Privacy Policy
Effective: 2026-05-08·Last updated: 2026-09-15·App version: 1.2.0
This policy explains what Jeni (formerly JeniFit) collects across the iOS app and our website (jenifit.app), why, where it's stored, who can see it, and how to delete it. Jeni is provided by bay82 Studio LLC (“we”, “us”). Most sections describe the app; the The website (jenifit.app) section below covers the site, including the free-guide email signup. We aimed for plain language and kept the legal terms only where they do real work. If something's unclear, email support@jenifit.app.
TL;DR
- Your weight-care record syncs to your account. Weigh-ins, food logs, your medication and dose marks, and how you felt (side effects and symptoms) are stored in your private rows at Supabase so they survive a reinstall or a new phone.
- Food photos and meal descriptions are sent to OpenAI. Body scans are not. Meal photos, and the meals you type or say out loud, travel through our backend to OpenAI for a calorie and macro estimate. When you speak a meal, your voice becomes text on your iPhone and the audio itself is never recorded, stored, or uploaded. Body progress scans are processed on your iPhone and never go to any AI provider, and never to a clinic.
- Apple Health is read-only, and one thing crosses over. We read more than steps. Weigh-ins imported from Apple Health are saved to your Jeni account like ones you typed. The rest stays on your phone, with one exception: if you use the coach, a few of those signals travel with the message you send. See the Apple Health section.
- We use analytics and ad attribution. PostHog measures how the app is used and is linked to your account id. If you write to us through the in-app feedback box, that text is delivered through the same analytics pipeline. The app also includes the TikTok Business SDK and the Meta (Facebook) SDK, which report install, activation and purchase events so we can measure our ads, and can use your device advertising identifier only if you allow tracking in the iOS prompt.
- Five setup screens are screen-recorded, and no screen that asks you something ever is. To find and fix usability problems in sign-up, the app records a visual replay of exactly five presentation screens in onboarding. No question screen is ever recorded, so no answer you give can appear in a recording, and recording ends for good before your plan appears. It never runs inside the app itself. See “Session recordings” below.
- Health information never goes to advertising systems. We do not sell your health data. Your weight, medication, doses, symptoms, Apple Health values, cycle information, food logs, photos, and anything about a clinic are not sent to TikTok, to Meta, or to any other ad or audience-building platform, and are never used for advertising.
- A clinic sees nothing unless you connect one. If your practice participates and you enter its invite code, you choose what to share. Off by default, revocable anytime.
- The website only collects an email if you ask for a free guide. We use it to send the guide and a few follow-up notes (via Resend), and you can unsubscribe in one tap.
- Delete everything anytime. Settings → account → delete account removes your cloud rows, your photos, and your local data.
What we collect
Stays on your phone
In short: These inputs are not stored in our database, so for the most part there is nothing on our side to share or delete on request, and uninstalling is the delete action. The one to read carefully is coach conversation content, which is not stored by us but does pass through our backend to be answered.
- Body progress scans. Guided scans are processed on your iPhone by Apple's Vision framework into ink silhouettes. Photos and silhouettes are excluded from device backups and stripped of location metadata, and stay only on your phone unless you turn on the optional cloud backup described below. We never estimate weight, body fat, or any number from a photo.
- Lifestyle answers from onboarding. Typical sleep duration band, self-reported stress level, eating cadence, eating window, previous attempts, food relationship, and what you said you wanted to change are stored in iOS UserDefaults and are not synced to our database. They do travel with a coach message if you use the coach, the same way a few Apple Health signals do, so jeni's answer fits the week you described. A “prefer not to say” option is offered where it applies, and declining does not change pricing or feature access.
- Coach conversation content. The messages in your chat history are kept on your device, not in our database. They are sent to OpenAI to generate each reply, as described below.
- Your voice, when you speak a meal. Holding the mic open to say what you ate turns your speech into text on your iPhone, using Apple's on-device recognition. The audio is never written to disk, never stored, and never uploaded, to us or to anyone. On a device that cannot do that recognition on-device, voice logging is simply unavailable; we never fall back to a server. Only the resulting sentence travels, and it travels exactly where a typed one does: through our backend to OpenAI, to be counted. The microphone is used only while you hold it open, and only after you allow it.
