Consumer Health Data Privacy Policy
Effective Date: July 28, 2026
About This Policy
This Consumer Health Data Privacy Policy is provided in addition to our general Privacy Policy to comply with the Washington My Health My Data Act (MHMDA), Nevada SB 370, the Connecticut CTDPA health data provisions, and other applicable state consumer health data privacy laws. Where this policy addresses topics also covered in our general Privacy Policy, the more protective provision applies.
Our aim in this document is accuracy rather than reassurance. Every statement below describes what the Services actually do today. Where something is imperfect, we say so instead of leaving it out.
Tailored Nutrition LLC ("Tailored Nutrition," "we," "us," or "our") operates the Tailored Nutrition mobile application (the "App") and the website tailorednutritionllc.org (the "Website"). This Consumer Health Data Privacy Policy describes how we collect, use, share, and protect consumer health data as defined under applicable state health data privacy laws.
- Definitions
- Consumer Health Data We Collect
- Sources of Consumer Health Data
- Purposes for Collecting Consumer Health Data
- Sharing of Consumer Health Data
- Third-Party Processors
- We Do Not Sell Your Consumer Health Data
- Consent
- Your Rights
- Data Security
- Data Retention & Deletion
- Children's Data
- Location and Geofencing
- Changes to This Policy
- Contact Us
1. Definitions
For purposes of this policy, these terms have the following meanings:
- "Consumer health data" — Personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. This includes, but is not limited to: individual health conditions, treatment history, diseases or diagnoses, health-related measurements (height, weight, body mass index), nutrition and diet data, reproductive or sexual health information, biometric data, medications, allergen information, and data that may be used to infer any of the above.
- "Consumer" — A natural person who is a resident of a state with applicable consumer health data privacy laws (including Washington, Nevada, and Connecticut) and whose consumer health data is collected in connection with the Services.
- "Collect" — To buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner.
- "Share" — To provide consumer health data to a third party, whether for consideration or otherwise.
- "Sell" — To exchange consumer health data for monetary or other valuable consideration.
- "Processor" — A person or entity that processes consumer health data on behalf of Tailored Nutrition pursuant to a binding contract.
Note that the definition of consumer health data is broad, and it covers information you may not think of as medical. Your height and weight, the meals you log, and the foods you avoid are all consumer health data under these laws, and we treat them that way.
2. Consumer Health Data We Collect
Everything in this section is information you type into the App yourself, or a value our own software calculates from it. The Services have no other way to learn anything about your health.
| Category | Specific Data Elements |
|---|---|
| Body Measurements |
|
| Values We Calculate About Your Body |
|
| Reproductive Health (asked only if you select female; optional) |
|
| Health Conditions & Medications (optional; free text) |
|
| Dietary & Allergy Information |
|
| Activity & Fitness |
|
| Substance Use |
|
| Goals & Wellness Targets |
|
| Nutrition & Wellness Tracking |
|
| Health-Related Communications |
|
The survey is the only place most of this is collected, and much of it is optional. Medications, health conditions, allergies, food dislikes, reproductive health, and cardio detail can all be left blank. You will still receive a plan; it simply will not account for what you did not tell us.
2a. Consumer Health Data We Do Not Collect
Because earlier versions of this policy described collection that no longer happens, and because these categories are the ones consumers most often worry about, we state them explicitly:
- No menstrual cycle tracking of any kind. We do not ask for cycle length, cycle regularity, or the date of your last period. These questions existed in an earlier version of the App and were removed in July 2026.
- No birth control information. Also removed in July 2026.
- No postpartum status or duration. Also removed in July 2026.
- No specific performance-enhancing compounds, doses, cycle phases, or post-cycle therapy. An earlier version of the App contained a module that collected these. That module is switched off and asks nothing. Only the single yes or no answer described above survives.
- No body composition measurements. We do not collect body fat percentage, waist, hip, neck, or any other circumference.
- No photographs. The App has no camera access and no photo or file upload capability of any kind, so progress photos are not possible.
- No biometric identifiers. No face scan, fingerprint, or voiceprint. The App does not use Face ID or Touch ID.
