Privacy Policy

Last updated: June 10, 2026

1. What Sona is, and who we are

Sona is a personal health companion app. It helps you store and review your own medical records, medications, vitals, lab results, appointments, and vaccinations. Sona is not a medical device, does not provide medical advice, and is not a substitute for professional healthcare.

Data controller. Sona (sonahealth.app) is operated by Individual Entrepreneur Giorgi Aphkhazava, registered under the legislation of Georgia, identification number 61001081474, who acts as the data controller for the personal data described in this policy. For any matter concerning your personal data, contact us at info@sonahealth.app.

2. What data we collect

  • Account data: email address, display name, profile photo (optional).
  • Health data you enter: medications, vitals, lab markers, appointments, vaccinations, conditions, allergies, symptoms, and documents you upload.
  • Device data: push notification subscription endpoint (if you opt in), browser user agent (stored for troubleshooting, max 500 chars).
  • Usage data: API request timestamps, AI request metadata (function, model, token counts, cost) — used for rate limiting, abuse prevention, and our own internal service statistics. Never sold or shared.
  • Marketing measurement data (opt-in only): if you accept analytics & advertising cookies, Google Analytics and the Meta Pixel set identifiers (_ga, _fbp, _fbc) in your browser, and we send hashed conversion identifiers to Meta (see Section 7). This is entirely optional and off by default.

We do not sell your data, and your health data is never shared for marketing or advertising purposes under any circumstances. Advertising/analytics identifiers are used only with your explicit opt-in consent, which you can withdraw at any time.

3. Where your data is stored

All data is stored on Supabase servers in the EU (Frankfurt, Germany), which complies with GDPR. Uploaded health documents are stored in Supabase Storage within the same region. AI features (document analysis, health assistant, specialist briefs) send relevant data to AI model providers via OpenRouter (openrouter.ai) — data is processed transiently and not retained by the model provider after responding. Subscription payments are processed by our third-party payment processor, who acts as merchant of record and handles all billing and payment disputes. OpenRouter's privacy policy: openrouter.ai/privacy.

International transfers. Your stored records never leave the EU. However, when you explicitly use an AI feature, the data relevant to that request is processed transiently by AI model providers that may be located outside the EU/EEA (primarily in the United States), routed via OpenRouter. These transfers happen only when you initiate the action, are encrypted in transit, are covered by the providers' data processing terms (including no retention after responding and a prohibition on using the data for model training), and rest on your explicit consent to health data processing. If you withdraw that consent, no such transfers occur at all — your data then remains exclusively in the EU.

4. How we use your data

  • To display your health records and provide the app features you use.
  • To send push notifications you opt into (dose reminders, appointment alerts).
  • To generate AI-powered summaries, insights, and specialist briefs from your own data.
  • To enforce rate limits and prevent abuse.

Direct marketing. With your separate, granular consent we may send you product news and updates by email or SMS. Marketing consent is optional and never a condition of using the service. You can opt out at any time in notification settings, and opt-outs take effect immediately. Essential service messages (security alerts, billing, changes to terms) are sent regardless, as part of providing the service itself.

Automated decision-making (profiling). We do not make automated decisions, including profiling, that produce legal or similarly significant effects on you. AI features generate informational summaries only when you explicitly request them; they never determine your access to the service, its pricing, or any other outcome.

5. Family profiles

You may add family members as managed profiles. Their health data is stored under your account and is fully isolated — family members you invite can only see their own profile's data. You are responsible for obtaining consent from family members whose data you enter.

6. Menstrual and reproductive health data

Sona may store menstrual cycle dates, flow intensity, basal body temperature (BBT), ovulation data, and related cycle logs that you enter. This category of data receives the highest level of protection:

  • It is never shared with law enforcement, government agencies, insurers, or employers.
  • It is processed transiently by AI model providers (via OpenRouter) for AI features only when you explicitly use the AI assistant, and is not retained by the model provider after responding.
  • It is stored exclusively in the EU (Frankfurt) under your account and is accessible only to you.
  • When you share a specialist brief or medical card via a link, cycle data is included only if you explicitly opt it in during brief creation.

7. Data sharing

Sona does not share your data with third parties except:

  • OpenRouter / AI model providers — processes health data transiently for AI features (document analysis, chat, specialist briefs). No storage after responding.
  • Supabase — hosts and stores all your data under our agreement.
  • Payment processor — processes subscription payments as merchant of record. Handles billing, invoices, and payment disputes. Does not receive your health data.
  • Specialists you share with — when you generate a specialist brief or medical card link, the recipient can view that data via the secure link. You control what is included and can revoke access at any time from your Profile settings.
  • Meta (Facebook) — only with your opt-in consent — to measure advertising performance we may send conversion events (sign-up, subscription) containing SHA-256-hashed identifiers: email, phone, name, country, city, gender, and an internal user ID, plus the Meta browser/click identifiers. No health data is ever included. If you decline or withdraw analytics consent, nothing is sent.
  • Google Analytics — only with your opt-in consent — receives anonymous usage statistics and conversion events to help us understand how visitors find and use Sona. No health data is ever included.

