Legal

Privacy Policy

Effective date: 2 July 2026 · Last updated: 2 July 2026

01

About This Policy

HUMNS ('we', 'our', 'us') operates human nutrition, emotional wellness and sustainability products. We take your privacy and health data seriously. This Privacy Policy applies to all users of the Mood Nutrition Connect mobile application (iOS and Android), our website, and any related services. By using our products, you agree to the collection and use of information as described in this Policy. If you do not agree, you can choose to discontinue use of the App. This Policy is designed to comply with applicable laws including India's Digital Personal Data Protection (DPDP) Act 2023, the Information Technology Act 2000 and IT Rules 2011, GDPR (EU/UK), CCPA (California), and PIPEDA (Canada), and the health data requirements of the Apple App Store and Google Play Store. Important notice: Mood Nutrition Connect is currently in a closed testing phase. The app is accessible by invitation only and is not yet publicly available. Data collected during this phase is limited to invited testers and is handled in accordance with this Privacy Policy. 1.1 Our Privacy Promise Unlike many wellness apps, HUMNS makes the following commitments to every user: • We never sell your data to advertisers, data brokers, or any third party • We never share identifiable data with social media platforms (Facebook, Google, Snapchat, or any advertising network) • We use no advertising tracking pixels, ad SDKs, or cross-app tracking in our App • Research data is anonymised - it is stored under a random identifier generated on your device, never derived from or linked to your account, name, or email • You control what you share and can opt out of research data sharing at any time • You can permanently delete your account and personal data at any time from within the App, and opt out of research data sharing whenever you choose • We use only a small, carefully selected set of service providers, and never for advertising • AI chat conversations are not stored - they exist only during the active session These commitments are built into our technical architecture, not just our words. 1.2 Data Protection Officer HUMNS has designated a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and applicable data protection laws, including GDPR, India's DPDP Act 2023, CCPA and PIPEDA. Our interim Data Protection Officer is: Interim Data Protection Officer: Ravinder Singh Email: contact@ihumns.com You have the right to contact our DPO directly at any time regarding: • How your personal data is being processed • Exercising your data rights (access, deletion, correction, portability) • Raising a privacy concern or complaint • Withdrawing consent for data processing If you are an EU or UK resident and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. For EU residents, this is your national Data Protection Authority. For UK residents, this is the Information Commissioner's Office (ICO) at ico.org.uk.
02

