Low Ox Life
Privacy Policy
What changed in this version
- Health information (symptoms, notes and bathroom breaks) is now described as a separate choice, with its own consent and a switch in Settings
- AI requests: some AI model providers may keep a request for up to about 55 days for abuse monitoring, and Microsoft (Azure OpenAI) is named as a provider
- New sections on your rights under Washington, Nevada, Connecticut and other state privacy laws, and for users in Canada
- Our Consumer Health Data Privacy Policy is now published separately, at lowoxlife.app/consumer-health-data
- The protections our service providers give your data, and when we notify you of a breach, are stated
- Requests are answered within 45 days; Open Food Facts is named as receiving your IP address, and the website serves its own fonts
- A plain-English summary now opens each section
- How we respond to Do Not Track and Global Privacy Control signals is stated
- California: how each kind of information is used and kept, how an authorized agent can make a request for you, and a “Shine the Light” notice
Big Freight Life LLC (“we”, “us”), the developer of Low Ox Life, is committed to protecting your privacy and ensuring the security of your personal health information.
Data Controller:
Big Freight Life LLC
1351 N Buckner Blvd #180397
Dallas, TX 75218
United States
1. Information We Collect
In plain English: We collect only what the app needs: your sign-in details from Apple, what you log (food, water, symptoms, notes, bathroom breaks, fasting), your subscription status, and basic device details for notifications and security. Symptoms, notes and bathroom breaks are saved only after you agree to a separate health information consent.
Personal Information
- Name, as provided by Sign in with Apple or entered by you
- Email address. If you use Sign in with Apple’s “Hide My Email”, this is the private relay address Apple gives us
- Your device’s time zone, sent with some requests so that entries are grouped into the right days. It is not stored
Health Information
Our Consumer Health Data Privacy Policy, published at lowoxlife.app/consumer-health-data, describes the health information you log (symptoms, notes, bathroom breaks and food logs), who receives it, and your rights over it.
- Food journal entries: the foods, amounts and times you log
- Water you log
- Symptoms (type and severity) and notes you write in the journal
- Bathroom breaks you log (BB1 or BB2, and the time)
- Fasting sessions: start and end times, and the goal you set
- Your daily oxalate target, water goal and serving preferences
- Food lists you create or import, recipes you save or create (including any recipe photos you add), meal plans and grocery lists
- Saved favourite meals: a name you choose and the foods and serving sizes in it. No oxalate figure is stored with a saved meal; it is worked out from the foods each time
Awards
- Your progress toward each in-app award, the awards you have earned, and your logging streaks and milestones. The app works these out from what you log and stores them with your account; they are deleted with it
Subscription Information
- Your subscription tier and when it renews or ends
- The subscription transactions Apple signs for your purchase (product, transaction identifiers, expiry and any refund), which the app and Apple’s own App Store notifications send to our server so that we can confirm a subscription is paid. We never receive your card or payment details
Device Information
- A device identifier, device name and model, and iOS version, used to alert you when your account signs in on a new device
- Your Apple push notification token, with the app and iOS version, to send notifications
Usage Information
- Crash reports and diagnostic data, through Firebase Crashlytics. These carry no account identifier and no journal content
- A count of your AI requests (which feature, and when) so that we can apply usage limits. The count does not include what you sent
- The app uses no third-party analytics or advertising tools
Feedback You Send
- What you write and the topic you pick when you use Settings › Send Feedback, linked to your account so that we can look into it
- If you leave “Include app version and device” on (the default), the app version, iOS version and device model with it. Your name, email and journal are not attached
- Feedback is deleted with your account
2. How We Use Your Information
In plain English: We use your information to run the app: track oxalate, sync your devices, send reminders and tailor tips. AI features are off until you turn them on, and each one sends only what it needs.