- Notification preferences and reminder times. Reminders are scheduled locally by iOS. Nothing leaves your device for them.
- Most Apple Health readings. See the Apple Health section for the exact split.
Syncs to your account at Supabase
In short: Your record, the things you would not want to lose when you change phones, syncs to our database under your account id. This includes your medication and dose record and the symptoms you log.
| Data | Why |
|---|---|
| Name (first, optional) | Greeting + personalization |
| Age range, gender, height | Calorie and protein targets, pacing (published equations) |
| Weight logs (current, goal, history, typed or imported from Apple Health) | Trend chart, goal pace, plan recalibration |
| Medication record: which weight medication, dose, schedule, and whether you marked each dose taken or skipped | Composing your day around your medication rhythm; protein and muscle-preservation targets |
| How you felt: side effects, symptoms, and tolerability notes | Pacing the plan, and the summary you can bring to a visit |
| Safety screening answers (pregnancy status, eating-pattern screen) | Deciding what the program may safely show you; can hide all numbers |
| Food journal: logged meals, nutrition estimates, your edits, free-text descriptions | Daily totals, your journal, restoring on a new device |
| Meal photo thumbnails | So your journal photos come back after a reinstall (you can turn this off) |
| Evening reflections and written notes | Your private journaling surface in the app |
| Movement and program records (sessions, day progress, weekly reads) | Progress tracking and plan adjustment |
| Subscription state (RevenueCat customer ID, entitlement) | Unlocking the program |
What we don't collect
- Contacts and location. Microphone audio: voice meal logging is transcribed on your device and the audio is discarded, so no recording of your voice ever reaches us.
- Your photo library. We never read it. If you save a share card, iOS asks for add-only permission.
- Browsing history outside the app.
- Payment details. Apple handles billing; we never see your card.
Photos: two different flows
In short: Food photos and body scans are handled differently on purpose. Food photos go to an AI provider for analysis. Body scans never do.
Food photos
- When you snap a plate or a nutrition label, the image is sent over TLS to our backend, which passes it to OpenAI's vision model to estimate calories and macros.
- The full-size photo is not stored. A small thumbnail (long edge capped at 480px) is kept with the journal entry on your device and in your private cloud storage folder, so your meal photos survive a reinstall.
- You can turn keeping off. Settings → food → photo retention → “discard after analysis”. Then no photo is saved or uploaded and only the nutrition estimate is kept.
- The storage bucket is private and access rules enforce that only your signed-in account can read, write, or delete objects in your own folder.
- Deleting a journal entry removes its thumbnail from your device and from cloud storage. Deleting your account removes all of them.
- Barcode scanning happens on your device; only the barcode number is looked up against Open Food Facts.
Body progress scans
- Processed entirely on your iPhone. They are never sent to OpenAI or any other AI provider, and never shared with a connected clinic.
- Cloud backup is opt-in and off by default. If you turn it on, encrypted-in-transit copies go to a private storage folder only you can reach. Turning backup off deletes those cloud copies rather than pausing them.
- No number is ever derived from a body photo. We do not estimate weight or body fat from an image.
Apple Health (HealthKit)
In short: Read-only, and iOS lets you grant or deny each category. One category crosses over to your account: weigh-ins. The rest is read on your phone, and a few of those signals travel with a coach message if you use the coach. We write only one thing, and only if you turn it on.
With your permission, we read the following. We only ever see what you allow:
| What we read | What it's for |
|---|---|
| Steps, walking and running distance, active energy, workouts | Your movement rail and weekly read |
| Sleep analysis | Pacing your plan honestly |
| Body weight | Passive weigh-in import and your trend chart |
| Body fat percentage, lean body mass | Composition, only if a smart scale you already use writes it |
| Resting heart rate, heart-rate variability | The recovery line in your weekly read |
| Menstrual flow | The cycle-season signal, so your plan expects a normal scale bump instead of treating it as a setback |
Two things are worth stating plainly, because a blanket “health data never leaves your device” claim would not be accurate:
- Weigh-ins imported from Apple Health are saved to your Jeni account. That is the point of passive import: your trend chart has to survive a reinstall. They become ordinary weight rows in your private cloud space, identical to ones you type in.
