Tranqui is an app for managing stress and understanding your emotions. The moods you log and the reflections you write say something about your mental health, and two state laws — Washington's My Health My Data Act and Nevada Senate Bill 370 (SB 370) — call that kind of information "consumer health data" and regulate it specifically.
Both laws require this to be its own document, published and linked separately rather than folded into a privacy policy. So this is a short document about one thing. Everything else about how Tranqui handles your information is in the Privacy Policy, and the two agree. Where this document is brief, the Privacy Policy is the fuller account.
1. Who this policy is for
This policy exists because Washington and Nevada require it. If you are in either state, it is the disclosure their law entitles you to, and Section 7 sets out the rights those laws give you.
The commitments in Section 6 are not limited to those two states. They describe how we handle this data for every person who uses Tranqui, anywhere. We did not want two standards, because operating two standards is a good way to get one of them wrong.
In this policy, "we" and "us" mean AZEApps LLC, an Illinois limited liability company, and "you" means the person using Tranqui. Tranqui is for adults; you must be 18 or older to have an account.
Tranqui is not a health care provider, and we are not a covered entity or a business associate under HIPAA. That is precisely why these state laws exist: they cover health information that HIPAA does not reach.
2. What consumer health data we collect
Both laws define consumer health data broadly, as information linked to you that identifies your past, present, or future physical or mental health status. In Tranqui, that is five things:
- The answers you give when you set up your account. When you create an account we ask a few questions about your goals, your preferences, and your current situation. What you tell us about your current situation is what brings these answers inside the definition above, so we treat all of them as consumer health data.
- Moods and emotional states you log. What you selected, and when.
- Reflections and entries you write. Free text. Whatever you choose to put in it is yours, and we treat all of it the same way.
- Your wellness activity inside the app. Which exercises, prompts, and educational material you open, and which screens and features you use.
- Inferences we draw from your mood and emotion logs and from your setup answers. Patterns we use to choose which content the app offers you, and for nothing else.
We do not collect, and Tranqui has no way to receive:
- Precise or GPS location. The only location we have is the approximate city or region implied by your IP address.
- Biometric or genetic data, or audio or video. Tranqui does not record any of these.
- Diagnoses, medications, symptoms, test results, or treatment records, as structured data. If you write about a diagnosis in a reflection, that text is consumer health data and is handled exactly as every other reflection is — but nothing in the app asks you for it or stores it as a field.
- Anything from a health care provider, pharmacy, insurer, laboratory, or health app. Tranqui does not connect to Apple Health or to any other device-level health service, and there is no such integration to enable.
3. Where it comes from
There are three sources, and all three are you:
- Directly from you, when you answer the setup questions, log a mood, or write a reflection.
- Automatically from the app, as you use it — which exercises and screens you open.
- From us, in the sense that the inferences described in Section 2 are drawn by us from what you told us and logged.
Nobody else sends us health data about you. We do not buy consumer health data, we do not obtain it from data brokers, and we do not receive it from any health care provider, insurer, or advertising partner. Section 3.3 of the Privacy Policy lists every third party that sends us anything at all — Apple, RevenueCat, Supabase, and AppsFlyer — and what they send is sign-in, subscription, and advertising attribution information. None of it is health data.
4. Why we collect it
We collect consumer health data for these purposes and no others:
- To show you your own history. Seeing your own patterns over time is what the app is for.
- To personalize the content the app offers you. Which exercises, prompts, and educational material you are shown, based on the moods and emotions you log and on the answers you gave when you set up your account.
- To run your account. Storing your entries, syncing them across your devices, and restoring the service after a failure.
- To improve the app. Understanding which screens and features are used and which are ignored, so we can decide what to build next. This uses in-app activity, never the content of what you write.
- To answer you when you ask for help. We access journal content only where it is strictly necessary to resolve a support request you have made and that cannot be resolved another way, or where the law requires it.
- To keep the service secure. Detecting unauthorized access to an account, abuse of free trials, and automated attacks. This uses in-app activity and account records, never the content of what you write.
- To comply with the law. Responding to lawful demands, as described in Section 5.
That is the complete list. Consumer health data is not used to advertise Tranqui to you or to anyone else, to measure advertising, or to build a profile of you for any purpose outside the app.
