Privacy Notice

Last updated March 27, 2026

This privacy notice for Eudemonia, LLC (“Company,” “we,” “us,” or “our”) describes how and why we collect, store, use, and share your information when you use The Quantified Self mobile application and website at the-quantified-self.com (collectively, the “Services”).

Information We Collect

We collect information you provide directly, including:

Health and Ambient Data

With your explicit permission, the app reads data from Apple Health (HealthKit), including workouts, steps, heart rate, sleep analysis, blood pressure, blood glucose, and active energy. This data is uploaded to our servers to power automations, dashboard summaries, and ambient consolidation into journal entries.

We also collect calendar event metadata (title, start/end time) if you enable the calendar ambient stream. Calendar data is used solely for automations and journal context.

Health and calendar data is stored in your account and is never sold or shared with third parties for advertising purposes.

AI-Assisted Features

Our LLM-assisted journaling feature sends your journal entry text to OpenAI's API (GPT-4o Mini) to extract entity and reference suggestions. When you use this feature:

Subscription and Payment Data

Subscriptions are managed through Apple's App Store and RevenueCat. We do not directly collect or store payment card information. We receive subscription status, transaction identifiers, and entitlement information from RevenueCat to manage your access to premium features.

New accounts receive a 14-day free trial of premium features. After the trial, a subscription is required for continued access to premium features including journaling, automations, ambient streams, dashboard trends, LLM assist, and API keys.

How We Use Your Information

Data Retention

We retain your data for as long as your account is active. Deleted journal entries are soft-deleted (marked as deleted but retained for sync purposes) and permanently purged after 90 days. You may request full account deletion at any time by contacting us.

Data Security

Data is transmitted over HTTPS and stored in a PostgreSQL database hosted on Heroku. API keys are stored as bcrypt hashes; only the raw token is shown once at creation. The Services are not HIPAA or FISMA compliant.

Third-Party Services

Your Rights

You may request access to, correction of, or deletion of your personal data at any time by emailing us. California residents have additional rights under the CCPA, including the right to know what data is collected and the right to opt out of data sales (we do not sell personal data).

Children

The Services are not intended for users under 18 years of age. We do not knowingly collect data from children.

Changes to This Notice

We may update this privacy notice from time to time. The “Last updated” date at the top reflects the most recent revision.

Contact

For questions or concerns about this privacy notice, contact us at email@the-quantified-self.com.