- Everything else stays on your phone, with one narrow exception. Steps, sleep, workouts, distance, active energy, heart-rate data, body composition, and menstrual flow are read on your phone to compose your day and your weekly read. They are not stored on our servers as health records, and they are not sent to PostHog, to TikTok, or to Meta. The exception is the coach: once you have accepted the coach disclosure and you send jeni a message, a small set of these signals travels with that message as context, so the reply can be about your actual week. Today that is how long you slept last night, today's step count, how many strength sessions you logged in the last week, and whether you are in a luteal or menstrual stretch. That context passes through our coach service to OpenAI for the length of the reply. Connecting Apple Health does not upload your Health database; if you never use the coach, none of it leaves your phone.
Writing back is off by default. If you turn on the Apple Health write toggle in food settings, the meal calories you log are written to Apple Health as Dietary Energy. That is the only thing we ever write, and nothing else is. Apple Health measurements are not used for advertising and are not shared with advertising partners.
You can revoke any category at any time in iOS Settings → Privacy & Security → Health → Jeni. Revocation needs no action on our side.
Medication and symptoms
In short: Jeni keeps a record of the medication you are already prescribed. It does not prescribe, dispense, or change anything. This record syncs to your account.
If you use the medication features, Jeni stores the medication you tell it about, its dose and schedule, whether you marked each scheduled dose taken or skipped, and any side effects or symptoms you log. This is kept in your private rows at Supabase so your record survives a new phone, and so you can bring an accurate summary to an appointment.
Recording a medication is bookkeeping, not medical direction. Jeni does not prescribe medication, does not dispense it, and does not change a prescription your clinician gave you. See our Terms for the full health and safety disclaimer.
None of this is sent to TikTok, to Meta, or to any other advertising system. What does reach product analytics is described under “Product analytics (PostHog)” below, and it is categorical: never the medication's brand name, never your dose. See also “Advertising and tracking” below.
Content you send to OpenAI
In short: Three features send content off your device: food photos, the meals you type or say, and messages to the coach. All of them travel through our backend, never directly from your phone to OpenAI. Replies and estimates are generated by a model and can be wrong.
- Photo meal logging. The image is sent through our backend to OpenAI's vision model to estimate calories and macros.
- Typed and spoken meal logging. You can also log a meal by typing a sentence, or by holding the mic and saying it. Either way the sentence is sent through our backend to the same OpenAI model to estimate calories and macros. A spoken meal is turned into text on your iPhone first, and only that text travels. Before your first food log, whichever door you came in by, the app shows a disclosure that names OpenAI and says what makes the trip; nothing is sent until you accept it.
- The coach. Before your first message the app shows a disclosure that names OpenAI and lists what travels; nothing is sent until you accept it. After that, when you send a message, the text of your recent conversation plus the program context needed to answer well is sent through our backend to OpenAI's language model to generate the reply.
What OpenAI receives with a coach message: your first name, your plan and recent trend, today's record, your medication record and any symptoms you logged, your cycle stretch, the Apple Health signals named in the Apple Health section, the onboarding answers about your sleep, stress, appetite and relationship with food, whether the safety screen asked us to hide numbers from you, your evening notes, and what you have asked jeni to remember. What it does not receive: your email, your Apple ID, your body scans, or your payment details. It is a summary of your record assembled to answer the question in front of it, not a copy of your Jeni database.
Retention. We reach OpenAI through its API. Under OpenAI's API terms, content submitted through the API is not used to train its models. OpenAI describes its own API retention in its privacy policy and its API data-usage terms, and those documents govern what OpenAI does on its side. Our own copy of the estimate lives at Supabase under your account. Your chat messages are kept on your device.
Because estimates and replies are generated by a model, they can be inaccurate. Please avoid sending anything to the coach that you would not want processed by a third-party provider.
Your care team (optional clinic connection)
In short: Off unless you turn it on. Nothing about a clinic exists in your account until you enter a practice's invite code and accept. You choose what to share and can revoke it at any time.
