Contents
- 1. Who we are and what this covers
- 2. Privacy at a glance
- 3. What “personal information” and “consumer health data” mean
- 4. Consumer health data (Washington My Health My Data Act)
- 5. Information we collect, and where it comes from
- 6. Accounts and integrations you connect
- 7. How we use information
- 8. What we never do
- 9. How and when we share information
- 10. Cookies, local storage, tracking, and advertising
- 11. Data retention and deletion
- 12. Security
- 13. Your privacy rights and how to use them
- 14. Children’s privacy
- 15. Other U.S. state privacy rights
- 16. Where your data is processed
- 17. Changes to this policy
- 18. How to contact us
1. Who we are and what this covers
This Privacy Policy explains how WeirdWorldMedia, LLC, doing business as metabomap (“metabomap,” “we,” “us,” or “our”), collects, uses, and shares information when you use our websites (metabomap.com and app.metabomap.com), our web and mobile applications, our APIs, and related services (together, the “Services”).
metabomap is a wellness and self-tracking tool. Much of what you log is health-related, so this policy is written to serve as our Consumer Health Data Privacy Policy under Washington’s My Health My Data Act (MHMDA), in addition to explaining our general privacy practices. If you are a Washington resident (or your health data is collected in Washington), the consumer-health-data terms in Sections 4 and 13 apply to you.
By creating an account or using the Services, you acknowledge this policy. Where the law requires consent - in particular for collecting or sharing consumer health data beyond what is necessary to provide a feature you request - we ask for it separately and specifically, at the moment it matters (for example, on the consent screen you see before connecting a device integration).
2. Privacy at a glance
- Our business model is subscriptions, not data. We never sell your personal information or your health data, and we never use your health data to target advertising. The Services carry no advertising today; Section 10 explains what we would and would not do if that ever changes.
- Your log is private by default. Nothing you record is visible to anyone else unless you explicitly post or share it.
- Health data is collected only because you choose to log it or you connect an integration and approve exactly what it may share.
- Integrations are opt-in, scoped, and reversible. You pick the data categories on the provider’s consent screen and can disconnect at any time.
- Data received from Google is used only to provide features to you, under Google’s Limited Use requirements (Section 6) - never for ads, never sold, never used to train AI models.
- You can export your data and delete your account at any time, and Washington’s MHMDA rights - withdraw consent, delete, appeal - are built into this policy (Sections 4 and 13).
3. What “personal information” and “consumer health data” mean
Personal information is information that identifies you or is reasonably linkable to you - for example, your email address, account identifiers, the entries in your log, and technical identifiers like session tokens.
Consumer health data (“CHD”) is the subset of personal information that identifies your past, present, or future physical or mental health status. On metabomap, CHD includes the wellness data you choose to log and the health-related data you authorize an integration to share - for example, foods and meals, nutrition and macronutrient information, body measurements and weight, blood-glucose and ketone readings, fasting and exercise activity, and data such as activity, sleep, and glucose synced from a device or account you connect.
De-identified or aggregated information is information that can no longer reasonably be linked to you (for example, “the median logged breakfast contains 14 g of carbohydrate”). It is not personal information, and we may use it to operate and improve the Services. We commit to maintaining de-identified data as de-identified and never attempting to re-identify it, and we require the same of anyone we share it with.
4. Consumer health data (Washington My Health My Data Act)
For consumer health data, this policy discloses, as MHMDA requires:
- the categories of CHD we collect and the purposes for collecting them (Sections 5, 6, and 7);
- the sources we collect CHD from (Sections 5 and 6);
- the categories of CHD we share, if any, and the categories of third parties we share it with (Section 9);
- that we do not sell CHD (Section 8); and
- how you exercise your rights, including the right to withdraw consent, to have CHD deleted, to confirm whether we collect or share your CHD, and to appeal (Section 13).
Consent. We collect the health data you log because you choose to enter it in order to receive the Services. We ask for your affirmative consent before collecting CHD beyond what is necessary to provide a feature you request - connecting an integration is always your action, scoped by the categories you approve on that provider’s consent screen - and we obtain separate consent before sharing CHD in any way not necessary to provide the Services. We do not sell CHD, and we would never do so without the separate, valid written authorization the law requires. You may withdraw consent at any time (Section 13).
