Privacy Policy
Effective Date: July 28, 2026
Tailored Nutrition LLC ("Tailored Nutrition," "we," "us," or "our") operates the website tailorednutritionllc.org (the "Website") and the Tailored Nutrition mobile application (the "App"). Together, the Website and App are referred to as the "Services."
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Services. Because our App collects sensitive health-related data to generate personalized nutrition plans, we encourage you to read this policy carefully.
Related Policies
This Privacy Policy works alongside our Consumer Health Data Privacy Policy, which provides additional protections for health data under state consumer health data privacy laws (including Washington, Nevada, and Connecticut). Where both policies address a topic, the more protective provision applies. Please review both documents to understand your full rights.
- We collect health data only to personalize your meal plans and nutritional guidance
- We never sell your personal information or health data
- Our AI provider (Anthropic) does not use your data to train its models
- You can export or delete your data at any time from within the App
- We do not use tracking cookies, advertising pixels, ad networks, or advertising identifiers
- We do not share your data with advertisers, data brokers, employers, or insurers
- We extend privacy rights to all U.S. residents, not just California
- Some health-related information does reach our error-reporting and analytics providers, as described in Section 4. We tell you exactly what and why rather than claiming otherwise
- Information We Collect
- How We Use Your Information
- AI and Automated Processing
- Third-Party Service Providers
- Information Sharing and Disclosure
- Cookies, Tracking Technologies, and Do Not Track
- Data Retention
- Data Security and Breach Notification
- Your Rights and Choices
- U.S. State Privacy Rights
- Children's Privacy
- International Users
- Changes to This Policy
- Contact Us
1. Information We Collect
We collect different types of information depending on how you interact with our Services.
1a. Website Visitors
Our Website is informational. The home page and these policy pages have no account system, no sign-up form, and no analytics or advertising code. We do not collect names, email addresses, or any other personal information from you when you browse them.
There is one exception. Our account deletion page exists so you can delete your account from the web without installing the App, as the app stores require. To confirm the request is really yours, that page signs you in, which means it sends your email address and password to our servers. It collects nothing else, and it stores nothing in your browser.
Our Website loads fonts from Google Fonts. As with any resource loaded from another server, that request discloses your IP address and browser information to Google. This happens on every page of our Website, including this one.
1b. App — Account Information
When you create an account in our App, we collect:
- Email address — used as your account identifier
- Name — your display name
- Password — stored only in hashed form (we never store or see your plaintext password)
If you sign in using a third-party authentication provider (Google or Apple), we receive your email address and, optionally, your name from that provider. We do not receive or store your Google or Apple password.
1c. App — Health and Body Composition Data
Our App collects detailed health information through an in-depth survey to generate personalized nutrition plans. This includes:
- Demographics — date of birth, biological sex, height, and weight
- Body metrics — calculated values such as BMI and basal metabolic rate (BMR)
- Goals — your target weight and the pace at which you want to reach it
- Reproductive health (asked of users who select female, at your discretion) — whether you are pregnant and your current pregnancy week, whether you are breastfeeding along with the type and your baby's age, and menopause stage. We also ask about reproductive health conditions such as PCOS, endometriosis, thyroid conditions, PMDD, and a history of anemia. We do not collect menstrual cycle tracking data, cycle length, cycle regularity, birth control type, or postpartum status. These were previously collected and have been removed
- Activity and training — occupation activity level, lifestyle movement, resistance training details (frequency, duration, intensity, body part focus, volume, progressive overload), cardio activities, and training experience level
- Performance enhancing substances — a single yes or no answer to whether you use them, which affects your protein target only. We do not collect specific compounds, dosages, or cycle information
- Health conditions — any medical conditions you choose to disclose (e.g., PCOS, diabetes, hypertension) and any details you add
- Medications — names, dosages, and frequency for medications you choose to disclose
- Dietary preferences — your dietary pattern, food allergies and intolerances, food dislikes in your own words, and health-oriented nutrition targets (e.g., increased energy, improved sleep, blood sugar management). The dietary pattern choices include religious dietary practices such as halal, kosher, Hindu vegetarian, and Adventist, so your answer may reveal a religious affiliation
- Cooking preferences — how many meals a day you want and your cooking skill level
- Motivations — why you are using the App, which includes "manage a health condition" as an option, plus anything you write in your own words
Medications, health conditions, allergies, and reproductive health information are optional. You can complete the survey and use the Services without providing them, though the plan you receive will not account for them.
