Low Ox Life

Consumer Health Data Privacy Policy

Version 1.0Last Updated: 5 October 2026Effective Date: 5 October 2026

Big Freight Life LLC (“we”, “us”), the developer of Low Ox Life, publishes this policy for the consumer health data we collect in the app. It is written for Washington’s My Health My Data Act (RCW 19.373), Nevada’s consumer health data law (SB 370, NRS 603A) and Connecticut’s consumer health data law, and we apply it to every user, wherever you live.

Our Privacy Policy (lowoxlife.app/privacy) covers everything else. Where the two differ about consumer health data, this policy applies.

Low Ox Life is not a healthcare provider and is not covered by HIPAA. This policy and the state laws above are what protect the health information you enter.

1. The consumer health data we collect

Everything below is something you enter in the app yourself.

  • Symptoms: the symptom you choose, how bad it was (on a four-step scale), any note you add, and the date and time
  • Notes: anything you write in a journal note, which may describe how you feel, symptoms, medicines or other health details, and the date and time
  • Bathroom breaks: whether each break was BB1 (urination) or BB2 (a bowel movement), and its date and time. Nothing else is recorded
  • Food and drink logs: the foods and drinks you log, the amounts, the meal and the time, with the oxalate figures and daily totals the app works out from them. Because people often track oxalate on a clinician’s advice, these logs may reveal that you manage a health condition such as kidney stones
  • Water and fasting: the water you log, and the start time, end time and goal of each fast
  • Health-related settings: your daily oxalate target, your water goal, and your choices about which data AI features may use
  • Meal photos and meal descriptions you send to an AI feature, if you use one. They are passed to the AI provider and are not stored by us

We do not collect precise location or biometric data, and we do not collect health data about you from anyone else.

2. Why we collect it

We use consumer health data to provide the app to you, and for nothing else:

  • To show you your own history, totals, counts and trends, in the Journal, Today, Insights, your widgets and your Apple Watch
  • To run the features you ask for, including AI features if you turn them on
  • To choose what the app shows you from what you have logged, for example which tip to show, a lower-oxalate food you have eaten before to swap in, and reminders to drink water
  • If you choose to take part in community averages, to count your logged days, without your identity, in the daily averages shown in Insights. This is off unless you agree to it

What we do not do

  • We do not use consumer health data for advertising or marketing, ours or anyone else’s
  • We do not build advertising profiles from it
  • We do not use it to make automated decisions that have legal or similarly significant effects on you

3. Where it comes from

All of it comes from you, entered in the app. We do not buy consumer health data and do not receive it from other companies.

Consent to collect

The app asks for your consent before it saves symptoms, notes or bathroom breaks, on its own screen called “Health information” (version 1.0, effective 5 October 2026), separate from the Terms and the Privacy Policy, with two buttons: “Agree” and “Not now”. It is shown once after you sign in, and you can open it again from the “Turn On…” button the app shows when you try to log a symptom or a bathroom break while your consent is off. Your answer is kept on your device with the date and the version, and a copy is saved with your account when the app can reach our server.

If you choose “Not now”, symptoms, notes and bathroom breaks are not saved, you can keep logging foods, water and fasts, and the screen is not shown again when the app opens. You can agree later from that button or with the switch “Allow logging symptoms, notes and bathroom breaks” in Settings › Privacy & Security › Privacy › Health data, which shows the screen again.

Turning that switch off withdraws your consent straight away. It stops new symptoms, notes and bathroom breaks from being saved. Entries you already logged stay in your account, where you can see, edit or delete them. Bathroom breaks logged on an Apple Watch while your consent is off wait on your iPhone and are saved only if you agree again.

Consent to share

We share consumer health data with AI providers only if you turn on AI features, on the separate “Allow AI features” consent screen. You can turn AI off at any time in Settings › Privacy & Security › AI Data Access, and choose there which data AI may use. Notes and symptoms are included only if you turn on “Journal Notes”, which is off by default.

5. Who we share it with, and why

We do not sell consumer health data, and we do not share it for advertising. Apart from the legal requests and community averages described in this policy, we share it only with the service providers below, and only to run the app. Bathroom breaks are never sent to any AI provider.

