Privacy Policy
Last updated: September 3, 2026
Introduction
At Supplepedia, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and mobile application (collectively, the "Service").
Information We Collect
Account Information
When you create an account, we collect:
- Name and email address
- Authentication credentials (managed securely by our authentication provider)
- Profile preferences and display name
Supplement and Health Goal Data
- Supplements you track in your stack
- Health goals and progress tracking data
- Questionnaire responses for personalized recommendations
- Community posts, ratings, and reviews you submit
Usage Information
- Device type, operating system, and app version
- Pages visited and interaction patterns
- App performance and crash data
Subscription Information
If you subscribe to Supplepedia Premium through our mobile app, your subscription status, plan type, and expiration date are stored to manage your access to premium features. We do not collect or store your payment card details, billing address, or other financial information. All mobile in-app payments are handled directly by Apple (App Store) or Google (Google Play Store).
If you subscribe to a practitioner plan on the web, payments are processed by Stripe. We store your Stripe customer ID, subscription ID, plan tier, status, and renewal dates. We do not store your full payment card number. Stripe holds card details directly.
Practitioner Profile Data
If you create a practitioner account, we additionally collect:
- Practice name, practice type, professional title, and (optionally) bio, website, city, and state
- Contact email used for patient-facing communications
- NPI (National Provider Identifier), stored encrypted at rest and never written to application logs
- Notification preferences for protocol imports and adherence reports
Practitioner-Shared Data
When you (a patient/user) import a practitioner's protocol, the practitioner who created that protocol can see your display name and that you imported the protocol, along with the import timestamp, and adherence reports you choose to send to the practitioner. You control whether to send a report.
Practitioners do not see your account email, address, payment information, or any data outside the protocols you have imported. You can revoke a practitioner's access to a protocol at any time from the app. Adherence summaries are generated from your logs each time your practitioner views them, rather than stored as separate reports. Revoking access stops those summaries immediately, and your underlying logs are retained as described in Data Retention below.
How HIPAA applies depends on how you use Supplepedia. If you use it on your own to track supplements and goals, that is consumer wellness information you created for yourself, and HIPAA does not generally apply to it.
If you work with a practitioner through Supplepedia, that changes. Your practitioner may record clinical notes about you, exchange messages with you, request validated health assessments, and review your logs as part of your care. That information can be Protected Health Information under HIPAA, and your practitioner is the covered entity for it.
Practitioner relationships run at one of two levels. In a clinical engagement, which is the default when a practitioner invites you, Supplepedia acts as your practitioner's business associate and handles that information on their behalf, under an agreement their practice must have in place before the invite can be sent or accepted. A practitioner can instead choose a protocol-sharing-only relationship, where the clinical features are switched off and only your protocol and adherence data are shared. We do not act as a business associate for that lighter arrangement, and practitioners whose use involves Protected Health Information are required to use the clinical engagement instead. Clinical fields are encrypted at rest under a key held separately from the database, and access to them is recorded in an audit log that cannot be altered afterward.
Third-Party Services
We use the following third-party services to operate the Service:
- Clerk: authentication and account management. Clerk processes your email and login credentials securely.
- Apple App Store / Google Play Store: in-app purchase and subscription payment processing. We do not receive or store your payment details.
- Stripe: payment processing for web-based practitioner subscriptions. Stripe receives your card details and billing information directly; we receive only a customer ID, subscription metadata, and payment status.
- Loops: transactional and inquiry email delivery. We send Loops your email address, name, and (for practitioners) practice metadata in order to deliver account, subscription, and adherence-summary emails.
- Flex (withflex.com): third-party telehealth provider that issues Letters of Medical Necessity (LMNs) for HSA/FSA-eligible purchases. If you click through to Flex from our site, you are interacting with Flex directly under their terms; we do not transmit your account or health data to Flex.
- Sentry: error and crash reporting to improve app stability. Error reports are anonymized and do not contain personally identifiable information such as IP addresses by default.
- Neon: cloud database hosting for storing your account and supplement data.
- Amazon Web Services: AWS Cognito provides sign-in on our newer authentication system as we migrate away from Clerk, holding your email address, name, and multi-factor authentication settings. We have also built support for storing encrypted backups with AWS, but it is not switched on today; backups currently stay on the application host.
- Fly.io: application hosting and compute. Every request you make is processed on Fly infrastructure, so your data passes through it in the course of using the Service.
