This Privacy Policy explains how Brizo Finance LLC, the operator of MinervaOS ("MinervaOS," "we," "us," or "our") collects, uses, shares, and protects information when you use the MinervaOS iPhone application and related services (the "Service"). By using the Service, you agree to this Privacy Policy. Capitalized terms not defined here have the meaning given in our Terms of Service.
Our commitments, in plain terms: We do not sell your personal information. We do not use it for third-party or cross-app advertising. We do not track you across other companies' apps or websites. We use no analytics, advertising, or tracking SDKs. Data we read from Apple Health is used on your device to compute your estimates; the raw samples are not sent to our servers, and the only derived figures that reach them are the ones you choose to share — a logged workout, or the daily step count and calorie burn you switch on for followers (Section 2b). Cloud wearables you connect through our wearable-connection provider (Junction) are different: their data does reach our servers, because that is how it gets to your phone. It is stored for your account alone, kept on a rolling 35-day window, deleted when you delete your account, and never sold or used for advertising (Section 2b).
If you are a California resident, please also see Section 13 (Your California Privacy Rights), which includes the disclosures required by the CCPA/CPRA and CalOPPA.
If you live in Virginia, Colorado, Connecticut, Texas, Oregon, or another U.S. state with a comprehensive privacy law, see Section 14 (Other U.S. State Privacy Rights) — including how to appeal if we refuse a request.
If you are a resident of Washington, Nevada, or another state with a consumer health data law, our separate Consumer Health Data Privacy Policy also applies to your health data and controls where it is more specific.
What changed on August 17, 2026. Three corrections so this Policy matches the app. Section 2b now says exactly which Apple Health-derived figures can reach our servers: none of the raw samples, but a workout you import becomes a logged workout, and while Workouts (on by default), Burned, or Eaten is on under What followers see — or when you share a daily summary to a group or your feed — the day's step count and calorie-burn figures are stored so the people you allow to see your profile can see them. Section 6 now lists the five follower switches as they exist in the app. Section 2c now discloses the crash and performance diagnostics (Apple's MetricKit reports) the app sends us when it crashes or hangs, and corrects the microphone sentence: a video you record for a post or group chat is stored with its audio track. Nothing about selling or advertising changed: we still do neither.
What changed on August 8, 2026. Corrections so this Policy describes what the Service actually does. Section 2b now sets out what happens to data from the cloud wearable platforms you connect through our wearable-connection provider, Junction: those platforms deliver it to our servers, where it is stored for your account alone on a rolling 35-day window and deleted when you delete your account. Junction is named as a processor in Sections 7 and 13.3, and the list of platforms you can connect is brought up to date. Sections 6a and 7 now state that our first-pass moderation classifier (OpenAI) reads images and sampled video frames as well as text, so photos and video you publish to a social surface are transmitted to it. Our separate Consumer Health Data Privacy Policy was corrected the same way. Nothing about selling or advertising changed: we still do neither.
What changed on July 30, 2026. We added retention periods for each category of data (Section 9.1), a breach-notification commitment including the FTC Health Breach Notification Rule (Section 19), rights and an appeals route for U.S. states beyond California (Section 14), default protections for users under 18 (Section 15.2), and a fuller account of how AI is used and what we do not do with it (Section 4). Nothing about what we collect, or our commitment never to sell it, changed.
1. Who We Are
MinervaOS is a nutrition, fitness, and wellness tracking app for iPhone. The business responsible for your information (the "data controller") is Brizo Finance LLC, contactable at support@minervaos.app.
2. Information We Collect
a. Information you provide
- Account information: your email address and password (passwords are handled by our authentication provider and are not stored by us in readable form). If you use Sign in with Apple, we receive the identifier Apple provides and, if you choose to share it, your name and a relay email.
- Profile and health inputs you enter: display name; username; profile photo; and health/body information you choose to enter, which may include height, weight, age, date of birth, sex, activity level, goal and target rate, body-fat percentage and lean mass (and the measurement method, e.g. DEXA or a smart scale), resting heart rate, VO₂max, measured resting metabolic rate, thyroid (TSH) value, free-text lab notes, and custom calorie/macro/micronutrient targets.
- Logged content: foods and meals you log (name, calories, macros, micronutrients, portion notes), workouts (type, duration, intensity, exercises, sets/reps/weights, average heart rate), body-weight entries, saved meals and recipes, and custom foods you create.