No health-location tracking. We do not use geofencing around any healthcare facility, and we do not track your precise location to identify or infer health services you seek.
5. Information we collect, and where it comes from
We collect information from you directly and from integrations you explicitly connect - nowhere else. We do not buy personal information about you from data brokers.
Account information. Email address, display name, and a hashed password. If you sign in with Google instead of a password, we receive basic profile information from Google (Section 6).
Wellness and health data you log (consumer health data). The foods, meals, and recipes you record; water, fasting sessions, and exercise; body measurements and weight; and blood-glucose and ketone readings you enter. This is the core of the Service and is collected because you enter it.
Integration data you connect (may include consumer health data). If you connect a third-party account such as Google Health or Fitbit, we sync the data categories you authorize at the time you connect it - and only those. Section 6 describes each integration in detail. You control every connection and can disconnect at any time.
Community content you choose to share. Posts, comments, and any progress you share in community features. This is visible to others only when you choose to post or share it.
Payment information. When you subscribe, our payment processor Stripe collects and processes your payment details. We do not receive or store your full card number; we receive limited billing status and confirmation information needed to manage your subscription.
Technical and usage information. Basic information needed to operate and secure the Services - for example, log-in sessions, API keys you create, device and browser type, and security and error logs. We keep this to what running the Service securely requires.
Cookies and similar technologies. We use only the cookies and local storage necessary to sign you in and keep the Services working (Section 10). We do not use cross-site tracking cookies and we do not build advertising profiles about you.
6. Accounts and integrations you connect
None of the connections below are required to use metabomap. Each one is opt-in, starts with an explicit consent screen, is limited to the categories you approve there, and can be ended by you at any time in Settings → Integrations (or from the provider’s side, as noted). Health data received through any of them is consumer health data and gets every protection in Section 4.
Google Sign-In
If you choose “Sign in with Google,” Google sends us the basic profile of your Google Account: your name, your email address (and whether it is verified), and a Google account identifier we use to recognize your sign-in. That is all. We never see your Google password, and signing in does not give metabomap any ongoing access to your Google Account or its data.
Google Health
If you connect Google Health - Google’s service for health and fitness data from Fitbit devices, Pixel devices, and other compatible apps and devices - we access, read-only, only the data categories you approve on Google’s consent screen. Depending on what you approve, these are:
- activity and exercise - steps, active minutes, calories burned, and workouts;
- body measurements - weight and body-fat percentage;
- sleep - sleep sessions and stages; and
- blood glucose - glucose readings recorded by a connected device or app.
Synced entries are stored in your metabomap account alongside the data you log by hand and are used for exactly one thing: showing your own data back to you - in your log, charts, trends, goals, and reports. Disconnecting (in Settings → Integrations, or from your Google Account permissions page) stops all future syncing. Entries already synced remain in your log, where you can delete them individually or with your account, or ask us to delete them (Section 13).
Limited Use disclosure. metabomap’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and metabomap’s use of information received from the Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements. In plain language, that means data we receive from Google is:
- used only to provide the user-facing features described above, visible to you in your account;
- never used for advertising of any kind;
- never sold, and never transferred to data brokers or advertising platforms;
- never used to train generalized AI or machine-learning models; and
- never read by a human, except with your explicit consent, for security or abuse investigation, or where the law requires it.
Fitbit
If you connect a Fitbit account directly, we sync the activity, weight, and sleep data you authorize on Fitbit’s consent screen, under the same rules as above. Google is retiring the standalone Fitbit developer platform during 2026; direct Fitbit connections will transition to the Google Health connection described above, and we will ask you to re-authorize before or as that happens - the data categories and how we treat them stay the same.
Your AI assistant, and API keys you create
metabomap lets you connect your own AI assistant (for example, Claude) to your account, and lets you create personal API keys. These exist so that tools you choose can read and write your log at your direction - for example, asking your assistant to log a meal. Anything your assistant reads from your account is processed by that assistant’s provider under its terms and privacy policy, so connect only tools you trust. We do not send your data to any AI provider ourselves, and connections and keys can be revoked at any time in Settings.
