一句话说清楚:我们只收你自己填进来的东西(邮箱、面谈答复、体重围度、吃了什么练了什么、和 AI 的对话),只用来给你生成和调整方案。不卖、不用来训练模型、不投广告、没有第三方追踪代码。你随时可以发邮件到 [运营方邮箱] 要一份导出,或者要求全部删掉。
我们不是 HIPAA 意义上的「受保护实体」(covered entity),也不是它的业务伙伴 —— 你在这里填的健康信息不受 HIPAA 保护。它受这份隐私政策、以及适用的州消费者健康数据法保护。这点我们说在前面,你自己判断要不要填。
| 类别 | 具体内容 |
|---|---|
| 账号 | 你的邮箱地址。登录用魔法链接,我们不存密码。 |
| 同意记录 | 你勾选同意的时间、条款版本号、界面语言、浏览器 User-Agent 字符串。 |
| 面谈档案 | 性别、年龄、身高、体重、训练史、目标、每周怎么练、器械、忌口、饮酒和含糖饮料、记录方式;以及伤病、慢性病、用药、怀孕或哺乳状态。还包括面谈全过程的对话原文。 |
| 身体记录 | 体重、腰围等围度、体脂率(你自己填或设备读数)。 |
| 饮食与训练记录 | 你记的每一餐、每次训练的动作重量次数。 |
| 对话 | 你在「你的团队」页面问的每一句,以及 AI 的回答。 |
| 运行日志 | Vercel 和 Supabase 自动产生的技术日志(时间、请求路径、错误信息、IP 地址),用于排障和防滥用。 |
我们不收集:精确地理位置、通讯录、照片库、健康 App 的后台数据;也没有接入任何广告 SDK、社交插件或跨站追踪像素。网站只在你自己的浏览器里存少量本地数据(登录会话、同意暂存),用于让你保持登录,不用于追踪你。
我们不把你的数据用于:出售或出租、定向广告、和其他用户共享、训练或微调任何 AI 模型、任何形式的画像分析用于商业目的。
这一节是专门给华盛顿州(My Health My Data Act)、内华达州(SB 370)以及其他有消费者健康数据法的州的居民写的,但它描述的做法对所有用户一样适用。
上面第 1 节里的「面谈档案」「身体记录」「饮食与训练记录」「对话」这四类,都属于消费者健康数据:身高体重体脂围度、饮食摄入、运动情况、伤病、诊断过的慢性病、正在服用的药物、怀孕或哺乳状态、饮食失调经历。
全部来自你自己在网站上填写或说出来的内容。我们不从数据经纪商、第三方 App、可穿戴设备或任何其他来源获取你的健康数据。
只有第 2 节列的那几项:生成方案、调整方案、安全提示、年龄门槛、服务运行。没有别的用途。
只共享给下面第 4 节列的三类服务商(云托管、数据库、AI 模型转发与模型提供方),它们只能按我们的指示处理数据。我们不把你的健康数据共享给关联公司、广告商、数据经纪商、保险公司或雇主。
我们不出售你的消费者健康数据,也不做任何构成「出售」的换取对价的转移。我们从来没有出售过,将来若要出售,需要事先另外拿到你签署的书面授权 —— 而这不在计划里。
发邮件到 [运营方邮箱],写清你要什么。你可以:
我们会在收到请求后 45 天内回复。确实需要更多时间的,会在 45 天内告诉你原因,最多再延 45 天。如果我们拒绝你的请求,会说明理由,你可以回信申诉,我们会重新审一次并书面答复。
我们不使用地理围栏(geofencing),也不采集你的位置。
| Supabase(美国区) | 存放账号和全部记录。数据库开了行级安全策略(RLS),一个账号只能读写自己的行。 |
|---|---|
| Vercel(美国) | 托管网页和后端函数,产生访问日志。 |
| OpenRouter | 把你的面谈内容和提问转发给模型提供方。按 OpenRouter 的默认策略,它不留存提示词和回答内容(只留时间、模型、token 数等计费元数据),我们没有开启它的「提示词日志」选项。 |
| Anthropic、Google | 实际生成回答的模型提供方。它们按各自的 API 条款处理请求,一般用于生成回答和滥用检测,不用于训练它们的模型。 |
| [运营方] | 运营方本人在排查故障时可能看到你的数据。除此之外不会主动读。 |
说清楚一件事:我们能约束的是自己的做法和自己的配置,不能代第三方作保证。上述服务商的政策可能变化,你可以直接去看它们各自的隐私政策。
另外,法律强制的情况(有效的法院命令、传票)下我们可能需要披露数据;发生这种情况时,只要法律不禁止,我们会通知你。
不管你住在哪个州,你都可以发邮件到 [运营方邮箱] 要求:
我们不会因为你行使这些权利而降低服务质量或收你钱。加州居民依 CCPA/CPRA 享有的知情、删除、更正、限制敏感个人信息使用、不受歧视等权利,我们按上面这套流程一并处理。
诚实地说:这是一个个人做的小项目,没有做过 SOC 2 或第三方安全审计,也没有专职安全人员。没有任何系统是绝对安全的。如果发生涉及你健康信息的数据泄露,我们会按 FTC 的 Health Breach Notification Rule 和适用的州法通知你和监管机构。
这个网站只面向 18 岁以上的人,不面向儿童。我们不会故意收集 13 岁以下儿童的个人信息。如果你是家长,发现孩子提交了信息,发邮件到 [运营方邮箱],我们会删除。
我们不做跨站行为追踪,所以浏览器的 Do Not Track(DNT)信号对我们没有实际影响 —— 无论你是否发送 DNT,我们的做法都一样:不追踪。也没有第三方在我们的页面上收集你的个人信息用于跨站追踪。
有实质性改动时,我们会更新本页顶部的生效日期,并在你下次登录时提示;涉及新的数据用途或新的共享对象时,会另发邮件,并在需要时重新征求你的同意。
隐私相关的任何问题、请求、申诉:[运营方邮箱]。请在标题里写「隐私请求」,方便我们优先处理。
In one line: We collect only what you enter (email, intake answers, weight and measurements, meals and workouts, your conversations with the AI) and use it only to generate and adjust your plan. We do not sell it, do not train models on it, do not run ads, and use no third-party trackers. Email [运营方邮箱] any time for an export or full deletion.
We are not a HIPAA covered entity or business associate — the health information you enter here is not protected by HIPAA. It is protected by this policy and by applicable state consumer health data laws. We state this up front so you can decide what to enter.
We do not collect precise location, contacts, photo library, or background health-app data, and we include no advertising SDKs, social plugins, or cross-site tracking pixels. The site stores a small amount of local data in your own browser (session, pending consent) to keep you signed in — not to track you.
We do not use your data to sell or rent, to target advertising, to share with other users, to train or fine-tune any AI model, or to profile you for commercial purposes.
This section is written for residents of Washington (My Health My Data Act), Nevada (SB 370), and other states with consumer health data laws. The practices it describes apply to all users.