Before the survey begins, the App shows you a health data consent screen describing what is collected and how it is used. You must accept it to continue. You can withdraw that consent at any time by deleting your account.
For detailed information about how we handle consumer health data under state health data privacy laws, see our Consumer Health Data Privacy Policy.
1d. App — Usage and Tracking Data
As you use the App, we collect:
- Food log entries — meals consumed, nutritional values, dates, and timestamps
- Weight log entries — weight measurements over time, and any note you attach to an entry
- Meal preferences — meals you have liked, disliked, or requested substitutions for, and the reasons you provide
- Meal request notes — if you ask for an additional meal and describe what you want in your own words, we keep that note on your profile and reuse it to steer later requests
- Grocery cart data — meals added to your shopping list and custom grocery items
- Chat conversations — if we make the in-app nutrition assistant available to you, the messages you send and the responses you receive. This feature is not currently available to users
- Feedback and feature requests — posts you submit through the in-app feedback system, which are displayed to other users without your name or email
- Notification preferences — your chosen notification categories and quiet hours
- Analytics events — we collect usage events via PostHog, including app opens, onboarding completion, sign-ups, logins, paywall views, subscription purchases, survey progress and completion, meal generation outcomes, meal views, likes, dislikes, meal logging, grocery item interactions, and weigh-in submissions. These events are tied to a randomly generated account identifier, and your name and email address are attached to that identifier so we can respond to support requests and understand how the App is used. Some events do include health-related values, specifically the body weight you log, your calculated energy expenditure at the end of the first-week calibration, and the names of meals you view or rate. Your survey responses, health conditions, medications, allergies, and calorie or macronutrient targets are not sent
1e. App — Subscription Information
- Subscription status — whether your subscription is active, the source (promotional code, in-app purchase), and expiration date
- Promotional codes — codes you have redeemed
We do not directly collect or store payment card numbers. Payment processing for in-app purchases is handled entirely by Apple (App Store) or Google (Play Store) through their respective payment systems.
1f. Device and Technical Information
We automatically collect certain technical information to maintain and improve our Services:
- Device information — device type, model, operating system version, language and region, time zone, and screen size. This is collected by our crash reporting, and separately by our analytics provider, which attaches it to every event
- App version — the version of the Tailored Nutrition App you are using
- App lifecycle events — our analytics provider records automatically when the App is installed, updated, opened, brought to the foreground, or sent to the background
- Crash and error data — error stack traces and application performance metrics (collected via Sentry when the App encounters an error)
- IP address — recorded in server access logs for security and rate-limiting purposes. Analytics events are sent from your device straight to PostHog, so PostHog also sees your IP address and derives an approximate location from it, such as country, region, and city
- Time zone — sent with some requests so the App knows which calendar day it is where you are. We use it and discard it; it is not stored on your account
We do not collect advertising identifiers (IDFA/GAID), GPS or other precise location data, contacts, photos, camera or microphone access, health data from other apps on your device, or biometric identifiers. The App never asks for location permission and cannot read your device's location. The only location signal that exists anywhere in our Services is the approximate, IP-derived one described above.
We do not connect to Apple Health, Google Fit, or any wearable or fitness tracker. Every piece of health information we hold is something you typed into the App yourself.
1g. Local Device Storage
To provide a seamless experience, certain data is stored locally on your device:
- Authentication tokens — stored in your device's encrypted secure storage (platform-native secure keychain)
- Survey draft — if you begin but do not complete the health survey, your in-progress answers, which include any health information you have entered so far, are saved locally on your device so you can resume later. This draft is stored in standard app storage and is cleared when you submit the survey or log out. It may persist on the device if your session ends unexpectedly rather than through logout
- Consent and preference flags — small boolean values recording whether you have completed onboarding steps (e.g., health data consent acknowledgment)
Data stored in your device's standard app storage (as opposed to the encrypted secure storage used for authentication tokens) is protected by your device's built-in security features (device lock, OS-level app sandboxing) but is not additionally encrypted by our App.
2. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Personalized nutrition plans — Calculate your nutritional targets (calories, macronutrients, micronutrients) and generate AI-powered meal plans | Survey responses, health data, dietary preferences | Your consent; performance of services you requested |
| Adaptive recommendations — Refine your calorie and macronutrient targets over time through our adaptive TDEE system | Food log, weight log | Your consent; performance of services you requested |
| Time-sensitive updates — Automatically recalculate age, pregnancy week, breastfeeding stage, and training progression | Date of birth, reproductive health data, training data | Performance of services you requested |
| In-app chat assistance — Provide personalized answers through the nutrition assistant, if and when we make this feature available | Profile data, chat messages | Your consent; performance of services you requested |
| Account authentication — Verify your identity and provide secure access | Email, password hash, auth tokens | Performance of services you requested |
| Communications — Send password reset codes and service-related communications, and respond to support requests | Email address | Performance of services you requested; your consent (for marketing) |
| Service improvement — Improve our algorithms and Services | Aggregated, de-identified usage patterns only | Legitimate interest |
| Security and abuse prevention — Detect fraud, enforce rate limits, and prevent abuse | IP address, device info, authentication logs | Legitimate interest |
3. AI and Automated Processing
Our Services use artificial intelligence to provide core functionality. We want you to understand exactly how your data is processed by AI systems.
Your data is NOT used to train AI models. Our AI provider, Anthropic, processes your data solely to generate responses on our behalf. Under Anthropic's commercial API data usage policy, customer API inputs and outputs are not used to train their models. Your health data, survey responses, and chat conversations are never used for AI training by our provider or by Tailored Nutrition.
We do not send your name, email address, or account identifier to our AI provider. The information we send is pseudonymous, but because it can include free-text medical details, it is not fully anonymous. Our provider retains data under its own policies, and we have not contracted for a zero-retention arrangement. To reduce cost, we also ask our provider to cache the reusable part of our prompts, which can hold that content on its systems for up to an hour.
3a. Meal Plan Generation
Meal generation is only partly an AI process, and we think the distinction matters for your privacy. Your meals are selected from a curated recipe catalog and portioned by our own software; nutrition values are computed from the USDA FoodData Central database. An AI model is then asked to write the recipe text around ingredients and amounts that are already fixed.
Because of that design, the data sent to our AI provider for meal generation is narrower than you might expect. The meal-writing request contains the ingredients and exact amounts we have already fixed, your dietary restrictions and religious dietary preferences, your food allergies, your food dislikes in your own words, and any food limits or timing guidance derived from the medications and conditions you disclosed. Those limits are sent as food names. The name of the medication or condition behind a limit is not written into the meal request itself, although it can appear in the short explanatory note attached to timing guidance. Your age, sex, height, weight, and overall energy expenditure are not sent for meal generation.
Two narrower cases send more. If you ask for an additional meal and describe what you want, that note is sent to our AI provider as you wrote it, after we strip control characters and shorten it. And if a generated meal drifts from your targets, we may send that meal together with your calorie and macronutrient targets for the slot so a model can help correct it.
3b. Health Data Interpretation
When you enter free-text health information during the survey, specifically medications with their doses and frequencies, medical conditions with any details you add, and custom allergy descriptions, that text is sent to our AI provider so it can be interpreted. The model returns nutrient effects, food restrictions, meal-timing notes, supplement suggestions, and an assessment of whether a stated dose falls outside typical ranges. This is the most sensitive data we send to any third party. It is sent as free text, exactly as you typed it.
3c. Nutrition Chat Assistant
The in-app chat assistant is not currently available to users. If we make it available, your messages, your current health profile including medications, conditions, and reproductive health status, your recent food and weight logs, and your recent conversation history would be sent to our AI provider so the assistant can respond in context.
