Version 2.0 · Effective 2026-08-13
This policy applies to consumer health data and is provided under the Washington My Health My Data Act (RCW 19.373) and Nevada SB 370. It is a separate document from our general Privacy Policy, which continues to apply to all other information.
Ketonoir LLC is the entity responsible for the consumer health data described here. If anything in this policy conflicts with the general Privacy Policy in respect of consumer health data, this policy governs.
Version 2.0 is a substantial expansion of version 1.0. It names every category of consumer health data the product collects and every third party that receives any of it, including categories and recipients that version 1.0 did not list. Where this version and an earlier one differ, this version is the accurate one. Nothing here is a new practice being announced; it is a fuller description of what the product does.
The descriptions in this policy are true for every user. The rights in section 6 are given to Washington and Nevada residents by statute, and we honour them for anyone who asks.
This section lists every category of consumer health data we collect. Because the statute makes this document a ceiling on what we may collect, use and share, the list is written to be exhaustive rather than illustrative. If a category is not named here, we do not collect it.
We do not collect consumer health data in order to advertise to you. We do use it beyond delivering the feature you are using at the time, in one way, and it is set out below rather than buried: we analyse it internally to operate the business (section 1.9).
During onboarding we ask whether any of the following apply to you: pregnancy or nursing, kidney, liver or pancreatic disease, a history of eating disorders, medication for diabetes, blood pressure or blood thinners, gallbladder issues, type 1 diabetes, a heart attack, stroke or major cardiac event in the last six months, use of an SGLT2 inhibitor, and active cancer treatment.
Purpose. To decide whether AI coaching is made available to you or whether the app operates in tracking-only mode, and to give the AI coach the safety context it needs so its guidance accounts for your declared conditions. This is a safety control, not a marketing input.
What else happens to it. Your declared conditions are sent to Anthropic on every AI coach turn, so that the coach can take them into account. We separately record the outcome of the screening: how many conditions you flagged and the fact that your account is in restricted mode. That outcome is sent to our analytics provider against your account identifier, is visible to our operators, and is included in the operator analysis described in section 1.9. Your answers and the outcome are also written into the consent record described in section 7, which survives account deletion.
Body weight and body composition, blood ketones (BHB), blood glucose, blood pressure (systolic and diastolic), blood lipid panel values (total cholesterol, LDL, HDL and triglycerides), and any free-text note you attach to a reading.
Where a reading was imported from Apple Health or Health Connect rather than typed in, we store two further things with it. One is the health platform’s own record identifier for that sample. The other is the name of the app or device that originally produced the reading — for example a continuous glucose monitor, a smart scale or a blood-pressure cuff. A device name can itself indicate a condition, so we treat it as consumer health data. It is kept permanently in the reading’s note field, and it is included in the biomarker history sent to Anthropic on an AI coach turn.
Purpose. To display your trends, to inform coaching guidance you ask for, to avoid importing the same reading twice, and to show you where a reading came from.
Meals and foods logged (name, portion, calories, protein, fat, carbohydrate, net carbs, fibre, meal slot and time), water intake, exercise, height, weight, goal weight, sex at birth, activity level, dietary preferences and diet type, allergies and sensitivities (both the standard allergen list and anything you type in yourself), health goals, and your birth year.
We also collect the food search terms you type, the product barcodes you scan — including barcodes of dietary supplements, which we look up against the NIH Dietary Supplement Label Database — and the restaurant chains and menu items you choose. Search terms and barcodes are sent to outside food databases, listed in section 4.1, so that we can return nutrition facts.
Purpose. To calculate your macro targets, produce your logs and forecasts, warn you when a logged food contains an allergen you listed, look up what you are eating, and confirm you are 18 or older. Only your birth year is retained; the full date of birth is evaluated on your device and is not transmitted to us.
Every message you send to the AI coach and every reply it sends you, kept verbatim. In the mobile app the whole conversation thread is stored under your account identifier. In the web beta, each exchange is stored with your message truncated to 500 characters and the coach’s reply to 800 characters.
We also keep coach memory: short free-form facts about you that the coach extracts from your conversations so it does not have to ask again. These are written by the model from whatever you told it, so they can contain any health information you have mentioned.
Purpose. To generate the coaching response you asked for and to give the coach continuity between sessions. Coach conversations are also read by our operators and used for internal analysis; see sections 1.9 and 4.
All of the following leave your device and are sent to Anthropic for analysis. This is the complete list of image and document paths in the product.
Two things about this are easy to miss, and we would rather state them than let you discover them. First, you may select any existing photograph from your device library rather than taking one for KetoNoir, and we cannot tell the difference. Second, an image is transmitted and analysed before we decide whether it is the right kind of image, so a photo the app then refuses has already been sent.
On mobile, a resized copy of the photograph is written into the app’s cache folder on your phone so it can be shown on the review screen. It stays on your phone until you or the operating system clears the app’s storage. We do not upload that copy again.
Purpose. To produce the nutrition estimate, body-composition estimate, recipe, pantry list, meal plan or barcode reading you asked for.