- Food and report photos: photos of meals or nutrition labels you scan, and images of body-composition reports (e.g. DEXA/InBody/smart-scale reports) you choose to upload. See Section 4 (AI Processing).
- Group / social content: if you use Groups, the group content you create — posts ("shares") of workouts, meals, or daily summaries; chat messages and any photos you attach; comments; emoji reactions; and moderation actions you take (users you block, content you report).
b. Health and wearable data
- With your permission, the Service reads data from Apple Health, which may include steps, walking/running distance, flights climbed, heart rate and resting heart rate, heart-rate variability, VO₂max, sleep, workouts, body mass, body-fat percentage, and lean body mass. It can also write the body weight you log back to Apple Health (so apps like WHOOP stay in sync). Apple Health data is processed on your device: the raw samples — step counts, heart-rate series, sleep stages, and the like — are not transmitted to our servers. Two derived records are the exception, and both are things you choose: (1) a workout imported from Apple Health or your Apple Watch becomes a logged workout (type, duration, intensity, average heart rate where available) and is stored on our servers like any workout you log by hand; and (2) the daily figures you let followers see. Under Profile → Privacy & sharing → What followers see, the Workouts switch (on by default) shows the people who can see your profile the sessions you logged plus the day's step count, resting (BMR) burn, and movement calories; Burned (off by default) shows the day's total burn; Eaten (off by default) shows calories and macros against your targets. While any of those three is on — or when you share a daily summary to a group or your feed — the day's step count and calorie-burn figures (total burn, resting/BMR, and the movement portion), which your phone computes from Apple Health and any connected wearable, are stored on our servers so the people you allow can see them. Your profile is private by default, so until you approve a follower or make it public, nobody sees them. Turning those switches off hides the figures and stops new days being published; nothing else from Apple Health leaves the phone.
- With your permission, the Service can connect cloud wearable platforms — currently Garmin, Oura, Fitbit, Polar, Withings, Wahoo, Ultrahuman, Peloton, Eight Sleep, and Zwift — through our wearable-connection provider Junction, and retrieve activity, workout, sleep, heart-rate, and body-measurement data. WHOOP, where it is available, connects directly instead.
- How cloud wearable data is handled: these platforms do not talk to your phone. When you connect one, the platform sends your data to Junction, which normalizes it and delivers it to our servers, where it is stored — scoped to your account only, readable by no other user — and read back by your phone to compute your estimates (such as your calorie burn). What is stored is the per-day record the platform sends: daily activity and step summaries, workouts, sleep sessions, heart-rate series (averaged into two-minute buckets before they are stored), body measurements such as weight, body-fat percentage and VO₂max, and any other daily metric that platform reports. We keep it on a rolling 35-day window and delete anything older; we do not build a long-term history from it. It is never used for advertising, never sold, and never shown to other users — what others can see remains only the summaries you explicitly choose to share (Section 2a). Disconnecting a platform stops new data arriving; deleting your account deletes all of it, immediately and permanently.
- WHOOP (direct connection) is still processed on your device; its OAuth tokens are stored securely in your device Keychain and its data stream is not sent to our servers.
c. Information collected automatically
- Device push token: to deliver group push notifications, we register an Apple Push Notification service (APNs) device token and the notification environment.
- Log and technical data: when your app communicates with our backend, our infrastructure provider automatically logs standard request metadata — including IP address, timestamps, request/endpoint details, and error/diagnostic information — for security, abuse prevention, and reliability. This is standard server logging; we do not use it to build advertising profiles.
- Crash and performance diagnostics: if the app crashes or hangs, iOS's MetricKit produces a diagnostic report (stack traces, app/OS version, device model) that the app sends to our server, stored against your account, so we can fix the fault. It contains no food, health, or message content. It is kept until you delete your account (Section 9.1).
- We do not collect precise geolocation, your contacts, advertising identifiers (IDFA), or any cross-app tracking identifiers. The microphone is used only while you record a video for a post or a group chat, and a video you choose to post is stored with its audio track as part of that post; we do not otherwise record or collect audio.
d. Purchase information
If you buy a subscription, the purchase is processed by Apple. We receive your subscription/entitlement status from Apple; we do not receive your full payment-card details.
e. Information from third parties
If you sign in with Apple (or another provider we may offer), that provider gives us a token confirming your identity and, if you allow it, your name and email.
