Legal
Privacy Policy
This policy describes the LeanLife mobile app and leanlifeapp.com. LeanLife connects bank accounts through Plaid and lets you track medications and supplements for cost and refill reminders. Those categories are disclosed in full below. LeanLife is not a bank, not a medical provider, and not a HIPAA covered entity.
1. Who we are
LeanLife (“we”, “us”) is a household savings app. The product includes FreshTrack (pantry and expiry), SubScan (recurring charges and spending snapshots via Plaid), MedMind (medication and supplement cost tracking), PriceIQ (nearby fuel prices by ZIP), and MoneyMap (monthly Waste Report of recovered dollars and still-on-the-table opportunities). LeanLife does not include a grocery-list module. We store account data on Supabase and bill subscriptions through the Apple App Store or Google Play via RevenueCat.
Contact: support@leanlifeapp.com · Support: leanlifeapp.com/support
2. Data we collect
We collect only what the product needs. Categories below match Apple’s Privacy Nutrition Labels and Google Play’s Data safety form.
Account and contact
- Email address and password (password is hashed by our auth provider; we do not store it in plaintext).
- Display name (first and last name you enter at sign-up).
- Waitlist email if you join from leanlifeapp.com before creating an app account.
Financial information (SubScan / Plaid)
- If you choose Connect a bank, Plaid Link opens so you can sign in with your financial institution. We never receive your bank username or password.
- Plaid returns an access token that we store server-side on your user id, plus institution name.
- We pull up to 24 months of transactions (merchant name, amount, date, category, and similar metadata), keep a spending snapshot, and keep detected recurring charges: merchant, amount, currency, frequency, last charge, next renewal, confidence, and whether you marked the charge cancelled in LeanLife. Bank linking is available only on a paid LeanLife subscription, not during the 7-day trial.
- We do not store full account numbers, routing numbers, or card PANs. We do not use Plaid to move money.
Health-adjacent information (MedMind)
- Medication or supplement name, dose, form, quantity, NDC or barcode if scanned, refill or run-out date, estimated cost, pharmacy name and cash/coupon price, GoodRx link, ZIP used for local prices, and used/expired status.
- This is user-provided inventory and cost data. We do not connect to Apple Health, HealthKit, Google Health Connect, or a clinic. We do not diagnose, treat, or give medical advice.
- Camera frames used to scan a bottle barcode are processed to look up the product. We do not keep a photo gallery of your medications.
Pantry, photos, and receipts (FreshTrack)
- Food item name, quantity, storage, category, expiry, estimated cost, barcode, and optional product image URL from Open Food Facts.
- Receipt photos are sent to a secure function for text detection (Google Cloud Vision), parsed into line items, and are not stored as a public gallery. Parsed item names and prices may be saved to your pantry.
Approximate location
- ZIP code (and optional city/region) that you type for PriceIQ gas prices and MedMind pharmacy lookups. We do not request GPS or precise location.
- Usual gas station name, fuel type, and price so we can alert you when a nearby pump is cheaper.
Purchases
- LeanLife Premium status, trial dates, product id (
leanlife_premium_monthlyorleanlife_premium_annual), and RevenueCat app user id. Card numbers are processed by Apple or Google, not by us.
Device, identifiers, and notifications
- Expo push token, platform (iOS/Android), and device timezone so we can send local-morning expiry, refill, and renewal reminders.
- Face ID / biometrics stay on device to unlock sign-in; we do not receive biometric templates.
- Optional “remember email” on the device via the OS secure store.
Support and user content
- In-app and website Help chat messages, session id, and (if you escalate) email, subject, question, and transcript sent to support@leanlifeapp.com.
- Optional notes you attach to a medication.
Permissions on the device
- Camera — barcodes, grocery receipts, and medication bottles.
- Notifications — refill, expiry, subscription renewal, and cheaper-gas alerts.
- Biometrics — optional sign-in.
- We do not need microphone, contacts, photos library, or tracking (IDFA).
3. How we use data
- App functionality: sign-in, pantry, bank-linked subscription and spending analysis, refill reminders, gas alerts, Waste Report (recovered vs potential), and customer support.
- Account management: trial, paid access, restore purchases, and a 2-month data hold after access ends so you can resubscribe. Linked banks stay connected for 1 week after a paid plan ends, then the Plaid item is revoked. Bank linking is not part of the trial.
- Product improvement: anonymized or aggregated patterns may inform FAQ training after a support ticket is resolved. We do not sell personal data or use it for third-party advertising.
