Consumer Health Data Privacy Policy
Effective date: August 7, 2026
SJL Craig LLC (“BareVue,” “we,” “us,” or “our”) provides the BareVue mobile application, the barevue.app website, and related support services. This Consumer Health Data Privacy Policy describes how BareVue collects, uses, and shares consumer health data through those services and how a consumer may exercise the rights provided by the Washington My Health My Data Act.
This notice is separate from BareVue’s general Privacy Policy and is limited to consumer health data and the disclosures required by that Act.
When this notice describes an action performed by the account holder, the same data practice applies if an authorized adult household member operates that account and performs the action. Authorized operators may have access to the consumer health data available through the shared account.
1. Consumer Health Data Collected and How It Is Used
Depending on the features you choose to use, BareVue can collect the following categories of consumer health data:
| Category | Examples | Purposes |
|---|---|---|
| Profile and demographic information | Profile identifier, profile name, birth date or age, sex, height, activity level, allergies, and dietary restrictions | Create and distinguish profiles; calculate and display age-, sex-, activity-, and diet-related nutrition information; maintain account and profile continuity |
| Body measurements and goals | Weight, body composition, height, measurements, weight goals, and related trends | Record and display measurements, calculate trends and targets, and generate reports requested by the account holder |
| Nutrition and dietary information | Food and water logs, nutrient intake, nutrition and macro targets, meal timing, food or product searches, barcode and recent scan history, OCR or label results, recipes, supplements, saved meals, custom foods, and meal settings | Provide food logging, nutrition analysis, product and ingredient matching, meal and recipe features, configured targets, and reports |
| Reproductive information | Pregnancy, lactation, trimester, and menstrual information | Adjust applicable nutrition standards, display reproductive-state context, and provide requested tracking features |
| Symptoms and related observations | Symptoms, bowel movements, stress, sleep, food-mood entries, elimination protocols, slips, reintroduction state, and notes | Provide the symptom, food-mood, and elimination-diet records and comparisons requested by the account holder |
| Derived health and nutrition information | Nutrition-standard results, adaptive energy estimates, nutrient totals, trends, correlations, summaries, guidance, and report calculations derived from information entered into BareVue | Produce the calculations, comparisons, guidance, and reports requested through BareVue |
| Local reminder information | Reminder enabled state, schedule, timezone, sound, semantic kind, and task-related notification copy | Schedule and reconcile optional device-local reminders requested by an authorized account operator |
| Linked identifiers | BareVue account identifier, persistent profile identifier, account-to-profile association, timestamps, and record identifiers associated with the categories above, including when an authorized adult account operator creates a profile for another person | Keep records associated with the correct account and profile, resolve nutrition standards, provide optional synchronization and restoration, and process authenticated rights or deletion requests |
Most of these records are stored and processed on the device by default. Limited profile information is processed by BareVue’s nutrition-standard service even when optional cloud sync is off. If an authorized account operator enables eligible cloud sync, the selected profile, nutrition, health, recipe, and preference records are also processed in BareVue’s cloud systems to provide synchronization and restoration.
Recent-scan history and settings for locally scheduled reminders are stored on the device. The scan history can be cleared in the app.
2. Sources of Consumer Health Data
BareVue collects consumer health data from:
- the adult account holder or another authorized adult operating the account, including information entered for the account holder or a dependent profile;
- activity within BareVue, such as food logging, searching, scanning, OCR, measurement, symptom, food-mood, elimination-diet, recipe, supplement, notification, reminder, and report actions;
- calculations and inferences BareVue produces from information entered into the app, such as nutrition standards, nutrient totals, trends, targets, and adaptive energy results;
- records restored from the account holder’s optional BareVue cloud sync or an account holder-selected backup;
- BareVue-operated catalog and search services, and the public product-data sources those services consult, when the account holder requests a product search, barcode lookup, or related catalog result;
- an account holder-selected website or file source when the account holder directs Recipe Import or file restoration; and
- information a person chooses to include in a support or privacy message to BareVue.
3. Consumer Health Data Shared
The following verified technical flows can make the consumer-health categories listed above available outside the device:
- persistent profile identifier, birth date, sex, requested nutrition standard, and applicable pregnancy, lactation, or trimester state are sent to BareVue’s nutrition-standard service;
- profile, demographic, measurement, nutrition, food-log, reproductive, symptom, food-mood, elimination-diet, recipe, supplement, derived-result, and linked-record information is sent to BareVue’s cloud service when eligible cloud sync is enabled;
- local BareVue data can be included in an Apple or Google device backup when the account holder enables the applicable operating-system backup;
- selected health and nutrition information is provided to a destination chosen by the account holder when the account holder exports, backs up, shares, prints, or saves that information;
- a website selected for Recipe Import receives the requested recipe URL and ordinary network information. Recipe information saved into BareVue then follows the local-storage and optional-sync choices above; and
- health information a person chooses to include in an email exchange with BareVue is transmitted through that person’s email service and BareVue’s email provider.
