Privacy Policy

Version 2.0 · Effective July 16, 2026 · Consumer Health Data Privacy Policy

Pippa exists to support eating-disorder recovery. That only works if you can trust us with some of the most sensitive information there is. This policy explains exactly what we collect, why, who can see it, how long we keep it, and the controls you have. The short version: your health data is used only to run the service, is shared only with clinicians you approve, is never sold, is never used for advertising, and is never used to train AI models.

Because nearly everything Pippa handles relates to your health, we also publish a separate Consumer Health Data Privacy Policy that describes our handling of consumer health data in the form some state laws (such as Washington's My Health My Data Act and Nevada's consumer health data law) require. The two documents are consistent; if they ever conflict, the one giving you stronger protection controls.

1. What We Collect

DataWhat it includesWhy
Account Email address, sign-in method (email, Sign in with Apple, or Google), date of birth (from the age screen) Creating and securing your account; age-appropriate consent flow
Profile Weight, height, birthday, gender; optional blind weight check-ins on the cadence your clinician sets Personalizing your daily eating rhythm and the chart your care team sees
Meal logs Meal photos, the food name and calorie estimate generated from them, the meal time (which you can edit), and your answers to post-meal check-in questions, including any questions your clinician configures The core of the service: logging meals and tracking consistency
Meal plan & grocery list The meal plan you or your clinician set up, and your shared grocery list Planning support you and your care team edit together
Mood & check-ins Mood entries and notes, daily check-in answers, and responses to any questionnaires your clinician assigns Mood support features and, with your consent, care-team visibility
Chat with Pippa Your recent chat messages, a rolling summary the app keeps so Pippa remembers context, and automated safety flags when a message suggests a crisis Making the chat useful across sessions and keeping you safe; see the Safety page
Care-team messages Messages between you and clinicians you've approved, including messages they send you Direct communication with your care team
Consent records Terms acceptance (who signed, when, version), guardian consent for teen accounts, data-sharing agreements with clinicians Legal records of the permissions you've granted
In-app rewards Coins, showing-up streaks, and the cosmetic items you've collected Keeping your buddy and room in sync across your devices
Subscription status Whether your account has an active premium subscription, verified through Apple Unlocking premium features. Apple processes payment; we never see your card details
Device & usage Device identifier, push notification token, time zone, app-open times, app settings Sync, notifications delivered at times that make sense where you are, and timing reminders when they actually help

What stays on your device only

Your journal is private to your device. Journal entries are stored locally and are never uploaded, synced, or visible to anyone, including your care team and us. If you ask Pippa to reflect on a journal entry, the text is processed once to generate the reflection and is not stored on our servers. Sticker collections and similar keepsakes also stay local.

Photos and metadata

Meal photos are re-encoded on your device before upload, which removes embedded metadata including location (EXIF/GPS). When you import a photo from your library, the app reads the photo's capture date on your device to suggest the meal time; that metadata itself is not uploaded. We perform no facial recognition or biometric processing on any image, ever. We do not collect your precise location.

2. What We Never Do

3. Who Can See Your Data

Service providers that help us run Pippa

These companies process data only on our instructions to operate the service. None of them may use your data for their own purposes such as advertising or AI training:

ProviderWhat they do for us
OpenAIGenerates chat responses, meal-photo food and calorie estimates, and safety-moderation checks. Content is processed through their API, which is not used to train their models.
Amazon Web ServicesDatabase, sign-in infrastructure, and transactional email (for example guardian consent links and clinician alerts)
CloudflareApplication server and meal-photo storage
ApplePush notifications, Sign in with Apple, and App Store subscription billing
GooglePush notifications on Android and Google Sign-In
StripeBilling for clinics and institutions only; Stripe never receives patient health data

We have no affiliates, and we share consumer health data with no third parties other than the service providers above and the clinicians you approve.

4. How Long We Keep It (Retention Policy)

5. Children and Teens

6. Security

We maintain reasonable administrative, technical, and physical safeguards: data is encrypted in transit, stored in access-controlled cloud infrastructure, and every clinician read of patient data is written to an append-only audit log. Access to production systems is limited and logged. No system is perfectly secure. If a breach affects your data, we will notify you without unreasonable delay, no later than 60 days after we discover it and sooner where the law requires, and we will notify regulators as required.

7. Your Rights and Controls

We offer these rights to every user, wherever you live, and we will never retaliate against you or degrade your service for using them:

We respond to privacy requests within 45 days (extendable once by 45 days for complex requests, with notice). If we decline a request, we'll explain why and you can appeal by replying to our response; we answer appeals within 45 days, and if you're still unsatisfied you can contact your state Attorney General. Because we sell no data and do no targeted advertising, there is nothing to opt out of under state "do not sell or share" rules, and browser opt-out signals like Global Privacy Control have nothing to switch off; we honor the spirit of them by default.

8. Not for Emergencies

Pippa and your care team do not monitor the app 24/7. If you believe you are experiencing a medical emergency, call 911. If you are in suicidal crisis or emotional distress, call or text 988 (Suicide & Crisis Lifeline), available 24/7. Our full crisis protocol is published on the Safety page.

9. Changes to This Policy

If we make material changes, we'll notify you in the app and require re-acceptance before continued use. We will never apply a material change to previously collected data without your affirmative consent. The version and effective date at the top of this page always reflect the current policy.

10. Contact

Pippa LLC. Questions, requests, or concerns: pippa.app.general@gmail.com.