Privacy Policy & Consumer Health Data Notice

Last Updated: March 19, 2026

1. Introduction

Welcome to JellyPal ("we," "our," or "us"), operated by Inverse Collective LLC. We provide a mobile application designed to help you track your GLP-1 medication dosage, injection sites, and related health metrics (the "App"). We are committed to protecting your privacy and treating your data with the sensitivity it deserves.

IMPORTANT NOTICE: This policy includes dedicated disclosures for international and state-specific regulations, including GDPR (EU/UK), LGPD (Brazil), CCPA (California), and the Washington My Health My Data Act. See the relevant sections below for your specific rights.

2. Not a Medical Device

The App is a data management tool for your personal use. It is not a medical device and does not provide medical advice, diagnosis, or treatment. The data you visualize in the App is for your informational purposes only.

Data Accuracy and Methodology Disclosure

The App's "Medication Level" or "PK Plotter" feature uses mathematical models based on published half-life data from drug manufacturers (e.g., semaglutide half-life ~7 days, tirzepatide half-life ~5 days). The visualization estimates medication concentration using exponential decay formulas:

  • These are theoretical estimates and do not reflect your actual blood concentration
  • Individual metabolism, kidney function, drug interactions, and other factors are NOT accounted for
  • The models assume standard pharmacokinetic parameters that may not apply to you

⚠️ Do not make medical decisions based on these visualizations. Always consult your healthcare provider before changing your medication regimen.

3. Data We Collect

We adhere to a "Data Minimization" principle. We collect only what is necessary to provide the tracking features of the App.

Data CategorySpecific TypesSourcePurpose
Medication DataDrug name, dosage, injection timestamp, injection siteUser InputInjection history and reminders
Health MetricsWeight, body fat %, measurementsUser Input / HealthKitProgress visualization
Adverse Event LogsSide effects, symptom severityUser InputPattern identification
Device DataDevice model, OS version, timezonePassive CollectionApp functionality
Food Noise DataCraving/appetite level (5-point scale), timestamps, optional notesUser InputAppetite pattern tracking and medication effectiveness insights
Inventory/Supply DataMedication pen or vial details (name, total mg, remaining mg, open date, expiration date, active status)User InputSupply management and expiration reminders
Muscle Safety DataProtein intake, lean mass estimates, body composition metricsUser InputLean mass preservation monitoring during weight loss
Account DataEmail address, display name, authentication provider (Google or Apple)User Input via sign-inAccount management and cloud sync
Subscription DataPurchase status, entitlements, subscription tierSubscription Management SDKFeature access management

4. HealthKit Data Integration

If you choose to connect the App to Apple HealthKit, we will read and/or write data to the Health app on your device. HealthKit integration is entirely optional and you can use the App without granting HealthKit permissions.

  • Usage: We use HealthKit data solely to display your progress within the App. Specifically, we may read weight measurements, body mass index, and body fat percentage to show progress charts. We may write medication dose records to your Health app for your records.
  • Purpose Limitation: HealthKit data is used ONLY for the core functionality of tracking your medication journey and visualizing health metrics. We do not use HealthKit data for advertising, marketing, or data mining purposes under any circumstances.
  • No Sharing or Selling: We do not sell HealthKit data to third parties. We do not share HealthKit data with advertisers, data brokers, or analytics companies.
  • Storage: HealthKit data read by the App is processed locally. If you sign in to your JellyPal account, derived health metrics (weight entries, body measurements) may be synced to our secure cloud database to enable cross-device access and backup. We do not store raw HealthKit data on our servers.
  • User Control: You can revoke HealthKit permissions at any time via iPhone Settings → Health → Data Access & Devices → JellyPal.

5. Where Your Data is Stored

Your data is stored in two places depending on whether you create an account:

  • Local Storage: All data is stored locally on your device using SharedPreferences. The App works fully offline — no account is required to use any core feature.
  • Cloud Sync: If you sign in with Google or Apple Sign-In, your data automatically syncs to our secure cloud database (a managed PostgreSQL service hosted in the United States). This enables backup and cross-device sync.
  • Authentication: Sign-in is handled through a third-party authentication provider using Google Sign-In or Apple Sign-In.
  • Automatic Sync: Cloud sync is automatic when signed in. If you do not sign in, your data stays entirely on your device.

If you create an account, your health data is stored in our secure cloud database to provide backup and cross-device sync. This database is encrypted at rest and in transit. Access is restricted to authorized personnel for technical support purposes only.

6. Data Sharing and Disclosure

We do not sell your Personal Information. We share data only with the following categories of service providers who assist in operating the App:

Provider CategoryService ProvidedData Shared
Cloud Infrastructure ProviderAuthentication, Cloud FunctionsEmail, auth tokens, synced health data (processed server-side)
Database ProviderCloud DatabaseAll synced health data (medication, weight, food noise, side effects, inventory)
Subscription Management ProviderSubscription ManagementAnonymous user ID, purchase history, entitlement status
Platform ProviderPayment Processing, Push NotificationsPayment info, device push token

For a detailed list of our service providers and their Data Processing Agreements, please contact privacy@jellypal.app.