If your weight-management practice participates, you can connect your Jeni account to it from Settings → your care team. You enter the invite code the practice gave you, review who it is, and choose which of three consents to grant:
| Consent | What the practice can then see or do |
|---|---|
| Your visit packet | The 4-week summary you already prepare for a visit: dose adherence counts, weigh-in count and direction, symptoms you logged, days logged and protein days met, movement days and step average, plus your questions and gaps |
| Your daily records | Your dose marks, how meals sat, hydration, and weigh-ins |
| Your care plan | Lets the practice set the medication plan and protocol your app then follows |
- Access is enforced at the database, not just in the app. Row-Level Security requires an active, unrevoked consent before a practice can read your rows or before your device will publish anything to it.
- Your photos are never shared with a practice. Neither meal thumbnails nor body scans are part of any care scope.
- Your coach conversations are never shared with a practice.
- Revoking stops future sharing. Revoke a single consent or disconnect entirely at any time. Information the practice already received stays in that practice's own records, and how it handles that is governed by the practice's privacy notice and the laws that apply to it, not by this policy.
Advertising and tracking
In short: The app includes two ad-attribution SDKs, TikTok's and Meta's, so we can measure whether our ads work. They receive app events: install, launch, retention, activation and purchase. They do not receive health information. The iOS tracking prompt controls whether your advertising identifier is used.
Jeni includes the TikTok Business SDK for app-install attribution and ad measurement. It reports app install, launch, retention, and purchase events to TikTok so we can tell whether an ad led to a download. It is not started until the iOS tracking prompt has been answered.
Jeni also includes the Meta (Facebook) SDK for the same reason. It reports app install and activation to Meta, and your purchases are reported to Meta through RevenueCat, our subscription provider, so we can measure whether our ads work. We turn Meta's automatic in-app event logging off, in the app's configuration and again in code before the SDK initializes, so it does not log your activity in the app on its own. Your device advertising identifier is only shared if you allow tracking at the App Tracking Transparency prompt; if you tap “Ask App Not to Track”, it is not. A per-install identifier that Meta generates on your device is used for attribution either way. No health data, no food data, no medication data, and none of your in-app answers are sent to Meta.
- You control the advertising identifier. iOS shows the App Tracking Transparency prompt during onboarding. If you tap “Ask App Not to Track”, your device advertising identifier (IDFA) is not used. You can change this any time in iOS Settings → Privacy & Security → Tracking. Declining changes nothing about what the app does for you.
- We also use Apple's SKAdNetwork, which reports install attribution to Apple in a privacy-preserving, aggregated form.
The boundary we hold. We do not sell your health data. Health information is not sent to advertising or audience-building systems and is not used for behavioral targeting. That means your weight and weight changes, medication, dose and adherence, GLP-1 status, symptoms and side effects, Apple Health readings, menstrual and cycle information, food and nutrition logs, food photos, body scans, and anything about a clinic relationship. What TikTok and Meta receive is app events, install, launch, retention, activation and purchase, plus the identifiers described above.
We do not use the Meta Pixel or the TikTok Pixel on this website, and we do not use Firebase, Crashlytics, Amplitude, Mixpanel, Segment, Google Analytics, AppsFlyer, Adjust, or Branch anywhere.
Product analytics (PostHog)
In short: We track how the app is used so we can improve it. These events are linked to your account id. They do not carry your weight numbers, your meals, your photos, your coach conversations, medication brand names, doses, or any measured Apple Health value. Three things do travel and are worth knowing: the text you write in the in-app feedback box, the technical message in a crash or error report, and a screen recording of five presentation screens in onboarding, described in its own section below.
Jeni uses PostHog for first-party product analytics: onboarding steps, screens opened, features used, paywall and purchase funnel outcomes, and coarse program signals (for example, that a dose was marked taken or skipped, or that a milestone was reached).
Product-event payloads are counts, choices, and fixed categorical words. A validator in the app checks each registered event against a registry of allowed keys and allowed values, so a registered event cannot carry free text or a raw measurement. The two paths below sit outside that registry, which is exactly why we name them rather than leave them to the general rule.