Service Provision
- Personalized oxalate tracking and dietary management
- Health insights and pattern analysis
- Reminders and notifications
- Cross-device data synchronization
- Looking up products you scan by barcode (see Section 3)
- We use your journal to personalise what the app shows you, for example tips, suggestions and reminders
AI Processing
AI features are off until you allow them. The app asks before the first AI feature is used, and you can decline and keep using everything else. You can turn AI off at any time in Settings › Privacy & Security › AI Data Access. While it is off, nothing is sent to an AI provider.
When AI is on, each feature sends only what it needs:
- Food photos and described meals: the photos of a meal you take or choose, or the description you type or dictate, to identify the foods and estimate amounts. Dictation uses Apple’s speech recognition: on devices that support it, the audio stays on your device; otherwise Apple processes it under its own privacy policy. Only the resulting text is sent. The AI returns food names and amounts only; every oxalate figure comes from the app’s own food data. Photos and descriptions are not stored by us
- Recipe scanner: the text of a recipe you photograph. The text is read from the photo on your device, and only the text is sent
- Recipe creation and meal suggestions: what you ask for, the number of servings, the meal type, your oxalate limit, and the names of candidate foods the app has picked
- Insights: a summary of the last few weeks of your journal (daily oxalate totals and food names). Your symptoms and notes are included only if you turn on “Journal Notes”, which is off by default
- Food list import: the food names in a list you import, to sort them into categories
Our servers send each request to OpenRouter, which passes it to a model from Google (Gemini), OpenAI, Microsoft (Azure OpenAI, which can serve OpenAI’s models) or TypeSafe. Requests go through OpenRouter, and only to model providers that OpenRouter lists as not training on your data. Some of these providers may keep a request for a limited time (up to about 55 days) for abuse monitoring. If no such provider is available, the request fails. AI responses are for education, not medical advice.
Service Improvement
- Bug fixing and crash resolution
- Anonymous community averages (see Section 3)
3. Information Sharing
In plain English: We don’t sell your information and we use no advertising or tracking services. We share it only with the service providers that run the app, with AI providers if you allow AI, when the law requires it, and in anonymous community averages if you choose to take part.
We do not sell your personal information, and we do not use advertising or tracking services.
Limited Sharing
We may share your information only in the following circumstances:
- With your explicit consent, including the AI features in Section 2
- Legal obligations: When required by law or legal process
- Service providers: Third parties who help us operate the app, listed below
- Anonymous community averages: Only if you choose to take part, your logged days are counted in daily averages shown in Insights. Taking part is off unless you agree to it. No identities are stored with the averages, an average is shown only when at least 10 people contribute to it, and a food is listed only if at least 5 people logged it
Third-Party Services
Apart from disclosures the law requires and the anonymous community averages described above, we share personal data only with the service providers named in this policy, and only to run the app. Our database host (Supabase), our email sender (Resend) and our crash reporter (Google Firebase Crashlytics) process it under data-processing agreements that require them to use it only on our instructions, to keep it secure, and to tell us about breaches. Those protections are at least as strong as the ones this policy describes.
