Consumer Health Data Privacy Policy
Version 3.0 · Effective September 18, 2026
This Consumer Health Data Privacy Policy is required by the Washington My Health My Data Act (RCW 19.373) and the consumer health data laws of Nevada (SB 370) and Connecticut. It describes the consumer health data Idunia collects, the purposes and sources, the categories of third parties and affiliates it is shared with, and how you exercise your rights. It is separate from our general Privacy Policy and our Terms.
1. Categories of consumer health data we collect
Most of this you enter yourself; the exceptions are workout data you choose to import from a connected health platform, described in the Training & body data row below and in Section 2, and what the Idunia Apple Watch app reads during a run you start on it, described in the same row:
- Cycle / reproductive data — menstrual cycle dates, flow, and a single on/off setting for whether you track your cycle. We do not ask or store why you turn cycle tracking off.
- Nutrition data — foods you log and the resulting macro- and micronutrient totals.
- Training & body data — workouts, sleep, hydration, supplements, and body metrics you enter (age, height, weight, optional body-fat %). If you choose to connect Apple Health (iOS) or Health Connect (Android), we also import workouts and the calories those workouts burned from that connected health platform. On Health Connect (Android) that means both the active-calorie and the total-calorie records covering the workout, because several widely used Android health apps, including Google Fit and Google Health, write only the total-calorie kind; see Section 2. Idunia writes to Apple Health only the runs you start on the Idunia Apple Watch app, saved as workouts, and never writes food, weight, cycle, or any other data. During a run you start on the Idunia Apple Watch app, that app also reads your heart rate, active energy, and distance for that run, to show them on your wrist and in Idunia.
- Health indicators we calculate — your energy-availability / RED-S indicators and micronutrient-sufficiency indicators, derived from the data above.
- Feedback you send us — if you use the in-app Feedback feature, the free text you type and any photos or screenshots you choose to attach. A screenshot may incidentally show other data described in this policy (for example logged nutrition or a cycle summary) if it was on your screen when you took it; any other photo you attach could likewise show personal information depending on what it is a photo of.
2. Sources
We collect consumer health data directly from you, through what you enter in the app, and — only if you choose to turn it on — from your device's connected health platform (Apple Health on iOS, Health Connect on Android). That connection is optional, off by default, gated behind your explicit in-app consent, and revocable at any time in Settings → Training sync. When connected, we import workouts and the calories burned during them only. On Apple Health (iOS) that is the energy each workout itself records. On Health Connect (Android) it is the active-calorie and total-calorie records for that workout's own time window, from the same app that recorded the workout; we read the total-calorie record only when no active-calorie data exists for the workout, and we subtract a standard resting-energy allowance from it so it reflects the workout rather than the whole period. Idunia writes to Apple Health only the runs you start on the Idunia Apple Watch app, saved as workouts, and never writes food, weight, cycle, or any other data. Once connected, the import can happen automatically in the background (not only when you have the app open), so you keep receiving your training data without opening the app every time. We do not buy consumer health data and do not obtain it from data brokers or advertising networks.
3. Purposes
Solely to provide the app's features to you: calculating your targets and indicators, showing your own history back to you, and — if you use the in-app Feedback feature — reading and responding to what you send us. We do not use it for advertising, marketing, profiling, or to train models for anyone else.
4. Categories of consumer health data we share
We do not share or sell your consumer health data. We have no advertising, analytics, attribution, or tracking software in the app.
Three service providers handle your data solely on our behalf, only to run the app for you. Each is contractually prohibited from using your data for any purpose of its own. One public database, Open Food Facts, is also listed below: it receives only the number of a barcode you scan, never anything about you. Using a service provider to process or store data for you is not "sharing" or "selling" under these laws.
- Supabase, Inc. — our hosting provider. Stores your account, nutrition, training, and body data, and any feedback you send us.
- AWS (Amazon Bedrock): our AI parsing provider. With your in-app consent (asked before first use and revocable at any time in Settings, under "AI meal logging"), the inputs you choose to provide are sent to Amazon Nova, an Amazon-built model running on AWS Bedrock, to structure them into entries you review. Exactly four kinds of input can be sent, each only at the moment you use its feature: the meal text you type (for example, turning "oatmeal with a banana" into a list of items), a meal photo you choose to submit, the text of a recipe page you share into the app (sent only when the page does not already carry machine-readable recipe data), and the training description you type when you ask for a training suggestion. Only the input you provide is sent. It is not tagged with your name or email, and no cycle or body data is included with it. The nutrient numbers are then looked up from our own food database, and your targets and indicators are computed by the app itself; the model never produces your numbers. What comes back is always an editable suggestion you review. Under AWS's terms, your input is not used to train Amazon Nova or any other model and is not shared with any third-party model provider; it is encrypted in transit (TLS) and at rest. If you decline or turn AI parsing off, manual logging keeps working in full. See AWS's Bedrock Security and Privacy page and Bedrock Data Privacy FAQ.