Registered analytics events do not include your weight number, goal weight, weight delta, medication brand or product name, dose amount, meal content, photos, your coach conversations, any measured Apple Health value, or your email. Some carry a categorical word rather than a number, for example that a dose was marked taken or skipped, which side effect you logged and how strong you said it was, or whether Apple Health access is granted, never a step count, a sleep duration, or a weight.
The in-app feedback box goes through analytics. If you write to us from Settings, the text you type is delivered through the same analytics pipeline, attached to your account id, so we see it and can act on it. We would rather say so than let you assume otherwise: please do not put anything in that box you would not want us to read. This is the feedback box only. Your conversations with jeni are not sent to analytics.
Crash and error reports are collected. These carry technical information: the error type, where in the app it happened, and a technical error message, which can occasionally include a fragment of the underlying system or database error. They are not health records and are not read as such, but they are not something we can promise is always free of incidental detail.
Analytics are linked to your account. In release builds, PostHog is identified with your account id, so events can be tied to your account. Your analytics profile carries which sign-in method you used, plus a small set of categorical attributes so we can understand how different groups use the app: whether you are on a GLP-1 medication now, have stopped one, are considering one, or are losing weight on your own; whether the medication is oral or injected; how often it is scheduled; and whether the plan is yours or your clinic's. It never carries the medication's brand name or your dose. If you want this gone, delete your account and the associated records go with it.
Session recordings (five setup screens)
In short: The app records a visual replay of exactly five presentation screens in onboarding, so we can see where sign-up confuses people. No screen that asks you a question is ever recorded, so no answer you give can appear in a recording. Recording ends permanently before your plan appears, and never runs inside the app itself.
New in app version 1.2.0. Sign-up is the part of Jeni we can least afford to get wrong and can least see going wrong, so PostHog's session replay records a visual playback of five screens in the setup flow: the opening screen, the drawn explainer page, the two product demonstrations, and the “why this works” pages. The two demonstrations show our own sample data, never yours.
The limits are enforced in the app, and they fail closed. Recording is governed by a list of the five screens that may be recorded, not a list of screens to avoid. Anything not on that list is not recorded, including a screen we add later and forget to classify. Concretely:
- No screen that asks you anything is ever recorded. Your name, your weight, your medications, your cycle answers, the safety screening: none of it can appear in a recording, because the screens you answer them on are never recording. The same holds for the running summary of your answers, which is why the five recordable screens are ones that replace the whole view rather than sit beside it.
- It stops before your plan appears, and stays stopped. Recording ends when setup ends and does not resume for that session. It never runs anywhere inside the app: not on your plan, not on the paywall, not on the food or coach screens, and not on a returning launch.
- Text inputs and images are masked on your device as well. Because a replay is captured as pictures of the screen, we do not rely on masking alone; scope is the real protection, and masking is the second layer. Every text field, every image, and every system-rendered view is masked at the source, before anything leaves your iPhone.
Recordings go to PostHog, the same provider as the analytics above, and are keyed to the same account id, so they are retained and deleted on the same terms described in that section. They are never sold, and never shared for advertising or audience building.
Where it's stored
In short: Your synced record sits at Supabase (US region). Food photos, meal descriptions, and coach messages pass through OpenAI to be processed. Subscription state sits at RevenueCat. Analytics and the onboarding recordings sit at PostHog. Ad measurement events sit at TikTok and Meta.
- On your device in a SwiftData store inside the app's sandboxed Application Support directory, plus iOS UserDefaults for the on-device-only answers, plus your body scans.
- In the cloud at Supabase (managed Postgres, US region). Each row is keyed to your auth user id, and Row-Level Security policies enforce that you can only read or write your own rows.
- In private storage buckets for meal photo thumbnails, and for body scans only if you opted into backup, under your own user id.
- At OpenAI transiently, when a food photo, a meal you typed or said, or a coach message is processed.
- At RevenueCat for subscription state, keyed to your auth user id.
- At PostHog for the analytics events and the five-screen onboarding recordings described above, keyed to your account id.
- At TikTok and at Meta for the ad measurement events described above.
- At Apple if you signed in with Apple, and for local notifications scheduled by iOS.