Food-database lookups
When you search the food catalog or scan a barcode, our servers may query public food databases (for example, Open Food Facts) using only the search text or barcode - never your identity, your account, or anything from your log.
7. How we use information
We use information for a short, defined set of purposes:
- To provide the Services - the main purpose: showing your data back to you as logs, charts, goals, reports, meal plans, and the features you ask for.
- To operate securely - authentication, fraud and abuse prevention, debugging, and keeping the Services available.
- To handle billing - managing your subscription, renewals, and refunds through Stripe.
- To communicate with you - service and account messages, responses to your requests, and (only if you opt in) product news. You can opt out of non-essential email at any time.
- To improve the Services - understanding, in aggregate, what works and what breaks. We use the minimum data necessary and prefer aggregated or de-identified information (Section 3) for this.
- To meet legal obligations - complying with law and enforcing our Terms.
We will never use your health data for marketing or advertising without your separate, explicit consent.
8. What we never do
These are standing commitments - things we will not do, not merely descriptions of how the Services happen to be configured this month:
- We do not sell your personal information or your consumer health data.
- We do not share your health data with advertisers or data brokers.
- We do not use your health data to target advertising or to build advertising profiles, and we will never use your health data for marketing without your separate, explicit consent.
- We do not allow third-party behavioral advertising pixels or cross-site trackers behind your login.
- We do not use your data to train AI or machine-learning models.
Separately, and as a matter of present fact rather than permanent promise: the Services carry no advertising at all today. Section 10 explains what would change, and what would not, if we ever introduce it.
9. How and when we share information
Your log is private by default. Nothing you record is visible to other users unless you explicitly post or share it. We share information only in these limited ways:
- Service providers (“processors”). Companies that help us run the Services under contract, bound to use the information only on our instructions and to protect it. These are: our hosting and infrastructure provider (Amazon Web Services, in the United States), our payment processor (Stripe), and, when live, our email-delivery provider. Where a provider processes consumer health data, it does so only to perform that service for us - not for its own purposes.
- Integrations you direct. When you connect a third-party account (Section 6), generate an API key, or connect an AI assistant, information flows to or from that service at your direction. You control these connections and can end them at any time.
- Community, when you choose. Content you post in community features is shared with other users as you direct.
- Legal and safety. When we reasonably believe disclosure is required by law, legal process, or to protect the rights, safety, or property of users, the public, or metabomap. If a demand for consumer health data ever comes without a valid legal instrument, we will refuse it.
- Business transfer. If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will require the successor to honor this policy, and we will notify you of any change in who controls your data.
We do not share consumer health data with any third party for that party’s own purposes, and we do not share it with advertisers or data brokers. Other websites linked from the Services have their own privacy practices, which this policy does not cover.
10. Cookies, local storage, tracking, and advertising
We use only strictly necessary cookies and browser storage:
- Session cookie - keeps you signed in. Deleted or expired when your session ends.
- Security tokens - protect forms and requests against forgery, for as long as your session lasts.
- Local preferences - your device stores interface choices (for example, theme or which chart view you prefer) locally, on your device, so the app remembers how you like it.
That is the whole list. We do not use advertising, analytics-for-advertising, or cross-site tracking cookies, and our marketing site loads no third-party resources at all. Because we do not track you across sites, we honor “Do Not Track” and Global Privacy Control signals by default - there is no cross-site tracking to opt out of.
Advertising and affiliate links. The Services carry no advertising today. We may introduce advertising, sponsored placements, or affiliate links in the future - most likely on the free tier. If we do, every one of the following will hold:
- any advertising will be contextual only - selected from the page or feature you are looking at, never from your health data, your log, or a profile built about you;
- we will not share your personal information or consumer health data with advertisers, ad networks, or data brokers;
- we will not allow third-party behavioral advertising pixels or cross-site trackers behind your login;
- data we receive from Google APIs will never be used for advertising of any kind, in line with the Limited Use commitments in Section 6, which are unaffected by anything in this section; and
- we will update this policy and notify you before any advertising goes live - you will not discover it by finding an ad.
