WELLlife Care Privacy Policy

Effective date: September 27, 2026  ·  Last updated: September 27, 2026

1. Who we are

WELLlife Care ("WELLlife Care", "we", "us", "our") is a consumer health-tracking mobile application operated by Wondfo USA Co., Ltd. Questions about this policy or your data: appadmin@wondfousa.com. Our mailing address is available on request.

The Service is offered for use in the United States and Canada. Canadian users: see Section 9.4.

Washington, Nevada, and other residents: our separate Consumer Health Data Privacy Policy is available at https://welllifebio.com/pages/consumer-health-data-policy and in the app.

2. What WELLlife Care is — and is not

WELLlife Care helps you log symptoms, how you feel, temperature, SpO₂, heart rate, blood pressure, blood glucose, medications, notes, and the results of rapid tests you read yourself; keep optional photos of test strips; follow a recovery "Journey"; read public-health information from the CDC; and produce a personal report you can choose to share.

WELLlife Care is not:

  • a medical device, a diagnostic tool, or a substitute for the instructions for use (IFU) of any rapid test;
  • an FDA-cleared or FDA-authorized companion app to any rapid test (the app does not read, scan, or analyze strip photos);
  • a HIPAA covered entity or business associate (see Section 8);
  • an emergency, 911, or real-time monitoring service.

Our AI assistant, Nina, gives general information only and does not provide medical advice.

3. Information we collect

3.1 Information you give us

Category What it includes When
Account Email address, password (handled by Amazon Cognito — we never receive your plaintext password), optional display name Registration, profile changes
Sign in with Apple / Google (optional) The identity token from Apple or Google, from which we take your verified email address and, if provided, your name When you choose that sign-in option
Health records Symptoms, how you feel, temperature, SpO₂, heart rate, blood pressure, blood glucose, medications, notes, dates, Journey type (e.g., COVID-19, flu, cold, allergies) and recovery status Each time you log
Rapid-test entries Test type, the result you entered, the line appearance you chose, date When you log a test
Strip photos (optional) A photo you take or pick of a test strip, kept as your personal record only When you add a photo
Family profiles Name, initial, color, chosen avatar, and optional profile photo for people you add, and the health records you log for them (see Section 10) When you add a family member
Nina chat The messages you type to Nina and Nina's replies (see Section 5) When you use Nina
Daily Care Log (optional) The name you enter, your account email, your chosen care contact's email address, whether the contact approved, and the time you last tapped "I'm OK today" When you turn on Daily Care Log
Support messages Your message, your account email, and an optional different reply-to email When you use "Contact support"
Feedback survey (optional) Anything you type into our feedback survey, which is hosted by Tally (see Section 6) When you open the survey

3.2 Information collected automatically

  • Screen-time statistics. While you are signed in, the app counts, per day, which main screens you open (for example Home, History, Nina chat, Report) and how many seconds you actively spend on each (idle time is excluded). It never records what you type or log. Counts are kept on your device for up to 7 days and sent to our server in small batches whether or not Cloud Sync is on. On the server they are added into daily totals per screen. To count each person only once per screen per day, we also keep a daily code computed from your account ID and the date. It does not contain your name or email, but because it is derived from your account ID it can be matched back to your account; we use it only to count distinct users and delete it after 60 days.
  • Technical data. A random device identifier generated by the app, which is sent with requests to our Daily Care Log, support, statistics and account-deletion services and is stored only with Cloud Sync and Daily Care Log records; your time zone (stored with Cloud Sync and Daily Care Log); and the app version and operating-system version (added to the feedback-survey link). Our service providers process your IP address and standard request information to deliver each request; our sign-up email service uses a one-way code derived from your IP address for short-term rate limiting.
  • Security and service logs. Sign-in events handled by Amazon Cognito; technical logs from our servers (for example request time, request size, error type, and your account's internal identifier — not the text of your health records or chat messages); and a record of every time an authorized staff member views account or health data (see Section 7).

We do not use advertising SDKs, analytics SDKs, crash-reporting SDKs, cross-app tracking, session replay, or behavioral profiling.

3.3 What stays on your device and what goes to the cloud

Cloud Sync is off by default. With Cloud Sync off, your health records, test entries, strip photos, family profiles, and Nina chat history are stored on your device and are not uploaded to our servers — with one exception that you control: if you choose to use Nina's AI replies (Nina asks you first), your message and a short summary of the journey you are viewing are sent to our third-party AI service provider through our chat server to write the reply (Section 5).

