Legal
Privacy and Consumer Health Data Policy
1. Who is responsible for your information
Fareplan is owned and operated by Nicholas Alexander Harris, also known as Alex Harris, doing business as Fareplan. Privacy questions and requests may be sent to [email protected].
2. Scope
This Policy covers the Fareplan website, account service, meal-generation features, support interactions, and interest list. It explains both ordinary personal information and consumer health data. Fareplan is a planning service, not a health care provider, insurer, or medical-record system.
3. Information we collect
Depending on the features you use, Fareplan collects:
- Account and demographic information: email address, name, date of birth, gender or a prefer-not-to-say selection, password hash, timezone, unit and week preferences, account status, and role.
- Planning content: meals, recipes, ingredients, shopping items, household tasks, dates, notes, and related organization.
- Consumer health data: workout sessions and notes, dietary needs, allergies, disliked ingredients, meal preferences, serving and budget preferences, and other health-related planning information you choose to provide.
- AI-planning records: generation preferences, scoped requests, safety results, proposals, reviews, approvals, and application activity. Fareplan does not send your email address, name, date of birth, or gender to OpenAI as part of a meal-planning request.
- Security and device information: IP address, browser or device user-agent, session-token hashes, timestamps, login and password-reset activity, audit events, and security decisions. Audit records describe actions and do not contain meal, workout, or other health payloads.
- Support and interest information: messages you send to support and, if you join the interest list, your name, email address, and permission to contact you about access or launch.
- Limited product analytics: daily counts of visits to public pages, broad referral source and campaign labels, interest-list actions, account activation, first plan approval, and first shopping-list use. Public-page analytics do not store an analytics cookie, IP address, user agent, full referring URL, or cross-page visitor identifier. Account milestones retain only the minimum account and event key needed to avoid counting the same milestone more than once.
Fareplan receives this information from you, from an administrator who creates or supports your invited account, from your browser or network connection, and from service providers responding to requests made on your behalf.
4. How we use information
Fareplan uses information to:
- provide, synchronize, back up, and restore the features you request;
- authenticate accounts, enforce account limits, and protect users and the service;
- generate meal-plan proposals when you request them;
- provide support, account access, exports, corrections, and deletion;
- confirm age eligibility and understand aggregate user demographics when making product decisions;
- measure whether public information and the invite funnel are useful, using limited first-party analytics;
- send transactional messages such as invitations, password resets, security notices, and requested launch contact;
- diagnose failures, prevent abuse, maintain auditability, and improve reliability; and
- comply with law and protect legal rights.
Fareplan does not sell personal or consumer health data. Fareplan does not use consumer health data for targeted advertising and does not disclose it for another company’s independent advertising or data-broker purposes.
5. Consumer health data consent
Fareplan processes the health-related information you choose to enter so it can provide food, training, and generation features. Before an account first uses the current service, Fareplan asks separately for consent to collect, use, and disclose that consumer health data as described here. You may withdraw consent by requesting deletion of the relevant information or your account. Withdrawal does not affect processing that occurred before withdrawal or information that must be retained for security or legal reasons.
6. When information is disclosed
Fareplan discloses information only as needed to operate the service:
- Amazon Web Services: production hosting, PostgreSQL storage, encrypted database backups, transactional email infrastructure, and related infrastructure in the US West (Oregon) region.
- Cloudflare: DNS, proxying, transport security, and protection of the public website. Cloudflare may process network information such as IP addresses.
- OpenAI: the minimum meal-planning inputs needed for a generation request and safety review. Fareplan sets provider response storage to disabled. OpenAI may retain limited safety or abuse-monitoring records under its applicable policies.
- Authorized administrators: limited account and audit information when needed for account administration, security, support, or a user-requested export or import. Health content is not used for unrelated purposes.
- Legal and safety disclosures: when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, protect rights or safety, or establish and defend legal claims.
Fareplan does not authorize these providers to sell your information or use it for their independent advertising. Their own privacy terms also govern their processing.
Fareplan does not use a third-party advertising or behavioral analytics service. Public-page measurement honors browser Do Not Track and Global Privacy Control signals by not sending the page-view event.
7. Storage and retention
- Active account content is retained while the account is active or until you delete it.
- An account-deletion request begins a 30-day grace period. After that period, account content is removed and identifying account fields are anonymized through Fareplan’s deletion process.
- Verified production database backups are encrypted and retained in hourly copies for up to 48 hours and nightly copies for up to 30 days. Deleted information can remain in those backups until they expire.
- Authentication, audit, fraud-prevention, consent, and legal records may be retained after account deletion when reasonably necessary to protect users, demonstrate compliance, resolve disputes, or enforce agreements.
- Interest-list information is retained while Fareplan is managing invitations and launch contact, or until you ask us to remove it.
8. Your choices and rights
Subject to applicable law, you may ask Fareplan to confirm whether it holds your information, provide access or an export, correct inaccurate information, delete information, withdraw consumer health data consent, or review a denied request. Account settings provide profile correction, export, and deletion functions where available. You may also contact [email protected]. We may need to verify your identity before fulfilling a request.
Fareplan will not discriminate against you for exercising a privacy right. If a request is denied, you may appeal by replying to the decision or emailing support with “Privacy appeal” in the subject line.
9. Security
Fareplan uses HTTPS, hashed passwords and session tokens, tenant isolation, least-privilege database access, security logging, restricted administrative access, encrypted infrastructure and backups, and tested restore procedures. No system is perfectly secure. Contact support immediately if you suspect unauthorized access.
10. International access
Fareplan is based in the United States and its production systems are located in Oregon. If you use Fareplan from another country, your information is transferred to and processed in the United States. Local mandatory privacy rights may still apply.
11. Age eligibility and children
Fareplan accounts are available to people age 13 and older. A person under the age of legal majority where they live may use Fareplan only with permission from a parent or legal guardian. Fareplan is not directed to children under 13 and does not knowingly collect personal information from them. If Fareplan learns that an account belongs to someone under 13, it will delete the account and associated personal information. Contact support if you believe a child under 13 has provided information.
12. Breach notification
Fareplan investigates suspected unauthorized access and will notify affected users, regulators, or others when required by applicable law, including applicable consumer health data breach-notification requirements.
13. Changes to this Policy
Fareplan may update this Policy as the service and its legal obligations change. Each update receives a version and effective date. Signed-in account holders will receive a one-time in-app notice describing meaningful changes, with links to the current Terms and Policy. Future revisions, including changes to the consumer health data practices described here, use this notice process rather than another checkbox, consent screen, or sign-in gate.
14. Contact
Send privacy requests, consumer health data requests, complaints, or appeals to [email protected].