- Cloudflare: DNS for our domain, and content delivery for the www and payment subdomains. As of August 17, 2026 the main site and API no longer pass through Cloudflare, so it does not see the content of your requests or responses to the app. If you reach the site by typing www, Cloudflare handles the redirect and sees the web address you asked for, though not the page content.
- OpenAI: powers the in-app AI assistant. Anything you type into the assistant is sent to OpenAI to generate a response, so please do not enter information you would not want processed by a third-party AI provider. The assistant is turned off entirely for practitioners and for any patient following a protocol shared by a provider, because we do not have a Business Associate Agreement with OpenAI.
- Expo: delivers push notifications to your device. Notification titles and bodies use generic wording by default so health details do not appear on your lock screen or pass through the notification relay.
- Meta (Facebook): website advertising measurement only. The Meta Pixel may collect advertising data after you consent via our cookie banner. The iOS app does not include the Meta SDK and does not send device identifiers or app events to Meta.
- Google Analytics: website analytics to understand traffic sources, page views, and user engagement on our website.
Advertising and Tracking
We use advertising tools to measure the effectiveness of our marketing campaigns and to deliver relevant ads to users who may be interested in our Service.
Mobile App (iOS)
The iOS app does not track your activity across other companies' apps and websites. It does not include the Meta advertising SDK, does not access the Identifier for Advertisers (IDFA), and does not present Apple's App Tracking Transparency prompt.
Crash and performance reports may be sent to Sentry so we can keep the app stable. That data is used for diagnostics, not for advertising, and is not linked with third-party data for tracking.
Android
The Android app does not currently send advertising identifiers or app events to Meta. If we enable advertising measurement in a future release, you can opt out of personalized advertising in your device settings under Google > Ads.
Website
Our website uses the Meta Pixel and Google Analytics for advertising measurement and website analytics. These tools use cookies and similar technologies. On our website, these tracking tools are only activated after you provide consent via our cookie consent banner. You can withdraw consent at any time by clearing your cookies or using your browser's privacy controls.
How We Use Your Information
- To provide and maintain the Service, including your supplement stack and progress tracking
- To provide personalized supplement recommendations
- To manage your subscription and premium feature access
- To enable community features (posts, ratings, discussions)
- To improve our services, fix bugs, and enhance the user experience
- To communicate with you about your inquiries or account
Data Sharing
We do not sell your personal information to third parties. We share data with the third-party service providers listed above for the purpose of operating the Service and improving user experience. On the website, advertising measurement tools may share limited data with Meta after you consent, as described in the "Advertising and Tracking" section. The iOS app does not share device identifiers or app events with Meta. We may also disclose information if required by law or to protect our rights.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it by law. While your account is active, your supplement and progress logs are retained indefinitely so your history and trends stay available to you. Deleting your account removes them. Subscription billing records may be retained longer where required for tax or accounting compliance.
Data Storage and Security
We implement appropriate technical and organizational measures to maintain the security of your personal information, including encryption in transit and at rest. Measures currently in place include:
- Encryption in transit (HTTPS with HSTS) and AES-256-GCM encryption at rest for sensitive health fields, under a key separate from the database.
- Database backups are encrypted with a distinct key, and encryption cannot be disabled in production.
- Practitioner and administrator sessions time out automatically after a period of inactivity, and the session cannot be resumed afterward without signing in again. Background activity such as a page refreshing on its own does not count as activity.
- Sensitive account changes, such as turning off multi-factor authentication or changing your email address, require you to have signed in recently. Changing your password signs out your other devices.
- An audit log records access to health records and cannot be edited or deleted after the fact.
- Notification content is generic by default, so health details do not appear on a locked screen.
However, no Internet-based service can be 100% secure, and we cannot guarantee the absolute security of your data.
Data Protection Rights (GDPR)
Under GDPR, users in the European Union have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
To exercise any of these rights, including requesting an export of your personal data, please contact us at kacey@thesupplepedia.com. We will respond to your request within 30 days.
California Privacy Rights (CCPA)
California residents have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Say no to the sale of personal information
- Access their personal information
- Request deletion of their personal information
- Equal service and price, even if they exercise their privacy rights
Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us so we can delete it promptly.
Third-Party Links
Our website and mobile application contain links to third-party websites, including Amazon affiliate links. We are not responsible for the privacy practices or content of these third-party sites.
Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
Contact Us
For any questions about this Privacy Policy, to exercise your data rights, or to request deletion of your account data, please contact us at: kacey@thesupplepedia.com