Legal

Privacy Policy

Last updated: August 17, 2026

This Privacy Policy explains how Brizo Finance LLC, the operator of MinervaOS ("MinervaOS," "we," "us," or "our") collects, uses, shares, and protects information when you use the MinervaOS iPhone application and related services (the "Service"). By using the Service, you agree to this Privacy Policy. Capitalized terms not defined here have the meaning given in our Terms of Service.

Our commitments, in plain terms: We do not sell your personal information. We do not use it for third-party or cross-app advertising. We do not track you across other companies' apps or websites. We use no analytics, advertising, or tracking SDKs. Data we read from Apple Health is used on your device to compute your estimates; the raw samples are not sent to our servers, and the only derived figures that reach them are the ones you choose to share — a logged workout, or the daily step count and calorie burn you switch on for followers (Section 2b). Cloud wearables you connect through our wearable-connection provider (Junction) are different: their data does reach our servers, because that is how it gets to your phone. It is stored for your account alone, kept on a rolling 35-day window, deleted when you delete your account, and never sold or used for advertising (Section 2b).

If you are a California resident, please also see Section 13 (Your California Privacy Rights), which includes the disclosures required by the CCPA/CPRA and CalOPPA.

If you live in Virginia, Colorado, Connecticut, Texas, Oregon, or another U.S. state with a comprehensive privacy law, see Section 14 (Other U.S. State Privacy Rights) — including how to appeal if we refuse a request.

If you are a resident of Washington, Nevada, or another state with a consumer health data law, our separate Consumer Health Data Privacy Policy also applies to your health data and controls where it is more specific.

What changed on August 17, 2026. Three corrections so this Policy matches the app. Section 2b now says exactly which Apple Health-derived figures can reach our servers: none of the raw samples, but a workout you import becomes a logged workout, and while Workouts (on by default), Burned, or Eaten is on under What followers see — or when you share a daily summary to a group or your feed — the day's step count and calorie-burn figures are stored so the people you allow to see your profile can see them. Section 6 now lists the five follower switches as they exist in the app. Section 2c now discloses the crash and performance diagnostics (Apple's MetricKit reports) the app sends us when it crashes or hangs, and corrects the microphone sentence: a video you record for a post or group chat is stored with its audio track. Nothing about selling or advertising changed: we still do neither.

What changed on August 8, 2026. Corrections so this Policy describes what the Service actually does. Section 2b now sets out what happens to data from the cloud wearable platforms you connect through our wearable-connection provider, Junction: those platforms deliver it to our servers, where it is stored for your account alone on a rolling 35-day window and deleted when you delete your account. Junction is named as a processor in Sections 7 and 13.3, and the list of platforms you can connect is brought up to date. Sections 6a and 7 now state that our first-pass moderation classifier (OpenAI) reads images and sampled video frames as well as text, so photos and video you publish to a social surface are transmitted to it. Our separate Consumer Health Data Privacy Policy was corrected the same way. Nothing about selling or advertising changed: we still do neither.

What changed on July 30, 2026. We added retention periods for each category of data (Section 9.1), a breach-notification commitment including the FTC Health Breach Notification Rule (Section 19), rights and an appeals route for U.S. states beyond California (Section 14), default protections for users under 18 (Section 15.2), and a fuller account of how AI is used and what we do not do with it (Section 4). Nothing about what we collect, or our commitment never to sell it, changed.


1. Who We Are

MinervaOS is a nutrition, fitness, and wellness tracking app for iPhone. The business responsible for your information (the "data controller") is Brizo Finance LLC, contactable at support@minervaos.app.

2. Information We Collect

a. Information you provide

b. Health and wearable data

c. Information collected automatically

d. Purchase information

If you buy a subscription, the purchase is processed by Apple. We receive your subscription/entitlement status from Apple; we do not receive your full payment-card details.

e. Information from third parties

If you sign in with Apple (or another provider we may offer), that provider gives us a token confirming your identity and, if you allow it, your name and email.

3. How We Use Information

We use information to: provide, operate, and secure the Service and your account; generate your estimates, targets, and AI outputs (calorie/macro/micronutrient estimates, calorie-burn and metabolism calculations, food recognition, and suggestions); sync and back up the data you log; operate Group features you choose to use; deliver notifications and reminders you enable; look up products you scan by barcode; provide support; prevent fraud and abuse and enforce our Terms; comply with legal obligations; and maintain and improve the Service. We do not use your health data, food photos, or personal content to serve advertisements, and we do not sell this information.