- Open Food Facts: the public food database behind barcode scans. When you scan a packaged food's barcode, our server sends the barcode number to Open Food Facts (
world.openfoodfacts.org) over an encrypted (HTTPS) connection to look up that product's name, brand, serving size, and nutrient values. Only the barcode number is sent, never your identity. The lookup carries no account identifier, name, email, or health data, and because our server makes it for you, Open Food Facts does not see your device either. A barcode number identifies a product, not you. What comes back is that product's label data, which the app shows you as an entry you review and can edit. Our server keeps its own log that your account looked up that barcode, to operate the feature and protect it from abuse; that log stays with our hosting provider (Supabase) and is never sent to Open Food Facts. Open Food Facts is a public database, not a contracted service provider, and it receives nothing else. - RevenueCat, Inc. — our subscription-billing provider. To run the paid subscription, your account identifier (the same ID that identifies you to our backend) and your purchase and subscription-status events are sent to RevenueCat (
api.revenuecat.com). No cycle, nutrition, body, training, or other health data is sent to RevenueCat — only the account identifier and purchase events. RevenueCat does not collect any advertising or device identifier from you (we do not enable that feature); the Google Play payment itself is processed by Google. See RevenueCat's Privacy Policy.
Your cycle/reproductive data never reaches any of these providers on its own, because it stays on your device. The one exception: if you choose to attach a photo or screenshot to the in-app Feedback feature that happens to show cycle/reproductive information, that image reaches Supabase as feedback content you deliberately chose to send, not as an automatic transfer of your cycle data (see Section 1 and Section 6).
5. Categories of third parties and specific affiliates
- Specific affiliates: We have no affiliates.
- Third parties we share consumer health data with: None.
- Service providers (processors acting only for us): Supabase, Inc. (hosting/storage), AWS (Amazon Bedrock) (AI parsing of the inputs you provide only: meal text, meal photos, shared recipe page text, and training descriptions; see Section 4), and RevenueCat, Inc. (subscription billing only; see Section 4).
6. Where your data is stored and how it is protected
- Your cycle/reproductive data is stored only on your device, in an encrypted file whose key is held by your device's operating system. It is never sent to our servers, so we cannot access it or be compelled to produce it. The one exception is a photo or screenshot you deliberately choose to attach to the in-app Feedback feature: if it shows cycle/reproductive information, that image is uploaded to our servers as feedback content, not as your cycle data (see Section 1 and the Feedback row above).
- Your other data is stored on our hosted backend (Supabase). It is encrypted in transit (TLS) and at rest, access is limited to operating the app, and we do not browse your health data.
- Feedback you send us (text and any attached photos or screenshots) is stored privately in Supabase. Only we can read it: there is no way for anyone, including you, to read a submission back through the app after you send it.
- When you use AI parsing (optional and consent-gated), the meal text, meal photo, recipe page text, or training description you provide is sent over an encrypted (TLS) connection to AWS (Amazon Bedrock) to structure it into entries you review (see Section 4). Under AWS's terms the input is not used to train its models and is not shared with third-party model providers, and it is not tagged with your identity.
- When you subscribe, your account identifier and purchase/subscription events are sent over an encrypted (TLS) connection to RevenueCat to manage your subscription (see Section 4). No health data is included, and no advertising or device identifier is collected.
7. Your rights
You may at any time:
- Access / confirm what consumer health data we hold and the list of any third parties or affiliates that received it. Our service providers are Supabase, Inc. (hosting; privacy contact: privacy@supabase.com), AWS (Amazon Bedrock) (AI parsing of the inputs you provide only: meal text, meal photos, shared recipe page text, and training descriptions), and RevenueCat, Inc. (subscription billing only). We share your consumer health data with no other third parties or affiliates.
- Export your data (in a machine-readable file). Your server-side data is included, with two exceptions: your cycle/reproductive data lives only on your device and is not included (this version of the app does not move cycle data off your device), and feedback you have sent us is stored so only we can read it and is likewise not included in this export.
- Delete your data. In Settings: delete cycle data (wipes it from your device) and/or delete your account (removes your server-side data). Deleting your account does not erase cycle data already on your device — delete cycle history or uninstall to remove that. If you cannot use the app, you can also request deletion from our account-deletion page or by emailing founders@maxoutput.ai.
- Withdraw consent. Cycle tracking is optional — turn it off anytime and choose to delete it, and keep using the app. If you connected Apple Health or Health Connect, disconnect it anytime in Settings → Training sync — you can keep logging training manually either way, and no account deletion is required. Nutrition and training data you enter yourself are required to run the app; to stop that collection, delete your account.
To exercise any right, use the in-app controls or email founders@maxoutput.ai. We respond as soon as we can and no later than 45 days; if we need more time we will tell you why. If we decline a request, we will explain why and how to appeal.
8. Retention
Cycle data stays on your device until you delete it or uninstall the app; we keep no server copy. Other data is retained until you delete it or close your account; we remove deleted data from active systems promptly and from backups within 90 days.
9. Changes
If we materially change what we collect or how we use it, we will ask for your consent again before the change applies to data already collected. We will not retroactively apply new uses to previously collected data without your opt-in.
