Privacy Policy — Weight Pocket

Effective date: September 4, 2026

Version: 2.0.0 — Last updated: September 4, 2026

1. Who we are and how to reach us

Weight Pocket is operated by JP Medicina de la Montaña LLC ("we", "us"). We are the data controller for the information described here.

  • Mailing address: Urb Estancias del Golf, 121 Calle Miguel Rivera Texidor, Ponce, Puerto Rico 00730, USA
  • Privacy contact: support@weightpocket.com
  • Data Protection Officer: we have not appointed one, because our processing does not require it. Privacy questions go to the contact above.
  • EU/UK representative (GDPR Art. 27): we have not designated one. If we become required to, we will designate a representative and update this policy.

Weight Pocket is an educational coaching and wellness tool. It is not a medical device, not telemedicine, and not a healthcare provider. Using the app does not create a doctor-patient relationship with us. Decisions about your health, your treatment and your medication stay between you and your own licensed healthcare provider.

2. Who this policy covers

This policy applies to:

  • Members who use the app on their own.
  • Members connected to an educator (coach) through the app.
  • Educators / coaching staff who use the staff side of the app.

Age. Weight Pocket is for people 16 and older. The app asks your age during sign-up and blocks accounts below that minimum, the profile editor applies the same minimum, and the server enforces it too: the database rules require an age between 16 and 120 on both create and update, so the check does not depend on the app alone. We store your age in years, never your date of birth, and if a legacy date-of-birth field exists we delete it the next time you edit your profile.

We do not knowingly collect data from anyone under 16. If we learn that an account belongs to someone under 16, we delete the account and its data.

3. What we collect

We collect only what the features you use need.

  • Account and identity — email, account ID, display name, profile photo, age in years, sex, height, city, time zone. From you, at sign-up with Apple or Google. Purpose: run your account. Legal basis: contract.
  • Profile and goals — calorie, protein, fat, carb, step and water goals. From you. Purpose: personalise your targets. Legal basis: contract.
  • Weight and body measurements — current, starting, goal and treatment-start weight; morning weight and body measurements in the daily log. From you, or from a scale or smart tape you connect. Purpose: track progress. Legal basis: explicit consent (Art. 9(2)(a)).
  • Daily log — energy, symptoms and their intensity, free-text notes, pain, injection reactions. From you. Purpose: show trends and support coaching. Legal basis: explicit consent.
  • Nutrition and meals — meals, macros and water, stored per day. From you, your camera or a barcode. Purpose: log food and compute goals. Legal basis: explicit consent.
  • Medication and injections — medication type, dose, brand, status and schedule; a dose history; the dose and the injection site in the daily log. From you. Purpose: reminders and dose history. Legal basis: explicit consent.
  • Exercise and activity — exercises, steps and active minutes. From you, or from your device's health platform. Purpose: track activity. Legal basis: explicit consent.
  • Device health data — steps, sleep, heart rate, resting heart rate, heart rate variability and body weight, stored as one snapshot per day. From your device (Apple Health or Health Connect), with your permission. Purpose: fill in activity and recovery. Legal basis: explicit consent.
  • Behaviour and engagement signals — in-app events with timing-only metadata, learned daily routines, streaks, and which coaching insights you have already seen. Derived in the app. Purpose: nudges, streaks and coaching lines. Legal basis: legitimate interest or consent.
  • Photos — your profile photo and any screenshot you attach to a feedback report are stored on our servers and readable only by you; meal and product photos stay on your phone only. From your camera or library. Purpose: food recognition, profile, support. Legal basis: explicit consent.
  • Subscription data — your account ID, the product you bought and the store receipt, handled by RevenueCat; plan and renewal fields are written only by our server. From the App Store or Google Play. Purpose: manage your plan. Legal basis: contract.
  • Device and technical data — notification token, approximate city, and AI usage counters keyed to a hashed account ID. From your device. Purpose: deliver notifications, security and quality. Legal basis: legitimate interest.
  • Diagnostics — crash reports and screen-view events, off unless you turn them on. From your device, only if you opt in. Purpose: fix bugs. Legal basis: consent.
  • Consent records and audit trail — the consent type, the date and the policy version you accepted, in your account and in our audit trail. From the app, when you accept something. Purpose: prove we asked. Legal basis: legal obligation.

We never ask for your card number. Payments are handled by the App Store or Google Play, and receipt validation by RevenueCat (§8).