If you turn Cloud Sync on (you are asked to agree first), we store a copy of your health records, test entries, family profiles, and strip photos with your account so they can be restored on your other devices. We also store your Cloud Sync choice, when you made it, your time zone, and the app's device identifier. Profile photos you add for yourself or family members stay on the device. You can turn Cloud Sync off at any time and choose to keep or delete the cloud copy. Turning Cloud Sync off, or deleting the cloud copy, stops syncing on all of your devices; to sync a device again, turn Cloud Sync back on from that device.

Some features always use our servers, whether or not Cloud Sync is on: your account, Nina (Section 5), Daily Care Log, Contact support, screen-time statistics, and system notices.

Nina chat history is kept on your device only; it is not stored on our servers. Reminders (check-in and retest reminders) are scheduled as local notifications on your device; no push-notification service is used.

3.4 Information we do not collect

  • Precise or approximate location (state-level CDC maps use public data only)
  • Contacts, calendar, or microphone
  • Your photo library, except a photo you pick
  • Government identifiers
  • Payment card information (the app is free)

4. How we use your information

  1. Provide the app: sign-in, logging, Journeys, reminders, reports, family profiles, and — if you turn it on — Cloud Sync.
  2. Answer your questions through Nina (Section 5).
  3. Send Daily Care Log emails to the care contact you chose and approved.
  4. Respond to support messages.
  5. Send essential account emails (verification codes, password reset, and a notice if you try to sign up with an email that already has an account). We do not send marketing email.
  6. Understand which screens are used, in aggregate, to improve the app.
  7. Keep the Service secure, prevent abuse, and meet legal obligations.

Public-health features (CDC news, respiratory-illness maps) download public data only; they do not send your personal data to the CDC.

We do not sell your personal information, use it for targeted advertising, or use your health data, photos, or chat messages to profile you.

5. Nina, the AI assistant

  • Your permission first. The first time you chat, Nina explains in the chat what is sent and asks you to tap OK, let's chat. Nothing is sent to the AI service before you do. If you choose "Not now" (or later turn it off in Profile → Privacy & data), Nina's AI replies are unavailable; built-in quick answers (maps, CDC news, games, how-to) keep working because they run on your device.
  • Who processes it. Your message goes, over an encrypted connection, to our chat server on Amazon Web Services (us-west-2), which forwards it to a third-party AI service provider to generate a reply using a model configured for Wondfo.
  • What is sent. Your recent messages and Nina's replies; a short (500-character maximum) summary of your earlier conversation, which is itself created by the same AI service from those older messages; and a short summary of the Journey you are viewing — whether it is yours or a family member's (never their name), the illness type, recovery day, your latest logged feeling, symptoms, and strip appearance, and recovery status. Before sending, the app replaces email addresses, phone numbers, street addresses, dates, and Social-Security-style numbers in your messages with placeholders when it detects them. Detection is automatic and can miss things, and names are not reliably removed, so please leave names and other identifying details out of your messages. Requests are identified only by your account's internal identifier, not your email. Strip photos are never sent to Nina.
  • Emergencies. Nina is not an emergency service. When a message looks like a crisis or medical emergency, the app shows fixed guidance (988 and 911) instead of an AI reply; this check can miss some wording, so if you are in danger, call 911 or call or text 988 directly.
  • Reporting replies. Each AI reply has a Report option that opens a support message quoting the reply.
  • Jokes. When Nina fetches a light-hearted joke, the request contains no personal data.
  • What we keep. Our chat server does not store the text of your messages or Nina's replies. It logs technical metadata (request ID, internal account identifier, number of messages, timing). Our AI service provider may retain request data for up to 30 days for abuse monitoring and, under its API terms, does not use it to train its models. We do not use your chat messages to train or fine-tune AI models.
  • Earlier beta. An earlier beta version of the chat server saved chat transcripts in Amazon S3. To have any remaining beta transcripts deleted, contact us (Section 14).
  • Nina's answers can be wrong. Do not rely on them for medical decisions.

6. Service providers and other recipients

We use the following service providers to run the Service. They process your information on our behalf and under our instructions.

