H2U

Privacy Policy

Effective 12 September 2026 Version 1.0 Applies to the H2U Android app and h2u.tennightlabs.com

1Who we are

H2U is a hydration tracking app for two people. You log what you drink; if you pair with a partner, each of you can see the other's daily progress and send short encouragements.

The controller of your personal data — the party that decides why and how it is processed — is:

ControllerNaman Mehta, trading as Ten Night Labs — a sole proprietor established in Japan
Postal address205-Cracia22, 2-11 Kita 22, Nishi 2, Kita-ku, Sapporo, Hokkaido 001-0022, Japan
Privacy contact[email protected]
Data protection officerNot appointed. Our processing does not meet the thresholds in GDPR Art. 37; the contact above reaches the person responsible for privacy.

Throughout this policy, "we" and "us" mean that entity, and "you" means the person using the app. It covers the H2U Android app and our website. It does not cover Google or any other service you reach from the app, each of which has its own policy.

2Summary at a glance

The detail follows, and the detail is what binds us. This is only an orientation. If you read nothing else, read §5, health data and your consent, and §10, how long we keep data — those cover the parts of this policy that are unusual.

We collect health dataYour sex, age, height, weight, activity level and hydration record. This is special category data and we ask for your explicit consent before collecting it.
We do not sell your dataWe do not sell or share personal data for advertising, cross-context behavioural advertising, or any other value. The app carries no advertising.
We run no analytics or ad SDKsNo Google Analytics, no attribution SDK, no advertising identifier. A deliberate choice, not an oversight.
Your partner sees totals, not detailA paired partner sees your daily total and whether you met your goal — not your individual drinks, and none of your body metrics.
You can delete your accountFrom inside the app, or from our website. Two irreversible hashes survive it, and §10 explains exactly what and why.
The camera never uploadsQR pairing decodes frames on your device. No image or video ever leaves your phone.
This is not medical adviceYour daily target is general wellness guidance calculated from figures you enter. It is not medical advice and must not be relied on for any health condition.

3What we collect

Everything below is data the app actually stores. It is listed by category rather than by database table, but every category corresponds to real fields, and nothing has been padded with things we might collect one day.

Account and identity

Health and body data

This is the category that matters most, and §5 deals with it separately.

Your daily routine

We store the wake and sleep times you set, so reminders arrive while you are awake, and your time zone, so a "day" means your day and not ours.

We want to be plain about this, because it is more revealing than it looks: taken together, these fields describe the hours you are usually awake. We use them only to schedule reminders and to draw the day boundary correctly. We do not use them to infer anything else about you, and they are not shared with your partner or anyone else.

Pairing and messages

Device and technical data

Subscription data

If you subscribe, our payments provider gives us a subscriber identifier, which plan you bought, whether it is active, which store processed it and when it expires. It also records any free trial or coupon you redeemed. We never see your card number. Payment is handled entirely by Google Play.

Our website

Our web pages — the home page, this policy, our terms, the invite links and the account deletion page — set no cookies and carry no analytics, advertising or tracking scripts. They make no requests to any third party at all, including for typefaces, so visiting them discloses your IP address to nobody but our web host. There is no cookie banner because there is nothing to consent to. Our web host records standard server logs, including your IP address and request time, for a short period for security and diagnostics.

Because we do not track you across sites, there is nothing for a "Do Not Track" or Global Privacy Control signal to switch off. We honour them by default: we do not sell or share personal information, and we use no cross-site advertising technology.

What we do not collect

4Why we use it, and our lawful basis

If you are in the EEA, the UK or another jurisdiction that requires it, we must have a lawful basis for each purpose. Here they are, one row per purpose.

