โ† Back to Home

Privacy Policy

Last Updated: November 16, 2025

1. Introduction

Welcome to S.A.K.U.R.A. ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our wellness platform.

๐Ÿงช Beta Notice: S.A.K.U.R.A. is currently in beta testing. During this phase, we are actively developing features and improving infrastructure. While we implement security best practices, some enterprise features (like automated backups and multi-region redundancy) are not yet available.

By using our service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Personal Information

We collect the following personal information:

  • Account Information: Email address, username, password (encrypted), display name
  • Profile Information: Date of birth, sex, height, location, timezone
  • Avatar: Profile picture (optional)

2.2 Wellness Data

  • Goals & Habits: Wellness goals, habit tracking data, completion records
  • Biometric Data: Sleep patterns, exercise metrics, nutrition logs, stress levels, heart rate (from wearable devices)
  • Device Measurements: Body measurements, weight, body composition (if uploaded)
  • Chat & Conversations: Messages with AI agents, wellness queries
  • Preferences: Dietary preferences, wellness priorities, activity preferences

2.3 Technical Information

  • Browser Storage: Authentication tokens, theme preferences, UI layout preferences
  • Usage Data: Feature interactions, page views, session duration
  • Device Information: Browser type, operating system, IP address (for security)

2.4 Third-Party Integrations

  • Wearable Devices: Sleep data, readiness scores, activity metrics (like Oura Ring, Apple Watch)
  • Location Data: City/region for weather-based recommendations (via OpenWeatherMap)

3. How We Use Your Information

We use your information for the following purposes:

  • Service Delivery: Provide personalized wellness recommendations, AI-powered coaching, habit tracking
  • AI Processing: Analyze your wellness data to generate insights, predictions, and recommendations
  • Account Management: Authenticate users, manage profiles, secure your account
  • Communication: Send important updates, respond to support requests
  • Improvement: Analyze usage patterns to improve features and user experience
  • Legal Compliance: Comply with legal obligations and protect our rights

4. Third-Party Data Processing

Your data is processed by the following third-party services:

  • Google Gemini AI: Your chat messages and wellness data are sent to Google's Gemini AI service to generate personalized recommendations. Data is transmitted securely via HTTPS.
  • OpenWeatherMap: Your location (city/region) is sent to retrieve weather data for context-aware recommendations.
  • Wearable Device APIs: If connected, biometric data is retrieved from device providers' servers.
  • Google Cloud Storage: Avatar images are stored on Google Cloud Platform (production environment).

Important: We do not control how these third parties use your data. Please review their privacy policies: Google Privacy Policy, OpenWeatherMap Privacy Policy.

5. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

  • Active Accounts: Data is retained while your account is active
  • Deleted Accounts: Upon account deletion, personal data is permanently removed within 30 days
  • Legal Requirements: Some data may be retained longer if required by law
  • Aggregated Data: Anonymized, non-identifiable data may be retained for analytics

6. Your Privacy Rights

Under GDPR and other privacy laws, you have the following rights:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Rectification: Update or correct inaccurate information via your Profile page
  • Right to Erasure: Request deletion of your account and all associated data
  • Right to Data Portability: Export your data in JSON format via Profile โ†’ Data Export
  • Right to Restrict Processing: Request limitations on how we use your data
  • Right to Object: Object to certain data processing activities
  • Right to Withdraw Consent: Withdraw consent for optional data processing at any time

To exercise these rights, contact us at hello@mysakura.ca.

7. Data Security

We implement industry-standard security measures:

  • Encryption: All data is transmitted via HTTPS/TLS encryption
  • Password Security: Passwords are hashed using bcrypt with secure salt rounds
  • Authentication: JWT token-based authentication with refresh tokens
  • Database Security: Cloud-hosted database with end-to-end encryption and access controls
  • Access Control: Role-based access controls ensure users can only access their own data

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email. Your continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email: hello@mysakura.ca