Legal · Privacy
Privacy Policy
Your health journal is sensitive. This policy explains what stays on your device, what is stored when you sign in, and the controls available to you.
Effective and last updated: July 20, 2026
The short version
- You can explore the app and prepare an automatic draft before signing in. A draft stays on that device for up to seven days, but it is not added to your journal until you sign in and save. Ordinary sign-in alone does not attach an anonymous draft or tracked pattern to the account.
- On the published service, saving a journal entry requires an account. Your journal and any food photos you choose to keep are stored through Supabase so they can appear on your other devices.
- Optional product analytics are off by default. Body Clarify does not use session replay or automatic page-content capture.
- We do not sell health information, use it for advertising, or provide it to data brokers.
Body Clarify is an independent health-journaling project. In this policy, “Body Clarify,” “we,” and “us” refer to the project.
Information we handle
Information you add
This may include food names, ingredients, food and label photos, pain or itch locations and intensity, symptoms, possible triggers, timing, duration, notes, normal-day records, pattern decisions, and tracking preferences.
Account information
If you sign in, Supabase Auth provides an account identifier and the information needed for the sign-in method you choose, such as your email address or Google account identifier. Body Clarify does not receive your Google password.
Messages you send us
If you email us, we receive the sender address, message, attachments, and later correspondence so we can answer the request, verify account ownership when needed, and keep an appropriate record of the response.
Device and service information
The app uses browser storage for automatic drafts, a local journal cache, preferences, duplicate-cleanup choices, and pending offline changes. Necessary technical requests may include an IP address, browser type, device type, timestamps, and error or security information in ordinary hosting logs.
Optional product analytics
If you turn analytics on in Account and privacy, Body Clarify sends a pseudonymous account identifier when you are signed in and limited interaction events such as which section was opened or whether a save succeeded. We do not intentionally include food names, ingredients, symptoms, body regions, notes, photos, email addresses, or report contents in those events.
How we use information
We use information to provide the journal, save and sync entries, restore drafts, create pattern summaries and exports, prevent duplicates, maintain account security, troubleshoot failures, and improve flows when you have chosen to share analytics.
Depending on where you live, the legal basis may be providing the service you requested, your consent for optional analytics, our legitimate interest in securing and maintaining the service, or compliance with law. You may withdraw analytics consent at any time.
Body Clarify looks for associations in self-reported data. It does not use your journal to make medical diagnoses, determine insurance eligibility, or target advertising.
Where information is stored
Before you sign in
An automatic draft and your device preferences may be stored in local or session browser storage. The published service does not add the draft to your journal until you sign in and save it. Clearing browser data, uninstalling the app, using private browsing, or changing browsers can remove or hide this information.
After you sign in
Journal entries and health-related settings such as your working pattern list are stored in Supabase-hosted, Row Level Security-protected tables. Health-related settings are not stored in authentication-token metadata. Food photos are stored in a private Supabase Storage bucket only when photo saving is enabled. The browser also keeps a local cache, and offline changes may wait in IndexedDB on the device until they can sync.
Older device-only logs are not copied into an account automatically. If the app finds them after sign-in, Account and privacy shows the number found and asks you to confirm they belong to you before importing.
Local-only fallback
If a development or self-hosted deployment does not have Supabase configured, the app may disclose a device-only mode and save entries in that browser instead. Device-only records do not sync and can be lost if that browser’s data is cleared.
Account sync is not end-to-end encrypted. Data is protected in transit and by the hosting provider and access-control configuration, but no internet service can guarantee absolute security.
Service providers and external requests
Body Clarify uses service providers only to operate specific features:
- Supabase for authentication, database storage, and private photo storage.
- Google identity services only if you choose Google sign-in. Google confirms your identity to Supabase; Body Clarify does not receive your Google password.
- PostHog for limited product analytics only after you opt in. Autocapture and session recording are disabled.
- Vercel for application hosting and ordinary infrastructure logs.
- Cloudflare for domain services and for routing messages sent to hello@bodyclarify.com to Body Clarify’s chosen destination inbox. The provider of that inbox also processes the forwarded message.
- Open Food Facts when you request a barcode lookup. The barcode number is sent to its public product API; camera frames remain in the browser and are not uploaded by Body Clarify.
These providers may process data in other countries under their own terms. We do not sell personal information or share health-log content for targeted advertising.
Your choices and privacy rights
Inside Account and privacy, you can turn optional analytics on or off, decide whether new food photos are kept, export your records, and delete synced logs and saved photos. “Sign out and clear this device” removes Body Clarify drafts, cached logs, tracked patterns, preferences, and unsynced changes from that browser without deleting records already saved in your cloud account.
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing, withdraw consent, or complain to a privacy authority. Email hello@bodyclarify.com to request authentication-account deletion, ask for privacy help, or exercise a legal right. We may need to verify that the request belongs to you.
Retention and deletion
Incomplete drafts expire after up to seven days. Signed-in journal records and saved photos remain until you delete them, use Delete all logs and photos, or request account deletion. Photo deletion can wait briefly so Undo works; failed cleanup is queued on that device for retry. A local cache or pending offline copy may remain on a device until it syncs, you use the in-app device-clear control, or its browser data is cleared. Limited backups or records may be retained temporarily for security, fraud prevention, legal compliance, or recovery.
Optional analytics records are retained only as long as reasonably needed to understand product use and maintain the service. Turning analytics off stops new analytics events and resets the local analytics identity, but it does not automatically erase events already received. You may request deletion by contacting us.
Support and privacy-request correspondence is kept only as long as reasonably needed to answer the request, document the response, protect the service, and meet legal obligations.
Security and incident response
We use HTTPS, private storage, authenticated access, database Row Level Security, restricted analytics fields, and dependency and release checks. You are responsible for securing your device and account access. If we discover a breach that legally requires notice, we will notify affected users and authorities as required.
Do not put information in Body Clarify that you are not comfortable storing on your device or with the listed service providers.
International use
Body Clarify and its providers may process information in countries other than the one where you live. Those countries may have different privacy laws. Where required, appropriate contractual or legal safeguards should be used for cross-border processing.
Children
Body Clarify is intended for adults aged 18 and older. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so it can be reviewed and deleted.
Changes to this policy and contact
We may update this policy when the product or legal requirements change. Material changes will be identified by a new effective date and, when appropriate, an in-app notice.
Questions, account-deletion requests, or privacy requests: hello@bodyclarify.com.
This policy is a product-facing disclosure, not legal advice. Body Clarify should obtain qualified legal review before a broad commercial launch or expansion into regulated clinical services.