Skip to main content
← Back to SoliVana

Legal

Privacy Policy

Effective April 30, 2026

SoliVana ("we," "us," "our") operates SoliVana OS — a wellness platform that helps members track, train, earn, and reset across in-person therapies and connected health devices. This policy explains what we collect, how we use it, and the choices you have. We wrote it to be read, not to hide behind. If anything here is unclear, email info@solivana.com.

1. What we collect

  • Account data — name, email, optional phone, referral code, role.
  • Wellness activity — sessions you book and complete at SoliVana, protocol completions, points and rewards, journey progression.
  • Connected device data — when you authorize an integration (Oura, Apple Health, Whoop, Withings, Garmin, Ultrahuman, CGM, etc.) we receive metrics such as HRV, sleep duration and quality, resting heart rate, recovery score, workouts, body composition, glucose, and activity. We only request the scopes needed for the features you use.
  • Photos — only the before/after progress photos you choose to upload.
  • Technical data — IP address, user agent, device type, request timestamps, used to keep the service secure and debuggable.

We do not sell your data, share it with advertisers, or use it to train third-party AI models.

2. How we use it

  • Personalize your wellness journey, protocol recommendations, and SoliVana Score.
  • Award points, unlock tier benefits, and track streaks.
  • Deliver in-person session reminders and post-visit follow-ups.
  • Operate, secure, and improve the service.
  • Comply with law and respond to lawful requests.

3. Connected devices

Device integrations are opt-in. You authorize each provider individually via OAuth, and you can disconnect any provider from your dashboard at any time. When you disconnect, we stop pulling new data and delete your stored metrics from that provider within 30 days. Data we receive from device providers is governed by the provider's own terms in addition to this policy.

4. Health information

SoliVana is a wellness platform, not a HIPAA-covered entity, and the metrics we display are not medical advice. We treat health and biometric data with the same standard of care HIPAA-covered entities apply: encrypted in transit and at rest, access-controlled, and never shared with third parties without your consent or a legal obligation.

5. Sharing

We share data only with:

  • Service providers we depend on to run the platform — hosting (Railway, Vercel), email delivery (Resend), payments (Stripe), CRM (GoHighLevel). Each is contractually required to protect your data.
  • Device providers you authorize — only the data each provider asks for to maintain your connection.
  • Authorities when required by valid legal process.

6. Your rights

You can access, correct, export, or delete your account and its data at any time. Email info@solivana.com and we'll act within 30 days. Members in California, Colorado, the EU/UK, and other regions with comprehensive privacy laws have the additional rights granted by their local laws and we honor those rights regardless of where you live.

7. Retention

We keep account data for as long as your account is active. Device metrics older than 24 months are aggregated or removed. When you delete your account, we delete personal data within 30 days, except records we are legally required to retain (e.g., transaction logs).

8. Security

All traffic uses TLS. Passwords (when used) are hashed with bcrypt at cost 12. Magic-link tokens are single-use, expire in 15 minutes, and stored only as SHA-256 hashes. Database backups are encrypted. We require multi-factor authentication on all administrative accounts.

9. Children

SoliVana is intended for adults. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, email info@solivana.com and we'll remove it.

10. Changes

When we make material changes to this policy, we'll post the new effective date at the top and email account holders. Continued use after the effective date means you accept the updated policy.

11. Contact

SoliVana — questions about this policy or your data: info@solivana.com.