🚀 Subscribe right here on our website — 7-day free trial, cancel anytime. Get Started →

Legal

Privacy Policy

Effective Date: May 23, 2026  ·  SJK & Sons LLC  ·  Wallingford, CT

Your privacy is not a legal checkbox for us — it is a core product principle. This policy explains what data we collect, why we collect it, how we protect it, and what rights you have over it. We have written it to be readable, not just compliant.

Contents

1. Information We Collect2. How We Use Your Data3. Data Security4. Your Rights5. Third-Party Services6. Health Data — Our Commitments8. Children's Privacy9. Changes to This Policy10. Contact Us

1. Information We Collect

Account Data

When you create a GritLeanPulse account, we collect your name, email address, and password (stored as an encrypted hash). You may also optionally provide your date of birth and profile photo.

Health & Tracking Data

GritLeanPulse is a health tracking application. By using it, you voluntarily provide health-related data including: body weight and measurements, nutrition and food intake logs, physical activity and step counts, GLP-1 medication details (type, dose, schedule, injection sites), body composition measurements, mood and energy levels, water intake, lab results and bloodwork values, and any other information you choose to log. This data is used solely to provide the services you request within the application.

Usage Data

We collect standard technical information about how you use our application, including: device type and operating system, app version, session timestamps, features accessed, and crash logs. This information helps us improve the product and diagnose technical issues. It does not include the content of your health logs.

Communications

If you contact us for support or other inquiries, we retain the content of those communications to provide assistance and improve our service.

2. How We Use Your Data

Service Delivery

Your data is used to operate and deliver the features of GritLeanPulse — including health tracking, AI meal planning, GLP-1 toolkit functionality, analytics, and coaching reports. We process your health data only to provide the services you have requested.

Product Improvement

Anonymized, aggregated usage data may be used to understand how the product is being used and to guide feature development. This data cannot be linked back to any individual user.

Communications

We may send you transactional emails related to your account (password resets, billing confirmations) and, with your consent, product updates and health tips. You can unsubscribe from non-transactional emails at any time.

We Do Not Sell Your Data

GritLeanPulse does not sell, rent, license, or trade your personal information or health data to any third party for marketing, advertising, or any other commercial purpose. This is a core commitment of our company.

3. Data Security

Infrastructure

Your data is stored on Supabase, a SOC 2 Type II compliant cloud database platform. All data is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.2 or higher.

Row-Level Security

We implement row-level security (RLS) in our database, which means that database queries are automatically scoped to the authenticated user. Even within our own infrastructure, a query cannot return another user's data. Only you can access your health records.

Authentication

Account access is protected by industry-standard authentication. We support secure email/password authentication as well as OAuth providers (Apple, Google). Passwords are never stored in plain text.

Limitations

No method of data transmission or storage is 100% secure. While we use industry-standard practices to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

4. Your Rights

Access

You have the right to access the personal data we hold about you. You can view all of your health data within the app at any time. To request a full account data export, go to Settings > Data & Privacy > Export My Data.

Deletion

You have the right to request deletion of your account and all associated data. To permanently delete your account, go to Settings > Account > Delete Account. This action is irreversible and will permanently remove all of your health data from our systems within 30 days.

Data Export

You can export your health data at any time in CSV format from within the app. Premium subscribers can also generate provider-ready PDF reports. Your data is yours, and you should always have access to it.

Correction

You can update or correct any information in your profile or health logs at any time within the app. If you need assistance correcting data you cannot access directly, contact us at support@gritleanpulse.com.

5. Third-Party Services

Service Providers

We use a limited number of trusted third-party services to operate GritLeanPulse, including: • Anthropic (Claude AI) — AI coaching, food scanning, body analysis, and health insights. When you use an AI feature, relevant health data from your profile and recent activity logs (nutrition, activity levels, GLP-1 medication details, and health goals — only what is contextually relevant) is transmitted to Anthropic's API over an encrypted HTTPS connection to generate personalized responses. This data is not used to train Anthropic's models and is not sold. AI features require explicit consent and are only available to users who have agreed to AI data sharing in the app's onboarding. See Anthropic's privacy practices: anthropic.com/privacy. • Supabase — database and authentication (SOC 2 Type II compliant; gritleanpulse.com/supabase-dpa) • RevenueCat — subscription management for mobile (App Store / Google Play) and web (via Stripe) • Stripe — payment processing for web subscriptions (via RevenueCat's web checkout; stripe.com/privacy) • Nutritionix — food and nutrition database API powering food search, restaurant menus, and natural language food and exercise logging. Food search queries are transmitted to Nutritionix servers; no personally identifiable information is included in these requests. • USDA FoodData Central — publicly accessible federal food database used for the Diet-Friendly Foods browser; no personal data is transmitted • Open Food Facts — open-source food database used for barcode scanning fallback; no personal data is transmitted • Expo — mobile app build and delivery infrastructure • Strava — optional activity sync via OAuth (only accessed if you choose to connect your Strava account; we receive only activity data you authorize) These providers are contractually bound to process data only as directed by us and may not use your data for their own purposes.

Subscription Billing

iOS subscriptions are processed by Apple (App Store). Web subscriptions are processed by RevenueCat's web checkout, which uses Stripe as the payment processor. In all cases, SJK & Sons LLC® does not receive, process, or store your full payment card details. Billing is governed by the respective privacy policies of Apple, RevenueCat, and Stripe. Android (Google Play) is coming soon.

No Advertising Networks

GritLeanPulse does not use advertising networks, third-party trackers, or behavioral analytics services. We do not embed tracking pixels or share your data with ad platforms.

6. Health Data — Our Commitments

How We Protect Your Health Information

GritLeanPulse is a consumer wellness and health tracking application. As a consumer app, we are not a HIPAA-covered entity (we are not a healthcare provider, health plan, or healthcare clearinghouse). However, we treat your health data with the same seriousness and care that those standards require: • Your health data is encrypted at rest (AES-256) and in transit (TLS 1.2+) • Row-level security ensures only you can access your own records • We never sell, share, or license your health data to third parties • You can export or permanently delete your data at any time • Our infrastructure (Supabase) is SOC 2 Type II certified • We comply with the FTC Act and applicable state health data privacy laws

Sharing With Your Healthcare Provider

GritLeanPulse includes features to generate provider-ready reports and export your data for your healthcare appointments. When you share data with your provider, you control exactly what is shared. We do not transmit your health data to any healthcare provider, insurer, or third party without your explicit action and consent.

If You Are a Clinic Partner

If your clinic has enrolled you in GritLeanPulse through our Clinic Connect program, your clinic may have access to aggregate program participation data (not your individual health records) as part of their program administration. Your individual health data remains private. Your clinic agreement will specify what, if any, data is shared.

8. Children's Privacy

GritLeanPulse is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at support@gritleanpulse.com and we will promptly delete that data.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective Date" at the top of this page and notify you via email or in-app notification if the changes are material. Your continued use of GritLeanPulse after any changes constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at: SJK & Sons LLC® support@gritleanpulse.com

Terms of Service →Help Center →Contact Us →