Consumer Health Data
Consumer Health Data Privacy Policy
This policy is specifically about consumer health data — the health-related information you enter into Together. It sits alongside our general Privacy Policy and explains, in one place, what health data we collect, why, who it is shared with, and the rights you have over it.
Last updated August 26, 2026.
What this covers
“Consumer health data” means information that is linked or reasonably linkable to you and that identifies your health status. In Together that includes the protocol and compound you record, your dose and dose changes, your weight over time, symptoms and side effects you log, any body-composition estimate, and any notes or photos you choose to attach. This policy explains how Together Tech LLC handles that category of information; our general Privacy Policy covers everything else.
What health data we collect, and why
We collect consumer health data only to operate the app you asked for:
- Your protocol: the compound, drug class, dose and unit, cadence, and start date — to build and show your record.
- Your logs: weight, symptoms and side effects (with severity), and any optional notes — to plot your trend over time.
- Health context from onboarding: your reason for taking a compound, any medical conditions you select, and your prescriber category — to organize your record and power the “people like you” comparison inside the app.
- Body-composition estimates: if you use the body scan, the estimated body-fat percentage and its range — stored as numbers only.
We collect this data because it is necessary to provide the service you requested. We do not collect consumer health data in order to sell it.
Where it comes from
All of your consumer health data comes from you — what you type and choose in the app, and any photo you choose to add for a scan. We do not buy health data about you or infer it from third-party sources.
How it is shared
Your identifiable health data is not shared for advertising and is not sold. We use a small set of service providers (sub-processors) strictly to run the app — Supabase (database and authentication), RevenueCat (subscription validation), Resend (account emails), and Vercel (website hosting) — and they may process only what is needed for those functions, on our instructions.
One additional processor applies only if you use the body scan: Google (the Gemini API) receives the two scan photos in order to compute your body-fat estimate. The photos are sent only for that request and are not stored by us; only the resulting number and range are kept. We use Google’s paid Gemini API, under which Google’s API terms provide that inputs are not used to train Google’s models and are logged only transiently for abuse prevention and legal compliance.
We may sell, license, or share health data only after it has been fully de-identified — stripped of identifiers, generalized into changes and bands rather than exact values, and released only in groups of at least 30 people so no individual can be singled out. We publicly commit to keep that data de-identified and never to attempt to re-identify it, and we require by contract that anyone who receives it does the same. Your photos are never part of this and are never sold, licensed, or shared.
Your rights
You can, at any time:
- Confirm whether we are collecting, sharing, or selling your consumer health data, and access that data.
- Withdraw consent to our collection and sharing of your consumer health data.
- Have your consumer health data deleted — including from backups, within the timeframe the law allows.
You can start permanent deletion yourself in the app at Profile → Delete Account, which removes your account, records, and the key that could ever link de-identified data back to you. To exercise any of these rights, or to appeal a decision, email us at admin@togetherpep.com. We respond within the timeframes required by law, and we will never require you to create a new account to exercise a right.
Body-scan photos
If you use the body scan, we handle the photos with particular care and ask for a separate, explicit approval before any scan. The scan produces only numbers — an estimated body-fat percentage and range. To compute that estimate the two photos are sent to Google’s Gemini API for that single request (see “How it is shared” above); we store no photo as part of the estimate, and Google does not use them to train its models. A photo you separately choose to keep is stored privately, visible only to you, and is deleted within 30 days of account deletion or when you withdraw the scan approval. Photos are never sold, licensed, or added to any shared or de-identified dataset.
Contact
Questions about your consumer health data? Email admin@togetherpep.com.