Privacy Policy

Last updated: July 20, 2026 — added an optional Apple Health integration on iOS: with your permission the App can write your completed meditation time to Apple Health as “Mindful Minutes” (write-only — we never read Health data, and it is never shared or used for advertising). Disclosed in § 1.6. Previous revision (June 16, 2026): added Apple Ads (App Store Search Ads) attribution to the iOS App via Apple's first-party AdServices framework and SKAdNetwork (no IDFA, no App Tracking Transparency prompt); the resulting campaign/keyword identifiers are recorded in our analytics to measure sign-ups and subscriptions per campaign. Disclosed in § 3 (sub-processor categories) and § 6 (“In the App”).

Comads OÜ (registry code 17276947), located at Ahtri St. 12, 15551 Tallinn, Estonia ("we", "us", or "our"), operates the Elynd mobile application ("the App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

By using Elynd, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the App.

1. Information We Collect

1.1 Information You Provide

When you create an account or use our App, you may provide us with:

1.2 Information Collected Automatically

When you use the App, we automatically collect certain information, including:

1.3 Analytics Data

We use Firebase Analytics (provided by Google) to collect anonymised usage data about how you interact with the App. This may include:

Analytics data is collected in aggregate and is used solely to understand usage patterns and improve the App. You can opt out of analytics data collection through your device settings.

1.4 AI-Generated Content Data

When the App generates personalised meditation content or provides AI-powered features, your inputs and preferences may be sent to our AI service providers for processing. We do not use your personal data to train AI models.

1.5 Health and Wellness Data

The App may collect wellness-related information such as meditation session history, session duration, mood and emotional state indicators, and personal progress data. Under the EU General Data Protection Regulation (GDPR), some of this information may be considered health-related data, which is a special category of personal data. We process this data based on your explicit consent, which you provide during the account registration process. This data is used solely to provide and personalise your meditation experience. You may withdraw your consent at any time by contacting us at [email protected]. Please note that withdrawing consent will limit or prevent access to core App features that rely on wellness data processing, such as personalised meditations and progress tracking. For information about refunds and cancellations, please refer to our Terms of Service.

1.6 Apple Health & Health Connect (optional)

If you turn on “Sync to Apple Health” (iOS) or “Sync to Health Connect” (Android, on devices where Health Connect supports mindfulness sessions), the App writes the length of each completed meditation to Apple Health as “Mindful Minutes” or to Health Connect as a mindfulness session. This feature is optional and off by default: it requires your explicit permission via the system permission prompt, and you can turn it off at any time in the App’s Settings, in the iOS Health app, or in the Health Connect app. The App only writes this data to the health store on your device — we never read any information from Apple Health or Health Connect, and this health data is never transmitted to our servers, used for advertising, or shared with any third party.

2. How We Use Your Information

We use the information we collect to:

3. Third-Party Services (Sub-processors)

We rely on a small number of carefully selected third-party vendors ("sub-processors") to operate the App. These vendors process personal data on our behalf, under contractual data-processing terms.

The authoritative, always-current list of our sub-processors — including each vendor's name, role, location, and legal transfer mechanism — is published at elynd.app/subprocessors. We maintain that page as the single source of truth so that the sub-processor list can be updated without a full Privacy Policy revision.

At a high level, our sub-processors fall into the following categories:

4. Data Storage and Security

Your data is stored and processed using the following infrastructure:

We implement appropriate technical and organisational measures to protect your personal data, including encrypted data transmission (HTTPS/TLS), secure authentication tokens, and access controls.

5. Legal Basis for Processing (GDPR)

6. Cookies and Website Tracking

In the App. The Elynd mobile app does not use browser cookies — native mobile apps do not have a cookie jar. Firebase Analytics and the Meta (Facebook) SDK use device identifiers and similar technologies to collect usage and app-event data; these are covered in the sub-processors list. The Meta SDK is used solely to measure and attribute our app-install advertising — on iOS via Apple's privacy-preserving SKAdNetwork (we do not request App Tracking Transparency and collect no IDFA), and on Android via the device advertising ID. On iOS we also use Apple's first-party AdServices framework to attribute Apple Ads (App Store Search Ads) campaigns — this likewise uses no IDFA and shows no App Tracking Transparency prompt; the campaign/keyword identifiers (never your name, email, mood notes, or session content) are recorded in our analytics to measure sign-ups and subscriptions per campaign. We do not display ads inside the App.

On this website (elynd.app). We operate a three-category consent model. When you first visit the site we show a banner, and nothing in the Analytics or Marketing categories runs until you make a choice.

We also apply Google Consent Mode v2: until you grant the relevant category, Google-family tags are instructed to deny storage and ad signals. If a category has never been populated with a provider ID in our configuration, no script for that category is loaded at all — not even after consent.

You can change your decision at any time via Cookie Settings. For the full, current list of cookies the website may set and the live status of each category, see our Cookie Policy. For the vendors that power these categories, see the sub-processors page.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our services. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.

8. Your Rights

Under the EU General Data Protection Regulation (GDPR) and other applicable laws, you have the right to:

To exercise any of these rights, contact us at [email protected].

9. Children's Privacy

The App is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16.

10. International Data Transfers

Comads OÜ is established in Estonia (EU), and our application backend (API servers, object storage of meditation-session audio, and content delivery) is hosted in the European Union — specifically in Frankfurt, Germany, on Amazon Web Services. That processing therefore remains within the European Economic Area (EEA).

Some of your data is, however, transferred to and processed in countries outside the EEA — specifically the United States — where Google's infrastructure (Firebase and the Gemini API), OpenAI's servers, our text-to-speech service providers, and Meta (for app-install ad attribution) are located. Where such transfers occur, we ensure appropriate safeguards are in place, including the EU-U.S. Data Privacy Framework (DPF) for transfers to certified U.S. organisations, and Standard Contractual Clauses (SCCs) approved by the European Commission.

The per-vendor location and transfer mechanism is listed on our sub-processors page.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, contact us:

Email: [email protected]

Address: Comads OÜ, Ahtri St. 12, 15551 Tallinn, Estonia

Registry code: 17276947