Contact: founders@maxoutput.ai
Change history
- v3.0 (September 18, 2026): Idunia now writes to Apple Health the runs you start on the Idunia Apple Watch app, saved as workouts, governed by the Apple Health permission sheet. A new write direction changes what we do with your data, so this is a major version. It also discloses a new read: during a run you start on that watch app, the watch app reads your heart rate, active energy, and distance for that run, to show them on your wrist and in Idunia. Reading a new record type is a change to what we collect, not a wording revision (the same rule the v2.0 entry states), which is the second reason this is a major version.
- v2.1 (August 23, 2026): Re-authored, as a post-2.0 revision, the AI-input disclosure that the voided v1.8 draft attempted (Sections 4 through 7): our AI parsing provider, AWS Bedrock running Amazon Nova, receives not only the meal text you type but also, at your request, a meal photo you submit, the text of a recipe page you share into the app, and the training description you type when you ask for a training suggestion. Disclosed the explicit AI consent gate that ships with the same release: a consent sheet shown before first use, plus a revocable Settings toggle ("AI meal logging"); declining leaves manual logging fully working. Stated plainly that the model never produces your nutrient numbers, targets, or indicators, and that cycle data never goes to the AI provider. This corrects Section 4 of v2.0, which said only meal text is sent while the shipped app already had all four input paths. Also disclosed the barcode-scan lookup (Section 4), which the voided v1.8 described but no published version ever did: when you scan a packaged food's barcode, our server sends the barcode number, and nothing about you, to the public Open Food Facts database to identify the product. Versions 1.7 through 1.9 remain void and unpublished (see the v2.0 entry); their remaining non-AI corrections (the platform-split wearable import description and what account deletion does to on-device cycle data) are not absorbed here and still await their own post-2.0 revision. The wearable and total-calorie disclosures are unchanged from v2.0.
- v2.0 (August 17, 2026): Widened the wearable-import disclosure (Sections 1 and 2) from "workouts and active-calorie totals" to the calorie data actually read. On Health Connect (Android) Idunia now also reads the total-calorie record, not only the active-calorie one, and derives your exercise energy by subtracting a standard resting-energy allowance from it. It reads the total-calorie record only when no active-calorie data exists for that workout, and only from the same app that recorded the workout. Google Fit and Google Health write only total-calorie records, so before this change athletes using those apps received no calorie data from their own workouts at all. The connection remains optional, off by default, gated behind your explicit in-app consent, and revocable at any time in Settings, and nothing is ever written back to your health app. Apple Health (iOS) is unchanged. Numbered 2.0 rather than 1.7 because reading a new record type is a change to what we collect, not a wording revision. Versions 1.7 through 1.9 were drafted for a release that has not shipped and are not reflected in this document; no version between 1.6 and 2.0 was ever published.
- v1.6 (August 11, 2026): Disclosed wearable/health-platform import (Sections 1, 2, 7): workouts and active-calorie totals imported from a connected Apple Health (iOS) or Health Connect (Android) account are now a collected category alongside data you enter yourself, the connected health platform is now a listed source alongside "directly from you," and Section 2 states plainly that the connection is optional, off by default, consent-gated, revocable anytime in Settings, that import can happen automatically in the background, and that nothing is ever written back to your health app. Section 7's withdraw-consent row now states that disconnecting a health platform does not require deleting your account. Corrects the prior version, which stated (Sections 1–2) that all consumer health data was entered directly by you — no longer accurate once wearable import shipped.
- v1.5 (August 11, 2026): Broadened the Feedback disclosures (Sections 1, 4, 6) from "screenshot" to "photo or screenshot," matching that the in-app picker accepts any image, not only a screenshot of the app. Added feedback review/response to the stated purposes (Section 3). Qualified Section 4's blanket "cycle/reproductive data never reaches any of these providers" to reference the exception Section 6 already disclosed: an attached photo or screenshot showing that data does reach Supabase, as feedback content you chose to send.
- v1.4 (August 9, 2026): Disclosed the in-app Feedback feature (Sections 1, 4, 6, 7): the free text you type and any screenshots you attach are stored privately in Supabase, are not readable back by anyone including you, and are excluded from your data export. v1.1 removed an earlier description of a "report a problem" feature because it did not exist yet in the app; it now does, disclosed accurately here.
- v1.3 (June 8, 2026): Corrected the meal-text parsing provider to AWS (Amazon Bedrock), running the Amazon Nova model (Sections 4–7). The prior version named Anthropic, PBC (Claude), which no longer reflects the deployed parser. Replaced the Anthropic-term citations with AWS Bedrock's data-handling terms (not used to train models, not shared with third-party model providers, encrypted in transit and at rest).
- v1.2 (June 4, 2026): Disclosed RevenueCat, Inc. as our subscription-billing service provider (Sections 4–7): it receives your account identifier and purchase/subscription events only — no health data, and no advertising or device identifier. Updated the service-provider count from two to three.
- v1.1 (June 4, 2026): Disclosed Anthropic, PBC as a service provider that parses meal text into food items (Sections 4–7). Removed the description of a "Report a problem" diagnostics feature that is not present in v1; diagnostics are not collected.
- v1.0 (June 3, 2026): Initial version.