For the DrunR mobile applications, provider dashboard, and drunr.com
Effective date: July 21, 2026
Company: DrunR, Inc. | 101 Taylor Ave N, Seattle, WA 98109, United States | support@drunr.com
DrunR is designed to help adults make more informed nutrition and wellness decisions using information they choose to provide and read-only data from connected wearable and health platforms. This Privacy Policy explains what we collect, how we use and protect it, and the choices available to you.
1. Scope and eligibility
This Policy applies to the DrunR mobile applications, the DrunR provider and nutrition professional dashboard, drunr.com, and related services (collectively, the “Services”). The Services are offered only in the United States and are intended for adults age 18 or older. DrunR is not directed to children, and we do not knowingly collect personal information from anyone under 18.
2. Information we collect
Account and authentication information
- Name and email address.
- Account credentials or authentication identifiers when you sign in with email and password, Sign in with Apple, or Google Sign-In.
- We do not collect your phone number for account registration.
Profile, nutrition, and wellness information
- Information you enter about your nutrition preferences, dietary needs, allergies or sensitivities, goals, meals, restaurant choices, and food selections.
- Profiles information you choose to provide, which may include age, height, weight, and sex-related information used to personalize the Services.
- The name of a GLP-1 medication you choose to identify. DrunR does not request or collect medication dosage through the current Services.
- Your interactions with recommendations, saved items, plans, and other features.
Connected wearable and health-platform data
With your permission, DrunR may read selected data from supported wearable devices and health platforms, such as Apple Health or Android Health Connect. Depending on the connection and permissions you grant, this may include activity, steps, sleep, heart rate, resting heart rate, heart-rate variability, calories burned, workouts, weight, and glucose or continuous glucose monitoring data. Access is read-only: DrunR does not write data back to connected health platforms. You control the categories authorized through the relevant platform settings.
Provider connection information
A doctor, registered dietitian, nutritionist, or other wellness professional may recommend DrunR or send a connection request. We collect the information needed to display and manage that request. We do not disclose your DrunR data to that professional unless you affirmatively authorize the connection.
Technical and operational information
We may collect limited technical information necessary to operate, secure, and troubleshoot the services, such as IP address, device and operating-system type, app version, login events, security logs, and error information. DrunR does not currently use third-party advertising analytics, behavioral analytics, or cross-app tracking tools.
3. How we use information
- Create, authenticate, and maintain your account.
- Provide nutrition, activity, and wellness features and personalize recommendations based on your profile, food context, connected signals, goals, and current state.
- Process multimodal inputs through DrunR’s scientific and deterministic scoring systems to reduce noise, define relevant states, apply weights and scores, and produce structured insights.
- Present those structured insights and recommendations in understandable natural language. DrunR does not send your personal or health data to external large-language-model providers.
- Enable a provider or nutrition professional to view authorized data after you approve a connection.
- Operate, secure, debug, improve, and support the Services; comply with law; and enforce our Terms of Service.
4. Consumer health data
Certain information described above may qualify as “consumer health data” under state law, including Washington’s My Health My Data Act. The categories we collect may include nutrition and dietary information, medication name, physical activity, sleep, heart and biometric signals, weight, glucose data, and inferences or scores derived from those inputs.
We collect consumer health data directly from you and, with your authorization, from connected wearable devices and health platforms. We collect it to provide the features you request, personalize wellness guidance, maintain your account, secure the Services, and support an authorized provider connection. We do not sell consumer health data. We do not use it for advertising. We do not share it with third parties for their independent commercial or noncommercial purposes.
You may withdraw permission for a connected source through the relevant device or platform settings. Disconnecting a source stops future collection from that source but does not automatically delete data already imported to your DrunR account. You may delete the imported data by deleting your account or contacting us.