- Supabase: Database hosting and authentication, in the United States
- OpenRouter, Google (Gemini), OpenAI, Microsoft (Azure OpenAI) and TypeSafe: AI processing, only if you allow AI features (see Section 2). See OpenRouter’s Privacy Policy
- Open Food Facts and USDA FoodData Central: When you scan a barcode, the barcode number is sent to Open Food Facts, and if it is not found there, through our server to the USDA. As with any request over the internet, Open Food Facts also receives your phone’s IP address. Nothing else about you is sent
- Apple: Sign in with Apple, App Store subscriptions, push notifications, and syncing some app preferences through your own iCloud account. Apple also tells our server when you stop using Sign in with Apple with this app, delete your Apple Account, or turn email forwarding for a Hide My Email address off or on. We record each notice (the identifier Apple uses for you with this app, what happened and when), and on the first two we sign you out of the app without deleting anything. These records are kept after your account is deleted, no longer linked to it
- Firebase Crashlytics: Crash reports without your name, email or account ID. See Firebase Privacy Policy
- Resend: Sends the email confirming that your account was deleted
Bio Break, Widgets and Apple Watch
- Bio Break: If you log bathroom breaks (BB1 for urination, BB2 for a bowel movement), Low Ox Life stores only the kind and the time of each, in your journal with your account, like the foods you log. They are health information. They appear in your Journal, counts and Insights, and in your widgets and on your Apple Watch. They are never sent to an AI provider, never sold, and never used for advertising. You can edit or delete any break, and deleting your account deletes them
- Widgets and Apple Watch: The app writes a short summary (today’s oxalate budget, water and any running fast) to storage on your iPhone for its widgets, and sends the same summary directly to your paired Apple Watch
4. Data Security
In plain English: Your data is encrypted in transit and at rest, each account can reach only its own data, and you can lock your health data with Face ID. If a breach affects you, we will tell you without unreasonable delay and within 60 days.
Technical Measures
- Encryption at rest: Stored data is encrypted by our database host
- Encryption in transit: TLS for all data transmission
- Account isolation: Database rules allow each account to read and change only its own data
- Key management: Sign-in credentials are kept in your device’s Keychain, and AI provider keys are held only on our servers
Access Controls
- Sign in with Apple
- Optional Face ID lock for your health data
- Alerts when your account signs in on a new device
If There Is a Breach
If a breach of security affects your data, we will notify you without unreasonable delay and in any case within 60 calendar days, and to the Federal Trade Commission when 500 or more people are affected, as the FTC Health Breach Notification Rule requires. No system is perfectly secure.
5. Data Retention
In plain English: We keep your data while your account exists, and you can export or delete it at any time. An account that goes unused for a year is deleted after two warning emails, but never one with an active paid subscription.
Active Accounts
- Data is retained while your account exists
- You can choose to have journal entries older than a set period deleted automatically, in Settings › Health & Data › Data Management. This is off unless you turn it on
- You can export your data (Settings › Privacy & Security › Privacy › Download My Data), and delete your account and its data (Settings › Delete Account), at any time, except a record of the deletion and a few records that are no longer linked to you (such as Apple’s sign-in notices). Deletion takes effect immediately; copies in our database host’s backups expire on their own schedule
- When an account is deleted we keep a record of the deletion (the email address, the time, and the IP address and device type of the request) as evidence that it was carried out
When a Subscription Ends
- Nothing is deleted
- Your journal, food lists and other saved data stay in your account, and you can still view them in the app (read-only)
- You can resubscribe at any time and carry on where you left off
Inactive Accounts
- One year: An account that is not used for 12 consecutive months is deleted, with its data. “Used” means signing in, opening the app while signed in, or saving anything to the account
- The year is counted from the latest of the last time the account was used, the day its subscription ended, and September 26, 2026. An account with an active, paid subscription is never deleted for inactivity
- Warnings: Before an account is deleted for inactivity, we will email a warning to the address on the account 30 days and again 7 days before the deletion. Using the account at any point before then cancels the deletion and starts the year again
- This rule started with version 3.1 of this policy, on September 26, 2026. No account can be deleted for inactivity before September 26, 2027
AI Requests
- Photos, descriptions and other content sent to AI features are not stored by us. They go only to model providers that OpenRouter lists as not training on your data; some of these providers may keep a request for a limited time (up to about 55 days) for abuse monitoring
- AI results shown in Insights are kept on your device, not on our servers
6. Cookies & Tracking
In plain English: The app uses no cookies, no advertising ID and no tracking across other apps or websites. Our website sets no cookies.