- No data from Apple Health, Google Fit, or any wearable or fitness tracker. There is no such integration in the App. Our Apple privacy manifest does declare that we collect health and fitness data, which is correct, but that refers to what you type into our survey, not to anything read from another app.
- No precise location. See Section 13.
- No smoking, alcohol, sleep duration, or mental health diagnosis questions. Sleep, stress, and mood appear only as wellness targets you may select, never as measured data.
- No genetic data, laboratory results, or clinical records, and no connection to any healthcare provider, pharmacy, insurer, or health information exchange.
3. Sources of Consumer Health Data
- Directly from you — Your survey answers, your food and weight logs, your meal preferences and notes, your notification settings, and anything you write to us.
- Derived by our systems — The calculated values listed in Section 2, all of which are computed from what you provided.
Those are the only two sources. We do not obtain consumer health data from data brokers, social media platforms, advertising networks, healthcare providers, insurers, public records, or any other outside party.
We do read from the U.S. Department of Agriculture's FoodData Central database to get nutrition values for ingredients. That flows toward us, not away from you: we send generic ingredient names and receive nutrition figures. No information about you is included in those queries.
4. Purposes for Collecting Consumer Health Data
We collect and use consumer health data for the following purposes, and only these:
- Building your plan — Calculating your calorie and macronutrient targets, selecting meals from our recipe catalog that fit those targets, and portioning them.
- Excluding food that is wrong for you — Filtering meal options against your allergies, intolerances, dietary pattern, dislikes, and any food limits derived from the medications and conditions you disclosed.
- Adapting your plan over time — Re-estimating your energy expenditure from your logged weight and intake, and proposing adjustments you accept or decline.
- Showing you your own data — Displaying your food log, weight history, intake, macronutrient breakdown, and micronutrient amounts.
- Supplement suggestions and food-timing notes — General, non-prescription suggestions generated from your survey answers.
- Writing your Personal Nutrition Profile — A written summary of your plan and what shaped it.
- Reminders you have enabled — See Section 4a.
- Understanding how the App is used — A limited set of usage events, described in Section 5, reaches our analytics provider. A few of those events carry health-related values.
- Diagnosing failures — When something breaks, an error report is sent to our error-reporting provider. Where the failure happened while processing health information, that information can appear in the report.
- Improving the Services — Using aggregated, de-identified data that cannot be traced back to you.
We do not use consumer health data for advertising, for marketing to third parties, for any form of profiling that produces legal or similarly significant effects, for discrimination, or for any purpose unrelated to providing and improving the Services.
4a. Notifications and Your Lock Screen
If you enable reminders, the App schedules them on your own device rather than sending them through a server. That means the reminder text does not travel to a push provider. It also means the text appears wherever your device shows notifications, including your lock screen.
Some reminders name your health status. Depending on what you told us and what you enabled, a notification may refer to your pregnancy stage, your due date, whether you are still breastfeeding, an enhancement cycle, or how closely you hit your calorie target yesterday. The App has no setting that hides sensitive notification content. If you would rather that text not be visible to people near you, use your device's own notification privacy settings, or turn off the relevant reminder category in the App.
One notification is delivered through a push service rather than scheduled locally: the message telling you your meal plan is ready. It contains no health information.
5. Sharing of Consumer Health Data
We share consumer health data only with service providers who process it on our behalf, and only as needed to run the Services. The table below is the complete list of providers that can receive consumer health data, and what each one gets.
