Version 1.1 — effective 17 September 2026. Changes from 1.0: the operator is now 42 TAPS INC (§1).
This is the health-specific part of the Grif Privacy Policy. It exists as a separate page because the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 and Connecticut's consumer-health-data provisions ask for one, and because Apple and Google both want a plain statement of what a health app reads and writes. It applies to everyone, not only to residents of those states.
Grif is not a medical device. It does not diagnose, treat, cure or prevent any condition, and nothing in it is medical advice. It computes calorie and macronutrient targets by published formulas, builds a training and meal programme, and keeps a diary.
42 TAPS INC, a Delaware corporation, 200 Continental Dr Ste 401, Newark, Delaware 19713-4337, United States. Contact: support@grif.fit.
| Category | Examples in Grif |
|---|---|
| Body measurements | Sex, date of birth, height, weight, neck / waist / hip circumferences, body-fat percentage (estimated from your circumferences, or read from your health store) |
| Nutrition and diet | Food exclusions (allergies and foods you do not eat), calories and macronutrients eaten, saved meals with their ingredients and grams, meal photographs and any note you type with them |
| Physical activity | Steps, workouts (type, minutes, sets, effort), active energy, the training programme and the week you are on |
| Derived data | Basal and total energy expenditure, calorie and protein targets, body-fat estimate, weekly averages — all computed by formula from the figures above |
| Consent records | Which health-related consents you gave, at which text version, when, and when you withdrew them |
We do not collect: reproductive or sexual health data, gender-affirming care data, biometric identifiers, genetic data, precise location, or any diagnosis or treatment information. The app asks no question about medical conditions.
We do not use consumer health data for advertising, for profiling with legal effect, to train models, or for any purpose you did not ask for.
| What is shared | With whom | Why | Their role |
|---|---|---|---|
| A meal or nutrition-label photograph, the note you typed with it, the meal slot, your language | Google LLC (Gemini API, primary) and, if the primary fails, OpenAI, L.L.C. (fallback) — both in the United States | To recognise the food and estimate portions. The providers may keep their copy for up to 55 days (Google) or 30 days (OpenAI) for abuse monitoring, and act only on our instructions | Processors under their data-processing terms; both are certified under the EU-US Data Privacy Framework |
| The weight, calories and macronutrients you confirmed; body-fat % once released | Apple Health or Health Connect on your own phone | To keep your health store in step with the diary | Your device; not a transfer to a third party |
| Nothing else | — | — | — |
Specifically: no consumer health data is shared with Apple, Google or Apphud for billing; no health value is sent to analytics, error reporting, or push services; a barcode lookup sends only the product's digits to Open Food Facts, with nothing about you. We have no affiliates, and we do not sell consumer health data and never have.
Separate consent for sharing. Sending a photo to a vision provider needs your specific "Food diary photographs" consent, which names the providers and the retention period on the card you accept, and is separate from the "Health data processing" consent that covers collection. Neither is bundled into the Terms of Service. Both can be withdrawn in Profile → Consents.
| Right | How |
|---|---|
| Confirm whether we collect, share or sell your consumer health data, and access it | Profile → Data and privacy → Export my data (one JSON file), or email support@grif.fit |
| Obtain the list of third parties with whom we shared it | This page, section 5. On request we will confirm which of the two vision providers handled a given scan, where our records allow |
| Withdraw consent to collection | Profile → Consents → Health data processing → "Withdraw consent and erase data" |
| Withdraw consent to sharing | Profile → Consents → Food diary photographs → off. Further scans stop at once; cached results are deleted |
| Delete your consumer health data | Profile → Data and privacy → Erase my data (keeps the account) or Delete account. We erase it from our systems immediately; the vision providers' own copies expire within their stated retention (55 / 30 days); a nightly backup may hold the erased rows for up to 30 days (Privacy Policy §8) |
| Appeal | If we refuse a request, reply to our answer within 30 days and say you are appealing. A different person will review it and answer in writing within 45 days with the reasons. Washington residents may also contact the Washington Attorney General; other states' residents, their Attorney General |
We will not discriminate against you for exercising these rights. Requests by email are verified by asking you to write from the account's address.
| Platform | Read | Write | How the permission is asked |
|---|---|---|---|
| iOS — HealthKit | Steps, weight, body-fat %, dietary energy / protein / fat / carbohydrates, workouts, active energy burned | Weight; dietary energy, protein, fat, carbohydrates of a meal you confirmed; body-fat % (once released) | From Profile → Health, behind a screen that explains why; never at first launch |
| Android — Health Connect | READ_STEPS, READ_WEIGHT, READ_BODY_FAT, READ_NUTRITION, READ_EXERCISE, READ_ACTIVE_CALORIES_BURNED | WRITE_WEIGHT, WRITE_NUTRITION (and body fat once released) | Same; Health Connect can open our rationale screen at any time |
Rules that hold on both platforms: nothing is written without your confirmation; nothing we compute (targets, programme) is ever written back; we never read back what we ourselves wrote; steps and workouts are never written by us because the phone already records them.
See the Privacy Policy §3 for the full table. In short: consumer health data is kept while your account exists and you have not erased it; it is deleted immediately on erasure, withdrawal of the health consent, or account deletion. What survives is not health data: purchase records, the consent history, and append-only journals of event types.
We will update this page whenever a category, a purpose or a recipient changes, and the in-app consent will be re-asked with a new version when the sharing terms change.
Website footer of grif.fit, the app's sign-in and paywall screens, and Profile → Legal → "Health data policy".
Terms · Privacy · Health data · Subscriptions · Third-party notices · Delete account · Home