How long we keep it
In short: Your record stays until you delete it. Deleting your account deletes it immediately and permanently.
- Your synced record is kept for as long as your account exists, because its purpose is to be your history. There is no automatic expiry.
- Meal photo thumbnails are kept with their journal entry until you delete the entry, switch photo retention to “discard after analysis”, or delete your account.
- Body scans stay on your device until you delete them. If you turned backup on, turning it off deletes the cloud copies.
- Deleting your account deletes everything described above, at once, with no soft-delete or recovery window.
- Our processors keep data under their own retention terms, linked in the provider table below.
Who can see it
In short: You. A clinic you deliberately connected, limited to what you consented to. The operator, read-only, when you write in for support. Our service providers, each for the narrow purpose it is listed for. Nobody else.
Apart from you and Apple's iOS systems on your device:
- A healthcare practice you have connected to, limited to the consents you granted. See “Your care team” above.
- The operator of bay82 Studio LLC has read-only access to Supabase for support and debugging. We don't browse routinely; we look only if you write in.
- Apple, for Sign in with Apple identifier mapping (we never receive your real Apple ID email if you use Hide My Email).
- Service providers listed below.
We do not sell or rent your personal data, and we do not disclose health information for anyone else's advertising. Because the TikTok and Meta ad measurement described above can involve your advertising identifier when you allow tracking, some state privacy laws may treat that as “sharing” for cross-context behavioral advertising. Declining the iOS tracking prompt, or turning tracking off later in iOS Settings, stops the identifier being used.
Service providers (third parties)
In short: Each one is listed with what it receives and why. Anything not on this list, we don't use.
| Provider | What they get | Why | More |
|---|---|---|---|
| Supabase | Authentication tokens, your synced rows (profile, weight logs, food logs, medication and dose records, symptoms, program records), and your photo thumbnails | Database, auth, and storage backend | supabase.com/privacy |
| OpenAI | Food photos and typed or spoken meal descriptions (for nutrition estimates), and coach messages with the program context needed to answer, including your first name, sent through our backend. No email, Apple ID, body scans, or payment details. Not used to train their models. | Photo, typed and spoken meal logging + coach replies | openai.com/policies/privacy-policy |
| TikTok | App install, launch, retention, and purchase events. Your advertising identifier (IDFA) only if you allow tracking in the iOS prompt. No health, medication, cycle, food, photo, or clinic data. | Ad attribution and measurement | tiktok.com/legal/privacy-policy |
| Meta (Facebook) | App install and activation events, purchase events forwarded by RevenueCat, and a per-install identifier. Your advertising identifier (IDFA) only if you allow tracking in the iOS prompt. No health, medication, cycle, food, photo, or clinic data. | Ad attribution and measurement | facebook.com/privacy/policy |
| PostHog | App: your account id, the product events described above, session recordings of five presentation screens in onboarding, your in-app feedback text, and crash reports. Website: page views, button taps, and UTM campaign tags. | First-party product + website analytics | posthog.com/privacy |
| RevenueCat | Customer ID, purchase and entitlement events | Subscription billing state | revenuecat.com/privacy |
| Apple (Sign in with Apple) | Apple-issued user identifier (and email if you choose to share it) | Sign-in option | apple.com/legal/privacy |
| Open Food Facts + USDA FoodData Central | The barcode number or food name being looked up. No account identifier. | Packaged-food and reference nutrition data | openfoodfacts.org/privacy |
| Resend | Your email address (only if you request a free guide on the website), to deliver the guide and follow-up emails | Email delivery | resend.com/legal |
Notifications are scheduled locally by iOS itself, not pushed from a server, so no data leaves your device for reminders.
The website (jenifit.app)
In short: If you ask for a free guide, we collect your email to send it and a few follow-up notes, via Resend. You can unsubscribe in one tap, anytime. The site uses first-party PostHog analytics (pages, clicks, campaign tags), no health data, no advertising pixels.
This covers everything on jenifit.app, including the home and marketing pages, the free-guide signup at jenifit.app/gift, the link-in-bio hub at jenifit.app/links, and the field-notes articles at jenifit.app/learn. Only the free-guide signup collects personal information (your email). The other pages are content and links, covered by the website analytics described below.