| Recipient | Consumer Health Data It Receives | Purpose |
|---|---|---|
| Anthropic (Claude) | Two separate flows. (1) Interpreting what you typed: your medication names with doses and frequencies, your health condition names and any details you added, and your custom allergy text, sent as free text exactly as you wrote it. This is the most sensitive information we send anywhere. (2) Writing recipe text: the fixed ingredients and amounts, your dietary restrictions, allergies, dislikes in your own words, and food limits derived from your medications and conditions. In this second flow the limits are sent as food names; the medication or condition behind a limit is not written into the request, although it can appear in a short explanatory note attached to timing guidance. Separately, your calorie target, your goal, and your training days per week are sent to phrase your Personal Nutrition Profile. | Interpreting free-text health information; writing recipe and summary text |
| Google Cloud Platform | Everything. Our application servers and our database run on Google Cloud, so all consumer health data described in Section 2 is stored and processed there. Application logs also run through Google Cloud. | Hosting, database, and logging |
| Sentry | Error and crash reports, which include your user ID and email address, your device and app version, and diagnostic context from the point of failure. That context includes the contents of the request that failed. So if an error occurs while the Services are handling your survey answers, a weight entry, or a medication or condition you typed, that information can appear in the report. We do not send health data to Sentry deliberately or as part of normal operation, and we do not use these reports for any purpose other than fixing faults, but we cannot represent that health information never appears in them. | Crash and error diagnosis |
| PostHog | Usage events tied to your account identifier, with your name and email address attached to it. A small number of those events carry health-related values: the body weight you log, your calculated energy expenditure at the end of first-week calibration, and the names of meals you view or rate. Your survey answers, conditions, medications, allergies, and nutrition targets are not sent. Because events are sent from your device directly to PostHog, PostHog also sees your IP address and derives an approximate location from it (country, region, city). Session recording is switched off. | Product analytics |
| Resend | The contents of email we send you, and of bug reports you send us. A bug report includes your name, email address, account identifier, and whatever you wrote, so any health detail you choose to put in one reaches Resend. | Email delivery |
| Expo | No consumer health data. Receives your device's push token, and the text of the one push message we send through it, which reports that your meal plan is ready. Reminders that name your health status are scheduled on your device and do not reach Expo (see Section 4a). Because the App checks Expo for over-the-air updates, Expo also receives a per-installation identifier, your platform, and your app runtime version on each check. | Push delivery and app updates |
| RevenueCat | No consumer health data. Receives your account identifier, email address, and subscription status only. | Subscription management |
| Upstash Redis | No consumer health data. Holds your email address and IP address briefly as security state for rate limiting and sign-in lockout. | Security caching |
| USDA FoodData Central | Nothing about you. Receives generic ingredient names with no identifier attached. | Nutrition reference data |
| Instacart | Nothing. This integration is switched off and no data is sent. If we activate it, it would receive grocery line items with no identifier and no health data. | Grocery hand-off (inactive) |
Important notes about our sharing:
- Under Anthropic's commercial API terms, the inputs and outputs we send are not used to train their models. To reduce cost we ask Anthropic to cache the reusable part of our prompts, which can hold that content on their systems for up to an hour. We have not contracted for a zero-retention arrangement.
- We have never used OpenAI to process your data. An earlier version of this policy listed OpenAI as a recipient of medication, condition, and birth control information. That was wrong, and it has been corrected. Anthropic is our only AI provider.
- We do not share consumer health data with advertising platforms, data brokers, social media companies, marketing services, or any party not named in the table above.
- We do not share consumer health data with employers, insurers, creditors, or law enforcement, except where we are compelled by valid legal process.
- If you applied a referral code, we share limited account information with that partner so we can pay their commission. That is your email address and whether your subscription is active. No consumer health data is shared with referral partners.
- Anything you post on the in-app feedback board is visible to other users. That is a publication you control, not a disclosure we make, but health information you put in a post becomes public and stays visible after your account is deleted.
6. Third-Party Processors
Each provider named in Section 5 processes consumer health data as our service provider, under that provider's standard data processing terms, which:
- Restrict the provider to processing the data for the purpose of delivering their service to us
- Prohibit the provider from selling the data or using it for its own purposes
- Require the provider to maintain appropriate technical and organizational security measures
- Require confidentiality obligations on personnel with access to the data
We are a small company using widely adopted commercial platforms on their published terms. We have not individually negotiated a bespoke contract with each provider, and we do not claim to have done so. Where a provider's terms permit deletion or return of data at the end of the relationship, we would exercise it, but that mechanism is the provider's, not ours.
