BareVue
FAQAboutJoin the waitlist
Features
Nutrient TrackingAdaptive TDEEFamily trackingElimination dietPregnancyFood-MoodSupplements
Learn
AboutFAQResearch & sources
Privacy

Privacy Policy

Effective date: August 7, 2026

SJL Craig LLC (“BareVue,” “we,” “us,” or “our”) provides the BareVue mobile application, the barevue.app website, support, and related services. This Privacy Policy explains what information those services handle, why they use it, where it may go, how long it may remain, and the choices available to you.

This general policy covers the mobile app, the website and support services, and product-contribution services, which have different data practices described separately below. BareVue also maintains separate consumer-health- data notices for disclosures and rights required by Washington and Nevada law.

1. The Short Version

  • BareVue is local-first. Most profile, nutrition, health, recipe, supplement, symptom, and logging information is stored on your device by default. It may be included in an Apple or Google device backup, depending on your platform and device-backup settings.

  • Some features and app services require information to leave your device, including account authentication, nutrition-standard calculations, catalog searches, optional cloud sync, subscriptions, security checks, analytics, crash reporting, rewarded advertising, Recipe Import, and voluntary product contributions.

  • Cloud sync is optional. Turning it off stops future ordinary synchronization but does not automatically delete information already stored in BareVue’s cloud systems.

  • BareVue does not send the health information, food logs, symptoms, dependent-profile information, pregnancy information, searches, scans, or other content you enter in the app to advertising systems for ad targeting. A rewarded-ad request can identify the broad category of benefit requested, but BareVue does not attach the more specific feature or activity that led to the request.

  • The app provides separate controls for optional sync, Usage Analytics, crash reporting, and Google privacy choices where applicable.

  • Files you export, share, print, or back up through another provider are then also governed by the destination you selected.

2. Who May Hold a BareVue Account

BareVue accounts are intended for people who are at least 18 years old. Every person who directly creates, accesses, or operates an account must be at least 18. BareVue is not intended for children to operate accounts. Before beginning Apple or Google sign-in to create or access an account, the person operating the device must confirm that they are at least 18, agree to the Terms of Use, and acknowledge this Privacy Policy.

An account holder may authorize another adult member of the same household to operate the account on another supported device. An authorized adult operator may be able to view, add, change, export, or delete information available through that account, including information for its profiles. The account holder remains responsible for deciding who receives access and should share account access only with adults they trust.

An adult account holder may create and manage dependent profiles for people of any age. The account holder controls the information stored for those profiles.

Dependent-profile information is provided and managed through the adult account holder rather than collected directly from the dependent. Requests concerning that information are handled through the adult account holder, subject to any verification of identity or authority required by law.

3. Information BareVue Handles

Account and authentication information

BareVue uses Apple or Google sign-in and Supabase authentication. Depending on the provider and information available, this can include:

  • your email address;
  • your name and profile image;
  • the provider’s account identifier;
  • a BareVue account identifier;
  • authentication tokens and session information; and
  • ordinary security and request information such as IP address, device or browser information, and sign-in events.

BareVue uses this information to create and secure your account, keep accounts separate, support account deletion, and provide authenticated services.

To document acceptance, BareVue records the BareVue account identifier, the Apple or Google account identifier and/or verified email associated with the acceptance, the selected country and language, the applicable legal-document and confirmation versions, and the server-recorded time. BareVue uses this limited record to identify the acceptance when reasonably needed for a verified privacy or legal matter and establish which documents and confirmations applied.

This record is separate from advertising and Usage Analytics choices. It does not contain profile, health, nutrition, food-log, payment, advertising, or device-tracking content.

Profiles, nutrition, and health-related information

Information you choose to store can include:

  • profile names, birth dates or ages, sex, height, and activity level;
  • weight, body composition, and related measurements;
  • nutrition targets, food logs, nutrient intake, recipes, and supplements;
  • pregnancy, lactation, menstrual, and reproductive information;
  • symptoms, bowel movements, food-mood entries, and elimination-diet records;
  • preferences and display settings; and
  • information about dependent profiles managed by the adult account holder.

