Privacy

The honest version.

Last updated: September 20, 2026

Plain language up top, full legal coverage below. Here's exactly what data Gal collects, why, who else sees it, and what you can do about it.

What we never do

  • We never sell your personal information.
  • We never share your cycle, symptom or meal data with advertisers or data brokers.
  • We never use your health data to target advertising.
  • We never use your Apple Health data for advertising or marketing.

The rest of this policy is the long version of the same commitments, plus everything else you are entitled to know.

1. About this policy

This Privacy Policy describes how Evori Ventures Inc. (“Evori,” “Gal,” “we,” “us,” or “our”), a corporation incorporated under the laws of Canada in 2026, collects, uses, discloses, and protects information when you use the Gal mobile application (the “App”), the website at heygal.app (the “Site”), and related services (collectively, the “Services”).

Evori Ventures Inc. is the controller of personal information processed through the Services. By using the Services, you acknowledge that you have read and understood this Privacy Policy.

2. Information we collect

We collect the following categories of information.

Information you provide

  • Account information — Gal works without an account: when you first open the App, we create a guest account identified by a random ID. If you choose to add sign-in, we store your email address and a password (stored as a one-way hash), or, if you sign in with Apple or Google, an authentication token, the email associated with that account and your name if you choose to share it. You can also add an optional first name so Gal can greet you.
  • Profile information — Age, height, weight, goals, activity level, eating style, dietary preferences, allergies, ingredient avoidances, and the sensitivities you choose to track.
  • Meal logs and food data — Meal descriptions and photos, barcodes you scan, foods you search for, meal times, portions and nutrition values, and any notes you add. If a photo carries location information, we remove it before the photo is stored or sent for estimation.
  • Cycle and reproductive health data — Period dates, flow, spotting and cramps, cycle and period length, daily check-ins (such as energy, bloating, cravings, digestion, skin, sleep, mood and stress), and any notes you add. See Section 5 for the special protections that apply to this data.
  • Health conditions you choose to share — optional conditions that help Gal tailor its guidance, such as PCOS, endometriosis, thyroid or digestive conditions, and mental-health conditions. You can skip this, or remove it at any time.
  • Body and wellness data — Weight and body-fat measurements, workouts, and supplements you log.
  • Communications — messages you send to support, feedback, survey responses, and any other content you submit to us.

Information we collect automatically

  • Device and technical information — Device model, operating system version, App version, language, time zone, IP address, and crash and performance diagnostics (such as how long the App takes to start). These contain no health data and are not linked to your name or email.
  • Usage information — Optional usage analytics: which screens you view and which features you use. If you turn it on, these events are linked to your account's random ID — never your name or email — and actions about your cycle, symptoms or conditions are counted without any ID at all. It never includes meal content, cycle dates, symptom values or other health values, and you can turn it off at any time in the App.
  • Cookies and similar technologies — on the Site, we use a small number of strictly necessary cookies. See Section 14 for details.

Information from third parties

  • Apple Health — only if you grant permission, and read-only: steps, active energy, weight, body fat, workouts, sleep, body temperature and menstrual flow. See Section 6.
  • Sign-in providers — if you sign in with Apple or Google, we receive a verified email and authentication token from that provider.
  • Apple App Store and our subscription management provider — subscription status (active, cancelled, in trial). We do not receive your payment card details.

3. How we use your information

We use information for the purposes below, on the legal bases indicated in Section 11.

  • Provide the Services — store and display your logs, generate the patterns and insights you came for, sync across your devices, and authenticate you.
  • Personalize your experience — tailor suggestions to the cycle phase, nutrition profile, and goals you have configured.
  • Maintain and improve the Services — monitor performance, fix bugs, prevent abuse, develop new features, and conduct internal analytics.
  • Communicate with you — respond to support requests, send service-critical notices (security, billing, policy changes), and, with your consent, send optional product updates.
  • Process payments — administer subscriptions through the Apple App Store and our subscription management provider.
  • Comply with law — meet legal, regulatory, and tax obligations, and respond to lawful requests as described in Section 17.

We do not sell your personal data, and we do not use it to target advertising. When you ask Gal to estimate a meal, we send that meal to a third-party AI provider: the text of a typed description, or the photo itself. The App asks for your agreement the first time before it does this. Nothing else from your Gal account is sent with it — no account identifier, no cycle dates, no symptom logs, no health conditions, no contact details.

4. How we share information

We do not sell your personal information. We do not share your meal logs, cycle data, or health information with advertisers, data brokers, or any third party for marketing purposes — ever.