Location. We do not collect precise GPS location. We ask for approximate location, only while you are using the app, and only to fill in your city. On Android the precise-location permission is actively removed from the app.

4. Health data, Apple Health and Health Connect

Health data is the heart of this app, and it gets the strictest treatment.

  • We use it only to run the features you use and, if you connected an educator, to show it to that educator.
  • We never sell it. We never use it for advertising — the app contains no advertising, attribution or cross-app tracking SDK, and its Apple privacy manifest declares no tracking. We never use it for insurance, underwriting, employment screening or credit decisions.
  • We never combine it with data from sources unrelated to the app's health features.
  • It is never sent to our AI providers: the requests we send them carry no steps, sleep, heart-rate, HRV or weight field.

If you connect Apple Health (iOS) or Health Connect (Android), we read exactly six data types and nothing else: steps, sleep, heart rate, resting heart rate, heart rate variability and body weight.

We only read. We never write anything back to Apple Health or Health Connect. On iOS we request authorisation with an explicitly empty write list; on Android every permission we request is read-only. iOS also requires us to declare a write purpose string; ours says, literally, that the app does not write data to Health.

We do not read your health data in the background. Background delivery is switched off and the corresponding iOS entitlement is deliberately left out, so every read happens while the app is open in front of you. In practice that is one snapshot per calendar day.

If Health data is unavailable, your steps can be counted by your device's own pedometer, with your permission.

You can revoke that permission at any time in your system settings — iOS: Settings → Health → Data Access & Devices → Weight Pocket; Android: Settings → Apps → Health Connect → App permissions. Revoking stops new data from flowing in. Data already synced is removed when you delete your account (§10).

5. Medication and other sensitive information

If you track a GLP-1 or any other medication, we store what you enter: the medication type, dose, brand, status and schedule; a dose history; and, in each daily log, the dose, the injection site, how you felt and any reaction. Your next and last dose dates are computed by our server from what you entered, not by the app.

This is sensitive information and we treat it as such:

  • It is never included in a push notification (§13).
  • It is never sent to any advertising or analytics service.
  • It is never sent to our AI providers.
  • It is visible to your connected educator only if you connected one (§7).
  • Reminders are computed from what you entered; we do not obtain your prescriptions from anyone.

Your calendar. If you choose to save your next dose to your device calendar from Settings, the event we create does not name your medication and does not carry your dose — its title is a neutral dose reminder, and its notes carry only the tag we use to find and replace our own previous event. That event lives in your own calendar, not on our servers, so it can sync to iCloud or Google Calendar along with the rest of your calendar, and deleting your Weight Pocket account does not remove it. Only you can delete it. We never create that event on our own — it takes an explicit tap.

The app does not prescribe, adjust doses, diagnose or treat. If you have a medical question, or a symptom that worries you, contact your own doctor or emergency services.

6. AI features

The app uses AI in two very different ways, and the difference matters for your privacy.

6.1 On your device. Most of what feels "smart" runs locally and sends nothing anywhere: coaching lines, pattern detection, weight projection, nudges, streaks and food matching against the app's own databases. None of that leaves your phone.

6.2 In the cloud. Three features send data to an AI provider through our own server. Nothing else does — our server accepts exactly three AI actions and rejects anything else.

  • Meal photo recognition — provider: Google Gemini. We send the photo you just took, your language, whether it is a barcode, the names of foods you logged recently, the names of products already in your pantry, and technical capture details read from the photo (lens, brightness, distance, reference object).
  • Label reading — provider: OpenAI. We send the photo of the label, optionally a photo of the front of the package, and your language.
  • Shopping advice — provider: OpenAI. We send your language, the period, counts by rating band, the dominant axis, the trend, and a list of product names with their rating band.

What is not sent in any of the three: your account ID, your name, your email, your weight, your medication, your symptoms, your notes, your health data or your GPS coordinates.

Neither Google Gemini nor OpenAI operates under a Business Associate Agreement with us. That is why both are gated (§6.4 and §15). For the OpenAI requests we explicitly ask the provider not to store the content of the request. What each provider does with a request under its own terms is governed by that provider's policy, not ours. Images are size-capped before they leave your phone.

6.3 Your control, and it is enforced on our server — not just in the app. AI processing runs on your consent. You can turn it off at any time in Settings → Privacy → AI features; we record the withdrawal with its date and the policy version. From that moment our server refuses the request before looking at anything you sent: without an active AI consent, no photo and no product list reaches Google or OpenAI. Turning it off disables the features that need it; it does not make past processing unlawful.