Provider What they do Data involved
Amazon Web Services — Cognito, AppSync, DynamoDB, S3, Lambda, API Gateway, SES, CloudWatch (region us-west-2, Oregon, USA) Accounts and sign-in; Cloud Sync storage; Daily Care Log, support, and screen-time servers; the Nina chat server; sending email; logs Everything stored or processed in the cloud as described in this policy
AI service provider (third-party large-language-model API) Generating Nina's replies The content described in Section 5
Apple / Google Sign in with Apple / Google, only if you choose it Your sign-in with them; they give us your email and name

Other third parties you may interact with:

  • Care contact (Daily Care Log). Only if you turn it on and your contact approves with a one-time code: we email them an invitation, and later a note if you have not tapped "I'm OK today" for 36 hours (and a second note 24 hours after that). Notes contain your name, that you have not checked in with WELLlife, and your last check-in time — no health records. Your contact can unsubscribe from any note.
  • Tally (tally.so) hosts our optional feedback survey. It opens in your browser with the app version and OS version attached; anything you submit is handled under Tally's privacy policy.
  • YouTube. The test-kit instruction video is embedded from youtube-nocookie.com with a thumbnail from img.youtube.com; playing it connects you to Google/YouTube under their policies.
  • Public data sources and code libraries. The app downloads public data from the CDC (data.cdc.gov, cdc.gov, tools.cdc.gov) and map data and code libraries from cdn.jsdelivr.net and cdnjs.cloudflare.com. These requests include only your IP address and standard request information — no personal data.
  • Shopping links. Links to welllifebio.com, Amazon, or Walmart open outside the app and are governed by those sites' policies.
  • Legal and safety. We may disclose information when required by valid legal process, to protect rights and safety, or in a merger or acquisition (the recipient must honor this policy).

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not disclose your health data to employers, schools, insurers, or health-care providers; sharing a report is something you do yourself, outside the app.

7. Where your data is stored and how it is protected

  • Cloud data is stored with Amazon Web Services in us-west-2 (Oregon, USA).
  • Canadian users: your information is stored and processed in the United States, where it may be accessible to courts, law-enforcement and national-security authorities under U.S. law.
  • All network traffic is encrypted in transit (HTTPS/TLS). Cloud data is encrypted at rest by AWS.
  • Cloud Sync records can be read only by your signed-in account; photos are stored in a private storage path tied to your sign-in identity.
  • Staff access. A small number of authorized staff can use an admin console that requires membership in an admin group and an authenticator-app (TOTP) second factor. Viewing a person's cloud health records requires entering a reason, and every view is recorded in an audit log.
  • No system is perfectly secure. If a breach of your health information occurs, we will notify you, the U.S. Federal Trade Commission as required by the FTC Health Breach Notification Rule (16 CFR Part 318), and any applicable state authorities within the timeframes those rules require.

8. HIPAA status

WELLlife Care is a consumer app: you install it, enter your own data, and decide whether to share any report. We are not a HIPAA covered entity or business associate, and HIPAA does not apply to the information you store in the app. Consumer-health-privacy laws, including those described in Section 9 and the FTC Health Breach Notification Rule, do apply.

9. Your rights and choices

In the app you can:

  • Export your records as a JSON file (Profile → Privacy & data → Export my data);
  • Correct or delete individual records, family profiles, or your name and email;
  • turn Cloud Sync off, with or without deleting the cloud copy;
  • turn Daily Care Log off;
  • turn Nina's AI replies off (Profile → Privacy & data → AI assistant);
  • Delete my data — delete health records, test history, photos, family profiles, and Nina chat history from the device and Cloud Sync while keeping your account;
  • Delete account — delete your account and the data described in Section 11;
  • manage camera, photo, and notification permissions in your device settings.

By email, you can ask us to confirm what we hold, give you a copy, correct it, delete it, or withdraw consent: write to appadmin@wondfousa.com from the email on your account. We may need to verify your identity. We respond within the time the law requires (for example, 45 days under California law, extendable once by 45 days). You will not be treated differently for exercising your rights.

9.1 California residents (CCPA / CPRA)

In the past 12 months we collected the categories in Section 3: identifiers (email, name, internal account and device identifiers, IP address); sensitive personal information (health information, account log-in); internet or other electronic activity (screen-time statistics); and photos. Sources: you, your device, and Apple or Google if you use their sign-in. We use them for the purposes in Section 4 and disclose them only to the recipients in Section 6. We do not sell or share personal information, and we use sensitive personal information only to provide the Service you request, so the right to limit does not require additional action. Retention is described in Section 11. You may use an authorized agent; we may ask you to confirm the request directly.

9.2 Washington, Nevada, and Connecticut consumer health data

Our separate Consumer Health Data Privacy Policy (https://welllifebio.com/pages/consumer-health-data-policy) explains the consumer health data we collect and share and how to exercise your rights under the Washington My Health My Data Act (RCW 19.373) and similar laws, including the right to appeal. We do not use geofencing.

9.3 Other states

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have similar rights, including an appeal of our decision by replying to it. Use appadmin@wondfousa.com for all requests.

