myNutrition Consumer Health Data Privacy Policy
Last updated: 29 September 2026
Policy URL: https://mynutrition.fitness/consumer-health-data/
This policy supplements our Privacy Policy, which remains the full description of what myNutrition does with your information.
This page is published for residents of Washington State under the My Health My Data Act (chapter 19.373 RCW), and for anyone else who wants it. It answers, in the order the Act asks, five questions: what consumer health data myNutrition collects and why, where it comes from, what is shared, with whom, and how you exercise your rights. Where the Act's words matter we quote them; everywhere else we use plain English.
Who we are. myNutrition is operated by Halocline Labs Limited, a company incorporated in Hong Kong (company number 80831136), registered office: Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong. You can reach us at support@mynutrition.fitness.
1. What consumer health data we collect, and why
The Act defines consumer health data as personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status, and it says that to “collect” is to “buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner”. Read that way, three kinds of information the app can hold count, and we treat the app’s storing of them on your device, its uploading of them as ciphertext if you turn on cloud backup, and its working out of targets from them, all as collection — even though, by design, we ourselves can read none of them.
- Your profile’s health-related fields. The profile holds First name, surname, date of birth, biological sex, height, weight, activity level, weight goal, pregnancy status, diet preference, gluten-free / dairy-free toggles; of these, biological sex, height, weight, activity level, weight goal, pregnancy status (none, pregnant or breastfeeding) and the diet settings are consumer health data. Your name and date of birth are not health data but are stored with them.
- Your food, drink and supplement logs, and your planned meals. Each log entry holds Item name, amount (g/ml), timestamp, supplement/probiotic servings, your notes, scanned product details; each planned meal holds Planned meals with date, ingredients, portions. What you eat and drink, and any supplements you take, can identify your health status, so we treat all of it as consumer health data.
- What the app works out from them. The app calculates your personalised nutrient reference values and targets from your profile, and shows notices such as “Low intake” when your logged intake of a nutrient has been low lately. The Act counts information derived from non-health information as consumer health data, so these count too.
Why we collect it, and how it is used. We use it only to work out your nutrient targets on your device, never to infer characteristics about you, never for advertising, and never to profile you. On the two most sensitive fields: They are optional where possible, are stored encrypted on your device only, and are used solely to tailor your nutrient reference values. They are never used for advertising or profiling. More generally: The app does calculate personalized nutrient targets from the profile you enter, on your device, but this is not used to make decisions about you. And in the words of the Act’s prohibitions: we use no geofencing of any kind, we do not sell your health or nutrition data or seek any authorization to do so, and we do not use it for targeted advertising, cross-context behavioral advertising, or profiling.
Where it lives. When cloud backup is off (the default), all of your personal data stays on your phone, encrypted, and we receive no copy of it. Cloud backup is disabled by default and only operates if you explicitly turn it on and agree to it. If you do turn it on, your food logs, profile and plans are uploaded as ciphertext we cannot read, and any health-related fields you chose to enter are inside it. We collect no other consumer health data, for no other purpose, and we will not start to without first telling you here and asking for your consent.
2. Where it comes from
- You. Every health-related field in the app comes from what you type, choose or log: you choose which profile details to enter and what food and drink to log, and cloud backup is off unless you turn it on.
- Product databases, for the products you log. Product and nutrient details you add from a scan or search originate from public databases (Open Food Facts and the NIH DSLD) and from fatsecret. Those details describe the product, not you; they become information about you only when you log that you consumed it.
- The app’s own calculations, on your device, described in section 1.
- A backup file you bring back yourself. You can also export/import backup files yourself (for example to your own Files app or personal cloud storage) using your device’s file picker — that’s entirely under your control and goes wherever you choose to save it. A backup you import is your own earlier data, restored by you.
We buy no data about you, receive none from data brokers, advertising networks or other apps, and infer nothing beyond the nutrient calculations above.
3. What consumer health data is shared
In the Act’s words, to “share” is to “release, disclose, disseminate, divulge, make available, provide access to, license, or otherwise communicate” consumer health data to a third party or affiliate. Nothing described in section 1 leaves your device unless you turn on cloud backup. If you do, this is what leaves it:
- The backup itself — your food logs, profile and plans are uploaded as ciphertext we cannot read, and any health-related fields you chose to enter are inside it. This is the only consumer health data that leaves your device, and it leaves encrypted with a key we never receive.
- Your account — your account itself holds the email address you sign in with and a one-way login code worked out from your password, which cannot be turned back into it. When you set up cloud backup, we also keep a short record used to check whether you have confirmed your email address: the address itself, a random number for the record, a number for your account once the record is linked to it, whether the address has been confirmed, when the record was made and when it was linked. It is deleted with your cloud account, and a record that never links to an account is deleted automatically after 7 days.
- Readable bookkeeping beside each backup — Alongside each backup we save the locked backup file, which day it is for in your own calendar, how big it is, a short code we use to check it arrived undamaged, which version of our backup format it uses, which version of the app made it, when it was first saved and when it was last changed, plus a number for the backup and a number for your account. We list it here for completeness: it does not describe your health, but taken together, the days and app versions above show which days you used the app, roughly what time zone you are in, and which version of the app you were running. We would rather you saw that than not.
