Privacy Policy
Pippa exists to support eating-disorder recovery. That only works if you can trust us with some of the most sensitive information there is. This policy explains exactly what we collect, why, who can see it, how long we keep it, and the controls you have. The short version: your health data is used only to run the service, is shared only with clinicians you approve, is never sold, is never used for advertising, and is never used to train AI models.
Because nearly everything Pippa handles relates to your health, we also publish a separate Consumer Health Data Privacy Policy that describes our handling of consumer health data in the form some state laws (such as Washington's My Health My Data Act and Nevada's consumer health data law) require. The two documents are consistent; if they ever conflict, the one giving you stronger protection controls.
1. What We Collect
| Data | What it includes | Why |
|---|---|---|
| Account | Email address, sign-in method (email, Sign in with Apple, or Google), date of birth (from the age screen) | Creating and securing your account; age-appropriate consent flow |
| Profile | Weight, height, birthday, gender; optional blind weight check-ins on the cadence your clinician sets | Personalizing your daily eating rhythm and the chart your care team sees |
| Meal logs | Meal photos, the food name and calorie estimate generated from them, the meal time (which you can edit), and your answers to post-meal check-in questions, including any questions your clinician configures | The core of the service: logging meals and tracking consistency |
| Meal plan & grocery list | The meal plan you or your clinician set up, and your shared grocery list | Planning support you and your care team edit together |
| Mood & check-ins | Mood entries and notes, daily check-in answers, and responses to any questionnaires your clinician assigns | Mood support features and, with your consent, care-team visibility |
| Chat with Pippa | Your recent chat messages, a rolling summary the app keeps so Pippa remembers context, and automated safety flags when a message suggests a crisis | Making the chat useful across sessions and keeping you safe; see the Safety page |
| Care-team messages | Messages between you and clinicians you've approved, including messages they send you | Direct communication with your care team |
| Consent records | Terms acceptance (who signed, when, version), guardian consent for teen accounts, data-sharing agreements with clinicians | Legal records of the permissions you've granted |
| In-app rewards | Coins, showing-up streaks, and the cosmetic items you've collected | Keeping your buddy and room in sync across your devices |
| Subscription status | Whether your account has an active premium subscription, verified through Apple | Unlocking premium features. Apple processes payment; we never see your card details |
| Device & usage | Device identifier, push notification token, time zone, app-open times, app settings | Sync, notifications delivered at times that make sense where you are, and timing reminders when they actually help |
What stays on your device only
Your journal is private to your device. Journal entries are stored locally and are never uploaded, synced, or visible to anyone, including your care team and us. If you ask Pippa to reflect on a journal entry, the text is processed once to generate the reflection and is not stored on our servers. Sticker collections and similar keepsakes also stay local.
Photos and metadata
Meal photos are re-encoded on your device before upload, which removes embedded metadata including location (EXIF/GPS). When you import a photo from your library, the app reads the photo's capture date on your device to suggest the meal time; that metadata itself is not uploaded. We perform no facial recognition or biometric processing on any image, ever. We do not collect your precise location.
2. What We Never Do
- We never sell your data, health data or otherwise.
- We never show you ads or share your data with advertisers or data brokers.
- We put no third-party advertising or analytics trackers in the app.
- We never use your data to train AI models. Our AI provider processes your content only to generate responses and, under our API agreement, does not use it for training. We never use children's or teens' data for AI training, and would never use anyone's data for AI training without a separate, optional opt-in.
- We never make your weight or trends visible to anyone except you and the care team you approved.
- We never change this policy retroactively: a new use of already-collected data requires your fresh consent, not just an updated document.
3. Who Can See Your Data
- You.
- Clinicians you approve. A clinician sees your detailed data only after a data-sharing agreement is signed, and you can sever it anytime in Settings; access stops immediately. Every clinician read of your data is written to an audit log. When you're enrolled through a treatment provider, Pippa acts as a service provider (HIPAA business associate) to that provider.
- Safety escalation. If the app detects signs of a crisis (for example in chat), it may alert the clinician you've consented to share with. If you haven't approved a clinician, no one is alerted; the app shows you crisis resources directly. See the Safety page.
- Legal requirements. We disclose data if validly required by law, and we limit any such disclosure to what is required.
