Higher Human / Privacy
Privacy Policy
This policy explains what Higher Human collects, why, and your rights under Irish and EU law (GDPR). It is written for a wellness tracking app. It is not medical advice.
We do not sell your personal data. We do not run advertising SDKs. We do not use your data to track you across other companies’ apps or websites.
1. Who we are
Higher Human is provided by Hugo Matos, an individual based in Ireland, trading as Higher Human (“we”, “us”). For privacy questions, account deletion, and data rights requests, emailsupport@higherhuman.app. Higher Human is not yet commercially released. Before paid launch, the geographic business address and telephone contact required by Irish law will be published here and in our App Store trader information.
Because we are established in Ireland, no separate EU Article 27 representative is required. The Irish Data Protection Commission (DPC) is our competent supervisory authority:dataprotection.ie.
2. The app this covers
This policy covers the Higher Human iOS app, related widgets and Live Activities, and the website at higherhuman.app, including accounts, cloud backup, and the Tribe community features.
3. Information we collect
An email address (or Apple/Google identity) is required to create an account and use signed-in features. If you do not provide it, you cannot sync a climb backup or use Tribe. Guest use without an account is not offered.
Account and identity
- Email address and authentication identifiers when you sign in with Apple, Google, or email OTP (via Supabase Auth).
- Display name and optional avatar you choose for Tribe and profile.
- A unique user ID assigned by our auth provider.
Climb data you create (synced backup)
When you are signed in, we store a backup of the climb data you enter so you can restore it across devices. That can include:
- Fasting sessions and related streak / expedition progress.
- Water intake, weight entries, food logs, moods, field notes, and settings you configure (for example height, age or birth year, goals, companion preferences, contraindication flags you declare).
- Other in-app progress such as badges, challenges, and preferences needed to run the product.
Tribe and photos (user content)
- Posts, comments, reactions, and follows you create in Tribe.
- Optional progress photos and avatars you upload to our storage.
- Reports you submit about other users’ content.
Purchases
Subscriptions and one-time purchases are processed by Apple. We receive entitlement status needed to unlock Premium features. We do not receive or store your full payment card details.
Support
If you email us, we process the content of that message and your email address to respond.
Technical and security logs
Our hosts and auth providers may process technical data needed to run the service securely, such as IP address, timestamps, device or app identifiers, push tokens, and request logs. We do not use that operational data to advertise to you or to track you across other companies’ apps.
What we do not collect via analytics or ads
We do not use a third-party analytics SDK, advertising network, or crash-reporting SDK. We do not request App Tracking Transparency permission for cross-app tracking, because we do not track you that way.
4. HealthKit and on-device health data
If you grant Apple Health access, Higher Human may read or write limited fitness-related data (for example water, weight, and read access used for on-device insights such as sleep, steps, or resting heart rate, depending on what you allow).
- HealthKit-derived analysis for Signals and related features runs on your iPhone.
- That HealthKit sensor data is kept in an on-device ledger. It is not uploaded to our cloud backup and is not used for advertising.
- iOS Health permission is separate from GDPR consent for any health-related data you choose to sync in your climb backup.
- You can revoke Health access anytime in iOS Settings or the Health app.
Body measurements and logs you type into Higher Human yourself (for example weigh-ins you enter in-app) are part of your climb backup if sync is on. That is separate from HealthKit samples we never send to our servers.
5. Why we process data (purposes and legal bases)
- Contract / service delivery (GDPR Art. 6(1)(b)): create your account, sync your climb, run Tribe, unlock purchases you bought, provide support.
- Special-category health data: some fasting records, weight and body data, food logs, moods, progress photos, and declared safety conditions may reveal information about health. GDPR requires both an Article 6 basis and an Article 9 condition before that information is stored in cloud backup.
- Consent for optional device features: camera, photo library, notifications, and HealthKit access are controlled by iOS permission prompts. Those OS permissions are not the same as Art. 9 consent above.
- Legitimate interests (Art. 6(1)(f)): keep the service secure, prevent abuse, moderate Tribe, operate infrastructure logs, and defend legal claims. We balance these against your rights.
- Legal obligation (Art. 6(1)(c)): where law requires retention or disclosure.
Pre-launch consent status: the general Terms acknowledgment, entering data, and granting an iOS permission are not explicit GDPR consent. Before public cloud backup of health-related climb data is enabled, the app will request separate, specific, affirmative consent under GDPR Articles 6(1)(a) and 9(2)(a), record the version and time, and provide an in-app way to withdraw it without closing the account. Public cloud sync of that data must remain disabled until this control is active.