3d. Nutrition Data Lookup
We query the USDA FoodData Central database for the nutrition values used to compute your meals. Only generic ingredient names are sent. No account identifier, personal information, or health data is included in these queries, and the results are cached on our servers.
3e. Automated Decision-Making
Our AI systems generate meal plan recommendations and nutritional targets based on the data you provide. These are recommendations, not binding decisions. You retain full control to:
- Review, modify, or reject any AI-generated meal plan
- Update your survey responses at any time to change the recommendations you receive
- Contact us to request human review of any AI-generated recommendation
We do not use automated processing to make decisions that produce legal effects or similarly significant effects concerning you.
3f. AI Limitations
AI-generated content, including meal plans, nutritional data, and chat responses, may contain errors, omissions, or suggestions that may not be appropriate for your specific health needs. While we strive for accuracy and cross-validate nutritional data against the USDA database, you should always verify critical nutritional information and consult with a healthcare professional before making significant dietary changes, especially if you have food allergies, medical conditions, or take medications.
3g. Personal Nutrition Profile
The Goals tab shows a written Personal Nutrition Profile summarizing your plan and what shaped it. The facts in it are calculated by our own software. To phrase them, we send our AI provider your daily calorie target, whether you are losing, gaining, or maintaining weight, how many days a week you train, and a note about how much your plan leans on protein. Your name, email address, account identifier, age, sex, height, weight, medications, and conditions are not sent for this feature.
4. Third-Party Service Providers
We use the following categories of third-party service providers to operate our Services:
- AI processing — Anthropic (Claude) — Anthropic is our only AI provider. It is used for recipe text generation and for interpreting the free-text health information you enter, as described in Section 3. Data sent to Anthropic is used solely to process our requests and generate responses, and is not used to train their models under their commercial API data usage policy. Anthropic does not receive your name, email address, or account identifier.
- Authentication providers — Google and Apple — If you choose to sign in with Google or Apple, your authentication token is verified with the respective provider. We receive only your email address and, optionally, your name.
- Email delivery — Resend — We use Resend to deliver password reset codes and to route bug reports and support correspondence to us. For a password reset, the service receives your email address and the reset code. For a bug report, it receives your name, email address, account identifier, and whatever you wrote in the report.
- Nutrition database — USDA FoodData Central — We query this U.S. government database for the nutrition values used to compute your meals. Only generic ingredient names are sent. No personal information or account identifier is included in these queries.
- Cloud infrastructure — Google Cloud Platform (GCP) — We host our Services on Google Cloud Run, and your account data is stored in a Google Cloud SQL database. GCP processes and stores your data as a contractually bound data processor. All data resides in the United States.
- Push notifications and app updates — Expo — We use Expo to deliver push notifications and over-the-air app updates. Expo receives your device's push notification token and the text of any push notification we send you. Because the App checks Expo for over-the-air updates, Expo also receives a per-installation identifier along with your platform and app runtime version each time it checks. Push notifications we send are generic, for example telling you that your meal plan is ready. Reminders that reference your logging activity are scheduled on your own device and are not sent through Expo.
- Crash and error reporting — Sentry — We use Sentry to collect crash reports and error logs from our mobile app and backend servers. Reports include device type, operating system version, app version, error stack traces, and your user ID and email address. Error reports can also include data you submitted in the request that failed, and diagnostic context from the point of failure. Where the failure happens while processing health information, that health information can appear in the report. We do not send health data to Sentry intentionally or as part of normal operation, but we cannot represent that error reports never contain it. Crash reporting is active in production; it is disabled in development builds of the mobile app but not on our backend servers.
- Product analytics — PostHog — We use PostHog to understand how users interact with our App. Events are tied to a randomly generated account identifier, and PostHog receives your name and email address attached to that identifier. As described in Section 1d, a small number of events do include health-related values: the body weight you log, your calculated energy expenditure at the end of first-week calibration, and the names of meals you view or rate. Your survey responses, health conditions, medications, allergies, and nutrition targets are not sent. Because analytics events are sent from your device directly to PostHog, PostHog also receives your IP address and derives an approximate location from it (country, region, city). Session replay is switched off. Events from our own internal development and test builds are labelled as such so they can be separated from real usage.