What the App Stores
- The app uses no cookies
- Your sign-in session, kept in your device’s Keychain
- Your preferences and cached data, kept on your device
What We Don’t Do
- No advertising identifier (IDFA) and no App Tracking Transparency requests
- No advertising services and no third-party analytics
- No cross-app or cross-site tracking
- No behavioral advertising
Do Not Track and Global Privacy Control
Some browsers and devices send a Do Not Track or Global Privacy Control signal. The app and the website do not track you across other apps or websites, and we do not sell or share personal information, so there is nothing for these signals to switch off. We treat a Global Privacy Control signal as a request to opt out of sale and sharing, and we honor it by doing what we already do for everyone.
Our Website
- Our website, lowoxlife.app, serves its own fonts and loads nothing from other companies, and our web host (Vercel) receives your IP address with each request. The website sets no cookies and uses no analytics or advertising tools
7. Children’s Privacy (COPPA)
In plain English: Low Ox Life is for people 13 and older, and people 13 to 17 may use it only with a parent or guardian’s permission. We don’t knowingly collect data from children under 13.
Age Requirements
- Under 13: The app is not for children under 13
- Ages 13 to 17: May use the app only with a parent or guardian’s permission
How We Handle Age
- The app does not ask for your date of birth
- We do not knowingly collect personal information from children under 13
- If we learn that an account belongs to a child under 13, we delete the account and its data
Parents and Guardians
- Parents and guardians can use the rights below by contacting us
Parental Rights
- Review: Request to see your child’s data
- Delete: Request deletion of your child’s data
- Refuse: Decline further data collection
- Opt-out: Remove your child from the service
- Access: Obtain a copy of collected data
Enhanced Privacy for Minors
- No advertising of any kind, for any user
COPPA Requests: Email privacy@bfl.design with subject line “COPPA Request”
8. International Data Transfers
In plain English: Our servers are in the United States. If you turn on AI features, requests may be processed in other countries.
- Primary servers: Located in the United States
- AI providers: If you allow AI features, requests may be processed by OpenRouter and the model providers in other countries
- AI processing location: Requests to AI providers may be processed outside the US or Canada under those providers' terms.
9. California Privacy Rights (CCPA/CPRA)
In plain English: California residents can ask to know, delete or correct their information and to limit use of sensitive information. We don’t sell or share personal information.
Your Rights Under California Law
- Right to Know: What personal information we collect and how it’s used
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt-out of sale or sharing of personal information
- Right to Limit: Limit use of sensitive personal information
- Right to Non-Discrimination: Equal service regardless of privacy choices
Categories of Information Collected
- Identifiers: Name, email, device identifiers, push notification token, and the device model, iOS version and app version stored with them
- Commercial Information: Subscription status and Apple-signed subscription transactions
- Health Information: Food, water, symptom, note, bathroom-break and fasting logs, and your targets
- Internet Activity: Crash diagnostics and counts of AI requests
- Feedback: Messages you send us from the app
- Audio or Visual Information: Recipe photos you save. Meal photos you send to an AI feature are passed to the AI provider and are not stored by us
- Inferences: Health patterns and dietary insights
- Sensitive Personal Information: Health data (with consent)
How We Use and Keep Each Category
- Identifiers and Commercial Information: To provide and secure the app, confirm your subscription, send notifications, alert you when your account signs in on a new device, and email you that an account was deleted.
- Health Information and Inferences: To provide the features you use: tracking, Insights, reminders and tips. Only if you allow AI features, the part each feature needs is sent to an AI provider to process that request.
- Internet Activity: To fix crashes and apply AI usage limits.
- Feedback: To read and respond to what you send.
- Audio or Visual Information: To show the recipe photos you save. A meal photo you send to an AI feature is used only to identify the foods in it and is not stored by us.
- Sensitive Personal Information: Only to provide the app’s features to you. We do not use it for advertising or for any other purpose, so there is nothing further for you to limit.
- How long we keep each category: While your account exists. It is deleted when you delete your account, except the records Section 5 describes.
Important: We do not sell personal information and do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the past 12 months.
