Privacy Policy

Effective October 5, 2026 · Apollo Wellness LLC

The short version

  • We collect what you put into Apollo, and what's needed to run it: your email address, your app data, and basic technical records.
  • We don't sell your personal information. We don't show ads, and we don't use third-party analytics or tracking.
  • We don't use your content to train AI models.
  • Your data is kept on your device first. When you sign in, it syncs to our servers so it's on all your devices. Synced data is not end-to-end encrypted: our systems can read it to sync it and to run features you use.
  • You can export your data and delete your account at any time.

Who we are

Apollo Suite (Alluvium, Hearth, Cambium and Talus, at apollo-suite.com) is operated by Apollo Wellness LLC (“we”, “us”). This policy explains what personal information we collect, how we use and share it, and your choices. Contact us at support@apollo-suite.com.

What we collect

Your account

  • Your email address, and a display name and picture if you add them (or Google provides them when you sign in with Google).
  • Sign-in codes (stored only as a hash) and, for each signed-in session, the session’s IP address and browser description, used to keep your account secure.
  • Your settings, such as units, time zone, appearance and whether AI features are on.

What you put into the apps

  • Alluvium: accounts, balances, transactions, categories, budgets, goals, rules and notes you enter or import, and receipts you add to a transaction (a photo, resized on your device, or a PDF), stored privately with your household’s files.
  • Hearth: recipes, meal plans, pantry items, shopping lists, ratings and price notes. A recipe’s photo is either a link to where the picture is hosted or a photo you add, which is resized on your device and stored privately with your household’s files.
  • Cambium: notes and their earlier versions, attachments (images, audio, PDFs and text files), voice recordings and their transcripts, and scanned pages.
  • Talus: workouts, sets, routines, exercises, goals and body measurements such as weight and waist.

Connections you choose to make

  • Bank connections (Plaid): if you connect a bank, Plaid gives us your account names and last digits, balances and up to two years of transactions, and we keep the records Plaid returns. Each time your bank syncs, our servers tidy the new and changed transactions: a clear payee name, the bank’s own statement description, transfers between your own accounts (including payees your past transfers show are one of your accounts), and a category and budget bucket from how you’ve filed similar transactions before. Anything you’ve changed yourself stays as you left it. We never see or store your bank username or password.
  • Kroger: if you connect Kroger, we keep your chosen store and the products matched to your shopping list, and use your permission to add items to your Kroger cart. Nothing is purchased by us.
  • Google sign-in: your name, email address and picture from Google.

Payments

Stripe processes payments; we never receive your full card number. We keep your Stripe customer and subscription details. If you receive a refund, we also keep a keyed hash of your email address and the card “fingerprint” Stripe provides, so the once-per-person refund rule can be applied.

Technical information

Our hosting provider records requests to our servers (such as IP address, time and page) for security and to keep the service running. Error details stay on your device unless you choose to send us a problem report, which you can review first. We don’t use analytics or advertising cookies.

How we use it

  • To provide Apollo: storing and syncing your data, showing your information across your devices and your household, and sending the emails and notifications you turn on.
  • To take payments, apply refunds and manage subscriptions.
  • To run the connections and AI features you choose to use.
  • To keep Apollo secure: preventing abuse and fraud, limiting sign-in attempts and AI spending, and investigating problems.
  • To reply to you, and to comply with the law.

AI features

Some features use AI models, such as choosing a bank transaction’s category during bank sync, matching a recipe’s ingredients to foods for nutrition, grouping payee names that are the same payee, matching a grocery product, tidying a recipe, reading a recipe from a photo, reading a scanned page, transcribing a voice note, suggesting tags or drafting a rule you describe. AI runs behind the scenes as part of these product features. The content needed for that feature (for example a transaction’s payee and amount, a recipe’s text, a page image or a recording) is sent to AI models run for us through Cloudflare. The model that makes choices (categories, buckets, grocery products, tags) is Jev, made by TypeSafe, a third-party model Cloudflare offers with zero data retention; the others are models Cloudflare runs.

Our AI gateway neither logs nor caches what is sent or returned. We record which feature was used, the model and the version that answered, how much it used and its cost, to limit spending; a request is refused before it is sent if it could exceed an internal service limit. We don’t use your content to train AI models. AI results can be wrong. Some features use a model that can only choose among options Apollo gives it (such as your own categories or a store’s products), and Apollo checks its choice before using it. During bank sync, when your own history doesn’t settle a transaction’s category or budget bucket, that model picks the closest of your categories and of your plan’s buckets, given the transaction’s payee, the bank’s description and category, its amount and date, and the payees, categories and buckets of some of your past transactions as examples (never notes or balances); it is applied automatically and never overrides your own changes, and your newest change for a payee applies to its other transactions you haven’t changed. The same happens for a transaction you enter yourself and leave without a category or bucket, after your own rules and that payee’s history: its payee, amount and date, with your categories, your plan’s buckets and examples from your past transactions, are sent to that model, and the result is marked as AI’s until you change it. Each recipe ingredient is matched automatically to a food in USDA FoodData Central: the ingredient’s name is sent to USDA to look it up (nothing else about you or the recipe), that model picks the closest of USDA’s foods for the line and, when Apollo can’t work it out itself, how much one of its units weighs; the recipe’s nutrition is calculated from those foods, and your own corrections are kept. If the model is unavailable, Apollo still looks ingredients up in USDA and picks by name itself. In Hearth, a recipe you import has its method tidied into one action per step (its amounts, temperatures and times are checked to be unchanged), a pantry item with a known bought or opened date gets an estimated use-by date, and each shopping-list item is matched to a product at your Kroger store, all automatically and each changeable. A voice note’s transcript and summary are added to the note automatically, marked as AI’s. When you import a recipe from a photo, the photo (resized on your device) is sent once to read the recipe as written; the draft is shown for you to check, nothing is saved until you do, and the photo isn’t kept. Scanned text and tag suggestions are shown for you to use. When you describe a rule in Alluvium and ask for a draft, what you wrote and the names of your categories, budget buckets, accounts and rule folders are sent to a model that drafts the rule; it opens for you to check, and nothing is saved or applied until you save it.

