Privacy Policy & Consumer Health Data Notice
Last Updated: March 19, 2026
1. Introduction
Welcome to JellyPal ("we," "our," or "us"), operated by Inverse Collective LLC. We provide a mobile application designed to help you track your GLP-1 medication dosage, injection sites, and related health metrics (the "App"). We are committed to protecting your privacy and treating your data with the sensitivity it deserves.
IMPORTANT NOTICE: This policy includes dedicated disclosures for international and state-specific regulations, including GDPR (EU/UK), LGPD (Brazil), CCPA (California), and the Washington My Health My Data Act. See the relevant sections below for your specific rights.
2. Not a Medical Device
The App is a data management tool for your personal use. It is not a medical device and does not provide medical advice, diagnosis, or treatment. The data you visualize in the App is for your informational purposes only.
Data Accuracy and Methodology Disclosure
The App's "Medication Level" or "PK Plotter" feature uses mathematical models based on published half-life data from drug manufacturers (e.g., semaglutide half-life ~7 days, tirzepatide half-life ~5 days). The visualization estimates medication concentration using exponential decay formulas:
- These are theoretical estimates and do not reflect your actual blood concentration
- Individual metabolism, kidney function, drug interactions, and other factors are NOT accounted for
- The models assume standard pharmacokinetic parameters that may not apply to you
⚠️ Do not make medical decisions based on these visualizations. Always consult your healthcare provider before changing your medication regimen.
3. Data We Collect
We adhere to a "Data Minimization" principle. We collect only what is necessary to provide the tracking features of the App.
| Data Category | Specific Types | Source | Purpose |
|---|---|---|---|
| Medication Data | Drug name, dosage, injection timestamp, injection site | User Input | Injection history and reminders |
| Health Metrics | Weight, body fat %, measurements | User Input / HealthKit | Progress visualization |
| Adverse Event Logs | Side effects, symptom severity | User Input | Pattern identification |
| Device Data | Device model, OS version, timezone | Passive Collection | App functionality |
| Food Noise Data | Craving/appetite level (5-point scale), timestamps, optional notes | User Input | Appetite pattern tracking and medication effectiveness insights |
| Inventory/Supply Data | Medication pen or vial details (name, total mg, remaining mg, open date, expiration date, active status) | User Input | Supply management and expiration reminders |
| Muscle Safety Data | Protein intake, lean mass estimates, body composition metrics | User Input | Lean mass preservation monitoring during weight loss |
| Account Data | Email address, display name, authentication provider (Google or Apple) | User Input via sign-in | Account management and cloud sync |
| Subscription Data | Purchase status, entitlements, subscription tier | Subscription Management SDK | Feature access management |
4. HealthKit Data Integration
If you choose to connect the App to Apple HealthKit, we will read and/or write data to the Health app on your device. HealthKit integration is entirely optional and you can use the App without granting HealthKit permissions.
- Usage: We use HealthKit data solely to display your progress within the App. Specifically, we may read weight measurements, body mass index, and body fat percentage to show progress charts. We may write medication dose records to your Health app for your records.
- Purpose Limitation: HealthKit data is used ONLY for the core functionality of tracking your medication journey and visualizing health metrics. We do not use HealthKit data for advertising, marketing, or data mining purposes under any circumstances.
- No Sharing or Selling: We do not sell HealthKit data to third parties. We do not share HealthKit data with advertisers, data brokers, or analytics companies.
- Storage: HealthKit data read by the App is processed locally. If you sign in to your JellyPal account, derived health metrics (weight entries, body measurements) may be synced to our secure cloud database to enable cross-device access and backup. We do not store raw HealthKit data on our servers.
- User Control: You can revoke HealthKit permissions at any time via iPhone Settings → Health → Data Access & Devices → JellyPal.
5. Where Your Data is Stored
Your data is stored in two places depending on whether you create an account:
- Local Storage: All data is stored locally on your device using SharedPreferences. The App works fully offline — no account is required to use any core feature.
- Cloud Sync: If you sign in with Google or Apple Sign-In, your data automatically syncs to our secure cloud database (a managed PostgreSQL service hosted in the United States). This enables backup and cross-device sync.
- Authentication: Sign-in is handled through a third-party authentication provider using Google Sign-In or Apple Sign-In.
- Automatic Sync: Cloud sync is automatic when signed in. If you do not sign in, your data stays entirely on your device.
If you create an account, your health data is stored in our secure cloud database to provide backup and cross-device sync. This database is encrypted at rest and in transit. Access is restricted to authorized personnel for technical support purposes only.
6. Data Sharing and Disclosure
We do not sell your Personal Information. We share data only with the following categories of service providers who assist in operating the App:
| Provider Category | Service Provided | Data Shared |
|---|---|---|
| Cloud Infrastructure Provider | Authentication, Cloud Functions | Email, auth tokens, synced health data (processed server-side) |
| Database Provider | Cloud Database | All synced health data (medication, weight, food noise, side effects, inventory) |
| Subscription Management Provider | Subscription Management | Anonymous user ID, purchase history, entitlement status |
| Platform Provider | Payment Processing, Push Notifications | Payment info, device push token |
For a detailed list of our service providers and their Data Processing Agreements, please contact privacy@jellypal.app.
