PRIVACY NOTICE

Last Updated: June 12, 2026 Effective Date: June 12, 2026

Operated by: Seven Six Labs LLC ("Seven Six Labs," "we," "us," or "our"), a Washington State Limited Liability Company. Product: LiveNori — a personal food, symptom, and wellness tracking application and related websites and services (collectively, the "Service"). Website: https://livenori.com Privacy Contact: privacy@livenori.com Mailing Address: Seven Six Labs LLC, Spokane, Washington, USA

Plain-English summary (not a substitute for the full notice): We are a tiny Washington-based company that makes a wellness journaling app. You log food, symptoms, mood, sleep, and other lifestyle data; we store it securely so you can analyze your own patterns. We do not sell your data, ever. We share your data only with the small set of vendors needed to run the app (such as our hosting provider and our payment processor) and only when legally required. You can ask us to export or delete your data at any time. The app is not a medical device, not intended for children under 13, and not a substitute for professional medical advice.


1. SCOPE AND ACCEPTANCE

This Privacy Notice describes how Seven Six Labs LLC collects, uses, discloses, retains, and protects information when you (a) install, access, or use the LiveNori mobile or web application; (b) visit https://livenori.com or any subdomain; (c) communicate with us by email or in-app messaging; or (d) interact with our marketing or support channels.

By creating an account or using the Service, you acknowledge you have read this Privacy Notice. Where required by law (including the EU/UK GDPR and the Washington My Health My Data Act), we will request your separate, affirmative, opt-in consent before processing your "Sensitive Personal Information" or "Consumer Health Data" (defined below). If you do not agree, do not use the Service.

This Privacy Notice supplements, but does not replace, our Terms of Service, End-User License Agreement, Subscription Terms, and Children's Privacy Notice (COPPA).


2. INFORMATION WE COLLECT

2.1 Information You Provide Directly

  • Account & Identity Data: Name or display name, email address, hashed password (we never see your plaintext password), date of birth, time zone, and any optional profile fields (gender, height, weight, dietary preferences, allergies).
  • Consumer Health Data / Sensitive Personal Information, including:
    • Food, beverage, and supplement logs (timestamps, ingredients, photos of meals).
    • Symptom reports (type, severity, duration, body location).
    • Mood, stress, and emotional state logs.
    • Weight, body measurements, sleep duration and quality, menstrual-cycle data (if you choose to log it), exercise activity, and other self-reported health metrics.
    • Free-text journal entries and notes that you voluntarily write.
  • User-Generated Content: Photos, voice notes, comments, and any other content you submit.
  • Communications: Support requests, feedback surveys, and any correspondence you send us.
  • Payment Information: Subscription tier, transaction history, and renewal status. We do not collect or store payment-card numbers. All payments are processed by Apple (App Store), Google (Google Play), or Stripe; we receive only a tokenized reference and metadata.

2.2 Information Collected Automatically

  • Device & Technical Data: Device model, operating system and version, unique device identifiers (e.g., IDFV on iOS — we do not request the IDFA / advertising identifier and do not show ATT prompts), app version, crash logs, language, and IP address (truncated where feasible).
  • Usage Data: Screens viewed, features used, session duration, in-app actions (anonymized or pseudonymized event names — never the contents of your health logs).
  • Approximate Location: Derived from IP address (city / region level) for fraud prevention and analytics. We do not collect precise GPS location unless you explicitly enable a future location-tagged feature and grant the relevant OS permission.

2.3 Permissions Requested on Your Device

  • Camera & Photo Library: To let you attach photos of meals, symptoms, or progress shots. Photos are uploaded to our cloud storage only when you choose to log them.
  • Notifications: To send reminders you have configured (e.g., meal-logging nudges). You can revoke this at any time in OS settings.
  • HealthKit / Health Connect (optional, future): If you opt in, we will read or write only the specific health data types you authorize. We never share HealthKit data with third parties for advertising.

2.4 Information We Do Not Collect

We do not collect: precise GPS location, contacts, microphone audio (other than voice notes you actively record), SMS, browsing history outside our app, biometric identifiers (face/fingerprint templates), advertising identifiers, or social-graph data.


3. SOURCES OF INFORMATION

We obtain information directly from you, automatically from your device, and from the limited third-party service providers listed in Section 6. We do not purchase personal information from data brokers.


4. HOW WE USE YOUR INFORMATION (Purposes & Legal Bases)

PurposeExamplesLegal Basis (GDPR)
Provide the ServiceDisplay your logs, generate insights, sync data across devicesPerformance of contract
Process Sensitive / Consumer Health DataAnalyze your food–symptom patterns, generate AI summariesExplicit opt-in consent (GDPR Art. 9(2)(a); WA MHMD Act; CCPA Sensitive PI)
Subscriptions & PaymentsValidate entitlements via RevenueCat / Apple / Google / StripePerformance of contract; legal obligation
Service emailsAccount confirmation, security alerts, billing receiptsPerformance of contract; legal obligation
Optional marketing emailsProduct updates, tips (opt-in only)Consent (revocable any time)
Improve the ServiceBug fixing, performance monitoring, aggregate analyticsLegitimate interest; consent where required
AI featuresGenerate meal recommendations, surface pattern insights, summarize entriesExplicit opt-in consent; performance of contract
Fraud, security, and legalPrevent abuse, enforce Terms, comply with subpoenasLegitimate interest; legal obligation
Anonymized researchTrend research using fully de-identified, aggregated data onlyLegitimate interest (you may opt out)

We will never use your Consumer Health Data for advertising, profile selling, or any purpose beyond what is described in this Notice without obtaining a new, separate consent.


5. AUTOMATED DECISION-MAKING & ARTIFICIAL INTELLIGENCE

The Service may use artificial-intelligence and machine-learning models — including third-party large language models (e.g., OpenAI, Anthropic) — to:

  • Parse meal descriptions and estimate nutrient content.
  • Detect possible correlations between foods/triggers and symptoms.
  • Generate personalized written summaries and suggestions.

Important caveats:

  • AI output is informational only. It is not medical advice, not diagnostic, and may be inaccurate, incomplete, or "hallucinated."
  • We send only the minimum data necessary to the AI provider, under a zero-retention or short-retention API agreement (e.g., OpenAI API data is, per OpenAI's API policy, not used to train their models and is retained for at most 30 days for abuse monitoring).
  • AI processing does not make legally significant decisions about you. You may request human review of any AI-generated insight by emailing privacy@livenori.com.
  • Where required (GDPR Art. 22, EU AI Act, Colorado AI Act), you have the right to object to solely-automated decision-making.

6. SERVICE PROVIDERS / SUB-PROCESSORS

We use the following vendors, each contractually bound to confidentiality and data-protection obligations (Standard Contractual Clauses where required):

VendorPurposeData CategoriesLocation
Supabase, Inc.Database, authentication, file storageAll account & health dataUnited States
Apple, Inc.App distribution, in-app purchases, push notifications, optional Sign in with AppleAccount ID, purchase tokensUnited States
Google LLCApp distribution and in-app purchases (Android)Account ID, purchase tokensUnited States
RevenueCat, Inc.Subscription management & entitlementSubscription metadata, anonymous app user IDUnited States
Stripe, Inc.Web payment processing (where applicable)Tokenized payment metadataUnited States
OpenAI, L.L.C. and/or Anthropic, PBCAI model inference for insights & summariesThe minimum log content required to fulfill the request, with identifiers strippedUnited States
Expo (650 Industries, Inc.)Mobile app build, OTA updates, crash reportingDevice & crash diagnosticsUnited States
Sentry / PostHog (or equivalent)Error monitoring & product analyticsPseudonymous event data, no health-log contentsUnited States / EU
Resend / Postmark / SendGrid (transactional email)Account & billing emailsEmail address, message contentUnited States
Cloudflare, Inc.DNS, CDN, DDoS protectionIP address, request metadataGlobal edge

We update this list as our stack evolves; the version on this page is authoritative.


7. DISCLOSURES — WHAT WE DO NOT DO

  • We do not "sell" your personal information for money or other valuable consideration as defined by the CCPA/CPRA, the Washington My Health My Data Act, or any U.S. state comprehensive privacy law.
  • We do not "share" your personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
  • We do not use Consumer Health Data, Sensitive Personal Information, or any data from users known or believed to be under 18 for targeted advertising or for training third-party AI models.
  • We do not participate in any data-broker registry program because we are not a data broker.

8. DISCLOSURES TO THIRD PARTIES

We disclose personal information only:

  1. To the service providers listed in Section 6, under written contracts that limit use to providing the Service.
  2. In response to lawful requests by public authorities (subpoena, court order). We will challenge overbroad requests and, where legally permitted, notify you before disclosing.
  3. As part of a corporate transaction (merger, acquisition, asset sale). Successors must honor this Notice or give you 30 days' notice to delete your data first.
  4. With your direction or consent (e.g., if you choose to share your data with a healthcare provider via a future feature).

9. WASHINGTON MY HEALTH MY DATA ACT (RCW 19.373)

Because Seven Six Labs LLC is a Washington company and the Service collects "consumer health data" as defined by the Washington My Health My Data Act ("MHMD"), we provide the following consumer-health-data-specific disclosures:

  • Categories of Consumer Health Data Collected: Food and beverage intake, symptoms, mood, sleep, body measurements, menstrual / reproductive data (only if you choose to log it), exercise, medications and supplements (only if you choose to log them), and any related free-text notes.
  • Sources: Directly from you.
  • Purposes of Collection, Use, and Sharing: Solely to provide and improve the Service as described in Section 4. No selling.
  • Categories of Third Parties to Whom We Share It: Only the service providers listed in Section 6, each acting as our processor.
  • Right to Confirm, Access, Withdraw Consent, and Delete: You may exercise these rights at privacy@livenori.com or in-app under Settings → Privacy. We will honor verifiable requests within 45 days.
  • Right to Appeal: If we deny your request, you may appeal by replying to our denial email; we will respond within 45 days. If we deny the appeal, you may file a complaint with the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.
  • Consent Record: We log your opt-in consents (timestamp, IP, app version) and provide a copy on request.
  • No Geofencing: We do not use geofences around healthcare facilities.

10. CALIFORNIA PRIVACY RIGHTS (CCPA / CPRA)

If you are a California resident:

  • Categories collected in the past 12 months: Identifiers; customer records; commercial information; internet/network activity; geolocation (coarse); sensory information (photos you upload); inferences; Sensitive Personal Information (account credentials, precise location if any, health data, contents of communications). See Section 2 for specifics.
  • Sources, purposes, and recipients: Sections 3, 4, and 6.
  • Sale/Share: None. We have not sold or shared personal information in the past 12 months and have no plans to do so.
  • Your rights: Right to know, access, correct, delete, port, and limit use of Sensitive Personal Information. Right to non-discrimination for exercising these rights. Submit requests to privacy@livenori.com.
  • Authorized agent: You may designate an agent in writing; we will require verification.
  • Shine the Light (Cal. Civ. Code § 1798.83): We do not share personal information with third parties for their direct-marketing purposes.

11. EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND

If you are in the EEA, UK, or Switzerland:

  • Controller: Seven Six Labs LLC.
  • Legal bases: Section 4.
  • Your rights under GDPR: Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), object (Art. 21), withdraw consent (Art. 7(3)), not be subject to solely automated decisions (Art. 22), lodge a complaint with your supervisory authority (https://edpb.europa.eu/about-edpb/about-edpb/members_en).
  • International transfers: Your data is stored in the United States. We rely on the EU Standard Contractual Clauses (2021/914), the UK Addendum, and the Swiss FDPIC-approved SCCs, supplemented by encryption in transit and at rest, where the recipient has not self-certified to the EU-U.S. Data Privacy Framework.
  • EU Representative / UK Representative: If/when required by GDPR Art. 27, we will appoint a representative and update this Notice.

12. OTHER U.S. STATE PRIVACY LAWS

Residents of Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Iowa, New Jersey, New Hampshire, Tennessee, Indiana, Minnesota, Maryland, and other states with comprehensive privacy laws have substantially the same access / correction / deletion / portability / opt-out rights described above. Submit requests to privacy@livenori.com. We will not discriminate against you for exercising any right.


13. CHILDREN'S PRIVACY (COPPA)

The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 13. Eligible users must be at least 18 years old (or the age of majority in their jurisdiction). If you believe a child has provided us with personal information, please email privacy@livenori.com and we will promptly delete it. See our dedicated Children's Privacy Notice for our COPPA-compliance procedures and parental-rights workflow.

For users between the relevant minimum age and the age of majority in jurisdictions that allow such use with parental consent (we currently do not), additional restrictions apply; we do not currently support that use case and will reject such accounts on detection.


14. HIPAA STATUS — NOT A COVERED ENTITY

Seven Six Labs LLC is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act ("HIPAA"). The Service is a consumer wellness tool, not a health-care provider, health plan, or clearinghouse. The data you provide is not Protected Health Information ("PHI") as that term is defined under HIPAA. If you input data that originated from a HIPAA-covered relationship (e.g., copying a lab result into your journal), that data loses its HIPAA protections once stored on the Service and is governed solely by this Privacy Notice.


15. DATA RETENTION

DataRetention period
Active account dataUntil you delete your account
After account deletionSoft-deleted within 24 hours; permanently purged from primary databases within 30 days; purged from encrypted backups within 90 days
Billing records7 years (tax & accounting obligations)
Anonymized analyticsIndefinite (no longer linkable to you)
Server logs30 days, then aggregated or deleted
Crash diagnostics90 days
Support emails3 years from last contact

You can delete your account at any time from in-app Settings → Account → Delete Account or by emailing privacy@livenori.com.


16. SECURITY

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • TLS 1.2+ encryption in transit; AES-256 encryption at rest (provided by Supabase / cloud storage).
  • Row-level security policies enforcing per-user data isolation.
  • Hashed and salted passwords (bcrypt or Argon2id via Supabase Auth).
  • Principle-of-least-privilege access controls; production access logged and auditable.
  • Vendor security reviews; regular dependency and vulnerability scanning.

No system is 100% secure. If we become aware of a security incident affecting your personal information, we will notify you and applicable regulators within the timeframes required by law (e.g., GDPR Art. 33: 72 hours; state breach-notification statutes: typically without unreasonable delay and within statutory deadlines).


17. INTERNATIONAL DATA TRANSFERS

We are headquartered in the United States and our service providers operate globally. By using the Service from outside the United States, you understand that your data will be transferred to and processed in the United States and other countries that may have data-protection laws different from those of your country. We use lawful transfer mechanisms as described in Section 11.


18. DO NOT TRACK & GLOBAL PRIVACY CONTROL

Our Service does not currently respond to "Do Not Track" headers because there is no industry-wide standard. We do honor recognized Global Privacy Control (GPC) signals on https://livenori.com as an opt-out of "sale" or "sharing" (even though we do neither).


19. THIRD-PARTY LINKS AND INTEGRATIONS

The Service may contain links to or embed content from third-party websites (e.g., a recipe blog). Their privacy practices are governed by their own notices, not this one. We are not responsible for those practices.


20. CHANGES TO THIS PRIVACY NOTICE

We may update this Privacy Notice from time to time. If we make material changes — such as expanding the categories of data we collect, expanding the third parties with whom we share data, or changing the legal bases for processing Consumer Health Data — we will:

  1. Update the "Last Updated" and "Effective Date" at the top of this page;
  2. Provide a prominent in-app notice and/or email at least 30 days before the changes take effect; and
  3. For changes affecting Consumer Health Data, obtain your renewed opt-in consent before processing under the new terms.

Continued use of the Service after the effective date of an update constitutes acceptance of the updated Notice (except for changes that legally require fresh opt-in consent, which will not take effect for you until you provide that consent).


21. CONTACT US

Email: privacy@livenori.com General support: support@livenori.com Mail: Seven Six Labs LLC, Spokane, Washington, USA

For unresolved privacy concerns, you may also contact your local data-protection authority or the Washington State Attorney General.


Seven Six Labs LLC and the LiveNori name and logo are trademarks of Seven Six Labs LLC. All rights reserved.