We share limited information with the following service providers, each bound by contract to use the data only to provide their service to us, to maintain confidentiality, and to apply security standards consistent with this policy:

  • Cloud infrastructure and database — Stores your account, logs, and cycle data, encrypted at rest. Hosted in the United States, under contract.
  • AI nutrition estimation (third-party AI providers) — When you ask Gal to estimate a meal, the typed description or the photo is sent to an AI provider, which returns a nutrition estimate. No account identifier, cycle dates, symptom logs, health conditions or contact details are sent with it. These providers process it only to return the estimate, under contract.
  • Subscription management — manages subscription state and entitlements. Receives a pseudonymous user identifier and subscription status only.
  • Crash and error reporting — Receives crash reports and app-speed measurements so we can fix what breaks or runs slowly. These carry no health data, name, email or account identifier.
  • Product analytics — Receives optional usage events about which screens and features are used, linked to your account's random ID. Never your name, email, meal content, cycle dates or symptom values — and actions about your cycle, symptoms or conditions are sent without any ID.
  • Email delivery — Receives your email address, if you have added one, to send account emails such as sign-in and password-reset messages.
  • Food databases — when you scan a barcode or search for a food, the barcode or search term is sent to public food databases (such as Open Food Facts and USDA FoodData Central), without anything that identifies you.
  • Payment processing (Apple Inc.) — handles in-app purchases under its own terms and privacy policy.

We identify these providers by the role they play rather than by name, so that we can change providers without rewriting this policy. You can ask us who our current providers are at any time by emailing privacy@heygal.app, and we will tell you. If we change a provider in a way that materially affects how your personal data is handled, we will notify you as described in Section 19.

The fit score itself is not generated by AI — it is a fixed formula we wrote, and Gal shows you the reasons behind every score. When an estimate comes from a photo or a description, the nutrition numbers feeding that formula are an AI estimate, and Gal labels them as estimated.

We may also disclose information: (i) in connection with a corporate transaction such as a merger, acquisition, or asset sale, in which case we will notify you and ensure equivalent protections apply to your data; (ii) to professional advisors (lawyers, auditors, accountants) under duties of confidentiality; and (iii) as required by law, as described in Section 17.

5. Health and reproductive data — special protections

When you first set up Gal, we ask you to agree — in a separate step, before any health question — to Gal using the health information you share: your cycle, symptoms, conditions and any health data you choose to connect. That agreement is our legal basis for handling this information where the law requires your explicit consent, and we keep a record of it. You can withdraw it at any time by deleting your account in the App (Profile → Delete my account), which deletes this data.

Reproductive and menstrual health information is sensitive. We treat it with the highest level of care permitted by law and our infrastructure.

  • We never sell your reproductive health data or share it with advertisers, data brokers, insurers, employers, or marketing partners. Service-provider processing and legally required disclosures are described in Sections 4 and 17.
  • We minimize what we collect. Cycle and symptom logs are stored only for the purpose of giving them back to you and computing your patterns.
  • We resist legal demands wherever lawful. If we receive a subpoena, warrant, court order, or other legal process for cycle, period, or pregnancy data, we will assess each request individually, challenge requests we believe overreach or are unlawful, narrow the scope of any production where possible, and notify you before producing data unless legally prohibited from doing so.
  • You can delete this data instantly. Cycle, period, and symptom entries can be deleted from inside the App at any time. Account deletion (Section 8) permanently removes your reproductive health data from our active systems within 24 hours. Residual copies may persist in encrypted backups for up to 30 days, after which they are overwritten on our provider's normal backup cycle.

See also our Consumer Health Data Privacy Policy.

6. Apple HealthKit

If you choose to connect Apple Health, the App reads the health and fitness data you allow — steps, active energy, weight, body fat, workouts, sleep, body temperature and menstrual flow. Gal never writes data to Apple Health. The following commitments apply specifically to Apple Health data, in addition to everything else in this policy:

  • We use HealthKit data solely to provide and improve features within the App.
  • We do not use HealthKit data for advertising, marketing, data mining, or any purpose unrelated to your health, wellness, or the operation of the App.
  • We do not share or sell HealthKit data with third parties for advertising, marketing, or any similar service.
  • We do not share or disclose HealthKit data to a third party without your express permission.
  • You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Gal.

7. Where your data is stored and international transfers

Your data is primarily stored on infrastructure located in the United States. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate.

Where the law requires safeguards for these transfers, we rely on contractual commitments with our service providers, together with encryption in transit and at rest.

8. Data retention and deletion

We retain your information only as long as needed to provide the Services or to meet legal obligations.

  • Account and log data — kept for as long as your account is active.
  • Account deletion — when you delete your account from inside the App, we permanently remove your personal data from our active systems within 24 hours. Residual copies may persist in encrypted backups for up to 30 days, after which they are overwritten on our provider's normal backup cycle.
  • Inactive accounts — accounts inactive for 24 months may be deleted. If you've added an email address, we'll remind you first.
  • Aggregated and anonymized data — once data has been irreversibly aggregated or anonymized so it can no longer identify you, we may retain it indefinitely for product analytics and research.
  • Legal holds — we may retain limited information longer than the periods above where required to comply with legal obligations, resolve disputes, or enforce our agreements.

