- Operating system name and version;
- Ohga app version;
- Device language and locale settings (for localization).
Usage Analytics
We collect privacy-safe event names and metadata sent to our first-party backend for product analytics. We
do not use third-party analytics SDKs (such as Google
Analytics, Firebase Analytics, or Mixpanel) that transmit raw personal information to external parties. Event
names are designed to describe feature usage in aggregate without embedding health data or message content.
You may disable analytics collection via the allowAnalytics privacy setting (see
Section 10a).
Crash and Error Reports
We use Sentry to collect crash and error reports, including pseudonymous user identifiers, sanitized stack traces, device and app version information, and error timestamps. Sentry reports do not include your health logs, AI conversation content, or other personally identifiable wellness data. Stack traces are sanitized to remove paths or values that could contain PII.
Network Connectivity
We detect network connectivity status (online/offline) to enable offline-first functionality and to determine when to sync data with our cloud backend.
3c. Device Permissions We Request
The Ohga mobile app requests the following device permissions to provide core features. You may deny any permission; denied permissions limit related functionality but do not prevent use of other features.
| Permission | Platform | Purpose |
|---|---|---|
| Camera | iOS, Android | Capture food photos for nutrition analysis, barcode/QR scanning |
| Microphone | iOS, Android | Voice copilot AI coaching, meal dictation |
| Photo Library | iOS, Android | Select food images from gallery, save analyzed photos |
| Health Data (HealthKit / Health Connect) | iOS, Android | Sync steps, heart rate, sleep, calories, workouts, distance |
| Notifications | iOS, Android | Focus timers, workout reminders, local scheduling |
| Activity Recognition | Android | Step counting for Health Connect |
| Audio Settings | Android | Headphone detection for binaural beats during focus sessions |
We do not request Location, Contacts, Bluetooth, or Biometric authentication permissions.
3d. Information from Third-Party Sources
When you choose to connect third-party services, we receive information according to the permissions you grant:
Apple HealthKit (iOS)
With your explicit consent, Ohga may read the following HealthKit data types:
- Step count;
- Heart rate and resting heart rate;
- Active energy burned;
- Sleep analysis (asleep, deep, light, REM, and in-bed durations);
- Distance walking and running;
- Workout sessions recorded in HealthKit.
Google Health Connect (Android)
With your explicit consent, Ohga may read:
- Step count, heart rate, and resting heart rate;
- Active energy burned and total calories burned;
- Sleep sessions (including stage breakdown where available);
- Distance delta and walking/running distance;
- Exercise sessions recorded in Health Connect.
Wearable Cloud Integrations
Planned integrations with Fitbit, Garmin, WHOOP, and Oura will allow you to sync daily metrics via OAuth after you authorize each connection. Until these integrations launch, no data is collected from these providers. When live, we will update this Policy with the specific data types received from each provider.
WorkOS (Authentication)
Our authentication provider, WorkOS, provides:
- Email address;
- First and last name (as provided by your OAuth provider);
- Profile picture URL (if available from your OAuth provider).
RevenueCat (Subscriptions)
RevenueCat provides subscription management data, including:
- Subscription status and entitlements;
- Purchase history and renewal dates;
- Anonymous RevenueCat user identifier linked to your Ohga account.
Open Food Facts (Nutrition Database)
When you scan a product barcode or search for nutrition data, your device sends the barcode identifier directly to Open Food Facts and text search queries, and receives nutritional product data (product name, ingredients, macros, and related fields) in return. We do not send your personal identity to Open Food Facts — only the barcode query or search terms.
3e. Information We Do NOT Collect
To be explicit, Ohga does not collect:
- Precise GPS or geolocation data — we do not request location permissions and do not track your physical location;
- Contact lists or address books — although a contacts permission may be enabled in our build configuration for a planned contact discovery feature, we do not actively access or upload your contacts today;
- Advertising identifiers — we do not integrate advertising SDKs or collect IDFA, GAID, or similar ad tracking identifiers;
- Biometric authentication data — we do not use Face ID, Touch ID, or fingerprint data for app unlock or store biometric templates;
- Browsing history outside Ohga — we do not monitor or collect your activity on other websites or applications.