- Subscription management — RevenueCat — We use RevenueCat to manage in-app subscriptions and verify purchase authenticity. RevenueCat receives your account identifier, email address, and subscription status, and processes subscription lifecycle events. RevenueCat does not receive your name, health data, or survey responses.
- Security cache — Upstash Redis — We use Upstash Redis to store rate limiting counters, authentication token blocklists, and account lockout data. This data is short-lived and automatically purged, typically within minutes to hours. It includes your email address and IP address as security state. No health data is stored in Redis.
- Web fonts — Google Fonts — Our Website loads fonts from Google, which discloses your IP address and browser information to Google when you visit a page on our Website. This applies to the Website only, not the App.
- Grocery shopping integration — Instacart — This integration is not currently active and no data is sent to Instacart. If we activate it, your grocery list items (ingredient names, quantities, and units) would be sent to Instacart to create a shoppable list, with no health data or account information included.
We do not use any advertising network, data broker, marketing automation platform, or cross-app tracking service. Our App requests no advertising identifier and cannot present a tracking permission prompt, because it does not track you.
All third-party service providers are contractually bound to use your information only for the purpose of providing services to us and are prohibited from using it for their own purposes. If we change service providers or add new ones that handle personal data, we will update this policy accordingly.
5. Information Sharing and Disclosure
We do not sell, rent, or share your personal information with third parties for their direct marketing purposes. We do not share your data with advertising platforms, data brokers, social media companies, employers, insurers, or creditors.
We may disclose your information only in the following circumstances:
- Service providers — As described in Section 4, to third-party providers who perform services on our behalf
- Legal requirements — If required by law, regulation, subpoena, court order, or other legal process
- Safety — If we believe disclosure is necessary to protect the rights, property, or safety of Tailored Nutrition, our users, or the public
- Business transfers — In connection with a merger, acquisition, or sale of all or a portion of our assets, in which case you will be notified via a prominent notice on our Website or within the App before your personal information is transferred to a new entity
- Anonymized feedback — Feature requests and bug reports you submit through the in-app feedback system are displayed to other users in an anonymized form (your name and email are never shown)
- Referral partners — If you signed up using a referral code from one of our promotional partners, we record that your account is attributed to that partner. Because we pay partners a commission based on referred subscriptions, we share limited account information with the partner who referred you, which may include your email address and whether your subscription is active. We do not share your survey responses, health data, meal plans, or logs with referral partners. This applies only if you applied a referral code
6. Cookies, Tracking Technologies, and Do Not Track
Our Website does not use cookies, tracking cookies, analytics services, or advertising pixels. We do not track your activity across other websites. The only third-party resource our Website loads is Google Fonts, which discloses your IP address and browser information to Google as described in Sections 1a and 4, and which does not set a cookie or identify you personally.
Our App uses local device storage (secure storage for authentication tokens) and the PostHog analytics SDK to collect usage events as described in Section 1d. PostHog does not use advertising identifiers or enable cross-app tracking. We do not use advertising networks or cross-app tracking technologies.
Do Not Track (DNT) and Global Privacy Control (GPC): Because our Services do not track users across third-party websites or apps, we do not respond to DNT browser signals — no third-party tracking occurs regardless. We honor Global Privacy Control (GPC) signals; however, since we do not sell or share personal information for advertising, no additional action is required when a GPC signal is detected.