Affiliate links are links to third-party products where we may earn a commission if you buy something, at no additional cost to you. They carry no tracking of you back to us beyond what the destination site does under its own policy, they are disclosed where they appear, and a commission never determines what we recommend.
11. Data retention and deletion
- Your account data is kept for as long as your account exists, so the Services can show it back to you.
- When you delete your account - or ask us to delete your data - we delete it (or de-identify it) within a reasonable period, except for the limited records we are legally required to keep (for example, certain billing and tax records).
- When you disconnect an integration, syncing stops immediately. Entries already synced stay in your log under your control, and you can delete them like anything else you logged.
- Backups are encrypted and age out on a defined cycle; deleted data leaves backups as they rotate.
- De-identified, aggregated data (Section 3) may be retained and used to operate and improve the Services.
12. Security
We protect your information with measures appropriate to its sensitivity:
- all traffic to and within the Services is encrypted in transit (HTTPS/TLS);
- passwords are stored only as salted hashes, never in a readable form;
- credentials for integrations you connect (such as Google Health or Fitbit access tokens) are stored encrypted at rest with modern authenticated encryption;
- backups are encrypted;
- administrative access to production systems is tightly limited; and
- accounts are protected by rate limiting and abuse monitoring.
No method of storage or transmission is perfectly secure, but we work to protect your data and to respond promptly to any incident. If a breach affecting your personal information ever occurs, we will notify you as the law requires.
13. Your privacy rights and how to use them
Wherever you live, you can:
- access the data you have logged, at any time, inside the app;
- confirm whether we collect, share, or sell (we don’t sell) your personal information or consumer health data;
- correct inaccurate information;
- delete your account and its data;
- obtain a copy of the data you provided, in a portable form; and
- withdraw consent for any integration by disconnecting it in Settings, and withdraw consent for our processing of your consumer health data.
Consumer health data rights (MHMDA). In addition to the above, you have the right to withdraw consent to our collection and sharing of your consumer health data, and the right to have your consumer health data deleted. When you exercise the right to delete consumer health data, we will delete it from our records and direct our service providers to do the same, consistent with the law.
How to exercise your rights. Manage and export much of your data directly in the app, or email info@weirdworldmedia.com. We will verify your request (to protect your account) and respond within the timelines that Washington’s My Health My Data Act and other applicable consumer-privacy laws require. We will not discriminate against you for exercising these rights.
Appeals. If we decline a request, we will tell you why and how to appeal. To appeal, reply to our decision or email info@weirdworldmedia.com with “Appeal” in the subject line. We will respond to your appeal in writing within the time the applicable law allows. If your appeal is denied, you may contact the Washington State Attorney General at www.atg.wa.gov or the consumer- protection authority for your state.
14. Children’s privacy
The Services are for adults and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact info@weirdworldmedia.com and we will delete it.
15. Other U.S. state privacy rights
Depending on where you live, you may have additional rights under your state’s privacy law (for example, California, Colorado, Connecticut, Virginia, and others) - such as the rights to know, access, correct, delete, and opt out of sale or targeted advertising. We do not sell personal information and we do not use it for targeted advertising - meaning advertising selected on the basis of your activity gathered across different businesses’ websites and services - so there is nothing to opt out of on that front. Should we ever introduce advertising, it will be contextual only, on the terms set out in Section 10. The other rights are covered in Section 13. To exercise any state-law right, email info@weirdworldmedia.com.
16. Where your data is processed
We are based in the United States and process data in the United States. If you access the Services from outside the U.S., you understand that your information will be processed in the U.S., where privacy laws may differ from those in your location.
17. Changes to this policy
If we change this policy, we will post the new version here with a new effective date, and - if the change is material - notify you in the app or by email. Your continued use of the Services after a change takes effect means you accept the updated policy.
18. How to contact us
- Privacy contact: info@weirdworldmedia.com
- Entity: WeirdWorldMedia, LLC (Washington, USA)
Questions about your privacy or this policy? Email info@weirdworldmedia.com.