Information We Collect

2.1 Account Data (Stored Securely in the Cloud) When you create an account, we collect: • Email address (for authentication and account communications) • Password (encrypted - we cannot see it) This data is stored securely using Supabase, our authentication provider, with encryption at rest and in transit. 2.2 Health Profile (Stored in Your Account, in the Cloud) When you complete your health profile, we collect information you voluntarily provide: • Basic profile: name, age, gender, region • Body metrics: height, weight • Health context: dietary preferences, allergies, food sensitivities, health conditions (e.g. PCOS, diabetes, anxiety) • Wellness goals: weight loss, better sleep, improved mood, gut health, etc. • Activity level and kitchen access Your health profile is stored in your account in our secure cloud database (Supabase), linked to your account ID, and is also cached on your device so the App works offline. It is used to personalise your nutrition and mood recommendations. It is protected by row-level security and is not accessible to any advertiser or third party other than the processors listed in Section 7. 2.3 App Activity Data (Stored in Your Account, in the Cloud) To sync your experience across sessions and devices, and to power your recommendations, the following data is stored in our secure cloud database (Supabase), linked to your account ID, and cached on your device: • Mood check-in entries (mood, emotions, energy level, activities, body sensations, journal notes) • Food consumption logs (foods you logged or that were identified by the AI food scanner) • Food–mood outcomes (which recommended foods you marked as eaten, the mood recorded just before eating, and your self-reported response afterwards) - these power your Mood Story and the optional "Share with your nutritionist" summary This data is retained until you delete it or delete your account. When you delete your account, it is permanently removed from our servers immediately (see Sections 5 and 12). When you choose to create a "Share with your nutritionist" summary, the entries for the period you select are processed by our secure backend (Supabase Edge Functions) to build the PDF or CSV file. The generated summary is not stored on our servers - the file is created on your device for you to share, and we do not retain a copy. Your AI chat conversations with Mo are not stored - see Section 2.4. 2.4 AI Chat & Search Data When you use Mo Chat (our AI nutrition advisor) or the AI-powered search and food scanner features: • Your message, query, or food photo is sent to our AI provider (Anthropic Claude) in real time to generate a response. Requests are routed through our secure backend (Supabase Edge Functions), except the AI food scanner, which sends your photo directly to Anthropic from the App. • Anthropic operates under a Zero Data Retention policy for our API usage - they do not store your inputs or outputs and do not use them to train AI models. • We do not store your Mo Chat conversations. Messages exist only during the active session, in the App's memory, and are not written to our servers or saved on your device. Each conversation starts fresh with no memory of previous sessions. • AI-powered search queries are processed in real time and are not stored on our servers after the response is generated. 2.5 Device-Stored Data (On Your Device Only) The following data is stored locally on your device only and is never synced to our servers: • Mood/wellness activity sessions (e.g. breathing, gratitude, and MoCare session history) • App preferences and settings (accessibility, language, notification, and AI voice settings) • Cached copies of your profile and activity data for offline use • Skipped-ingredient and other on-device personalisation preferences If you uninstall the App or clear its data, this on-device data is permanently deleted. 2.6 AI Voice (Text-to-Speech) When Mo speaks aloud, the text of Mo's response is sent through our secure backend to our voice provider (ElevenLabs) to generate audio. The audio is streamed back, saved to a temporary cache file on your device to play, and then deleted. We do not send your name or email for voice generation, and the generated audio is not retained on our servers. 2.7 Anonymised Research Data (Only With Your Explicit Consent) If you choose to opt in to "Help improve nutrition science" during onboarding or in Settings, we collect anonymised usage patterns to advance the science of mood and nutrition. This data: • Is stored under an anonymous identifier - a random value generated on your device. It is not derived from your account, and no link between this identifier and your account is ever stored on our servers, so research data cannot be traced back to you. • Uses age bands (e.g. "25-34") instead of your exact age • Uses region bands (e.g. "South Asia") instead of your exact location • Includes anonymised health conditions, dietary preferences, and mood-food patterns (mood check-ins, mood-food outcomes, and which recommendations you engaged with) • Is not linked to your name, email, or account. Because the identifier is random and generated on your device - with no user-to-identifier mapping stored on our servers - this data cannot be traced back to you at any time, whether or not you later delete your account. It is retained on an ongoing basis to support the science (see Sections 5, 11 and 12). You can opt out of research data sharing at any time in Settings → Data Sharing. If you opt out, no further research data leaves your device. 2.8 Payments & Subscriptions In-app subscriptions are managed by RevenueCat and the Apple App Store / Google Play. We receive anonymous purchase and subscription-status information. We do not receive or store your full payment card details - these are handled by the app stores' payment systems. 2.9 Notifications If you enable notifications, we use Expo push infrastructure and store a device push token to deliver reminders and wellness nudges. You can disable notifications at any time in your device settings or in the App. 2.10 Diagnostic & Error Data (to Keep the App Working) When the App runs into an unexpected error or crash, it sends us a technical diagnostic report so we can find and fix the problem. This report contains only: • A random per-install identifier - generated on your device, not derived from and never linked to your account, name, or email • The App version and your device platform (e.g. Android) • A technical error message and stack trace, automatically scrubbed before sending to remove personal content (we strip email addresses, security tokens, and long number sequences) This report does not contain your name, email, mood check-ins, food logs, chat messages, or any health data. It is stored in our secure backend (Supabase) and used only to diagnose and fix bugs. It is never used for advertising, profiling, or tracking, and is not sold or shared. This is our own first-party logging - we do not use Google Analytics, Firebase, or any third-party analytics or crash-reporting SDK. Because the report carries only a random per-install identifier and no account details, it cannot be traced back to you. We keep these reports only for as long as needed to investigate issues and clear them periodically. 2.11 What We Do Not Collect • We do not collect precise GPS location. Regional pricing and regional content are determined from your device's time zone, not your location. • We do not access your contacts or microphone. We access your camera and photo library only when you actively use the food scanner feature to select or take a photo. • We do not collect data from other apps on your device • We do not use device fingerprinting or cross-app tracking • We do not track you across websites or apps
03