7. Data Retention
We retain your personal information only for as long as necessary to provide the Services and fulfill the purposes described in this policy. The specific retention periods are:
| Data Type | Retention Period |
|---|---|
| Account credentials (email, name, password hash) | Duration of active account |
| Survey and health data | Duration of active account; permanently deleted on account deletion |
| Food and weight logs | Duration of active account; permanently deleted on account deletion |
| Chat conversations | Duration of active account; permanently deleted on account deletion |
| Meal plans and preferences | Duration of active account; permanently deleted on account deletion |
| Grocery cart data | Duration of active account; permanently deleted on account deletion |
| Notification preferences | Duration of active account; permanently deleted on account deletion |
| Subscription records | Duration of active account; may be retained up to 7 years after deletion for tax and legal compliance |
| Password reset codes | Unusable after 15 minutes. The stored record is removed when the code is used, when verification fails five times, or when you request a new one. A reset you request and never use may leave an expired, unusable record |
| Authentication tokens (revoked) | Until the token's original expiration, then automatically purged. Access tokens expire after 24 hours and refresh tokens after 90 days |
| Crash reports (Sentry) | Per Sentry's retention policy |
| Server and audit logs (including IP and email address) | Per our cloud provider's log retention settings. These logs are not deleted when you delete your account |
| Feedback board posts | Retained indefinitely. On account deletion the post is disassociated from you, but its text remains visible to other users |
| Support and bug report correspondence | Retained as business records; not deleted when you delete your account |
| Aggregated, de-identified data | May be retained indefinitely; this data cannot be used to re-identify any individual |
| Analytics events (PostHog) | Per PostHog's retention policy (typically 90 days) |
| Rate limiting and security data (Redis) | Minutes to hours (automatically purged). A revoked token identifier is held until the token would have expired on its own, which can be up to 90 days |
Account Deletion
You can delete your account at any time from the More tab in the App. When you do, your account record, survey responses and the health data in them, meal plans, food and weight logs, adaptive calculations and first-week calibration, meal preferences, grocery cart, chat history, meal generation history, notification data and push registrations are permanently deleted from our active systems. Deletion is immediate and irreversible.
We want to be precise about what deletion does not cover. None of the following is your survey data, your logs, or your plan, those are deleted:
- Feedback board posts remain visible, disassociated from your account
- Security and audit logs, which record events such as account creation, login, and deletion along with your email address and IP address, are retained
- Support requests and bug reports you sent us are retained as business records
- Transaction and promotional code records are retained where we need them for tax, accounting, or fraud prevention
- Data already held by third-party providers, including error reports at Sentry, analytics events at PostHog, purchase records at Apple, Google, and RevenueCat, and data processed by our AI provider, is subject to their own retention practices. Deleting your account does not trigger deletion at those providers. If you want data removed from a specific provider, contact us and we will make the request on your behalf where the provider supports it
- Database backups. Our database is backed up on a rolling basis, so a deleted record can remain inside a backup until that backup ages out. Backups exist for disaster recovery and are not used to restore a deleted account
As disclosed in our Terms of Service (Section 13), we may retain anonymized, aggregated data sets derived from User Content that do not identify individual users. Such data cannot be linked back to you after account deletion.
Inactive Accounts
We do not currently delete inactive accounts. Your data is retained until you delete your account. We may implement an inactive account deletion policy in the future to comply with data minimization principles. If we do, we will update this policy with specific timelines and notify you by email before any deletion occurs.
8. Data Security and Breach Notification
8a. Security Measures
We implement the following security measures to protect your personal information:
- Password hashing — Passwords are hashed using an industry-standard one-way hashing algorithm with salt. We never store plaintext passwords.
- Secure token storage — Authentication tokens are stored in your device's platform-native secure storage, not in plaintext or local storage.
- Token revocation — Logging out invalidates your active session token, and account deletion revokes access immediately.
- Access controls — Your data is stored in a managed cloud database that is not exposed to the public internet and is reachable only by our application servers. Your data is accessible only to you through your authenticated account.
- Encryption at rest — Data stored in our cloud database is encrypted at rest by our cloud provider at the storage layer. We do not apply an additional layer of application-level encryption on top of it.
- Input validation — User inputs are validated and sanitized to prevent injection attacks, including sanitization of free text before it is sent to our AI provider.
- Rate limiting — Endpoints are rate-limited to prevent brute-force and abuse, with account lockout after repeated failed login attempts. This state is shared across server instances via Redis.
- Encryption in transit — All data transmitted between your device and our servers is encrypted using TLS (HTTPS), enforced by HTTP Strict Transport Security.
- Server hardening — Our API sets restrictive security headers, limits request sizes, and restricts cross-origin access to an explicit allowlist.
- Audit logging — Security-sensitive operations (account creation, login, password changes, email changes, account deletion, survey resets, data exports) are logged with timestamps for incident investigation.
