Working policy ยท July 17, 2026

Privacy, plainly.

Pre-launch notice: this policy describes the intended product behavior in the current implementation. It requires final legal, security, vendor, and data-retention review before public membership sales.

What Proof collects

Proof may collect account details, the answers and corrections you give your coach, products on your shelf, routine and experiment activity, photos you intentionally capture, and health or calendar signals you explicitly permit.

Why it is used

Information is used to operate your account, remember your context, build and adjust your plan, measure active experiments, prepare verdicts, and keep recommendations within the safety boundaries you provide.

Health and photo data

Health, photo, and conversation data are sensitive. HealthKit collection must be tied to a declared purpose, and Proof should prefer derived features over raw samples where practical. Automated photo analysis is not a launch dependency; if enabled after validation, it must be self-relative and disclose method, processor, retention, and confidence.

Service providers

Proof's selected launch stack is Vercel for API hosting, PlanetScale for the relational record, Apple for App Store and device services, Twilio for phone verification and RCS/SMS, AWS S3 for private objects, Inngest for durable jobs, PostHog for allowlisted product analytics, Sentry plus Vercel for scrubbed operational observability, and Vercel Sensitive Environment Variables with restricted 1Password escrow for secrets. Proof also plans bounded model inference through OpenAI. Selection is not final production approval: regions, contracts, subprocessors, retention, access, and data controls must be reviewed and reflected here before sensitive data is processed. Providers receive only the data needed for their declared purpose.

Analytics

Product analytics is designed around pseudonymous identifiers, counts, versions, buckets, outcomes, cost, and latency. It must not receive raw conversations, prompts, model responses, photos, HealthKit values, calendar content, medication names, diagnoses, or advertising identifiers.

Your choices

Health, calendar, camera, microphone, notifications, and photo-library permissions are optional and revocable in iOS Settings. You may correct what Proof believes, request an export, or request deletion. These support and data-rights paths must remain available after membership lapses and app access locks.

Sale and advertising

Proof does not sell personal information. The product is designed without affiliate incentives touching verdicts or product recommendations.

Contact

Questions or requests: hello@proofwellness.co.