4. AI Processing and Third-Party AI Provider

4.1 What is sent, and to whom

To provide AI features, content you submit is transmitted through our backend to a third-party AI provider (Anthropic) via its API and processed to return a result to you. This includes: food/label photos and any description or correction you add; body-composition report images you upload (DEXA/InBody/smart-scale); and text you send to the AI assistant (and recent conversation turns). We instruct our AI provider to process this content only to return results to you and not to use it to train its models, consistent with its API terms. We do not retain your food-scan or report photos on our servers; a copy of a food-scan photo is kept on your device so you can review or edit the entry. If you prefer not to use AI photo analysis, you can enter foods manually instead.

Your name and email address are not included in what we send to the AI provider.

4.2 You are interacting with AI, not a person

Every AI feature in the Service — the assistant, food recognition, report parsing, and the suggestions and estimates they produce — is automated software, not a human being and not a licensed professional. We label AI features as such in the app. No AI output is reviewed by a clinician before you see it. This disclosure is made so that you are never misled into thinking you are communicating with a person, consistent with California Business & Professions Code §22601 et seq., California Health & Safety Code §1339.75 et seq., and Article 50 of the EU AI Act.

4.3 We do not train AI models on your data

We are a deployer of general-purpose AI models, not a developer of them. We do not build, train, fine-tune, or substantially modify generative AI models, and we do not use your content — food logs, photos, messages, health data, or group content — as training data for any model, ours or anyone else's. Because we do not develop or substantially modify a generative AI system, the training-data documentation duty in California AB 2013 falls on the model developers whose systems we call, not on us; their disclosures are published by those developers.

4.4 AI content provenance (California AI Transparency Act, SB 942)

California's AI Transparency Act imposes duties (a public AI-detection tool and provenance marking of AI-generated content) on "covered providers" — generative AI systems with more than one million monthly users in California. MinervaOS is below that threshold and is not currently a covered provider. We do not generate synthetic images, audio, or video for publication; our AI outputs are numeric estimates and short text shown to you. If we cross that threshold or begin producing synthetic media, we will implement the required provenance disclosures and update this Policy before doing so.

4.5 Safety limits on AI outputs

Our AI assistant is a nutrition and fitness tracking tool. It is not a companion, a therapist, or a crisis service. It is instructed to refuse to provide extreme-restriction, purging, or other disordered-eating guidance, and to surface crisis resources rather than engage when a conversation indicates risk of self-harm or an eating disorder. You can reach those resources at any time in the app under Settings → Safety & Crisis Resources. If you are in immediate danger, contact your local emergency number; in the US you can call or text 988 (Suicide & Crisis Lifeline), and the National Alliance for Eating Disorders helpline is 1-866-662-1235.

5. Barcode Lookup

When you scan a product barcode, the barcode number is sent to Open Food Facts (a third-party open food database) to look up product and nutrition information. Only the barcode is sent for this lookup; no account information is included.

6. Group and Social Features

Social features are optional. Groups: the content you share to a group — posts, messages, photos you attach, comments, and reactions — is stored on our backend and is visible to the other members of that group. Follows and public profiles: your profile is private by default. If you make it public, your posts, display name, username, bio, and avatar are visible to any signed-in user, and anyone may follow you; if it stays private, followers you approve see only what your follower-visibility settings allow. Those settings (Profile → Privacy & sharing → What followers see) are five switches, each governing one line of your profile panel for today and the past week: Workouts (on by default — the sessions you logged, plus the day's step count and resting burn), Burned (the day's total burn), Eaten (calories and macros against your targets), Meals (the list of what you ate), and Weight trend (the direction only, never a number, with progress photos as a separate switch). Personal records are shared by default and can be switched off. Everything other than Workouts and personal records is off until you turn it on. Your handle appears in user search unless you turn off discoverability in Settings. Group chat photo attachments are stored in a private storage area accessible to that group's members; your profile avatar is stored in a storage area readable by other signed-in users so they can display it, so avoid using a photo you wish to keep private. You can block users and report content; blocks and reports are stored to operate those features and for safety.

6a. Content Moderation

Because the Service carries user-generated content, we screen it. This is a condition of using the social features, and it is not optional for content you post.