9.4 Canadian residents (PIPEDA and Québec)

We handle personal information of users in Canada in line with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Québec residents, the Act respecting the protection of personal information in the private sector (Law 25).

  • Person in charge of privacy: Privacy Officer, Wondfo USA Co., Ltd. — appadmin@wondfousa.com.
  • Consent. We collect health information only with your express consent, given when you create an account and enter it, and when you turn on Cloud Sync or Nina's AI replies. You can withdraw consent at any time (Section 9), subject to legal or contractual limits; some features will then stop working.
  • Access and correction. You can ask to see the personal information we hold about you, how we used it and to whom we disclosed it, and ask us to correct it. We respond within 30 days.
  • Québec residents may also ask for a copy of their computerized personal information in a structured, commonly used format (Profile → Privacy & data → Export my data provides this), and ask us to stop disseminating it.
  • Transfers outside Canada and Québec. Your information is stored in the United States by our service providers (Section 6) under contracts that require them to protect it. Before transferring it, we assessed that it will receive adequate protection.
  • Incidents. If a confidentiality incident creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada and, for Québec residents, the Commission d'accès à l'information du Québec.
  • Complaints. Contact us first. You may also complain to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or, in Québec, the Commission d'accès à l'information (https://www.cai.gouv.qc.ca).

10. Children and family members

You must be 18 or older to create an account. The app is not directed to children, and we do not knowingly allow children to register.

A parent or legal guardian may add a child or other family member as a family profile and log that person's health information. By doing so, you confirm you have the authority to record and manage that information. Family-profile data is stored as part of your account, under your control: it stays on your device unless you turn on Cloud Sync, and you can delete a family profile at any time. If you believe a child has created an account, contact us and we will delete it.

11. Retention and deletion

Data How long we keep it
Records, photos, family profiles on your device Until you delete them, use Delete my data or Delete account, or uninstall the app
Nina chat history On your device only, until you delete it. Not stored on our servers
Cloud Sync copy Until you delete it (turn off Cloud Sync and delete the cloud copy, Delete my data, or Delete account)
Account (email, name) Until you delete your account
Daily Care Log Contact details are removed when you turn it off or your contact unsubscribes; the rest is deleted with your account
Support messages Until your account is deleted
Screen-time statistics On device up to 7 days; the daily account-derived code up to 60 days; daily totals per screen that do not identify you may be kept indefinitely
Staff-access audit log 12 months
Email-delivery bounce/complaint logs (no addresses) 3 months
Server technical logs For a limited period needed to operate and secure the Service
Backups Where our database backups (point-in-time recovery) are enabled, deleted records may remain in backups for up to 35 days
Anonymous account-deletion statistics (date of deletion and account age only) Indefinitely; they do not identify you

What Delete account removes: your Cloud Sync records and photos, your Cloud Sync settings, and — if you used Sign in with Apple — the app's authorization with Apple (we revoke it before deleting your account), your Daily Care Log record, your support messages stored in our database, any chat server files stored under your account, the data on this device, and your sign-in account. It does not remove the non-identifying or time-limited items above, and it cannot recall reports or exports you already shared outside the app.

What Delete my data removes: your records, test history, photos, family profiles, and Nina chat history from the device and Cloud Sync, and turns off Daily Care Log. Your account, email, password, and app settings remain.

You can also request deletion at https://welllifebio.com/pages/app-delete-data or by emailing appadmin@wondfousa.com with the subject "Data Deletion Request".

12. Device backups, other sites, and use outside the U.S.

  • Device backups. On Android, WELLlife Care data is not included in Google cloud backups; it can move to a new phone only through a direct device-to-device transfer that you start. On iOS, your device's own backup (iCloud or computer) may include app data according to your device settings. If you want your records available after losing a device, use Cloud Sync.
  • Other sites. Links to CDC, YouTube, Tally, or shopping sites are governed by those sites' privacy policies.
  • Outside the U.S. If you use the app outside the United States (including in Canada), your information is transferred to and processed in the United States. See Section 9.4.

13. Changes to this policy

We will update the "Last updated" date when this policy changes. For material changes, we will notify you in the app before they take effect and, where the law requires, ask for your consent again.

14. Contact

  • Email: appadmin@wondfousa.com
  • Deletion requests: https://welllifebio.com/pages/app-delete-data
  • Person in charge of privacy (Canada): Privacy Officer, Wondfo USA Co., Ltd. — appadmin@wondfousa.com
  • Mail: Wondfo USA Co., Ltd. — mailing address available on request.