6.4 HIPAA Mode. If your account has HIPAA Mode on, all traffic to the AI providers is refused by our server, whatever the feature, before the request is examined and before it costs you any quota. Food lookups to the public nutrition databases are refused too, and analytics, crash reporting and performance monitoring are forced off. See §15.

6.5 You always know it is AI. The app labels AI-generated content as such. You are never led to believe an automated feature is a human professional.

7. Your connected educator (coach)

Connecting with an educator is your decision, and nothing is shared until you make it. Before you connect, the app shows you what the educator will see, what they cannot do, and how to disconnect — and it records that you accepted, in both routes (sign-up and settings).

What your educator can see — this is the complete list, enforced by our server-side database rules, not by the app:

  • Your profile document: name, email, age, sex, height, city, time zone, your weights, your goals, your medication and your plan flags.
  • Your daily logs: morning weight, energy, symptoms, free-text notes, dose, injection site, pain and body measurements.
  • Your nutrition logs: meals, macros and water.
  • Your exercise logs: exercises, steps and active minutes.
  • Your daily health snapshots: steps, sleep, heart rate, resting heart rate and heart rate variability.
  • Readings from a scale or smart tape you connected.
  • Behavioural logs, alerts, signals and nudge deliveries.
  • A summary row used for their member list: your name, record number, weights, height, last log date, recent health values, and your medication trimmed to seven fields.
  • Your profile photo.

What your educator cannot see, because the rules block it: your conversations with WiPi, your in-app activity events, your learned routines, the coaching insights you have already seen, your food-recognition history, your private product list, your usage counters, your feedback reports and the screenshots you attached to them.

What your educator cannot do: change anything. They have read-only access. The rule that allows writing your data allows it only to you. There is no exception: coaching notes written by an educator were a feature retired in June 2026 and the rules no longer allow it at all. Their role is educational only: they do not treat you, do not diagnose you, do not prescribe or adjust medication, and do not give medical advice.

How to disconnect. You can disconnect at any time from Settings → your coach → Disconnect. In a single server operation we remove the educator from your account, recompute whether you are still connected to anyone, delete the denormalised coach name we had stored, and — if you were under HIPAA Mode — recompute it against your remaining educators and clear it if none of them requires it. From that moment the rules stop granting them access to everything listed above, and we write an audit entry recording the disconnection.

What we cannot undo: anything the educator read or wrote down outside the app, and any archived note tree from the retired notes feature. That archive is never readable through the app again, and it is fully deleted when you delete your account — our deletion sweeps the entire staff data tree, not only the educators you are currently connected to, precisely because disconnecting does not remove it.

An educator can also end the connection from their side, with the same mechanism and the same audit entry.

8. Providers and international transfers

We share data only with the providers below, only for what the app needs, and never for advertising. We do not sell your personal information.

  • Google Cloud / Firebase (Auth, Firestore, Functions, Storage, Cloud Messaging, Hosting, App Check) — receives your account, your entire record, your files and your notification delivery, for identity, database, backend, file storage, push, website and anti-abuse. The database is in the nam5 United States multi-region and every backend function runs in us-east1. Safeguard: a Business Associate Agreement accepted on 2026-06-06 for the weightpocket.com organisation, plus the standard contractual clauses in Google's own terms.
  • Google Gemini — receives the meal photo and the fields listed in §6.2. No account ID, no name, no clinical field. Purpose: meal photo recognition. Reached at the global Gemini API endpoint. No BAA: blocked server-side under HIPAA Mode and without your AI consent.
  • OpenAI — receives the label photo, or the list of product names with their rating band, as listed in §6.2. No account ID, no clinical field. Purpose: label reading and shopping advice. United States. No BAA: same server-side blocks, and we ask OpenAI not to store the request.
  • RevenueCat — receives your Firebase account ID in the clear, the product ID and the store receipt. No clinical data. Purpose: subscription and receipt validation. No BAA, and it is the only subscription route we have.
  • Apple App Store / Google Play — receive the purchase and the receipt, under their own terms.
  • Expo push service — receives your device notification token and the generic notification text. United States. Bodies are generic by construction (§13).
  • USDA FoodData Central — receives a barcode or a food search string. No account ID. United States. Public API, called through our server.
  • Open Food Facts — receives a barcode or a search string. No account ID, and our server calls it with a single technical identity, so your device's IP address never reaches them. France / global. Public database, called through our server.
  • Firebase Analytics, Crashlytics and Performance — only if you opt in: screen names, closed-vocabulary events, sanitised crash reports and latency traces, identified by a hash of your account ID. These three are not covered by the Google BAA, which is exactly why they never receive health data (§12).