The free guide (email)
When you request a free guide on jenifit.app, we collect your email address and the campaign/source tags (UTM parameters) from the link you arrived on. We use your email to:
- send you the guide you asked for,
- send a short series of related follow-up emails (a few over the following week), and
- recognize you as a returning lead if you later subscribe in the app.
We never sell or rent your email. Every email includes a one-click unsubscribe (RFC 8058) and a visible unsubscribe link; unsubscribing stops all marketing email. Your email is stored at Resend (our email provider) and is not added to the in-app analytics events described above.
Website analytics (PostHog)
The website uses the same first-party PostHog project for basic analytics: page views, button taps (for example, tapping the App Store badge), the open-in-Safari helper for in-app browsers, and the marketing-campaign tags (UTM parameters) on inbound links. Website analytics do not include health, lifestyle, or weight data, and the website carries no advertising pixels, no Meta Pixel, no TikTok Pixel, no Google Analytics. The TikTok and Meta ad attribution described above is in the iOS app only, not on this website.
PostHog may set first-party cookies or local storage in your browser for analytics. You can block these with your browser settings or a content blocker; the site works the same either way.
Lawful basis (EU / UK)
- The guide + follow-up emails: consent (Article 6(1)(a)), withdraw any time via the unsubscribe link.
- Website analytics: legitimate interest (Article 6(1)(f)) in understanding and improving the site.
Your rights
In short: See your data, update it, take it with you, delete it. Disconnect a clinic. Turn tracking off.
- See or update. Your numbers are editable in the app, and your journal is yours to edit or delete entry by entry.
- Export. Email support@jenifit.app and we'll generate a JSON dump of your synced rows. The on-device-only answers are not part of the export because we don't have them.
- Delete your account. Settings → account → delete account permanently deletes every row of yours from Supabase (including your medication, dose, symptom, and any care-related rows), your photos from cloud storage, your local data, and your RevenueCat customer record. There is no soft-delete; the data is unrecoverable.
- Disconnect a clinic. Settings → your care team → revoke a consent or disconnect entirely.
- Withdraw tracking consent. iOS Settings → Privacy & Security → Tracking, at any time.
- Revoke Apple Health access. iOS Settings → Privacy & Security → Health → Jeni, per category.
California residents (CCPA/CPRA)
In short: We do not sell your Personal Information. Ad measurement with your advertising identifier may count as “sharing”, and the iOS tracking prompt is how you opt out. You also have the right to know, delete, correct, and to non-discrimination.
If you reside in California, the CCPA as amended by the CPRA gives you the following rights:
- Right to know. The categories we collect are listed under “What we collect” above. For the specific pieces we hold, email support@jenifit.app.
- Right to delete. Use Settings → account → delete account, or email us. Deletion is permanent.
- Right to opt out of sale or sharing. We do not sell Personal Information. We do send install, launch, retention, activation and purchase events to TikTok and to Meta for ad measurement, which can involve your advertising identifier if you allow tracking. To the extent that is “sharing” for cross-context behavioral advertising, you opt out by declining the iOS App Tracking Transparency prompt or turning tracking off in iOS Settings → Privacy & Security → Tracking. We do not share health information for advertising.
- Sensitive Personal Information. We use the health-related information you give us to provide the app to you. The one further use is the categorical product analytics described above, so we can see how different groups use the app; it carries no measurement, no brand name, and no dose. We do not sell it, we do not disclose it for advertising, and we do not use it to infer characteristics about you.
- Right to correct. Edit in-app, or email us for fields you can't reach.
- Right to non-discrimination. We do not condition pricing or feature access on whether you exercise any of these rights.
Authorized agents may submit a request on your behalf with verifiable proof of authorization. We may need to verify your identity before responding.
EU + UK residents (GDPR)
In short: Consent for Apple Health, tracking, and notifications. Contract performance for your account, sync, and subscription. Legitimate interest for product analytics. You can object, restrict, or withdraw at any time.
If you reside in the European Economic Area, the United Kingdom, or Switzerland, the GDPR and UK GDPR give you specific rights. The data controller is bay82 Studio LLC, reachable at support@jenifit.app.