4. How We Use Your Information
We use Personal Information only for legitimate purposes related to providing and improving the Services. We do not use your health data for advertising, and we do not sell your Personal Information. The table below describes our primary purposes of processing:
| Purpose | Description | Data Categories Used |
|---|---|---|
| Core wellness tracking | Record, display, and analyze your nutrition, workouts, mood, hydration, sleep, and related metrics | Wellness logs, profile data, health integrations |
| AI coaching | Power conversational coaching, personalized recommendations, meal planning, and weekly summaries | AI messages, user memories, wellness context, food photos, voice audio |
| Nutrition & voice processing | Analyze food photos and transcribe voice inputs to facilitate meal logging | Food photos, voice recordings, meal descriptions |
| Cross-device sync | Synchronize your data across devices using encrypted local storage and cloud batch sync | All synced app data |
| Subscriptions & accounts | Process subscriptions, verify entitlements, and manage your account | Account data, RevenueCat purchase data |
| App stability | Monitor crashes and errors to diagnose and fix issues | Pseudonymous crash data (Sentry) |
| Product analytics | Generate anonymized, first-party analytics to understand feature usage patterns | Privacy-safe event names, device info |
| Security & fraud prevention | Enforce acceptable use, detect abuse, and protect account integrity | Account data, usage patterns |
| Legal compliance | Comply with applicable laws, regulations, and lawful requests | As required by law |
| Service improvement | Improve features based on aggregate usage patterns — not by training general-purpose AI on your individual data | De-identified and aggregated data |
We will not use your Personal Information for purposes materially different from those described in this Policy without providing notice and, where required by law, obtaining your consent.
5. AI Features & Data Processing
AI is central to the Ohga experience. This section provides detailed transparency about how our AI Features work, what data they process, and the safeguards we apply.
AI Features in Ohga
Ohga currently offers the following AI-powered capabilities:
- Conversational coaching — natural-language wellness guidance and Q&A;
- Food photo analysis — identify foods and estimate nutrition from photos;
- Meal planning — generate meal suggestions based on your goals and preferences;
- Voice copilot — transcribe voice input and respond conversationally;
- Workout generation — create exercise routines tailored to your profile;
- Label scanning — extract nutrition information from product labels;
- Weekly summaries — synthesize your wellness activity into periodic insights.
Architecture
All AI processing follows a client → Ohga backend → AI provider architecture. Your device does not make direct calls to large language model (LLM) APIs. Instead:
- You initiate an AI Feature within the Ohga app;
- Relevant data is transmitted over TLS to Ohga's backend servers;
- Our backend applies PolicyEngine rules, consent checks, and data minimization before forwarding requests to AI providers;
- AI provider responses are returned through our backend to your device;
- Material Agent Actions proposed by the AI require your explicit confirmation before execution.
Data Sent to AI Providers
Depending on the feature you use, the following data may be sent to AI processing partners:
- Your text messages and coaching prompts;
- Food photos (compressed to reduce payload size);
- Voice audio recordings (PCM16 format for transcription);
- Meal descriptions and logging context;
- Limited user context such as current time, timezone, and meal period (breakfast, lunch, dinner) — we do not include raw HealthKit/Health Connect data or full health histories in AI context by default;
- User memories you have explicitly stored for personalization (when personalization is enabled).
AI Providers
We use the following AI processing partners:
- Perplexity API — routes inference requests to underlying models (which may include Gemini, GPT, Grok, and other models). Used for conversational coaching, meal planning, workout generation, and related text-based AI Features;
- AssemblyAI — transcribes voice audio submitted to the voice copilot feature.
Both providers operate under contractual data processing agreements that prohibit them from using your data to train general-purpose AI models and require zero or minimal data retention beyond the immediate inference request.
Contractual Protections
- AI providers may not use your data to train their models;
- Data retention by AI providers is limited to zero or the minimum necessary to complete the request;
- AI providers are bound by confidentiality and security obligations comparable to our own;
- We conduct periodic reviews of provider compliance with these contractual terms.
