H2U
H2U is a hydration tracking app for two people. You log what you drink; if you pair with a partner, each of you can see the other's daily progress and send short encouragements.
The controller of your personal data — the party that decides why and how it is processed — is:
| Controller | Naman Mehta, trading as Ten Night Labs — a sole proprietor established in Japan |
| Postal address | 205-Cracia22, 2-11 Kita 22, Nishi 2, Kita-ku, Sapporo, Hokkaido 001-0022, Japan |
| Privacy contact | privacy@tennightlabs.com |
| Data protection officer | Not appointed. Our processing does not meet the thresholds in GDPR Art. 37; the contact above reaches the person responsible for privacy. |
Throughout this policy, "we" and "us" mean that entity, and "you" means the person using the app. It covers the H2U Android app and our website. It does not cover Google or any other service you reach from the app, each of which has its own policy.
The detail follows, and the detail is what binds us. This is only an orientation. If you read nothing else, read §5, health data and your consent, and §10, how long we keep data — those cover the parts of this policy that are unusual.
| We collect health data | Your sex, age, height, weight, activity level and hydration record. This is special category data and we ask for your explicit consent before collecting it. |
| We do not sell your data | We do not sell or share personal data for advertising, cross-context behavioural advertising, or any other value. The app carries no advertising. |
| We run no analytics or ad SDKs | No Google Analytics, no attribution SDK, no advertising identifier. A deliberate choice, not an oversight. |
| Your partner sees totals, not detail | A paired partner sees your daily total and whether you met your goal — not your individual drinks, and none of your body metrics. |
| You can delete your account | From inside the app, or from our website. Two irreversible hashes survive it, and §10 explains exactly what and why. |
| The camera never uploads | QR pairing decodes frames on your device. No image or video ever leaves your phone. |
| This is not medical advice | Your daily target is general wellness guidance calculated from figures you enter. It is not medical advice and must not be relied on for any health condition. |
Everything below is data the app actually stores. It is listed by category rather than by database table, but every category corresponds to real fields, and nothing has been padded with things we might collect one day.
This is the category that matters most, and §5 deals with it separately.
We store the wake and sleep times you set, so reminders arrive while you are awake, and your time zone, so a "day" means your day and not ours.
We want to be plain about this, because it is more revealing than it looks: taken together, these fields describe the hours you are usually awake. We use them only to schedule reminders and to draw the day boundary correctly. We do not use them to infer anything else about you, and they are not shared with your partner or anyone else.
If you subscribe, our payments provider gives us a subscriber identifier, which plan you bought, whether it is active, which store processed it and when it expires. It also records any free trial or coupon you redeemed. We never see your card number. Payment is handled entirely by Google Play.
Our web pages — the home page, this policy, our terms, the invite links and the account deletion page — set no cookies and carry no analytics, advertising or tracking scripts. They make no requests to any third party at all, including for typefaces, so visiting them discloses your IP address to nobody but our web host. There is no cookie banner because there is nothing to consent to. Our web host records standard server logs, including your IP address and request time, for a short period for security and diagnostics.
Because we do not track you across sites, there is nothing for a "Do Not Track" or Global Privacy Control signal to switch off. We honour them by default: we do not sell or share personal information, and we use no cross-site advertising technology.
If you are in the EEA, the UK or another jurisdiction that requires it, we must have a lawful basis for each purpose. Here they are, one row per purpose.
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and secure your account | Email, Google account ID, display name | Contract — we cannot provide the app without an account |
| Calculate your recommended daily intake | Sex, age, height, weight, activity level, climate | Explicit consent (GDPR Art. 9(2)(a)) |
| Record your hydration and show your progress | Drink logs, daily totals, goal | Explicit consent for the health element; contract for delivering the service |
| Show your progress to a partner you paired with | Daily total, goal-met status, display name, avatar | Contract — pairing is a feature you chose, and either of you can end it |
| Send and receive nudges | Nudge text, sender and recipient, push token | Contract |
| Send reminders at sensible times | Wake and sleep times, time zone, push token | Consent — you grant notification permission, and can withdraw it in your device settings |
| Keep the app working and diagnose crashes | Crash traces, device model, OS version | Legitimate interests — an app that crashes serves nobody |
| Prevent abuse of free trials and pairing rewards | An irreversible hash of your email address (see §10) | Legitimate interests — fraud prevention, which GDPR Recital 47 recognises |
| Enforce blocks | Block records | Legitimate interests — protecting users from unwanted contact |
| Manage subscriptions and trials | Subscriber ID, entitlement, status, expiry | Contract; and legal obligation for tax records |
| Respond to your support and rights requests | Your email and whatever you tell us | Legal obligation where it is a data protection right; otherwise legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and concluded ours do not override yours. You can object to any of it — §12 explains how, and we will explain our reasoning if you ask.
