Consumer Health Data Privacy Policy
Effective date: September 17, 2026
This Consumer Health Data Privacy Policy is a separate, standalone policy that applies specifically to "consumer health data" as defined by the Washington My Health My Data Act (RCW 19.373) and the Nevada consumer health data law (Nevada SB 370, NRS 603A.500 to 603A.560). It applies to residents of Washington and Nevada, and we extend the same protections to any other consumer whose data falls within these definitions. It is provided in addition to, and does not replace, our general Privacy Policy. Where this policy and the general Privacy Policy differ with respect to consumer health data, this policy controls.
In this policy, "consumer health data" (also "CHD") means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status, including information derived or extrapolated from non-health data.
The entity responsible for the consumer health data described here is TruFitAI App Co., operating the TruFitAI application ("TruFitAI", "we", "us"). Contact details are in the "Contact and How to Exercise Your Rights" section below.
1. Categories of Consumer Health Data We Collect, Their Sources, and Purposes
We collect the following categories of consumer health data. For each category we list the source(s) it comes from and the specific purpose(s) for which we process it. We do not use consumer health data for advertising, and we do not sell consumer health data.
| Category of consumer health data | Source | Specific purpose(s) |
|---|---|---|
| Body metrics — weight, height, age, body measurements | You (entered in the app) | Generating and adapting your workout and nutrition plans; tracking progress over time |
| Food and nutrition logs — meals, calories, macronutrients, water and supplement intake, food photos | You (entered in the app; food photos you capture) | Nutrition tracking; AI analysis of meal photos to estimate nutrition; personalized diet guidance |
| Recipes — ingredients, instructions, servings, and nutrition-per-serving information | You (created or imported in the app) | Maintaining your private Recipe Book; making a recipe available without login only when you explicitly use the Share feature and until you unshare it |
| Workout data — exercises, sets, reps, weights, workout logs | You (entered in the app) | Generating and adapting your workout plans; progress tracking; leaderboards you opt into |
| Check-in responses — mood, energy levels, and periodic check-in metrics | You (entered in the app) | Adapting coaching and plans to how you are progressing and feeling |
| Progress / body photos | You (uploaded to track physique changes) | Letting you review your progress over time; AI body-composition analysis when you request it |
| Activity and body data — steps, workouts, and body metrics (height, weight) | Entered by you in the app | Displaying health metrics in the app and informing AI recommendations |
| Supplement data — supplements you track or are recommended | You (entered in the app) and AI derivation | Supplement tracking and personalized supplement suggestions |
| Derived data — AI body-composition scores/ranks and an inferred pregnancy status | AI derivation from the inputs above (e.g., body-composition analysis; a conservative server-side scan of your profile free-text that infers whether you are pregnant in order to decline to generate plans during pregnancy) | Body-composition feedback and ranking; safety gating that refuses workout, nutrition, and supplement generation for pregnant users |
2. Third Parties and Affiliates That Receive Consumer Health Data
Except for a recipe you explicitly share as described below, we share consumer health data only with the specific service providers below, and only as needed to provide the app's features. Each is named individually:
- OpenAI — receives fitness/health profile data, food photos, progress/body photos, and coaching conversation content to perform AI processing (plan generation, meal-photo nutrition estimation, body-composition analysis, and coaching responses). Food photos are processed in real time and are not stored by TruFitAI after analysis; progress/body photos are stored by us (in Supabase Storage) and sent to OpenAI only when you request an analysis. OpenAI processes this data under its API data usage policy. Contact: [email protected].
- Supabase — stores and processes your account data, workout and nutrition logs, progress metrics, and the progress/body photos you upload. Supabase acts as our data processor and stores this data with row-level security. Contact: [email protected].
User-directed public sharing: Separately from these service providers, if you affirmatively choose “Make public & share” after the per-recipe disclosure, the recipe's title, description, image, ingredients, instructions, servings, timing, tags, and nutrition per serving are available without login to the category of recipients described as anyone with the public link. Recipients may save or redistribute the recipe. Your account identity, food logs, nutrition targets, and other consumer health data remain private. The link remains active until you use the visible Unshare control.
We have no other affiliates that receive consumer health data. In particular:
- RevenueCat (subscription management) does NOT receive any consumer health data — only an anonymous user identifier and subscription status.
We do not sell your consumer health data, and we do not share it with any third party for advertising or for cross-context behavioral advertising.