What we doData usedLawful basis
Create and secure your accountEmail, Google account ID, display nameContract — we cannot provide the app without an account
Calculate your recommended daily intakeSex, age, height, weight, activity level, climateExplicit consent (GDPR Art. 9(2)(a))
Record your hydration and show your progressDrink logs, daily totals, goalExplicit consent for the health element; contract for delivering the service
Show your progress to a partner you paired withDaily total, goal-met status, display name, avatarContract — pairing is a feature you chose, and either of you can end it
Send and receive nudgesNudge text, sender and recipient, push tokenContract
Send reminders at sensible timesWake and sleep times, time zone, push tokenConsent — you grant notification permission, and can withdraw it in your device settings
Keep the app working and diagnose crashesCrash traces, device model, OS versionLegitimate interests — an app that crashes serves nobody
Prevent abuse of free trials and pairing rewardsAn irreversible hash of your email address (see §10)Legitimate interests — fraud prevention, which GDPR Recital 47 recognises
Enforce blocksBlock recordsLegitimate interests — protecting users from unwanted contact
Manage subscriptions and trialsSubscriber ID, entitlement, status, expiryContract; and legal obligation for tax records
Respond to your support and rights requestsYour email and whatever you tell usLegal obligation where it is a data protection right; otherwise legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and concluded ours do not override yours. You can object to any of it — §12 explains how, and we will explain our reasoning if you ask.

We do not use your data for automated decision-making that has a legal or similarly significant effect on you. The daily intake calculation is automated, but it is a suggestion you can override, not a decision about you.

5Health data and your consent

Your sex, age, height, weight, activity level and hydration record are data concerning health under Article 9 of the GDPR, and comparable categories under other laws. That places them in a stricter class than ordinary personal data, and we treat them accordingly.

Before we collect any of it, the app asks you to consent explicitly, in a separate step requiring a deliberate action of your own. We record the fact and time of that consent. We do not treat installing the app, signing in, or tapping through a screen as consent to health data processing.

You can withdraw that consent at any time, in Settings. Withdrawal takes effect from that moment: it does not undo processing that was lawful when it happened, but it stops processing going forward, and we erase the body metrics we hold. Withdrawing means we can no longer calculate a personalised target — you can set one yourself instead, or delete your account entirely.

H2U is not a medical service

Your recommended daily intake is general wellness guidance derived from the figures you enter and published population estimates. It is not medical advice, H2U is not a medical device, and it does not diagnose, treat, cure or prevent any condition. Do not rely on it if you have a heart, kidney or liver condition, if you are pregnant, if you take medication affecting fluid balance, or if a clinician has given you a specific fluid target. Their advice governs, not ours.

HIPAA does not apply — and we do not claim it does

HIPAA binds healthcare providers, insurers, clearinghouses and their business associates. H2U is a direct-to-consumer wellness app and is none of those. Any app in this category advertising "HIPAA compliance" is telling you something that does not mean what it sounds like.

6What your partner can see

Pairing is optional. The app is fully usable alone, and you are never required to pair to keep using it.

When you are paired, your partner sees:

Your partner does not see:

This is enforced in the database, not merely hidden in the interface. Partners read from a daily-totals table and have no access path to the underlying log rows, and the seven-day boundary is applied when the pairing is created rather than filtered in the app.

You can unpair at any time, from Settings, without your partner's agreement. Unpairing stops all future sharing immediately and removes their access to your past totals. Figures they have already seen are facts we cannot retrieve from their memory, but they lose access from that point on.

7Nudges and user content

A nudge is a short message — up to 140 characters — that you send to your partner as a notification. It is content you write, sent to another person, so a few things follow.

There is no in-app reporting route today. If someone sends you unwanted nudges, block them — blocking stops all contact immediately — or write to us.

8Who we share data with

We name every recipient. We do not use phrases like "trusted partners" or "selected third parties", because they tell you nothing.

We do not sell your personal data, and we do not share it for advertising of any kind.

RecipientWhat it receivesWhy
SupabaseAll the data in §3, other than crash reports and payment recordsOur database, authentication and backend hosting. Acts on our instructions as a processor.
Google — Firebase Cloud MessagingYour push token, device platform, and the content of notifications we send youThe only route by which a notification reaches an Android device.
Google — Firebase CrashlyticsCrash traces, device model, OS version, a device identifierDiagnosing crashes.
Google — Sign-InYour sign-in requestIf you choose Google sign-in. Google processes this for its own purposes as an independent controller, under its own policy.
Google FontsYour IP address, when the app startsThe app loads its typeface from Google's servers at launch, which discloses your IP address to Google. We intend to bundle the typeface so this request stops; until then, we disclose it.
Google PlayThe install referrerSo an invite link still works after you install from the store.
RevenueCatA subscriber identifier, your purchases and entitlement statusManaging subscriptions. It does not receive your health data.
Google PlayYour payment details, directlyGoogle processes the payment. We never receive your card details.
Your paired partnerOnly what §6 listsBecause you chose to pair.