Core logging and profile information is stored in the app’s local database by default. BareVue uses it to provide the features you request, personalize nutrition calculations and displays, generate reports, and maintain your local records.

Camera, barcode, and OCR information

Barcode scanning, nutrition-label recognition, and contribution-photo capture use the device camera only when you initiate those features. Camera frames, barcode recognition, and OCR text are processed on the device for ordinary scanning and label-capture workflows. A contribution photo leaves the device only if you choose to submit the contribution described in Section 9.

BareVue does not currently access precise device location, contacts, Apple HealthKit, Google Health Connect, or body-sensor data.

On Android, Google Play Services may download machine-learning models needed for barcode or text recognition. Google states that ML Kit processes input images and text on-device and does not send that input or its results to Google servers. The SDK can still collect technical data such as device and app information, identifiers, performance metrics, API configuration, input and output size, feature events, and error codes for diagnostics and usage analytics.

Device and application information

BareVue and its service providers can process information such as:

  • device type, operating-system version, app version, build, and language;
  • installation or app-instance identifiers;
  • session, performance, diagnostic, and crash information;
  • network information and IP-derived approximate region; and
  • security and app-integrity signals.

The exact information depends on the feature and provider described below.

4. Local Storage, Optional Sync, and Device Backups

Local-first storage

Most BareVue records remain in a database and preferences on your device. Local information generally remains until you delete the relevant entry or profile, delete or replace the app’s data, uninstall the app in a way that removes its data, or restore an older operating-system backup.

Recent barcode scan history is stored in device preferences. It is scoped to the app installation rather than a particular BareVue account, so it can remain after sign-out or an account change until you clear the relevant scan history or remove the app’s data.

Product and recipe images loaded from BareVue or another source can remain in an on-device cache until the cache is automatically evicted or the app’s data is removed.

Optional cloud sync

Eligible subscribers may choose to synchronize selected account, profile, nutrition, health, recipe, and preference information through Supabase. BareVue uses this information to provide cross-device continuity and restoration.

Turning sync off pauses ordinary future synchronization. It does not automatically delete information that has already been synchronized. Deleting the relevant profile or BareVue account is a separate action.

Apple and Google device backups

Depending on your platform and device-backup settings, Apple or Google may include BareVue’s primary local database and preferences in a device backup. BareVue configures which app files are eligible, but BareVue does not receive, open, or control your Apple or Google device-backup account.

Deleting information from BareVue does not guarantee immediate deletion from an older operating-system backup. A later restoration can restore information that was present when that backup was created.

5. Feature-Specific Network Processing

Nutrition standards

When BareVue must resolve a nutrition standard, it sends only the bounded profile characteristics needed for that calculation to BareVue’s Supabase-hosted policy service. These include a persistent profile identifier, birth date, sex, the requested standard, and pregnancy, lactation, or trimester information when applicable.

BareVue maintains a limited server-side DRI profile record containing the account and profile identifiers, birth date, sex, timestamps, and whether the birth date has previously been corrected. This record is separate from optional cloud sync. It lets the service consistently resolve age- and sex-specific targets and enforce the profile birth-date correction rule. It does not contain the person’s food log.

Catalog searches and product lookups

Catalog and search requests can include the search text or barcode, market, language or locale, authentication information, app version, and sometimes an app-integrity check. BareVue, Cloudflare, Typesense, Open Food Facts, and the relevant catalog source may process those requests.

Search and catalog services do not receive the active profile’s health history or food log merely because a search is performed. Images and informational content can be loaded from BareVue or the source provider that hosts them.

Recipe Import

When you provide a recipe URL, your device contacts that website to download the page you requested. The website receives ordinary network information, including your IP address and a user agent. BareVue can store the source URL with the imported recipe and can later load an image supplied by that website. The external website controls its own logs and privacy practices.