What we screen. Everything you post or send through a social surface — group messages, posts and captions, comments, group names and descriptions, usernames and display names — passes the automated word/pattern check that runs on our own servers, and any of it can be reported and reviewed by us. The classifiers described below read the subset that is public or widely visible: posts and their captions, comments, usernames and display names, profile avatars, and the images and video uploaded to those surfaces. What you send inside an invite-only group — chat messages, the workouts and meals you share there, and the photos you attach — is a closed room between people who chose each other, so no classifier reads it; reporting, blocking, suspension and the word/pattern check all still apply. We do not apply any of this to your private food logs, weights, workouts, notes, Apple Health data, or connected-wearable records — those are not published to anyone and are never sent to a moderation classifier.

How. In layers. First, an automated word/pattern check that runs on our own servers as content is written. Second, where it is enabled, a fast first-pass classifier operated by OpenAI (its moderation endpoint, which OpenAI states is not used to train its models). That pass reads text and images: the text you wrote, and — for a photo, an avatar, or a video — the image itself, sent to OpenAI as the picture, not as a description of it. When that pass is not enabled, the next layer does all of the work. Third, for nuanced cases and for all images and video, an automated classifier run by Anthropic (Claude). Content a classifier cannot assess, and any content another user reports, is queued for review by an authorized human reviewer on our team.

What that means for your data. The content itself — the text, the image, or sampled frames of the video — is transmitted to both of those providers for the sole purpose of classification: photos you post, photos attached to a public surface, your profile avatar, and frames sampled from a video you upload all leave our servers as images, not as descriptions of images. Photos sent inside a private group room are the exception described above — registered, but not read by a classifier unless someone reports them. The providers act as our processors under contracts limiting their use of the content. Uploaded images and video are held and not shown to anyone but you until they pass this check.

What we keep. The verdict (approved / rejected), the category, and a timestamp, attached to the content. Reports you file and reports filed about you, and any enforcement action taken on your account, are retained as described in Section 9. Where content is unlawful we retain what the law requires us to retain and report it to the appropriate authority; apparent child sexual abuse material is reported to the National Center for Missing & Exploited Children (NCMEC).

Your rights. If content of yours is removed or your account is restricted, you can appeal to support@minervaos.app (Terms, Section 9.4). Decisions are supported by human review, not made by automated processing alone where that would carry legal or similarly significant effects for you.

7. How We Share Information

We share information only as described here, and we do not sell it or share it for cross-context behavioral advertising:

8. Legal Bases (EEA/UK Users)

If you are in the EEA or UK, we process your personal data on these bases: performance of a contract (to provide the Service you request); consent (for health data, Apple Health/wearable access, AI photo processing, and notifications — withdrawable anytime); legitimate interests (to secure, maintain, and improve the Service, balanced against your rights); and legal obligation. Health data is "special category" data, processed based on your explicit consent.

9. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account (Section 12), we delete your account and associated personal data from our active systems; residual copies may persist for a limited period in backups and server logs before being overwritten. Content you shared into a Group may remain visible to that group in de-identified form after your account is deleted.

9.1 Retention period by category

As required by the CCPA, this is how long we keep each category, or the criteria we use to decide:

Safety and moderation records are an exception. Reports (filed by you or about you), moderation verdicts, and enforcement actions such as suspensions and bans are retained for up to two years after the account is closed, and longer where a legal obligation or an ongoing investigation requires it. We keep them because deleting them would let a banned user return by re-registering, and because they are the record that shows we acted on reports. They are kept separately from your account data and are not used for any other purpose.

10. Security

We use reasonable technical and organizational measures designed to protect your information, including encryption in transit, row-level access controls that scope your data to your account, secure Keychain storage for tokens on your device, and reputable infrastructure providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Protect your credentials and notify us of any suspected unauthorized access.

11. Data Sent Off Your Device vs. Kept On It

For transparency: kept on your device (not on our servers) — the raw Apple Health data streams, WHOOP data, app preferences, and a local copy of your food-scan photos. Sent to and stored on our servers — your account, profile (including health/body values you enter), food/workout logs (including workouts imported from Apple Health), the daily step count and calorie-burn figures you turn on for followers (Section 2b), group content, avatars, push tokens, crash and performance diagnostics (Section 2c), cloud wearable data from platforms you connect via Junction (Section 2b, 35-day window), and a backup of your weight-log history, saved meals and workouts, and custom targets and exercises (see below). Sent for processing but not stored by us — food/report photos and AI-assistant text (to our AI provider) and barcodes (to Open Food Facts).

Backup of the data you enter. So you don't lose your information if you reinstall the app or switch to a new device, we back up your weight-log history, saved meals and workouts, and custom nutrition targets and exercises to our servers, associated with your account. This backup contains only information you enter in the app; it does not include Apple Health or wearable data. It is accessible only to you, is never sold or shared, and is deleted when you delete your account (Section 12).

