Privacy Policy for Supplement AI Inc.
Effective Date: September 7, 20261. Introduction
Supplement AI Inc. ("Supplement AI," "we," "us," or "our") respects your privacy and is committed to protecting the personal data we collect from you. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our website, iOS app, and related services (collectively, the "Service").
2. Information We Collect
We collect the following categories of personal data:
- Identification Information: Name and email.
- Transactional Information: Account details and purchase history.
- User Activity Information: Device information, IP addresses, usage analytics.
- Supplement and Health Data: health-adjacent information you voluntarily provide, such as current supplements, medications, conditions, goals, dietary constraints, DOB, sex, activity level, diet, Stack Optimizer history, saved snapshots, and product interactions.
- Uploaded Images and Extracted Product Data: supplement label photos you choose to upload, and information extracted from those photos, such as brand name, product name, barcode, serving information, ingredients, amounts, and units.
Supplement AI is not a healthcare provider, health plan, healthcare clearinghouse, or business associate unless we separately agree in writing. The Service is not designed to receive medical records from covered entities, insurance records, or information you expect to be protected as HIPAA Protected Health Information. Any health-adjacent information you provide is voluntary and is used to operate educational and informational supplement decision-support features.
3. How We Use Your Data
We process your personal data to:
- Provide personalized supplement decision support, product search, Stack Optimizer scoring, optimization detail, Analysis History, and saved snapshots based on your account state and scientific research.
- Analyze supplement label photos you upload to identify product details, serving information, ingredients, amounts, and units.
- Generate AI-assisted summaries and explanations while maintaining service history for continuity.
- Facilitate user onboarding and dashboard functionalities.
- Conduct research search and analysis related to supplements.
- Track user interactions, progress, and feedback.
- Process transactions and manage billing.
- Improve our Service through analytics, error tracking, and internal research using pseudonymized and aggregated data.
- Analyze usage patterns, trends, and behaviors to enhance recommendations, features, and overall Service quality.
- Protect data and ensure Service security.
We limit these uses to providing, securing, and improving the Service as described in this policy. Pseudonymous identifiers remain linked to an account; they are not anonymous data.
4. Sharing of Data
We do not sell your personal data. We share information with the providers needed to operate the Service, handle payments, and protect accounts, or when required by law. We do not use health or stack information for cross-context behavioral advertising.
Our service providers and payment providers include:
- MongoDB: Stores account, profile, stack, and other Service records.
- Firebase: Authenticates users and manages account identity, including email and supported sign-in providers.
- OpenAI: Generates AI-assisted explanations. When the AI-personalized overview setting is on, personalized Goal Support sends the selected goal and focus, support labels, current stack contributor and product labels, and proposed-product facts. We do not add your account ID, name, email, date of birth, full profile, or medication list to that request. Product labels you entered may contain personal text, so those labels can reveal information you put into them. Generic product overviews use research and evidence for population groups without your account or stack inputs.
- Google: Analyzes the supplement-label image you select. Before your first label-photo analysis, we ask whether to enable this feature and save your choice to your account. We send the selected image with the instructions needed to read its label; we do not add your account or profile information. Any personal information visible in the image is part of what Google receives.
- PostHog: Provides authenticated product analytics linked to your pseudonymous account identifier. Our structured events contain bounded actions, setup-step names, coarse counts and categories, subscription state, and product-interaction metadata. They do not include your name, email, exact goals, age or date of birth, diet answers, conditions, medications, or open-ended health text. Some web product-interaction events include a public product identifier. The web client also collects page, interaction, browser, and error metadata, with filtering on public product and paper detail pages. The iOS client is more restrictive: allowlisted lifecycle and screen events, coarse actions, sanitized diagnostic codes, and app/build metadata; it excludes exact product identifiers, raw URLs, raw errors, interaction autocapture, and session replay.
- Email delivery provider: Sends account and other transactional emails using your email address and delivery information through our configured email service.
- Cloudflare: Provides content delivery and security, including processing connection information.
- Vercel: Hosts the website and APIs and provides deployment and performance monitoring.
- Axiom: Receives operational logs from our hosting provider so we can investigate service and billing failures. Application logs use bounded metadata and, where user correlation is needed, a salted account hash rather than account or health payloads. Hosting logs may include connection metadata.
- Apple: Processes App Store purchases and subscription renewals through StoreKit using your Apple Account and payment information. Apple also provides Sign in with Apple when you choose it.