Security and app integrity

BareVue uses Apple App Attest or Google Play Integrity for selected security- sensitive operations. Apple or Google receives app and device integrity material, and BareVue receives a verification result tied to the protected request. BareVue does not put profile, food-log, symptom, reproductive, OCR, barcode, or search content in those integrity requests.

6. Usage Analytics and Crash Reporting

BareVue treats Usage Analytics and Crash Reporting as separate services and provides a separate Settings control for each one.

Usage Analytics

BareVue uses Firebase Analytics to understand which screens and workflows are used and whether fixed outcomes or failures occur. BareVue uses that information to improve the app’s design and reliability. Its own analytics events use predetermined screen, workflow, outcome, and failure-category labels. BareVue does not intentionally include account identifiers, profile identifiers, food logs, health records, symptoms, pregnancy information, searches, barcode values, OCR text, or other user-entered content in those events.

Firebase still processes pseudonymous app-instance, device, app, session, approximate-geography, app-open, and related technical information. This data is pseudonymous, not anonymous.

Before starting Usage Analytics, BareVue waits for Google’s configured regional privacy process to determine whether Analytics may run. Where applicable rules require neither a consent choice nor a separate BareVue opt-in, Usage Analytics is enabled by default. Where consent or another affirmative choice is required, it begins only after that choice. Under BareVue’s planned South Korean route, Usage Analytics starts off and requires a separate Korean opt-in even when Google’s process reports that its Consent Mode choice is not applicable. If any required decision is unavailable, Usage Analytics remains off for that session. You can turn Usage Analytics off separately in BareVue Settings.

Crash Reporting

BareVue uses Firebase Crashlytics to diagnose crashes and serious application errors. A crash report can include a stack trace, app and device information, an installation identifier, and technical state related to the failure. BareVue’s app-controlled nonfatal reports use predetermined operation and failure labels. Its app-controlled Dart and Flutter fatal reports replace the original exception object and message with a fixed source and failure category while retaining the technical stack trace. BareVue does not intentionally attach user-entered health content. Provider-controlled native crash handling can still produce exception, minidump, stack, and related technical information.

Crash Reporting is enabled by default. You can disable it separately in BareVue Settings. Google documents an approximately 90-day service-retention window for Crashlytics reports, minidumps, and associated identifiers before deletion from live and backup systems begins.

7. Rewarded Advertising and Google Privacy Choices

BareVue may request and prepare a rewarded ad in advance for an eligible free account so it is available when needed. BareVue displays the ad only after you choose the Watch Ad action to unlock a specified feature or operation.

Google Mobile Ads, Google’s User Messaging Platform, and authorized advertising buyers can process advertising and device information such as:

  • IP address and IP-derived approximate location;
  • device, operating-system, app, and language information;
  • the configured rewarded-ad unit, which identifies the broad category of benefit requested;
  • on Android, the resettable advertising ID when available, an App Set ID that can recognize apps published by BareVue on that device, and other device or account identifiers that Google says may apply;
  • a Google-generated identifier scoped to BareVue’s apps, which can recognize activity within BareVue but is not an identifier shared across unrelated publishers’ apps;
  • ad requests, impressions, interactions, diagnostics, and fraud signals; and
  • the consent or privacy-choice state managed by Google where applicable.

BareVue does not request Apple’s App Tracking Transparency permission and does not use IDFA-based tracking. BareVue also keeps Firebase-to-AdMob Analytics enrichment and Google User Insight Surveys disabled.

Where no applicable consent choice is required, Google may personalize ads using the advertising information available to it. Where consent is required, personalization begins only after the required consent. After refusal, BareVue requests non-personalized or otherwise limited ads where permitted. When Google requires a Privacy Options entry, BareVue provides access to Google’s form in Settings.

Google can distinguish the broad category of benefit requested from the configured ad unit. BareVue does not attach the more specific feature or activity that led to the request. BareVue also does not attach the nutrition, health, pregnancy, dependent-profile, food-log, symptom, search, barcode, OCR, or other content you enter in BareVue for ad targeting.

