Skip to content
RRomy
How it worksPrivacyPricingBlog
TürkçeSign inGet started
Back to Romy

Privacy Policy

How Romy collects, uses, protects, and shares data for connected health and life features.

Last updated: October 1, 2026

On this page
OverviewWho we areInformation we collectHow we use informationAI and service providersSharingSub-processorsApple Health (HealthKit)Location historyYour controlsYour rights (GDPR, UK GDPR, Swiss FADP)Users in Türkiye (KVKK)Retention and securityHealth privacy lawsChildren and changes

On this page

OverviewWho we areInformation we collectHow we use informationAI and service providersSharingSub-processorsApple Health (HealthKit)Location historyYour controlsYour rights (GDPR, UK GDPR, Swiss FADP)Users in Türkiye (KVKK)Retention and securityHealth privacy lawsChildren and changes

Overview

Romy is a private personal operating system for health and life data. This policy explains what we collect, how we use it, and the choices you have.

Romy is not a medical provider, emergency service, or substitute for professional medical advice. Do not use Romy for emergencies.

Who we are

Romy is provided by Hareword LLC, 604 Carson Dr, NT-1, Bear, DE 19701, United States. Hareword LLC is the controller of the personal data Romy handles.

The person responsible for privacy at Hareword LLC is Yusuf Serkan Haslak. You can reach us at privacy@romyapp.io.

We have no establishment in the European Union or the United Kingdom.

Information we collect

  • Account information, including name, email, authentication records, settings, and invitation status.
  • Health and life content you add, including notes, goals, protocols, products, symptoms, subjective states, files, lab reports, biomarker readings, radiology reports, and chat messages.
  • Integration data you choose to connect, including wearable, recovery, sleep, activity, workout, body measurement, and provider connection status from services such as WHOOP and Oura.
  • Document and media data you upload or create, including PDFs, images, voice snippets sent for transcription, extracted text, summaries, and metadata.
  • Approximate location (city, country, and timezone) if you turn on location history. See Location history below.
  • Technical data needed to operate Romy, including device/browser information, IP-derived request metadata, logs, rate-limit records, security events, error reports, and approximate usage events.

How we use information

  • Provide, secure, troubleshoot, and improve Romy.
  • Authenticate users, enforce access controls, and prevent abuse.
  • Sync integrations at your direction and show connected-provider data in the product.
  • Extract, organize, search, summarize, and display health and life information you choose to provide.
  • Generate AI responses, daily briefs, document extraction, trend analysis, and product features you request.
  • Comply with applicable law, respond to valid legal process, and send required notices.

AI and service providers

Romy runs on a small set of companies that process data on its behalf. Rather than describe them as categories, we name each one in Sub-processors below, with what it receives and why.

When you use AI or document features, the relevant prompts, files, excerpts, and context are sent to AI infrastructure and model providers to produce the requested output. We limit this to what is needed to provide the feature.

Sharing

  • We do not sell your personal information.
  • We do not share your information for cross-context behavioral advertising.
  • We share information with the service providers named in Sub-processors below, which process it to run Romy.
  • We share information with integration providers when you connect, refresh, revoke, or use that provider.
  • We may disclose information if required by law, to protect Romy or users, or in a business transfer subject to appropriate safeguards.

Sub-processors

These are the companies that receive your data, and what each one gets. The first four are part of how Romy runs and are involved in ordinary use. The rest receive something only when you use the feature they support.

This list describes how Romy works today. When it changes, we change this list, and the last-updated date above moves with it.