7. Analytics and Tracking
We use limited, privacy-preserving analytics to understand how the App is used (e.g., "How many users visit the Settings screen?"). We do not use "Pixels" or trackers that share your health status with advertising networks like Meta (Facebook) or TikTok.
8. Your Rights
We provide all users with comprehensive control over their data. Depending on your location (such as the EU, UK, Brazil, or California), you may have the following statutory rights:
- Right to Access: You can request a copy of your personal data in a structured, electronic format (JSON or CSV). We will respond within 30 days.
- Right to Rectification: You can correct inaccurate data directly within the App's log screens or by contacting support.
- Right to Erasure ("Right to be Forgotten"): You can request the permanent deletion of your cloud account and all associated health data. We will complete this within 30 days, subject to legal retention requirements.
- Right to Restrict Processing: You can request that we limit how we use your data, for example, by disabling cloud sync and using the App in offline-only mode.
- Right to Data Portability: You have the right to receive your data in a machine-readable format to transfer it to another service.
- Right to Object: You can object to our processing of your data. Since we do not perform direct marketing or profiling, this typically involves withdrawing consent for cloud storage.
- Right re: Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing. JellyPal does not use automated decision-making or profiling that produces legal effects.
- Right to Withdraw Consent: Where processing is based on consent (such as HealthKit access or cloud sync), you may withdraw it at any time via App or System settings.
To exercise any of these rights, please contact support@jellypal.app. We do not charge a fee for these requests and will respond within 30 days.
9. Consumer Health Data Privacy Policy (Washington & Nevada)
This section applies specifically to "Consumer Health Data" as defined by the Washington My Health My Data Act (MHMDA).
- Categories Collected: We collect data regarding your use of prescribed medications, bodily functions, and vital signs.
- Sources: This data is collected directly from you or your device's HealthKit sensors.
- Purpose: The data is used solely to provide the medication tracking and visualization utility you requested.
- Sharing: We share Consumer Health Data with service providers (listed in Section 6) solely for the purpose of operating the App. These providers are contractually prohibited from using your data for their own purposes. We do not sell Consumer Health Data.
- Consumer Rights: Washington residents have the right to confirm processing, access data, and request deletion. To exercise these rights, please contact us at support@jellypal.app.
10. Legal Basis for Processing (GDPR Article 6 & Article 9)
We process your personal data based on the following legal grounds:
- Explicit Consent (Article 9(2)(a)): We process your health data (medication logs, symptoms, weight) only with your explicit consent. This consent is freely given, specific, informed, and unambiguous. You can withdraw this consent at any time by deleting your account or disabling cloud sync.
- Contract Performance (Article 6(1)(b)): We process your account data (email, display name) to provide the services you have requested, such as account management and cross-device synchronization.
- No Automated Decision-Making: We do not use your health data for automated decision-making or profiling that produces legal or similarly significant effects.
11. International Data Transfers
JellyPal is operated from the United States. If you are accessing the App from the EU, UK, Brazil, or other regions with laws governing data collection and use, please note that your data will be transferred to and stored on servers in the United States.
- Standard Contractual Clauses (SCCs): For users in the EEA, UK, and Brazil, we ensure that transfers are authorized via Standard Contractual Clauses or other valid transfer mechanisms.
- Supplementary Safeguards: We implement technical safeguards including encryption in transit (TLS 1.3), encryption at rest, and restricted access logs to protect your data during and after transfer.
- Offline Mode: You can avoid international data transfers by using the App in offline mode without creating a cloud account.
12. Data Retention & Deletion
We retain your data only as long as necessary to provide our services:
- Local Data: Retained on your device until the App is deleted.
- Cloud Data: Retained while your account is active. If you delete your account, cloud data is deleted within 30 days.
- Backups: Data in disaster recovery backups may be retained for up to 90 days after account deletion.
- Security Logs: Retained for 12 months for audit and security purposes.
- Legal Obligations: We may retain data longer if required by law or a valid legal hold.
13. Data Breach Notification
In the event of a data breach:
- Authorities: We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals (as per GDPR).
- Individuals: We will notify affected individuals without undue delay if a breach is likely to result in a high risk to their rights and freedoms.
- Reporting: Please report any suspected security vulnerabilities to privacy@jellypal.app.
14. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
- Access Control: We use role-based access controls (RBAC) to ensure only authorized personnel with a legitimate business need can access our systems.
- Audit Logging: We maintain audit logs of all data access and system changes.
- Regular Reviews: We conduct regular security reviews and vulnerability assessments of our infrastructure.
15. European Economic Area, UK & Switzerland (GDPR/UK GDPR)
If you are in the EEA, UK, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Legal Basis: Our processing of health data is based on your explicit consent (Article 9(2)(a)).
- Rights: You have the right to access, rectify, erase, restrict, and port your data, as well as the right to object to processing.
- Complaints: You have the right to lodge a complaint with your local Data Protection Authority (DPA). In the UK, this is the ICO (ico.org.uk).