7. We Do Not Sell Your Consumer Health Data
Tailored Nutrition does not sell consumer health data. We have never sold consumer health data and have no plans to do so.
This is not only a promise, it is structural. There is no advertising network, tracking pixel, attribution service, data broker connection, or customer data platform anywhere in the App or on our servers. The App requests no advertising identifier and cannot present a tracking permission prompt, because there is nothing to track you with.
Under the Washington My Health My Data Act, selling consumer health data requires a valid written authorization signed by the consumer. We will never ask you for one, because we do not engage in the sale of consumer health data.
If this ever changes, we will update this policy, notify affected consumers, and obtain every authorization the law requires before any sale occurs.
8. Consent
8a. Collection Consent
Before the survey collects anything, the App shows you a full-screen consent notice that names the categories of health data it will collect, names Anthropic as the provider that processes it, states that we do not sell it, and links to this policy and to our Privacy Policy. You cannot proceed past that screen without accepting. The only alternative offered is to go back.
When you accept, we record that acceptance against your account: which policy, which version of it, when you accepted, and how. The version we record is the Effective Date printed at the top of this page. That record is what lets us tell whether you have seen the current version, and it is kept as an append-only history rather than a single overwritten flag.
Accepting the Terms of Service and Privacy Policy happens separately, when you create your account. The health data consent above is deliberately kept apart from it.
Your later use of the tracking features is its own consent to collect what you enter there. Logging a weight or a meal is an affirmative act, and nothing is collected from those features unless you use them.
8b. Sharing Consent
The consent described in Section 8a covers the sharing described in Section 5. We ask for it before any health data is collected, and therefore before any of it can be shared.
8c. Withdrawing Consent
You may withdraw your consent to the collection and sharing of consumer health data at any time by deleting your account, from the More tab in the App. Deletion is immediate and removes the health data described in Section 11.
We want to be straightforward about the limits here rather than describe a mechanism that does not exist:
- Deleting your account is the only way to withdraw consent. There is no partial withdrawal, and no setting that keeps your account while stopping health data processing. Health data is what the Services are built on, so withdrawing consent and continuing to use them is not possible.
- There is no separate analytics opt-out inside the App today.
- You may also contact us at support@tailorednutritionllc.org and we will action a withdrawal by deleting your account on your behalf, after verifying that the request is yours.
- Withdrawing consent does not reach back into records that survive deletion. Those are listed in Section 11.
9. Your Rights
Depending on where you live, you may have the rights below. We extend them to all of our users regardless of state.
9a. Right to Know and Right to Access
You have the right to confirm whether we collect, share, or sell your consumer health data, and to access what we hold. You do not need to ask us: the App has a self-service export at More > Export My Data, which generates a JSON file immediately containing your profile, survey answers, food and weight logs, adaptive calculations, meal preferences, grocery cart, chat history, notifications, notification preferences, and feedback posts. If you cannot reach the App, contact us and we will provide a copy within 30 days of a verified request.
9b. Right to Deletion
You have the right to request deletion of your consumer health data. You can do it yourself at any time from More > Delete Account in the App, which is immediate, or you can ask us and we will complete it within 30 days of a verified request.
What deletion does and does not reach is described in Section 11. In particular, and unlike what an earlier version of this policy stated, we do not issue deletion instructions to the providers listed in Section 5. Deleting your account removes your data from our systems; it does not reach into their systems. If you want data removed from a specific provider, contact us and we will make that request on your behalf where the provider supports it.
9c. Right to Withdraw Consent
You may withdraw consent as described in Section 8c.
9d. Right to Non-Discrimination
We will not discriminate against you for exercising any right under applicable consumer health data privacy laws. Exercising a right will not cause denial of service, different pricing, a lower quality of service, or retaliation of any kind.
9e. Right to Appeal
If we decline to act on your request, we will tell you why and explain how to appeal. You may also complain to the Attorney General of your state. Washington residents may additionally have a private right of action under the My Health My Data Act.
9f. How to Exercise Your Rights
Email support@tailorednutritionllc.org. We verify identity before acting on a request, usually by asking you to confirm information associated with your account. We will respond to a verified request within 30 days, and will tell you in writing if we need up to 15 additional days for a complex request.
