← Back to Alba home

Privacy Policy

Last updated: July 15, 2026 / Effective date: June 10, 2026

1. Introduction

Alba is a healthcare app that uses Apple Watch and iPhone to record sleep and vitals data and to visualize and reflect on your daily condition.

What Alba provides is “reference information for awareness, recording, and self-care” to help you record and reflect on your own state. Alba does not perform medical procedures and is not a medical device intended to diagnose, treat, prevent, or cure any disease. The statistics and baselines shown are general self-care references and are not a substitute for medical advice or diagnosis. If you have any health concerns, always consult a physician or other professional.

This Privacy Policy (the “Policy”) explains what information Alba (the “App”) collects and how it is used, stored, and shared. Please read this Policy carefully before using the App.

2. Operator and Contact

3. Information We Collect

The App collects the following information. The App collects only the items described in this Policy.

3.1 Sleep data (via Apple HealthKit)

Sleep data recorded by devices such as Apple Watch is obtained through Apple HealthKit.

  • Sleep stages: the time spent in each of in bed (inBed), awake (awake), core / light sleep (core), deep sleep (deep), and REM sleep (rem)
    • When detailed stage data cannot be obtained, estimates may be calculated from the total sleep time using typical proportions (such records are marked as estimates).
  • Vitals during sleep: average heart rate (bpm), average HRV (SDNN, ms), average SpO2 (%), average respiratory rate (breaths/min)
  • Wrist skin temperature during sleep (°C)
  • Sleep start and end times, total sleep time, and time in bed

3.2 Daytime vitals and activity data (via Apple HealthKit)

  • Steps
  • Stand time (minutes)
  • Daytime average heart rate
  • Resting heart rate
  • Daytime average HRV
  • Daytime average SpO2
  • Daytime average respiratory rate
  • Average body temperature
  • Environmental sound level (dB)

3.3 Condition data you enter

  • Condition score: 1 (very bad) to 5 (very good)
  • Comment: free-form notes
  • Recording time: Morning (Morning) / Evening (Evening)

3.4 Account information

  • Email address (for account authentication via Firebase Authentication)
  • Name (when you sign in with Apple or Google, we may receive your name as part of the profile information provided by those services)

3.5 App usage data

To maintain and improve the service, we collect events about how the App is used (app launches, screens and tabs viewed, and whether features such as logging or export are used). These events never include the content of your health data, such as sleep, vitals, condition scores, or comments.

3.6 Information we do not collect

The App does not collect the advertising identifier (IDFA). It also does not use any third-party SDKs for tracking users.

4. Purposes of Use

We use the information we collect only for the following purposes.

  • Recording sleep, vitals, and condition, and displaying them as daily reports and history
  • Calculating a baseline that indicates your “usual state” (an average that is continuously updated based on your recorded data) and comparing it against your daily data
  • Calculating and displaying sleep statistics by period (average sleep time, sleep stage breakdown, average bedtime/wake time, and so on)
  • Providing the CSV data export feature
  • Account authentication and management
  • Analyzing app usage (the interaction events described in Section 3.5) to maintain and improve the service
  • Responding to inquiries, investigating issues, and maintaining and improving the service

5. Provision to and Delegation to Third Parties

Except as required by law, the App does not provide or share your data with third parties without your consent. To deliver the service, the App uses the following providers.

5.1 Google / Firebase (subprocessor)

As the infrastructure and foundation of the App, we use Firebase and Google Cloud services provided by Google LLC as subprocessors for storing, authenticating, and processing data.

  • Firebase Authentication: account authentication (email address)
  • Cloud Firestore: storage of sleep, vitals, condition, baselines, and other data
  • Cloud Run (Tokyo region): backend API processing

These are delegations for the purpose of providing the App’s functionality, and these providers do not use the data beyond the scope of that delegation.

5.2 Processing in the AI analysis feature (where provided)

The App may provide an AI-based analysis and summary feature based on your sleep, condition, and vitals data. When this feature is provided and used, aggregated data may be sent, to the extent necessary for analysis, to AI processing providers outside Japan (for example, OpenAI, Anthropic (Claude), Google, and others).

  • The AI processing providers actually used will be specified in this Policy or within the App at the time the feature is provided.
  • Only the aggregated data necessary for analysis is sent, and we do not needlessly include information that identifies individuals. We also premise use via APIs under which the data sent is not used to train the AI provider’s models.
  • This feature is optional; unless you use it, no data is sent to these AI processing providers.

