Last Updated: September 28, 2026
Version 3.0
This Privacy Policy explains how Bazu Technologies, LLC (“Bazu,” “we,” “us”) collects, uses, shares, and protects your personal information when you use the Bazu mobile application, website, and related services (collectively, the “Service”).
This is version 3.0 of the Privacy Policy. It applies to app version 2.3.0 and later and replaces every earlier version. Where an earlier app version did something that app version 2.3.0 and later does not, this policy says so by version number.
Bazu is a wellness and food-rating app for adults (18+), operated from the United States. It rates the food you log, suggests a fix to the meal, and asks how each meal left you. The Service is not designed to diagnose, treat, or manage any medical condition. Please also read our Terms of Service and Medical Disclaimer.
If you are a Washington or Nevada resident, additional disclosures and rights apply to your consumer health data. Please read our separate Consumer Health Data Privacy Policy.
Account Information
OAuth Sign-In Details
If you sign in with Google or Apple, we receive your email address and an authentication token. We do NOT access your Gmail, Google Drive, iCloud, or other Google/Apple services. If you sign in with OAuth, you cannot change your email inside Bazu. Update it with Google or Apple directly.
Wellness Profile
Meal and Food Data
What you log about food, your energy check-in answers, and any diabetes answer an earlier app version stored can allow someone to infer something about your health. We treat all of it as sensitive: it is never used for advertising, never sold, and never shared except as this policy describes.
Optional Health Data (earlier app versions only)
Most users never provided any of the above. It was always optional and never required to use the Service.
Your Acceptance Record
Each time you accept a version of our Terms of Service, this Privacy Policy or our Consumer Health Data Privacy Policy, we record which version you accepted and when. This record is deleted with your account (see Section 6).
Website Forms
The contact form on withbazu.com takes your first name, last name, email address, phone number and message. The newsletter form in the website footer takes your email address. Both are delivered by Formspree (see Section 4.1). Neither form is part of your Bazu account.
Based on the data you provide, the Service generates algorithmic outputs. These are derived from your inputs and stored alongside your account:
Every one of these is worked out from the food you logged. They describe the food, not your body, and none of them is a diagnosis. The same food gets the same reads for every account. Your energy check-in answers are stored beside these outputs but are never used to compute any of them.
App versions before 2.3.0 also generated outputs from CGM readings imported through Apple Health: per-meal curves matched to your own readings, and time-in-range statistics. Those app versions could read blood glucose from Apple Health. The integration has been retired, and no app version generates these outputs any more.
These outputs are estimates only. See our Medical Disclaimer and Section 3 (Estimates, Not Measurements) of our Terms of Service.
Usage Data
Device Information
Update Delivery
The app checks for updates to its code through Expo (see Section 4.1). That check sends your device type, operating system version, app version and current update version. It sends no account data and no health data.
Local Device Storage
The following are stored encrypted on your device:
Local data is encrypted by your device's operating system and is deleted when you log out or uninstall the app.
We Do NOT Collect
About Meal Photos
This integration has been retired. App version 2.3.0 and later does not offer CGM integration, does not request Apple Health permission, and does not read any data from Apple Health.
App versions before 2.3.0 could read blood glucose from Apple Health, if you chose to enable the integration and granted permission. It was always optional, and most accounts never used it. This section describes what those app versions did, and what happens now to readings they imported.
What Those App Versions Accessed
What We Have Never Accessed
What Happens Now
How CGM Data Was Used
To display glucose trends inside the app and to overlay your own readings on the Estimated Glucose Curve for comparison. We did not use CGM data for advertising. We did not sell CGM data. We have never sent CGM data to any AI model or AI vendor. We have never used it to train a model, and we never will.
One Offline Copy
In September 2026 we exported the stored readings of two accounts. That was part of retiring this integration. The copy is encrypted and held offline. No third party has it, and it was never sent to any AI model or AI vendor. A scheduled job destroys it on December 14, 2026.
In app versions before 2.3.0 we also used blood glucose readings imported from Apple Health to show glucose trends in the app and to overlay your own readings on the Estimated Glucose Curve. That integration has been retired, and we no longer use CGM data for this or any other purpose (see Section 1.4).
We use third-party AI providers for two jobs. Today those providers are OpenAI and Anthropic.
Reading your meals. OpenAI receives the meal text you typed, the meal photo you took, and the food names you search. That is what identifies the food and estimates its nutrition. Nothing else is sent with it.
Writing your score summaries. Anthropic receives a summary of your recent logging, so it can write the sentences on your Bazu Score screens. That summary carries your meal names, your score numbers and your nutrient averages. Nothing about glucose goes once the readings older app versions imported are deleted, fourteen days after app version 2.3.0 was released.
