Consumer Health Data Privacy Policy
Last updated: August 27, 2026
Effective date: 2026-08-27
Applies to: residents of Washington State (My Health My Data Act) and Nevada (SB 370)
Operator: DevX Group LLC, PO Box 5010, PMB 76, Rancho Santa Fe, CA 92067
Contact: privacy@devxgroup.io
What consumer health data we collect
Meals and photos of meals, body weight and measurements, workouts, sleep duration and quality (including sleep sessions and workouts read from Apple Health or Health Connect if you connect them in Settings), supplements you take, blood work and lab reports you upload and the analyte values we extract from them, symptoms, biomarkers, mood, and any health information you type into the Journal.
Where it comes from
You. Every item above is something you enter, upload, or photograph inside the app, or, if you connect Apple Health or Health Connect in Settings, a sleep session or workout your phone or watch recorded and you chose to share with us. We do not buy health data, receive it from data brokers, or infer it from your activity outside Nutrify.AI.
Why we collect it
To run the features you asked for: logging and charting your health data, generating personalized nutrition, sleep, and exercise suggestions, and summarizing your lab reports. Nothing else.
Who we share it with
We do not sell your consumer health data and we have never sold it. We share it only with the service providers we need to run the app, each under a written contract that forbids them from using it for their own purposes:
- Supabase Inc. (United States): database, authentication, and file storage
- Google LLC, Gemini API (United States): AI inference and lab document reading
- Anthropic, PBC (United States): AI inference when Gemini is unavailable
These are processors acting on our instructions, not independent recipients.
How long we keep it
Until you delete your account. Deletion is immediate and permanent in the live database. Residual copies inside encrypted disaster-recovery backups age out within 90 days, and we never read individual accounts out of a backup.
Who inside our company can see it
Access is denied by default and enforced in the database. A DevX Group engineer can reach your health data only to fix a fault you have reported or to keep the service running, and every access is logged.
Your rights
- Confirm whether we hold your consumer health data and get a copy of it.
- Get a list of every third party we shared it with, and their contact details.
- Withdraw consent to our collection and sharing of it.
- Delete it. We hard-delete it from our systems right away and erase your analytics identity at PostHog; remaining vendor copies (crash diagnostics, encrypted backups) expire within 90 days. We respond within 30 days and will tell you if we need up to 30 more.
To use any of these rights, email privacy@devxgroup.io from the address on your account. You can also delete everything yourself in Settings then Account then Delete Account.
If we turn you down
We will tell you why in writing within 30 days and explain how to appeal. To appeal, reply to that email with the word "appeal". We answer appeals within 45 days. If we still say no, you can complain to the Washington State Attorney General at atg.wa.gov/file-complaint.