Privacy Policy
Effective date: August 18, 2026
MindSomo ("the app," "we," "us") is a personal wellness app for mindful eating and behavioral awareness, including optional GLP-1 medication support. This policy explains what we collect, why, and what control you have over it.
What we collect
Account information. Your email address, used only to authenticate you (via Supabase Auth). We don't require your real name, and any display name or profile photo you add is optional.
What you log. Everything you enter into the app is stored so the app can show it back to you — that's the whole point of a tracking app. This includes:
- Meals and their nutrition information (manually entered, searched, or scanned)
- Journal entries
- Habit check-ins and streaks
- Mindful/breathing session records
- Hunger, fullness, and (if you use GLP-1 support) medication-adjacent self-reports — hunger, nausea, energy, hydration, cravings, and whether you met your protein goal
- If you enable GLP-1 support: your medication name, dose, and schedule, entered by you — the app never verifies or advises on this information (see the in-app disclaimer on the GLP-1 check-in screen)
- App preferences (focus mode, recovery-safe display settings, etc.)
What we don't collect. We don't access your contacts, your location, your photo library, or any data from other apps. We don't sell data, and we don't show ads.
The camera. The app asks for camera access for one purpose: reading a barcode on food packaging. The camera feed is used to decode the barcode number and nothing else. No photograph is taken, stored, or transmitted.
Crash and error reporting
If crash reporting is enabled for a release, the app uses Sentry to report crashes and errors so they can be diagnosed and fixed. Sentry receives technical diagnostic data only: the error and stack trace, the app version, and the device model and OS version. It does not receive your journal entries, meals, medication records, or any other content you enter.
Sentry acts as a data processor under our instruction. See Sentry's privacy policy for their own commitments. A crash report can, in principle, contain fragments of technical state, so this is disclosed as a data flow even though no content is sent deliberately.
Performance traces are sampled at 20% of sessions. Crash reporting is disabled entirely in development builds, and is off unless a reporting key is configured for the release.
Why we collect it
Solely to run the app for you: to show your logged history, compute your weekly progress, award XP, and personalize what you see (for example, hiding calorie numbers if you've turned on recovery-safe mode). We do not use your data to train AI models, and we do not share it with advertisers.
Who else sees it
- Supabase (our database and authentication provider) hosts your data. They act as a data processor under our instruction — see [Supabase's privacy policy](https://supabase.com/privacy) for their own commitments.
- FatSecret provides the nutrition database. When you search for a food or scan a barcode, your search term or barcode is sent to FatSecret via our own server — FatSecret never receives your account identity, your other logged data, or any way to link your search back to you.
- We do not share your data with any other third party, and we do not sell it.
Security
Every table that stores your personal data has row-level security enabled at the database level — the technical effect is that no one (including us, through the app's normal client access) can read or write another user's rows through the app. This is independently tested; see docs/02-security-rules.md in the project repository for the specifics, or ask us for the current test results.
No API keys or credentials that could access your data are ever included in the app itself.
Your rights
- Access: everything you've logged is visible to you in the app at any time.
- Correction: edit or delete individual entries (meals, journal entries, habits) directly in the app.
- Deletion: Settings → Delete my account permanently removes your account and every row of data associated with it. This cannot be undone and there is no recovery window: no backups are retained, so there is nothing to restore from (see Data retention below).
- Portability: [describe export mechanism if/when built — not yet available as of this draft].
Data retention
We keep your data for as long as your account exists. If you delete your account, your personal data is removed from our active database immediately and permanently. No automated backups or point-in-time recovery snapshots are retained, so no copy survives the deletion.
Children
MindSomo is not directed at children and is not intended for use by anyone under 16.
Health data note
MindSomo is a personal wellness and self-tracking tool. It is not a covered entity under HIPAA, is not a medical device, and does not provide medical advice. Information you enter about GLP-1 medications, symptoms, or eating patterns is for your own reference only — always consult a qualified healthcare provider for medical decisions.
Changes to this policy
If this policy changes materially, we'll notify you in the app before the change takes effect.
Contact
Questions about this policy or your data: hello@mindsomo.com