Privacy Policy (draft)
HitThree ("we", "us") helps adults track calories, protein, and weight. We treat that information as sensitive health data.
What we collect
- Account email and authentication data (via Supabase Auth).
- Profile details you provide (e.g. date of birth, sex, height, goal weight, activity level, burn source).
- Daily logs: calories in, protein, calories burned, optional notes and weigh-ins.
- Optional integration tokens (e.g. Garmin) encrypted at rest when enabled.
- Technical logs needed to run and secure the service.
How we use data
- To provide the core tracking, targets, insights, and reminders.
- To enforce safety guardrails (e.g. 18+, intake floor messaging).
- To improve reliability (error monitoring such as Sentry, if enabled).
We do not sell your data or share it with advertisers. Analytics, if any, will be minimal and privacy-friendly.
Legal context (US / health data)
Depending on where you live and how the product evolves, rules such as the FTC Health Breach Notification Rule and state consumer-health-data laws (for example Washington's My Health My Data Act) may apply. EU users may bring GDPR obligations. This draft does not determine applicability — get a legal review before public launch.
Storage & security
- Primary database and auth: Supabase (Postgres) with row-level security.
- Every user-owned row is scoped by your user id; group features (later) share only opt-in fields.
- Secrets live in environment variables / a secrets manager — never in the client bundle beyond public keys.
Your choices
- CSV export of your data (Phase 1).
- Account deletion with hard delete within 30 days of request (Phase 1).
- Turn off reminders / notifications anytime.
Children
HitThree is 18+ only. We do not knowingly collect data from minors.
Contact
For privacy requests during private beta, contact the operator via the channel shared with beta users. Update this section with a public email before launch.