7. Analytics and Tracking

We use limited, privacy-preserving analytics to understand how the App is used (e.g., "How many users visit the Settings screen?"). We do not use "Pixels" or trackers that share your health status with advertising networks like Meta (Facebook) or TikTok.

8. Your Rights

We provide all users with comprehensive control over their data. Depending on your location (such as the EU, UK, Brazil, or California), you may have the following statutory rights:

  • Right to Access: You can request a copy of your personal data in a structured, electronic format (JSON or CSV). We will respond within 30 days.
  • Right to Rectification: You can correct inaccurate data directly within the App's log screens or by contacting support.
  • Right to Erasure ("Right to be Forgotten"): You can request the permanent deletion of your cloud account and all associated health data. We will complete this within 30 days, subject to legal retention requirements.
  • Right to Restrict Processing: You can request that we limit how we use your data, for example, by disabling cloud sync and using the App in offline-only mode.
  • Right to Data Portability: You have the right to receive your data in a machine-readable format to transfer it to another service.
  • Right to Object: You can object to our processing of your data. Since we do not perform direct marketing or profiling, this typically involves withdrawing consent for cloud storage.
  • Right re: Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing. JellyPal does not use automated decision-making or profiling that produces legal effects.
  • Right to Withdraw Consent: Where processing is based on consent (such as HealthKit access or cloud sync), you may withdraw it at any time via App or System settings.

To exercise any of these rights, please contact support@jellypal.app. We do not charge a fee for these requests and will respond within 30 days.

9. Consumer Health Data Privacy Policy (Washington & Nevada)

This section applies specifically to "Consumer Health Data" as defined by the Washington My Health My Data Act (MHMDA).

  • Categories Collected: We collect data regarding your use of prescribed medications, bodily functions, and vital signs.
  • Sources: This data is collected directly from you or your device's HealthKit sensors.
  • Purpose: The data is used solely to provide the medication tracking and visualization utility you requested.
  • Sharing: We share Consumer Health Data with service providers (listed in Section 6) solely for the purpose of operating the App. These providers are contractually prohibited from using your data for their own purposes. We do not sell Consumer Health Data.
  • Consumer Rights: Washington residents have the right to confirm processing, access data, and request deletion. To exercise these rights, please contact us at support@jellypal.app.

10. Legal Basis for Processing (GDPR Article 6 & Article 9)

We process your personal data based on the following legal grounds:

  • Explicit Consent (Article 9(2)(a)): We process your health data (medication logs, symptoms, weight) only with your explicit consent. This consent is freely given, specific, informed, and unambiguous. You can withdraw this consent at any time by deleting your account or disabling cloud sync.
  • Contract Performance (Article 6(1)(b)): We process your account data (email, display name) to provide the services you have requested, such as account management and cross-device synchronization.
  • No Automated Decision-Making: We do not use your health data for automated decision-making or profiling that produces legal or similarly significant effects.

11. International Data Transfers

JellyPal is operated from the United States. If you are accessing the App from the EU, UK, Brazil, or other regions with laws governing data collection and use, please note that your data will be transferred to and stored on servers in the United States.

  • Standard Contractual Clauses (SCCs): For users in the EEA, UK, and Brazil, we ensure that transfers are authorized via Standard Contractual Clauses or other valid transfer mechanisms.
  • Supplementary Safeguards: We implement technical safeguards including encryption in transit (TLS 1.3), encryption at rest, and restricted access logs to protect your data during and after transfer.
  • Offline Mode: You can avoid international data transfers by using the App in offline mode without creating a cloud account.

12. Data Retention & Deletion

We retain your data only as long as necessary to provide our services:

  • Local Data: Retained on your device until the App is deleted.
  • Cloud Data: Retained while your account is active. If you delete your account, cloud data is deleted within 30 days.
  • Backups: Data in disaster recovery backups may be retained for up to 90 days after account deletion.
  • Security Logs: Retained for 12 months for audit and security purposes.
  • Legal Obligations: We may retain data longer if required by law or a valid legal hold.

13. Data Breach Notification

In the event of a data breach:

  • Authorities: We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals (as per GDPR).
  • Individuals: We will notify affected individuals without undue delay if a breach is likely to result in a high risk to their rights and freedoms.
  • Reporting: Please report any suspected security vulnerabilities to privacy@jellypal.app.

14. Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
  • Access Control: We use role-based access controls (RBAC) to ensure only authorized personnel with a legitimate business need can access our systems.
  • Audit Logging: We maintain audit logs of all data access and system changes.
  • Regular Reviews: We conduct regular security reviews and vulnerability assessments of our infrastructure.

15. European Economic Area, UK & Switzerland (GDPR/UK GDPR)

If you are in the EEA, UK, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Legal Basis: Our processing of health data is based on your explicit consent (Article 9(2)(a)).
  • Rights: You have the right to access, rectify, erase, restrict, and port your data, as well as the right to object to processing.
  • Complaints: You have the right to lodge a complaint with your local Data Protection Authority (DPA). In the UK, this is the ICO (ico.org.uk).
  • DPO Contact: Our Data Protection Officer can be reached at privacy@jellypal.app.

