Privacy

Privacy Policy

Effective date: May 1, 2026

This Privacy Policy describes how Hobbes Health (“Hobbes”, “we”, “us”, or “our”) collects, uses, and shares information when you use the Hobbes mobile application and related services (the “Service”). It also explains the choices you have about your information and the third-party providers we rely on to deliver the Service.

By using Hobbes, you agree to the collection and use of information in accordance with this Privacy Policy. If you are using Hobbes from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, please also read Section 13 for the additional information that applies to you.

1. Information we collect

We collect the following categories of information:

Account information

  • Email address, first name, and last name
  • Authentication identifiers from Sign in with Apple or Sign in with Google (a unique user ID and, where you allow it, your email and name)
  • Password (stored only as a salted hash; we never see your plaintext password)

Health and nutrition information you provide

  • Meals and food items you log
  • Photos of meals you upload
  • Voice recordings of meal descriptions and conversations with our AI coach
  • Habits, goals, dietary preferences, allergies, and other profile attributes
  • Messages you send to our AI coach

This information includes data concerning your health, which is a special category of personal data under the GDPR and UK GDPR. See Section 13.3 for how we handle it.

Subscription information

  • Subscription tier, purchase history, and entitlements (managed via RevenueCat — see Section 5)
  • We do not receive your payment card or bank details. Apple and Google process your payment.

Device and diagnostic information

  • Device type, operating system, app version, language, and time zone
  • IP address (collected automatically when your device connects to our servers)
  • Crash logs, error reports, and breadcrumbs of in-app actions captured for diagnostic purposes (via Sentry — see Section 5)
  • Push notification tokens issued by Apple or Google
  • Mobile advertising identifier (Android Advertising ID on Android; Apple IDFA only if you grant App Tracking Transparency permission on iOS). Used by our subscription provider to attribute purchases and prevent fraud.
  • App install identifier — a per-install UUID generated by the Expo Updates framework so we can target over-the-air bug fixes to the correct app version.
  • Subscription user identifier — a stable, opaque identifier assigned by RevenueCat to link your subscription state across reinstalls.

Health and fitness data from your device

If you choose to connect Hobbes to Apple Health (iOS) or Health Connect (Android), we read the following, and only the categories you approve on the permission screen:
- Steps
- Active energy burned
- Total energy burned
- Sleep duration
- Exercise sessions (type, duration, and count)
- Body weight measurements

Connecting is entirely optional. Hobbes works fully without it, and you can disconnect at any time from Settings → Health.

When you first connect, we read up to the previous 30 days of this data so your history isn't empty on day one. After that, we read new data when you open the app. Hobbes does not read your health data in the background or while the app is closed.

We also write data back to Apple Health or Health Connect — specifically, the meals and weights you log in Hobbes — so your other apps stay in sync. We only write what you entered in Hobbes. Weight readings that Hobbes itself wrote are filtered out when we read, so they never appear twice.

Information we do not collect

  • We do not use third-party advertising or cross-app attribution SDKs, and we do not embed Google Analytics, Mixpanel, Facebook SDK, AppsFlyer, or Branch. We use PostHog for first-party product analytics only; we do not use it for advertising.
  • We do not sell your personal information.

2. How we use your information

We use the information we collect to:

  • Provide and operate the Service (account creation, sign-in, syncing your data across devices)
  • Run the AI features described in Section 3 (meal logging, coaching, nutrition Q&A, voice conversations)
  • Understand how the Service is used, measure feature adoption and retention, and improve the product (product analytics).
  • Send transactional emails such as one-time verification codes and support replies
  • Send push notifications you have opted into (e.g., meal reminders)
  • Diagnose crashes and errors and improve reliability
  • Process subscriptions and manage entitlements
  • Comply with legal obligations and enforce our Terms of Service

If you are in the EEA, UK, or Switzerland, the lawful bases on which we rely for each of these activities are set out in Section 13.2.

Product usage information

When you use the app, we record structured events about how you interact with features. For example that a meal was logged (and whether by text, photo, or voice), a habit was checked in, the paywall was viewed, or a subscription was started, along with standard technical context (device type, operating system, app version, language, time zone, and IP address, which our analytics provider uses to approximate coarse location).