How long we keep it. Every figure below is the same one in Section 10 of the Privacy Policy. This is the consumer health data subset of that schedule, not a second schedule that could drift away from it.
| Consumer health data | How long we keep it |
|---|---|
| The answers you give when you set up your account | Life of the account, plus 30 days |
| Moods, emotions, and the reflections you write | Deleted within 30 days of account deletion |
| Inferences drawn from your mood and emotion logs and from your setup answers | Life of the account, plus 30 days |
| In-app wellness activity — which exercises, prompts, and screens you opened | 26 months from when the record is made, whether or not the account is still open |
| A journal entry you chose to paste into a support email | 3 years, with the rest of that correspondence, or sooner if you ask us to delete it |
| Backups containing any of the above | Purged on a rolling 90-day cycle |
The in-app wellness activity row is the one place the clocks differ, and we would rather point at it than let you find it. Your setup answers, your moods, emotions, reflections, and the inferences we draw from them are tied to your account and go when it goes. In-app wellness activity is held as analytics data on a fixed 26-month clock that runs from when each record is made, and closing your account does not shorten it. Those records carry no entry content: they say that a screen was opened, never what you wrote or how you felt. Section 7 says plainly what that means for a deletion request.
5. Who we share it with
Washington's law requires us to list the categories of third parties that receive consumer health data and to name the specific affiliates; Nevada's requires us to identify the persons who receive it. We have gone further than the first of those and named every recipient, because a category is not an answer to the question you are actually asking. This is the entire list.
| Recipient | What it receives | Why |
|---|---|---|
| Supabase | The answers you give when you set up your account, moods, emotions, reflections, in-app wellness activity, and the inferences drawn from all of it | Infrastructure, database, and authentication — it stores this data for us |
| Purelymail | Only what you choose to put in an email to us | Sending and receiving support email |
Supabase is the only recipient that holds your consumer health data in the ordinary course of running Tranqui. It stores it for us as our database and authentication provider. It is bound by its published data processing terms, which we accepted when we signed up and which restrict what it may do with what it receives; we have not negotiated a bespoke agreement with it.
Our email provider only ever carries what you put in an email to us, so please do not paste an entry into a support message unless you need us to see it. Section 4 says how long that copy lasts, and Section 7 says how to have it deleted.
Nobody else receives it:
- Apple receives billing, subscription, and sign-in information. It never receives your journal content, and because Tranqui does not connect to Apple Health or any other device-level health service, no health data reaches Apple that way either.
- RevenueCat receives your subscription status and a device identifier. No health data.
- Meta, TikTok, Google, and AppsFlyer never receive it. Section 8 of the Privacy Policy lists exactly what they do receive, and Section 6 below explains the one thing about that arrangement we want you to be able to judge for yourself.
- Affiliates. We do not share consumer health data with any affiliate, subsidiary, or parent company.
- Purchasers. We do not sell consumer health data, so there is no list of purchasers to give you.
Three circumstances could take this data outside Supabase, and they are the same three set out in Section 7 of the Privacy Policy:
- Legal process. A subpoena, court order, warrant, or other lawful demand. We review each request, we disclose only what the request actually requires, and where we are permitted to tell you about it, we will.
- Safety. Where we believe in good faith that disclosure is necessary to prevent imminent physical harm to a person.
- Corporate transactions. If Tranqui were part of a merger, acquisition, financing, or sale of assets, information could transfer with it. The recipient would remain bound by this policy for data collected before the transfer, and we would tell you before any change to how your information is handled took effect.
6. What we never do with it
We do not sell your consumer health data. We do not share it with advertising or attribution partners. We do not use it to train artificial intelligence models. We do not operate a geofence around any facility that provides health care services.
Those four commitments are absolute, and they apply to every Tranqui user, not only to people in Washington and Nevada. Two of them are worth a sentence more:
No AI model reads or is trained on what you write. Nothing you write is sent to an AI model at all — there is no chatbot in Tranqui and nothing you write is answered by a machine. Section 6 of the Privacy Policy explains what artificial intelligence is used for, which is writing static in-app content before it ever ships.
We could not run a geofence even if we wanted to. Tranqui does not collect precise or GPS location. The nearest thing we have is the approximate city or region implied by an IP address, and we do not use it to identify anyone near a health care facility, or for any purpose beyond showing region-appropriate content and preventing fraud.
