Consumer Health Data Policy
Last updated 17 September 2026
Food Feel is not a doctor, a clinic or a health plan, so HIPAA does not apply to it. We treat what you log as sensitive health data anyway, because that is what it is.
Awaiting legal review. This document accurately describes how the product works today, and it was written by the people who built it rather than by a lawyer. It has not yet been reviewed by counsel and must be before Food Feel launches commercially. Consumer health privacy law reaches well beyond HIPAA, and several U.S. states regulate this category specifically.
Why this document exists separately
HIPAA covers healthcare providers, health plans and their business associates. A consumer app that somebody uses on their own is generally none of those, which surprises people. And is exactly why a second category of law now exists. Several U.S. states, Washington’s My Health My Data Act among them, regulate “consumer health data” held by companies like this one, with their own consent, disclosure and deletion requirements.
Rather than rely on not being covered, this document sets out how Food Feel handles that data. The privacy policy covers everything else.
What counts as consumer health data here
- Which foods, drinks and pills you rated, and how difficult each felt.
- The experience statements you selected. Coughing, pain, something feeling stuck, feeling afraid.
- Where in your body you reported feeling something, and when.
- Anything you typed in your own words on a profile or a meal log.
- Your meal logs, including outcomes, symptoms, amounts and Practice Mode ratings.
- Which education topics you opened, since that can imply something about you.
Why we collect it
To show you your own profile, to let you track and compare over time, and to suggest which educational topic might be relevant. That is the whole list. We do not collect it to build a marketing profile, to target advertising, to train a model, or to sell.
Consent, kept separate
Three consents exist in this product and none of them implies another:
- Creating an account. Your email address is how you sign in. This is not consent to marketing, and it never sets one.
- Education email. An unticked box with the exact sentence you are agreeing to shown next to it. We store which version of that sentence you saw and when.
- The Food Feel Plus early-access list. A separate list for a separate purpose, with its own consent.
You can withdraw any of these without affecting the others, and withdrawing marketing consent unsubscribes you for real rather than only flipping a flag.
Sharing
We do not sell consumer health data. We do not share it with advertising networks, data brokers or analytics companies, and no advertising or third-party tracking script is loaded on any page of this product.
The only third parties involved at all are the infrastructure needed to run the service: the hosting provider, the managed database, and the email service that delivers your sign-in codes and anything you asked for. They process data on our instructions and do not get it for their own purposes.
Your profile is never sent to a clinician or clinic by us. If you want somebody to see it, you export it and send it yourself.
Your rights
- Access. Download everything we hold about you, as a file, from your settings.
- Deletion. Erase all of it and close your account, from your settings. No grace period, not recoverable.
- Withdraw consent. Turn off education email at any time, from settings or from any email.
- Use Food Feel without an account at all. The profile and the full result work with nothing stored on our servers.
Depending on where you live you may have further rights, including a right to a list of who your data has been shared with. Ours is short and is above.
How it is protected
- Every table holding your data has row-level security, scoped to your account. A query cannot return somebody else's rows even if application code asked it to.
- The key the browser holds is a public, restricted key. The privileged key exists only on the server and is never sent to a browser.
- Free text cannot enter the analytics pipeline: every event property is validated against a fixed list of allowed values on the server, so a modified browser cannot smuggle anything in.
- Encrypted in transit; encrypted at rest and in backups by the platform.
- No IP addresses and no user agents are stored with analytics events.
How long we keep it
Your profiles and meal logs stay until you delete them. The point of the product is comparing today with three months ago. De-identified analytics events are retained in aggregate for product measurement. Deleting your account detaches your analytics rows from you, leaving only counts that were never attached to an identity in the first place.
If something goes wrong
If there is a breach affecting your data, we will notify affected people and the relevant authorities as required, and say plainly what happened and what it means. Our incident procedure is documented in the repository at docs/PRIVACY_SECURITY.md.
Contact
Questions about this policy, or a request about your data, go to the address on the contact page.