Legal
Privacy Policy
Effective Date: May 23, 2026 · SJK & Sons LLC · Wallingford, CT
Your privacy is not a legal checkbox for us — it is a core product principle. This policy explains what data we collect, why we collect it, how we protect it, and what rights you have over it. We have written it to be readable, not just compliant.
Contents
1. Information We Collect
Account Data
When you create a GritLeanPulse account, we collect your name, email address, and password (stored as an encrypted hash). You may also optionally provide your date of birth and profile photo.
Health & Tracking Data
GritLeanPulse is a health tracking application. By using it, you voluntarily provide health-related data including: body weight and measurements, nutrition and food intake logs, physical activity and step counts, GLP-1 medication details (type, dose, schedule, injection sites), body composition measurements, mood and energy levels, water intake, lab results and bloodwork values, and any other information you choose to log. This data is used solely to provide the services you request within the application.
Usage Data
We collect standard technical information about how you use our application, including: device type and operating system, app version, session timestamps, features accessed, and crash logs. This information helps us improve the product and diagnose technical issues. It does not include the content of your health logs.
Communications
If you contact us for support or other inquiries, we retain the content of those communications to provide assistance and improve our service.
2. How We Use Your Data
Service Delivery
Your data is used to operate and deliver the features of GritLeanPulse — including health tracking, AI meal planning, GLP-1 toolkit functionality, analytics, and coaching reports. We process your health data only to provide the services you have requested.
Product Improvement
Anonymized, aggregated usage data may be used to understand how the product is being used and to guide feature development. This data cannot be linked back to any individual user.
Communications
We may send you transactional emails related to your account (password resets, billing confirmations) and, with your consent, product updates and health tips. You can unsubscribe from non-transactional emails at any time.
We Do Not Sell Your Data
GritLeanPulse does not sell, rent, license, or trade your personal information or health data to any third party for marketing, advertising, or any other commercial purpose. This is a core commitment of our company.
3. Data Security
Infrastructure
Your data is stored on Supabase, a SOC 2 Type II compliant cloud database platform. All data is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.2 or higher.
Row-Level Security
We implement row-level security (RLS) in our database, which means that database queries are automatically scoped to the authenticated user. Even within our own infrastructure, a query cannot return another user's data. Only you can access your health records.
Authentication
Account access is protected by industry-standard authentication. We support secure email/password authentication as well as OAuth providers (Apple, Google). Passwords are never stored in plain text.
Limitations
No method of data transmission or storage is 100% secure. While we use industry-standard practices to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
4. Your Rights
Access
You have the right to access the personal data we hold about you. You can view all of your health data within the app at any time. To request a full account data export, go to Settings > Data & Privacy > Export My Data.
Deletion
You have the right to request deletion of your account and all associated data. To permanently delete your account, go to Settings > Account > Delete Account. This action is irreversible and will permanently remove all of your health data from our systems within 30 days.
Data Export
You can export your health data at any time in CSV format from within the app. Premium subscribers can also generate provider-ready PDF reports. Your data is yours, and you should always have access to it.
Correction
You can update or correct any information in your profile or health logs at any time within the app. If you need assistance correcting data you cannot access directly, contact us at support@gritleanpulse.com.
5. Third-Party Services
Service Providers
We use a limited number of trusted third-party services to operate GritLeanPulse, including: • Anthropic (Claude AI) — AI coaching, food scanning, body analysis, and health insights. When you use an AI feature, relevant health data from your profile and recent activity logs (nutrition, activity levels, GLP-1 medication details, and health goals — only what is contextually relevant) is transmitted to Anthropic's API over an encrypted HTTPS connection to generate personalized responses. This data is not used to train Anthropic's models and is not sold. AI features require explicit consent and are only available to users who have agreed to AI data sharing in the app's onboarding. See Anthropic's privacy practices: anthropic.com/privacy. • Supabase — database and authentication (SOC 2 Type II compliant; gritleanpulse.com/supabase-dpa) • RevenueCat — subscription management for mobile (App Store / Google Play) and web (via Stripe) • Stripe — payment processing for web subscriptions (via RevenueCat's web checkout; stripe.com/privacy) • Nutritionix — food and nutrition database API powering food search, restaurant menus, and natural language food and exercise logging. Food search queries are transmitted to Nutritionix servers; no personally identifiable information is included in these requests. • USDA FoodData Central — publicly accessible federal food database used for the Diet-Friendly Foods browser; no personal data is transmitted • Open Food Facts — open-source food database used for barcode scanning fallback; no personal data is transmitted • Expo — mobile app build and delivery infrastructure • Strava — optional activity sync via OAuth (only accessed if you choose to connect your Strava account; we receive only activity data you authorize) These providers are contractually bound to process data only as directed by us and may not use your data for their own purposes.
Subscription Billing
iOS subscriptions are processed by Apple (App Store). Web subscriptions are processed by RevenueCat's web checkout, which uses Stripe as the payment processor. In all cases, SJK & Sons LLC® does not receive, process, or store your full payment card details. Billing is governed by the respective privacy policies of Apple, RevenueCat, and Stripe. Android (Google Play) is coming soon.
No Advertising Networks
GritLeanPulse does not use advertising networks, third-party trackers, or behavioral analytics services. We do not embed tracking pixels or share your data with ad platforms.
6. Health Data — Our Commitments
How We Protect Your Health Information
GritLeanPulse is a consumer wellness and health tracking application. As a consumer app, we are not a HIPAA-covered entity (we are not a healthcare provider, health plan, or healthcare clearinghouse). However, we treat your health data with the same seriousness and care that those standards require: • Your health data is encrypted at rest (AES-256) and in transit (TLS 1.2+) • Row-level security ensures only you can access your own records • We never sell, share, or license your health data to third parties • You can export or permanently delete your data at any time • Our infrastructure (Supabase) is SOC 2 Type II certified • We comply with the FTC Act and applicable state health data privacy laws
Sharing With Your Healthcare Provider
GritLeanPulse includes features to generate provider-ready reports and export your data for your healthcare appointments. When you share data with your provider, you control exactly what is shared. We do not transmit your health data to any healthcare provider, insurer, or third party without your explicit action and consent.
If You Are a Clinic Partner
If your clinic has enrolled you in GritLeanPulse through our Clinic Connect program, your clinic may have access to aggregate program participation data (not your individual health records) as part of their program administration. Your individual health data remains private. Your clinic agreement will specify what, if any, data is shared.
8. Children's Privacy
GritLeanPulse is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at support@gritleanpulse.com and we will promptly delete that data.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective Date" at the top of this page and notify you via email or in-app notification if the changes are material. Your continued use of GritLeanPulse after any changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at: SJK & Sons LLC® support@gritleanpulse.com