Privacy Policy

This policy explains how SuppAI collects, uses, and protects information when you use the SuppAI app and website.

Information we collect

We collect the answers you choose to provide in the onboarding quiz, including goals, diet, lifestyle, medications or health flags, and optional lab information. We also create an anonymous device identifier and store your generated guide and checklist activity. If you opt in to usage analytics, we collect limited product events such as app opens, coarse screen visits, onboarding progress, feature use, and purchase outcomes. After you accept the updated analytics choice, PostHog receives an allowlisted subset of these events with a provider-specific pseudonymous identifier. PostHog does not receive your raw account identifier, email, health-integration events, or personal profile attributes. Starting with version 1.4, accepting the updated analytics choice also allows masked onboarding session recordings. Text, images, and system pickers are masked on the device; quiz answers, personalized guides, chat, and other sensitive screens are fully hidden. Replay network and console capture are disabled. PostHog receives network connection metadata to deliver the service; IP-based geolocation is disabled. Normal analytics events do not create person profiles. Account deletion temporarily creates an empty pseudonymous record so PostHog can queue event erasure, then removes that record. RevenueCat subscription lifecycle events used for attribution may include the product, transaction value, and currency for trial starts or conversions, purchases, renewals, cancellations, refunds, and billing issues. Events also include app version, build number, platform, and operating-system version. With your analytics opt-in, we collect production performance measurements such as launch and interaction timing. In the updated version 1.4 privacy flow, ad measurement is a separate choice controlled by Apple tracking permission. For Meta, TikTok, and ChatGPT Ads measurement, AppsFlyer may process opted-in install, app-open, and conversion events with network/device metadata and an AppsFlyer-generated pseudonymous identifier. SuppAI may set that pseudonymous identifier in RevenueCat so RevenueCat can send subscription lifecycle and revenue events to AppsFlyer. The app disables AppsFlyer collection of Apple's Identifier for Vendors. Starting with version 1.4, access to Apple's Identifier for Advertisers requires separate Apple tracking permission. The updated privacy flow starts AppsFlyer only when that permission is granted. These analytics and ad-measurement events never include quiz answers, medication names, lab results, Apple Health values, guide contents, or chat text. If you provide an email address, we associate it with your account for account support and important service communications. If you contact support, we collect your reply email and the message you submit.

SuppAI may collect privacy-filtered crash diagnostics, including stack traces, app and build version, operating-system version, and device model. Crash reports exclude names, email addresses, quiz answers, medication names, lab results, Apple Health values, guide contents, chat text, screenshots, view recordings, and network request data.

If you choose to connect Apple Health, SuppAI reads your age range, biological sex, height, weight, sleep duration and stages, resting heart rate, heart-rate variability, and respiratory rate. Raw Apple Health samples and exact birth date stay on your device. When you build or explicitly re-optimize a guide, the app sends a small derived summary to SuppAI and an AI provider (Anthropic, or OpenAI through Vercel AI Gateway as a fallback) for that request. SuppAI does not persist that summary in Neon; it is held only in memory while the request is processed.

How we use information

We use your information to create and save your supplement guide, answer questions about your plan, process optional lab uploads, operate subscriptions, provide support, protect the service, and improve app reliability. Before health-related answers or lab information are sent for AI processing, the app asks for your explicit consent. Apple Health access is optional, read-only, and can be disconnected in the app or revoked in iOS Settings. Usage analytics are optional and can be turned on or off on the paywall or in Profile. We may still record minimal guide-generation outcomes, rate-limit reservations, and error codes needed to operate and protect the service. Those operational records do not include your quiz answers, health values, guide contents, or chat text.

Service providers

Anthropic processes the information needed to generate guides, answer plan questions, and interpret optional lab uploads. If primary guide generation fails or is unusually slow, OpenAI may process the guide-generation information through Vercel AI Gateway. Neon and Vercel provide database and hosting infrastructure. Apple and RevenueCat process and manage subscription information. For users who allow ad measurement, RevenueCat may also send subscription lifecycle and revenue events associated with a pseudonymous AppsFlyer identifier to AppsFlyer. Sentry provides privacy-filtered crash diagnostics. AppsFlyer provides install and campaign attribution and may send selected opted-in conversion events to Meta, TikTok, and ChatGPT Ads (OpenAI), subject to tracking permission and partner privacy settings. Expo provides production performance monitoring. PostHog provides optional product analytics through SuppAI's event API and optional masked onboarding recordings. These providers may process information only as needed to provide their services to SuppAI.

We do not sell your personal information, use health information for advertising, or share quiz answers with advertising networks. In the updated version 1.4 privacy flow, iOS users may choose whether to allow Apple's cross-app tracking permission. Only with that permission may AppsFlyer use the advertising identifier (IDFA) and limited app activity to measure ads across companies. Declining leaves all app features available. Analytics and masked recordings have their own optional choice; accepting or declining them does not change Apple tracking permission. When the app observes that tracking permission has been revoked, it stops AppsFlyer and requests removal of the AppsFlyer identifier from RevenueCat for future attribution. IDFV collection remains disabled. Earlier privacy flows combined optional analytics and ad measurement, with aggregate privacy protections when Apple tracking was not allowed; releases before version 1.4 suppressed both IDFA and IDFV. Change analytics and recording sharing in Profile and Apple tracking permission in iOS Settings.

Optional website ad measurement

On our download page, you can optionally allow OpenAI's measurement pixel to report page visits and App Store button clicks. It may use browser information and first-party attribution cookies to connect website activity to an ad click. The pixel is loaded only after you opt in. Uncheck the option to stop future measurement; the download link works with measurement off. This website choice does not grant tracking permission in the iPhone app. We do not send health information or treat an App Store button click as a completed install. These website events are opted out of future user-level personalization.

Retention and deletion

We retain account information and saved guides while your account remains active. You can delete your account and server-side data from Delete my data on the paywall or in Profile. Deletion also cancels pending analytics deliveries and queues erasure of your PostHog events. Provider deletion is asynchronous and retried automatically if the provider is temporarily unavailable. You may also request help through our support form. Support messages are retained while needed to resolve your request. Some limited records may be retained when required for security, fraud prevention, or legal compliance.

Security and choices

We use reasonable technical and organizational safeguards, but no method of storage or transmission is completely secure. You may skip the optional email field and optional lab upload. You can turn analytics and recordings off on the paywall or in Profile. Profile also links to iOS Settings to manage Apple tracking permission separately. You can withdraw from AI processing by deleting your account and no longer using those features.

Questions or privacy requests can be sent through our support form.

Last updated: September 15, 2026.