Supabase (database host)

  • Why: stores your account and everything you log, so the app works and syncs across your devices
  • Consumer health data it receives: all of the categories above, except meal photos and descriptions
  • Contact: https://supabase.com/privacy

OpenRouter (routes AI requests)

  • Why: passes each AI request to one of the model providers below and returns the answer
  • Consumer health data it can receive, only if you turned on AI features: meal photos and descriptions you send; for Insights, food names and daily oxalate totals, and your notes and symptoms only if Journal Notes is on; your oxalate limit, for recipes and meal suggestions
  • Contact: https://openrouter.ai/privacy

Google (Gemini)

  • Why: the model behind Insights, recipe writing, recipe scanning, meal suggestions and sorting imported lists
  • Consumer health data it can receive, only if you turned on AI features: the Insights and recipe data described under OpenRouter
  • Contact: https://policies.google.com/privacy

OpenAI and Microsoft (Azure OpenAI)

TypeSafe

  • Why: sorts the foods in a list you import, checks which meal a food suits, and checks AI-written recipes
  • What it receives, only if you turned on AI features: food names from your lists and the meal planner, and the title, steps and main ingredient of an AI-written recipe. Never your journal, symptoms, notes or bathroom breaks
  • Contact: https://typesafe.ai/legal/privacy-policy

How AI requests are handled

Requests go through OpenRouter, and only to model providers that OpenRouter lists as not training on your data. Some of these providers may keep a request for a limited time (up to about 55 days) for abuse monitoring. If no such provider is available, the request fails.

We do not store the photos or descriptions you send. We cannot delete a copy a provider has kept.

Providers that receive no consumer health data

Legal requests

  • We disclose consumer health data to someone else only when the law requires it, and then only what is required

6. Your rights and how to use them

You have these rights wherever you live:

  • Confirm and access: find out whether we collect, share or sell your consumer health data, and get a copy of it. We do not sell it
  • Know who received it: the recipients are listed in this policy with a contact for each; ask us and we will confirm them in writing
  • Delete: have your consumer health data deleted
  • Correct: fix inaccurate data
  • Portability: get your data in a format you can take elsewhere
  • Withdraw consent: to collection and to sharing, separately, at any time (see “Your consent”)
  • No penalty: using any of these rights costs nothing and does not change your price or the features you get, other than features that need the data you asked us to stop using

In the app, with no request needed

  • Get a copy (access and portability): Settings › Privacy & Security › Privacy › Download My Data (JSON or CSV)
  • Correct: edit any entry in the Journal
  • Delete: delete any entry in the Journal, or delete your account and its data in Settings › Delete Account, except a record of the deletion and a few records that are no longer linked to you (such as Apple’s sign-in notices)
  • Withdraw consent to collect: turn off the switch in Settings › Privacy & Security › Privacy › Health data
  • Withdraw consent to share: turn AI off in Settings › Privacy & Security › AI Data Access

By email

Write to privacy@bfl.design with the subject “Consumer Health Data Request”, the email address on your account and what you want us to do. We check that the request comes from you, usually by confirming the account email. We respond within 45 days. If we need more time, we may extend that once by another 45 days, and we will tell you why within the first 45 days.

What deletion covers

  • Deleting your account deletes your consumer health data from our database straight away
  • Copies in our database host’s backups expire on their own schedule and are not restored into the app
  • A copy an AI provider may have kept for abuse monitoring (see above) expires on that provider’s schedule; we cannot delete it
  • We keep a record of the deletion itself (the email address, the time, and the IP address and device type of the request) as evidence that it was carried out

7. Appealing our answer

If we refuse a request, we will tell you why and how to appeal. To appeal, reply to our answer or write to privacy@bfl.design with the subject “Consumer Health Data Appeal”. We answer an appeal in writing within 45 days.

If we refuse your appeal, you may complain to your state attorney general. In Washington: https://www.atg.wa.gov/file-complaint. In Nevada: https://ag.nv.gov. In Connecticut: https://portal.ct.gov/ag.

8. How long we keep it

  • Until you delete it or your account
  • You can have journal entries older than a period you choose deleted automatically, in Settings › Health & Data › Data Management. This is off unless you turn it on
  • An account that is not used for 12 consecutive months is deleted, as our Privacy Policy describes; nothing is deleted for inactivity before 26 September 2027

9. How we protect it

  • Encryption in transit and at rest
  • Database rules that let each account read and change only its own data
  • An optional Face ID lock in the app
  • No system is perfectly secure, and we do not claim that ours is

If there is a breach

If a breach of security affects your consumer health data, we will notify you without unreasonable delay and in any case within 60 calendar days, and to the Federal Trade Commission when 500 or more people are affected, as the FTC Health Breach Notification Rule requires.

10. Children

Low Ox Life is not for children under 13, and people aged 13 to 17 may use it only with a parent or guardian’s permission. The app does not ask for a date of birth. We do not knowingly collect consumer health data from children under 13; if we learn that an account belongs to one, we delete the account and its data. A parent or guardian may ask to review or delete a minor’s data at privacy@bfl.design.

11. Changes to this policy

If we change how we collect, use or share consumer health data, we will update this policy and its effective date, and ask for your consent again where the law requires it.

Contact

Consumer health data requests
privacy@bfl.design
Mail
Big Freight Life LLC, 1351 N Buckner Blvd #180397, Dallas, TX 75218, USA

Last Updated: 5 October 2026Version: 1.0Effective Date: 5 October 2026