The answers we get back from the two food databases are cached on our servers for reuse: the cache is keyed by a hash of the query, carries no account ID, and expires on its own — 90 days for USDA, 7 days for Open Food Facts.

Where your data lives. Your data is stored on Google Cloud infrastructure in the United States, and the AI, notification and food-database providers above are also reached in the United States or globally. If you use the app from the EEA or the UK, that is an international transfer.

9. How long we keep your data

While your account exists:

  • Account, profile, goals, weights, medication — kept until you delete them; there is no automatic expiry.
  • Daily logs and daily health snapshots — kept until you delete them.
  • Nutrition and exercise detail — 24 months, after which we keep a monthly summary and delete the item-by-item detail.
  • Behaviour and engagement events — 12 months. You can also purge them yourself at any time.
  • Food-recognition history — 12 months.
  • Your conversation with WiPi — capped at the 100 most recent messages.
  • Coaching insights already shown — capped at 500 entries, pruned weekly.
  • Profile photo — kept until you replace it or delete your account.
  • Feedback screenshots — 90 days.
  • Data-export bundles — 7 days, and the download link itself expires in 15 minutes.
  • Consent records — the life of the account, mirrored in the audit trail.
  • Audit trail6 years, append-only. See below.
  • Subscription webhook events — 180 days.
  • AI usage metrics, keyed to a hashed account ID — 90 days.
  • Food-search cache, which carries no account ID — 90 days for USDA, 7 days for Open Food Facts.
  • Notification delivery receipts, which carry no account ID — 30 days.
  • Automated backups35 days, rolling.
  • Data stored on your phone — until you delete it (see §10 and §12).

When you delete your account, everything above that belongs to you is deleted immediately from the live database, with three exceptions you should know about: the audit trail (below), the anonymous cache and delivery receipts that carry no account identifier at all, and a backup copy, which survives only until the 35-day rotation overwrites it. Data held by the AI providers is governed by their own terms and is not under our control.

The audit trail is the one thing that outlives your account, and you should know it. Every privileged action — granting or withdrawing a consent, connecting or disconnecting an educator, exporting your data, deleting your account, granting a privileged role — is written to an append-only audit log that only our server can write and that nobody can edit or delete. It records that an action happened — who, what and when — and never your health content. HIPAA requires us to keep it for at least six years (§164.316(b)(2)(i) / §164.530(j)), so it is retained after you delete your account, and it contains your account identifier. After 6 years plus a one-week buffer it is purged automatically, monthly, and the purge itself leaves only counters — never health data.

Where the law requires it (tax records, fraud prevention), we may keep specific records for the legally mandated period.

10. Your rights

You have these rights over your data, wherever you live. We do not make you argue for them.

  • Access / portability — Settings → Privacy → Export my data. We build a complete JSON bundle of your data and give you a download link. One export per 24 hours, and you must have signed in within the last five minutes; if not, the app asks you to sign in with Apple or Google again and retries. The link expires in 15 minutes and the file is deleted from our storage after 7 days.
  • Rectification — edit the value in the app, or write to us. Corrected immediately.
  • Erasure — Settings → Delete account. It requires a sign-in within the last five minutes, and it is irreversible. It deletes your profile document and all of its sub-collections, your summary row, your subscription events, your AI usage metrics, your feedback reports, your tester entry, any retired appointment and message records, your entire coaching-notes tree across every educator, every file we hold for you in storage, and your entry in our authentication system. If any part of the coaching-notes deletion fails, the whole operation fails and we do not report your account as deleted.
  • Withdraw consent — Settings → Privacy (AI features, diagnostics); Settings → your coach → Disconnect. It takes effect at once and is enforced on our server (§6.3, §7); past processing stays lawful.
  • Restriction / objection — write to support@weightpocket.com. We answer within the deadlines below.
  • Complaint — your data protection authority. See §16.

What the export contains and what it does not. The bundle carries everything we delete — an invariant enforced by an automated check in our codebase — with two declared exceptions, both because they contain another person's data: the invitation codes and the staff invitations created by an educator (GDPR Art. 15(4)). The audit trail is also excluded, and the bundle itself says so and explains why.

