Immuno

Privacy Policy

Effective date: [EFFECTIVE DATE] Last updated: [EFFECTIVE DATE]

This Privacy Policy explains how [COMPANY LEGAL NAME] ("Immuno," "we," "us," or "our") collects, uses, shares, and protects information when you and your child use Immuno — including the website at playimmuno.com, the Immuno Pet game, the Parent Dashboard, and the Immuno Sync companion app for iPhone (together, the "Service").

Immuno is built for families. A parent or legal guardian creates the account, and children play under that account. Children do not create their own accounts and we do not knowingly collect personal information from a child without a parent's consent. Please read the Children's Privacy Notice together with this policy — it is our direct notice to parents under the U.S. Children's Online Privacy Protection Act ("COPPA").

Immuno tracks health-related information about children, including symptoms and nutrition. We treat that information as sensitive and describe our handling of it in detail below.


1. Quick summary

Who holds the accountA parent or legal guardian, 18 or older.
What we collect about your childOnly what is needed to run the game and the health features: a display name, birth date, an autoimmune condition (if you choose to enter one), food and habit logs, symptoms, and optional device metrics you connect.
Do we sell your data?No. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Do we show ads to children?No. There is no advertising in Immuno and no third-party advertising or analytics SDKs in the children's experience.
Do we use data to train AI models?No. Where we use AI vendors to process a voice log, they are contractually barred from training on your content.
Is this a medical service?No. Immuno is a general wellness and family habit product. See our Medical Disclaimer.
Can you delete everything?Yes. Email [PRIVACY EMAIL] and we will delete the account and its data.

2. Who we are and how to reach us

[COMPANY LEGAL NAME] [COMPANY MAILING ADDRESS] Email: [PRIVACY EMAIL]

For residents of the European Economic Area or the United Kingdom, [COMPANY LEGAL NAME] is the "controller" of the personal data described in this policy.


3. The information we collect

3.1 Information the parent gives us

3.2 Information about your child

You choose how much of this to provide. The game works with very little; the health features get more useful with more.

3.3 Information collected automatically

3.4 Voice food logging (paid plans)

If you use voice logging, the audio you record is sent to our transcription vendor to convert speech to text, and the resulting text is sent to our language-model vendor to turn it into a structured food entry. We instruct these vendors to process the data only to return that result. Audio is not retained by us after the transcript is produced, and neither vendor may use your content to train their models. If you would rather not use these vendors, do not use voice logging — every food entry can be made by hand.

3.5 Information we do not collect

We do not collect government identifiers, precise geolocation, contacts, photos beyond an avatar you deliberately upload, biometric identifiers, or any information from a child's device outside what is described above.


4. How we use information

We use the information described above to:

  1. Provide the Service — create and secure accounts, save game progress, show the Parent Dashboard, and sync data across devices.
  2. Run the health features — display nutrition and micronutrient summaries, trends, streaks, and the pattern signals we surface in the dashboard.
  3. Handle payments — start trials, process subscriptions, and manage renewals and cancellations through Stripe.
  4. Support you — answer your questions and troubleshoot problems.
  5. Keep the Service safe — detect fraud, abuse, and security incidents.
  6. Improve the product — understand which features are used, in aggregate. Where we report on usage internally, we use aggregate counts, not individual children's records.
  7. Comply with law — meet legal obligations and respond to lawful requests.

We do not use children's personal information for advertising, marketing, profiling for commercial purposes, or to train machine-learning models.

4.1 Legal bases (EEA and UK users)

Where the GDPR applies, we rely on: contract (to provide the Service you signed up for), legitimate interests (security, abuse prevention, and basic product improvement), legal obligation (tax, accounting, and lawful requests), and consent — which is the basis for processing health data, for connecting Apple Health, and for a child's data. Health data is "special category" data under Article 9 and we process it only with your explicit consent, which you may withdraw at any time.


5. Apple Health data

If you install Immuno Sync and grant access to Apple Health:


6. When we share information

We do not sell personal information. We share it only in these situations:

6.1 Service providers ("subprocessors")

We use a small set of vendors to operate the Service. Each is bound by contract to process data only on our instructions. The current list, with what each one receives, is maintained in SUBPROCESSORS.md and summarized here:

VendorPurposeData it can access
SupabaseDatabase, authentication, file storage, server functionsAll account, health, and game data
VercelWebsite hosting and deliveryTechnical request logs
StripePayment processing and subscriptionsParent email, billing details, payment card (Stripe only)
OpenAISpeech-to-text for voice logging (paid plans)The audio clip you record
AnthropicTurning a voice transcript into a food entry (paid plans)The text transcript
AppleDelivery of the Immuno Sync app and HealthKit access on your deviceHandled on-device; Apple does not receive your Immuno data from us

If we add or replace a vendor that handles children's personal information, we will update that list and, where the law requires it, obtain your consent again.