12. Your Choices and Rights

13. Your California Privacy Rights

This section provides the disclosures required by the California Consumer Privacy Act, as amended by the CPRA ("CCPA"), and the California Online Privacy Protection Act ("CalOPPA"), and applies to California residents.

13.1 Categories of personal information we collect

In the past 12 months we have collected the following CCPA categories (with examples). We collect these from you, your device, and services you connect (Apple Health/wearables, Sign in with Apple):

13.2 Sensitive personal information (SPI)

We collect the following SPI: account log-in credentials (email with password) and health information (the body metrics, nutrition, and fitness data you provide and log). We use and disclose SPI only for purposes permitted under the CCPA — namely to provide the Service you request and as otherwise allowed without a right to limit (e.g. security, preventing fraud, and ensuring the Service works). We do not use SPI to infer characteristics about you for any purpose other than providing the Service. Because we do not use or disclose SPI beyond these permitted purposes, the CCPA "right to limit" does not change how we handle it.

13.3 Purposes, sources, and disclosures

We collect each category to provide, secure, personalize, and improve the Service, as described in Sections 3–7. Sources are described in 13.1. We disclose personal information for these business purposes to our service providers — our hosting/database/storage provider (Supabase); our AI provider (Anthropic); our first-pass moderation classifier provider (OpenAI), which receives the text, images and sampled video frames you publish to a social surface; our wearable-connection provider (Junction), which receives and delivers to us the data from the cloud wearable platforms you connect (Section 2b); our email provider (Resend), which carries moderation reports to our review team; Apple (sign-in, subscriptions, and push); and Open Food Facts (barcode lookup) — and to other group members for content you choose to share.

13.4 No sale or sharing

We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the preceding 12 months. We do not sell or share the personal information of minors.

13.5 Your California rights

Subject to verification and legal exceptions, you have the right to: know/access the personal information we have collected about you; delete it; correct inaccurate information; opt out of sale/sharing (we do neither); limit the use of sensitive personal information (we already restrict it to permitted purposes); and not be discriminated or retaliated against for exercising your rights.

13.6 How to exercise your rights

You can exercise most rights directly in the app (edit your data, or Settings → Account → Delete Account), or contact us at support@minervaos.app. We will verify your request using information associated with your account. You may use an authorized agent to submit a request on your behalf with proof of authorization. We will respond within the timeframes required by law.

13.7 "Shine the Light"

California Civil Code §1798.83 lets California residents request information about disclosures of personal information to third parties for their direct marketing. We do not share personal information with third parties for their own direct marketing.

13.8 Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. Because we do not track users across third-party websites or apps and do not permit third parties to do so through the Service, we do not need to respond differently to DNT signals; our practice is not to track you regardless of any DNT setting.

13.9 Opt-out preference signals (Global Privacy Control)

Some browsers and extensions send an opt-out preference signal such as Global Privacy Control (GPC). Because we do not sell personal information and do not share it for cross-context behavioral advertising, there is no sale or sharing for a GPC signal to stop. We treat any GPC signal we receive on minervaos.app as a valid request to opt out anyway, and we honor it. Our website sets no advertising or analytics cookies and contains no third-party trackers, so nothing on it is disclosed to a third party for advertising purposes in the first place.

13.10 Notice at Collection

The disclosures in this Section 13, together with Sections 2, 3, 7 and 9, are our notice at collection. You see a short-form version of it in the app before you provide any health information — on the "Before you start" screen at first launch, which identifies the categories we collect (including the sensitive categories in 13.2), the purposes, that we do not sell or share, and the retention periods in Section 9.1, and links to this full Policy. You can reopen it at any time from Settings → Privacy.

13.11 Retention

We disclose the retention period for each category of personal information, including sensitive personal information, in Section 9.1. We do not keep personal information for longer than is reasonably necessary for the purpose for which it was collected.

13.12 Financial incentives

We do not offer any financial incentive, price difference, or service-level difference in exchange for the retention, sale, or sharing of your personal information.

14. Other U.S. State Privacy Rights

If you live in a U.S. state with a comprehensive consumer privacy law — currently including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, as those laws come into force — this section describes rights you have in addition to anything above. Where your state's law gives you more than we describe, your state's law wins.