Health-related information is a special category under Article 9. Where we process it, we do so on the basis of your explicit consent (Article 9(2)(a)), given when you choose to enter it, grant Apple Health access, or connect a clinic. You can withdraw that consent by turning the relevant feature off, revoking access, or deleting your account.
Lawful basis for processing
- Apple Health access: consent (Article 6(1)(a) and 9(2)(a)). Withdraw any time in iOS Settings → Health.
- Account, sync, medication and symptom records: performance of a contract (Article 6(1)(b)) with explicit consent for the health elements (Article 9(2)(a)).
- Clinic connection: explicit consent (Article 9(2)(a)), granted per scope and revocable per scope.
- Subscription data (RevenueCat): performance of a contract (Article 6(1)(b)).
- Product analytics and the five-screen onboarding session recording (PostHog): legitimate interest (Article 6(1)(f)) in understanding and improving the product. You can object by emailing us.
- Ad attribution (TikTok, Meta): consent (Article 6(1)(a)), given through the iOS App Tracking Transparency prompt and withdrawable in iOS Settings.
- Notifications: consent (Article 6(1)(a)).
Your rights under GDPR
- Access, see what we hold. Email support@jenifit.app.
- Rectification, edit in-app or email us.
- Erasure, Settings → account → delete account.
- Restriction, email us to pause processing.
- Portability, email us for a JSON export of your synced rows.
- Object to legitimate-interest processing, email us.
- Withdraw consent for Apple Health, tracking, notifications, or a clinic connection, at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with your national supervisory authority.
Your data is processed in the United States. We do not currently have an Article 27 EU representative. If a formal representative is required for your request, contact support@jenifit.app and we will name one within a reasonable period.
Health privacy law and HIPAA
In short: bay82 Studio LLC is not a healthcare provider or health plan, so the direct-to-consumer Jeni service is generally outside HIPAA. A clinic you connect to may itself be covered by HIPAA, and that relationship is a different legal context. We do not claim to be HIPAA compliant or certified.
HIPAA applies to healthcare providers, health plans, healthcare clearinghouses, and their business associates. bay82 Studio LLC is none of these in the direct-to-consumer app: we do not provide medical care and do not bill insurance. So the health information you enter into consumer Jeni is generally handled as consumer health data under general privacy law rather than as HIPAA protected health information.
The clinic-connected experience is a different context. If you connect to a healthcare practice, that practice may itself be a HIPAA-covered entity, and different obligations can apply to what it receives and to our role in carrying it. If you have questions about how your practice handles your information, ask the practice.
We do not claim to be HIPAA compliant, HIPAA certified, a Covered Entity, or a Business Associate, and we do not currently represent that a Business Associate Agreement is in place. Being outside HIPAA does not mean your information is unprotected: consumer health privacy laws in several states and countries apply to it, and this policy describes how we handle it.
Children (COPPA)
In short: Minimum age is 13. Target audience is 18+. If you are under 13, do not use Jeni.
Jeni is not directed at children under 13 (or 16 in the EU under GDPR). The app is designed for adults 18 and over. We don't knowingly collect data from anyone under 13. If you believe a child has signed up, contact us and we'll delete the account.
Security
In short: TLS in transit. Row-level security at the database. Private storage buckets. No long-lived service credentials in the app.
- TLS 1.2+ in transit for every connection the app makes.
- Postgres Row-Level Security on every Supabase table. You can't read or write rows belonging to another user even if our app code had a bug. Clinic access is gated by the same mechanism: a practice cannot read your rows without an active, unrevoked consent.
- Private storage buckets with per-account access rules for meal photo thumbnails and body scan backups.
- Sessions live in the iOS Keychain. No long-lived service credentials are bundled in the app, only publishable keys scoped by server-side rules.
Changes to this policy
In short: We'll bump the “Last updated” date and surface an in-app notice on next launch for non-trivial changes.
The current version reflects iOS app v1.2.0 and the jenifit.app website. If we make material changes, we'll bump the “Last updated” date above and (for non-trivial changes) surface an in-app notice on next launch.
Contact
bay82 Studio LLC
support@jenifit.app