3. How We Use Information
We use information to: provide, operate, and secure the Service and your account; generate your estimates, targets, and AI outputs (calorie/macro/micronutrient estimates, calorie-burn and metabolism calculations, food recognition, and suggestions); sync and back up the data you log; operate Group features you choose to use; deliver notifications and reminders you enable; look up products you scan by barcode; provide support; prevent fraud and abuse and enforce our Terms; comply with legal obligations; and maintain and improve the Service. We do not use your health data, food photos, or personal content to serve advertisements, and we do not sell this information.
4. AI Processing and Third-Party AI Provider
4.1 What is sent, and to whom
To provide AI features, content you submit is transmitted through our backend to a third-party AI provider (Anthropic) via its API and processed to return a result to you. This includes: food/label photos and any description or correction you add; body-composition report images you upload (DEXA/InBody/smart-scale); and text you send to the AI assistant (and recent conversation turns). We instruct our AI provider to process this content only to return results to you and not to use it to train its models, consistent with its API terms. We do not retain your food-scan or report photos on our servers; a copy of a food-scan photo is kept on your device so you can review or edit the entry. If you prefer not to use AI photo analysis, you can enter foods manually instead.
Your name and email address are not included in what we send to the AI provider.
4.2 You are interacting with AI, not a person
Every AI feature in the Service — the assistant, food recognition, report parsing, and the suggestions and estimates they produce — is automated software, not a human being and not a licensed professional. We label AI features as such in the app. No AI output is reviewed by a clinician before you see it. This disclosure is made so that you are never misled into thinking you are communicating with a person, consistent with California Business & Professions Code §22601 et seq., California Health & Safety Code §1339.75 et seq., and Article 50 of the EU AI Act.
4.3 We do not train AI models on your data
We are a deployer of general-purpose AI models, not a developer of them. We do not build, train, fine-tune, or substantially modify generative AI models, and we do not use your content — food logs, photos, messages, health data, or group content — as training data for any model, ours or anyone else's. Because we do not develop or substantially modify a generative AI system, the training-data documentation duty in California AB 2013 falls on the model developers whose systems we call, not on us; their disclosures are published by those developers.
4.4 AI content provenance (California AI Transparency Act, SB 942)
California's AI Transparency Act imposes duties (a public AI-detection tool and provenance marking of AI-generated content) on "covered providers" — generative AI systems with more than one million monthly users in California. MinervaOS is below that threshold and is not currently a covered provider. We do not generate synthetic images, audio, or video for publication; our AI outputs are numeric estimates and short text shown to you. If we cross that threshold or begin producing synthetic media, we will implement the required provenance disclosures and update this Policy before doing so.
4.5 Safety limits on AI outputs
Our AI assistant is a nutrition and fitness tracking tool. It is not a companion, a therapist, or a crisis service. It is instructed to refuse to provide extreme-restriction, purging, or other disordered-eating guidance, and to surface crisis resources rather than engage when a conversation indicates risk of self-harm or an eating disorder. You can reach those resources at any time in the app under Settings → Safety & Crisis Resources. If you are in immediate danger, contact your local emergency number; in the US you can call or text 988 (Suicide & Crisis Lifeline), and the National Alliance for Eating Disorders helpline is 1-866-662-1235.
5. Barcode Lookup
When you scan a product barcode, the barcode number is sent to Open Food Facts (a third-party open food database) to look up product and nutrition information. Only the barcode is sent for this lookup; no account information is included.
6. Group and Social Features
Social features are optional. Groups: the content you share to a group — posts, messages, photos you attach, comments, and reactions — is stored on our backend and is visible to the other members of that group. Follows and public profiles: your profile is private by default. If you make it public, your posts, display name, username, bio, and avatar are visible to any signed-in user, and anyone may follow you; if it stays private, followers you approve see only what your follower-visibility settings allow. Those settings (Profile → Privacy & sharing → What followers see) are five switches, each governing one line of your profile panel for today and the past week: Workouts (on by default — the sessions you logged, plus the day's step count and resting burn), Burned (the day's total burn), Eaten (calories and macros against your targets), Meals (the list of what you ate), and Weight trend (the direction only, never a number, with progress photos as a separate switch). Personal records are shared by default and can be switched off. Everything other than Workouts and personal records is off until you turn it on. Your handle appears in user search unless you turn off discoverability in Settings. Group chat photo attachments are stored in a private storage area accessible to that group's members; your profile avatar is stored in a storage area readable by other signed-in users so they can display it, so avoid using a photo you wish to keep private. You can block users and report content; blocks and reports are stored to operate those features and for safety.