You may use an authorized agent. We may ask the agent for written proof of authorization and may verify your identity with you directly.
10. Data Security
The measures below are the ones actually in place:
- Encryption in transit — All traffic between your device and our servers uses TLS, enforced with HTTP Strict Transport Security.
- Encryption at rest — Our database is encrypted at rest by our cloud provider at the storage layer.
- Password hashing — Passwords are hashed with bcrypt and a per-password salt. We never store or see your plaintext password.
- Secure token storage — Authentication tokens are held in your device's platform-native secure storage, not in ordinary app storage.
- Token expiry and revocation — Access tokens expire after 24 hours and refresh tokens after 90 days. Refresh tokens are single-use and rotate. Revoked tokens are held on a blocklist until they would have expired.
- Access controls — Our database is not exposed to the public internet and is reachable only by our application servers. Every request for health data is keyed to the authenticated account making it, so one account cannot read another's data.
- Sign-in protection — Accounts lock temporarily after 10 failed sign-in attempts within a short window, and authentication endpoints are rate limited.
- Server hardening — Restrictive security headers, a request size limit, and cross-origin access restricted to an explicit allowlist.
- Input validation — Inputs are validated and length-limited, and free text is sanitized before it is sent to our AI provider.
- Password reset codes — Stored hashed, expire in 15 minutes, and are invalidated after five failed attempts.
- Audit logging — Account creation, sign-in, password and email changes, survey resets, data exports, and account deletion are logged with timestamps for incident investigation.
Equally important is what we do not have, so that you are not relying on protections that are not there:
- We do not apply application-level encryption to health data on top of the cloud provider's storage encryption. Anyone with access to the database can read it.
- We do not verify email addresses at sign-up.
- We do not operate a web application firewall.
- Our error-reporting provider does not have a health data scrubbing filter in front of it. See Section 5.
- Signing out invalidates your current access token but does not revoke a refresh token already issued to that device.
Access to production systems is limited to the small number of people who operate the Services. No feature exposes one user's health data to another user, and no internal tool presents a user's survey answers, medications, conditions, weight history, or food log to anyone but that user. Someone holding our cloud database credentials could read stored health data directly, as is true of any hosted service.
No system is completely secure, and we cannot guarantee absolute security. If a breach affects your consumer health data, we will notify you as described in Section 8b of our Privacy Policy.
11. Data Retention & Deletion
We do not currently expire consumer health data. Your survey answers, food logs, weight logs, and adaptive calculations are retained for as long as your account exists. There is no automatic purge and no inactive-account deletion job. If your subscription lapses, your data is retained rather than deleted, and becomes available again if you resubscribe.
The exceptions, where data does expire on its own, are: chat conversations, which are limited to the five most recent and are cleared once they are more than 24 hours old the next time you use the feature; archived earlier versions of a meal, which are discarded after 7 days; and short-lived security state such as password reset codes and rate-limit counters.
Note that resetting your survey is not the same as deleting your data. A reset keeps a snapshot of your previous answers on your account so that a reset can be understood and recovered from.
11a. What Deletion Removes
Deleting your account deletes your health data. It happens immediately while you wait, not in a queue, and it cannot be undone.
It removes your survey answers and every health value derived from them, your meal plans, your food and weight logs, your adaptive energy expenditure history and first-week calibration, your meal preferences, your grocery cart, your chat history, your notifications, notification settings and push registrations, your meal generation history, your usage records, and your account record itself, including your email address, name, password hash, and the record of which policies you accepted.
11b. What Deletion Does Not Remove
This list matters, but read it for what it is. It contains none of your survey answers, none of your logs, and none of the plan built from them. Those are gone. What is left is limited to copies already sitting with the providers in Section 5 that we cannot reach into, rolling database backups, records we are required to keep, and text you chose to publish or send us.
- Posts you made on the feedback board. The post is disconnected from your account, but the text stays visible to other users. If a post contains health information you want removed, contact us before deleting your account.