While we take reasonable measures to protect your information, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.
8b. Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected individuals by email and through an in-app notification without unreasonable delay, and no later than 60 days after discovery of the breach, consistent with the FTC Health Breach Notification Rule
- Notify the Federal Trade Commission (FTC) as required by applicable law
- Provide a description of the breach, the types of data involved, the steps we are taking to address the breach, and recommended steps you can take to protect yourself
- Comply with all applicable state breach notification laws, which may require shorter notification timelines in certain jurisdictions
8c. HIPAA Disclaimer
Tailored Nutrition is not a HIPAA covered entity or business associate. We do not create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of any healthcare provider, health plan, or healthcare clearinghouse. The health data you provide is consumer-generated wellness data, not clinical health records. If you have questions about how your health data may be protected under other laws, see Section 10 (U.S. State Privacy Rights) and our Consumer Health Data Privacy Policy.
9. Your Rights and Choices
You have the following rights regarding your personal information. We extend these rights to all users, regardless of your state or country of residence:
- Access and data portability — You can download a copy of your personal data in JSON format at any time from More > Export My Data in the App. The export is generated immediately. You may also request a copy by contacting us.
- Correction — You may update your survey responses, name, and email address at any time within the App. You may also request corrections by contacting us.
- Deletion — You may delete your entire account at any time through the App (More > Delete Account), subject to the limits described in Section 7. You may also request deletion by contacting us.
- Withdraw consent — You may withdraw your consent to the collection and processing of your health data at any time by deleting your account or contacting us. Because health data is what the Services are built on, withdrawing consent effectively ends your ability to use them.
- Opt-out of communications — We do not currently send marketing email. The emails we send are transactional, such as password reset codes, and are necessary to operate your account. You may stop all email from us by deleting your account, and you may customize or disable notifications as described below.
- Notification control — You may customize or disable any category of in-app notifications through the App's notification preferences.
- Right to appeal — If we decline to take action on your request, we will inform you of the reason and provide instructions for how to appeal the decision. You may also file a complaint with the Attorney General of your state or the Federal Trade Commission.
How to Exercise Your Rights
To exercise any of these rights, contact us at support@tailorednutritionllc.org. You may also submit requests through an authorized agent; if you use an authorized agent, we may require the agent to provide proof of written authorization and we may verify your identity directly.
Response timeline: We will acknowledge your request within 10 business days and complete it within 30 days. If we need additional time (up to 15 additional days for complex requests), we will notify you in writing with an explanation.
Identity verification: Before processing requests to access, correct, or delete your data, we will verify your identity by asking you to confirm information associated with your account (such as your email address).
10. U.S. State Privacy Rights
We provide the core privacy rights described in Section 9 to all U.S. residents, regardless of which state you live in. The following disclosures address additional requirements under specific state privacy laws.
10a. California (CCPA/CPRA & CalOPPA)
If you are a California resident, you may have additional rights under the CCPA/CPRA depending on applicable thresholds. In compliance with CalOPPA and regardless of whether we currently meet CCPA thresholds, we voluntarily provide the following disclosures:
| Category of Personal Information | Specific Data Elements | Source | Business Purpose | Sold or Shared? |
|---|---|---|---|---|
| Identifiers | Email address, name, IP address | Directly from you; automatically collected | Account creation, authentication, security | No |
| Health information | Height, weight, BMI, health conditions, medications, reproductive health, allergies (see Section 1c). We do not collect biometric identifiers such as fingerprints or face scans | Directly from you; derived by our systems | Personalized meal plan generation, adaptive recommendations | No |
| Commercial information | Subscription status, promotional codes | From app store payment systems; directly from you | Subscription management, entitlement verification | No |
| Internet or electronic network activity | App usage data, food logs, weight logs, chat messages, crash reports (see Sections 1d, 1f) | Automatically collected; directly from you | Service delivery, adaptive recommendations, error monitoring | No |
| Sensitive personal information | Health data, medications, reproductive health, substance use (see Section 1c) | Directly from you | Personalized nutrition services at your explicit direction | No |
Additional California rights:
- Sale or sharing — We do not sell or share your personal information as defined by the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.
