Effective August 29, 2026 · version 2026-08-29

Consumer health data privacy

What may count as consumer health data

Depending on where you live, saved allergies and avoidances, dietary patterns, age, height, weight, activity level, goals, nutrition targets, meal logs, fitness level, movement preferences, and completed movement sessions may be consumer health data. We ask you not to enter diagnoses, medical records, medications, or unrelated sensitive information.

Where it comes from

It comes directly from information you choose to enter and from actions you take in the service, such as logging a meal or marking a movement session complete. We do not buy health data from brokers, infer a medical diagnosis, or connect to medical records or wearable devices.

Why it is collected and used

We use the minimum information needed to provide the features you ask for: screening recipes against saved food rules, ranking possible meals, building plans and grocery lists, showing optional nutrition totals, and arranging a general movement week. It is also used when necessary to secure the service, prevent abuse, answer your requests, and meet legal duties. We do not use it for medical decisions or targeted advertising.

Who receives it

Cloudflare processes account and planning data as the service's hosting, database, file-storage, and security provider. Professional advisers or authorities may receive only what is lawfully necessary. Stripe receives account and billing details when payments are enabled, but the app is not designed to send saved allergies, body measurements, meal logs, or exercise activity to Stripe. We do not sell consumer health data.

Your choices and rights

You can choose not to enable optional nutrition or movement features, edit saved preferences, remove individual logs and plan entries, and ask to access or delete consumer health data. You may also ask for a list of third parties with whom it was shared, withdraw consent for future optional collection or sharing, use an authorized agent where the law allows, and appeal a denied request.

Submit a request through Support. We verify requests before disclosing or deleting account data. A public contact email and the operator's legal identity must be added before paid public launch so people who cannot sign in have a direct request channel.

Security, retention, and changes

Access is limited by account authorization and data is transmitted over HTTPS. Health-related planning data is kept while the account is active or as needed to provide requested features, then deleted on a verified request subject to narrow legal and security exceptions. Material changes to the purposes, categories, or recipients described here will be posted and consent will be requested when required.