Consumer Health Data Privacy Policy
Version 1.3 · Effective June 8, 2026
This Consumer Health Data Privacy Policy is required by the Washington My Health My Data Act (RCW 19.373) and the consumer health data laws of Nevada (SB 370) and Connecticut. It describes the consumer health data Idunia collects, the purposes and sources, the categories of third parties and affiliates it is shared with, and how you exercise your rights. It is separate from our general Privacy Policy and our Terms.
1. Categories of consumer health data we collect
You enter all of this yourself:
- Cycle / reproductive data — menstrual cycle dates, flow, and a single on/off setting for whether you track your cycle. We do not ask or store why you turn cycle tracking off.
- Nutrition data — foods you log and the resulting macro- and micronutrient totals.
- Training & body data — workouts, sleep, hydration, supplements, and body metrics you enter (age, height, weight, optional body-fat %).
- Health indicators we calculate — your energy-availability / RED-S indicators and micronutrient-sufficiency indicators, derived from the data above.
2. Sources
We collect consumer health data directly from you, through what you enter in the app. We do not buy it and do not obtain it from data brokers or advertising networks.
3. Purposes
Solely to provide the app's features to you: calculating your targets and indicators and showing your own history back to you. We do not use it for advertising, marketing, profiling, or to train models for anyone else.
4. Categories of consumer health data we share
We do not share or sell your consumer health data. We have no advertising, analytics, attribution, or tracking software in the app.
Three service providers handle your data solely on our behalf, only to run the app for you. Each is contractually prohibited from using your data for any purpose of its own. Using a service provider to process or store data for you is not "sharing" or "selling" under these laws.
- Supabase, Inc. — our hosting provider. Stores your account, nutrition, training, and body data.
- AWS (Amazon Bedrock) — our meal-parsing provider. When you log a meal in plain language, the meal text you type is sent to Amazon Nova, an Amazon-built model running on AWS Bedrock, to structure it into food items (for example, turning "oatmeal with a banana" into a list of items). Only the meal text is sent. It is not tagged with your name or email, and no cycle, body, or training data is included. The nutrient numbers are then looked up from our own food database; the model never produces them. Under AWS's terms, your input is not used to train Amazon Nova or any other model and is not shared with any third-party model provider; the text is encrypted in transit (TLS) and at rest. See AWS's Bedrock Security and Privacy page and Bedrock Data Privacy FAQ.
- RevenueCat, Inc. — our subscription-billing provider. To run the paid subscription, your account identifier (the same ID that identifies you to our backend) and your purchase and subscription-status events are sent to RevenueCat (
api.revenuecat.com). No cycle, nutrition, body, training, or other health data is sent to RevenueCat — only the account identifier and purchase events. RevenueCat does not collect any advertising or device identifier from you (we do not enable that feature); the Google Play payment itself is processed by Google. See RevenueCat's Privacy Policy.
Your cycle/reproductive data never reaches any of these providers, because it stays on your device.
5. Categories of third parties and specific affiliates
- Specific affiliates: We have no affiliates.
- Third parties we share consumer health data with: None.
- Service providers (processors acting only for us): Supabase, Inc. (hosting/storage), AWS (Amazon Bedrock) (meal-text parsing only — see Section 4), and RevenueCat, Inc. (subscription billing only — see Section 4).
6. Where your data is stored and how it is protected
- Your cycle/reproductive data is stored only on your device, in an encrypted file whose key is held by your device's operating system. It is never sent to our servers, so we cannot access it or be compelled to produce it.
- Your other data is stored on our hosted backend (Supabase). It is encrypted in transit (TLS) and at rest, access is limited to operating the app, and we do not browse your health data.
- When you log a meal by typing it, the meal text only is sent over an encrypted (TLS) connection to AWS (Amazon Bedrock) to structure it into food items (see Section 4). Under AWS's terms the text is not used to train its models and is not shared with third-party model providers, and it is not tagged with your identity.
- When you subscribe, your account identifier and purchase/subscription events are sent over an encrypted (TLS) connection to RevenueCat to manage your subscription (see Section 4). No health data is included, and no advertising or device identifier is collected.
7. Your rights
You may at any time:
- Access / confirm what consumer health data we hold and the list of any third parties or affiliates that received it. Our service providers are Supabase, Inc. (hosting; privacy contact: privacy@supabase.com), AWS (Amazon Bedrock) (meal-text parsing only), and RevenueCat, Inc. (subscription billing only). We share your consumer health data with no other third parties or affiliates.
- Export your data (in a machine-readable file). Your server-side data is included. Your cycle/reproductive data lives only on your device and is not included in this export; this version of the app does not move cycle data off your device.
- Delete your data. In Settings: delete cycle data (wipes it from your device) and/or delete your account (removes your server-side data). Deleting your account does not erase cycle data already on your device — delete cycle history or uninstall to remove that. If you cannot use the app, you can also request deletion from our account-deletion page or by emailing founders@maxoutput.ai.
- Withdraw consent. Cycle tracking is optional — turn it off anytime and choose to delete it, and keep using the app. Nutrition and training data are required to run the app; to stop that collection, delete your account.
To exercise any right, use the in-app controls or email founders@maxoutput.ai. We respond as soon as we can and no later than 45 days; if we need more time we will tell you why. If we decline a request, we will explain why and how to appeal.
8. Retention
Cycle data stays on your device until you delete it or uninstall the app; we keep no server copy. Other data is retained until you delete it or close your account; we remove deleted data from active systems promptly and from backups within 90 days.
9. Changes
If we materially change what we collect or how we use it, we will ask for your consent again before the change applies to data already collected. We will not retroactively apply new uses to previously collected data without your opt-in.
Contact: founders@maxoutput.ai
Change history
- v1.3 (June 8, 2026): Corrected the meal-text parsing provider to AWS (Amazon Bedrock), running the Amazon Nova model (Sections 4–7). The prior version named Anthropic, PBC (Claude), which no longer reflects the deployed parser. Replaced the Anthropic-term citations with AWS Bedrock's data-handling terms (not used to train models, not shared with third-party model providers, encrypted in transit and at rest).
- v1.2 (June 4, 2026): Disclosed RevenueCat, Inc. as our subscription-billing service provider (Sections 4–7): it receives your account identifier and purchase/subscription events only — no health data, and no advertising or device identifier. Updated the service-provider count from two to three.
- v1.1 (June 4, 2026): Disclosed Anthropic, PBC as a service provider that parses meal text into food items (Sections 4–7). Removed the description of a "Report a problem" diagnostics feature that is not present in v1; diagnostics are not collected.
- v1.0 (June 3, 2026): Initial version.