- Right to limit use of sensitive personal information — Because we use sensitive personal information only to provide the services you have requested, no additional limitation is necessary.
- Non-discrimination — We will not discriminate against you for exercising any of your privacy rights.
- "Shine the Light" — We do not share personal information with third parties for their direct marketing purposes.
10b. Virginia (VCDPA)
If you are a Virginia resident, you have the rights described in Section 9. Additionally:
- Reproductive and sexual health data — Under the VCDPA amendments effective July 1, 2025, we are required to obtain consent before collecting reproductive and sexual health information. Before the survey begins, the App presents a health data consent screen that identifies reproductive health information as one of the categories collected and states that it is optional. You must accept it to proceed, and the reproductive health questions themselves are optional. You may withdraw this consent at any time by deleting your account.
- Right to opt out of profiling — You may opt out of profiling that produces legal or similarly significant effects. Our AI-generated meal plans are recommendations that you can accept, modify, or reject, and we do not believe they produce such effects. If you disagree, contact us to opt out.
10c. Colorado (CPA)
If you are a Colorado resident, you have the rights described in Section 9. We support universal opt-out mechanisms as required by the Colorado Privacy Act.
10d. Connecticut (CTDPA)
If you are a Connecticut resident, you have the rights described in Section 9. For additional protections specific to consumer health data, see our Consumer Health Data Privacy Policy, which includes geofencing restrictions and enhanced consent requirements under Connecticut law.
10e. Washington, Nevada, and Other State Health Data Laws
If you are a resident of Washington, Nevada, Connecticut, or another state with consumer health data privacy laws, please see our Consumer Health Data Privacy Policy for detailed disclosures about how we collect, use, share, and protect your consumer health data, including your specific rights under those laws.
10f. Additional States
As additional state privacy laws take effect, we will extend the rights described in Section 9 to residents of those states. Because we already provide core privacy rights to all users universally, we believe we meet or exceed the requirements of all currently effective U.S. state consumer privacy laws.
11. Children's Privacy
Our Services are restricted to users who are 18 years of age or older, and our app store listings are age-rated accordingly. We do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18, we will delete their account and the associated data.
In compliance with the Children's Online Privacy Protection Act (COPPA), if we learn that we have inadvertently collected personal information from a child under 13, we will promptly delete that information and terminate the associated account.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@tailorednutritionllc.org and we will take steps to delete that information.
12. International Users
Tailored Nutrition is operated from the United States. If you access or use our Services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
By using our Services, you consent to the transfer of your information to the United States and acknowledge that your data will be subject to U.S. law.
European Economic Area (EEA), United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland:
- Legal basis for processing — We process your personal data based on the legal bases described in Section 2 (consent, performance of a contract, legitimate interest). For health data classified as special category data under GDPR Article 9, we rely on your explicit consent, which is obtained during the onboarding survey.
- Data transfers — Your data is transferred to the United States. We rely on your explicit consent as the legal mechanism for this transfer.
- Your rights — In addition to the rights in Section 9, you have the right to lodge a complaint with your local data protection supervisory authority.
- Data Protection Officer — For privacy inquiries related to GDPR, contact us at support@tailorednutritionllc.org.
We are committed to protecting your data regardless of your location. If you have questions about how your data is handled under the laws of your jurisdiction, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Effective Date" at the top of this page
- Post the revised policy on our Website
- Give you advance notice by email or in-app notification before any change that materially affects how we collect, use, or share your personal information takes effect. We will make the notice period reasonable in light of the change rather than committing to a fixed number of days. Clarifications, corrections, and changes that do not materially affect your rights may take effect when posted
- Obtain your consent before using health data we already hold for a materially different purpose than the one disclosed when you provided it, where the law requires consent for that use. In those cases we will ask rather than rely on notice
Prior versions of this policy will be available upon request. We encourage you to review this page periodically.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights regarding your personal information, or have concerns about how your data is handled, please contact us:
Tailored Nutrition LLC
Email: support@tailorednutritionllc.org
We will respond to privacy-related inquiries within 30 days.