What the export does not include, because it never left your phone: the scan-and-purchase memory of the shopping feature, your offline check-in queue and your local error log are stored only on that device. They are deleted when you delete your account.

Deleting your account also deletes it from our authentication system, so you cannot sign back in. Anonymous aggregates that cannot be linked back to you may remain — for example, a product you chose to publish to the shared food catalogue carries no identifier of any kind and stays in the catalogue.

Response times: within one month for GDPR requests (extendable as the law allows), within 45 days for CCPA/CPRA requests. We may need to verify your identity first. Authorised agents may act for you with signed authorisation.

Consumer health data (Washington, Nevada, Connecticut and other states). This section is part of this policy and replaces the separate consumer health data notice we used to publish.

  • What it is. "Consumer health data" means information linked or reasonably linkable to you that identifies your past, present or future physical or mental health status. For Weight Pocket that includes your weight and body measurements, the medications you log with their dose and injection site, your symptoms, your meals and nutrition, your exercise, the health data you sync from your device, and the notes you write.
  • Where it comes from. From you, from the device platforms you authorise (Apple Health, Health Connect, a scale or smart tape you pair), and from nowhere else. We do not buy consumer health data from data brokers.
  • What we do with it. Only what §3 and §4 describe: run the features you use and, if you connected one, show your educator the data listed in §7. Never for advertising, ad targeting or profiling.
  • We do not sell it. We have never sold consumer health data. Under the Washington My Health My Data Act a sale would require a separate, specific valid authorisation from you; because we do not sell, we neither seek nor rely on any such authorisation.
  • Your consent. We ask for it before we process, separately from our terms, and each connection (a health platform, an educator) takes its own affirmative action from you. You can withdraw consent at any time in Settings → Privacy; withdrawal stops future processing and may disable the features that depend on it.
  • Your rights. You may confirm what we collected and with whom we shared it, withdraw your consent, and delete your consumer health data — in the app, or by writing to support@weightpocket.com. We respond within 45 days for Washington requests, extendable once by 45 days where reasonably necessary, and we will not discriminate against you for exercising any of these rights.
  • Right to appeal. If we decline to act on your request we will tell you why. You may appeal by replying to our response, or by writing to support@weightpocket.com with the subject line "Health Data Appeal". If we deny your appeal you may contact your state Attorney General.
  • Biometrics. We do not create, capture or store biometric identifiers such as faceprints. Photos are analysed only to recognise food, and any Face ID / Touch ID app lock is handled entirely by your device, which returns only a success or failure signal to us.

Residents of California and of other states with privacy statutes also have the right to limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of; ask us and we will confirm it in writing.

11. Security

  • Encryption in transit. Everything the app sends travels over HTTPS, both to our servers and to every external provider.
  • Encryption at rest. On our servers, Google Cloud's default encryption at rest. On your phone, the sensitive local store is encrypted with AES-256 using a key held in your device's secure keystore; if the device offers no secure keystore, we do not write that data at all rather than write it unprotected.
  • Access rules. Server-side rules decide who can read each document. Your data is readable by you and, if you connected one, by your educator — and the rule checks, on every single request, both that they hold a staff role and that their identifier is inside your own list of connected educators. Everything not explicitly allowed is denied.
  • The server decides who is staff, not the token. Staff and admin access is resolved against the server-side record, so withdrawing a role takes effect immediately instead of waiting for a session to expire; a mismatch between the token and the record is denied and logged.
  • Recent sign-in for sensitive operations. Six operations require that you authenticated within the last five minutes: deleting your account, exporting your data, granting a privileged role, granting tester access, and issuing or redeeming an educator invitation. If we cannot tell when you authenticated, the operation is refused.
  • App lock. You can require Face ID, Touch ID or your device passcode to open the app, with a re-lock window of 1, 2, 3 or 5 minutes. For educators and administrators it is mandatory, not optional, because they see other people's health data. The biometric never leaves your device: iOS or Android returns only success or failure, and if your device has no credential enrolled the lock fails closed.
  • Device attestation (App Check). The app attaches a proof that it is the real app running on a real device — App Attest on iOS, Play Integrity on Android, reCAPTCHA v3 on the web. Today we collect that signal in observation mode: no request is refused for lacking it.
  • Audit trail. Privileged actions are written to an append-only audit log kept for 6 years (§9).
  • Notifications carry no health content (§13).
  • Provider keys never ship with the app. Every external API key lives only on our servers.