6a. Content Moderation
Because the Service carries user-generated content, we screen it. This is a condition of using the social features, and it is not optional for content you post.
What we screen. Everything you post or send through a social surface — group messages, posts and captions, comments, group names and descriptions, usernames and display names — passes the automated word/pattern check that runs on our own servers, and any of it can be reported and reviewed by us. The classifiers described below read the subset that is public or widely visible: posts and their captions, comments, usernames and display names, profile avatars, and the images and video uploaded to those surfaces. What you send inside an invite-only group — chat messages, the workouts and meals you share there, and the photos you attach — is a closed room between people who chose each other, so no classifier reads it; reporting, blocking, suspension and the word/pattern check all still apply. We do not apply any of this to your private food logs, weights, workouts, notes, Apple Health data, or connected-wearable records — those are not published to anyone and are never sent to a moderation classifier.
How. In layers. First, an automated word/pattern check that runs on our own servers as content is written. Second, where it is enabled, a fast first-pass classifier operated by OpenAI (its moderation endpoint, which OpenAI states is not used to train its models). That pass reads text and images: the text you wrote, and — for a photo, an avatar, or a video — the image itself, sent to OpenAI as the picture, not as a description of it. When that pass is not enabled, the next layer does all of the work. Third, for nuanced cases and for all images and video, an automated classifier run by Anthropic (Claude). Content a classifier cannot assess, and any content another user reports, is queued for review by an authorized human reviewer on our team.
What that means for your data. The content itself — the text, the image, or sampled frames of the video — is transmitted to both of those providers for the sole purpose of classification: photos you post, photos attached to a public surface, your profile avatar, and frames sampled from a video you upload all leave our servers as images, not as descriptions of images. Photos sent inside a private group room are the exception described above — registered, but not read by a classifier unless someone reports them. The providers act as our processors under contracts limiting their use of the content. Uploaded images and video are held and not shown to anyone but you until they pass this check.
What we keep. The verdict (approved / rejected), the category, and a timestamp, attached to the content. Reports you file and reports filed about you, and any enforcement action taken on your account, are retained as described in Section 9. Where content is unlawful we retain what the law requires us to retain and report it to the appropriate authority; apparent child sexual abuse material is reported to the National Center for Missing & Exploited Children (NCMEC).
Your rights. If content of yours is removed or your account is restricted, you can appeal to support@minervaos.app (Terms, Section 9.4). Decisions are supported by human review, not made by automated processing alone where that would carry legal or similarly significant effects for you.
7. How We Share Information
We share information only as described here, and we do not sell it or share it for cross-context behavioral advertising:
- Service providers (processors) who operate the Service on our behalf under contracts limiting their use of the data, including: our backend, database, authentication, and file-storage provider (Supabase); our AI provider (Anthropic — Sections 4 and 6a); our first-pass moderation classifier provider (OpenAI — Section 6a, where that pass is enabled; it receives the text and the images and sampled video frames you publish to a social surface, including your profile avatar); our email provider (Resend), which delivers moderation reports to our review team and may therefore process the reported content; and Apple (Sign in with Apple, App Store subscriptions, and Apple Push Notification service — for group push we send Apple your device token and the notification text, which may include a group name, a sender's name, and a short message preview).
- Barcode database (Open Food Facts) — Section 5.
- Wearable platforms you connect (e.g. Garmin, Oura, Fitbit, Polar, Withings, WHOOP), to authenticate and retrieve data you authorize; and Junction (our wearable-connection provider), which operates the connection to those platforms on our behalf and processes your wearable data solely to deliver it to us.
- Other users — content you choose to share in a Group is visible to that group's members; if you make your profile public, your posts and profile are visible to any signed-in user, and to followers you approve according to your follower-visibility settings.
- Legal and safety — when required by law or legal process, or to protect the rights, safety, and security of users, the public, or us.