To confirm that an ad earned a reward, Google sends BareVue a signed confirmation tied to an opaque reward-attempt identifier. BareVue retains the verified reward evidence for approximately 24 to under 48 hours. It does not include your email address, advertising identifier, profile, nutrition, or health content.

8. Subscriptions and Purchases

BareVue uses RevenueCat and the Apple App Store or Google Play to offer and manage subscriptions. Apple or Google processes the payment method used for the purchase. BareVue and RevenueCat receive the purchase and subscription information needed to manage access, which can include:

  • a RevenueCat customer identifier linked to the BareVue account identifier;
  • store product, transaction, receipt, subscription, and entitlement information;
  • device, app, and operating-system information; and
  • IP-derived country or region.

BareVue receives entitlement information needed to provide subscription features. Apple, Google, and RevenueCat control their own payment and transaction records. BareVue and RevenueCat do not receive the payment-method credentials, such as a card number or security code, that you provide to the store.

9. Voluntary Product Contributions

When you voluntarily submit a food or supplement product contribution, BareVue can receive:

  • your authenticated account identifier and session;
  • product name, brand, barcode, category, country, market, language, claims, ingredients, and other label text;
  • app version and build information;
  • front-label, ingredient, nutrition, supplement-facts, or other label images; and
  • the applicable photo or submission acknowledgement.

BareVue does not include your private profile, food log, symptoms, pregnancy information, dependent-profile information, or nutrition history merely because you submit a product contribution.

BareVue may retain and use submitted product information and images to review submissions, prevent abuse, improve and maintain product databases, and publish information in BareVue or third-party product databases. Catalog information derived from a contribution may remain independently of your account, including after account deletion.

Food contributions can be forwarded to Open Food Facts with a stable pseudonymous contributor identifier derived from the BareVue account identifier. BareVue currently uses temporary Cloudflare queue and object storage for that delivery and makes a best-effort attempt to delete the temporary job after successful delivery. Open Food Facts controls information after it receives and publishes it.

Supplement contributions are retained by BareVue and Cloudflare for moderation and possible inclusion in BareVue’s product databases.

Contributions are final within BareVue’s product workflow. After submission, BareVue does not provide an in-app tool to edit or withdraw a contribution. Separate contributor terms govern the rights BareVue receives to use, modify, publish, distribute, sublicense, and incorporate contributed content. This product rule does not limit privacy rights that apply under applicable law.

10. Website and Support

Website operation

BareVue uses Cloudflare to deliver and protect barevue.app. Cloudflare can process ordinary request, browser, device, network, and security information. The website’s normal assets and typefaces are self-hosted.

BareVue uses Cloudflare Web Analytics to understand which pages are visited and how the website performs. It is cookieless and does not track people across websites.

Messages to BareVue

If you contact BareVue, we receive your email address, message, and anything else you choose to provide. BareVue uses it to respond, support the service, and maintain appropriate business records. Support messages are kept only as long as reasonably necessary to answer the request and maintain those records.

11. Notifications and Reminders

BareVue can schedule optional reminders locally on your device. A local reminder is scheduled after you enable the applicable reminder and grant any required notification permission. Its settings, schedule, and pending request are handled by the app and your device’s notification system.

Reminder text can identify the feature or task involved and can be visible on your lock screen according to your device notification settings. You can manage controls BareVue makes available for a reminder and can disable notification delivery through your operating-system settings.

If BareVue introduces remote notifications, it may use Apple or Google notification services to deliver account, security, service, product- operation, or optional promotional messages. Remote delivery may require a notification token, a limited account-or-installation association, delivery metadata, and the notification payload. Apple or Google processes that information to deliver the notification to the device.

If BareVue offers user-created reminders, the text, schedule, timezone, enabled state, and any applicable profile association may be stored on the device and may be included in Cloud Sync when that capability supports it and you enable Sync. If you choose remote delivery for a custom notification, its payload may include the text you wrote. Notification information stored by BareVue follows the retention and deletion rules in Sections 15 and 16.

