Privacy

Privacy Policy

Last updated: 14 May 2026 · Effective: 14 May 2026

Elixira is developed and operated by Hyperture Technologies. This Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it. We've written it in plain English — where the law requires technical terms, we explain them.

The short version

If you don't want to read all of this — here's the essence:

Who we are

Elixira (the "App", "we", "us", "our") is developed and operated by Hyperture Technologies ("the Company"). We are the data controller for the personal data processed through the App.

We take privacy seriously. This Policy covers the Elixira mobile application and the elixira.app website. It applies to users worldwide, including users in the United States, the United Kingdom, and the European Union.

Privacy contact

For any privacy-related matter, contact us at:

What personal data we collect

Data you provide when creating an account

Data you provide during onboarding

Data created as you use the app

Data collected automatically

Sensitive data

Some data we collect relates to your health and wellbeing — including lifestyle answers and check-in scores. Under applicable privacy laws (including the UK GDPR and EU GDPR), this is classified as sensitive personal data. We process it only with your explicit consent, given when you complete onboarding and continue using the App. You can withdraw consent at any time by deleting your account.

What we do not collect

Why we collect this data and our legal basis

PurposeData usedLegal basis
Account creation and sign-inEmail, password, namePerformance of contract
Calculating life expectancy and countdownDOB, biological sex, lifestyle answersContract + explicit consent for sensitive data
Generating AI Coach insightsProfile snapshot, recent activity statsContract + explicit consent
Tracking habits, goals, and bucket itemsItems you create + completion historyPerformance of contract
Sending push notificationsDevice token, nameConsent (chosen during onboarding)
Sending password reset emailsEmail addressPerformance of contract
Managing your subscriptionAnonymised user ID, purchase eventsPerformance of contract
Improving and debugging the AppCrash logs, device type, app versionLegitimate interest
Legal complianceAccount recordsLegal obligation

Who we share your data with

We never sell your data and never share it for advertising. We share data only with the technical providers who help us operate the App. Each is contractually bound to process your data only on our instructions.

ProviderPurposeData sharedLocation
SupabaseAuthentication and databaseAccount data, profile, all in-app entriesUSA / EU
Anthropic (Claude API)AI Coach insightsProfile snapshot, current stats, recent activityUSA
RevenueCatSubscription managementAnonymised user ID, purchase eventsUSA
OneSignalPush notificationsDevice token, nameUSA
ResendPassword reset emailsEmail address onlyUSA / EU
Google PlayApp distribution and billingSubscription receipts, anonymised user IDGlobal
Expo / EASApp build infrastructureNo runtime user dataUSA

Legal requests

We may disclose your data where required by law — for example, in response to a valid court order or government request. Where legally permitted, we will notify you before disclosing.

International data transfers

Some of our service providers are located in the United States. When we transfer personal data internationally, we ensure appropriate safeguards are in place:

How long we keep your data

Data typeRetention
Account data (email, name, DOB, profile)Active account lifetime + 30 days after deletion
In-app entries (habits, goals, journal, check-ins)Same as above
AI Coach prompt data (with Anthropic)Up to 30 days per Anthropic's policy — not used for model training
Subscription and billing records7 years (financial compliance requirement)
Crash and error logs90 days
Database backupsRolling 30-day cycle

How we protect your data

No system is perfectly secure. While we apply industry-standard protections, we cannot guarantee absolute security. You use the App at your own risk.

Your privacy rights

For users in the United States

Depending on your state, you may have rights under the California Consumer Privacy Act (CCPA/CPRA) or similar state laws:

For users in the UK and EU

Under the UK GDPR and EU GDPR, you have the right to:

How to exercise your rights

Most controls are available directly in the App:

For anything else, email privacy@elixira.app. We respond within 30 days (UK/EU GDPR) or 45 days (US state laws).

Children's data

Elixira is for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, contact privacy@elixira.app and we will delete it promptly.

AI-generated content

The AI Coach uses Anthropic's Claude API. When generating insights, a snapshot of your profile and recent activity is sent to Anthropic for processing.

Cookies and tracking

The elixira.app website does not use advertising cookies, tracking pixels, or third-party analytics. The only external resource loaded is Google Fonts for typography.

The Elixira app does not contain advertising trackers or cross-app fingerprinting. The only device identifier used is the OneSignal push notification token.

Changes to this Policy

We may update this Policy from time to time. For material changes we will notify you by in-app message or email. Continued use of the App after an update constitutes acceptance. Previous versions are available on request.

Supervisory authorities

If you're unsatisfied with how we handle your data, you can lodge a complaint with a supervisory authority:

Contact us

For any privacy question or data request:

Privacy: privacy@elixira.app
Support: support@elixira.app
Company: Hyperture Technologies

We acknowledge all requests within 5 business days and resolve them within 30 days.