14.1 Your rights

Subject to verification and the exceptions each statute allows, you may:

14.2 Sensitive data requires your consent

Most of these laws treat health data as sensitive, and require opt-in consent before it is processed. Your consent is the affirmative agreement you give on the "Before you start" screen at first launch, and separately at the iOS permission prompt before we read anything from Apple Health or a connected wearable. You can withdraw it at any time by revoking the permission in iOS Settings or deleting your account, and withdrawal is as easy as giving it.

14.3 How to exercise them

Use the in-app controls (Settings → Account → Delete Account, or edit your data directly), or email support@minervaos.app. We will verify the request against the email on your account. We respond within 45 days, extendable once where the law allows, and we will tell you if we need the extension.

You may use an authorized agent. We will ask for proof that you gave them permission.

14.4 Appeals

If we refuse your request, you can appeal. Reply to our decision, or email support@minervaos.app with "APPEAL" in the subject line. A person who was not involved in the original decision will review it, and we will respond in writing within 45 days (60 in some states), explaining the reasoning either way.

If we deny the appeal, you may complain to your state's Attorney General. We will tell you how to do that in the appeal response, because several of these laws require us to.

14.5 No discrimination

We will not deny you the Service, charge you a different price, or give you a worse experience because you exercised any of these rights.

15. Children and Teens

15.1 Under 13

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The date-of-birth control in the app does not accept a date that would make you younger than 13, and you must confirm you are at least 13 to pass the first-run gate. If you believe a child under 13 has provided us personal information, contact support@minervaos.app and we will delete the account and its data promptly, without requiring you to create an account to make the request. We do not condition any part of the Service on a child disclosing more information than is reasonably necessary.

15.2 Teens 13–17

Users between 13 and 17 may use the Service, and where the age of majority or digital-consent age in their jurisdiction is higher, only with the involvement and consent of a parent or guardian. For any account whose date of birth indicates the user is under 18, we apply the following by default, without the teen or their parent having to find a setting:

Parents and guardians may contact support@minervaos.app to review, correct, or delete a teen's information, or to close the account.

15.3 Why this app may not be right for a minor

Calorie and weight tracking is not appropriate for everyone, and can be actively harmful for a young person with, or at risk of, disordered eating. We say so in the app and in our Terms, and we encourage parents to make that judgement with their child and a professional.

16. International Data Transfers

We and our service providers may process and store your information in the United States and other countries whose data-protection laws may differ from yours. Where required, we use appropriate safeguards for international transfers. By using the Service, you understand your information may be transferred to and processed in these countries.

17. Apple Health Data — Specific Commitments

Consistent with Apple's requirements: we will not use Apple Health (HealthKit) data for advertising or marketing; we will not sell it or share it with third parties for advertising, marketing, data-mining, or similar purposes; we will not disclose it to third parties without your authorization except as needed to provide a health service you requested; and we use it only to provide health, fitness, and wellness features within the Service. As noted in Section 2b, Apple Health data is processed on your device and the raw samples are not transmitted to our servers; the only derived figures that reach them — an imported workout, and the daily step count and calorie burn you switch on for followers — are disclosed to other users only with your authorization, given by turning those switches on, and you can turn them off at any time.

17a. California Confidentiality of Medical Information Act

To the extent any information you store in MinervaOS — such as lab values, thyroid or blood-panel results, or body-composition reports you enter or import — constitutes "medical information" under the California Confidentiality of Medical Information Act (California Civil Code §56 et seq.), we maintain it in a manner that preserves its confidentiality, do not disclose it except as authorized by you or as permitted by that Act, and apply the same protections to it as to all your health data under this Policy. We do not use it for advertising or marketing and we do not sell it.

18. Third-Party Services

The Service integrates with and links to third-party services (Apple, our infrastructure/AI providers, wearable platforms, and Open Food Facts). Their handling of your information is governed by their own privacy policies, which we encourage you to review. We are not responsible for third parties' practices.

19. Security Incidents and Breach Notification

If your personal information is acquired by, or disclosed to, an unauthorized person, we will notify you and the relevant regulators as required by law.

Report a suspected vulnerability or unauthorized access to support@minervaos.app. We do not pursue legal action against good-faith security researchers who report privately and give us a reasonable time to fix an issue.

20. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, in-app or by updating the "Last updated" date) and, where required, obtain your consent. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.

21. Contact Us

Questions or requests regarding this Privacy Policy or your data: support@minervaos.app

Brizo Finance LLC, operator of MinervaOS. Because we operate exclusively online and have a direct relationship with you, email is our designated method for submitting privacy requests, as the CCPA permits. We respond to verifiable requests within 45 days, extendable once by a further 45 days where the law allows, and we will tell you if we need the extension.