What AI Does NOT Do
Ohga's AI Features are designed with the following limitations:
- AI does not make medical decisions or provide medical diagnoses;
- AI does not prescribe treatment, medication, or clinical interventions;
- AI does not share your data with advertisers or marketing networks;
- AI Features do not operate without user initiation — they respond only when you engage them;
- AI coaching is informational and educational, not a substitute for professional medical advice.
Agent Actions
When the AI proposes an action on your behalf (such as logging a meal or scheduling a workout), the proposed action passes through Ohga's PolicyEngine, which validates the action against safety rules and your consent settings. Material actions — those that modify your data or trigger external effects — require your explicit confirmation before execution. You remain in control of what the AI does on your account.
AI Memories
Preferences and facts you ask the AI to remember are stored locally in an encrypted database on your device
and synced to our servers when cloud sync is enabled. You can view, edit, and delete individual memories or
disable personalization entirely via the allowPersonalization privacy setting.
Additionally, Ohga may automatically learn implicit preferences from your interactions — for example, noting dietary restrictions mentioned during meal logging or exercise limitations discussed during workout planning. These implicit memories are stored locally on your device in encrypted storage and help personalize future AI coaching sessions. You can view and delete all memories (both explicit and implicit) in your AI settings.
Reporting AI Content
If you receive AI-generated content that is harmful, inaccurate, offensive, or inappropriate, you can report it by: (1) tapping the flag/report icon on any AI message in the app; (2) emailing support@ohga.app with the conversation details. We review all reports and use them to improve AI safety filters.
Model Training
We do not use your personal data, health logs, AI conversations, or voice recordings to train general-purpose AI models — neither on our own infrastructure nor through our AI providers. Our contracts with Perplexity API and AssemblyAI expressly prohibit providers from using your data for model training. Service improvements are based on aggregate, de-identified usage patterns, not on individual user content.
5g. EU AI Act Compliance
Ohga is classified as a limited-risk AI system under the EU AI Act. In accordance with Article 50 (effective August 2, 2026), we inform users at the point of interaction that they are communicating with an AI system.
AI-generated content — including coaching responses, meal plans, workout plans, recipes, and weekly summaries — is produced by artificial intelligence and may not be factually accurate. We are implementing content marking for machine-generated outputs in compliance with synthetic content obligations under the EU AI Act.
Our AI coaching does not constitute a high-risk AI system under Annex III, as it does not perform medical diagnosis, insurance pricing, or employment decisions.
6. Health Data — Special Protections
Health Data receives the highest level of protection in our systems. We apply the following commitments to all Health Data we process:
- Health Data is never sold to any third party, under any circumstances;
- Health Data is never used for advertising or marketing purposes;
- Health Data is never shared with insurance companies, employers, or data brokers;
- Data read from Apple HealthKit and Google Health Connect is read-only — Ohga does not write false or misleading health data back to HealthKit or Health Connect;
- Health Data is not stored in iCloud or other platform-managed cloud backup systems — it resides in Ohga's encrypted local database and our secured cloud infrastructure;
- Health Data is encrypted at rest using SQLCipher (AES-256) on mobile devices and encrypted in transit using TLS 1.3 for all API communications;
- Separate consent is required before Ohga begins collecting Health Data from HealthKit, Health Connect, or manual logging of health metrics;
- You may disconnect health data sources at any time through your device settings (iOS Settings → Health → Data Access & Devices, or Android Health Connect permissions) or by revoking permissions within the Ohga app.
We use Apple HealthKit and Google Health Connect data specifically to: (1) display your daily activity metrics (steps, distance, calories) in the Ohga dashboard; (2) incorporate sleep quality data into your wellness insights; (3) provide heart rate context for workout intensity tracking; and (4) enable your AI coach to reference your activity levels when providing personalized guidance. HealthKit and Health Connect data is never used for advertising, marketing, or data mining purposes beyond providing you with direct wellness intelligence.
These protections apply regardless of your location and are in addition to any rights provided under jurisdiction-specific laws described in Section 10.
7. How We Share Your Information
We share Personal Information only in the limited circumstances described below. We never sell Personal Information and never share Health Data for advertising.