Analysing an image produces new health data about you that you never typed in. We treat all of it as consumer health data:
Purpose. To produce the result you asked for, to keep your pantry and recipes usable afterwards, and to refuse an analysis that should not run.
If you connect Apple Health or Google Health Connect, we ask the platform for permission to read the following, and we read all of them:
We additionally request permission to read height and body-fat percentage on both platforms, and body mass index on iOS. We do not read any of those three. They appear on the operating system’s permission sheet only because we asked for them, and you can decline them without losing anything.
Blood ketones are not read from either platform — Apple Health has no blood-ketone type and we do not read a substitute for one. Every ketone reading in your account was entered by you or logged for you by the coach. Blood lipid values are likewise entered by hand only.
How far back we read. Weight, glucose and blood pressure are imported over the window you choose for the first import, which can be up to 365 days, and then re-imported on an ongoing basis. The Metabolic Forecast reads the last 28 days of sleep, activity, heart and workout data each time it runs. The Trends screen reads up to 365 days of those same signals each time you open it.
Where it goes. Weight, glucose and blood pressure are written into your KetoNoir account as biomarker rows, stored until you delete them or your account, and sent to Anthropic as part of your biomarker history on an AI coach turn. Sleep, active energy, basal energy, steps, resting heart rate, heart rate variability and workouts are not written into your account, but they are sent to Anthropic as part of the Metabolic Forecast, and the forecast produced from them is stored on our servers. VO2 max is read but stays on your device.
Turning it off. Switching the connection off inside KetoNoir stops the app presenting the connection as active, but it does not by itself revoke the permission you granted at the operating-system level, and imports can resume. The setting that actually governs is the one in Apple Health or Health Connect; revoke KetoNoir’s access there and reading stops. We are fixing the in-app control, and until that ships this is the accurate instruction.
Per-type control. The forecast signals listed above can each be turned off individually in the app. Weight, glucose and blood pressure are currently imported together whenever the connection is active: there is no working per-type switch for those three, and blood pressure has no switch at all. We would rather say so than let the settings screen imply otherwise.
We never write anything back to Apple Health or Health Connect. We hold read permission only, on both platforms.
Our operators can see, and use to run the business, your account identifier, your engagement and cost figures, your consent and screening outcome, your adherence measures, and your coach conversations in readable form. Operators can also write free-text notes about an account.
When an operator uses the AI panel in our internal tools, the contents of that screen are sent to Anthropic for the operator’s analysis. That can include your account identifier, your outcome data, the operator’s notes about you, and up to ten verbatim turns of your coach conversation. This is a different purpose from answering a question you asked, and section 4.1 lists it separately for that reason.
Our analytics provider holds a profile identified by your account identifier and your email address. Against it we send the calories, protein, fat and carbohydrate totals of each meal you log, which biomarker fields you log, your calorie target and how far a plan deviates from it, the fact that you edited your allergies, your screening outcome, which health chart you were looking at, and your subscription events. It does not receive your biomarker values, your declared conditions, your photographs or your coach conversations.
We do not buy consumer health data, and we do not obtain it from data brokers, advertising networks, or public records.
Two limits on the above, so that it is not read more widely than we mean it. Our analytics provider does receive some health-related event data tied to your account, and our public marketing websites do carry advertising pixels that fire if you accept marketing cookies. Both are described in section 4, in sections 4.1 and 4.4 respectively. Neither involves your biomarker values, your coach conversations, your photographs or your screening answers.
Below is every third party that receives consumer health data, or data derived from it, and what each one receives. Most of them act only on our instructions, to run the Service. One does not, and we have separated it out rather than blend it in: section 4.3, advertising and web analytics on our public websites.
Washington law treats a disclosure to a service provider as something other than a “share” only where that provider is bound by a contract setting out our processing instructions. We are putting those contracts in place and do not yet have all of them signed. Until we do, read everything in section 4.1 as a disclosure we are telling you about, rather than as something the processor exception removes from the conversation.
No provider other than Anthropic receives your photographs or the contents of your coach conversations. Analytics, crash reporting, email, payment and subscription providers do not receive your biomarker values, your declared conditions, your photographs or your coach conversations. The exceptions to that sentence are stated in section 4.1 rather than hidden behind it: the meal-macro and screening-outcome events that go to PostHog, and the ketone, weight and macro averages inside the progress-report email that goes through Postmark.
This section is about ketonoir.ai, ketonoir.com and our science site. It is not about the app or your account data. Those pages carry a Meta (Facebook) pixel and a TikTok pixel. Neither loads unless you accept marketing cookies in the banner. If you accept, the pixel reports the address of the page you are on together with your IP address, your browser and that network’s own cookies. The pages carrying the pixels include health-topic pages: our clinicians page, and the page on which a copy of this policy is published. The TikTok pixel reports the page path as a named “ViewContent” event.
A page address on a ketogenic-health site can indicate an interest in a health condition, so we treat this as capable of being consumer health data even though no account, biomarker or health record is involved. Decline the banner and neither pixel loads. The Cloudflare beacon described in section 4.1 is not currently behind that banner.