How We Use Your Data

3.1 Legal Basis for Processing (GDPR) For users in the EU and UK, we process your personal data on the following legal bases: • Consent - for health and mood data, research data sharing, and optional integrations • Contract performance - to deliver the services you have signed up for • Legitimate interests - for product improvement and security monitoring • Legal obligation - to comply with applicable laws and regulations You may withdraw consent at any time by contacting contact@ihumns.com or through your account Settings. 3.2 Personalised Nutrition & Mood Recommendations The core purpose of HUMNS is to provide evidence-based nutrition guidance connected to emotional wellbeing. We use your data to: • Generate personalised ingredient and meal recommendations based on your health profile, mood state, dietary preferences, and health conditions • Adapt recommendations to your kitchen access level and regional food availability • Provide AI-powered responses to nutrition and mood questions, AI meal analysis, and AI voice responses (subject to your plan) • Identify synergistic food combinations backed by nutritional science • Filter out ingredients based on your allergies, sensitivities, and preferences 3.3 Product Improvement (Anonymised Only) We use anonymised, aggregated data to improve the product: • Understand which recommendations are most helpful • Improve the accuracy of mood-nutrition pairings • Identify patterns in how food choices affect mood across populations • No directly identifiable data is used for product improvement 3.4 Research (With Consent Only) With your explicit opt-in consent, anonymised data is used to: • Advance the science of nutritional psychiatry and the gut-brain connection • Support research partnerships with universities and institutions • Generate evidence for the relationship between food, mood, and wellbeing • All research data is anonymised and, where results are shared or published, is aggregated so that individuals cannot be identified 3.5 Communications We use your email to send you: • Account and service notifications (password resets, policy updates) • Wellness and nutrition insights (opt-in only) You can manage communication preferences in Settings.
04

Your Data Rights & Controls

Your Rights at a Glance: 1. Right of access - request a full account of how we have collected and used your personal data 2. Right to rectification - update or correct inaccurate health information 3. Right to erasure - permanently delete your account and all associated data 4. Right to data portability - receive your data in a machine-readable format 5. Right to object - object to processing based on legitimate interests 6. Right to restrict processing - request that we limit how we use your data 7. Right to withdraw consent - withdraw consent for research data sharing at any time without affecting prior processing 8. Right to lodge a complaint - contact your local supervisory authority These rights are accessible directly within our App: • Edit your health profile: Settings → Preferences and Sensitivity • Export your data: Settings → Security & Data • Delete your account and all data: Settings → Security & Data • Manage research data sharing: Settings → Data Sharing • Manage communication preferences: Settings → Notifications • Withdraw consent or raise a grievance: contact@ihumns.com Indian Users (DPDP Act 2023): • Right to nominate another person to exercise your rights • Right to access information about data processing in a clear and accessible manner California Users (CCPA): • We do not sell personal information • We do not share personal information for cross-context behavioural advertising • Right to non-discrimination for exercising privacy rights
05

Data Retention Periods

We retain your personal data for the following periods: • Account data (email, profile): for the duration of your account; permanently deleted when you delete your account • Health profile data: for the duration of your account; permanently deleted when you delete your account • Mood check-ins and food logs: for the duration of your account, or until you delete them; permanently deleted when you delete your account • Mo Chat conversations: not retained - they exist only during the active session • AI search queries and food-scanner photos: not retained on our servers - processed in real time and discarded (subject to Anthropic's Zero Data Retention policy) • AI voice audio: not retained on our servers; the temporary playback file on your device is deleted after playback • On-device data (activity sessions, preferences, offline cache): stored on your device only - deleted when you uninstall the App or clear App data • Anonymised research data: retained on an ongoing basis to support research. It is stored under a random identifier generated on your device, with no link to your account stored on our servers, so it cannot be traced back to you at any time. You can stop further collection at any time by opting out in Settings → Data Sharing • Payment records (via RevenueCat and the app stores): retained by those processors in line with their legal obligations - not stored by us Where required by law, we may retain certain data for longer periods. Where appropriate, we retain information in aggregated form that cannot be used to identify you personally.
06