- RevenueCat: Helps verify App Store purchases and manage subscription access. It receives a randomly generated billing identifier and purchase/subscription metadata. We do not send RevenueCat your Supplement AI account ID, name, email, or health and stack information.
- Stripe: Processes website subscription payments and manages web billing, including payment information, contact details, and subscription records.
You can turn future personalized OpenAI Goal Support requests on or off in your account settings. The setting defaults to on for the website. The iOS app asks for an explicit choice before its first setup or manual analysis when no choice has been saved. Turning it off leaves saved analyses available and stops new personalized Goal Support requests until you turn it on again. Label-photo analysis has a separate account setting. We ask once before your first label-photo analysis when no choice has been saved. When enabled, selecting a label photo sends it for analysis without asking again for each photo. You can turn future label-photo analysis on or off in Account under AI features.
We use uploaded label photos to extract the product information you request and do not save the uploaded photos after analysis. Extracted brand names, product names, serving information, ingredients, amounts, and units may be retained to support your stack and improve the product database. This describes Supplement AI storage; it is not a promise of zero retention by an AI provider.
We limit provider payloads to the information needed for their function. Providers also handle information under their applicable service terms, privacy policies, and legal obligations. Their retention and processing practices can differ from our own.
5. Data Security
We use HTTPS/TLS for transmission, encrypted storage and account fields, access controls, restricted service credentials, and account-deletion barriers to protect information. Operational logs and analytics use limited data appropriate to their purpose. Account identifiers are pseudonymous, not anonymous, and are not a substitute for access controls or encryption. No system can guarantee absolute security.
6. Data Transfers
Supplement AI operates primarily in the United States. Our hosting and service providers may process information in the United States and other countries, where data protection laws may differ from those where you live. Contact us for information about the safeguards applicable to your data.
7. Your Data Rights
You have rights regarding your personal data, including:
- Access to your data.
- Correction or update of your data.
- Request deletion of your data, including account profile data, Stack Optimizer history, saved snapshots, and export artifacts retained by the Service.
- Data portability: Request a copy of your personal data in a commonly used, machine-readable format, including available account, stack, optimizer, and export records.
- Opt-out: Request that we not sell or share your personal information (note: we do not sell personal data).
- Withdraw consent where applicable, including future personalized OpenAI Goal Support sharing and Google label-photo analysis in Account under AI features. Withdrawal does not undo processing that already occurred.
These rights are provided in accordance with applicable laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). To exercise your rights, contact us at [email protected].
8. Retention of Data
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, provide ongoing Service functionality, or as required by applicable laws. You may request deletion of your account and associated data at any time through your account settings or by contacting us.
Account deletion removes your account-owned profile, stack, saved analyses, searches, and other private Service records. Provider cleanup can continue afterward. If billing cleanup needs another attempt, we temporarily retain the account and billing identifiers needed to finish it. PostHog erasure also retains the pseudonymous account identifier needed for cleanup until provider deletion is confirmed; a successful account-deletion response does not mean every provider has already completed erasure.
We retain a minimal one-way account-deletion security marker to prevent stale authenticated requests and delayed application writes from recreating deleted data. The marker does not contain your raw account identifier, email address, or health information. Payment providers may retain transaction records to meet legal obligations, and other provider retention remains subject to applicable terms and law.
Deleting your Supplement AI account does not cancel an Apple subscription. Manage or cancel it separately in iPhone Settings > your Apple Account > Subscriptions, or through Apple subscription management. Account deletion initiates cancellation and customer cleanup for Stripe website billing; if cleanup is incomplete, the deletion flow identifies that it needs another attempt.
9. Cookies and Tracking Technologies
Our website uses cookies, local storage, and similar technologies for sign-in, preferences, and authenticated product analytics. The iOS app uses device storage for account state and a bounded queue of allowlisted analytics events. These analytics are used to understand and improve Supplement AI, not to track you across other companies' apps and websites for advertising.
10. Compliance with Laws
Your privacy rights and our obligations depend on the laws applicable to you and the Service. Nothing in this policy limits rights you have under applicable data protection or consumer privacy law.
11. Changes to This Privacy Policy
We may update this policy occasionally. Any changes will be posted on this page, with the "Effective Date" updated accordingly.
12. Contact Information
If you have questions or concerns about this Privacy Policy, please contact:
Adam Schorr, FounderSupplement AI Inc.
1111B S Governors Ave STE 26626
Dover, Delaware 19904
[email protected]
By using Supplement AI, you acknowledge and agree to the practices described in this Privacy Policy.