- Business transfers — in a merger, acquisition, financing, or sale of assets, subject to this Policy.
8. Legal Bases (EEA/UK Users)
If you are in the EEA or UK, we process your personal data on these bases: performance of a contract (to provide the Service you request); consent (for health data, Apple Health/wearable access, AI photo processing, and notifications — withdrawable anytime); legitimate interests (to secure, maintain, and improve the Service, balanced against your rights); and legal obligation. Health data is "special category" data, processed based on your explicit consent.
9. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account (Section 12), we delete your account and associated personal data from our active systems; residual copies may persist for a limited period in backups and server logs before being overwritten. Content you shared into a Group may remain visible to that group in de-identified form after your account is deleted.
9.1 Retention period by category
As required by the CCPA, this is how long we keep each category, or the criteria we use to decide:
- Account identifiers (email, user ID, username, display name) — life of the account; deleted on account deletion.
- Profile and health/body values you enter — life of the account; deleted on account deletion.
- Food, workout, weight and micronutrient logs — life of the account; deleted on account deletion.
- Backup of saved meals, workouts, custom targets and exercises — life of the account; deleted on account deletion.
- Group content (posts, messages, comments, reactions) — life of the account; on deletion, removed from our active systems and de-identified where it remains visible to a group.
- Food-scan and body-report photos — not retained on our servers at all; held only for the seconds needed to return a result. The local copy on your device lives until you delete the entry or the app.
- AI assistant messages — kept only for the conversation history shown to you in the app; deleted on account deletion.
- Device push tokens — until the token is invalidated by Apple, you turn notifications off, or you delete your account.
- Cloud wearable data (activity, workout, sleep, heart-rate, and body-measurement records from platforms you connect via Junction) — up to 35 days on a rolling window, then deleted; disconnecting a platform stops new data from arriving, and account deletion removes all of it immediately.
- Server and security logs (including IP address) — up to 30 days for security, abuse prevention and reliability, then overwritten.
- Crash and performance diagnostics (MetricKit reports — Section 2c) — life of the account; deleted on account deletion.
- Shared daily figures (the step count and calorie-burn figures published while a What followers see switch that shows them is on — Section 2b) — life of the account; deleted on account deletion. Turning the switches off stops new days being published and hides the figures from other users.
- Subscription/entitlement status — life of the account, plus the period required for tax, accounting and audit obligations.
- Moderation records (reports filed by or about you, verdicts, enforcement actions) — up to 2 years after the account closes, and longer where a legal obligation or an open investigation requires it. See the note below.
- Terms-acceptance records — life of the account plus 2 years, as the evidence of your consent.
- Backups — overwritten on a rolling cycle of no more than 35 days.
Safety and moderation records are an exception. Reports (filed by you or about you), moderation verdicts, and enforcement actions such as suspensions and bans are retained for up to two years after the account is closed, and longer where a legal obligation or an ongoing investigation requires it. We keep them because deleting them would let a banned user return by re-registering, and because they are the record that shows we acted on reports. They are kept separately from your account data and are not used for any other purpose.
10. Security
We use reasonable technical and organizational measures designed to protect your information, including encryption in transit, row-level access controls that scope your data to your account, secure Keychain storage for tokens on your device, and reputable infrastructure providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Protect your credentials and notify us of any suspected unauthorized access.
11. Data Sent Off Your Device vs. Kept On It
For transparency: kept on your device (not on our servers) — the raw Apple Health data streams, WHOOP data, app preferences, and a local copy of your food-scan photos. Sent to and stored on our servers — your account, profile (including health/body values you enter), food/workout logs (including workouts imported from Apple Health), the daily step count and calorie-burn figures you turn on for followers (Section 2b), group content, avatars, push tokens, crash and performance diagnostics (Section 2c), cloud wearable data from platforms you connect via Junction (Section 2b, 35-day window), and a backup of your weight-log history, saved meals and workouts, and custom targets and exercises (see below). Sent for processing but not stored by us — food/report photos and AI-assistant text (to our AI provider) and barcodes (to Open Food Facts).
Backup of the data you enter. So you don't lose your information if you reinstall the app or switch to a new device, we back up your weight-log history, saved meals and workouts, and custom nutrition targets and exercises to our servers, associated with your account. This backup contains only information you enter in the app; it does not include Apple Health or wearable data. It is accessible only to you, is never sold or shared, and is deleted when you delete your account (Section 12).