- DPO Contact: Our Data Protection Officer can be reached at privacy@jellypal.app.
16. Brazil (LGPD)
Para usuários no Brasil, processamos dados de acordo com a Lei Geral de Proteção de Dados (LGPD):
- Dados Sensíveis: Dados de saúde são considerados "dados pessoais sensíveis" sob o Artigo 5 da LGPD.
- Base Legal: O processamento é baseado no seu consentimento específico e destacado (Artigo 11).
- Direitos: Confirmação de processamento, acesso, correção, anonimização, bloqueio ou eliminação, e portabilidade de dados.
- Autoridade: A Autoridade Nacional de Proteção de Dados (ANPD) é a autoridade supervisora (gov.br/anpd).
- Encarregado (DPO): privacy@jellypal.app.
17. California (CCPA/CPRA)
This section provides additional disclosures for California residents under the CCPA and CPRA:
- Sensitive Personal Information: Your health and medication data is classified as "sensitive personal information."
- No Sale or Sharing: We do NOT sell your personal information or share it for cross-context behavioral advertising.
- Rights: You have the right to know, delete, correct, and limit the use of your sensitive personal information.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Authority: The California Privacy Protection Agency (CPPA) oversees these rights (cppa.ca.gov).
18. Canada (PIPEDA)
For users in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Rights: You have the right to access and correct your personal information and to withdraw consent.
- Response Time: We will respond to access requests within 30 days.
- Authority: The Office of the Privacy Commissioner of Canada (priv.gc.ca).
19. Australia (Privacy Act 1988)
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988:
- Sensitive Information: We collect health information only with your consent and where necessary for our functions.
- Rights: You have the right to access and correct your information and to make a complaint about a breach of the APPs.
- Authority: The Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
20. Japan (APPI)
For users in Japan, we comply with the Act on the Protection of Personal Information (個人情報保護法, APPI):
- Special Care-Required Information: Your health and medication data is classified as "Special Care-Required Personal Information" (要配慮個人情報) under Article 2(3). We obtain your explicit consent before collecting or processing this data.
- Purpose of Use: We use your data only for the purposes disclosed at the time of collection, as required by Article 17.
- Cross-Border Transfers: Your data is processed on servers in the United States. We ensure adequate protection as required by Article 28 for international transfers.
- Rights: You have the right to request disclosure, correction, suspension of use, and deletion of your personal information under Articles 33-39.
- Breach Notification: In the event of a data breach affecting your information, we will notify the Personal Information Protection Commission (PPC) and affected individuals within 3-5 business days as required.
- Authority: The Personal Information Protection Commission (PPC) at ppc.go.jp.
21. South Korea (PIPA)
For users in South Korea, we comply with the Personal Information Protection Act (개인정보 보호법, PIPA):
- Sensitive Information: Health and medication data is classified as "sensitive information" under Article 23. We collect this data only with your separate, explicit written consent.
- Consent: We obtain distinct consent for each purpose of processing, as required by Article 15. You may withdraw consent at any time.
- Cross-Border Transfers: We disclose the recipient country (United States), recipient identity, purpose, and items transferred as required by Article 17(3).
- Rights: You have the right to access, correct, delete, and suspend processing of your personal information under Articles 35-37.
- Breach Notification: We will notify affected individuals within 15 days of discovering a breach, as required by Article 34.
- Authority: The Personal Information Protection Commission (PIPC) at pipc.go.kr.
22. Singapore (PDPA)
For users in Singapore, we comply with the Personal Data Protection Act 2012 (PDPA):
- Consent: We collect, use, and disclose your personal data only with your consent as required by Part IV of the PDPA. You may withdraw consent at any time.
- Purpose Limitation: We collect and use your data only for purposes a reasonable person would consider appropriate under the circumstances.
- Retention: We retain medical and health-related data for up to 6 years as recommended by Singapore's healthcare data retention guidelines, or until you request deletion.
- Cross-Border Transfers: Your data is transferred to the United States. We ensure the recipient provides a comparable standard of protection as required by the PDPA.
- Breach Notification: We will notify the Personal Data Protection Commission (PDPC) and affected individuals within 3 calendar days of assessing a notifiable data breach.
- Rights: You have the right to access and correct your personal data under Parts V and VI of the PDPA.
- Authority: The Personal Data Protection Commission (PDPC) at pdpc.gov.sg.
23. Children's Privacy
The App is intended for users aged 18 and older. We do not knowingly collect information from children.
- COPPA (USA): We do not knowingly collect personal information from children under 13.
- GDPR (EU): The age of consent for data processing varies by member state (typically 13-16). We do not knowingly process data from individuals under these ages.
- Action: If you believe a child has provided us with data, please contact privacy@jellypal.app and we will delete it immediately.
24. Changes to This Policy
We may update this policy to reflect changes in our practices or regulatory requirements. If we make material changes, we will notify you via an in-app alert or email.
25. Contact Us
If you have questions about this policy or wish to exercise your rights, please contact our privacy team:
Inverse Collective LLC
5900 Balcones Drive Suite 16274
Austin, TX 78731
General Support: support@jellypal.app
Privacy & DPO: privacy@jellypal.app