We do not use your data for automated decision-making that has a legal or similarly significant effect on you. The daily intake calculation is automated, but it is a suggestion you can override, not a decision about you.
Your sex, age, height, weight, activity level and hydration record are data concerning health under Article 9 of the GDPR, and comparable categories under other laws. That places them in a stricter class than ordinary personal data, and we treat them accordingly.
Before we collect any of it, the app asks you to consent explicitly, in a separate step requiring a deliberate action of your own. We record the fact and time of that consent. We do not treat installing the app, signing in, or tapping through a screen as consent to health data processing.
You can withdraw that consent at any time, in Settings. Withdrawal takes effect from that moment: it does not undo processing that was lawful when it happened, but it stops processing going forward, and we erase the body metrics we hold. Withdrawing means we can no longer calculate a personalised target — you can set one yourself instead, or delete your account entirely.
Your recommended daily intake is general wellness guidance derived from the figures you enter and published population estimates. It is not medical advice, H2U is not a medical device, and it does not diagnose, treat, cure or prevent any condition. Do not rely on it if you have a heart, kidney or liver condition, if you are pregnant, if you take medication affecting fluid balance, or if a clinician has given you a specific fluid target. Their advice governs, not ours.
HIPAA binds healthcare providers, insurers, clearinghouses and their business associates. H2U is a direct-to-consumer wellness app and is none of those. Any app in this category advertising "HIPAA compliance" is telling you something that does not mean what it sounds like.
Pairing is optional. The app is fully usable alone, and you are never required to pair to keep using it.
When you are paired, your partner sees:
Your partner does not see:
This is enforced in the database, not merely hidden in the interface. Partners read from a daily-totals table and have no access path to the underlying log rows, and the seven-day boundary is applied when the pairing is created rather than filtered in the app.
You can unpair at any time, from Settings, without your partner's agreement. Unpairing stops all future sharing immediately and removes their access to your past totals. Figures they have already seen are facts we cannot retrieve from their memory, but they lose access from that point on.
A nudge is a short message — up to 140 characters — that you send to your partner as a notification. It is content you write, sent to another person, so a few things follow.
There is no in-app reporting route today. If someone sends you unwanted nudges, block them — blocking stops all contact immediately — or write to us.
Our database is hosted in the ap-northeast-1 (Tokyo) region. Our other providers process data in the United States and elsewhere.
We are established in Japan, which the European Commission has recognised as providing an adequate level of data protection. Personal data reaching us from the EEA therefore transfers on the basis of that adequacy decision, without needing Standard Contractual Clauses.
Where data goes on to providers outside Japan and the EEA, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures in §15. Where a provider states it is certified under the EU–US Data Privacy Framework, we rely on that framework in addition to the clauses above.
You can ask us for a copy of the safeguards applying to any specific transfer.
| Data | Kept for |
|---|---|
| Account, profile and body metrics | While your account exists. Erased on deletion. |
| Drink logs and daily totals | While your account exists. Erased on deletion. |
| Nudges | While your account exists. Erased on deletion. |
| Invite codes | QR codes expire after 15 minutes; shareable links after 7 days. Expired unredeemed invites are deleted automatically. |
| Pairing records | Erased when you unpair or delete your account. |
| Blocks | Until you remove the block, or your account is deleted. |
| Push tokens | Until replaced, until notifications are disabled, or until the account is deleted. |
| Crash reports | 90 days. |
| Subscription and payment records | 7 years after the subscription ends, because tax law requires transaction records. |
| Support correspondence | 24 months after the matter is closed. |
| Backups | Deleted data persists in encrypted backups until they rotate out. |
| Two anti-abuse email hashes | Survive account deletion, then deleted after 3 years. See below. |
We are specific about this rather than letting "we delete everything" stand as a claim we cannot honour. Both are one-way hashes of your email address. Neither can be turned back into it, neither is used to contact you, and neither builds any profile of you.
1. So a reward cannot be claimed twice. H2U gives a free trial and a pairing reward, once per person. To stop the same person claiming them repeatedly by deleting and re-registering, we keep a hash of your address with the date it was claimed and the reason.
2. So a block cannot be escaped. If someone blocked you, a hash of your address stays on that block after your account is deleted. Without it, deleting your account would clear every block against you and let you reach the person again — which would make blocking meaningless for the person who relied on it.
For both:
Three years is a deliberate number rather than a round one. What these hashes prevent is worth about five weeks of free premium, and nobody waits three years to collect that — so a longer period would add no real protection while holding your data for longer. We would rather keep less.
Our lawful basis is legitimate interests: preventing fraud for the first, and protecting another user from unwanted contact for the second. Because both exist to prevent harm, we may retain them even after an erasure request — GDPR Art. 17(3) permits retention where necessary for establishing or defending legal claims and for overriding legitimate grounds. The block hash in particular protects a different person's safety, and their interest weighs against your erasure request. If you object, tell us and we will review it against your circumstances and tell you what we decide.