Use of Cookies

This section applies to our website (ihumns.com) only. Our mobile App does not use cookies. Please refer to our Cookie Policy at ihumns.com/cookie-policy for full details of how we use cookies and similar technologies on our website. In summary, our website uses: • Strictly necessary cookies - required for the website to function • Functional cookies - to remember your preferences • Analytics cookies - to understand how our website is used (not linked to App data) You can manage your cookie preferences at any time through our cookie consent banner on the website. Health data from the App is never stored in or accessed by website cookies.
07

Third-Party Services

We work with a limited number of third-party service providers to operate the App. We have carefully selected providers that respect user privacy: Supabase (Authentication, Database & Backend Functions) • Purpose: User authentication, secure storage of your profile, mood check-ins, and food logs, and hosting our secure backend functions • Data shared: Email, encrypted password, health profile, mood and food data • Security: Encryption at rest and in transit, row-level security • Role: Data processor under GDPR, bound by a Data Processing Agreement • Privacy: supabase.com/privacy Anthropic Claude API (AI Features) • Purpose: Powers Mo Chat (AI nutrition advisor), AI-powered search, and the AI food scanner • Data shared: Your query text, food photos, and relevant health-profile context (e.g. dietary preferences, allergies, recent mood) - but never your name or email • Data retention: Zero Data Retention - Anthropic does not store your inputs or outputs and does not use them to train AI models • Privacy: anthropic.com/privacy ElevenLabs (AI Voice / Text-to-Speech) • Purpose: Generates the spoken voice for Mo • Data shared: The text of Mo's response to be spoken aloud - no name, email, or profile data • Data retention: Audio is generated on demand and not retained by us • Privacy: elevenlabs.io/privacy RevenueCat (Subscription Management) • Purpose: Manages in-app subscriptions and billing • Data shared: Anonymous purchase data, subscription status • Data not shared: No health data, no mood data, no personal profile data • Privacy: revenuecat.com/privacy Expo (App Framework & Push Notifications) • Purpose: App framework and push notifications • Data shared: Device push tokens (only if you enable notifications) • Privacy: expo.dev/privacy Services We Do Not Use: • Google Analytics, Firebase Analytics, or any advertising analytics platform • Facebook SDK, Facebook Pixel, Meta tracking, or any social media tracking • Any advertising network, ad exchange, or data broker • Any service that profiles users for targeted advertising International Data Transfers: Your personal data may be transferred to and processed in countries where our service providers operate. Such transfers are conducted in accordance with applicable data transfer mechanisms, including Standard Contractual Clauses (SCCs) for EU/UK users.
08

Security

We implement appropriate physical, technical, organisational, and administrative safeguards tailored to the type of data we process. These include: • Encryption at rest and in transit for all personal and health data (TLS 1.2+) • Row-level security on our database infrastructure, so each user can access only their own data • Access controls limiting data access to authorised personnel only • Regular security monitoring and vulnerability assessment • Anonymised research data stored separately from identifiable account data, under a random identifier that is not derived from or linked to your account • AI and voice requests transmitted over HTTPS; AI content not retained by our AI provider • On-device data protected by the operating system's secure storage You can also help keep your data secure by choosing a strong password, limiting access to your devices, and signing out when finished. While we are committed to protecting your information, no method of transmitting or storing data online is entirely without risk.
09

