← Back to MetabolicOS

METABOLICOS

Privacy Policy
Effective Date: April 5, 2026

This Privacy Policy describes how [MetabolicOS Company Name] ("Company," "we," "us," or "our") collects, uses, stores, and protects your information when you use the MetabolicOS application and related services (the "Service").

Our Core Privacy Principle: Your health data belongs to you. We collect only what is necessary to provide the Service, we never sell your personal data, and we give you full control over your information at all times.

1. Information We Collect

1.1 Information You Provide Directly

Account Information: Email address and password (stored hashed). Optionally: name, date of birth, and profile preferences.

Health and Wellness Data: The health data you voluntarily enter, including:

Payment Information: Payments are processed by our third-party payment processor. We do not store your full credit card number or bank account details. We receive only a transaction ID and subscription status.

1.2 Information Collected Automatically

1.3 Information from Third Parties

We may receive data from third-party services you connect (fitness trackers, health device APIs, SSO providers). We only access data you explicitly authorize.

2. How We Use Your Information

Purpose Data Used Legal Basis (GDPR)
Provide core tracking featuresHealth data, account infoContract performance
Generate predictions & insights (Pro/Elite)Health trends, logged dataContract performance
Sync data across devicesAll user data (encrypted)Contract performance
Process paymentsTransaction ID, subscription statusContract performance
Improve the ServiceAggregated, de-identified usage dataLegitimate interest
Send service communicationsEmail, account infoLegitimate interest
Ensure security & prevent fraudLog data, device info, IPLegitimate interest
Comply with legal obligationsAs required by lawLegal obligation
We will NEVER:

3. Data Storage and Security

3.1 Local Storage (Free Tier)

By default, MetabolicOS stores your data locally on your device using browser local storage. Your data never leaves your device and is not transmitted to any server. This means complete privacy, but data can be lost if browser data is cleared.

3.2 Cloud Storage (Pro/Elite Tiers)

If you opt into cloud sync, your data is:

3.3 Security Measures

3.4 Data Breach Notification

In the event of a data breach, we will notify you via email and in-app notification within 72 hours, in accordance with applicable laws including GDPR.

4. Data Sharing and Disclosure

4.1 Service Providers

All service providers are contractually obligated to protect your data.

4.2 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

4.3 Business Transfers

If the Company is involved in a merger or acquisition, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.

4.4 With Your Consent

We may share data with your explicit consent, such as when using Provider Export to generate a health report for your doctor.

5. Your Rights and Choices

5.1 Rights for All Users

5.2 Additional Rights for EEA/UK/Swiss Users (GDPR)

Data Transfers: We use Standard Contractual Clauses (SCCs) for EEA/UK to US data transfers.

5.3 California Residents (CCPA/CPRA)

To exercise any rights, contact us at privacy@metabolicos.app.

6. Cookies and Tracking

We do not use advertising cookies, tracking pixels, cross-site tracking, or behavioral advertising.

7. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect data from children. If we become aware of such data, we will promptly delete it.

8. Data Retention

9. Health Data — Special Provisions

MetabolicOS is not a HIPAA-covered entity. We are a consumer health and wellness application, not a healthcare provider, health plan, or healthcare clearinghouse.

Despite this, we apply strong protections to your health data:

10. International Data Transfers

MetabolicOS is operated from the United States. If you access from outside the US, your data will be transferred to and processed in the US with appropriate safeguards including Standard Contractual Clauses, data processing agreements, and technical encryption measures.

11. Changes to This Policy

We may update this Privacy Policy from time to time with at least 30 days' notice for material changes. Notification will be provided via in-app notice and email.

12. Contact Us

[MetabolicOS Company Name]
Privacy Inquiries: privacy@metabolicos.app
General Support: support@metabolicos.app
Website: www.metabolicos.app

For EEA/UK users, you may also contact your local data protection authority.