Two routes, neither of which requires you to email us:
When you delete your account:
If you want only part of your data removed rather than the whole account, ask us — §12 covers that.
Depending on where you live, you have some or all of the following. We honour them for everyone, regardless of location, because operating two standards is a way of getting one of them wrong.
| Right | What it means | How to use it |
|---|---|---|
| Access | A copy of the personal data we hold about you | Email us; we reply with a machine-readable copy |
| Rectification | Correct anything inaccurate | Most fields are editable in Settings; email us for the rest |
| Erasure | Delete your data | Settings, then Delete account, or the deletion page on our website. See §11 for the exception. |
| Portability | Your data in a structured, common format you can take elsewhere | Email us; we provide JSON |
| Restriction | Freeze processing while a dispute is resolved | Email us |
| Objection | Object to processing based on legitimate interests | Email us, saying which processing and why |
| Withdraw consent | Stop health data processing, or turn off notifications | Settings for health data; device settings for notifications |
| Complain | Raise it with a regulator | See §18 |
Write to privacy@tennightlabs.com and tell us which right you want to use and which data it concerns. We respond within 30 days, and will tell you if a request is genuinely complex enough to need longer.
We will verify who you are before we act. Normally that means writing from the email address on your account, since handing someone else's hydration and body data to whoever asks would be a breach in itself. If we cannot match your request to an account, we may ask for one further piece of information — and we will not use it for anything else. An authorised agent may act for you with written proof of their authority.
Two limits worth stating plainly. We may keep records we are legally required to keep, such as payment records, even after an erasure request. And a request made mid-transaction — a subscription being processed, for instance — takes effect once that transaction completes.
Exercising any of these rights is free, and we will never treat you differently — no degraded service, no different price, no missing features — for having done so.
The rights in §12 are your rights under the GDPR and UK GDPR. Our lawful bases are in §4, and our transfer safeguards in §9. Health data is processed on the basis of your explicit consent under Art. 9(2)(a), which you can withdraw at any time.
You may complain to your national supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). In the EEA, you may complain to the authority where you live, where you work, or where the alleged infringement took place; the list is at edpb.europa.eu.
Under the Digital Personal Data Protection Act 2023, we process your personal data on the basis of the consent described in §4 and §5, or for the legitimate uses the Act permits. You have the right to access a summary of your data, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance redressal mechanism. Contact us first; if we do not resolve your grievance, you may complain to the Data Protection Board of India.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
California residents may request to know the categories and specific pieces of personal information we have collected, its sources, our purposes, and the categories of third parties to whom it is disclosed; may request deletion and correction; and may limit the use of sensitive personal information. Your health and body metrics are sensitive personal information under the CCPA/CPRA — we use them only to provide the service you asked for, but you can withdraw consent under §5 and we will erase them. We do not discriminate against anyone exercising these rights. An authorised agent may act for you with written proof.
Residents of Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws have broadly equivalent rights, including a right to appeal a refusal. To appeal, reply to our decision and we will review it and respond within 45 days.
H2U is for people aged 16 and over. The app is not directed at children, it is not listed in a children's category, and we do not knowingly collect personal data from anyone under 16.
We chose 16 rather than 13 deliberately. Several EU member states set the age of digital consent at 16, and health data raises the stakes of getting it wrong. A single threshold satisfying the strictest applicable rule is safer than one that varies by country.
If we learn that someone under 16 has created an account, we delete it and the data with it. If you believe a child has given us personal data, write to us and we will act promptly.
No system is perfectly secure, and we will not pretend otherwise. What we can say is that the measures above are the ones actually implemented, not aspirations.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as the GDPR requires.
If the breach is likely to result in a high risk to you, we will tell you directly and without undue delay — by email and in the app — describing what happened, what data was involved, what we are doing about it, and what you should do.
Given that we hold health data, we will treat any incident involving it as high risk unless we have clear evidence otherwise.
We update this policy when what we do changes. Every version carries an effective date and version number at the top.
Previous versions are available on request.
For anything in this policy, including any request under §12:
| privacy@tennightlabs.com | |
| Post | Naman Mehta, trading as Ten Night Labs 205-Cracia22, 2-11, kita22, nishi2, kita-ku, Sapporo, Hokkaido, Japan 001-0022 |
| Response time | Within 30 days, usually much sooner |
If you want to complain about how we have handled your data, say so and we will treat it as a complaint rather than a query. We will respond to a complaint within 45 days.
If you are not satisfied with our response, you can complain to a data protection authority. You do not have to come to us first, though we would rather you did — most complaints are misunderstandings we can fix in a day.
edpb.europa.eu lists them)ico.org.uk