How to Exercise Your Rights
- Email: privacy@bfl.design
- Subject line: “CCPA Request”
- Response time: 45 days, extendable once by another 45 days
Requests Through an Authorized Agent
You may ask a person or business you have authorized to make a request for you. We will ask for your written permission, or a power of attorney, and may confirm your identity with you directly before we act.
California “Shine the Light”
We do not disclose personal information to third parties for their own direct marketing. California residents may ask us about this at privacy@bfl.design.
10. Your Rights if You Live in Washington, Nevada, Connecticut or Another State With a Privacy Law
In plain English: If you live in Washington, Nevada, Connecticut or another state with a privacy law, you can ask for a copy of your data, a correction or deletion, withdraw consent, and appeal if we refuse.
Your Rights
- Access: confirm whether we process your personal data, and get a copy of it
- Delete: have your personal data deleted
- Correct: have inaccurate personal data corrected
- Portability: get your data in a format you can take elsewhere
- Withdraw consent: withdraw any consent you gave, including the health information and AI consents
- Opt out of targeted advertising, the sale of personal data, and profiling that has legal or similarly significant effects. We do none of these
How to Ask
- In the app: get a copy in Settings › Privacy & Security › Privacy › Download My Data; correct or delete any entry in the Journal; delete your account and its data in Settings › Delete Account, except a record of the deletion and a few records that are no longer linked to you (such as Apple’s sign-in notices)
- By email: write to privacy@bfl.design with the subject “Privacy Request”. We check that the request comes from you, usually by confirming the account email
- We respond within 45 days. If we need more time, we may extend that once by another 45 days, and we will tell you why within the first 45 days
- Appeal: if we refuse a request, reply to our answer or write to privacy@bfl.design with the subject “Privacy Appeal”. We answer an appeal in writing within 45 days. If we refuse your appeal, you may contact your state attorney general
- For health information, our Consumer Health Data Privacy Policy (lowoxlife.app/consumer-health-data) gives the details
11. If You Are in Canada
In plain English: In Canada, we ask for your express consent before collecting health information. Your data is stored in the United States, and you can complain to the Office of the Privacy Commissioner of Canada.
- Express consent: the app asks for your express consent before it collects health information, on its own “Health information” consent screen, and separately before it sends anything to an AI provider
- Where your data is: it is stored in the United States, in our database host’s US East region
- AI requests: if you turn on AI features, requests may be processed outside Canada, by OpenRouter and the model providers described in this policy
- Your rights: you may ask to access your personal information, correct it, and withdraw your consent, as described above
- Complaints: you may complain to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca)
- Contact: privacy@bfl.design
12. European Privacy Rights (GDPR)
In plain English: If you are in the EU or EEA, you can ask to access, correct, delete, move or restrict your data, and you can complain to your local data protection authority.
Legal Basis for Processing
- Consent: For health data and optional features, including AI
- Contract: To provide the services you’ve requested
- Legitimate Interests: For security, fraud prevention, and service improvement
Additional Rights for EU/EEA Users
- Right to Lodge a Complaint: With your local data protection authority
- Right to Withdraw Consent: At any time, without affecting prior processing. For AI, turn it off in Settings › Privacy & Security › AI Data Access
- Right to Transparency: Clear information about data processing
13. Your Data Rights
In plain English: You can see, correct, export or delete your data from the app, or ask us by email. We answer within 45 days.
Rights Available to All Users
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (“right to be forgotten”), or delete your account yourself in the app
- Portability: Receive your data in a portable format, or export it from the app
- Object: Object to certain types of processing
- Restrict: Limit how we process your data
How to Exercise Your Rights
- Support Portal: lowoxlife.app/support
- Response Time: Within 45 days. If we need more time, we may extend that once by another 45 days and will tell you why
Contact Us
- Support Portal
- lowoxlife.app/support
- Privacy Inquiries
- privacy@bfl.design
- Mailing Address
- Big Freight Life LLC
1351 N Buckner Blvd #180397
Dallas, TX 75218, USA