SuppLabJoin the beta

Privacy Policy

How SuppLab handles information about you — what we collect, why, and the choices you have.

Last updated August 8, 2026Version 1.1Applies to SuppLab for iOS
In short

We collect only what the app needs: your sign-in identity and the supplements and check-ins you log. Apple Health data never leaves your device. We never sell your data, show no ads, run no third-party analytics, and never track you across other apps. You can delete everything from Settings.

This Privacy Policy explains what information the SuppLab iOS app (“SuppLab,” “we,” “us”) collects, how we use it, who we share it with, and the choices you have. SuppLab is offered in the United States and is intended only for adults 18 years of age or older. If you do not agree with this policy, do not use the app.

SuppLab is a private supplement-tracking and educational tool. It is not a medical service and does not provide medical advice, diagnosis, or treatment.

01 · Information we collect

We collect only what we need to run your account and the tracking features you use.

Account and identity. You sign in with Sign in with Apple or Google. We never see your Apple or Google password. From the sign-in provider we receive a stable user identifier, your email address (which may be Apple’s private relay address if you choose to hide it), and your name, if the provider shares it, used as your default display name. You may edit your display name in Settings.

Profile and onboarding answers. Information you provide during onboarding and in Settings: your gender, age, goals, primary metric, “hardest part” answers, theme preference, and notification preferences.

Supplement tracking data. The core content you create in the app: the supplements in your stack (name, dose, schedule, reminders, reasons, and cycling configuration), your supplement logs (when you marked a supplement as taken, and how), your daily entries (mood, mental clarity, energy, sleep quality, and optional notes), and the personalized insights generated for you.

Subscription data. If you subscribe, Apple processes your payment. We do not receive your card details. We receive and store transaction identifiers and subscription status from Apple’s App Store Server API so we can grant access to premium features.

Device data. An APNs push token (if you enable notifications) and your device time zone (used to schedule insights and reminders correctly). We currently run no third-party analytics or crash-reporting SDKs, so no product-analytics or crash events are collected.

We do not track you across other companies’ apps or websites, and we do not show a tracking-permission (ATT) prompt because we do not do cross-app tracking.

02 · Apple Health (HealthKit)

If you connect Apple Health, SuppLab reads last night’s sleep duration to display alongside the sleep rating you enter yourself. That is the only Health data we read, and it is read-only — we never write anything back to Health.

This data is processed entirely on your device. It is never transmitted to our servers, never stored by us, never shared with anyone, and never used for advertising or marketing. It is not included in the de-identified data sent for insight generation.

You can disconnect at any time in the app (Settings → Apple Health), or revoke access entirely in the iOS Health app.

03 · How we use your information

  • To provide the app: store your stack, logs, daily entries, streaks, and adherence, and sync them across your devices.
  • To generate your weekly insights using an automated AI process.
  • To send notifications you have enabled (supplement reminders, daily-log reminders, and subscription win-back messages).
  • To operate subscriptions and grant or restrict premium access.
  • To keep the service secure, debug problems, and improve the product.

We do not sell your personal information, and we do not use your supplement or health-related data for advertising.

04 · Third-party service providers

SuppLab runs on infrastructure and services operated by third parties who process data on our behalf under their own terms:

  • Apple — Sign in with Apple, App Store subscriptions, and push delivery.
  • Google — Google sign-in identity verification.
  • Google (Gemini AI) — generates your insights from de-identified daily tracking data: supplement names, doses, dose dates and times of day, and your 1–5 well-being ratings. No name, no email, no account identifier, and none of your free-text notes are sent. Apple Health data is never sent.
  • Our hosting, database, and queue providers, which store your account data as the source of truth.

These third parties act as service providers/processors and are not permitted to use your data for their own independent purposes.

05 · Your data is your own record

Your tracking data is yours. You can view it in the app at any time. Because the backend is the source of truth, your data is available again when you reinstall the app or sign in on a new device.

06 · Deleting your account and data

You can delete your account from Settings → Delete Account. When you do:

  • your account is immediately hidden and scheduled for permanent deletion,
  • there is a 30-day restore window — if you sign in again with the same Apple or Google account within 30 days, you can restore everything, and
  • after 30 days, your account and all associated data are permanently hard-deleted from our systems.

Deleting your SuppLab account does not cancel your Apple subscription. Manage or cancel it separately in iOS Settings → your Apple ID → Subscriptions. Signing out clears SuppLab data from the device but does not delete your account on our servers.

07 · Data retention

We keep your account data while your account is active. Supplement logs and daily entries are retained as your historical record until you delete your account. After account deletion completes (30 days), we remove your personal data except where we must retain limited records to comply with law (for example, subscription/transaction records required for tax or audit purposes).

08 · Security

We use industry-standard measures to protect your data in transit (HTTPS/TLS) and at rest. Your session token is stored in the iOS Keychain on your device. No method of transmission or storage is perfectly secure, but we work to protect your information.

09 · Children

SuppLab is for adults 18 and older. We do not knowingly collect data from anyone under 18. If we learn we have collected data from someone under 18, we will delete it.

10 · Your privacy choices

Depending on where you live, you may have rights to access, correct, or delete your personal information, and to obtain a copy of it. You can exercise the core of these rights directly in the app (view your data, edit your profile, delete your account) or by contacting us at the address below.

11 · Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.

12 · Contact us

Questions about this policy or your data? Email supplab_support@cornerstonesoftwaregroup.com.