Neither provider receives your name, email address, account identifier, date of birth, weight, diabetes answer, energy check-in answers or an insulin dose. A request carries the food and the numbers, and nothing that says who you are.
We do not use your data to train AI models, ours or anyone else's. OpenAI and Anthropic confirm in their API terms that data submitted via API is not used to train their models by default. We rely on those commitments and never opt in to training-data programs. Each provider may hold API inputs for up to 30 days for abuse monitoring under its own API policy, then deletes them. Where a provider offers a zero-retention option for API traffic, we use it.
We may use aggregated, de-identified data, meaning data that cannot reasonably be linked back to you, to evaluate and improve our own scoring methods and product features.
We do not sell, rent, or trade your health-related data, including meals, meal photos, nutrition data, energy check-in answers, weight, any diabetes answer, or any glucose or insulin value an earlier app version stored, to advertisers, data brokers, insurers, or anyone else, ever.
We never use data about your health for marketing. Nothing you log about food, nothing you answer about how a meal left you, and no diabetes answer ever reaches an advertising platform, an ad audience, or a marketing segment.
We have not sold or shared any personal information for cross-context behavioral advertising in the preceding twelve (12) months, with one limited exception: if you grant permission through the iOS App Tracking Transparency prompt, your device's advertising identifier (IDFA) and standard non-health app events may be shared with Meta Platforms, Inc. and TikTok (Bytedance Ltd.) for app-install advertising attribution. Under the California Consumer Privacy Act (CCPA/CPRA), this activity may be considered a “sale” or “share” of personal information. It involves only the advertising identifier and non-health events; it never involves your health data. You can opt out at any time (see Section 4.2 and Section 8).
We share data with trusted third-party service providers who help us operate the Service. Each is contractually obligated to protect your data and use it only for the purposes we specify. This list is complete: no provider outside it receives your data.
Supabase: cloud database, storage, and authentication
Railway: backend application hosting
Expo: app update delivery
OpenAI and Anthropic: AI nutrition, meal parsing, and score summaries
Edamam and Open Food Facts: food databases
Apple App Store and RevenueCat: subscription payment and processing
OneSignal: push notification delivery
Vercel: website hosting and website analytics
Sentry: crash and error monitoring
Resend: transactional email
Formspree: website form delivery
Google: OAuth (if you sign in with Google)
Apple: OAuth and Apple Health
Bazu uses two third-party advertising services, integrated solely for app-install advertising attribution: the Meta (Facebook) SDK and the TikTok Business SDK. Neither is initialized for users in the European Economic Area, the United Kingdom, or Switzerland.
What Meta and TikTok Receive
What Meta and TikTok Do NOT Receive
Your Control
Provider Privacy Policies
Meta and TikTok receive no health data from Bazu. Only the advertising identifier and standard non-health events, and only with your permission.
We may disclose your information if required by law, court order, or lawful government request, or if we reasonably believe disclosure is necessary to:
If Bazu is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
We use industry-standard security measures to protect your information:
No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
We keep your information only as long as needed to provide the Service and meet legal obligations:
When You Delete Your Account
Deleting your account starts a 30-day grace period. During those 30 days your data is kept but inactive, and logging back in restores the account. When the 30 days end, a scheduled job permanently erases your personal data in one pass: your account and profile, every meal, every photo file, every read and score, every energy check-in answer, your weight history, your XP and streaks, the dated diabetes record, and any glucose or insulin value or CGM reading an earlier app version stored. Your login is deleted with it. Backups are purged within 90 days.
Like every service, we keep a small set of records after that, to comply with legal obligations, resolve disputes and enforce our agreements: the record that you accepted our terms and policies, the record of your deletion request, and the payment records Apple and RevenueCat hold. None of them contains your name, your email, your meals or anything about your health. Statistics that identify nobody are kept as well.
You can view and edit most of your profile information directly in the app (Settings and Update Your Profile). For other access or correction requests, email hello@withbazu.com.
You can delete your account using the “Delete Account” option in Settings, or by emailing hello@withbazu.com. Deletion starts a 30-day grace period in which logging back in restores your account. After that, everything is permanently erased as described in Section 6.
To request a copy of your data in a structured, machine-readable format, email hello@withbazu.com with your account email. We will respond within 30 days. The copy includes your meals and the reads and scores stored with them. An in-app export feature is in development.
The iOS App Tracking Transparency prompt is your opt-out for advertising-identifier sharing with Meta and TikTok. Choose “Ask App Not to Track,” or change your choice anytime in iOS Settings → Privacy & Security → Tracking. Section 8 lists your California rights and how to exercise them.
