Skip to main content
Trigger AI

Privacy Policy

If you live in Washington, Nevada, or Connecticut, a separate policy governs your consumer health data. Where the two differ on health data, that policy controls.

Read the Consumer Health Data Privacy Policy

Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED]

1. Who we are

Trigger AI is made by [LEGAL NAME], [MAILING ADDRESS]. You can reach us at support@triggerai.app or through the Support page. This policy explains what information the Trigger AI app and this website collect, how it is used, who receives it, and the choices you have.

2. Not a healthcare provider

Trigger AI is not a healthcare provider and does not provide medical care. We are not a covered entity or business associate under HIPAA, and the information you store in Trigger AI is not protected health information under HIPAA. It is instead protected by this policy, by the Consumer Health Data Privacy Policy, and by the consumer privacy laws that apply to you.

3. What we collect

  • Account. Your email address, display name, and the identifiers Apple provides when you sign in with Apple.
  • Health and wellness. Meals and ingredients you log; symptoms with severity and timing; the symptom categories you choose during onboarding; allergies and foods of concern; height, weight, age, and sex; activity and dietary goals; calorie targets; heart-profile answers; and the associations the app generates between foods and symptoms.
  • Meal photographs. Photographs you take or choose when logging a meal, and the ingredient and portion data derived from them.
  • Purchase status. Your subscription entitlement status, provided through RevenueCat. Apple handles payment; we never receive your card details.
  • Device and usage data. Basic information about your device and how the app is used, collected without third-party analytics SDKs.
  • Approximate location (optional). If you turn it on, coarse location used to suggest nearby restaurants when you log a meal. Off by default.
  • Apple Health (optional). If you turn it on, the app writes nutrition entries to Apple Health on your device.

4. How we use it

  • Account — to sign you in, keep your data synced to your account, and respond when you contact us.
  • Health and wellness — to run the core of the app: your log, your history, and the associations the app surfaces between foods and symptoms.
  • Meal photographs — to identify the foods in a photograph so you do not have to enter them by hand (see section 6).
  • Purchase status — to unlock the features your subscription includes.
  • Device and usage data — to operate the app and investigate problems.
  • Approximate location — only to suggest nearby restaurants while you are logging.
  • Apple Health — only to write nutrition entries you asked the app to write.

5. Third-party processors

These are the companies that process data on our behalf, and what each one does. We do not share your data with anyone not listed here.

Third-party processors and their roles
ProviderWhat it does
SupabaseDatabase, authentication, and file storage for your account and logs.
AnthropicIdentifies foods in meal photographs (see section 6).
MiniMaxSecond food-identification model for meal photographs (see section 6).
RevenueCatTracks subscription entitlement so the app knows what your subscription includes.
AppleSign in with Apple, payment, app distribution, and Apple Health where you enable it.
Open Food Facts and USDABarcode and food-search lookups only. They never receive health data or account identifiers.

6. Meal photos and AI processing

When you photograph a meal, the photograph is transmitted to third-party AI providers — Anthropic and MiniMax — to identify the foods in it. Photographs are sent without your name, email address, or account identifier attached. One provider, MiniMax, processes photographs outside the United States.

If you would rather your photographs never be processed this way, log by barcode scan or manual entry instead. Neither sends a photograph to an AI provider.

7. Apple Health

Data the app writes to Apple Health is never used for advertising, marketing, or data mining, and is never sold. Apple Health data stays on your device under Apple’s controls; the app only writes the nutrition entries you asked it to write.

8. Photo metadata

Photographs are re-encoded before upload. Re-encoding strips the file’s embedded metadata, including GPS location, so it never leaves your device.

9. No advertising or tracking

We do not use third-party advertising or analytics SDKs. We do not track you across other companies’ apps or websites. We do not sell personal information.

10. How long we keep data

  • Account data — while your account is active, then deleted within [30] days of account deletion.
  • Health and wellness data — until you delete the item or your account.
  • Meal photographs[90] days after processing, then deleted.
  • Purchase records[7] years, as financial records.
  • Device and usage data[X] months.

Bracketed windows are placeholders pending owner confirmation and must be finalized before launch.

11. Security

Data is encrypted in transit with TLS and encrypted at rest. Database records are isolated per account with row-level security, so one account’s records are not reachable from another’s. Your session token is stored in the device Keychain. If a breach of unsecured health data ever occurs, we will notify affected users and the FTC as the FTC Health Breach Notification Rule requires.

12. Your rights

  • Export. Download your data as CSV from Settings in the app.
  • Correction. Edit anything you have logged in the app, or write to us to correct account details.
  • Deletion, per item. Delete any individual meal, symptom, or photograph in the app.
  • Deletion, full account. Delete your whole account in the app or by email — the Delete account page documents both routes.

To exercise a right by email, use the subject line “Privacy Request” (see the Support page). We respond within 45 days. Where reasonably necessary we may take one 45-day extension, and we will tell you before the first window ends. If we decline a request, you may appeal by replying to our decision.

13. Children

Trigger AI is for adults 18 and older. It is not directed at minors, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

14. International transfers

We operate from the United States and store data there. One AI provider processes meal photographs outside the United States, as described in section 6. If you use the app from outside the United States, your information is transferred to and processed in the United States.

15. Changes to this policy

When this policy changes, the updated version is posted on this page with a new [LAST UPDATED] date. For material changes to how health data is handled, we announce the change in the app before it takes effect.

16. Effective date and contact

This policy is effective [EFFECTIVE DATE].

[LEGAL NAME]
[MAILING ADDRESS]
support@triggerai.app

Contact us through the Support page