These events are tied to a pseudonymous identifier derived from your account ID (a one-way keyed hash), not to your name or email. They contain only structured categories and counts. They do not include the content of your meals, photos, voice recordings, messages to the AI coach, or any free-text you enter. We do not record your screen. We record technical performance metadata about our AI features (model used, response time, token counts, and estimated cost). We do not record the content of your prompts and the AI's responses.

3. AI processing

Hobbes is built around AI features. Hobbes uses third-party AI services to power core features including meal logging from text/photo/voice, the in-app AI coach, and voice conversations. By using these features, you consent to your inputs being transmitted to the providers listed below for the sole purpose of generating a response to you.

Google Gemini (via Google Vertex AI). We use Google’s Gemini family of large language models — accessed through Google Vertex AI — to:

  • Understand text and voice messages you send to the AI coach
  • Recognize foods and estimate nutrition from photos you upload
  • Generate coaching responses, meal-logging confirmations, and nutrition guidance

If you connect Apple Health or Health Connect, Hobbes can show a short daily insight on your home screen — a plain-language sentence about your activity, sleep, or weight trend. To write that sentence, we send the specific figures it refers to (for example: your step count, sleep duration, workout count and length, or change in weight) to Google Vertex AI. We do not send your raw health records, your meal history, or anything that identifies you.

This is off unless you turn it on. It requires both your general consent to AI features and a separate consent for health insights, which you give when connecting and can withdraw at any time. If either consent is off, Hobbes writes the same insight itself using a fixed template, and no health data is sent to Google.

When you use these features, the relevant input is sent to Google Vertex AI for processing. This may include the text you type, voice transcripts, food photos, your dietary preferences and goals, your meal history, and prior messages from the same conversation, where these are needed to produce a response.

We use Google Vertex AI under terms that prohibit Google from using your data to train Google’s foundation models. Google may temporarily process and log requests for abuse prevention and service operation under its own terms.

Google Vertex AI — text embeddings and Discovery Engine. We generate numeric vector embeddings of your meal history and stored notes so we can retrieve relevant context when answering your questions. The text used to generate these embeddings is sent to Vertex AI under the same training-opt-out terms.

Tavily. When you ask a health or nutrition question that benefits from up-to-date information, we may send a sanitized version of your query to Tavily, a web search provider, and use the returned web results to ground the AI’s response. We do not send your account identifiers to Tavily.

The AI coach offers suggestions and information; it is not a medical professional, and its responses do not produce legal or similarly significant effects on you. See Section 13.8 for our position on automated decision-making.

4. Voice processing

Voice features are delivered through a real-time pipeline made up of several providers. Here is what happens when you speak to the AI coach:

  1. LiveKit transports your voice from your device to our backend over an encrypted WebRTC connection. LiveKit sees the audio stream, your user ID, your display name, and room/session metadata. Audio is streamed in real time and is not retained by Hobbes after the session ends.
  2. Deepgram receives the audio stream and converts it to text (speech-to-text).
  3. The resulting transcript is sent to Google Gemini (see Section 3) to understand what you said and decide how to respond.
  4. The assistant’s reply is converted to audio by either ElevenLabs or Google Cloud Text-to-Speech, depending on the configuration in effect, and streamed back to your device through LiveKit.

What is and isn’t retained from voice sessions:

  • Raw audio: not retained. Audio is processed in real time and discarded.
  • Voice exchanges in your chat history: the text of what you said (after speech-to-text) and what the assistant replied is saved into your chat history alongside text chat, under the same retention rules described in Section 9.
  • Quality-monitoring sample: approximately 1% of user voice transcripts are randomly sampled and retained for up to 7 days so that we can review accuracy and improve the system. These samples are automatically deleted after 7 days.

We do not use your voice for biometric identification or voice-print recognition.

5. Third-party services we use

We rely on the third parties listed below to operate the Service. Each only receives the data it needs for its function. Where data is described as 'shared,' it leaves Hobbes' systems and is processed under the provider's own privacy policy. We recommend reviewing each provider’s own privacy policy.