Controls on third-party transfers. Each sub-processor is bound by data processing terms covering confidentiality, security, and GDPR compliance. Health data is transferred only to the two sub-processors that need it to deliver the service (Supabase for storage in the EU; OpenRouter transiently for AI features), only over encrypted TLS connections, and only the minimum data relevant to the specific request. AI providers are contractually prohibited from using submitted data for model training. The payment processor never receives health data — it processes payment and billing information only. We do not engage new sub-processors that would receive health data without updating this policy and notifying users in-app.

8. Lawful basis and your rights (GDPR)

We process your health data on the basis of your explicit consent (Article 9(2)(a) of the GDPR and equivalent provisions of the Georgian Personal Data Protection Law). You provide this consent when you create your account, and it is recorded with a full audit trail: the exact consent text shown to you, a server-side timestamp, your IP address, the method of consent, and the policy version in force — so we can demonstrate at any time what you agreed to and when.

Withdrawing consent. You may withdraw your consent to health data processing at any time from Profile → Privacy & Security, without deleting your account. Withdrawal takes effect immediately and is enforced on our servers, not just in the app interface: every AI processing request is checked against your current consent status before any health data leaves our infrastructure. Withdrawal stops all future AI processing; your stored records remain available to you and you may re-grant consent at any time. To erase stored data entirely, delete your account.

Other lawful bases. Health data is processed only on explicit consent, but some processing rests on other grounds: account, authentication, and subscription data are processed to perform our contract with you (Article 6(1)(b)); security logging, rate limiting, and abuse prevention rest on our legitimate interest in protecting the service (Article 6(1)(f)); and breach notification or responses to lawful requests rest on legal obligation (Article 6(1)(c)). Marketing communications rest on separate, optional consent.

You also have the right to:

  • Access: download all your data via Profile → Export data.
  • Portability: your export is in standard JSON format.
  • Erasure: delete your account via Profile → Delete account. All your data is permanently deleted.
  • Rectification: edit any record directly in the app.
  • Restriction / objection: contact us and we will respond within 30 days.
  • Complaint: lodge a complaint with the Personal Data Protection Service of Georgia (personaldata.ge) or, if you are in the EU/EEA or UK, with your local supervisory authority.

9. Data retention

Your data is retained as long as your account is active. When you delete your account, all personal data is permanently and irrecoverably deleted within 30 days. Backups containing your data are rotated out within 90 days of deletion.

10. Security, internal controls, and access management

10.1. Technical safeguards

  • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access isolation is enforced at the database level through row-level security policies — every query is restricted to the authenticated user's own records, independently of application code.
  • Tables that hold no user-facing data are locked away from client access entirely; they are reachable only by our servers.
  • API keys and server credentials are stored as environment secrets, never in source code, and the application enforces a strict Content Security Policy limiting which external services the app may contact.

10.2. How special category data is processed

  • Health data is processed by AI features only when you explicitly initiate the action (asking the assistant, uploading a document for analysis, generating a brief). There is no background or automatic processing.
  • Before any health data leaves our infrastructure, our servers verify your current consent status. If consent has been withdrawn, the request is refused server-side.
  • Each request includes only the minimum data relevant to it — never your full record set.
  • Subscription status and rate limits are likewise verified server-side on every AI request.

10.3. Company-side access management

  • Administrative access is restricted to named administrator accounts. Every administrative server function independently re-verifies the administrator role on each call — possession of an app account is never sufficient.
  • Production database credentials with elevated privileges exist only as server-side secrets and are never exposed to browsers or client applications.
  • Administrators access aggregate statistics by default; individual record access is limited to support and abuse-prevention purposes.

10.4. Monitoring and audit

  • Every AI processing request is logged (function, model, timestamp, token volume, cost) and reviewed through internal dashboards — anomalous usage patterns are visible immediately.
  • Per-user and global rate limits and spending caps automatically stop runaway or abusive processing; accounts can be frozen pending investigation.
  • All consent decisions form a permanent audit trail (see Section 8).
  • Application errors are monitored through an error-tracking service configured to scrub personal data from reports.

11. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay, explaining the nature of the breach, likely consequences, and measures taken. Notifications will be sent to the email address associated with your account.

12. Minimum age and children

You must be at least 18 years old to create a Sona account — account holders give explicit consent to health data processing and enter a subscription contract, both of which require legal capacity. Sona is not directed at children. A child's health data may be tracked by their parent or legal guardian under the parent's own account, as a managed family profile; the parent remains the data subject's representative and controls that data, including its deletion.

13. Changes to this policy

We may update this policy. Significant changes will be communicated via an in-app notification. The "last updated" date at the top of this page reflects the most recent revision.

14. Cookies and Local Storage

Essential (always on): one functional cookie (sidebar_state) remembering your navigation preference (expires after 7 days, contains no personal information), and your browser's localStorage for maintaining your authenticated session via Supabase and remembering your settings (language, theme, cookie choice).

Analytics & advertising (opt-in only): if — and only if — you accept them via the cookie banner or settings, Google Analytics sets _ga cookies and the Meta Pixel sets _fbp/_fbc cookies to measure how our marketing performs. These are never loaded before you consent, and you can change your choice at any time (cookie banner before sign-in, or Notification Settings → Consent in the app). Declining never limits any feature.

15. Contact

Questions about your data or this policy: info@sonahealth.app