There is one thing we want to be precise about, because it is exactly what a document like this usually glosses over. We advertise Tranqui on Meta, TikTok, and Google, and to measure whether that advertising works, those partners and AppsFlyer receive device and advertising identifiers — the advertising identifier only where you granted App Tracking Transparency permission — an IP address, basic device information, and four app lifecycle events: install, open, session, account registration, subscription or trial start, and purchase. Those events say that a Tranqui app was installed and opened on a device. They never carry a mood, an emotion, a reflection, a topic, an answer you gave when you set up your account, or any record of what you do inside the app — there is no event in Tranqui that could. We do not treat the bare fact of an install as consumer health data, and we are telling you it happens rather than leaving you to work it out. Section 8 of the Privacy Policy lists precisely what those partners receive, and Section 9 of the Privacy Policy tells you how to stop it.
7. Your rights
Washington and Nevada law give you the rights below over your consumer health data. We honor them for every Tranqui user, wherever you live.
Confirm that we collect it, and see who has received it. You can ask us to confirm whether we collect, share, or sell your consumer health data, and to give you the list of every third party and affiliate that has received it. The answer to the second part is the list in Section 5. We will confirm it to you in writing on request, and give you contact details for anyone on it.
Access it. You can ask for a copy of the consumer health data we hold about you. We provide it in a structured, machine-readable format that you can take elsewhere.
Delete it. You can ask us to delete your consumer health data, and you can choose whether that means your journal content and setup answers only, or your whole account and everything in it — tell us which. We begin deletion immediately and complete it within 30 days. Backups are not individually editable, so deleted content can persist in an encrypted backup until that backup ages out, which takes no more than 90 days; during that window the backup is used for nothing except restoring the service after a failure.
Two limits on that, both of which we would rather state than have you discover:
- Support email. Apart from those backups, and any support email in which you chose to include an entry, there is nowhere else this data sits. If you have pasted an entry into a message to us and want that copy gone as well, tell us and we will delete the correspondence rather than hold it for the three years in Section 4.
- In-app wellness activity. The 30-day deletion covers the answers you gave when you set up your account, your moods, emotions, reflections, and the inferences drawn from them — everything tied to your account. It does not reach the in-app wellness activity described in Section 2. Those records are held as analytics data on the fixed 26-month clock in Section 4, and a deletion request does not shorten it. They contain no entry content, only that a screen or exercise was opened, and they are never shared with an advertising or attribution partner. We are telling you where the deletion stops instead of letting you assume it goes further than it does.
Withdraw your consent. You consent to our collection of this data when you answer the setup questions, log a mood, or write a reflection. You can withdraw that consent at any time by emailing us and asking us to delete your journal content and setup answers, or your whole account. Withdrawing consent does not undo processing we carried out before you withdrew it. We should be straight with you about one limit: if you keep using Tranqui after withdrawing, logging a new mood or writing a new reflection is a fresh consent for that new entry — we have no way to keep the app running while refusing to store what you put into it. If you want the collection to stop for good, ask us to delete the account.
Be free of retaliation. We will not deny you service, charge you a different price, or give you a lower level of service because you exercised any of these rights.
Appeal a refusal. If we refuse one of these requests, we will tell you why in writing. You may appeal by replying to that message or by writing to privacidad@apptranqui.com with the word "appeal" in the subject line. We will review the decision afresh rather than restate it, and respond within 45 days with our conclusion and the reasons for it.
How to exercise any of them. Email privacidad@apptranqui.com. Tell us which right you want to exercise; you do not need any particular wording, and a message from the address on your account is enough to start. You may also use an authorized agent, in which case we will ask the agent for proof of your authorization and may ask you to confirm it directly.
Identity verification. Before we act on a request to confirm, access, or delete, we need to be confident you are who you say you are — releasing someone's journal to an impostor would be a worse privacy failure than any this policy is trying to prevent. Normally we verify you by confirming that you control the email address on the account. We will not ask for more information than the verification actually needs, and we will not use anything you send for verification for any other purpose.
Response times. We acknowledge requests within 10 business days and respond substantively within 45 days. If a request is complex, we may extend that once by a further 45 days, and we will tell you before the first 45 days are up. Deletion, once we have verified you, is complete within 30 days as described above.
Complaints. If you are not satisfied with how we handled a request, you may complain to the Washington State Attorney General or the Nevada Attorney General.
8. How to contact us
AZEApps LLC
229 West Ash Street, Lombard, IL 60148
Consumer health data requests: privacidad@apptranqui.com
Email is the route for every right in Section 7. A person reads that address and acts on what arrives there.
For the full picture of what Tranqui collects and who receives it — including everything that is not consumer health data — read the Privacy Policy. This document covers consumer health data only, and the two are written to agree.