Privacy Policy
Version 1.3 · Effective June 8, 2026
Health data is also covered by our separate Consumer Health Data Privacy Policy.
Who we are
Idunia is a US-only mobile app for adults (18+) that helps female athletes track nutrition and training. Idunia is operated by Max Output LLC (North Carolina). Contact: founders@maxoutput.ai.
What we collect
- Account info: email and authentication data, so you can log in.
- Health data you enter: nutrition, training, body metrics, and — only if you opt in — cycle data. Detailed in our separate Consumer Health Data Privacy Policy.
- Subscription status: your purchase and subscription state, so we can unlock the paid app and restore your access across reinstalls. Handled by our billing provider, RevenueCat (see "Subscriptions & billing" below).
- We do not collect precise location, advertising identifiers, or contacts.
- We do not collect diagnostics or crash logs in v1.
What we DON'T do
- We do not sell your data.
- We do not share your data with advertisers, analytics providers, or social platforms.
- We have no third-party advertising, analytics, attribution, or tracking software in the app.
- We do not use your data to build advertising profiles or to train models for anyone else.
Where your data lives and how it's protected
- Your cycle data is stored only on your device, in an encrypted file whose key is held by your device's operating system. It is never sent to our servers, so we cannot access it.
- Account and other data are stored on our hosted backend, provided by Supabase, Inc. as our service provider — a company we hire solely to run the app, contractually prohibited from using your data for its own purposes. Data is encrypted in transit (TLS) and at rest; access is limited to operating the app.
- Meal text you type is processed by AWS (Amazon Bedrock), running Amazon Nova (an Amazon-built model), to structure it into food items (see "Meal-text parsing" below). AWS is a service provider acting only for us.
- When you subscribe, your account identifier and purchase/subscription events are processed by RevenueCat, Inc., our subscription-billing provider, to manage your access (see "Subscriptions & billing" below). RevenueCat is a service provider acting only for us.
- Using a service provider to store or process your data for you is not "sharing."
How we use it
Only to operate the app for you: authenticate you, calculate your targets and indicators, and show your own history back to you.
Meal-text parsing (AWS Bedrock)
When you log a meal by typing it in plain language, the meal text you type is sent to our parsing provider, AWS (Amazon Bedrock), which runs Amazon Nova, an Amazon-built model, to structure it into food items (for example, "oatmeal with a banana" becomes a list of items). Only the meal text is sent. It is not tagged with your name or email, and no cycle, body, or training data is included. The nutrient numbers are looked up from our own food database; the model never produces them. Under AWS's terms, your input is not used to train Amazon Nova or any other model and is not shared with any third-party model provider; the model providers themselves cannot access it. The meal text is encrypted in transit (TLS) and at rest. See AWS's Bedrock Security and Privacy page and Bedrock Data Privacy FAQ. AWS acts only as our service provider; this is not "selling" or "sharing" your data.
Subscriptions & billing (RevenueCat)
Idunia's paid subscription is managed through RevenueCat, Inc. When you subscribe, your account identifier (the same ID that identifies you to our backend) and your purchase and subscription-status events are sent to RevenueCat (api.revenuecat.com) so we can unlock the app and restore your access across reinstalls. No health data of any kind — nutrition, training, body, or cycle — is sent to RevenueCat, and RevenueCat does not collect any advertising or device identifier from you (we do not enable that feature). The payment itself is processed by Google Play. RevenueCat acts only as our service provider; this is not "selling" or "sharing" your data. See RevenueCat's Privacy Policy.
Diagnostics
We use no background crash, analytics, or diagnostics software, and v1 has no "report a problem" feature. We do not collect diagnostic or crash logs.
Your choices and rights
- Access, export, or delete your data anytime in Settings, or email founders@maxoutput.ai. If you cannot use the app, you can request deletion from our account-deletion page.
- Deleting your account removes your server-side data. Cycle data lives only on your device — deleting your account does not remove it; delete cycle history in Settings or uninstall to remove it.
- Withdraw consent: cycle tracking is optional (turn it off and delete it anytime, keep using the app); nutrition/training data is required to run the app, so to withdraw it, delete your account.
- California residents: we do not sell or share your personal information; you may access and delete your data as above.
Children
The app is for adults 18+. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it. If you believe a minor is using Idunia, email founders@maxoutput.ai.
Geography
We offer the app to US users only and do not target users outside the United States. The app is intended for use within the US; if you use it while traveling, your data is still processed in the US.
Security & breach
We protect your data with TLS in transit, encryption at rest, and least-privilege access. If a breach affects your health data, we will notify affected users (and regulators where required).
Retention
We keep your data until you delete it or close your account; deleted data is removed from active systems promptly and from backups within 90 days. Uninstalling the app removes on-device cycle data but does not delete your account or server-side data — use Settings → delete account for that. Cycle data is retained on your device until you delete it or uninstall.
Changes
If we materially change our practices, we will update this policy and, where required, ask for your consent again before applying changes to data already collected.
Change history
- v1.3 (June 8, 2026): Corrected the meal-text parsing provider to AWS (Amazon Bedrock), running the Amazon Nova model. The prior version named Anthropic, PBC (Claude), which no longer reflects the deployed parser. Replaced the Anthropic-term citations with AWS Bedrock's data-handling terms (not used to train models, not shared with third-party model providers, encrypted in transit and at rest).
- v1.2 (June 4, 2026): Disclosed RevenueCat, Inc. as our subscription-billing provider — it receives your account identifier and purchase/subscription events only, with no health data and no advertising or device identifier. Added a "Subscriptions & billing" section and listed subscription status under "What we collect."
- v1.1 (June 4, 2026): Disclosed Anthropic, PBC as the meal-text parsing provider. Removed the "Report a problem" diagnostics description; v1 collects no diagnostics or crash logs. Added the web account-deletion route.
- v1.0 (June 3, 2026): Initial version.
Contact: founders@maxoutput.ai