Categories collected: the intake profile, body records, food and workout logs, and conversations described in Section 1 — including height, weight, body fat, measurements, dietary intake, exercise, injuries, diagnosed chronic conditions, current medications, pregnancy or nursing status, and eating-disorder history.
Sources: only what you type or state in the app. We obtain no health data from data brokers, third-party apps, wearables, or any other source.
Purposes: only those listed in Section 2.
Categories of third parties we share with: only the service providers listed in Section 4 (cloud hosting, database, AI gateway and model providers), acting on our instructions. We do not share health data with affiliates, advertisers, data brokers, insurers, or employers.
Sale: we do not sell your consumer health data and have never done so. Any future sale would require your separate signed written authorization — and none is planned.
Exercising your rights: email [运营方邮箱] to (a) access the consumer health data we hold about you and the list of third parties we have shared it with, (b) delete your consumer health data, including requesting deletion by our processors, or (c) withdraw your consent to collection and sharing. We respond within 45 days; if we need longer we will tell you why within those 45 days and may extend once by 45 days. If we deny a request, we explain why and you may appeal by reply email, which we review and answer in writing.
Geofencing: we use none and collect no location data.
To be clear: we can commit to our own practices and configuration, but we cannot make guarantees on behalf of third parties. Their policies may change; review their privacy policies directly. We may also have to disclose data when legally compelled (valid court order or subpoena); we will notify you unless prohibited from doing so.
Regardless of where you live, email [运营方邮箱] to access, export (machine-readable JSON), correct, or delete your data, or to withdraw consent and stop using the service. We will not degrade your service or charge you for exercising these rights. California residents' CCPA/CPRA rights — to know, delete, correct, limit use of sensitive personal information, and not be discriminated against — are handled through the same process.
HTTPS everywhere; passwordless one-time email links; row-level security between accounts; API keys held only in server-side environment variables and never sent to the browser.
Honestly: this is a small personal project with no SOC 2 report and no third-party security audit, and no dedicated security staff. No system is perfectly secure. If a breach involves your health information, we will notify you and regulators as required by the FTC Health Breach Notification Rule and applicable state law.
This site is for people 18 and older and is not directed to children. We do not knowingly collect personal information from children under 13. Parents who believe their child submitted information should email [运营方邮箱] and we will delete it.
We do no cross-site behavioral tracking, so a browser Do Not Track signal changes nothing about our practices — we do not track either way. No third parties collect personal information on our pages for cross-site tracking.
For material changes we update the effective date at the top of this page and show a notice at your next sign-in. New purposes or new recipients are announced by email and, where required, we ask for consent again.
Privacy questions, requests, and appeals: [运营方邮箱]. Please put "Privacy request" in the subject line.