Draft — pending legal review. This page is not final.

Consumer Health Data Privacy Policy

Effective [EFFECTIVE DATE] · Policy version 2026-09

This policy covers the health information you give A1cMealPrep. It's written for Washington's My Health My Data Act, Nevada's SB 370 and Connecticut's consumer health data rules, and we give the same rights to everyone in the United States.

It goes with our Privacy Policy, which covers everything else. A1cMealPrep is published by Nodogames, LLC ("we", "us"), [LEGAL ADDRESS OF NODOGAMES, LLC]. We aren't a doctor, a hospital or a health plan, so HIPAA doesn't apply to us.

What we collect, and why

A1cMealPrep is built for people with prediabetes and type 2 diabetes. Because of that, we treat the categories below as consumer health data. We collect them only after you sign in and turn on "Plan with my health info".

CategoryExamplesWhy we collect it
Health conditions Prediabetes, type 2 diabetes without insulin, or cooking for someone who has it To pick your starting carb range and the safety rules that apply to you.
Medicines you tell us about The type, such as metformin, a GLP-1 medicine, an SGLT2 inhibitor or a sulfonylurea. Never doses. To show low blood sugar warnings and to keep plans from going below safe carb limits. We never suggest medicine or insulin doses.
Health goals Steadier sugar after meals, a lower A1C, losing weight, eating healthier To shape your plan.
Allergies and dietary needs Allergies, foods you don't eat, food style (for example vegetarian, halal or kosher) To keep those foods out of your plans and recipes.
Carb range Your grams of carbs per meal and per snack To build meals that fit it.
Plans, shopping list, ratings and favourites Meals in your recent plans and the carb range they were built for, prep tasks you tick, your shopping list (items, amounts, ticks and pantry check), meals you liked or disliked, favourite recipes To keep your plans and list on your account, so they come back on another phone, and to make the next plan better. They can point to your health status, so we treat them as health data.
Account and subscription details Your account ID, email address (with Google, also your name and profile picture link), an encrypted Sign in with Apple token if you use Apple, and whether you subscribe To run your account. Using a diabetes meal planner can suggest a health condition, so we treat these as linked to health data.

We don't collect precise location, blood sugar readings or Apple Health data. Usage data (anonymous counts from everyone, and usage linked to your account only if you turn on "Help improve the app") is designed to hold no health data.

Where it comes from

  • You, when you answer the questions in the app and change your settings.
  • Your phone's region setting, which fills in your country and state for you to confirm.
  • Apple, when you sign in with Apple (an account ID and, if you share it, your email address).
  • Google, when you sign in with Google (an account ID, your email address, your name and a link to your profile picture).
  • Apple and RevenueCat, for whether you have a subscription.

We don't get consumer health data from other apps, data brokers or your doctor.

How we use it

  • To build and save your meal plans, swaps and recipes.
  • To apply safety rules, such as low blood sugar warnings.
  • To run your account and subscription, and to answer your support requests.
  • To keep the service secure and to meet legal obligations.

We don't use consumer health data for advertising, and we don't sell it. We don't use it to track you across other companies' apps or websites. We don't geofence, and we don't collect precise location at all.

Who we share it with

We share consumer health data only with the companies below, which work for us as processors. They can use it only to provide their service to us. We don't share consumer health data with any other third party, and we have no affiliates that receive it. [TO CONFIRM: no affiliates]

Third partyCategoryWhat it may receive
Supabase Database and login provider All of the categories above, stored for your account.
Railway Server hosting provider Requests that pass through our API server. We don't log request bodies.
Anthropic AI provider Only if you turn on "Share with our AI provider": the meal type, carb range, time limit, food style, allergies and foods you don't eat. Never your name, email, account ID, medicines or condition.
RevenueCat Subscription provider Your account ID and subscription status.

We may also disclose data when the law requires it, or in a sale or merger of our business, where the buyer must honour this policy.

We ask before we collect your health information and before we share it, in separate choices:

  • Plan with my health info lets us collect and store it.
  • Share with our AI provider lets us send the recipe brief described above.

Both start off. You can take back either one at any time in the app, in Me → Privacy & data. Withdrawing "Plan with my health info" stops syncing and deletes the consumer health data we hold: the health details, food style and foods you don't eat in your profile, and your plans, shopping list, ratings and favourites. Your settings (household size, budget, time per meal, cooking style, region and units) aren't health data and stay with your account. We don't sell consumer health data, so we never ask you to authorize a sale.

Your rights, and how to use them

You can:

  • Confirm and access. Ask whether we collect or share your consumer health data, and get a copy, including a list of the third parties we share it with and how to contact them.
  • Withdraw consent. In the app: Me → Privacy & data.
  • Delete it. In the app: Me → Privacy & data → Delete my account. That removes your plans, shopping list, ratings, favourites, settings and health info from our servers and your phone. We also ask our processors to delete it. Backups that still hold it are overwritten on our provider's normal schedule, and always within six months. It doesn't cancel your subscription, which Apple bills. Cancel it first in Settings → Apple Account → Subscriptions.
  • Correct it. Edit your answers in the Me tab.

To make a request the app doesn't cover, email support@a1cmealprep.com with the subject "Consumer health data request". We don't ask for your name, so tell us the email address on your Apple sign-in, which may be an Apple relay address. We may ask you to confirm it's you.

We reply within 45 days. If we need more time, we can take up to 45 more days, and we'll tell you why. If we turn down a request, we'll explain. You can appeal by replying with "Appeal" in the subject line, and we'll answer within 45 days. If you still disagree, you can contact your state attorney general: Washington, Nevada or Connecticut.

Security and how long we keep it

We protect consumer health data with encrypted connections, a database that only our server can read, and limits on who at Nodogames can see it. We keep it until you delete your account. Our Privacy Policy has the details.

Changes and contact

If we change this policy, we'll update the date at the top. If a change affects how we collect or share consumer health data, we'll ask for your consent again first.

Nodogames, LLC
[LEGAL ADDRESS OF NODOGAMES, LLC]
Privacy officer: [PRIVACY OFFICER NAME]
Email: support@a1cmealprep.com