Our iOS app also carries the advertising-attribution identifiers of these two networks, which authorise Apple to send them install and conversion notifications about the app. Those notifications carry no health data.
Washington law requires your consent before we collect consumer health data, a separate consent before we share it, and a signed authorization on a statutory form before any sale. We ask for consent to collection when you accept this policy and the disclaimers during onboarding, and again at the operating-system level before anything is read from Apple Health or Health Connect. We do not sell, and have never sought a sale authorization.
One place where our consent mechanics do not yet match this document. We state it here rather than leave you to find it. We do not yet take a KetoNoir-side consent for health-platform reading that is separate from the operating system’s own permission sheet. Section 1.7 tells you how to stop it. Until that consent step exists in the product, treat this policy as our disclosure of what happens and as your notice of how to refuse.
If you are in the United Kingdom or the European Economic Area, almost everything in section 1 is data concerning health, and therefore special-category personal data under Article 9(1) of the GDPR. Our lawful basis for processing it is your explicit consent under Article 9(2)(a), together with Article 6(1)(a). We do not rely on legitimate interests, on contractual necessity, or on the scientific-research condition in Article 9(2)(j), for any health data.
We accept what that basis costs us. Consent must be freely given, specific and informed, so it reaches only what this policy describes: if we want to process a new category, or send it somewhere new, we have to update this policy and ask you again first. Consent is also separable. You can use the app and refuse the health-platform connection, or the photograph features, and the rest keeps working.
Withdrawing consent. You may withdraw at any time, for all of it or any part of it, and it must be as easy to withdraw as it was to consent. Withdrawal operates going forward: it stops the processing, and it does not make what we already did unlawful. When you withdraw consent to a feature, we stop the collection that feature performs, and we delete what it produced if you ask us to. When you withdraw consent to our processing your health data at all, we cannot operate the account, so we treat that as a deletion request and close it. Withdrawal never limits your separate right to have what we already hold deleted.
To withdraw: turn the feature off in the app, revoke KetoNoir’s access in Apple Health or Health Connect, or write to the address in section 8 telling us what you are withdrawing.
Several recipients in section 4 are in the United States. Where we transfer personal data out of the United Kingdom or the European Economic Area we rely on the same explicit consent, and on our providers’ standard contractual clauses where they offer them.
If you are a Washington or Nevada resident, you have the following rights regarding consumer health data. We will not discriminate against you for exercising them. We honour the same rights for any other user who asks.
Email legal@ketonoir.ai with the subject line “Consumer Health Data Request” and tell us which right you wish to exercise. We respond within 45 days, and may extend once by a further 45 days where reasonably necessary, in which case we will tell you why before the first period ends.
You may also delete your account and its associated data at any time from inside the app, under Profile, without contacting us.
We will ask you to confirm the request from the email address on your account. If we cannot verify that you are the account holder, we will tell you rather than act on an unverified request.
Deleting your account from inside the app removes, from our live systems, your profile, food log, biomarkers, coach conversation thread, coach memory, pantry, saved recipes, body-fat estimate history and forecasts, and closes your sign-in. Your consent records are deliberately kept, for the reason given in section 7.
We also notify service providers and direct them to delete your data, and we tell you which ones, because a blanket promise here would not be accurate. We send a deletion instruction to PostHog, which removes your analytics profile and its event history, to MailerLite, which removes you as a subscriber, and to RevenueCat, which removes your subscriber record. Each result is recorded, and a provider we could not reach is recorded as not notified rather than assumed done. Stripe is deliberately not deleted: payment and invoice records carry their own retention obligations under tax, anti-fraud and chargeback rules, and erasing them to satisfy a privacy request would breach a different law. Sentry, Postmark and Anthropic have no per-user deletion path. Sentry reports are already stripped of health, food, biomarker and coach fields before they leave the device. Postmark keeps suppression records so that an unsubscribe stays honoured. Anthropic holds no per-user store to delete under the commercial terms in force.
Two things that deletion does not reach today. We would rather tell you than let you assume otherwise. If you used the web beta rather than the mobile app, the verbatim coach transcripts from that beta are stored under a separate beta code and the in-app deletion does not remove them either. And the resized copy of a photograph in your phone’s app cache sits on your device, not ours; clearing the app’s storage removes it.
Write to us at the address in section 8 and we will remove any web-beta transcripts by hand and confirm to you when that is done.
We keep consumer health data for as long as your account is active, so that the Service can show you your own history. When you delete your account we delete the associated consumer health data, to the extent set out in section 6.2.
Some specific periods, because “as long as your account is active” is not the whole picture:
One narrow exception to deletion: records of which disclaimers and policies you accepted, and when, are retained for seven years as a legal compliance record. Those records include the outcome of your health screening and the conditions you declared, because that is the evidence that the safety gate was applied correctly. They are not used for any other purpose.
Ketonoir LLC
1145 Santa Fe Drive #1297
Weatherford, TX 76087-3846
legal@ketonoir.ai