Product lookups are described here so you can judge them yourself. When you scan or search for a product, a request goes to a product database. The content of those requests is a barcode number or a product name/brand, with nothing about you attached. When you scan a barcode, your device may also ask our own lookup server in Germany, which queries fatsecret for you; that request carries the barcode and reaches our server with your device’s IP address, which we use as the key that limits how many requests any one device can make. We do not attach your identity, account, profile or logs to any of these requests. A barcode says what product was scanned, not who scanned it or whether they consumed it; with no account, profile or log attached, we do not treat these lookups as sharing consumer health data. Our Privacy Policy, Section 5, describes them in full, including what our own server keeps.
We do not sell consumer health data, and we do not share it for advertising. No selling or renting of your data. No sharing of your data for anyone else’s marketing.
4. Who it is shared with: the categories of third parties, and our affiliates
Affiliates. We have no affiliates as the Act defines them — no other legal entity shares our branding or controls, is controlled by, or is under common control with Halocline Labs Limited — so there is none to list.
Third parties. Your personal data, including the consumer health data described in section 3, may be transferred to:
- (a) our cloud-backup provider Supabase, together with the sub-processors it uses to run its service — but only if you enable cloud backup, and then as end-to-end-encrypted ciphertext, your account email, and the readable information described in section 3. Those sub-processors fall into three categories: the cloud-infrastructure provider on which Supabase hosts our database and its backups in the EU (Ireland) region; the network-edge provider that stands in front of Supabase’s data interface, so that each request the app sends to that interface is handled first at whichever of that provider’s locations is nearest to you — a step that processes the request’s technical details, including your device’s IP address and request headers, and that Supabase has told us in writing is not restricted to any region; and the further providers Supabase engages to operate and support its platform. Supabase publishes one current list of all its sub-processors, each with a short description of its role, at supabase.com/legal/customer-resources/subprocessor-list, and offers an email notification when it changes. We point you to that list rather than copy it here: it is the document Supabase’s own data-processing terms incorporate, it is Supabase’s to maintain, and Supabase has told us in writing that it does not certify any subset of it for a particular feature or region;
- (b) the public product databases used for the barcode/product lookups you trigger (Open Food Facts, Open Beauty Facts, Open Products Facts and the NIH DSLD), to which only a barcode number or product name/brand is sent and no personal data;
- (c) the hosting provider of our own lookup server, in Germany, which holds that server and so receives your device’s IP address as an unavoidable part of the request, and which is bound as our data processor; and
- (d) fatsecret, the commercial product database our own server asks about a scanned barcode: that server queries fatsecret — so fatsecret never receives a request from your device and never sees your device’s IP address.
We do not transfer your personal data to any other class of person. Separately, the app store through which you obtain the app — Apple — may process limited account or transaction data as an independent controller under its own privacy policy; we do not send your personal data to it. On request, we will give you an email address or other online contact for each third party with whom your consumer health data has been shared.
5. Your rights, and how to exercise them
Under RCW 19.373.040 you have three rights: to confirm whether we are collecting, sharing or selling your consumer health data and to access it, including a list of the third parties and affiliates we have shared it with and a way to contact them; to withdraw your consent to our collecting and sharing it; and to have it deleted. Because almost all of your data lives only on your own device, you can already do most of this yourself in the app. Here is how each right works for myNutrition.
- Confirm and access — ask whether we hold any personal data about you and get a copy. In practice the personal data we hold is your account email, a one-way login code and the readable details listed in Section 6, and only if you turned on cloud backup; everything else lives on your device, where you can already view it. The third parties are listed in section 4 above.
- Withdraw consent — cloud backup is the only thing you consent to, and You can withdraw this consent at any time, free of charge and as easily as you gave it, by turning cloud backup off in Settings > Backup, or deleting your cloud account, or both (see Section 9); withdrawal doesn’t affect the lawfulness of processing carried out before you withdrew.
- Delete — in the app: Settings → Backup → myNutrition cloud → “Delete cloud account & data”. You must be signed in. This runs a server function that permanently removes your cloud account, its email-confirmation record and all encrypted backups. For the copy on your phone, a full local wipe is available from the app’s lock screen. If you ask us to delete instead, we will delete what we hold and notify every third party listed in section 4 with whom your consumer health data was shared, as the Act requires.
- Non-discrimination — we will never deny you the app, charge you a different price, or give you a lower-quality experience for exercising any of these rights. We offer no financial incentives in exchange for your personal information.
How to make a request. Email support@mynutrition.fitness and tell us what you would like. Where a request concerns cloud-backup account data, we will take reasonable steps to confirm that you are the account holder — for example by asking you to send the request from, or to confirm, the email address registered to the cloud account — before we disclose, change or delete anything, so that we do not act on a request made by the wrong person. We aim to respond within 45 days; for a complex request we may take up to another 45 days and will tell you why. Because nearly all of your data is encrypted and held only on your device, there may be data we genuinely cannot access or produce — we will explain this where it applies.
How to appeal. If we refuse your request, you may ask us to reconsider by replying to our decision or emailing support@mynutrition.fitness with the word “appeal”. We will review and write back, normally within 45 days, explaining our decision. If we still refuse, you may complain to the Washington State Office of the Attorney General at atg.wa.gov/file-complaint, or to your own state’s Attorney General.
6. Changes to this policy
If we ever intend to collect a new category of consumer health data, or to use or share it for a new purpose, we will first change this page and ask for your consent, as the Act requires. When we change this page we will update the “Last updated” date at the top and post the new version at the address above. Previous versions are available on request.