- Security and audit log lines, which record events such as account creation, sign-in, and deletion together with your email address and IP address.
- Support requests and bug reports you already sent us, which are retained as business records, along with anything health-related you wrote in them.
- Records of transactions and promotional code redemptions, retained for tax, accounting, and fraud prevention.
- Data already held by the providers in Section 5. Deleting your account sends no deletion instruction to Anthropic, PostHog, Sentry, Expo, Resend, RevenueCat, Apple, or Google. In particular, analytics events that included your logged body weight, and the profile holding your name and email at our analytics provider, are not deleted by this action.
- Database backups. Our database is backed up on a rolling basis, so a deleted record can persist inside a backup until that backup ages out. Backups exist for disaster recovery and are not used to restore deleted accounts.
- Aggregated, de-identified data that cannot be linked back to you.
Export your data before deleting your account. Deletion is immediate and we cannot recover it afterward. Also note that deleting your account does not cancel an active subscription; cancel that separately through your device's subscription settings first.
12. Children's Data
The Services are intended for adults. Our Terms of Service require you to be 18 or older, and our app store listings are age-rated accordingly. We do not knowingly collect consumer health data from anyone under 18, and if we learn that a user is under 18 we will delete the account and its data.
We rely on app store age ratings and on your representation of your age rather than on identity verification, so we cannot guarantee that every user meets that requirement.
In compliance with the Children's Online Privacy Protection Act, if we learn that we have collected consumer health data from a child under 13, we will promptly delete it and terminate the account. If you are a parent or guardian and believe your child has provided us with health data, contact us at support@tailorednutritionllc.org.
13. Location and Geofencing
Tailored Nutrition does not use geofencing. We do not, and technically cannot, establish a virtual boundary around any health care facility, mental health facility, reproductive health clinic, substance use treatment center, or any other location, whether to identify or track consumers, to collect consumer health data, or to send any notification or advertisement.
This is not a policy choice layered on top of a capability we hold back. The App never requests location permission and has no ability to read your device's location. It contains no location library, declares no location permission on either iOS or Android, and includes no usage description string, without which iOS would refuse the request outright. Our servers use no IP geolocation service and store no location on your account.
Two qualifications, so this section is complete:
- Analytics events are sent from your device directly to our analytics provider, so that provider sees your IP address and derives an approximate location from it, typically country, region, and city. That is coarse, it is not derived from GPS, and it is nowhere near precise enough to indicate a visit to a particular building. We disclose it because your IP address is a regulated identifier.
- Your device's time zone is sent with some requests so the App knows which calendar day it is where you are. It is used and discarded, never stored on your account.
14. Changes to This Policy
We may update this policy. When we do, we will update the Effective Date at the top of this page and post the revised policy on our Website.
If a change materially affects how we collect, use, or share consumer health data, we will give you advance notice by email or in-app notification before it takes effect, and we will make the notice period reasonable in light of the change. We do not commit to a fixed number of days for every change. Clarifications, corrections, and changes that do not materially affect your rights may take effect when posted, and a change we are required to make immediately for legal, regulatory, or security reasons may take effect without advance notice, in which case we will tell you as soon as reasonably practicable afterward.
Where we want to use consumer health data we already hold for a materially different purpose than the one disclosed when you provided it, we will ask for your consent rather than rely on notice. The App records which version of this policy you accepted, so it can tell when you have not yet seen a current one and prompt you.
Prior versions of this policy are available on request.
15. Contact Us
If you have questions about this Consumer Health Data Privacy Policy, wish to exercise your rights regarding your consumer health data, or have concerns about how your health data is handled, please contact us:
Tailored Nutrition LLC
Email: support@tailorednutritionllc.org
We will respond to all inquiries within 30 days.
Which Policy Should I Read?
Our general Privacy Policy covers all data we collect, how we use it, your rights, and our security practices. This Consumer Health Data Privacy Policy provides additional protections specifically for health data under state consumer health data privacy laws. Our Terms of Service governs your use of the Services. For the most complete understanding, we recommend reviewing all three documents.