16. Brazil (LGPD)

Para usuários no Brasil, processamos dados de acordo com a Lei Geral de Proteção de Dados (LGPD):

  • Dados Sensíveis: Dados de saúde são considerados "dados pessoais sensíveis" sob o Artigo 5 da LGPD.
  • Base Legal: O processamento é baseado no seu consentimento específico e destacado (Artigo 11).
  • Direitos: Confirmação de processamento, acesso, correção, anonimização, bloqueio ou eliminação, e portabilidade de dados.
  • Autoridade: A Autoridade Nacional de Proteção de Dados (ANPD) é a autoridade supervisora (gov.br/anpd).
  • Encarregado (DPO): privacy@jellypal.app.

17. California (CCPA/CPRA)

This section provides additional disclosures for California residents under the CCPA and CPRA:

  • Sensitive Personal Information: Your health and medication data is classified as "sensitive personal information."
  • No Sale or Sharing: We do NOT sell your personal information or share it for cross-context behavioral advertising.
  • Rights: You have the right to know, delete, correct, and limit the use of your sensitive personal information.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Authority: The California Privacy Protection Agency (CPPA) oversees these rights (cppa.ca.gov).

18. Canada (PIPEDA)

For users in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA):

  • Rights: You have the right to access and correct your personal information and to withdraw consent.
  • Response Time: We will respond to access requests within 30 days.
  • Authority: The Office of the Privacy Commissioner of Canada (priv.gc.ca).

19. Australia (Privacy Act 1988)

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988:

  • Sensitive Information: We collect health information only with your consent and where necessary for our functions.
  • Rights: You have the right to access and correct your information and to make a complaint about a breach of the APPs.
  • Authority: The Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

20. Japan (APPI)

For users in Japan, we comply with the Act on the Protection of Personal Information (個人情報保護法, APPI):

  • Special Care-Required Information: Your health and medication data is classified as "Special Care-Required Personal Information" (要配慮個人情報) under Article 2(3). We obtain your explicit consent before collecting or processing this data.
  • Purpose of Use: We use your data only for the purposes disclosed at the time of collection, as required by Article 17.
  • Cross-Border Transfers: Your data is processed on servers in the United States. We ensure adequate protection as required by Article 28 for international transfers.
  • Rights: You have the right to request disclosure, correction, suspension of use, and deletion of your personal information under Articles 33-39.
  • Breach Notification: In the event of a data breach affecting your information, we will notify the Personal Information Protection Commission (PPC) and affected individuals within 3-5 business days as required.
  • Authority: The Personal Information Protection Commission (PPC) at ppc.go.jp.

21. South Korea (PIPA)

For users in South Korea, we comply with the Personal Information Protection Act (개인정보 보호법, PIPA):

  • Sensitive Information: Health and medication data is classified as "sensitive information" under Article 23. We collect this data only with your separate, explicit written consent.
  • Consent: We obtain distinct consent for each purpose of processing, as required by Article 15. You may withdraw consent at any time.
  • Cross-Border Transfers: We disclose the recipient country (United States), recipient identity, purpose, and items transferred as required by Article 17(3).
  • Rights: You have the right to access, correct, delete, and suspend processing of your personal information under Articles 35-37.
  • Breach Notification: We will notify affected individuals within 15 days of discovering a breach, as required by Article 34.
  • Authority: The Personal Information Protection Commission (PIPC) at pipc.go.kr.

22. Singapore (PDPA)

For users in Singapore, we comply with the Personal Data Protection Act 2012 (PDPA):

  • Consent: We collect, use, and disclose your personal data only with your consent as required by Part IV of the PDPA. You may withdraw consent at any time.
  • Purpose Limitation: We collect and use your data only for purposes a reasonable person would consider appropriate under the circumstances.
  • Retention: We retain medical and health-related data for up to 6 years as recommended by Singapore's healthcare data retention guidelines, or until you request deletion.
  • Cross-Border Transfers: Your data is transferred to the United States. We ensure the recipient provides a comparable standard of protection as required by the PDPA.
  • Breach Notification: We will notify the Personal Data Protection Commission (PDPC) and affected individuals within 3 calendar days of assessing a notifiable data breach.
  • Rights: You have the right to access and correct your personal data under Parts V and VI of the PDPA.
  • Authority: The Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

23. Children's Privacy

The App is intended for users aged 18 and older. We do not knowingly collect information from children.

  • COPPA (USA): We do not knowingly collect personal information from children under 13.
  • GDPR (EU): The age of consent for data processing varies by member state (typically 13-16). We do not knowingly process data from individuals under these ages.
  • Action: If you believe a child has provided us with data, please contact privacy@jellypal.app and we will delete it immediately.

24. Changes to This Policy

We may update this policy to reflect changes in our practices or regulatory requirements. If we make material changes, we will notify you via an in-app alert or email.

25. Contact Us

If you have questions about this policy or wish to exercise your rights, please contact our privacy team:

Inverse Collective LLC

5900 Balcones Drive Suite 16274

Austin, TX 78731

General Support: support@jellypal.app

Privacy & DPO: privacy@jellypal.app