Service Providers
We engage trusted third-party service providers who process data on our behalf under contractual obligations that limit their use of your data to the services they provide to us. These include cloud hosting (AWS), crash reporting (Sentry), subscription management (RevenueCat), and authentication (WorkOS).
AI Processing Partners
As described in Section 5, we share limited data with Perplexity API and AssemblyAI for AI inference and voice transcription. These partners operate under data processing agreements (DPAs) with contractual restrictions on data use and retention.
User-Directed Sharing
If you enable social features and adjust your privacy settings, you may choose to share wellness progress, workout data, or profile information with friends, workout buddies, or challenge participants. All social sharing is opt-in and controlled by granular privacy settings (see Section 10a). Most social features are off by default.
Legal Requirements
We may disclose Personal Information when we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request. We oppose overbroad or unlawful requests and will challenge requests that we believe exceed lawful authority, including by seeking to narrow the scope of production where permitted.
Business Transfers
If Mavik Labs LLC is involved in a merger, acquisition, reorganization, or sale of assets, your Personal Information may be transferred as part of that transaction. We will provide notice before your Personal Information becomes subject to a different privacy policy and will ensure the acquiring entity commits to protections no less stringent than those in this Policy.
What We Never Do
- We never sell Personal Information to data brokers or any third party;
- We never share Health Data for advertising or marketing;
- We never share Personal Information for cross-context behavioral advertising.
Subprocessor Table
The following table lists our key subprocessors as of the effective date of this Policy.
| Provider | Purpose | Data Received | Country |
|---|---|---|---|
| AWS (S3, CloudFront, Aurora) | Hosting, storage, CDN | All synced app data | US |
| WorkOS | Authentication | Email, name, OAuth tokens | US |
| Perplexity AI | AI coaching inference | Chat messages, food photos, context | US |
| AssemblyAI | Voice transcription | Audio recordings | US |
| RevenueCat | Subscription management | User ID, purchase receipts | US |
| Sentry | Crash reporting | Pseudonymous error data | US |
| Open Food Facts | Nutrition database (direct client query) | Barcode queries, text search queries | France |
| Spotify | Music playback integration | OAuth tokens, playback state, track metadata | Sweden/US |
| Apple (MusicKit) | Music playback integration | MusicKit authorization, playback metadata | US |
8. Data Retention
We retain Personal Information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- Account data: retained while your account is active, plus up to 30 days after you submit a deletion request, to allow for account recovery and complete erasure from backup systems;
- Health and wellness logs: retained until you delete individual entries or delete your account;
- AI chat history: retained until you delete a conversation or delete your account;
- Voice recordings: processed transiently for transcription; not stored beyond the transcription step on our servers;
- Food photos: retained with associated nutrition entries; deleted when you delete the entry or your account;
- Crash reports: retained for 90 days (Sentry default retention period);
- Analytics events: retained for 12 months, then aggregated and anonymized;
- Backup systems: deleted data may persist in encrypted backups for up to 30 days after deletion from primary systems;
- De-identified and aggregated data: may be retained indefinitely for product improvement and research, as it cannot reasonably identify you.
You may request earlier deletion of your data at any time by deleting your account in the app or contacting privacy@ohga.app.
9. Data Security
We implement technical and organizational measures designed to protect your Personal Information against unauthorized access, alteration, disclosure, or destruction.
- Encryption at rest: SQLCipher with AES-256 encryption for the local database on iOS and Android devices;
- Encryption in transit: TLS 1.3 for all API communications between your device and our servers;
- Secure credential storage: authentication tokens stored in iOS Keychain and Android Keystore;
- Data export encryption: AES-256-GCM encryption for data export files generated through the in-app export feature;
- Access controls: role-based access with the principle of least privilege for all personnel with access to production systems;
- No third-party analytics with raw PII: we do not use Firebase or other third-party analytics platforms that transmit raw personally identifiable information;
- Privacy-by-default settings: most social and sharing features are disabled by default, requiring affirmative opt-in;
- Regular security assessments: we conduct periodic reviews of our security posture and address identified vulnerabilities;
- Incident response: in the event of a data breach, we will notify affected users and relevant authorities within 72 hours where required by applicable law.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your Personal Information, we cannot guarantee absolute security.