We do not use automated decision-making that produces legal or similarly significant effects about you.
6. Third parties who help us run the app
We use processors and platforms necessary to operate Higher Human. They process data under their own terms and our instructions where they act as processors:
- Supabase: authentication, database, and file storage for accounts, backups, and Tribe content. The production hosting region, processor entity, subprocessors, and transfer safeguard will be verified and identified here before commercial release.
- Apple: Sign in with Apple, App Store billing, HealthKit (on device), and Apple push / Live Activity infrastructure as applicable.
- Google: Google Sign-In if you choose that method.
- Giphy: if you search or insert a GIF, your device may send the search query and standard technical data (such as IP address) to Giphy under Giphy’s terms. We apply PG-oriented filters in-app. Do not use Giphy features if you do not want that processing.
We do not share your personal data with advertisers. We may disclose information if required by law, to protect safety, or to enforce our Terms.
7. International transfers
Our primary operations are in Ireland / the EU. Apple, Google, Giphy, or Supabase (depending on region and subprocessors) may process data outside the EEA/UK. Where personal data leaves the EEA/UK, we rely on appropriate safeguards such as an EU adequacy decision or Standard Contractual Clauses used by the provider. Email support@higherhuman.app if you want details of the safeguards that apply to your account.
8. Retention
- Account and climb backup: kept while your account is active.
- After you delete your account: active account records, climb backups, and Tribe content and media we host for you are deleted or anonymised, except limited records that must be kept for legal, security, tax, or dispute reasons.
- Screenshots or copies others made of your public Tribe posts are outside our control.
- Support emails: kept as long as needed to resolve your request and for ordinary business records (typically up to 24 months unless a longer period is required).
- Security and infrastructure logs: kept for the operational periods set and documented by our providers, then rotated.
Before commercial release, we will verify the account-deletion cascade and publish the actual active-system and disaster-recovery backup deletion periods here. We will not promise a deletion period that the production systems cannot demonstrate.
9. How to access, export, and delete your data
- In the app: Settings → Delete account removes your Higher Human account, hosted Tribe content tied to you, and cloud climb backup from our servers (subject to the retention exceptions above). Settings → Integrations can export a JSON climb backup and an on-device health CSV. Those exports are a convenience for climb/health data you can reach in-app; they may not include every server log or purchase receipt Apple holds. Email us for a fuller access request.
- By email: write to support@higherhuman.app from the address on your account. We may need to verify it is you.
Deleting the app from your phone does not by itself delete your cloud account. Use Delete account or email us.
10. Your GDPR rights
If GDPR applies to you (including users in the EEA/UK and Ireland), you can ask us to:
- Access your personal data
- Correct inaccurate data
- Erase data (subject to legal exceptions)
- Restrict or object to certain processing
- Receive a portable copy of data you provided (where applicable)
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
- Lodge a complaint with the Data Protection Commission or your local supervisory authority
We will respond within the timeframes GDPR requires. Contact support@higherhuman.app.
11. Sale of data
We do not sell your personal data and we do not share it for cross-context behavioural advertising.
12. Children
Higher Human is for adults aged 18 and over only. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, email us and we will delete it.
13. Security
We use technical and organisational measures designed to protect personal data, including encrypted transport (HTTPS/TLS), access controls, and device permissions for sensitive sensors. These measures reduce risk but cannot guarantee absolute security. Keep your device and Apple ID secure.
14. Personal data breaches
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission when GDPR requires it. If the breach is likely to result in a high risk to you, we will also inform affected users when GDPR requires that notice.
15. App Store privacy labels
Apple’s App Privacy nutrition labels on the App Store listing summarize categories we declare for app functionality (for example contact info, user ID, fitness-related climb data, photos, and other user content). Those labels must stay consistent with this policy. HealthKit samples we analyze on-device are described here as not leaving the device.
16. Changes
We may update this policy. The “Last updated” date will change. Material changes may also be noted in the app or on the website. We will notify you before a material change takes effect. If a new purpose requires consent, we will request fresh consent. Continued use is not consent to new health-data processing.
17. Contact
Privacy and data rights: support@higherhuman.app
General: hello@higherhuman.app
Controller: Hugo Matos trading as Higher Human, Ireland
Related: Terms of Use · Support