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
Your Rights
“Sale” and “Sharing” Disclosure
We do not exchange your personal information for money. The only activity that may be considered a “sale” or “share” under CCPA/CPRA is the sharing of your IDFA and standard non-health app events with Meta and TikTok for app-install advertising attribution, and only when you grant permission via the iOS ATT prompt. See Section 4.2.
How to Exercise Your Rights
This section is our Your Privacy Choices notice. Everything you need is here.
To opt out of the only sharing we do. On your iPhone, open Settings, then Privacy & Security, then Tracking. Turn Bazu off. No advertising identifier is collected or shared after that. You can also choose “Ask App Not to Track” on the prompt itself. Declining does not affect any feature of Bazu.
To know, correct, delete, or appeal. Email hello@withbazu.com. Include your full name, the email address on your account, and what you want. We will respond within 45 days. We may extend that once when reasonably necessary, and we will tell you why.
To delete everything yourself. Open the Bazu app, then Settings, then Delete Account.
You may use an authorized agent. Send us written proof that you authorized them.
If you are a Washington or Nevada resident, the health-related information you provide to Bazu is treated as “consumer health data” under Washington's My Health My Data Act (MHMDA) and Nevada's SB 370.
Please read our separate Consumer Health Data Privacy Policy for the full disclosures and rights that apply to that data, including your rights to access, delete, withdraw consent, and appeal.
We provide the Consumer Health Data Privacy Policy as a separate, distinctly linked document as required by Washington law.
Bazu is not a HIPAA-covered entity and is not a business associate of one. The health-related information you enter into Bazu is:
Your information is instead protected by general consumer-privacy laws (such as CCPA/CPRA and, where applicable, Washington MHMDA and Nevada SB 370, see Section 9) and by this Privacy Policy. We strongly recommend that you do not rely solely on Bazu for any health-related decision and that you consult a qualified healthcare provider when needed.
On iOS, Bazu uses Apple's App Tracking Transparency (ATT) framework. The first time it is relevant, iOS will show you a prompt asking whether you allow Bazu to track you across apps and websites owned by other companies.
What the Prompt Controls
Important
Bazu is for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and if we learn that we have, we will close that account and delete the information promptly.
If you believe a person under 18 has provided us personal information, contact us at hello@withbazu.com.
Bazu is operated from the United States and is available worldwide. If you use the Service from outside the U.S., your data is transferred to and processed in the United States, as described in Section 14. We protect it the same way wherever you are.
Why we process your data. If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on your consent to process your health data (the food, weight, and check-in data you log), which you give at signup and can withdraw at any time. We process your account data because it is needed to provide the Service you signed up for, and we send service emails and keep security logs because we have a legitimate interest in running the Service safely. We do not run advertising SDKs on your device in these regions (Section 4.2).
Your rights. You may ask us for access to your personal data, correction, erasure, a copy in a portable format, or restriction of processing, and you may object to processing based on our legitimate interest. You may withdraw your consent to health data processing at any time by deleting your account in the app under Settings or by emailing us. Withdrawing consent does not affect processing that happened before you withdrew it. To exercise any of these rights, email hello@withbazu.com with your full name and the email address on your account. We will respond within 30 days. We do not charge for these requests and we will not treat you differently for making one.
Complaints. If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the data protection authority in the country where you live or work. We would appreciate the chance to address your concern first at hello@withbazu.com.
Transfers. Because our servers and service providers are in the United States, using the Service means your data leaves your country. Where the law requires a transfer mechanism, we rely on your explicit consent given at signup and, with our service providers, on standard contractual clauses.
All personal data collected by Bazu is processed and stored in the United States. We do not intentionally transfer your data outside the United States. By using the Service, you consent to this processing location.
If we experience a security breach involving your personal information, we will notify you and the relevant authorities as required by applicable law, including the FTC Health Breach Notification Rule (16 CFR Part 318) for breaches involving identifiable health information, and applicable state breach-notification statutes. Notice will be given without unreasonable delay and, in any event, within the timeframes those laws require.
The Service may contain links to third-party websites or services. We are not responsible for their privacy practices. Review their privacy policies before providing any information.
The reads, scores and suggestions in the Service are produced automatically from the food you log, as described in Section 1.2. They are ratings of food. They are not decisions about you, they are not used to decide what you may access or pay, and none of them produces a legal or similarly significant effect on you. We do not profile you for advertising, and we make no automated decision about you based on your health data.
We may update this Privacy Policy from time to time. When we do:
For questions, concerns, or requests about this Privacy Policy or our data practices:
Bazu Technologies, LLC
Email: hello@withbazu.com
Website: https://withbazu.com
For data subject requests (access, deletion, etc.), please include your full name, the email address on your account, and the specific request. We will respond within 30 to 45 days, depending on the applicable law.
By creating an account or using Bazu, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
© 2026 Bazu Technologies, LLC. All rights reserved.