BareVue will use promotional notifications only after a separate opt-in and will provide an in-app way to opt out of them. Other available notification controls may be provided in BareVue, and operating-system settings can disable all notification delivery.

12. Backups, Reports, Exports, Sharing, and Printing

When you choose Export Backup, BareVue creates an encrypted .barevuebackup file on your device and sends it only to the destination you select. BareVue can also create data exports and PDF reports containing sensitive profile, nutrition, or health information on your device and send them only to the location, app, printer, or person you select.

BareVue’s .barevuebackup files are encrypted. To restore one, the app uses BareVue’s authenticated backup-key service. Because BareVue operates the key service needed for restoration, these backups are not designed so that only you can decrypt them.

Other exports and PDF reports are not necessarily encrypted by BareVue. Their protection depends on the destination, app, account, or person you choose.

PDF generation currently downloads font resources from Google. Google receives ordinary network and request information for the font download, not the contents of the report.

Once you export, share, print, upload, or save a file elsewhere, that copy is controlled by you and the selected destination. Deleting the corresponding information from BareVue does not delete independent copies held by another app, person, printer, cloud-storage provider, email service, or operating-system backup.

13. Service Providers and Other Recipients

Depending on the features you use, BareVue works with:

Recipient Purpose
Supabase and its infrastructure providers Authentication, optional sync, nutrition standards, security records, backup-key service, account deletion, reward verification, and subscription entitlement mirroring
Cloudflare Website delivery and protection, Workers, catalog services, contribution processing, queues, object storage, and related security
Apple Sign in with Apple, App Attest, App Store purchases, and user-controlled device backup
Google Google sign-in, Play Integrity, Google Play purchases and model delivery, Firebase Analytics, Crashlytics, Mobile Ads/UMP, PDF font delivery, BareVue support and privacy email delivery, and user-controlled device backup
RevenueCat Subscription products, receipts, customer identity, and entitlements
Typesense Catalog and reference search
Open Food Facts Product lookups, images, and current public food-contribution destination
A website you provide for Recipe Import Downloading the recipe page and related image you requested
A destination you select Exports, backups, PDF reports, sharing, printing, email, files, or other user-directed transfers

Some recipients process information to provide a service to BareVue. Other recipients—such as app stores, a website requested for Recipe Import, Open Food Facts, and destinations you select—can act independently for parts of their processing and apply their own terms and privacy controls.

BareVue can also disclose information when required by law or when reasonably necessary to protect BareVue, its users, or others; investigate abuse or security incidents; enforce applicable agreements; or establish, exercise, or defend legal claims.

14. Legal Bases Where Applicable

Where applicable law requires BareVue to identify a legal basis, BareVue relies on the following bases for the purposes described in this Policy. The same category of information can be processed under different bases when it is used for separate purposes.

  • Providing the service and performing BareVue’s agreement with you. BareVue processes information when it is objectively necessary to create or operate an account; provide the profile, nutrition, wellness, calculation, subscription, reward, and support services you request; perform an import, export, sharing, or other action you select; or provide optional Cloud Sync after you enable it.
  • Consent. BareVue relies on consent where required for specified activities, including processing health, reproductive, or other sensitive information; Usage Analytics; personalized advertising and related device-storage or access; and optional promotional communications. Consent applies only to the stated purpose. Agreement to the Terms, acknowledgement of this Policy, Google privacy choices, BareVue’s Usage Analytics preference, and any other consent control are separate and do not substitute for one another.
  • Legitimate interests. BareVue can process information as reasonably necessary to secure and operate the service; prevent, detect, and investigate fraud, abuse, or security incidents; diagnose crashes and reliability problems; provide and proportionately measure the website; moderate contributions; maintain appropriate acceptance, transaction, and security records; and establish, exercise, or defend BareVue’s rights. BareVue relies on this basis only where those interests are not overridden by the person’s rights and interests.
  • Compliance with law. BareVue processes information when necessary to comply with applicable law, respond to valid legal process or privacy-rights requests, and maintain records required by law.

