Annela
Privacy
Last updated 25 September 2026
Annela is a habit and challenge tracker. It holds what you log and very little else. There is no advertising, no analytics, no tracking across other apps or sites, and nothing here is sold or shared with data brokers.
What is stored
Only what you enter, plus what is needed to sign you in.
- Your account — email address, a display name, a profile picture if you add one, and a friend code.
- What you log — challenge days and whether each task was done, workouts and their sets, focus sessions, books and reading progress, day notes and journal entries, and the tasks you plan.
- Health-adjacent measurements — where a challenge asks for them: weight, water, calories, diet adherence, and progress photos. These are stored because you chose a challenge that tracks them, and are covered in more detail below.
- Social — friend connections, posts you write, and comments and reactions you leave.
There is no location tracking, no contacts access, no advertising identifier, and no background collection of any kind. Nothing is recorded while you are not using the app.
Progress photos and body data
Progress photos are private by default. They are kept in private storage and reached through short-lived signed links, not public URLs, so a photo is not viewable by anyone who happens to have an address.
A photo becomes visible to other people in a challenge only if you turn sharing on — either for that challenge or for the individual photo. A shared challenge shows co-participants what you logged for the days you shared; it never exposes anything from outside that challenge.
Weight, water and calorie entries follow the same rule as everything else: yours, unless you are in a shared challenge that tracks that measurement and you have chosen to share it.
Apple Health and Health Connect
Annela can read a few figures from Apple Health on iPhone and Health Connect on Android, so a challenge that counts steps or workouts does not have to be typed in by hand. This is off until you turn it on, it is asked for one data type at a time, and the app works without it.
What is read. Steps, walking and cycling distance, active energy, exercise sessions, mindful minutes, hydration, body weight, and heart rate during a workout you are recording. Nothing else — not sleep, not location, not clinical records, not anything about medication or conditions, and no heart rate outside a workout.
Heart rate specifically. It is read only for the span of a workout, and only if you wear something that measures it — an Apple Watch, or a chest strap. Your phone has no heart-rate sensor, so without one of those there is nothing to read. The readings are thinned to one every five seconds, stored against that workout, and used to show you the average, the peak and the line between them. They are not used to infer anything about your health, and they are deleted with the workout.
What is written. The workouts and the weights you log here, so they count in the rest of your health data too. Nothing is written that you did not enter.
Where it goes. A figure read from Health is stored in your account the same way a typed one is, alongside a note of which app recorded it and whether the platform reported it as recorded automatically or entered by a person. That note exists so a shared leaderboard can tell a watch reading from a hand-typed number; it is shown to you and, on a challenge you have joined, to the people in it.
What it is never used for. Health data is not used for advertising, not sold, not shared with data brokers, and not shared with anyone outside the service providers listed below. It is not used to build a profile of you for any purpose other than showing you your own progress and your standing in challenges you chose to join.
Turning it off. Revoke the permission in iOS Settings → Health → Annela, or in Health Connect on Android, and reading stops immediately. Figures already saved to your account stay until you delete them — see below — because they are part of the days and challenges you logged.
Who else is involved
These service providers, and no one else. Each processes data on our behalf under its own terms, and none is permitted to use it for anything else:
- Supabase — the database, the file storage and sign-in. Everything you log lives here.
- Vercel — serves this website.
- Expo — delivers push notifications. To send one to your phone we give Expo a device token and the text of the notification. Turn notifications off and nothing is sent.
- RevenueCat — keeps track of Pro subscriptions. If you buy Pro, Apple takes the payment; we never see your card, and neither does RevenueCat. RevenueCat receives the purchase record Apple issues, together with your account's ID in this app, so it can tell us whether your subscription is active. If you never buy Pro, it holds nothing about you.
- Anthropic — would process text you typed if you used an AI feature. No feature in the app currently uses it; the capability is built and not switched on. It is named here so this list is true before it is, rather than after.
If you sign in with Google, Google confirms your identity to us and we receive your email address and name. We do not receive your password and we do not get access to any other Google service.
Share links are the one thing you can make public. Opening a share link shows the day or challenge you chose to share, to anyone with the link. That is the purpose of the link, and it holds only what the card shows.
Why we are allowed to hold it
Under UK and EU data protection law every use of your data needs a lawful basis. Ours:
- To provide the service (performance of a contract) — your account, what you log, your challenges, and anything you share with people you connect to. Without this there is no app.
- Because you asked (consent) — reading from Apple Health, push notifications, and progress photos. Each is off until you switch it on, and switching it off withdraws it.
- To keep it working and safe (legitimate interests) — sign-in security, abuse reports, and stopping people gaming a public leaderboard. Weighed against your interests, and limited to what that needs.
Health and fitness data gets extra protection in the UK and EU. We rely on your explicit consent for it, which is what the Health permission prompt is asking for — and you can withdraw it in Settings or in iOS at any time.
Who is responsible
Shubham Raghav is the data controller. Write to 1037/29B, Gali no. 10, Krishna Colony, Sector 7 Extension, Gurgaon, Haryana 122001, India, or support@annela.app.
You can complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority. We would rather you told us first.
Getting your data out, and deleting it
Export. Settings → Your data writes everything you have logged to a single readable JSON file. It leaves out other people’s words.
Deletion. Settings → Delete account removes your profile and everything attached to it — every challenge day, workout, focus session, note, book, photo, friendship and post — along with your sign-in. It happens immediately and it is not recoverable. There is no waiting period and nothing to email anyone about.
Two things survive deletion, and neither identifies you: posts you wrote inside a shared challenge are removed, but another person’s record that they completed their own day is theirs and stays. And if someone joined through your invite, the fact that they joined remains on their account with the link to you removed.
Backups are kept by our database provider for a short period for disaster recovery and are overwritten on their own schedule.
Children
Annela is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and it will be removed.
Changes
If this policy changes in a way that affects what is collected or who it is shared with, the date at the top changes and the change is described here. This document lives in the app’s source repository and is updated in the same change as the code it describes.
Contact
Questions about any of this, or a request about your data, go to support@annela.app.