Legal
Privacy Policy
Last updated 3 September 2026
On this page
JengaPulse is a health tracking app covering nutrition, fitness, mental wellness and sobriety. This policy explains what the app collects, why it needs it, who else handles it, and how to get it removed. It applies to the JengaPulse mobile apps and to jengapulse.com.
The short version. Your health entries are yours. We do not sell them, and we do not use them for advertising. The only data that leaves our systems goes to the named service providers below, each doing one job on our behalf. You can delete your account and everything in it from inside the app, and that deletion is permanent.
1. What we collect
| Category | What it is | Why we need it |
|---|---|---|
| Account | Phone number or email address, display name, and — if you use Sign in with Apple or Google — the identifier and email that service returns. | To create your account and sign you back in. JengaPulse has no passwords; we send a one-time code instead. |
| Profile | Age, height, current and target weight, activity level, and the goals and preferences you set during onboarding. | To calculate your calorie and macro targets and personalise what the app shows you. |
| What you log | Meals and their nutrition, water, weight entries, workouts and exercises, mood check-ins, journal entries, sobriety records, triggers and emergency contacts. | This is the product. Without it the app has nothing to show you. |
| Photos | Photos you take or choose for AI meal scanning, and a profile photo if you set one. | To identify food and estimate its nutrition. See section 3. |
| Health app data | With your permission: steps, workouts and exercise sessions, distance, floors climbed, heart rate and sleep, read from Apple Health or Health Connect. | So you don't have to log by hand what your phone or watch already counted. |
| Device and usage | Device model and operating system, app version, a device identifier for push notifications, time zone, and anonymised records of which screens and features are used. | To deliver reminders, keep daily totals on your local day, and find out which parts of the app are broken or unused. |
| Subscription | Which plan you are on, when it renews, and the receipt identifier from Apple or Google. | To unlock the features you paid for. We never see your card details — payment is handled entirely by Apple or Google. |
2. Health and wellness data
Nutrition, weight, mood, journal and sobriety entries are sensitive personal data, and we treat them that way.
- They are used to operate the app for you, and for nothing else.
- They are never sold, rented, or shared with advertisers or data brokers.
- They are not used to train anyone's AI models.
- Our analytics records that a feature was used — never what you wrote in it.
Data read from Apple Health or Health Connect is only read after you grant permission, and only the specific types listed above. You can revoke that permission at any time in your device settings, and the app keeps working without it. In line with Apple's rules, Health data is never used for advertising or shared with third parties for their own purposes.
3. AI features and what leaves your device
Several features send data to OpenAI for processing: meal photo scanning, nutrition label scanning, recipe and meal plan generation, workout generation, and the AI chat.
The app shows you a consent prompt before the first time any of these runs. If you decline, that feature stays off and the rest of the app works normally.
- Only what the feature needs is sent — the photo, or the message you typed, plus relevant context such as your calorie target.
- Requests are not tied to your name, phone number or email.
- Under OpenAI's API terms, data sent through the API is not used to train their models.
The AI is not a clinician. Nutrition estimates from a photo are approximations, and the chat is not therapy, diagnosis or medical advice. If you are in crisis, use the SOS resources in the app or contact your local emergency services.
4. Who else processes your data
Each of these does one job on our behalf, under contract, and may not use your data for their own purposes.
| Provider | What they handle |
|---|---|
| MongoDB Atlas | Stores your account and everything you log. |
| Render | Runs our servers. |
| OpenAI | Processes AI requests — see section 3. |
| Twilio | Sends the one-time code to your phone. |
| Resend | Sends the one-time code to your email. |
| RevenueCat | Manages subscription state. Receives a receipt identifier, not payment details. |
| Apple & Google | Take the payment and manage the subscription. They never share your card with us. |
| PostHog | Product analytics — which features are used, and where the app fails. |
| Bunny CDN | Stores and serves images you upload. |
| Expo | Delivers push notifications. |
These providers operate in various countries, so your data may be processed outside Kenya. We only use providers that commit to appropriate safeguards for international transfers.
We will also disclose data if the law requires it, or to protect someone's safety. If JengaPulse is ever acquired, your data may transfer with it — we will tell you before that happens and before this policy changes.
5. How long we keep it
- While your account is open — your entries are kept so you can see your own history, which is the point of a tracking app.
- When you delete your account — your data is removed from our live systems immediately. Encrypted backups roll off within 30 days.
- Photos sent for AI scanning — held only as long as the request takes, then discarded. Photos you attach to a meal are kept with that entry until you delete it.
- Records we must keep — a minimal transaction record may be retained where tax or accounting law requires it.
6. Your rights, and deleting your account
You can, at any time:
- See and correct everything you have logged, from inside the app.
- Export your data — available on the Premium plan, from Profile.
- Withdraw AI consent or revoke Health permissions, without losing the rest of the app.
- Delete your account and all of your data — Profile → Privacy & Security → Danger Zone → Delete Account. You will be asked to confirm. This is permanent and cannot be undone.
Depending on where you live you may also have rights to object to or restrict processing, or to complain to a data protection authority — in Kenya, the Office of the Data Protection Commissioner. Write to support@jengapulse.com and we will respond within 30 days.
7. Security
Traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting and database providers. Sign-in uses one-time codes and signed tokens rather than passwords, so there is no password of yours for us to lose. Access to production systems is limited to those who need it.
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authority as the law requires.
8. Children
JengaPulse is not intended for anyone under 13, and we do not knowingly collect their data. Some features — sobriety tracking in particular — are written for adults. If you believe a child has given us data, write to support@jengapulse.com and we will delete it.
9. Changes and contact
If this policy changes materially we will update the date above and notify you in the app before the change takes effect. Continuing to use JengaPulse after that means you accept the revised policy.
Questions, requests, or anything that looks wrong: support@jengapulse.com.