  • Cloudflare — the infrastructure Romy is built on. It hosts the app and stores what is in it: your account, your health and life content, your files and lab reports, and your chat history. Cloudflare also delivers Romy's email, checks sign-up and password-reset requests for automated abuse, receives Romy's request logs and error traces, routes Romy's AI requests through its AI gateway, and runs the models that transcribe your voice messages and build the search index over your own content.
  • OpenAI and Google — run the models behind Romy's private AI gateway proxy that answer you in chat and power other AI features. They receive your messages and any image you attach, the context Romy assembles for the turn, which can include your profile, your records, and earlier conversation, and the results of the tools the model uses. They also receive the product label photos and descriptions you ask Romy to read or tidy up, the text of articles you save so Romy can summarize them, and the conversation text Romy's background features use for memory, conversation summaries, and safety checks. Romy can change which models it runs, and a request can move to a backup model when the first one fails, so the provider that receives a given request can change.
  • Sentry — receives an error report when something in Romy fails. A report carries the technical detail of the failure and your account id. Romy removes message content, prompts, model output, credentials, and web address query strings before sending it.
  • Mixpanel — new product analytics are sent only if you choose to turn them on on this website or in Romy's Privacy & data settings. New events are limited to generic screen and action names, an anonymous or account identifier, device platform, and event times. They contain no name, email, chat or health content, IP address, or screen recording. Earlier analytics may have included more information; contact us to request removal of existing Mixpanel data. You can turn analytics off at any time.
  • OpenRouter — only when you upload a document. It routes what you sent to the model that reads it, and receives the lab reports, radiology reports, and other files you upload for extraction.
  • Research services — only when Romy looks something up to answer you. The search terms and web addresses the model writes for your question, which can reflect what you asked about, go to Romy's own company-operated research service for web, Reddit, X, and GitHub searches and page reading, and to the public Europe PMC, ClinicalTrials.gov, and openFDA databases for medical literature, clinical trials, and drug labels. The company-operated research service does not forward queries to additional AI providers. Romy does not attach your name, email, account id, or files to these requests.
  • Google — only if you choose to sign in with Google. Google confirms who you are and passes Romy the email address, name, and account id on that Google account.
  • Apple — only if you turn on notifications on a mobile device. Apple's push service receives your device's notification token and the title and text of each notification Romy sends you.
  • Expo — only if you use the mobile app. The app checks Expo's update service for app updates, and Expo receives the technical details of that check, such as the app version, device platform, an installation identifier, and the IP address it comes from. It receives no account, chat, or health content.
  • Jina AI — only when you save an article by its web address. Jina's reader service receives that address and fetches the page so Romy can read it.
  • WHOOP and Oura — connections you choose. When you connect one, Romy exchanges access tokens with that provider and pulls the recovery, sleep, activity, workout, and body data it makes available. Disconnecting in Romy or at the provider stops it.

Apple Health (HealthKit)

On iPhone, you can connect Romy to Apple Health in You → Connections → Apple Health. Romy reads nothing from Apple Health until you tap Connect and choose, in Apple's permission screen, which data Romy may read. Romy only reads from Apple Health. It never writes to it.

Romy can read sleep, heart rate (including resting and walking heart rate), heart rate variability (HRV), respiratory rate, blood oxygen, steps, active energy, exercise minutes, workouts, VO2 max, body weight, and body fat percentage. Your iPhone combines these into one summary per day, plus your workouts, and sends them to Romy's servers, which run on Cloudflare. Romy reads Apple Health when you open the app or tap Sync now, not in the background. The first sync covers the previous 90 days.

Romy uses this data to show your sleep, heart, activity, workout, and body trends on Today, to update the weight in your profile when Apple Health has a newer reading, and so your Romy coach can use the readings when it answers you. When the coach uses them, they are sent to the AI providers named in Sub-processors (Cloudflare's AI gateway and the OpenAI and Google models behind it), under the AI permission you give before your first AI request. If you connect WHOOP or Oura to Romy directly, Romy skips the copies those apps write into Apple Health and uses the data from the provider instead. If you connect your own AI assistant, such as Claude, to Romy through Romy's connector, that assistant can read these readings when you ask it to.

  • We do not use Apple Health data for advertising, marketing, or data mining, and we do not sell it.
  • We do not disclose Apple Health data to third parties, except to the service providers named in Sub-processors when that is needed to provide the features you use, or when required by law.
  • We do not store Apple Health data in iCloud.
  • Disconnecting Apple Health in Romy stops syncing. Data already synced stays in your Romy history, and is included when you export your data, until you delete your account or ask us to delete it. Deleting your account deletes it.
  • To change what Romy can read, or to turn its access off completely, open the Health app → Sharing → Apps → Romy.

Location history

Location history lets Romy know which city you are in and when you travel, so your coach can account for things like jet lag, changed routines, and local times. It is optional.

Romy keeps stays, not pings. A stay is a city, a country, a timezone, and the days you were there. Three days in Istanbul is one stay. We do not store your exact position or a trail of coordinates.

  • On iPhone, with your permission, the app works out your city on the device using Apple's location services. Apple's geocoder, which works under Apple's own privacy terms, turns the position into a city name. Only the city, country, and timezone are sent to Romy. Your exact position is never sent to Romy.
  • On the website, Romy uses the approximate city and country that your network (IP) address indicates, plus your browser's timezone. The IP address itself is not stored with the history.
  • We keep location history for 6 months. Older stays are deleted automatically.
  • You can view it, delete it, export it, or turn it off in Settings → Privacy → Location history. Turning it off deletes the stored history.
  • In the EEA, the UK, Switzerland, and Türkiye, location history stays off until you turn it on. That choice is separate from creating an account or accepting these terms and this policy.
  • Elsewhere, the website's approximate location is on by default, and you can turn it off at any time. On iPhone it is always your choice: the app asks first.