3. How We Collect Your Consent
You provide consumer health data by entering it in the app (for example, your workouts, meals, steps, and body metrics), and selected Apple Health or Google Health Connect records only after separate platform authorization and TruFitAI upload consent. Before collection begins, TruFitAI separately requests consent to collect health data and consent to share relevant health data with OpenAI. You may withdraw either consent in Settings → Privacy Choices & Data. Withdrawing does not delete your account, but dependent personalized AI features pause.
Public recipe sharing uses a third, separate consent presented when you choose to make a specific recipe public; the OpenAI-sharing consent does not authorize a public recipe link. Before publication, the disclosure identifies the recipe fields shared, the purpose (providing a public recipe link), the category of recipients (anyone with the link), the possibility of recipient redistribution, and the Unshare withdrawal method. If you cancel the share sheet while creating a new link, TruFitAI attempts to return the recipe to private and tells you if that rollback fails.
4. Your Rights
Washington and Nevada residents (and consumers we extend these rights to) have the following rights regarding consumer health data:
- Right to confirm whether we collect, share, or sell your consumer health data, and to access that data.
- Right to a list of third parties with whom we have shared your consumer health data (for us, this is OpenAI and Supabase, plus recipients of a recipe link you explicitly create, as described in Section 2), including an active email or other online contact for each where applicable. Public share-link recipients are not required to identify themselves to us, so we cannot provide their individual identities.
- Right to withdraw consent to our collection and sharing of your consumer health data.
- Right to delete your consumer health data, including directing our processors to delete it.
- Right not to be discriminated or retaliated against. We will not deny goods or services, charge a different price, or provide a different level of quality because you exercised any of these rights.
How to exercise each right
- Deletion (self-serve): You can delete your account, consumer health data, and uploaded progress/body photos directly in the app under Settings → Delete Account. Deletion also removes stored photos from our processor (Supabase Storage). Limited consent/withdrawal and qualifying safety evidence may be retained only for an applicable lawful evidence period; public- recipe consent evidence keeps an opaque recipe id but no copy of recipe content.
- Access and portability: Download your account data under Settings → Privacy Choices & Data → Download my data.
- Confirm recipients and withdraw consent: Open Your Consumer Health Data Rights under Privacy Choices & Data to review service-provider recipients and change collection or OpenAI-sharing consent. To withdraw consent for a public recipe, open that recipe in Recipe Book and choose Unshare; the link stops working immediately.
- Other requests or authorized agents: Email [email protected]. We will verify identity and agent authority where required.
Note on data already processed by OpenAI: when you delete your data or withdraw consent, we stop sending your data to OpenAI and delete what we store, but data previously processed by OpenAI is subject to OpenAI's own retention policy, which we do not control.
Note on copies made by public-link recipients: Unshare stops future access through TruFitAI's link. We cannot identify every public-link recipient or recall copies a recipient already saved or redistributed. Contact us if you need help with a deletion request involving a known recipient.
Response timeline
For Washington residents, we will respond within 45 days of receiving your request; where reasonably necessary we may extend once by an additional 45 days and will tell you why. For Nevada residents, we will respond within 60 days, extendable by an additional 30 days where reasonably necessary. There is no charge for your first request in a 12-month period.
Appeals
If we decline your request, we will tell you why. You may appeal that decision by replying to our response or emailing [email protected] with the subject line "CHD Appeal". We will respond to your appeal in writing with our decision and reasons. If your appeal is denied, Washington residents may submit a complaint to the Washington State Attorney General at atg.wa.gov/file-complaint, and Nevada residents may contact the Nevada Attorney General's office.
5. Data Retention and Security
We retain consumer health data for as long as your account is active, and we delete it when you delete your account (see Section 4) or otherwise as described in our general Privacy Policy, which contains our full per-category retention schedule. Private consumer health data is encrypted in transit and at rest and is protected with row-level security so that only you and our AI processing pipeline can access it. Recipe content you explicitly publish through a public share link is the limited exception described in Section 2 and remains public until you unshare it. We retain append-only evidence of the public-sharing grant and withdrawal for the legally permitted evidence period; that record identifies the recipe by an opaque id and does not retain a copy of the recipe content.
6. Changes to This Policy
We may update this policy from time to time. Material changes will be handled consistently with the notice commitments in our general Privacy Policy, and the effective date above will be revised.
7. Contact and How to Exercise Your Rights
To exercise any right described here, or for questions about our consumer health data practices:
- Entity: TruFitAI App Co.
- Postal address: 131 Continental Drive, STE 305, Newark, DE 19713, USA
- Email: [email protected]