No system is perfectly secure and we do not claim otherwise. If a breach affects your data we will notify you and the authorities as the law requires — including the FTC Health Breach Notification Rule (16 CFR Part 318) for US users, GDPR Art. 33-34 for EEA/UK users, and the applicable state breach statutes.

12. Analytics and crash reports

Diagnostics are off unless you turn them on. Analytics and crash collection are disabled in the app's own build configuration and only start if you switch them on in Settings → Privacy → Analytics. They are also forced off whenever HIPAA Mode is active on your account.

When they are on:

  • These services never receive health data. No weight, no meal, no medication, no symptom, no note, no photo.
  • The identifier we send is a hash of your account ID, never the ID itself, and the only user properties we send are your role, your plan and where your subscription came from.
  • Crash reports are sanitised before they leave your phone: we keep the error class, the error code and the call stack, and we deliberately drop the error message and any metadata the calling code attached, because either of them could echo something you typed. Only errors of medium severity or above are sent at all.
  • Turning diagnostics off deletes the analytics identifier and the user properties from your device; signing out does the same.

We use no advertising SDKs, no third-party trackers and no cross-app tracking identifiers, and the app's Apple privacy manifest declares exactly that. We do not use the microphone: the microphone permission is switched off in both components that could request it and is not declared on either platform.

We do not publish over-the-air updates: the update mechanism is disabled on both platforms.

13. Notifications

We send reminders and coaching nudges if you allow notifications. The text is always generic — for example, "Time for your check-in". A notification never names a food, a weight, a medication, a dose or a symptom, so a message on your lock screen reveals nothing about your health.

Delivery goes through the Expo notification service, which receives your device token and the notification text. We keep the delivery receipt for 30 days, without any account identifier, to detect and clean up dead device tokens.

You can turn notifications off at any time in your device settings. When you sign out, we remove your notification token from your account before signing you out and cancel every reminder already scheduled on that phone, so that the next person to use it receives nothing.

14. Changes to this policy

When we change this policy we update the effective date and the version number. For material changes we notify you inside the app — we do not send a push notification about policy changes — and, where the change affects how we process health data, we ask you to accept the new version before continuing. Each acceptance is recorded with its date and the version you accepted, both in your account and in our audit trail, in a single operation that either records both or neither.

There are three consents we record this way: AI processing, the educational disclaimer, and sharing with your educator. §6.3, §7 and §10 explain how to withdraw each one.

15. HIPAA Mode — what it means for you

Most members use Weight Pocket directly, and in that case HIPAA does not apply to us: we are not your healthcare provider. Where an organisation subject to HIPAA uses Weight Pocket with its own patients, that organisation is the covered entity and, if we sign a Business Associate Agreement with it, we act as its business associate under that agreement.

HIPAA Mode is set on your account by our server when you connect to an educator whose organisation requires it; you cannot set it yourself and neither can the educator, because it is one of the fields the app is forbidden to write. When you disconnect, we recompute it against your remaining educators and clear it if none of them requires it.

When HIPAA Mode is active on an account:

  • Every request to the AI providers is refused by our server, before the request is examined (§6.4).
  • Food lookups to the public nutrition databases are refused as well.
  • Analytics, crash reporting and performance monitoring are forced off.
  • Everything else works the same, with the same technical safeguards as any other account.

We do not claim to be "HIPAA certified": no such certification exists. Our BAA status with each provider is summarised in §8 — and it is not uniform: Google Cloud is covered, while Gemini, OpenAI and RevenueCat are not.

16. Contact and complaints

  • Privacy questions and rights requests: support@weightpocket.com
  • Postal: JP Medicina de la Montaña LLC, Urb Estancias del Golf, 121 Calle Miguel Rivera Texidor, Ponce, Puerto Rico 00730, USA
  • We answer within one month (GDPR) or 45 days (CCPA/CPRA).

If you are in the EEA or the UK you may lodge a complaint with your national data protection authority. If you are in the United States you may also contact your state Attorney General.

17. Where our nutrition data comes from

Food composition data comes from three public sources, and we want you to know which is which. USDA FoodData Central (U.S. Department of Agriculture) — a public-domain work of the U.S. government. TACO, Tabela Brasileira de Composição de Alimentos, 4th edition, published by NEPA/UNICAMP (Brazil). And packaged-product and barcode data from Open Food Facts: © Open Food Facts contributors, made available under the Open Database License (ODbL). None of these organizations endorses Weight Pocket or is responsible for how we present their data, and any error you find in the app is ours to fix, not theirs.