Personal Data of Children

Our Services are not intended for children under the age of 13 (or 16 in the EU/UK, and 18 in India under the DPDP Act 2023). We do not knowingly collect or solicit Personal Data from anyone under these ages, and we ask that minors do not attempt to register for or use our Services. If we become aware that we have inadvertently collected Personal Data from a child, we will take prompt steps to delete that information. If you believe a child may have provided us with their Personal Data, please reach out to us at contact@ihumns.com.
10

Artificial Intelligence Disclosure

HUMNS uses Claude AI, developed by Anthropic, to power our AI nutrition advisor (Mo Chat), AI-powered search, and AI food scanner. We use ElevenLabs to give Mo a spoken voice. How AI works in our App: • Your message, search query, or food photo is sent to Anthropic's Claude API in real time to generate a response • Your health profile context (dietary preferences, health conditions, allergies, recent mood) is included in the AI prompt to personalise responses - but never your name or email • Anthropic operates under a Zero Data Retention policy for API usage - they do not store your inputs or outputs and do not use them to train AI models • Your Mo Chat conversations are not stored on our servers or your device - each session starts fresh with no memory of previous sessions • The text of Mo's spoken responses is sent to ElevenLabs to generate audio, which is not retained on our servers Important limitations: • AI responses are generated based on nutritional science and your health profile but are not a substitute for professional medical or dietitian advice • Always consult a qualified healthcare professional for medical decisions • AI may occasionally provide inaccurate or incomplete information • You can report any concerning AI responses to contact@ihumns.com
11

Anonymised Research Programme

HUMNS operates a voluntary research programme to advance the science of mood, nutrition and sustainability. This programme is entirely opt-in and separate from the core App functionality. How it works: 1. During onboarding or in Settings, you can choose to "Help improve nutrition science" 2. If you opt in, your research data is stored under an anonymous identifier - a random value generated on your device, not derived from your account. No mapping between this identifier and your account is ever stored on our servers 3. Anonymised patterns (age band, region band, health conditions, mood-food interactions, and which recommendations you engaged with) are sent to our research database 4. The data is not linked to your name, email, or account, and cannot be traced back to you 5. You can opt out at any time in Settings → Data Sharing, and no further data will be sent. Research data already collected is retained to support ongoing science; because it carries no link to your account, it remains anonymous whether or not you later delete your account What anonymised means in practice: • Your exact age (e.g. 28) becomes an age band (e.g. "25-34") • Your exact location (e.g. "Mumbai, India") becomes a region band (e.g. "South Asia") • Your name and email are never included in research data • Your data is stored under a random identifier generated on your device, not your account details - and no mapping between the two exists on our servers, so it cannot be traced back to you How research data is used: • To study the relationship between nutrition and mood across populations • To identify which food combinations are most effective for specific health conditions • To generate evidence for nutritional psychiatry and the gut-brain connection • To support research partnerships with universities and institutions (anonymised datasets only) • Research findings may be published in academic papers or reports - always using aggregated data that cannot identify individuals This programme is governed by our commitment to ethical research and data privacy. For more about our research mission, visit ihumns.com/research.
12

How to Delete Your Data

You can delete your data in two ways: 1. In the App: Go to Settings → Security & Data → Delete account 2. By email: Send a request to contact@ihumns.com Deleting your account will, immediately and permanently: • Remove your email and account from our authentication system (Supabase) • Delete your health profile, mood check-ins, and food logs from our cloud database • Clear all locally stored data on your device (activity sessions, preferences, and cached data) Anonymised research data you previously contributed is retained to support ongoing science. Because it is stored under a random identifier that is never linked to your account on our servers, it cannot be traced back to you - whether or not you delete your account. If you want to stop contributing before you delete your account, toggle off "Data Sharing" in Settings first.
13

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification and email at least 30 days before the changes take effect. Your continued use of the App after the effective date constitutes your acceptance of the updated policy. Previous versions of this policy are available upon request.
14

Contact Us

For privacy questions, data requests, or concerns: Interim Data Protection Officer: Ravinder Singh Email: contact@ihumns.com HUMNS Initiative for Human Nutrition & Sustainability