We may also disclose data where the law requires it — a valid court order, a lawful request from an authority — or to establish or defend legal claims. We will tell you if that happens, unless prohibited. If the business is ever sold or merged, your data may transfer to the acquirer, who will be bound by this policy until you are given notice of any change.

9International transfers

Our database is hosted in the ap-northeast-1 (Tokyo) region. Our other providers process data in the United States and elsewhere.

We are established in Japan, which the European Commission has recognised as providing an adequate level of data protection. Personal data reaching us from the EEA therefore transfers on the basis of that adequacy decision, without needing Standard Contractual Clauses.

Where data goes on to providers outside Japan and the EEA, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures in §15. Where a provider states it is certified under the EU–US Data Privacy Framework, we rely on that framework in addition to the clauses above.

You can ask us for a copy of the safeguards applying to any specific transfer.

10How long we keep data

DataKept for
Account, profile and body metricsWhile your account exists. Erased on deletion.
Drink logs and daily totalsWhile your account exists. Erased on deletion.
NudgesWhile your account exists. Erased on deletion.
Invite codesQR codes expire after 15 minutes; shareable links after 7 days. Expired unredeemed invites are deleted automatically.
Pairing recordsErased when you unpair or delete your account.
BlocksUntil you remove the block, or your account is deleted.
Push tokensUntil replaced, until notifications are disabled, or until the account is deleted.
Crash reports90 days.
Subscription and payment records7 years after the subscription ends, because tax law requires transaction records.
Support correspondence24 months after the matter is closed.
BackupsDeleted data persists in encrypted backups until they rotate out.
Two anti-abuse email hashesSurvive account deletion, then deleted after 3 years. See below.

The two things that survive deletion

We are specific about this rather than letting "we delete everything" stand as a claim we cannot honour. Both are one-way hashes of your email address. Neither can be turned back into it, neither is used to contact you, and neither builds any profile of you.

1. So a reward cannot be claimed twice. H2U gives a free trial and a pairing reward, once per person. To stop the same person claiming them repeatedly by deleting and re-registering, we keep a hash of your address with the date it was claimed and the reason.

2. So a block cannot be escaped. If someone blocked you, a hash of your address stays on that block after your account is deleted. Without it, deleting your account would clear every block against you and let you reach the person again — which would make blocking meaningless for the person who relied on it.

For both:

Three years is a deliberate number rather than a round one. What these hashes prevent is worth about five weeks of free premium, and nobody waits three years to collect that — so a longer period would add no real protection while holding your data for longer. We would rather keep less.

Our lawful basis is legitimate interests: preventing fraud for the first, and protecting another user from unwanted contact for the second. Because both exist to prevent harm, we may retain them even after an erasure request — GDPR Art. 17(3) permits retention where necessary for establishing or defending legal claims and for overriding legitimate grounds. The block hash in particular protects a different person's safety, and their interest weighs against your erasure request. If you object, tell us and we will review it against your circumstances and tell you what we decide.

11Deleting your account

Two routes, neither of which requires you to email us:

When you delete your account:

If you want only part of your data removed rather than the whole account, ask us — §12 covers that.

12Your rights

Depending on where you live, you have some or all of the following. We honour them for everyone, regardless of location, because operating two standards is a way of getting one of them wrong.