BareVue does not intentionally supply profile information, food logs, symptoms, reproductive information, searches, scans, or other entered content to advertising systems for ad targeting. The configured ad unit does identify the broad reward category, but a shared-access request does not include the internal feature that led to it.
Transfers to Supabase for nutrition-standard resolution, eligible Sync, restoration, deletion, and related account services are made to a processor acting under BareVue’s instructions and are not treated as statutory sharing.
Depending on the feature and destination selected by the account holder, BareVue can share these categories of consumer health data:
- profile, demographic, measurement, nutrition, food-log, reproductive, symptom, food-mood, elimination-diet, recipe, supplement, derived-result, reminder, and linked-record information included in an Apple or Google operating-system backup or device transfer;
- any of those categories the account holder selects for an export, encrypted backup, share, print, email, file-provider, or other destination;
- a Recipe Import URL and ordinary request information when the URL or request itself identifies health or nutrition activity; and
- health or nutrition information a person chooses to include in a support or privacy email exchange.
Information that does not qualify as consumer health data is not included in this statutory list merely because it is processed by a nutrition app.
4. Third Parties and Affiliates
Current recipients that can process the consumer health data described above are:
| Recipient category | Current recipient | Purpose |
|---|---|---|
| BareVue cloud and database processor | Supabase, including authorized subprocessors used under its Data Processing Addendum | Nutrition-standard processing, optional synchronization and restoration, authenticated deletion, and related account services |
| Operating-system backup provider selected by the account holder | Apple or Google | Device backup or device transfer controlled through the account holder’s platform settings |
| Destination selected by the account holder | A file provider, email service, share destination, printer, or other selected application | Complete an export, backup, share, print, or save action requested by the account holder |
| Website selected by the account holder | The website entered for Recipe Import and any host it uses for requested recipe content | Deliver the recipe page or image requested by the account holder |
| BareVue communications provider | BareVue’s email provider | Deliver a support or privacy message to or from BareVue |
| Independently selected email service | The person’s email service | Deliver a support or privacy message the person chooses to send or receive |
Subject to the feature used and whether the transferred information qualifies as consumer health data, the categories of third parties with whom BareVue shares consumer health data are:
- an Apple or Google operating-system backup or device-transfer provider selected through the account holder’s platform settings;
- a file provider, email service, share destination, printer, or other destination selected by the account holder;
- a website and its content host selected by the account holder for Recipe Import; and
- the person’s independently selected email service when the person sends or receives a support or privacy message containing consumer health data.
Supabase, including authorized subprocessors used under its Data Processing Addendum, is treated as a processor for the stated BareVue services. Other contracted infrastructure or communications providers are treated as processors rather than third parties only when they act on BareVue’s instructions under the required contract for the stated purpose.
SJL Craig LLC has no corporate affiliates and therefore does not share consumer health data with an affiliate. If BareVue’s corporate structure changes, this notice will be reviewed before any such sharing begins.
5. Consumer Health Data Rights
Subject to the Washington My Health My Data Act, a consumer may:
- ask whether BareVue is collecting, sharing, or selling consumer health data concerning the consumer and request access to that data;
- request a list of the third parties and affiliates with whom that consumer health data was shared or sold, together with an available way to contact them;
- withdraw consent from future collection or sharing when the processing depends on consent; and
- request deletion of consumer health data concerning the consumer.
Signed-in account holders can use BareVue’s in-app account-deletion control. To submit another consumer-health-data request, email privacy@barevue.app and describe the request and the BareVue account or other interaction involved. An account-linked request will ordinarily be authenticated through the same Apple or Google sign-in used for that account. BareVue will not require a person to create a new account solely to make a request.
If ordinary sign-in is unavailable, BareVue may request only the minimum additional information reasonably necessary to authenticate the request. If BareVue cannot authenticate the request using commercially reasonable efforts, BareVue may decline to act and will provide the explanation and appeal route required by law.
BareVue will respond without undue delay and ordinarily within 45 days after receiving the request. When reasonably necessary, BareVue may extend that period once by another 45 days and will explain the extension during the first 45-day period. Information supplied in response to a request is free up to twice per year, except where the law permits a reasonable charge or refusal for a manifestly unfounded, excessive, or repetitive request.
When a verified deletion request applies, BareVue will delete the covered consumer health data from BareVue-controlled systems and notify the applicable affiliates, processors, contractors, and other third parties as required by law. Deletion from BareVue-controlled archived or backup systems may be delayed, but not longer than six months after the request is authenticated. Copies controlled independently by the account holder or a destination the account holder selected may require deletion through that destination.
If BareVue refuses a request, the consumer may appeal by emailing
privacy@barevue.app with Privacy Appeal in the subject line. BareVue will
respond to the appeal in writing within 45 days. If the appeal is denied,
BareVue will provide a method for contacting the Washington Attorney General
to submit a complaint.
6. Changes to This Consumer Health Data Privacy Policy
Before BareVue collects, uses, or shares an additional category of consumer health data, or uses consumer health data for an additional purpose, BareVue will update this Consumer Health Data Privacy Policy and obtain affirmative consent when required by the Washington My Health My Data Act.