Where EU or UK law treats health, reproductive, or related information as special-category data, BareVue relies on explicit consent for the core service. BareVue obtains separate consent for optional purposes when applicable law requires it. Without the core-service consent, BareVue cannot provide the core service. If that consent is later withdrawn, BareVue can no longer provide the core service; Section 16 describes the available export and account-deletion path. When special-category information is genuinely necessary to establish, exercise, or defend a legal claim, BareVue can instead rely on the legal-claims condition for that limited purpose.

Swiss law uses a different legal framework. Where Swiss law applies, BareVue relies, as applicable, on the overriding private interest connected with providing the service you request, consent where required, compliance with law, and the establishment, exercise, or defense of legal claims.

The legal basis can affect the privacy rights available to you. Section 16 describes those rights and how to exercise them.

15. Retention

BareVue retains different information according to the feature and purpose:

Information Retention or deletion boundary
Local app records Until the applicable entry, profile, account, app-data, or device-backup boundary described above
Information synchronized to Supabase Until the applicable profile or account deletion process; turning sync off does not delete information already synchronized
Previously synchronized profile information Removed through the profile-deletion process even when ordinary sync is off
Ordinary hosted account-owned records Deleted with the hosted account except where a record follows a separately disclosed security, fraud-prevention, transaction, backup, or legal retention boundary; provider-managed technical logs and backups follow their own schedules
Deleted-account marker The former BareVue account identifier and deletion time remain for the life of the service; the marker contains no profile, health, nutrition, or food-log information
Legal acceptance record The limited document/confirmation record and its provider identifier and/or verified email are retained while the account exists and, after the deleted-account marker records deletion, for six years before a private scheduled purge. Six years is BareVue’s chosen evidentiary period, not a claimed universal legal requirement
Verified rewarded-ad evidence Approximately 24 to under 48 hours
Firebase Usage Analytics event and user data BareVue’s Firebase property is currently configured for two-month event and user-data retention; aggregate reporting and provider backup behavior can follow different boundaries
Crashlytics reports Google currently documents an approximately 90-day service window for reports, minidumps, and associated identifiers
Support and privacy messages As long as reasonably necessary to answer the request, maintain appropriate business records, resolve disputes, or meet applicable legal obligations; the email provider can retain copies under its service settings
Contribution-derived catalog information May remain independently of the contributor’s account; temporary failed-job and raw moderation-source records are retained only as long as reasonably needed to process, review, retry, secure, or document the contribution
Subscription, purchase, security, integrity, search, and infrastructure records For as long as reasonably needed to provide or verify the requested service, protect the service, satisfy transaction or legal requirements, or follow the applicable provider’s settings
Copies sent to another destination or included in an operating-system backup Controlled by that destination or platform under its own settings and retention practices

16. Deletion, Choices, and Privacy Rights

Controls available in BareVue

Depending on the feature, you can:

  • edit or delete individual entries;
  • delete a profile;
  • export applicable information;
  • turn optional cloud sync off;
  • separately disable Usage Analytics and Crash Reporting;
  • use Google advertising privacy choices where Google makes them available;
  • delete the hosted BareVue account through the app.

Where an applicable country route uses a separate sensitive-data consent to provide BareVue’s core service, withdrawing consent means BareVue can no longer provide the service. BareVue offers an optional data export before final confirmation. Confirming Withdraw consent and delete account uses the hosted-account deletion process described below; it does not leave the account in a stale nutrient-standard or reduced-function mode.

Deleting a profile removes that profile’s information from the device where deletion is requested and, if it was previously synchronized, from BareVue’s cloud systems. This deletion is handled even if ordinary cloud sync is turned off.

Deleting the hosted BareVue account removes the authentication account and ordinary account-owned hosted information. BareVue signs the deleted account out on the device where deletion is requested. Its local database remains inaccessible while signed out and is erased before a different account is allowed to begin using that app installation.