Provider Purpose Data they receive
Google Vertex AI / Gemini AI model for chat, photo, and voice understanding Messages, voice transcripts, food photos, profile, health insights, and meal context. Data is processed under Google Cloud's Data Processing Addendum; not used to train Google's models.
Google Vertex AI (Embeddings, Discovery Engine) Semantic search over your meal history Meal text and stored notes
Tavily Web search for health Q&A grounding Sanitized search queries
LiveKit Real-time voice transport (WebRTC) Voice audio, user ID, display name, session metadata
Deepgram Speech-to-text for voice Voice audio
ElevenLabs Text-to-speech for assistant replies Assistant reply text
Google Cloud Speech-to-Text / Text-to-Speech Alternative speech-to-text and text-to-speech Voice audio (STT) or assistant reply text (TTS)
Google Cloud Storage Storage of meal photos and voice-related media Photos and audio files you upload
Sign in with Apple Authentication Apple user ID, email (real or relay)
Sign in with Google Authentication Google account ID, OAuth tokens
SendGrid (Twilio) Transactional email delivery Email address, message contents (OTP codes, support replies)
Expo Push Notifications (delivered via Apple APNs and Google FCM) Push notification delivery Device push token, notification payload
RevenueCat Subscription management Android Advertising ID, RevenueCat App User ID, app build, OS version, country, subscription status, purchase history
Apple App Store / Google Play Billing Payment processing Whatever Apple or Google needs to process the purchase. We never see your payment details.
Sentry Crash and error reporting Stack traces, app version, device info, user ID, breadcrumbs of in-app actions
fatsecret Nutrition lookup for foods you log Generic food queries (names, serving). No account or personally identifying information.
Posthog Product analytics Structured events related to product interaction. No account or personally identifying information.

These providers act as our processors (or, where applicable, joint or independent controllers — for example, Apple and Google for sign-in and payments). Where a provider acts as our processor, they are contractually required to provide privacy and security protections equivalent to those described in this Privacy Policy, to use your data solely to deliver the contracted service to Hobbes, and not to retain it beyond what is necessary, sell it, or use it for their own purposes (including training their own models on it). Where a provider acts as an independent controller (e.g., Apple, Google, Stripe), their own privacy policies govern that processing; we link to them in the table above. Most are based in the United States; see Section 11 for how we lawfully transfer data outside the EEA/UK.

6.Advertising and tracking

Hobbes does not show ads. We do not sell your personal information, and we do not use any advertising, analytics, or attribution SDK that profiles you across other apps or websites.

The only place a mobile advertising identifier is read is by RevenueCat, our subscription provider. On Android, RevenueCat reads the Android Advertising ID to attribute App Store purchases to the correct install and to detect fraudulent refund patterns. On iOS, RevenueCat reads the Apple IDFA only if you have granted App Tracking Transparency permission — by default, no IDFA is collected. In neither case is the identifier used to show you ads inside Hobbes or to build a marketing profile of you outside Hobbes.

Specifically, Hobbes does not integrate:

  • Google Analytics, Firebase Analytics, or any third-party usage-analytics SDK
  • The Meta (Facebook), TikTok, Snap, or Pinterest SDKs, or any social pixel
  • Any advertising network or third-party attribution provider beyond RevenueCat
  • Any cross-app or cross-device tracking of any kind

If you would prefer that no advertising identifier reach RevenueCat at all, you can disable or reset your device's advertising identifier from your operating system's privacy settings. Apple and Google both document the current steps for iOS and Android respectively. Your subscription will continue to work normally if you opt out; RevenueCat will simply fall back to an internal install identifier for purchase attribution.

7. Authentication

When you sign in with Apple or Google, Hobbes receives an identity token verifying who you are along with your email address (or a private relay address, in the case of Apple) and, where you allow it, your name. We do not receive your Apple or Google password.

8. Storage

Meal photos, voice-related media, and other files you upload are stored in Google Cloud Storage in buckets owned and controlled by Hobbes. Uploads use signed URLs scoped to your account and expire after a short window.

