Who we are and our roles
wellnizz is the operating name for this website, the API at app.wellnizz.com, and the developer dashboard. For visitors to this site and people who open a developer account directly with us, wellnizz decides how data is handled and acts as the controller. When a developer or organization sends their own users' data to the API, wellnizz processes it on that customer's behalf and under their instructions, as a processor. A data processing agreement for that relationship is available on request at privacy@wellnizz.com.
Data residency
Genetic, biomarker, and wearable records are stored on EU-hosted infrastructure. The service does not require processing personal health data in the United States, and any future processor has to meet the same data-residency and consent model.
Consent
Genetic and blood-derived data are special-category personal data. They are processed only with explicit, informed consent. People should know what is collected, why it is processed, how long it is kept, how to export it, and how to request deletion before anything is uploaded. Consent can be withdrawn at any time; withdrawal stops future processing, and existing data can be deleted on request.
Legal bases
Account, organization, and billing details are processed to provide the service you signed up for (Art. 6(1)(b) GDPR). Security controls, audit logs, and abuse prevention rest on our legitimate interest in running the service safely (Art. 6(1)(f)). Health and genetic data are processed only on the basis of explicit consent (Art. 9(2)(a)) — given directly to us, or collected from their users by the developer whose product sends the data.
What we process
- ✓Account and organization details for the developer holding an API key.
- ✓Genetic files (VCF and WGS, 23andMe, AncestryDNA) sent to the import endpoints.
- ✓Blood biomarker panels (CSV or JSON) sent for analysis.
- ✓Wearable metrics synced from WHOOP, Oura, Apple Health, and Google Health Connect with the person's authorization.
- ✓No payment card data is stored by wellnizz; billing runs through our payment processor.
Retention
Data is kept while the associated account or organization is active, and removed from live systems when you delete it, use the deletion endpoints, or close the account. Residual copies in encrypted backups expire on a rolling schedule. Minimal billing records are kept only as long as tax and accounting law requires.
Security
Access is gated by scoped API keys carrying per-endpoint and per-org claims. Data is encrypted at rest, processing is isolated per organization, and every request is written to an audit log. Keys can be revoked or re-scoped at any time.
Your rights
Every user has deletion and export endpoints, and health and genetic data is never sold or shared for advertising. Under the GDPR you can also request access, rectification, erasure, restriction, and portability, object to processing based on legitimate interests, and withdraw consent at any time — email privacy@wellnizz.com or use the in-product endpoints. You additionally have the right to lodge a complaint with your local data protection supervisory authority.
Service providers
A small set of providers supports the product:
- ✓Cloudflare serves this website and provides network security.
- ✓An EU infrastructure provider hosts the API and the encrypted data stores.
- ✓Stripe processes payments for paid plans; card data never touches wellnizz.
- ✓Mintlify hosts the documentation site, which handles no health data.
- ✓The OpenStreetMap Foundation provides map tiles and Nominatim place search for Find a Lab. These requests go directly from your browser to provider-operated infrastructure.
Find a Lab location privacy
Opening Find a Lab loads OpenStreetMap tiles, which gives the OpenStreetMap Foundation the usual web-request data such as your IP address, browser details, referrer, and the requested map area. If you search by city or postcode, the text you enter is sent directly to the Foundation's Nominatim service to return coordinates. If you choose Use my location, your browser asks permission first; the resulting coordinates are used in your browser to rank the bundled lab snapshot and are not sent to wellnizz. The map tile requests will still reveal the map area being viewed. wellnizz does not store these searches or coordinates. We use these services under our legitimate interest in providing the map you requested; you can browse the provider directory without granting precise-location access.
International transfers
Health and genetic records are stored in the EU. This website is delivered through Cloudflare's global network, which caches pages and assets worldwide but carries none of your health data. Find a Lab map and location-search requests go directly to OpenStreetMap Foundation infrastructure, a UK-based provider, and are governed by its privacy notice. Where another provider processes limited account data outside the EEA, we rely on recognized safeguards such as adequacy decisions or the EU standard contractual clauses.
Cookies and tracking
This website sets no cookies and runs no advertising or cross-site trackers, which is why there is no cookie banner. If we measure traffic, we use cookie-less, non-profiling analytics (Cloudflare Web Analytics). The developer dashboard at app.wellnizz.com uses only what is strictly necessary to keep you signed in.
Automated analysis
The analysis itself is automated — that is the product. Results are wellness observations and interpretations with sources, not decisions with legal or similarly significant effects, so no automated decision-making under Art. 22 GDPR takes place. Output must not be used to gate employment, insurance, credit, or medical care.
Wearables and Health Connect
Wearable syncs, including Android Health Connect, read only the data types a person explicitly authorizes — activity, heart, sleep, body, and related metrics. Access is permission-gated and user-initiated, transmitted over encrypted connections, never sold, and never used for advertising. Syncing can be stopped or disconnected at any time in the app or in Health Connect settings.
Medical limitation
wellnizz provides wellness and healthspan insights. It is not a medical diagnosis, a medical device, a prescription, or a substitute for a licensed clinician. High-stakes findings should be confirmed clinically.
Age, and changes to this notice
The service is intended for adults, 18 and over. When this notice changes, the date at the top changes with it, and substantive changes are called out on this page.