12. Your Choices and Rights
- Account deletion. Delete your account and associated data anytime in the app: Settings → Account → Delete Account. This removes your profile, logs, weight history, saved items, AI estimates, device tokens, and your group content from our active systems.
- Access & correction. You can view and edit your profile, logs, and content directly in the app. For other requests, contact support@minervaos.app.
- Permissions. Control camera, photo, Apple Health, notification, and wearable permissions in iOS Settings and within the app. Revoking a permission may limit related features.
- Marketing. We don't run third-party ads or sell your data; messages are limited to operating the Service and the notifications you enable.
13. Your California Privacy Rights
This section provides the disclosures required by the California Consumer Privacy Act, as amended by the CPRA ("CCPA"), and the California Online Privacy Protection Act ("CalOPPA"), and applies to California residents.
13.1 Categories of personal information we collect
In the past 12 months we have collected the following CCPA categories (with examples). We collect these from you, your device, and services you connect (Apple Health/wearables, Sign in with Apple):
- Identifiers — name, username, email address, account/user ID, IP address, device push token. (Collected: Yes.)
- California customer-records information (Civ. Code §1798.80(e)) — name and account contact information. (Yes.)
- Protected classification characteristics — age/date of birth and sex (used to calculate your nutrition and energy targets). (Yes.)
- Commercial information — your subscription/entitlement status (payment is processed by Apple). (Yes, limited.)
- Internet or other electronic network activity — app usage and interaction data, and server log/request metadata. (Yes.)
- Geolocation data — we do not collect precise location; an approximate region may be inferable from your IP address in standard server logs. (No precise location.)
- Sensory information — photos you submit (food/label images, body-composition report images, group photos). (Yes.)
- Inferences — estimates and targets we derive from your data (e.g. estimated calorie burn, personalized targets). (Yes.)
- Sensitive personal information (see 13.2). (Yes.)
- We do not collect: biometric identifiers used to identify you, professional/employment information, education records, or precise geolocation.
13.2 Sensitive personal information (SPI)
We collect the following SPI: account log-in credentials (email with password) and health information (the body metrics, nutrition, and fitness data you provide and log). We use and disclose SPI only for purposes permitted under the CCPA — namely to provide the Service you request and as otherwise allowed without a right to limit (e.g. security, preventing fraud, and ensuring the Service works). We do not use SPI to infer characteristics about you for any purpose other than providing the Service. Because we do not use or disclose SPI beyond these permitted purposes, the CCPA "right to limit" does not change how we handle it.
13.3 Purposes, sources, and disclosures
We collect each category to provide, secure, personalize, and improve the Service, as described in Sections 3–7. Sources are described in 13.1. We disclose personal information for these business purposes to our service providers — our hosting/database/storage provider (Supabase); our AI provider (Anthropic); our first-pass moderation classifier provider (OpenAI), which receives the text, images and sampled video frames you publish to a social surface; our wearable-connection provider (Junction), which receives and delivers to us the data from the cloud wearable platforms you connect (Section 2b); our email provider (Resend), which carries moderation reports to our review team; Apple (sign-in, subscriptions, and push); and Open Food Facts (barcode lookup) — and to other group members for content you choose to share.
13.4 No sale or sharing
We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the preceding 12 months. We do not sell or share the personal information of minors.
13.5 Your California rights
Subject to verification and legal exceptions, you have the right to: know/access the personal information we have collected about you; delete it; correct inaccurate information; opt out of sale/sharing (we do neither); limit the use of sensitive personal information (we already restrict it to permitted purposes); and not be discriminated or retaliated against for exercising your rights.
13.6 How to exercise your rights
You can exercise most rights directly in the app (edit your data, or Settings → Account → Delete Account), or contact us at support@minervaos.app. We will verify your request using information associated with your account. You may use an authorized agent to submit a request on your behalf with proof of authorization. We will respond within the timeframes required by law.
13.7 "Shine the Light"
California Civil Code §1798.83 lets California residents request information about disclosures of personal information to third parties for their direct marketing. We do not share personal information with third parties for their own direct marketing.
13.8 Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. Because we do not track users across third-party websites or apps and do not permit third parties to do so through the Service, we do not need to respond differently to DNT signals; our practice is not to track you regardless of any DNT setting.