10. Your Rights & Choices
Depending on your location, you may have specific rights regarding your Personal Information. This section describes rights available to all users and additional rights under regional privacy laws.
10a. Rights for All Users
Regardless of where you live, Ohga provides the following controls:
- Access your data: export your data in-app with AES-256-GCM encrypted export files;
- Correct inaccurate data: edit profile information and wellness logs directly in the app;
- Delete your account and data: initiate account deletion in app settings or by contacting privacy@ohga.app;
- Withdraw consent: revoke consent for specific processing activities (health data, AI personalization, analytics) at any time;
- Disconnect health data sources: revoke HealthKit or Health Connect permissions through device settings;
- Control AI personalization: toggle the
allowPersonalizationsetting; - Control analytics: toggle the
allowAnalyticssetting; - Manage social visibility: configure comprehensive privacy settings for social features.
Privacy Settings
Ohga provides the following granular privacy settings (defaults shown in parentheses):
shareProgress— share wellness progress with friends (default: off)publicProfile— make your profile visible to other users (default: off)allowAnalytics— allow first-party usage analytics (default: on)allowPersonalization— allow AI personalization and memories (default: on)shareWorkoutData— share workout details with connections (default: off)allowSocialFeatures— enable social features (default: off)shareSensitiveMetrics— share sensitive health metrics (default: off)shareExactValues— share exact metric values vs. ranges (default: off)shareIncludeName— include your name in shared content (default: off)hideFromLeaderboards— hide from challenge leaderboards (default: off)
10b. European Economic Area, United Kingdom, and Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland, the following additional provisions apply:
Legal Bases for Processing
- Consent: health data collection, AI Features, and optional analytics;
- Contract: providing the Services you have requested, including account management and subscription processing;
- Legitimate interest: security monitoring, fraud prevention, and service improvement using de-identified data — balanced against your rights and freedoms.
| Processing Activity | Legal Basis | Art. 9 Condition (if health) |
|---|---|---|
| Provide core wellness tracking | Contract (Art. 6(1)(b)) | Explicit consent (Art. 9(2)(a)) |
| AI coaching and personalization | Consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| Process nutrition photos/voice | Consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| Sync data across devices | Contract (Art. 6(1)(b)) | Explicit consent (Art. 9(2)(a)) |
| Process subscriptions | Contract (Art. 6(1)(b)) | N/A |
| Monitor stability / crash reporting | Legitimate interest (Art. 6(1)(f)) | N/A |
| Product analytics | Consent (Art. 6(1)(a)) | N/A |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) | N/A |
| Legal compliance | Legal obligation (Art. 6(1)(c)) | N/A |
Our legitimate interests in security monitoring and crash reporting are balanced against your rights and freedoms. These processing activities use pseudonymous data only and do not process health information. You may object to legitimate-interest processing at any time by contacting privacy@ohga.app.
Your GDPR Rights
- Right of access to your Personal Information;
- Right to rectification of inaccurate data;
- Right to erasure ("right to be forgotten");
- Right to restriction of processing;
- Right to data portability;
- Right to object to processing based on legitimate interest;
- Right to withdraw consent at any time (without affecting the lawfulness of prior processing);
- Right to lodge a complaint with your local supervisory authority.
Automated Decision-Making
Our AI coaching features provide informational recommendations only. We do not make solely automated decisions that produce legal or similarly significant effects on you. You may request human review of any AI-generated recommendation by contacting privacy@ohga.app.
Data Protection Contact
For GDPR-related inquiries, contact our privacy team at privacy@ohga.app.
EU Representative (Article 27 GDPR): To be appointed. We will update this section when our EU representative is designated.
International Transfers
Your data is processed primarily in the United States. Where Personal Information is transferred outside the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as an appropriate safeguard, supplemented by organizational security measures described in Section 9.
10c. California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) provides you with specific rights regarding your Personal Information.