Your structured data (account, meals, habits, chat history, memory, etc.) is stored in a PostgreSQL database operated by Hobbes. Short-lived caches and queue state are stored in Redis operated by Hobbes.

9. Diagnostics and error reporting

We use Sentry to capture crash reports and unhandled errors. A Sentry report can include the error stack trace, app version, device information, your user ID, and a recent trail of in-app actions (“breadcrumbs”). We use this only to find and fix bugs.

We do not use third-party product analytics, advertising SDKs, attribution SDKs, or session-replay tools.

10. Data retention

  • Account and personal data: retained for as long as your account is active.
  • Chat history (text and voice transcripts): retained as part of your account so that your AI coach has memory of past conversations.
  • Meal photos and voice media in Google Cloud Storage: retained for as long as your account is active or until you delete the associated record.
  • Voice quality-monitoring samples: automatically deleted after 7 days.
  • Raw voice audio: not retained.
  • Diagnostic and crash data: retained according to Sentry’s default retention (typically 30–90 days).
  • Backups: routine backups of our databases are retained for a limited period for disaster recovery and then expire.
  • Health and fitness data synced from your device (daily summaries, insights, and related records): automatically deleted after 90 days.
  • Weights synced from your device: retained in your weight log alongside weights you entered manually, so your trend stays intact, and deleted when you delete your account.
  • Health connections you stop using: if an installation hasn't synced for 60 days, we expire the connection automatically and stop retaining data for it. Reopening the app reconnects it.

If you delete your account, we delete or de-identify your personal data within a reasonable period, except where retention is required by law (for example, tax, fraud-prevention, or legal-defense purposes).

11. Sharing your information

We share your personal information only:

  • With the third-party providers listed in Section 5, solely so they can perform their function
  • With law enforcement or regulators when required by valid legal process
  • In connection with a corporate transaction (e.g., merger or acquisition), in which case we will require the recipient to honor this Privacy Policy
  • With your consent, in any other circumstance

We do not sell your personal information, and we do not share it with advertisers.

12. International data transfers

Hobbes is operated from the United States, and most of the third-party providers in Section 5 are based in the United States. When you use the Service from the EEA, the UK, or Switzerland, your personal information is transferred to and processed in the United States and other countries that may not provide the same level of protection as your home jurisdiction.

Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on one or more of the following safeguards under Articles 45–46 of the GDPR / UK GDPR:

  • Adequacy decisions issued by the European Commission or the UK Government, where applicable
  • The EU–US Data Privacy Framework (and its UK Extension and Swiss–US Framework), where the recipient is certified
  • Standard Contractual Clauses (“SCCs”) approved by the European Commission, with the UK International Data Transfer Addendum where the transfer originates from the UK
  • Your explicit consent, where appropriate

You can request a copy of the safeguards we use for a particular transfer by contacting us at the address in Section 17.

13. Your rights and choices

You can:

  • Access and update your account information from inside the app
  • Export your data by emailing us at the address in Section 17
  • Delete your account from the in-app Settings screen, or by emailing us. Deletion removes your personal data from our active systems within a reasonable period.
  • Manage push notifications through your device’s notification settings
  • Manage microphone, camera, and photo permissions through your device’s privacy settings
  • Manage subscriptions through your Apple App Store or Google Play account

Users in the EEA, UK, and Switzerland have additional rights — see Section 13.

14. Additional information for users in the EEA, UK, and Switzerland

This section applies if you are located in the European Economic Area, the United Kingdom, or Switzerland. It supplements the rest of this Privacy Policy and prevails over it where there is any conflict.