13.9 Opt-out preference signals (Global Privacy Control)
Some browsers and extensions send an opt-out preference signal such as Global Privacy Control (GPC). Because we do not sell personal information and do not share it for cross-context behavioral advertising, there is no sale or sharing for a GPC signal to stop. We treat any GPC signal we receive on minervaos.app as a valid request to opt out anyway, and we honor it. Our website sets no advertising or analytics cookies and contains no third-party trackers, so nothing on it is disclosed to a third party for advertising purposes in the first place.
13.10 Notice at Collection
The disclosures in this Section 13, together with Sections 2, 3, 7 and 9, are our notice at collection. You see a short-form version of it in the app before you provide any health information — on the "Before you start" screen at first launch, which identifies the categories we collect (including the sensitive categories in 13.2), the purposes, that we do not sell or share, and the retention periods in Section 9.1, and links to this full Policy. You can reopen it at any time from Settings → Privacy.
13.11 Retention
We disclose the retention period for each category of personal information, including sensitive personal information, in Section 9.1. We do not keep personal information for longer than is reasonably necessary for the purpose for which it was collected.
13.12 Financial incentives
We do not offer any financial incentive, price difference, or service-level difference in exchange for the retention, sale, or sharing of your personal information.
14. Other U.S. State Privacy Rights
If you live in a U.S. state with a comprehensive consumer privacy law — currently including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, as those laws come into force — this section describes rights you have in addition to anything above. Where your state's law gives you more than we describe, your state's law wins.
14.1 Your rights
Subject to verification and the exceptions each statute allows, you may:
- Confirm whether we process your personal data, and access it;
- Correct inaccuracies, taking into account the nature of the data and our purpose for it;
- Delete the personal data we hold about you;
- Obtain a portable copy in a readily usable format, where the processing is automated;
- Opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. None of those three things happen here — we do not run targeted advertising, we do not sell personal data, and we do not profile you for decisions with legal or similar effects — so there is nothing for an opt-out to switch off. We honor a request anyway rather than argue about it.
14.2 Sensitive data requires your consent
Most of these laws treat health data as sensitive, and require opt-in consent before it is processed. Your consent is the affirmative agreement you give on the "Before you start" screen at first launch, and separately at the iOS permission prompt before we read anything from Apple Health or a connected wearable. You can withdraw it at any time by revoking the permission in iOS Settings or deleting your account, and withdrawal is as easy as giving it.
14.3 How to exercise them
Use the in-app controls (Settings → Account → Delete Account, or edit your data directly), or email support@minervaos.app. We will verify the request against the email on your account. We respond within 45 days, extendable once where the law allows, and we will tell you if we need the extension.
You may use an authorized agent. We will ask for proof that you gave them permission.
14.4 Appeals
If we refuse your request, you can appeal. Reply to our decision, or email support@minervaos.app with "APPEAL" in the subject line. A person who was not involved in the original decision will review it, and we will respond in writing within 45 days (60 in some states), explaining the reasoning either way.
If we deny the appeal, you may complain to your state's Attorney General. We will tell you how to do that in the appeal response, because several of these laws require us to.
14.5 No discrimination
We will not deny you the Service, charge you a different price, or give you a worse experience because you exercised any of these rights.
15. Children and Teens
15.1 Under 13
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The date-of-birth control in the app does not accept a date that would make you younger than 13, and you must confirm you are at least 13 to pass the first-run gate. If you believe a child under 13 has provided us personal information, contact support@minervaos.app and we will delete the account and its data promptly, without requiring you to create an account to make the request. We do not condition any part of the Service on a child disclosing more information than is reasonably necessary.
15.2 Teens 13–17
Users between 13 and 17 may use the Service, and where the age of majority or digital-consent age in their jurisdiction is higher, only with the involvement and consent of a parent or guardian. For any account whose date of birth indicates the user is under 18, we apply the following by default, without the teen or their parent having to find a setting:
- No personalized or algorithmically ranked feed. Group content is shown in reverse chronological order to everyone. We do not operate an "addictive feed" as defined by California SB 976: we do not rank, select, or recommend social content based on behavioral profiling, engagement signals, or information about the user or their device.