Service providers that help us run Pippa
These companies process data only on our instructions to operate the service. None of them may use your data for their own purposes such as advertising or AI training:
| Provider | What they do for us |
|---|---|
| OpenAI | Generates chat responses, meal-photo food and calorie estimates, and safety-moderation checks. Content is processed through their API, which is not used to train their models. |
| Amazon Web Services | Database, sign-in infrastructure, and transactional email (for example guardian consent links and clinician alerts) |
| Cloudflare | Application server and meal-photo storage |
| Apple | Push notifications, Sign in with Apple, and App Store subscription billing |
| Push notifications on Android and Google Sign-In | |
| Stripe | Billing for clinics and institutions only; Stripe never receives patient health data |
We have no affiliates, and we share consumer health data with no third parties other than the service providers above and the clinicians you approve.
4. How Long We Keep It (Retention Policy)
- While your account is active: we keep your data so the service works. We keep only what the service needs; we don't warehouse data "just in case."
- When you delete your account: your care team is notified immediately and loses access; the account can no longer sign in; all your data (photos, logs, moods, chats, messages, plans, profile) is permanently erased from our systems within 30 days. Backup copies age out on our standard rotation schedule.
- What we must keep: a minimal record of consent grants/revocations, the deletion request itself, and clinician-access audit logs, retained approximately six years as required by law, keyed to an internal identifier rather than your name or email.
- Children's and teens' data is kept only as long as reasonably necessary for the specific purpose it was collected for, never indefinitely.
5. Children and Teens
- Under 13: Pippa does not accept accounts from children under 13, except through a participating treatment provider under a verifiable-parental-consent program (if and when offered). If we learn we have collected personal information from a child under 13 without verifiable parental consent, we delete it.
- 13–17: a parent or legal guardian must agree to the Terms as the contracting party, and the teen confirms an age-appropriate assent. Guardian consent is recorded. Minor accounts default to the highest-privacy settings: no targeted advertising, no geolocation, no data sale, ever. In chat, minors also get periodic reminders that Pippa is an AI and prompts to take breaks during long sessions.
- Parent/guardian rights: the consenting guardian may review the categories of information collected, revoke consent, and direct deletion of the minor's information at any time via pippa.app.general@gmail.com or the in-app deletion flow.
6. Security
We maintain reasonable administrative, technical, and physical safeguards: data is encrypted in transit, stored in access-controlled cloud infrastructure, and every clinician read of patient data is written to an append-only audit log. Access to production systems is limited and logged. No system is perfectly secure. If a breach affects your data, we will notify you without unreasonable delay, no later than 60 days after we discover it and sooner where the law requires, and we will notify regulators as required.
7. Your Rights and Controls
We offer these rights to every user, wherever you live, and we will never retaliate against you or degrade your service for using them:
- Access & export: ask us to confirm what we have and get a copy of your data in a portable format, including which third parties it has been shared with.
- Correction: most data can be edited directly in the app; for anything else, email us.
- Deletion: delete your account in Settings (with the 30-day erasure timeline above), or ask us to delete specific data without closing your account. Deletion extends to backups as they rotate and is passed along to our service providers. See Delete Your Account.
- Withdraw consent: sever a clinician's access in Settings, immediately. Guardians of teen accounts can revoke consent by email.
- Notification control: manage notifications in your device settings or inside the app.
We respond to privacy requests within 45 days (extendable once by 45 days for complex requests, with notice). If we decline a request, we'll explain why and you can appeal by replying to our response; we answer appeals within 45 days, and if you're still unsatisfied you can contact your state Attorney General. Because we sell no data and do no targeted advertising, there is nothing to opt out of under state "do not sell or share" rules, and browser opt-out signals like Global Privacy Control have nothing to switch off; we honor the spirit of them by default.
8. Not for Emergencies
Pippa and your care team do not monitor the app 24/7. If you believe you are experiencing a medical emergency, call 911. If you are in suicidal crisis or emotional distress, call or text 988 (Suicide & Crisis Lifeline), available 24/7. Our full crisis protocol is published on the Safety page.
9. Changes to This Policy
If we make material changes, we'll notify you in the app and require re-acceptance before continued use. We will never apply a material change to previously collected data without your affirmative consent. The version and effective date at the top of this page always reflect the current policy.
10. Contact
Pippa LLC. Questions, requests, or concerns: pippa.app.general@gmail.com.