Some browsers transcribe speech (in Hearth’s hands-free cook mode and Cambium’s live transcripts) using their maker’s speech service, such as Google or Apple, under their own terms.

How it’s shared

We don’t sell your personal information or share it for advertising. We share it only as follows.

  • Service providers that work for us: Cloudflare (hosting, storage, email delivery and AI models), Stripe (payments), Plaid (bank connections), Kroger (grocery connections, if you connect), Google (sign-in, and website icons shown beside payees), Brandfetch (company names you search for, to find logos), the U.S. Department of Agriculture’s FoodData Central (ingredient names, to look up nutrition) and your browser’s push notification service (notifications you turn on; their content is encrypted).
  • Your household: if you join or create a household, its members see its shared money and recipes, and any notes you choose to share. Your private notes and your training are never shared with your household.
  • Links you share: anyone with a recipe or routine link you create can see what it contains, until you stop sharing it.
  • When required: to comply with law or legal process, to protect the rights, safety and property of our users, us or others, or as part of a merger, acquisition or sale of assets (you would be told of any change to how your information is handled).

Cookies and on-device storage

We use one essential cookie to keep you signed in (it lasts up to seven days and renews while you use Apollo). Apollo stores your app data in your browser’s storage so it works offline. We don’t use advertising, analytics or other tracking cookies, and we don’t track you across other websites.

How long we keep it

  • We keep your information while you have an account. Notes in the trash are removed after 30 days, and earlier note versions after 90 days.
  • When you delete your account, we disconnect your banks and erase your account, your private data and files, a household you own alone, your settings, sessions and AI usage records. What you added to someone else’s household stays with that household.
  • We keep some records after deletion where we need them: payment and refund records and the technical records of payment and bank-connection events (for accounting, tax, fraud prevention and the once-per-person refund rule), and a security log entry that the account was deleted. Stripe keeps its own payment records.
  • Database backups are kept for up to 35 days. Our hosting provider’s request logs are kept according to its own retention.

Your choices and rights

  • See and export: each app exports your data from its menu, even after a plan ends.
  • Correct: you can edit your information in the apps and in Account.
  • Delete: delete your account from Account → Delete account, or delete individual items in the apps.
  • Limit: turn off notifications, bank and Kroger connections, and partner sharing at any time.

Depending on where you live, you may have further rights, such as to know what we hold about you, to receive a copy, to have it corrected or deleted, and to appeal our decision on a request. Email support@apollo-suite.com from your account’s email address; we may need to confirm it’s you, and we’ll reply within 45 days. You can use an authorized agent where the law allows. We won’t treat you differently for using these rights.

Consumer health data

This section is our Consumer Health Data Privacy Policy for the purposes of laws such as Washington’s My Health My Data Act and Nevada’s consumer health data law.

  • What we collect: information you enter that may relate to your health: body measurements (such as weight and waist), workouts and exercise history, fitness goals, and food, recipes and nutrition estimates.
  • How we get it: only from you, when you enter it in Talus or Hearth.
  • Why: only to provide the features you ask for, such as showing your progress, suggesting your next set and estimating nutrition.
  • Who receives it: the service providers that host and process it for us (see “How it’s shared”). We don’t sell it, and we don’t share it with your household or anyone else.
  • Your rights: you can see, export and delete it in the apps, delete your account, and ask us to confirm what we hold, to delete it, or to withdraw consent, by emailing support@apollo-suite.com. You can appeal a decision on your request by replying to our answer.

Security

We protect your information with encrypted connections, encryption of bank and Kroger access tokens, hashed sign-in codes and links, and checks that every request is allowed to reach the data it asks for. Synced data is not end-to-end encrypted. No system is perfectly secure; if a breach affects your information, we’ll tell you as the law requires.

Children

Apollo is for people 18 and older. It isn’t directed at children, and we don’t knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we’ll delete it.

Where your data is processed

We are based in the United States. Your information is stored and processed in the United States and wherever our service providers operate, which may be outside your country.

Changes to this policy

We’ll post any change here with a new effective date. If a change is significant, we’ll tell you in Apollo or by email before it takes effect, and ask you to accept the new version.

Contact

Apollo Wellness LLC · support@apollo-suite.com