- Notifications are silenced overnight and during school hours — 12:00 a.m. to 6:00 a.m. every day, and 8:00 a.m. to 3:00 p.m. on weekdays — matching the default quiet periods California requires for minors. Notifications withheld during those windows are not re-delivered in a batch afterwards.
- No public discoverability. A teen's profile is not surfaced in user search to people they are not already in a group with.
- No sale or sharing, ever. We do not sell or share the personal information of any user, and specifically not of any user we know to be under 18. We do not use a minor's personal information for targeted advertising, profiling, or any purpose other than providing the Service.
- No engagement mechanics targeted at minors. We do not use streaks, infinite scroll, autoplay, or notification pressure to extend session length.
Parents and guardians may contact support@minervaos.app to review, correct, or delete a teen's information, or to close the account.
15.3 Why this app may not be right for a minor
Calorie and weight tracking is not appropriate for everyone, and can be actively harmful for a young person with, or at risk of, disordered eating. We say so in the app and in our Terms, and we encourage parents to make that judgement with their child and a professional.
16. International Data Transfers
We and our service providers may process and store your information in the United States and other countries whose data-protection laws may differ from yours. Where required, we use appropriate safeguards for international transfers. By using the Service, you understand your information may be transferred to and processed in these countries.
17. Apple Health Data — Specific Commitments
Consistent with Apple's requirements: we will not use Apple Health (HealthKit) data for advertising or marketing; we will not sell it or share it with third parties for advertising, marketing, data-mining, or similar purposes; we will not disclose it to third parties without your authorization except as needed to provide a health service you requested; and we use it only to provide health, fitness, and wellness features within the Service. As noted in Section 2b, Apple Health data is processed on your device and the raw samples are not transmitted to our servers; the only derived figures that reach them — an imported workout, and the daily step count and calorie burn you switch on for followers — are disclosed to other users only with your authorization, given by turning those switches on, and you can turn them off at any time.
17a. California Confidentiality of Medical Information Act
To the extent any information you store in MinervaOS — such as lab values, thyroid or blood-panel results, or body-composition reports you enter or import — constitutes "medical information" under the California Confidentiality of Medical Information Act (California Civil Code §56 et seq.), we maintain it in a manner that preserves its confidentiality, do not disclose it except as authorized by you or as permitted by that Act, and apply the same protections to it as to all your health data under this Policy. We do not use it for advertising or marketing and we do not sell it.
18. Third-Party Services
The Service integrates with and links to third-party services (Apple, our infrastructure/AI providers, wearable platforms, and Open Food Facts). Their handling of your information is governed by their own privacy policies, which we encourage you to review. We are not responsible for third parties' practices.
19. Security Incidents and Breach Notification
If your personal information is acquired by, or disclosed to, an unauthorized person, we will notify you and the relevant regulators as required by law.
- Health data (FTC Health Breach Notification Rule). MinervaOS is a health app that is not covered by HIPAA — we are not a healthcare provider, health plan, or clearinghouse, and your use of the Service creates no doctor-patient relationship. Health apps in that position are covered by the FTC Health Breach Notification Rule (16 C.F.R. Part 318). If there is an unauthorized acquisition of your identifiable health information, we will notify you and the Federal Trade Commission without unreasonable delay and in no case later than 60 calendar days after discovery, and, where an incident affects 500 or more people, we will also notify prominent media as the Rule requires. Notice will describe what happened, what information was involved, what we are doing, and what you can do.
- California (Civ. Code §§1798.29, 1798.82). We will notify affected California residents in the most expedient time possible and without unreasonable delay, in the form the statute requires.
- Other states and the EEA/UK. We will meet the equivalent obligations that apply where you live, including notifying a supervisory authority within 72 hours where the UK/EU GDPR requires it.
Report a suspected vulnerability or unauthorized access to support@minervaos.app. We do not pursue legal action against good-faith security researchers who report privately and give us a reasonable time to fix an issue.
20. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, in-app or by updating the "Last updated" date) and, where required, obtain your consent. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.
21. Contact Us
Questions or requests regarding this Privacy Policy or your data: support@minervaos.app
Brizo Finance LLC, operator of MinervaOS. Because we operate exclusively online and have a direct relationship with you, email is our designated method for submitting privacy requests, as the CCPA permits. We respond to verifiable requests within 45 days, extendable once by a further 45 days where the law allows, and we will tell you if we need the extension.