5. Provider and nutrition professional access
Professionals do not receive access merely because they recommend DrunR or send a request. Before any disclosure, DrunR will present a clear authorization identifying the professional and the categories of information to be made available. Once authorized, the professional may use the dashboard to view the data and insights included in your authorization. You may revoke access at any time through the Services or by contacting us. Revocation stops future dashboard access but cannot require a professional to delete information previously exported or documented in the professional’s own records. Ask the professional about their privacy practices.
6. When information may be disclosed
DrunR does not sell, rent, license, or disclose personal or health information for advertising, data brokerage, model training, or unrelated commercial purposes. We may disclose information only in the following limited circumstances:
- At your direction, including to a provider or nutrition professional you explicitly authorize.
- To infrastructure, security, authentication, and other service providers acting only on DrunR’s instructions and subject to contractual confidentiality and data-protection obligations. For example, Apple or Google may process authentication information when you choose their sign-in service. These providers may not use DrunR data for their own advertising or unrelated purposes.
- When reasonably necessary to comply with law, legal process, or a valid governmental request; protect users, DrunR, or others; investigate fraud or security incidents; or establish or defend legal claims.
- In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections and applicable law.
7. Data storage, retention, and security
DrunR stores account and health-related information on systems controlled by DrunR in the United States. We retain information while your account is active and for as long as reasonably necessary to provide the Services, meet legal obligations, resolve disputes, and protect the security and integrity of the Services. We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls and protections for data in transit and at rest. No security measure can guarantee absolute security.
When you delete your account, DrunR initiates deletion immediately and removes active account data without an avoidable waiting period. Limited information may remain temporarily in encrypted backups, security logs, or records retained where required by law, and is deleted or isolated under our ordinary backup and retention cycle.
8. Your choices and rights
- Access and correction: review or update available account and profile information in the Services or contact us.
- Deletion: delete your account directly in the app. Account deletion is available without contacting support.
- Wearable permissions: change or revoke permissions through the connected platform or device settings.
- Provider access: approve, decline, or revoke a professional connection.
- State privacy rights: depending on where you live and whether a law applies to DrunR, you may request access, correction, deletion, or a copy of personal information and may appeal a denied request. DrunR does not sell personal information or use it for targeted advertising, so an opt-out of those practices is not necessary.
To exercise a right or appeal a decision, use available in-app controls or email support@drunr.com. We
may take reasonable steps to verify your identity and authority. We will not discriminate against you for
exercising applicable privacy rights.
9. Apple Health and Health Connect
DrunR requests access only to health-data categories used for visible app functionality. Health data obtained through Apple Health or Android Health Connect is not used for advertising, marketing, data mining, or sale. DrunR does not disclose such data to third parties except as necessary to provide the user-requested functionality, with the user’s explicit authorization, or as required by law. You can manage permissions at any time in the applicable platform settings.
10. Artificial intelligence and automated processing
DrunR uses software models, deterministic rules, and scoring methods to transform the data you provide into state definitions, scores, and recommendations. Natural-language technology may be used within DrunR-controlled systems to explain recommendations in a conversational format. DrunR does not disclose your personal or health information to external LLM providers and does not permit your data to be used to train third-party AI models. Automated outputs are informational and should be evaluated in light of your circumstances and professional medical advice.
11. Not a HIPAA notice
This Privacy Policy is not a Notice of Privacy Practices under the Health Insurance Portability and Accountability Act (“HIPAA”). DrunR’s direct-to-consumer Services may not be subject to HIPAA. A healthcare provider using information obtained through the Services may have separate obligations under HIPAA or other law. If DrunR enters into a relationship in which it acts as a business associate of a covered entity, that relationship will be governed by the applicable agreement and legal requirements.
12. Changes to this Policy
We may update this Policy as the Services or legal requirements change. We will post the updated Policy with a revised effective date and provide additional notice when required. Material changes affecting consumer health data will not be applied retroactively without any consent required by law.
13. Contact us
DrunR, Inc.
101 Taylor Ave N, Seattle, WA 98109, United States
support@drunr.com