Consumer Health Data Privacy Policy
Consumer Health Data Privacy Policy
Applies to MeuMenu (the iOS and Android apps and the legacy web app, for as long as it remains online).
Controller and regulated entity: OXETECH TECNOLOGIA LTDA ("we", "us"), Brazilian company registration (CNPJ) 67.217.613/0001-56, headquartered at Av. Miguel Castro, 1264 — Nossa Senhora de Nazaré, Natal/RN, CEP 59.062-000, Brasil. Data Protection Officer: OXETECH TECNOLOGIA LTDA — suporte@oxetech.cloud.
1. Why this document exists
Washington State's My Health My Data Act (RCW 19.373) requires services that handle "consumer health data" to maintain a separate privacy policy dedicated exclusively to that data. We have adopted that requirement as our single standard, because it is the most protective of the regimes we are subject to: this policy applies to every MeuMenu user, in every country, not only to Washington residents. It supplements our general Privacy Policy; where consumer health data is concerned, this document governs.
2. What counts as "consumer health data" in MeuMenu
In plain terms: when you photograph your finished plate, our artificial intelligence estimates the portion weight and nutrition values — calories (kcal), protein, carbohydrates, fat, fiber, and sodium. Those estimates say something about what you eat, so Washington law treats them as health data: the Act expressly covers information derived or extrapolated by algorithms or machine learning from data that is not, on its own, health data (such as a photo of food).
In this policy, "consumer health data" therefore means:
- the photo of your finished plate that you submit for analysis (the raw material of the inference);
- the portion details you may choose to enter yourself (plate size or portion weight — by default, the AI estimates them);
- the nutrition estimates the AI derives from the photo;
- your meal history, if you choose to turn it on.
Photographing restaurant menus (MeuMenu's other feature) produces no health data and is covered by our general Privacy Policy.
The estimates are approximate: they are generated by AI from an image, may differ from the actual values, and are no substitute for official nutrition labeling or the guidance of a health professional. MeuMenu is not a medical service.
3. Categories of consumer health data we collect, and the purpose of each
| Category | Purpose and use | Do we store it? |
|---|---|---|
| Photo of the finished plate | The primary input to the nutrition analysis: it is processed in memory on our server (in Brazil) and sent to the Google Gemini API to generate the estimate. It is used for no other purpose. | No. We do not store the photo. |
| Portion details (optional: plate size or portion weight) | To calibrate that one estimate. | Only as part of the analysis record, and only if meal history is turned on. |
| Nutrition estimates (estimated weight, kcal, protein, carbohydrates, fat, fiber, sodium) | To show you the result of the analysis. | Only if meal history is turned on (opt-in — see Section 6). |
| Meal history | To let you look back at your past analyses. It exists only with your specific, separate consent (Section 6). | Yes, for as long as your consent remains active. |
We also record usage events (analysis counts, tokens consumed, and cost). These records contain neither the photo nor the nutritional content of any analysis; they exist only to operate and bill the service.
We do not collect medical records, test results, biometric data, precise location, or any health data beyond what is listed above.
4. Categories of sources
- You: the plate photo you take or upload, and any portion details you choose to enter.
- AI inference: the estimates are derived from your photo by algorithms (Google Gemini) acting on our behalf.
We obtain health data from no other source: we do not buy data, we do not use data brokers, and we do not receive health data from third parties.
5. Sharing: which categories of data, with whom, and why
Categories of consumer health data we share: the photo of the finished plate and the content of the analysis (the prompt sent and the response generated) pass through the Google Gemini API so that the estimate can be produced.
List of categories of third parties we share with:
- Google LLC — category: AI infrastructure provider (Gemini API, paid services). Google acts as a processor on our behalf, under the Data Processing Addendum for the Gemini API paid services: it processes the photo to generate the estimate and may retain limited logs of prompts and responses for security and abuse-prevention purposes, as set out in that agreement. This is processing carried out on our behalf — it is not a sale of data and not sharing for advertising.
Specific affiliates we share with: none. We share consumer health data with no affiliate.
No one else receives your health data. The Apple and Google app stores only process your subscription payment (they receive pseudonymous subscription identifiers, not health data). The app contains no advertising SDKs and no third-party analytics SDKs. We will disclose data only if legally compelled to (for example, by court order) — and then only to the narrowest extent possible.
6. Consent
- One-off analysis: the photo is processed at your request — you are the one who photographs the plate and asks for the analysis. That processing is what is necessary to provide the service you asked for, and the photo is not kept.
- Meal history: keeping your analyses goes beyond what a one-off analysis requires. Meal history is therefore opt-in, with its own separate consent: a dedicated toggle in the app, never buried in the terms of service and never pre-checked.
- Withdrawal: turning the toggle off deletes the stored history — it does not merely stop collection going forward.
- We keep a versioned record of your consents (date, text version, and IP address) as proof of what was accepted and when.
7. Your rights and how to exercise them
At any time, you may:
- Confirm and access the health data we hold about you, and export it (JSON + media);
- Correct data that is incomplete or out of date;
- Withdraw consent for meal history (which deletes the history);
- Delete your health data and your account.
How to ask: in the app itself (account/settings), through the account-deletion web page, or by email to suporte@oxetech.cloud. We may need to verify your identity through your account email. The same channels serve requests grounded in other applicable laws (LGPD, GDPR).
Timelines: our internal target is to respond within 15 days. We will never exceed 45 days, the maximum allowed by Washington law. Deletion is applied to active systems within that period and reaches backup copies within 6 months at most.
Denials and appeals: if we deny a request, we will explain why, and you may appeal through the same email address; we will answer the appeal within 45 days. Washington residents may also raise a complaint with the Washington State Attorney General; in Brazil, with the ANPD (the national data protection authority).
Please note: deleting your account does not cancel your subscription — cancellation is done in the store where you subscribed (App Store or Google Play).
8. Retention
| Data | Period |
|---|---|
| Photo of the finished plate | Not retained by us (processed in memory). Google may retain limited logs, as described in Section 5. |
| Meal history | For as long as your consent is active; deleted upon withdrawal or account deletion, with backups purged within 6 months. |
| Consent records | For as long as the account exists; after deletion, we keep only a cryptographic proof (HMAC) that does not contain your email address. |
| Server access logs (no photo or analysis content) | 6 months (required by art. 15 of Brazil's Internet framework law, the Marco Civil da Internet). |
Subscription and tax records — which are not health data — are kept for up to 5 years after the underlying event and are de-identified when the account is deleted.
9. What we do not do
- We do not sell consumer health data — to anyone, ever.
- We do not share health data for advertising or marketing.
- We do not use geofencing — no virtual geographic fences, around health services or anywhere else.
- We use no tracking pixels, third-party analytics SDKs, or data brokers.
10. Children
MeuMenu is not directed to children under 13, and we do not knowingly collect health data from children under that age.
11. Changes to this policy
Any change will be published on this same page, with a new version and date at the top of the document.
12. Contact
OXETECH TECNOLOGIA LTDA — CNPJ 67.217.613/0001-56 Av. Miguel Castro, 1264 — Nossa Senhora de Nazaré, Natal/RN, CEP 59.062-000, Brasil Data Protection Officer: OXETECH TECNOLOGIA LTDA Email: suporte@oxetech.cloud