9. Security

We protect your data with safeguards appropriate to its sensitivity, including encryption in transit (TLS) and at rest (AES-256), row-level access controls so each account can only reach its own data, encryption of the data the App stores on your device, and limiting access to the people who need it. No method of transmission or storage is perfectly secure; if a breach affects your personal information, we will notify you and the relevant regulators as required by law.

10. Your choices and controls

You can do the following from inside the App, in the Profile tab:

  • Access and export — download a complete machine-readable copy of your data as JSON (Profile → Download my data).
  • Correct or update — edit any logged entry or profile field.
  • Delete entries — remove individual logs at any time.
  • Delete your account — permanently delete your account and all associated data (Profile → Delete my account).
  • Manage notifications — turn reminders on or off in the App or in iOS Settings.
  • Usage analytics — turn usage sharing on or off at any time (Profile → Share usage analytics). Crash and app-speed reports are always sent; they carry no health data and don't identify you.
  • Revoke permissions — disable HealthKit, camera, photos, and other system-level permissions in iOS Settings.

You can also email privacy@heygal.app to exercise any of these rights. We respond within 30 days, and may need to verify your identity before fulfilling certain requests.

11. EEA, UK, and Swiss residents

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection apply. The legal bases on which we process your personal data are:

  • Performance of a contract — to provide the Services you have requested.
  • Legitimate interests — to operate, secure, and improve the Services, where these interests are not overridden by your rights.
  • Consent — your explicit consent for processing of special category data (cycle and health information) and HealthKit data; your consent for optional marketing communications and other uses where we ask you.
  • Legal obligation — where processing is required to comply with law.

You have the right to:

  • access your personal data;
  • request correction of inaccurate data;
  • request erasure;
  • request restriction of, or object to, certain processing;
  • data portability;
  • withdraw consent at any time, without affecting processing already carried out;
  • lodge a complaint with your local data protection authority. You can find yours at edpb.europa.eu/about-edpb/about-edpb/members_en.

To exercise any of these rights, contact privacy@heygal.app.

12. California residents

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the rights below.

  • Right to know what personal information we have collected about you, the categories of sources, purposes, and recipients.
  • Right to delete personal information we have collected, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of any “sale” or “sharing” of personal information for cross-context behavioural advertising. We do not sell or share your personal information as those terms are defined under California law.
  • Right to limit use of sensitive personal information. We use sensitive personal information (which includes health and reproductive data) only for the purposes described in this policy and not for inferring characteristics about you for advertising.
  • Right to non-discrimination for exercising any of the above.

To exercise these rights, contact privacy@heygal.app. You may also designate an authorized agent to make a request on your behalf, in which case we will verify the agent's authority before responding.

13. Canadian residents

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws (including, in Quebec, the Act respecting the protection of personal information in the private sector, as modified by Law 25) apply to our handling of your personal information.

  • You may request access to, and correction of, the personal information we hold about you.
  • You may withdraw consent to our processing, subject to legal or contractual restrictions and reasonable notice.
  • You may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, if you are in Quebec, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
  • For the purposes of Quebec's Law 25, our person responsible for protection of personal information can be reached at privacy@heygal.app.

14. Cookies and similar technologies

On the Site, we use only strictly necessary cookies (for example, to remember whether you have dismissed a banner). We do not use third-party advertising, tracking, or analytics cookies on the Site or in the App.

The App does not use the advertising identifier and does not track you across other companies' apps or websites.

15. Notifications

With your permission, Gal sends reminders and notifications. Reminder text can mention your cycle and appear on your lock screen. You can turn reminders off at any time in the App or in iOS Settings → Notifications → Gal.

16. Children's privacy

The Services are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that someone under 18 has used the Services, we will delete their information. If you believe this has happened, contact privacy@heygal.app.

17. Law enforcement and legal requests

We disclose information to law enforcement, government agencies, or in response to legal process only when we are legally required to do so or where we believe in good faith that disclosure is necessary to protect rights, property, or safety.

For requests touching reproductive health, cycle, period, pregnancy, or related data, we apply the heightened protections described in Section 5: we assess each request individually, challenge requests we believe overreach or are unlawful, narrow scope where possible, and provide advance notice to the affected user unless we are legally prohibited from doing so.

18. Third-party services

The Services may contain links to third-party websites or integrate with third-party services. This policy does not apply to those third parties; their own privacy policies do. We are not responsible for the practices of those third parties, but we choose them carefully and require them to apply protections consistent with this policy.

19. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or in-App notice before the changes take effect, and we will update the “Last updated” date at the top of this page. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

20. How to contact us

For privacy questions, data subject requests, or anything that doesn't sit right, email privacy@heygal.app. A real person responds, normally within 30 days.