RightWhat it meansHow to use it
AccessA copy of the personal data we hold about youEmail us; we reply with a machine-readable copy
RectificationCorrect anything inaccurateMost fields are editable in Settings; email us for the rest
ErasureDelete your dataSettings, then Delete account, or the deletion page on our website. See §11 for the exception.
PortabilityYour data in a structured, common format you can take elsewhereEmail us; we provide JSON
RestrictionFreeze processing while a dispute is resolvedEmail us
ObjectionObject to processing based on legitimate interestsEmail us, saying which processing and why
Withdraw consentStop health data processing, or turn off notificationsSettings for health data; device settings for notifications
ComplainRaise it with a regulatorSee §18

Write to [email protected] and tell us which right you want to use and which data it concerns. We respond within 30 days, and will tell you if a request is genuinely complex enough to need longer.

We will verify who you are before we act. Normally that means writing from the email address on your account, since handing someone else's hydration and body data to whoever asks would be a breach in itself. If we cannot match your request to an account, we may ask for one further piece of information — and we will not use it for anything else. An authorised agent may act for you with written proof of their authority.

Two limits worth stating plainly. We may keep records we are legally required to keep, such as payment records, even after an erasure request. And a request made mid-transaction — a subscription being processed, for instance — takes effect once that transaction completes.

Exercising any of these rights is free, and we will never treat you differently — no degraded service, no different price, no missing features — for having done so.

13Regional information

European Economic Area and United Kingdom

The rights in §12 are your rights under the GDPR and UK GDPR. Our lawful bases are in §4, and our transfer safeguards in §9. Health data is processed on the basis of your explicit consent under Art. 9(2)(a), which you can withdraw at any time.

You may complain to your national supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA, you may complain to the authority where you live, where you work, or where the alleged infringement took place; the list is at edpb.europa.eu.

India

Under the Digital Personal Data Protection Act 2023, we process your personal data on the basis of the consent described in §4 and §5, or for the legitimate uses the Act permits. You have the right to access a summary of your data, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance redressal mechanism. Contact us first; if we do not resolve your grievance, you may complain to the Data Protection Board of India.

California and other US states

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

California residents may request to know the categories and specific pieces of personal information we have collected, its sources, our purposes, and the categories of third parties to whom it is disclosed; may request deletion and correction; and may limit the use of sensitive personal information. Your health and body metrics are sensitive personal information under the CCPA/CPRA — we use them only to provide the service you asked for, but you can withdraw consent under §5 and we will erase them. We do not discriminate against anyone exercising these rights. An authorised agent may act for you with written proof.

Residents of Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws have broadly equivalent rights, including a right to appeal a refusal. To appeal, reply to our decision and we will review it and respond within 45 days.

14Children and minimum age

H2U is for people aged 16 and over. The app is not directed at children, it is not listed in a children's category, and we do not knowingly collect personal data from anyone under 16.

We chose 16 rather than 13 deliberately. Several EU member states set the age of digital consent at 16, and health data raises the stakes of getting it wrong. A single threshold satisfying the strictest applicable rule is safer than one that varies by country.

If we learn that someone under 16 has created an account, we delete it and the data with it. If you believe a child has given us personal data, write to us and we will act promptly.

15How we protect your data

No system is perfectly secure, and we will not pretend otherwise. What we can say is that the measures above are the ones actually implemented, not aspirations.

16If something goes wrong

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as the GDPR requires.

If the breach is likely to result in a high risk to you, we will tell you directly and without undue delay — by email and in the app — describing what happened, what data was involved, what we are doing about it, and what you should do.

Given that we hold health data, we will treat any incident involving it as high risk unless we have clear evidence otherwise.

17Changes to this policy

We update this policy when what we do changes. Every version carries an effective date and version number at the top.

Previous versions are available on request.

18Contact us and complain

For anything in this policy, including any request under §12:

Email[email protected]
PostNaman Mehta, trading as Ten Night Labs
205-Cracia22, 2-11, kita22, nishi2, kita-ku, Sapporo, Hokkaido, Japan 001-0022
Response timeWithin 30 days, usually much sooner

If you want to complain about how we have handled your data, say so and we will treat it as a complaint rather than a query. We will respond to a complaint within 45 days.

If you are not satisfied with our response, you can complain to a data protection authority. You do not have to come to us first, though we would rather you did — most complaints are misunderstandings we can fix in a day.