Privacy
Last updated: 2026-07-25. This is an educational tool operated by Lisle Head, open to self-serve registration by adults 18 and over.
What we collect
- Email address and a password hash (for sign-in).
- Profile data you enter: name, date of birth, sex assigned at birth, gender (optional).
- Intake answers: primary goal, hard-block health flags, medications, supplements, training, lifestyle, waiver acceptance.
- Bloodwork files you upload (PDF or image), the structured marker values OCR extracts, and your manual corrections.
- Body weight entries, progress photos, macro inputs and targets.
- Suggestions generated for you and the snapshots they were built against.
- Payment metadata recorded by the admin (amount, method, period — we do not collect or store credit-card data).
- Audit metadata: timestamps, IP address, and user-agent for consequential actions (sign-in, intake submission, lab upload, suggestion generation, payment recording).
Where it lives
Data is stored in Supabase (Postgres + Storage), hosted on AWS in the United States. Files are kept in private buckets with per-user folder isolation enforced at the storage layer. The application is deployed on Vercel.
Who can see it
Only you and the tool administrator (Lisle Head). Row-level security is enabled on every table that contains user data; RLS allows you to select / insert / update / delete only your own rows. The administrator bypasses RLS only for support, debugging, and to record payments. We do not sell, share, or use your data for advertising.
Third parties
- Supabase — database, authentication, file storage. Subject to its privacy policy.
- Vercel — hosting. Subject to its privacy policy.
- Anthropic — Claude API for OCR (bloodwork) and narrative rendering (suggestions). Calls are made server-side; your file content and Bible content are sent to Claude for processing. We use a paid Anthropic plan; under their commercial terms your inputs are not used to train Anthropic models.
- Resend — transactional email (invites, reminders). Subject to its privacy policy.
We use no third-party analytics on pages that show health data. There are no advertising trackers anywhere in the app.
Your rights
You can export every record we have on you at any time from Settings → Account — the export is a JSON file generated server-side. You can also delete your account from the same page; deletion removes auth credentials, cascades all per-user tables, and empties your storage folders. Audit-event records are retained with your user_id detached so we have a record of consequential actions.
Contact
Questions: lisle@lislehead.com.