Some limited records or copies can remain, including:

  • a private deleted-account marker retained for the life of the service so BareVue can recognize a previously deleted account when later handling local information associated with it;
  • app-integrity, fraud-prevention, reward-verification, transaction, managed- log, and backup records;
  • the limited legal-acceptance record, including the Apple or Google account identifier and/or verified email used to locate it, retained for six years after account deletion;
  • operating-system backups and user-selected exports or shared copies;
  • vendor-controlled purchase, analytics, crash, infrastructure, or security records; and
  • catalog information derived from a final contribution or information already delivered to an external public product database.

Contribution submission does not include a BareVue edit or withdrawal mechanism. Requests involving account-linked contribution metadata will be handled as required by applicable law, but do not necessarily remove catalog information that is no longer linked to the account or copies controlled by an external recipient.

Rights that may apply

Depending on where you live and which law applies, you may have rights to:

  • know about or access certain personal information;
  • correct inaccurate personal information;
  • request deletion;
  • receive a portable copy;
  • restrict or object to certain processing;
  • withdraw consent where processing depends on consent;
  • opt out of certain targeted advertising, sale, or sharing;
  • appeal a denied request; and
  • complain to an applicable regulator.

These rights are not identical in every jurisdiction and can be subject to identity verification and lawful exceptions. BareVue may retain information when required or permitted for security, fraud prevention, legal compliance, transactions, free expression, public information, or legal claims.

Signed-in account holders can use BareVue’s in-app account-deletion control. To make another privacy request, contact privacy@barevue.app and identify the BareVue account or other interaction involved. For an account-linked request, BareVue will ordinarily verify control through the same Apple or Google sign-in used for that account.

If that sign-in is unavailable, BareVue may request only the minimum additional information reasonably needed to authenticate the request. BareVue will not use food logs, weight, pregnancy, dependent-profile information, or other health details as identity-verification questions, and routine requests will not require government-issued identification. If BareVue cannot reasonably authenticate a request, it may decline the request and will provide the explanation or appeal route required by applicable law. An authorized representative may be required to provide proof of authority and, where permitted, confirmation from the account holder.

17. Security

BareVue uses technical and organizational safeguards intended to protect information, including authenticated access, account isolation, row-level database controls, encrypted network connections for BareVue-owned APIs, encrypted backup files, app-integrity checks, bounded reward evidence, and restricted service access.

No method of storage or transmission is completely secure. Websites and other destinations selected by the user control their own copies, and BareVue depends on service providers whose systems and retention are not controlled solely by BareVue.

18. International Processing

BareVue and its providers can process information in the United States and other countries. Supabase-hosted BareVue services currently use a United States region, Cloudflare operates a global edge network, and the other providers and user-selected destinations described above can process information outside your country.

The privacy and data-protection laws in those locations can differ from those where you live.

Where applicable law requires a transfer mechanism, BareVue relies on recognized safeguards for its service-provider relationships. Depending on the provider and transfer, these can include an adequacy decision, an applicable data-privacy framework, or contractual safeguards such as the European Commission’s Standard Contractual Clauses and the United Kingdom’s approved transfer addendum.

Some recipients, including advertising, identity, store, and user-selected services, can determine their own purposes and apply their own privacy and international-transfer terms.

19. Changes to This Policy

BareVue may update this Privacy Policy when features, providers, legal requirements, or data practices change. The policy will show its effective date.

If a change materially affects how BareVue handles information, BareVue will provide any notice or renewed choice required by applicable law.

20. Contact

For questions or privacy requests, contact:

SJL Craig LLC

Email: privacy@barevue.app

If applicable law gives you a right to appeal BareVue’s response, email privacy@barevue.app with Privacy Appeal in the subject line. BareVue’s response will also explain any appeal method required by applicable law.

Related documents

  • Terms of Use
  • Privacy Policy
  • Washington Consumer Health Data Privacy Policy
  • Nevada Consumer Health Data Privacy Notice
  • Account deletion

© 2026 SJL Craig LLC. All rights reserved.

FAQAboutSupportResearchWebsite & Waitlist PrivacyLegal & IP
Terms of UseApp PrivacyWashington Health Data PrivacyNevada Health Data PrivacyAccount Deletion