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following CCPA categories:
- Identifiers: email, username, device identifiers, IP address;
- Personal information (Cal. Civ. Code § 1798.80): name, age, gender;
- Protected classification characteristics: age, gender (as voluntarily provided);
- Commercial information: subscription status, purchase history;
- Internet or network activity: in-app feature usage events;
- Sensory data: food photos, voice recordings (transient);
- Health information: nutrition, fitness, sleep, mood, weight, and related wellness data;
- Inferences: wellness trends and coaching recommendations derived from your data.
We Do Not Sell or Share for Advertising
We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising. We have not sold or shared Personal Information in the preceding 12 months.
Your California Rights
- Right to know: what Personal Information we collect, use, disclose, and sell;
- Right to delete: request deletion of your Personal Information;
- Right to correct: request correction of inaccurate Personal Information;
- Right to opt-out: of sale or sharing (not applicable — we do neither);
- Right to limit: use of Sensitive Personal Information to service delivery purposes;
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
Sensitive Personal Information (including health data) is processed only for providing the Services you request — not for advertising or profiling beyond what is necessary to deliver the Services.
Authorized Agents
You may designate an authorized agent to submit a request on your behalf. The agent must provide proof of authorization (such as a signed power of attorney or written permission) and we may require you to verify your identity directly.
Verification Process
When you submit a rights request, we verify your identity by matching your request details against information already in our records (email address, account information). For deletion requests involving sensitive data, we may require additional verification steps. If we cannot verify your identity, we will inform you and explain what additional information is needed.
Response Timeline
We will respond to verifiable consumer requests within 45 days. If we need more time (up to an additional 45 days), we will notify you of the extension and the reason.
10d. Other US States
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive consumer privacy laws have rights similar to those described above, including rights to access, delete, correct, and opt out of certain processing activities.
- Opt-out of targeted advertising: not applicable — Ohga does not engage in targeted advertising;
- Appeal process: if we deny your privacy request, you may appeal by contacting privacy@ohga.app within 45 days of our response. We will respond to appeals within the timeframe required by your state's law.
10e. Australia
We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Australian users have the right to access and correct their Personal Information and to complain to the Office of the Australian Information Commissioner (OAIC) if they believe we have interfered with their privacy.
In accordance with amendments effective December 2026, we disclose that Ohga uses automated decision-making (AI coaching) that is informational only and does not produce legal or similarly significant effects. You may request information about how automated decisions are made by contacting privacy@ohga.app.
10f. India (DPDP Act)
Under India's Digital Personal Data Protection Act, 2023, we process your personal data based on your consent. You have the right to access, correct, and erase your data, withdraw consent, and nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance Officer: privacy@ohga.app;
- You may lodge a complaint with the Data Protection Board of India if you are unsatisfied with our response.
10g. Brazil (LGPD)
Under Brazil's Lei Geral de Proteção de Dados (LGPD), we process health data based on your explicit consent (Art. 11). Brazilian users have the following rights:
- Confirmation of the existence of processing;
- Access to your data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or excessive data;
- Data portability;
- Deletion of data processed with consent;
- Information about entities with whom we have shared data;
- Revocation of consent;
- Review of decisions made solely by automated processing.
You may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
10h. Canada (PIPEDA)
We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). We obtain meaningful consent before collecting Personal Information and obtain express consent before collecting health data. Canadian users may access, correct, and challenge our compliance by contacting privacy@ohga.app or by filing a complaint with the Office of the Privacy Commissioner of Canada (OPC).
11. Children's Privacy
Ohga is designed for users aged 18 and older. We do not knowingly collect Personal Information from children under 13 years of age (as defined by the U.S. Children's Online Privacy Protection Act, COPPA) or from children under 16 years of age (as defined by the GDPR).
If we discover that we have collected Personal Information from a child:
- We will delete the information immediately upon discovery;
- We will notify the parent or guardian if contact information is available;
- We will terminate the associated account;
- We will not sell or share the minor's data under any circumstances.
If you believe we have collected information from a child, please contact us immediately at privacy@ohga.app.
12. Cookies & Website Tracking
This section describes our use of cookies and similar technologies on the ohga.app website. The Ohga mobile application does not use browser cookies.