- Security: authenticate sessions, prevent abuse, and debug failures.
We do not use your data to track you across other companies’ apps or websites. We do not run a third-party advertising SDK.
4. Who we share data with
We share data with processors who help us run LeanLife. They are not allowed to use it for their own marketing of LeanLife users.
| Recipient | Why | Typical data |
|---|---|---|
| Supabase (Postgres, Auth, Edge Functions) | Host accounts and app data | All account-linked records listed above |
| Plaid | Bank connection and transaction fetch | Link session; Plaid holds bank login. We receive tokens and transactions |
| Apple / Google / RevenueCat | Subscriptions and restore | App user id, product, entitlement, store transaction identifiers |
| Anthropic (Claude) | Meal ideas, Waste Report summary, Help chat, FAQ training | Pantry names/expiry; monthly savings totals; chat text you type |
| Google Cloud Vision | Receipt text detection | Receipt image for that request |
| GoodRx (when credentials are configured, otherwise a search link) | Local cash/coupon pharmacy prices | Medication name, dose, form, quantity, NDC, ZIP |
| GasBuddy | Nearby fuel prices | ZIP / city |
| Open Food Facts | Barcode product lookup | Barcode |
| Expo (push) | Send reminder notifications | Push token and notification body |
| Email (support inbox) | Human follow-up you request | Your email, question, and chat transcript |
We may disclose information if required by law or to protect users, our service, or others. We do not sell personal information as that term is used in the CCPA/CPRA.
5. Retention
- Active accounts: data stays while the account is open.
- After trial or paid access ends: pantry, medications, detected charges, and reports are retained for 2 months so you can restore. Linked banks stay connected for 1 week after a paid plan ends, then the Plaid connection is revoked so it does not keep billing. After 2 months those household records are deleted.
- Plaid access tokens are kept only while a bank remains linked on a paid account, or for 1 week after that paid plan ends; we revoke the item after that week, when you ask us to disconnect, or when the 2-month retention window is purged. Trial accounts cannot connect a bank.
- Receipt images are processed in transit and are not kept as a user-facing gallery.
- Support tickets and emails are kept as needed to resolve the request and improve Help answers.
6. Your choices
- Skip bank linking. Connecting a bank is a paid SubScan feature and is not available during the 7-day trial. After you subscribe, we pull up to 24 months of transactions if you connect.
- Skip MedMind or enter only the meds you want tracked.
- Change or clear ZIP in PriceIQ.
- Turn off notifications in system settings.
- Change email or password in Help.
- Request deletion: email support@leanlifeapp.com from the address on the account with subject “Account Deletion Request”. We will delete the account, pantry, medications, Plaid item, push tokens, and related records except what we must keep for legal, security, or billing records.
- Plaid’s own controls: you can also manage connected apps in your Plaid portal where available. See Plaid’s legal center.
7. Children’s privacy
LeanLife is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child created an account, email support@leanlifeapp.com and we will delete it.
8. Health and financial notices
MedMind is a household inventory, reminder, and price-comparison tool. It is not a medical device, not clinical decision support, and not a substitute for a pharmacist, clinician, or prescription label. Do not rely on LeanLife for dosing, interactions, or diagnosis.
SubScan is read-only transaction analysis. After you subscribe and connect a bank, we may pull up to 24 months of transactions to categorize spending, detect recurring and duplicate charges, and keep a spending snapshot. LeanLife is not a bank, broker, or money transmitter. Marking a charge “cancelled” in LeanLife does not cancel the merchant. Bank login happens inside Plaid, not inside LeanLife.
9. Security
Data in transit uses HTTPS. Row-level security ties pantry, medications, subscriptions, spending snapshots, and reports to your user id. Plaid tokens are stored server-side and are not exposed to the client. No method of transmission or storage is 100% secure.
10. International users
We currently operate the service from the United States. If you use LeanLife from elsewhere, you consent to processing in the U.S. If you are in the EEA/UK, you may have rights to access, correct, delete, restrict, or port your data, and to object to certain processing. Email support@leanlifeapp.com to exercise those rights.
11. California and similar U.S. state laws
We collect the categories in Section 2 for the business purposes in Section 3. We do not sell or share personal information for cross-context behavioral advertising. You may request access or deletion as described in Section 6. We will not discriminate against you for exercising those rights.
12. Changes
We will post updates on this page and change the “Last updated” date. Material changes that affect Plaid or MedMind data will be highlighted in the app or by email when we have an address on file.