Effective August 12, 2026
1. Who this policy covers
TrueMe is operated by Dongho Kang, a sole proprietor based in New York, United States (“TrueMe,” “we,” “us,” or “our”). This policy covers the TrueMe iOS application, trueme.io, customer support, and related services.
TrueMe is a direct-to-consumer wellness, tracking, and educational service. TrueMe is not a healthcare provider, insurer, pharmacy, prescribing service, or HIPAA covered entity. It does not diagnose, prescribe, recommend dose changes, or replace a qualified healthcare professional.
2. Information TrueMe handles
Account and device information
When you sign in, Apple or Google may provide an account identifier, name, and email address according to the choices you make with that provider. TrueMe also handles a user ID, install identifier, app version, build number, locale, device capabilities, and security or fraud-prevention signals.
Health, fitness, and journey information
This may include medications and dose schedules you enter, injection records, symptoms, side effects, weight and measurements, food and nutrition, water, goals, exercise, steps, workouts, sleep, mood, journal entries, treatment notes, and progress history.
Content you choose to provide
This may include progress or meal photos, label images and extracted text, food searches and barcodes, voice transcripts, companion chat messages and memories, feedback, support correspondence, and other notes you add.
Purchases and product activity
Apple supplies transaction and entitlement information needed to provide or restore subscription access. TrueMe does not receive your full payment-card number. Operational records may include request outcomes, quotas, costs, feature interaction, and redacted security audit data.
3. Where information comes from
- directly from you when you enter, photograph, scan, record, or send information;
- from Apple Health, only for categories you authorize in iOS;
- from Apple or Google when you choose their sign-in service;
- from Apple for App Store transactions and entitlement status;
- from your device for permissions, locale, install identity, notifications, widgets, and security signals; and
- from nutrition providers when you request food search, barcode, or serving details.
4. How TrueMe uses information
TrueMe uses information to provide local storage and optional cloud synchronization; authenticate accounts; restore records; show treatment, food, activity, and progress views; personalize companions and goals; process requested AI and nutrition features; provide reminders and widgets; verify subscriptions; enforce provider quotas; prevent fraud or abuse; troubleshoot failures; respond to support; comply with law; and protect users and the service.
5. Services that receive information
| Service | Role and information involved |
|---|---|
| Supabase | Authentication, account-scoped database records, private progress-photo storage, and protected server functions. |
| OpenAI | User-requested companion and food processing. The protected backend sends only the text, transcript, image, or label context needed for the request and sets the Responses API store field to false. OpenAI may retain abuse-monitoring data under its applicable API terms unless approved retention controls apply. |
| Apple | Sign in with Apple, StoreKit purchases, HealthKit, DeviceCheck, notifications, widgets, photos, speech recognition, and other iOS functions you choose. |
| Authentication when you choose Google sign-in. | |
| FatSecret and USDA FoodData Central | Food search, barcode, serving, and nutrition information. Requests may contain the query or barcode, region, language, and serving details needed to return results. |
| Hetzner | A restricted static-egress proxy used to reach FatSecret from TrueMe’s backend. Provider credentials remain server-side. |
We may also disclose information to professional advisers, authorities, courts, successors, or other parties when required by law, needed to protect rights or safety, prevent fraud, or complete a business transfer.
TrueMe does not sell personal information and does not use it for cross-context behavioral advertising. The current app does not include advertising or cross-app tracking SDKs.
6. Local storage, synchronization, and security
TrueMe is local-first. Many records begin in app-owned storage on your device. If you sign in, account-scoped records and progress photos synchronize through Supabase so they can be restored and used across signed-in sessions. Data is transmitted over HTTPS, cloud tables and files use authenticated owner-scoped access policies, and provider credentials are not shipped in the app. No storage or transmission method is perfectly secure.
Widget and notification content may be visible while your device is locked depending on your iOS privacy settings. You control Apple Health, photo, microphone, speech, and notification permissions through iOS Settings.
7. Retention
Account records and synchronized journey content are retained while your account is active and as reasonably needed to provide the service. The backend currently applies these operational limits:
- FatSecret provider-cache entries: no more than 24 hours;
- USDA provider-cache entries: up to 30 days;
- rate-limit state: 2 days;
- synchronization receipts: 30 days, capped per owner;
- redacted request audits: 90 days; and
- usage and App Store idempotency evidence: 400 days.
When you confirm account deletion, TrueMe’s account-lifecycle service removes TrueMe-controlled authentication records, owner-scoped database rows, and private progress-photo objects and revokes Sign in with Apple authorization when applicable. Limited security records, provider records, backups, or information required for law, fraud prevention, subscription disputes, or other legitimate obligations may remain for their applicable periods.
8. Your choices and rights
TrueMe provides in-app controls to export your account data, sign out, and delete your account. You may revoke optional iOS permissions at any time. Depending on where you live, you may also request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or appeal a denied request.
Send privacy requests to privacy@trueme.io. We may need to verify your identity before completing a request. You may also complain to your local privacy or data-protection authority.
For details specifically about consumer health data, read the Consumer Health Data Privacy Notice.
9. International processing
TrueMe is controlled from New York, United States. TrueMe and its providers may process information in the United States and other countries where they operate, where privacy protections may differ from those in your location. Where required, we rely on service-provider contractual terms and other lawful transfer mechanisms.
10. Age eligibility
TrueMe is intended only for people age 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that a person under 18 has provided personal information, we will take reasonable steps to delete it.
11. Changes and contact
We may update this policy as the service, providers, or law changes. We will change the effective date and provide additional notice when required.
Privacy contact: privacy@trueme.io
Legal entity: Dongho Kang
Mailing address: 605 West 42nd Street, Apt. 36K, New York, NY 10036, United States