5.3 In-app purchases / RevenueCat (subprocessor)

Some features of the App (such as analysis features) are available through the paid subscription “Alba Pro.”

  • Billing and payment are processed by Apple (App Store). The App does not collect or store payment information such as credit card numbers.
  • To verify purchases and manage subscription status, we use RevenueCat, Inc. (USA) as a subprocessor. What is shared with RevenueCat is limited to an ID that identifies the user (the App’s authentication ID) and transaction metadata such as purchases, renewals, and cancellations; no health data is shared.
  • You can restore purchases at any time from the in-app purchase screen. You can manage or cancel your subscription from your device under “Settings > Apple ID > Subscriptions.”

5.4 Product analytics / PostHog (processor)

To analyze app usage (the interaction events described in Section 3.5) and improve the service, we use PostHog, Inc. (USA) as a processor. The data is processed and stored on servers located in the EU.

  • What is sent to PostHog is limited to interaction events and an ID that identifies the user (the App’s authentication ID). The content of your health data (such as sleep, vitals, or condition records), your name, and your email address are never sent.
  • This data is never used for advertising, and is never combined with third-party data to track you.

6. Handling of HealthKit Data

For health and fitness data obtained from Apple HealthKit, the App follows Apple’s HealthKit guidelines and observes the following.

  • We do not use data obtained from HealthKit for advertising or marketing purposes.
  • We do not share or sell data obtained from HealthKit with third parties without your consent.
  • HealthKit data is used only to provide the features described in this Policy, such as recording, statistics, and baselines.
  • Access to HealthKit occurs only within the scope you have permitted through the iOS permission dialog. You can change or revoke this permission at any time from the iOS “Settings” app.

The Apple Watch app uses Background Delivery to obtain newly recorded sleep data after you wake. The obtained data is sent only to your own backend (Cloud Run) endpoint, protected by a Firebase ID token.

7. Data Storage Location and Retention Period

  • Storage: Google Cloud (Cloud Firestore). Backend processing takes place in the Tokyo region of Cloud Run (asia-northeast1).
  • On-device storage: to speed up history display and enable offline viewing, some data (such as sleep and condition) is temporarily stored on the device as a cache.
  • Retention period: while your account is active, data is retained so you can look back on your records and so baselines can be calculated. If you delete your account, data is deleted in accordance with Section 8.

8. Deletion of Data and Account

You can delete your data and account at any time.

  • Running “Settings > Delete account” in the App deletes your account (Firebase Authentication) and all record data stored on the server (all data linked to your account, including sleep, vitals, condition, baselines, and analysis results).
  • The on-device cache is deleted when you uninstall the App.
  • The original data within HealthKit is managed by Apple’s “Health” app; deleting the App does not delete the data within HealthKit.
  • If you have questions about deletion, or if in-app deletion should fail, please contact us at info@albaapp.jp.

9. Data Storage Location

Storage and processing of the App’s sleep, vitals, condition, and other data takes place, in principle, in Japan (Tokyo region, asia-northeast1). However, when the AI analysis feature described in Section 5.2 is provided and used, the aggregated data necessary for analysis may be sent to AI processing providers outside Japan. In that case, the specific destination will be specified at the time the feature is provided. In addition, the app usage data described in Section 5.4 is processed and stored on servers of PostHog, Inc. (USA) located in the EU.

10. Use by Minors

If a minor uses the App, we assume it is used with the consent of a guardian. If we learn that we have collected personal information from a minor without a guardian’s consent, we will delete it promptly. If this applies to you, please contact us at info@albaapp.jp.

11. Analytics and Cookies

The App itself does not use advertising identifiers or any third-party SDKs for advertising or tracking. To understand app usage, we use only the product analytics tool (PostHog) described in Section 5.4. The website (landing page) that introduces the App may use cookies or similar technologies to deliver display fonts and to understand access trends. You can disable cookies through your browser settings.

12. Changes to This Policy

We may revise this Policy in response to changes in law or in the content of the service. When we make significant changes, we will announce them in the App or on the website. The revised Policy takes effect from the time it is posted.

13. Governing Law

This Policy is governed by and construed in accordance with the laws of Japan.

14. Contact

For inquiries regarding this Policy and the handling of data, please contact us below.