Your controls

  • Disconnect wearable and provider integrations in the product or at the provider.
  • Export or delete account data where the product exposes those controls.
  • Request access, correction, deletion, portability, or restriction where applicable law gives you those rights.
  • Delete your account from settings. Some limited records may remain when needed for security, legal, backup, or fraud-prevention purposes.

Your rights (GDPR, UK GDPR, Swiss FADP)

This section applies if the EU General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection (FADP) covers you. The controller is Hareword LLC (see Who we are). It has no establishment in the EU or the UK.

You have the right to access your personal data, have it corrected, have it erased, receive it in a portable format, restrict how we use it, and object to our processing. Where we rely on your consent, you can withdraw it at any time. Withdrawing does not affect processing that happened before.

To use a right, email privacy@romyapp.io or use the controls in Settings. We answer within one month.

You can complain to a supervisory authority: the data protection authority in your EU country, the Information Commissioner's Office (ICO) in the UK, or the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland.

Hareword LLC and the providers named in Sub-processors are in the United States and elsewhere, so your data is processed outside the EEA, the UK, and Switzerland. Where the law requires it, we rely on safeguards such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses (or the UK and Swiss equivalents), depending on the provider.

We rely on these legal bases:

  • Providing Romy to you: contract (Art. 6(1)(b)).
  • Your health data: your explicit consent (Art. 9(2)(a)).
  • Location history: your consent (Art. 6(1)(a)).
  • Security and abuse prevention: our legitimate interests (Art. 6(1)(f)).

Users in Türkiye (KVKK)

If you use Romy in Türkiye, the Personal Data Protection Law No. 6698 (KVKK) applies. The Turkish version of this page carries the full information notice under KVKK Art. 10 as "KVKK Aydınlatma Metni"; this section gives the same content in English. The data controller is Hareword LLC, 604 Carson Dr, NT-1, Bear, DE 19701, United States (responsible person: Yusuf Serkan Haslak; contact: privacy@romyapp.io).

We process your personal data to provide and secure Romy, to run the features you use, and to meet legal obligations, as described in How we use information above.

The legal grounds are KVKK Art. 5 and Art. 6: the performance of a contract, our legitimate interests, legal obligations, and your explicit consent (açık rıza). Health data and location history are processed on your explicit consent.

We collect your data through the Romy app, the website, and the services you connect.

Your data is processed outside Türkiye, on Cloudflare and by the AI and other providers named in Sub-processors. Transfers abroad follow KVKK Art. 9.

Your explicit consent for location history is given separately, in Romy's Settings or when the iPhone app asks, and is not part of this notice. You can withdraw it at any time.

You can exercise your KVKK Art. 11 rights (below) by applying to us in writing or at privacy@romyapp.io (KVKK Art. 13). We answer as soon as possible and within 30 days at the latest, free of charge; if the request needs a separate cost, the fee in the Personal Data Protection Board's tariff may be charged. If you are not satisfied with our answer, you can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 30 days of learning our answer, and in any case within 60 days of your application.

  • Learn whether your personal data is processed.
  • Request information if it has been processed.
  • Learn the purpose of the processing and whether it is used accordingly.
  • Know the third parties to whom your data is transferred, in Türkiye or abroad.
  • Request correction if the data is incomplete or incorrect.
  • Request deletion or destruction of your data under KVKK Art. 7.
  • Request that corrections and deletions be notified to the third parties to whom your data was transferred.
  • Object to a result against you that comes from analysis exclusively by automated systems.
  • Request compensation for damage caused by unlawful processing.

Retention and security

We keep information for as long as needed to provide Romy, comply with obligations, resolve disputes, preserve security, and maintain backups.

Location history is the exception: we keep it for 6 months, and Romy automatically prunes stays that are older.

We use technical and organizational safeguards such as access controls, encryption, authentication, and operational monitoring. No system can be guaranteed completely secure.

Health privacy laws

Consumer health apps can be subject to privacy and breach-notification rules even when they are not HIPAA-covered entities. Romy is designed to treat health data carefully and to provide notices required by applicable law.

Children and changes

Romy is not intended for children under 18.

We may update this policy as Romy changes. The updated date shows when the policy last changed.

RRomy

Your health's memory. Labs, wearables and your own story, in one private place.

Romy

  • How it works
  • Pricing
  • Blog
  • Sign in
  • Get started

Legal

  • Privacy
  • Terms
  • Editorial policy
  • Support

Language

  • English
  • Türkçe

© 2026 Romy. All rights reserved.

Romy is not a medical service and does not replace your clinician. Photos from Unsplash by Sohrob Fatoorechie, Kelly Sikkema, Mina Rad, Marcos Paulo Prado, Jessica Fadel, Angel Balashev.

Help us improve Romy by sharing which screens and features you use. No health details, chat messages, or screen recordings are shared. This is off until you choose to turn it on. You can change your choice any time.