Privacy Policy
Eatopia is a nutrition service for people with chronic digestive and metabolic conditions. Most of what you tell us is health information, so this policy is specific about what we collect, why, who can see it, and what we do not do with it.
Who this service is for
Eatopia is built for adults. You must be 18 or older to create an account. If we learn that someone under 18 has created an account, we will delete it and the associated data. A parent or guardian may not create an account on behalf of a minor at this time.
Information you give us directly
Account information. Your name, or what you would like Sage to call you, your email address, and your age range. You do not create a password. You sign in with a one time code sent to your email. Our dietitians and staff use separate password protected accounts to reach the clinical tools.
Health and clinical information. This is the core of the service and includes:
- Your primary health focus and any conditions you tell us about, for example irritable bowel syndrome, celiac disease, acid reflux or diabetes
- Symptoms you report, including symptoms you log after meals
- Medications and supplements you take, including dose if you provide it
- Diagnosed food allergies, intolerances and sensitivities
- Body measurements you choose to enter: height, weight, age and sex, used only to compute your nutrition targets. You may decline to provide these.
- Your answers to intake and safety questions, including questions about eating disorder history, pregnancy, and current symptoms that may require clinical review
- Whether you are currently working with a clinician or dietitian
- Recent bloodwork or lab reports you choose to share
Food and meal information. Meals you log by text or by photo, the foods and portions Sage identifies in them, and how you felt after eating.
Photos. Photos of meals, menus or the contents of your fridge that you choose to take or upload. We store meal photos so you and your dietitian can look back at them.
Uploaded documents. If you upload a lab report or similar document, we process it to produce a summary. We keep that summary and the nutrition relevant values we extract from it, and we do not keep the original file. Plain text documents have personal identifiers removed before analysis. A PDF or a photograph is sent to our model provider as it is, because the text has to be read from the page, so anything printed on it, including your name, is part of what is sent. Identifiers are removed from the summary before it is stored.
Messages. What you write to Sage, and messages you exchange with your assigned registered dietitian if you are on a plan that includes one.
Payment information. If you subscribe on the web, payment is processed by Stripe. If you subscribe in the iPhone app, payment is processed by Apple through in-app purchase. In either case we do not see or store your card number. We receive a confirmation of your subscription status and a reference so we can associate your subscription with your account.
Apple Health, only if you allow it. In the iPhone app you can let Eatopia read steps, workouts, height, weight, resting heart rate and sleep from Apple Health. We use them to keep your routine and starting ranges current and to time your meal and wind-down reminders to your own day. We never write to Apple Health, never use Apple Health information for advertising or marketing, and never share it with anyone, including Apple. You can revoke access at any time in the Health app.
Feedback and preferences. Plan feedback, whether you accepted or adjusted a recommendation, your timezone, and your language preference.
Information collected automatically
Session and device information. When you use the service we receive your IP address, browser or device type, and the pages or screens you use. We use this to run the service, keep it secure, and apply rate limits.
Error reports. If something goes wrong in the app, an error report is sent to our error monitoring provider. These reports are configured to exclude request bodies, session data and application logs, which is where health information would otherwise appear, and email addresses are removed from whatever remains. They describe the failure, not your data.
Temporary sessions. If you begin using certain features before creating an account, we create a temporary guest session. If you then create an account, the guest session is merged into it. An unclaimed guest session expires after 30 days, after which it can no longer be used or claimed.
What we do not collect
- We do not use advertising trackers, advertising cookies, or cross site tracking of any kind.
- We do not use third party analytics services. Our product analytics are first party and stay on our own systems.
- We do not collect precise location.
- We do not sell your information, and we do not share it for advertising.
- Apart from Apple Health on iPhone, with your permission, we do not connect to Oura, Whoop, continuous glucose monitors or other wearables today. The app may ask which devices you use so we can plan for future support. Selecting one does not connect it, and no device data is collected. If those integrations launch, we will update this policy first.
How we use your information
To provide the service. To build and update your nutrition plan, read your meals against it, track your progress, and let you talk to Sage and to your dietitian.
To compute your nutrition targets. Your body measurements, if provided, are used by a deterministic engine to calculate energy, protein and nutrient targets. Those numbers are produced by formulas, not by an artificial intelligence model.
To keep you safe. Every message you send is screened by safety rules before it is answered. Some messages are routed to a person rather than answered by Sage. Certain intake answers cause your plan to be reviewed by a registered dietitian before it reaches you.
To let a dietitian review your care. If your plan includes a registered dietitian, they can see your health and meal information in order to review, approve and adjust your plan and to reply to your messages.
To send you service messages. Sign in codes, check in reminders, and notices about your plan.
To remind you at your own times. In the iPhone app, meal and wind-down reminders are scheduled on your phone from the times you usually log meals and, if you allow it, your sleep pattern from Apple Health. That schedule never leaves your device, and you can turn the reminders off in Settings.
To run and secure the service. To detect abuse, apply rate limits, diagnose errors, and maintain the security of our systems.
To meet legal obligations and to respond to lawful requests.
We do not use your information for marketing without your consent, and we do not use it to train artificial intelligence models.
How Sage handles your information
Sage uses large language models to understand what you write and to draft replies. When you send a message, the text of your message and relevant context from your profile is sent to our model provider to generate a response.
Identifiers are removed first. Your name is replaced in the profile we send, and pattern matching removes identifiers such as email addresses, phone numbers and dates of birth from the text. This is automated and cannot catch everything, so please avoid typing information you would not want shared. The model does receive your health information, because it needs it to answer you.
The model does not do your clinical math. Plans and nutrient targets come from a deterministic engine that makes no model calls. Sage cites from a curated clinical knowledge base and links to sources indexed in PubMed where they exist. We do not independently verify every citation at the moment it is shown, so please check anything clinically important with your dietitian or your clinician.
How we protect your information
- All connections to the service are encrypted.
- You sign in with a one time code, so there is no password of yours to steal.
- Identifiers are removed by pattern matching before information is sent to models.
- Error reports exclude request bodies, session data and application logs, and email addresses are removed from what remains.
- Uploaded documents are processed for a summary and the original file is not kept.
- Automated safety screening records a hash of your message rather than the text. If a message triggers an escalation to a person, that message is stored and sent to the on-call dietitian so they can respond.
- Administrative access to patient records is written to an append only audit trail.
- Our code is scanned automatically for known vulnerabilities and leaked secrets.
No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur. If we become aware of a breach affecting your unsecured health information, we will notify you and, where required, regulators, in accordance with applicable law.
How long we keep your information
We keep your information for as long as your account is active. When you delete your account, your information is deleted within 90 days, except where we are required to keep it by law. We keep a minimal record that the deletion happened.
Your rights and choices
Access and export. You can request a copy of the information we hold about you.
Correction. You can edit your profile, conditions, medications and body measurements in the app at any time.
Deletion. You can request deletion of your account and associated data.
Text messages. If you opted in to check ins by text message, you can stop them at any time by replying STOP or changing your preferences in the app.
Email. Service emails such as sign in codes and plan notices are necessary to operate your account. We do not send marketing email.
California residents
Under the California Consumer Privacy Act you have the right to know what personal information we collect, to delete it, to correct it, and to be free from discrimination for exercising these rights.
We do not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information for any purpose other than providing the service. The categories we collect are described above.
Children
The service is not directed to anyone under 18, and we do not knowingly collect information from anyone under 18.
Changes to this policy
If we make material changes, we will notify you by email or in the app before they take effect, and update the effective date above.
Contact us
Questions about this policy, or to exercise any of the rights above, reach us at: