Privacy Policy
Last updated: July 13, 2026 · Effective: July 13, 2026
Jump to: Who we are What we collect Children's data How we use it Who processes it No tracking / no sale Retention & deletion Your rights Security Breach notification State privacy rights Changes Contact
1. Who we are
Krestrel ("we", "us", "the app") is a mobile application that lets a parent or legal guardian record and track their child's metabolic diet and related care. This policy explains what personal information the app processes and the choices you have. It applies to the Krestrel iOS and Android apps and this website.
The app is direct-to-consumer: you create an account for yourself as a caregiver, and you decide what information about your child to enter. You are the account owner and controller of your family's records within the app.
2. Information we collect
We only collect information you (or a caregiver you invite) actively provide, plus the minimum technical information required to operate a secure account and keep the app working (crash reports, described below). We do not collect location, contacts, advertising identifiers, or behavioral analytics.
Caregiver account information
- Your name.
- Your email address (used to sign in, verify your account with a 6-digit code, and send care-circle invitations).
- Authentication data (an encrypted password and session tokens managed by our auth provider).
Child health & care information you enter
This is sensitive health information about a minor. You choose what to enter; the app can store:
- Child's name, date of birth, and sex.
- Growth measurements (e.g. height, weight).
- Medical conditions and diagnoses.
- Medications and dosing.
- Lab and bloodwork results.
- Adverse events (for example, seizures) and related notes.
- Food and nutrition logs, meals, and nutrient targets.
- Appointments.
- Free-text notes.
Care-circle information
- Email addresses of caregivers you invite to view or help manage a child's records, and their role/permissions within your care circle.
Technical & permissions
- Standard account and security data required to keep you signed in and to protect the account (such as timestamps for records you create).
- Crash reports — if the app encounters an error, a technical report (the error and stack trace, app version, device model, and operating-system version) is sent to our error-reporting provider so we can find and fix the bug. Crash reports are configured to exclude your name, email, account identifier, and the health records you enter — they are not linked to your identity and are used for nothing except fixing defects.
3. Children's data & who may use the app
Krestrel is intended for use by adults (18+) who are the parent or legal guardian of the child being tracked. The app is not directed to children and children may not create accounts. At sign-up you must confirm that you are 18 or older and are the child's parent or legal guardian.
Because the child's information is provided by a parent/guardian for the family's own record-keeping, the parent/guardian controls that information and may correct, export, or delete it at any time as described below. If you believe a child's information was entered by someone without authority, contact us and we will help resolve it.
4. How we use information
We use information only to provide and secure the app's features:
- To create and secure your account and verify your email.
- To store, display, and organize the child-care records you enter.
- To calculate nutrition and growth summaries from the data you provide, alongside USDA reference values.
- To let caregivers you invite access the records you share with them.
- To send transactional messages you request (account verification, care-circle invitations).
- To respond to support requests and to protect against fraud, abuse, and security threats.
5. Who processes your data (sub-processors)
We do not sell or rent your information and we do not share it for advertising. We use a small number of service providers ("sub-processors") strictly to run the app on our behalf. They may process your data only to provide their service to us and are bound by their own security and privacy obligations.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Cloud hosting, database, and authentication | All account and child-care data listed above | United States |
| Sentry | Error and crash reporting (app diagnostics) | Anonymous technical crash reports only: error/stack trace, app version, device model, OS version. No health records, names, emails, or account identifiers. | United States |
| Resend | Delivery of care-circle invitation emails | Recipient email address and invitation content | United States |
| Apple / Google | App distribution and, for account email codes, email delivery infrastructure | Account email; standard app-store data governed by their own policies | United States |
We may also disclose information if required by law, to comply with a valid legal request, or to protect the rights, safety, and security of our users or the public. We will limit any such disclosure to what is legally required.
International users: your data is stored and processed in the United States. If you use the app from outside the U.S., you consent to processing in the U.S.
6. No tracking, no ads, no sale
- The app contains no advertising SDKs.
- The app performs no cross-app or cross-site tracking and requests no App Tracking Transparency permission (its privacy manifest declares tracking = false).
- We do not use third-party analytics on health data. The only diagnostics we collect are the anonymous crash reports described above — they contain technical error details, never your health entries or identity, and are used only to fix bugs.
- We do not sell your personal information or share it for cross-context behavioral advertising, and we never use your child's health data for advertising or marketing.
7. Data retention & deletion
We keep your information for as long as your account is active, so that your records remain available to you. You are in control of deletion:
- Delete individual records (a meal, lab, medication, etc.) at any time in the app.
- Delete your account from Settings → Danger zone. This permanently deletes your caregiver account and the child records you own — including profiles, growth, labs, medications, adverse events, food logs, appointments, and notes — from our systems. This action cannot be undone.
After deletion, residual copies may persist for a short period in encrypted backups before being overwritten on our provider's normal backup-rotation cycle, and we may retain the minimum records required to comply with legal obligations.
8. Your rights & choices
Depending on where you live, you may have the right to access, correct, export (portability), or delete your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. Most of these are available directly in the app:
- Access & correct: view and edit any record inside the app.
- Export: request a copy of your data by emailing us (see Contact).
- Delete: use in-app account deletion, or ask us to delete it for you.
To make a request you can't complete in the app, email us and we will verify your request (to protect the account) and respond within the time required by applicable law.
9. How we protect your data
- Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider.
- Access to records is restricted by row-level security so that each account can reach only its own family's data and only the records shared within its care circle.
- Passwords are stored only as salted hashes; sign-in uses email verification with a 6-digit code.
- Sessions use short-lived access tokens that are refreshed automatically.
- Session tokens on your device are held in the platform secure store (iOS Keychain / Android Keystore).
No system is perfectly secure, but we work to protect your information using industry-standard safeguards. Encryption protects data in transit and at rest; it is not end-to-end encrypted, so our systems process your data as needed to provide the app's features.
10. Breach notification
If a breach of security leads to the unauthorized acquisition of your unsecured personal health information, we will notify affected users and, where applicable, the U.S. Federal Trade Commission and relevant authorities, consistent with the FTC Health Breach Notification Rule and applicable state breach-notification laws. Notice will describe what happened, the information involved, and steps you can take.
11. U.S. state privacy rights
Health information is specially protected under a number of state laws, and we honor those rights for residents of applicable states:
- California (CCPA/CPRA, CMIA): rights to know, access, correct, delete, and to opt out of "sale"/"sharing" — we do not sell or share your data, so there is nothing to opt out of.
- Washington (My Health My Data Act) & similar laws: we obtain your consent before collecting consumer health data, do not sell it, and honor deletion requests.
- Residents of other states with comprehensive privacy laws may exercise equivalent access, correction, deletion, and portability rights.
To exercise any of these rights, use the in-app tools or contact us. You may designate an authorized agent to act on your behalf where the law permits.
12. Changes to this policy
We may update this policy as the app evolves. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you in the app. Your continued use after an update means you accept the revised policy.
13. Contact us
Questions, requests, or privacy concerns:
You can also reach us through the Support page.