Privacy Policy
Last updated: August 2026
Renova Wellness is a wellbeing platform operated by Trinity Wellness LLC, a Maryland registered limited liability company ("Trinity Wellness", "we", "us"). Organizations license the platform and deploy it to their members under their own name and branding. This Policy explains how we handle information in the Renova Wellness mobile application and on this website (together, the "Service"), whichever brand you encountered it under.
Trinity Wellness is the operator of the Service. The organization that licensed it (your employer, benefits broker, school or coach) is responsible for deciding to offer it to you and for the branding you see, but it does not receive your individual health data from us (see section 4).
1. Information we collect
- Account information: name, email address, and authentication credentials.
- Organization membership: which licensing organization your account belongs to, and any group or cohort you are enrolled in.
- Health and activity data: information you record or choose to sync, which may include sleep, heart rate and heart rate variability, steps, workouts, and nutrition entries.
- Connected sources: where you explicitly authorize a connection, data from third-party sources such as Oura or Apple Health. These connections are optional and can be revoked at any time.
- Content you create: notes, check-ins, and any posts or comments in community features where those are enabled.
- Device and usage data: device type, operating system version, app interactions, and diagnostic or crash logs.
2. How we use information
3. Legal bases and consent
4. What the licensing organization can see
A licensing organization can see aggregate, de-identified information about its deployment, such as how many people enrolled, how many are active, and participation trends over time. Where an aggregate figure would be small enough to identify an individual, we withhold or suppress it.
A licensing organization cannot see an individual member's health metrics, sleep or recovery data, nutrition entries, private notes, or individual app activity. We do not provide employers or brokers with individual-level health reporting, and we will not do so on request.
5. Service providers
We use a limited set of providers to run the Service. Each processes data only as needed to provide its function:
- Cloud database, authentication, and file storage hosting.
- Push notification delivery.
- Product analytics and crash reporting.
- An AI provider, where AI-assisted guidance features are enabled for your deployment.
- Oura and Apple Health, only where you have authorized a connection.
We will provide a current, named subprocessor list to any licensing organization or member on request at joshua@trinitywellness.co.
6. Security
Data is encrypted in transit using TLS and encrypted at rest by our hosting provider. Access to production data is restricted to personnel who need it to operate or support the Service, and is authenticated individually.
Trinity Wellness does not currently hold SOC 2, ISO 27001, or HIPAA certification or attestation, and nothing in this Policy should be read as claiming one. We describe our actual practices and will answer security questionnaires directly.