14.1 Controller

The data controller of your personal information is:

Lavender Technology Inc.
13001 NE 32nd Pl Bellevue WA 98005
Email: support@hobbes.health

14.2 Lawful bases for processing

We process your personal information on the following lawful bases under Article 6 of the GDPR / UK GDPR:

Activity Lawful basis
Creating your account, authenticating you, providing the core Service, and storing your meals, habits, chat history, and other content Contract (Article 6(1)(b)) — necessary to perform our Terms of Service with you
AI processing of your messages, photos, and voice for coaching, meal logging, and Q&A Contract (Article 6(1)(b)) and, for special category data, explicit consent (see Section 13.3)
Sending transactional emails (OTPs, support replies) Contract (Article 6(1)(b))
Push notifications you opt into Consent (Article 6(1)(a)) — you can withdraw at any time in your device settings
Crash and error diagnostics via Sentry Legitimate interests (Article 6(1)(f)) — to keep the Service stable and secure
Voice transcript quality-monitoring sample (≈1%, 7-day TTL) Legitimate interests (Article 6(1)(f)) — to monitor and improve the accuracy of the voice pipeline. We have carried out a balancing test and minimized the data via random sampling and short retention.
Subscription management via RevenueCat and Apple/Google billing Contract (Article 6(1)(b))
Complying with legal obligations (e.g., responding to lawful requests, tax records) Legal obligation (Article 6(1)(c))
Defending or establishing legal claims Legitimate interests (Article 6(1)(f))

You have the right to object to processing based on legitimate interests on grounds relating to your particular situation; see Section 13.4.

14.3 Special category data (health data)

The information you log in Hobbes — meals, dietary restrictions, allergies, habits, photos of food, and your conversations with the AI coach — concerns your health and is a special category of personal data under Article 9 of the GDPR / UK GDPR.

We process this data on the basis of your explicit consent under Article 9(2)(a). You provide that consent when you create an account and start logging information in the app. You may withdraw your consent at any time by deleting your account or by emailing us at the address in Section 17. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

If you do not wish for us to process your health data, please do not enter it into the Service.

14.4 Your rights under the GDPR / UK GDPR

You have the following rights with respect to your personal information:

  • Right of access (Article 15) — to obtain confirmation of whether we process your data and a copy of it
  • Right to rectification (Article 16) — to correct inaccurate or incomplete data
  • Right to erasure (“right to be forgotten”, Article 17) — to have your data deleted in certain circumstances
  • Right to restrict processing (Article 18) — to limit how we process your data in certain circumstances
  • Right to data portability (Article 20) — to receive your data in a structured, machine-readable format and have it transmitted to another controller
  • Right to object (Article 21) — to object to processing based on legitimate interests, including the voice quality-monitoring sample
  • Right to withdraw consent (Article 7(3)) — at any time, where processing is based on consent
  • Right not to be subject to solely automated decisions (Article 22) — see Section 13.8

To exercise any of these rights, contact us at the email address in Section 17. We will respond within one month, as required by law. We may need to verify your identity before acting on your request. Most rights can also be exercised directly in the app: access, rectification, and erasure are available via in-app account settings.

14.5 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal information infringes the GDPR or UK GDPR.

We would, however, appreciate the chance to address your concerns first; please contact us at the email address in Section 17.

14.6 International transfers

Personal information collected in the EEA, UK, or Switzerland is transferred to the United States and processed there by us and by the providers listed in Section 5. Section 11 describes the safeguards we rely on (Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, and the UK International Data Transfer Addendum where the transfer originates from the UK).

14.7 Automated decision-making

Our AI coach generates suggestions, summaries, and coaching messages automatically. These outputs do not produce legal effects concerning you and are not used to make decisions that significantly affect you in the sense of Article 22 of the GDPR. The AI coach is informational only and is not a substitute for advice from a qualified medical professional.

If you have concerns about a particular AI-generated response, you may contact us at the email address in Section 17 to discuss it with a person.

15. Children’s privacy

Hobbes is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us so we can delete it.

16. Security

We use industry-standard practices to protect your information, including encryption in transit (TLS), encryption at rest for backups and object storage, scoped access tokens, and least-privilege access for our team. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where the breach is likely to result in a high risk, we will inform affected users without undue delay, in accordance with Articles 33 and 34 of the GDPR / UK GDPR.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Effective date” at the top of this page and, where the changes are material, we will notify you in the app or by email before they take effect.

18. Contact us

If you have questions about this Privacy Policy or how we handle your information, contact us:

Email: support@hobbes.health