Website Cookies
The ohga.app website uses only the following:
- Strictly necessary cookies: including the CloudFront bot
management cookie (
__cf_bm) used to protect against automated abuse; - We do not use advertising cookies;
- We do not use third-party tracking pixels;
- We do not use Google Analytics or similar third-party analytics on the website.
Mobile App
The Ohga mobile application does not use cookies. Authentication and session management rely on secure token storage in the iOS Keychain and Android Keystore.
Global Privacy Control
We honor Global Privacy Control (GPC) signals transmitted by supported browsers. When we detect a GPC signal, we treat it as a valid opt-out request for any sale or sharing of Personal Information (though as stated, we do not sell or share Personal Information for advertising in any case).
13. Third-Party Links & Integrations
Ohga integrates with third-party services that you choose to connect. Each integration is user-initiated and may be revoked at any time.
- Apple Health (HealthKit): read-only health data sync on iOS — governed by Apple's privacy policy;
- Google Health Connect: read-only health data sync on Android — governed by Google's privacy policy;
- Spotify and Apple Music: music playback integrations for workout and meditation sessions — governed by each provider's privacy policy;
- Wearable providers (Fitbit, Garmin, WHOOP, Oura — planned): daily metrics via OAuth when available.
Push notifications (FCM/APNs) are not yet implemented. When they are, we will update this Policy to describe notification data handling and provide opt-out controls.
Third-party services are governed by their own privacy policies and terms. We are not responsible for the privacy practices of third-party services, and we encourage you to review their policies before connecting them to Ohga.
14. Consumer Health Data Notice
This notice supplements our Privacy Policy for users in Washington State and Nevada, and applies to consumer health data as defined under the Washington My Health My Data Act and Nevada consumer health data laws.
Health Data Categories
Ohga collects the following categories of consumer health data:
- Nutrition and dietary information;
- Fitness metrics and workout data;
- Sleep duration and sleep stage data;
- Heart rate and resting heart rate;
- Mood and mental wellness entries;
- Weight and body composition data.
Purposes of Collection
We collect consumer health data for the following purposes:
- Providing wellness coaching and personalized insights;
- Personalizing your Ohga experience based on your health goals;
- Delivering the core Services you have requested.
We Do Not Sell Consumer Health Data
We do not sell consumer health data. We do not share consumer health data with third parties for advertising or marketing purposes.
Your Rights
- Right to delete your consumer health data;
- Right to withdraw consent for consumer health data collection;
- Right to access your consumer health data through the in-app export feature.
Consent
We obtain your affirmative opt-in consent before collecting consumer health data, at or before account creation, through a dedicated consent flow that explains the categories of health data collected and how they will be used.
15. International Data Transfers
Ohga is operated from the United States. Your Personal Information is processed primarily in AWS US regions. If you access the Services from outside the United States, your data will be transferred to, stored in, and processed in the United States and potentially other countries where our subprocessors operate.
Safeguards for international transfers include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Organizational security measures described in Section 9;
- Contractual data processing agreements with all subprocessors;
- Data minimization — we transfer only the data necessary for each processing purpose.
Countries where our subprocessors currently operate:
- United States: AWS, WorkOS, Perplexity AI, AssemblyAI, RevenueCat, Sentry;
- France: Open Food Facts.
You may request additional information about specific international transfers by contacting privacy@ohga.app.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- Material changes (such as new data collection practices or new sharing categories) will be communicated via email to the address associated with your account and via an in-app notice before the changes take effect;
- Non-material changes (such as clarifications or formatting updates) will be posted on this page with an updated effective date;
- Continued use of the Services after the notification period for material changes constitutes acceptance of the updated Policy;
- Prior versions of this Policy are available upon request by contacting privacy@ohga.app.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
- Privacy inquiries: privacy@ohga.app
- General support: support@ohga.app
- Mail: Mavik Labs LLC, [Physical mailing address to be added]
We aim to respond to all privacy requests within 30 days. For requests under California law (CCPA/CPRA), we will respond within 45 days as required by statute. If we need additional time, we will notify you of the extension and the reason.
18. Policy Version History
| Version | Date | Summary |
|---|---|---|
| v1.0 | June 1, 2026 | Initial comprehensive privacy policy |