6.2 Within the family

The parent or guardian who holds the account can see all of the child's logs, progress, and health information. That is the point of the Parent Dashboard. Children see their own game progress.

6.3 Legal and safety

We may disclose information if we believe in good faith that it is required by law, or necessary to protect the rights, safety, or property of a child, of you, of the public, or of us.

6.4 Business transfers

If the Service is acquired or merged, information may transfer to the successor. If the new owner would use children's information in a materially different way, we will notify you and obtain consent before that happens.

6.5 With your direction

If you ask us to share a report — for example, exporting a symptom history to bring to your child's doctor — we will do what you direct.


7. How long we keep information

If you stop using Immuno without deleting your account, we may delete an inactive account and its data after [24] months of inactivity, after emailing you first.


8. Security

We protect information with encryption in transit (TLS) and at rest, row-level access rules in the database so one family cannot read another family's data, hashed passwords, access controls on our own administrative tools, and least-privilege service credentials.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as required by law.


9. Your rights and choices

Whatever jurisdiction you are in, you can:

To exercise any of these, email [PRIVACY EMAIL] from the address on your account. We respond within 30 days (45 days for U.S. state privacy requests, extendable once where the law allows). We will not discriminate against you for exercising a privacy right.

9.1 U.S. state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Texas, or another state with a comprehensive privacy law, you have the rights listed above and the right to opt out of "sale," "sharing," and targeted advertising. We do not sell or share personal information for those purposes, and we do not engage in targeted advertising. California residents may also designate an authorized agent to make a request on their behalf.

Under California law, we disclose that in the previous 12 months we collected the categories of information listed in Section 3 for the purposes listed in Section 4, disclosed them for business purposes only to the vendors listed in Section 6.1, and sold or shared none of them.

9.2 Consumer health data (Washington, Nevada, Connecticut)

Nutrition logs, symptom entries, vitals, and health conditions in Immuno are consumer health data under Washington's My Health My Data Act and comparable laws.

Washington residents: see Your Washington Privacy Rights.

9.3 A note on HIPAA

Immuno is a direct-to-consumer wellness product. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a business associate of one, so HIPAA does not apply to the information you enter here. That does not lower our standard of care — this policy and the state health-data laws above govern how we handle it — but you should know the difference. Do not assume information you enter into Immuno carries HIPAA protections.


10. Children's privacy

Immuno is designed for children to use with a parent. Our full COPPA disclosures, including how a parent gives and revokes consent and how to review or delete a child's information, are in the Children's Privacy Notice.

In short: a parent creates the account and provides consent; we collect only what the Service needs; there is no advertising, no behavioral tracking, and no public sharing of anything a child creates; and a parent can review, export, or delete a child's information at any time by emailing [PRIVACY EMAIL].


11. Cookies and similar technologies

Immuno uses browser storage and cookies that are strictly necessary — keeping you signed in, remembering your session, holding your preferences and unsaved logs, and protecting against abuse. We do not use advertising cookies, third-party trackers, or cross-site tracking pixels. You can clear this storage in your browser settings, but you will be signed out and local preferences will reset.


12. International transfers

We are based in [COUNTRY] and our infrastructure providers may process data in the United States and other countries. If you are in the EEA or the UK, transfers out of your region rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) together with additional safeguards, or on your explicit consent. You can request a copy of the relevant safeguards at [PRIVACY EMAIL].


13. Changes to this policy

If we change this policy, we will update the date at the top and post the new version. For material changes — especially any change to how we handle children's information — we will email the parent on the account and, where the law requires, obtain fresh consent before the change takes effect. We will not apply a materially different use to information already collected without your consent.


14. Contact

Questions, requests, or complaints:

[COMPANY LEGAL NAME] [COMPANY MAILING ADDRESS] [PRIVACY EMAIL]

If you are in the EEA or the UK and we have not resolved your concern, you may complain to your local supervisory authority.