Privacy Policy
Last updated: 2026-08-15
1. Who is responsible for your data
My Health Engineer ("MHE", "we") is the data controller. My Health Engineer is the registered business name (Companies Registration Office no. 768945) of Keith Young, a sole trader based in Ireland, trading as My Health Engineer. Contact for any privacy matter: support@myhealthengineer.com.
2. The data we collect
Depending on how you use MHE, we hold:
- Account details — name, email, password (hashed) or Google sign-in, and security data (sessions, two-factor settings).
- Health information you give us when you set up (special category, Article 9) — date of birth, biological sex, height, body-fat where you provide it, medical conditions and medication flags you choose to share, pregnancy or breastfeeding status where you tell us, your stated health concerns, your sleep and fasting windows, and — if you choose the cycle-phase refeed schedule — the cycle details you enter for it (last period start date, cycle length, whether your cycle is regular). This is the core of how MHE personalises and keeps your plan safe.
- Health information you log as you go (special category, Article 9) — your trackers, check-ins and reviews over time: weight and tape measurements, what you eat against your targets, the food diary where you use it (specific foods and portions, including foods you name yourself, with a photo of the meal if you add one), water and electrolytes, blood ketones, sleep hours and quality (including nightly wake counts, how long you were awake and what woke you), stress, energy, hunger and cravings, symptoms you tick, workout sessions down to individual sets, habit streaks, your weekly review answers, and the sleep and stress self-checks you fill in during setup and every couple of weeks after. If one of those answers prompts us to suggest speaking to your doctor, we record that we showed you the prompt and whether you told us it is already being looked after — never what the diagnosis or treatment is. On the programs built around a clinical marker, it also includes readings you type in yourself on the Markers tab: blood pressure, HbA1c, fasting glucose, total cholesterol, LDL, HDL and triglycerides. We never receive results from a lab or clinic — only what you type.
- Plans and progress — your computed nutrition and training plans, weekly planner history, and any plan setup you started but didn't finish (kept so you can resume it).
- What we work out from your data (special category, Article 9) — the app's own estimates learned from your logs: your derived daily energy use and its confidence, the history of every calorie-target change (shown on your dashboard with a revert option), an internal flag when results stay off-model despite good logging, and your weekly coaching reports. We generate these rather than collect them, and treat them with the same Article 9 care.
- Meal-planning data — saved recipes, custom foods, weekly meal plans, kitchen inventory, and any photos you choose to upload — stored on a private bucket scoped to your account only. When you save a food our ingredient database doesn't carry, its name and figures also go onto a shared improvement list that holds no link to your account.
- Membership and access — your program entitlements and (where you link it) your Skool community email.
- Your answer about sharing your wins — whether you have said yes or no to MHE re-sharing something you post with other members, the exact wording version you were shown, and where you answered. Every answer is kept rather than overwritten. If we did share something, we also keep a register entry describing what, where, and under which permission — that is how a change of mind becomes an actual takedown.
- Technical and app-state data — IP address, device/browser, usage analytics (see §7), and operational app state such as reminder preferences and the record of reminders you've snoozed or skipped.
This section describes categories with real examples rather than a field-by-field inventory. The exact record we hold about you at any moment is the export you can download from your account page (§6) — that is the complete, current version, and it is yours.
3. Why we use it, and our lawful basis
- To deliver your programs and plans — lawful basis: performance of our contract with you.
- To process your health information (every category marked Article 9 in §2 — what you give us at setup, what you log as you go, and what we work out from it) so plans are personalised and safety gates work — lawful basis: your explicit consent (Article 9(2)(a)), captured at onboarding. You can withdraw it at any time by erasing those categories from your account page or deleting your account (see §6).
- To share a win you post with other members, if you say yes — lawful basis: your explicit consent (Article 9(2)(a)), asked separately from everything else and never required. The question lives in your account settings, unticked by default — nothing is shared unless you go there and say yes, and you can change the answer any time. We keep a record of what you were shown and what you answered. Nothing of yours goes to the public or into an advert on the strength of this.
- To keep accounts secure (sessions, two-factor, audit logging) — lawful basis: legitimate interest in protecting your data.
- To improve the product via analytics — lawful basis: our legitimate interest in understanding how features are used so we can improve them (Article 6(1)(f)). These events are behavioural only and carry no health information, nothing is stored on your device, and you can switch analytics off at any time in your account settings (see §7).
- To decide what the recipe library and ingredient database add next — lawful basis: our legitimate interest in improving the product (Article 6(1)(f)), fed by the anonymous improvement list described in §2 and a periodic internal read-only review of member-created recipes and foods. What comes out is new curated content for everyone — never anything that identifies you.
- To publish aggregate outcome statistics, in future — if we ever publish figures like "members who finished lost an average of X", they will be computed only across groups of at least 30 with no subgroup below that, so no individual is identifiable, and clinical blood-marker aggregates are excluded entirely for now. Nothing has been published yet; our standard for this is under specialist review.
4. Who processes your data, and where
We use a small set of vetted processors. Your database sits in the EU; some service providers are outside the EU and are covered by Standard Contractual Clauses or an adequacy framework.
- Supabase — primary database. EU (Frankfurt).
- Vercel — application hosting. US/global edge; SCCs.
- Google — optional sign-in (email, name, avatar). US; adequacy framework / SCCs.
- Resend — transactional email. EU (Ireland).
- PostHog — product analytics. EU.
- Skool — membership community that grants program access (we receive your email and group membership); also processes your subscription payment on our behalf. US; SCCs.
- Sentry — error and performance monitoring, so we find out when something breaks before you have to tell us. It receives technical diagnostic data (the error, timing, browser and device type), never your health entries, logs or plan content. We scrub the four clinical program names and knowledge-topic addresses before anything is sent; because a page address could still imply something about how you use the app, we treat this data as capable of revealing health information and it is covered by the same consent as the rest of your health data.
- Google Fonts— one icon stylesheet loads from Google's servers, which means Google receives your IP address and browser type on each page load. It sets no cookie and gets no account or health information. US; SCCs.
- Upstash — holds short-lived rate-limit counters (your account ID and request timestamps only) so bulk-download abuse can be throttled.
We never sell your data, and we never share special-category health information for advertising.
5. How long we keep it
We treat your account as a longitudinal health record across life stages, so we keep it for as long as your consent stands. We ask you to re-affirm or revoke consent at least every 24 months, starting 24 months after your consent was given. When you delete your account, your data is removed — the deletion cascades across all your records, including uploaded files, and we also instruct our analytics processor to erase the events tied to your account ID.
A small amount of data deliberately survives deletion, and we would rather name it than have you find it: the security audit trail keeps its entries with your account link removed but your email retained (including the record of the deletion itself), so we can show what happened and reconcile past access against our membership roster. If you had agreed to us sharing a win and we had shared one, the register entry saying what we shared and where also survives, with your email, because something of yours may still be live somewhere and deleting the record would leave us unable to take it down — deleting your account flags everything still published for removal. And food names you contributed to the anonymous ingredient improvement list stay on it, because nothing on that list links to you.
6. Your rights
Under GDPR you can, at any time:
- Access and export your data — download a complete JSON copy from your account page (Articles 15 and 20).
- Correct your data — edit your profile in-app (Article 16).
- Delete your account and data permanently from your account page (Article 17). Deletion reaches everything except the small set of surviving records named in §5.
- Withdraw consent for health-data processing at any time, which stops that processing without you having to close your account (Article 7). Your account page lets you erase each health-data category on its own, and erasing a category also removes anything we computed from it.
- Object to analytics — switch it off in your account settings and we stop immediately — and object to or restrict our other processing (Articles 18 and 21).
- Complain to the Irish Data Protection Commission (dataprotection.ie), your supervisory authority.
7. Cookies and analytics
We use essential cookies to keep you signed in. For product analytics we use PostHog, run in cookieless mode, to understand how features are used. Nothing is stored on your device for analytics — no analytics cookie, no local storage, no persistent tracking identifier — because you are already signed in when you use MHE, so we have no need to tag your browser to recognise you.
We rely on legitimate interest for analytics (Article 6(1)(f)) rather than consent. The processing is limited to behavioural events on our own service, stays inside the EU, is never shared with third parties, and is never used for advertising, profiling, or automated decisions about you. We do not send your health values (conditions, medications, metrics) to analytics, and we deliberately do not record which health conditions or knowledge topics you read about, so an analytics event can never reveal your health status.
You can switch analytics off at any time from your account settings and we stop immediately, on every device you sign in from. Our reasoning for relying on legitimate interest rather than consent is documented in a Legitimate Interests Assessment, available on request.
8. Security
Your data is held on EU infrastructure, encrypted in transit, with passwords hashed and optional two-factor authentication. We exclude security-sensitive material (password hashes, two-factor secrets and backup codes, sign-in and OAuth tokens, short-lived verification tokens) from data exports so a downloaded copy can't be used to compromise your account. Beyond that named security material and the anonymous ingredient improvement list (§2, which holds no link to you), the export contains everything we hold about you.
9. Children
MHE is for adults aged 16 and over, matching the Irish digital age of consent. Date of birth is required during onboarding and under-16 dates are refused, both on the form and by the server behind it. We do not knowingly collect data from anyone under 16; if we learn an account belongs to someone under 16, we close it and delete the data.
10. Changes and contact
We'll update this page when our processing changes, with the "Last updated" date reflecting the most recent revision, and flag material changes in-app. Questions or requests: support@myhealthengineer.com. See also our Terms of Service.