1. Who we are
Grown (the “App”) is operated by Muze Office [[ENTITY TYPE — e.g., LLC]], based in Las Vegas, Nevada, United States [[UPDATE STATE]] (“Muze Office,” “we,” “us,” or “our”). Muze Office is the data controller for personal data collected through the App. You can reach us any time at zacyoung@muzeoffice.com.
Grown is an iOS application (bundle identifier
com.grown.app) that helps you track meals, nutrition,
peptides, and supplements. This Privacy Policy explains what data we
handle, why, and the choices you have.
2. Plain-English summary
- We collect only what’s needed to run the app and compute your targets.
- We do not run ads, analytics SDKs, or any tracking identifiers. The App does not use IDFA.
- We do not sell your personal information, and we do not share it with advertisers or data brokers.
- Apple HealthKit data the App reads or writes stays on your device and in your Health store. It is not transmitted to any third party.
- You can delete your account and all associated data from inside the App (Settings → Delete Account).
3. Data we collect
3.1 Account identifiers
- Email address (required).
- Optional display name.
- Apple user identifier if you use “Sign in with Apple.”
- A Supabase user UUID generated when your account is created.
3.2 User profile
To compute your Total Daily Energy Expenditure (TDEE) and nutrition targets, we collect: age, biological sex, height, weight, activity level, and fitness goal.
3.3 Meal logs
Meal name, nutrition macros (calories, protein, carbs, fat, fiber, sugar, etc.), and an optional meal photo you choose to add. Photos are stored in a private Supabase Storage bucket protected by per-user row-level security: only you can read your own photos.
3.4 Peptide logs
Peptide or supplement name, dose, administration route, injection site (if applicable), and timestamps.
3.5 Health information
Bloodwork results (if you choose to enter them) and daily health logs such as weight, sleep, energy, mood, and side effects.
3.6 Apple HealthKit
With your permission, the App reads activity calories, weight, and nutrition metrics from Apple Health, and writes logged meals back into Apple Health. See Section 5 for details.
3.7 Purchases
Subscriptions are processed by Apple through the App Store. We see your entitlement status (active / inactive) via Apple receipt validation. We do not see, collect, or store your payment method, card details, or Apple ID password.
3.8 Device & diagnostics
We do not operate a third-party analytics SDK. Apple may provide aggregated, anonymized App Store and crash data (via App Store Connect and opt-in Apple diagnostics) that we use to find and fix bugs.
4. How we use your data
- To create and maintain your account.
- To compute your nutrition targets, dose schedules, and protocol reminders.
- To provide AI food-photo recognition and the nutrition chat feature (see Section 6).
- To look up foods and barcodes in public food databases.
- To process subscription purchases through Apple.
- To respond to your support requests and enforce our Terms of Service.
- To comply with legal obligations.
Legal bases (where GDPR applies): performance of a contract with you, your consent (for optional data such as photos, bloodwork, or HealthKit), our legitimate interest in keeping the App secure and functional, and compliance with legal obligations.
5. Apple HealthKit
When you grant HealthKit permissions, the App may read activity calories, weight, and nutrition data, and may write meals you log back into your Health store. Consistent with Apple’s HealthKit policy:
- HealthKit data is not transmitted to any third party by the App.
- HealthKit data is not used for advertising or any other use-based data mining.
- HealthKit data is not sold, shared with data brokers, or disclosed to information resellers.
- You can revoke HealthKit permissions at any time in iOS Settings → Health → Data Access & Devices.
6. Subprocessors & sharing
We use a small number of vetted subprocessors, each of whom processes data only to provide their service to us:
- Supabase (United States) — authentication, Postgres database, file storage for meal photos, and edge functions. Acts as our data processor.
- OpenAI — powers food-photo recognition and nutrition chat. Calls are proxied server-side through a Supabase Edge Function; the App does not ship or expose an OpenAI API key. Where available, OpenAI is configured with zero data retention, and images and prompts are used only to generate your response and are not used to train models.
- FatSecret Platform API — food database lookups, accessed only server-side through a Supabase database proxy.
- OpenFoodFacts — public food and barcode database. No personal information is sent.
- Apple — Sign in with Apple, HealthKit, and App Store / StoreKit. Governed by Apple’s standard developer program terms.
We may also disclose data if required by law, subpoena, or court order, or to protect the rights, safety, or property of Muze Office, our users, or the public. We do not sell your personal information.
7. No ads, analytics, or tracking
The App does not include advertising networks, third-party analytics SDKs, or tracking identifiers such as the iOS Advertising Identifier (IDFA). There is no cross-app or cross-site tracking, and we do not build advertising profiles.
8. Data retention & deletion
Account data (profile, meals, peptide logs, bloodwork, daily logs, and photos) is retained until you delete your account. You can delete your account at any time from inside the App at Settings → Delete Account. That action triggers a cascade delete of all user-owned rows in our Supabase database and removes your meal photos from storage.
Backups and logs containing deleted data are purged within 30 days, except where retention is required by law — for example, tax and purchase records retained for approximately seven (7) years to comply with U.S. tax and accounting rules.
9. Security
Data is transmitted over TLS. Data at rest in Supabase is encrypted. Database rows and storage objects are protected by row-level security policies so that only the authenticated owner can read or modify them. Server-side keys for third-party services (OpenAI, FatSecret) are held by our edge functions and never shipped inside the App.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (you can do this yourself in the App).
- Export a copy of your data.
- Object to, or restrict, certain processing.
- Withdraw consent where we rely on it.
- Lodge a complaint with your local data protection authority (European Economic Area and United Kingdom residents).
California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, the right to correct, and the right to non-discrimination for exercising these rights. We do not sell or “share” personal information as those terms are defined under the CCPA.
To exercise any of these rights, email zacyoung@muzeoffice.com. We may ask you to verify ownership of the account before responding.
11. Children
Grown is intended for users 18 years of age or older and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
12. International transfers
We are based in the United States, and our primary subprocessors are in the United States. If you use the App from the European Economic Area, the United Kingdom, or other regions with data-protection laws, your data will be transferred to and processed in the United States under appropriate safeguards.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above, and material changes will be announced inside the App or by email.
Note on continuity: Grown was previously released under the name “Stackt.” Any data originally collected under the Stackt name continues to be governed by this Privacy Policy.
14. Contact
Questions, requests, or complaints? Email zacyoung@muzeoffice.com.