Grown

Legal

Privacy Policy

Effective date: April 18, 2026 · Last updated: April 18, 2026

1. Who we are

Grown (the “App”) is operated by Muze Office [[ENTITY TYPE — e.g., LLC]], based in Las Vegas, Nevada, United States [[UPDATE STATE]] (“Muze Office,” “we,” “us,” or “our”). Muze Office is the data controller for personal data collected through the App. You can reach us any time at zacyoung@muzeoffice.com.

Grown is an iOS application (bundle identifier com.grown.app) that helps you track meals, nutrition, peptides, and supplements. This Privacy Policy explains what data we handle, why, and the choices you have.

2. Plain-English summary

3. Data we collect

3.1 Account identifiers

3.2 User profile

To compute your Total Daily Energy Expenditure (TDEE) and nutrition targets, we collect: age, biological sex, height, weight, activity level, and fitness goal.

3.3 Meal logs

Meal name, nutrition macros (calories, protein, carbs, fat, fiber, sugar, etc.), and an optional meal photo you choose to add. Photos are stored in a private Supabase Storage bucket protected by per-user row-level security: only you can read your own photos.

3.4 Peptide logs

Peptide or supplement name, dose, administration route, injection site (if applicable), and timestamps.

3.5 Health information

Bloodwork results (if you choose to enter them) and daily health logs such as weight, sleep, energy, mood, and side effects.

3.6 Apple HealthKit

With your permission, the App reads activity calories, weight, and nutrition metrics from Apple Health, and writes logged meals back into Apple Health. See Section 5 for details.

3.7 Purchases

Subscriptions are processed by Apple through the App Store. We see your entitlement status (active / inactive) via Apple receipt validation. We do not see, collect, or store your payment method, card details, or Apple ID password.

3.8 Device & diagnostics

We do not operate a third-party analytics SDK. Apple may provide aggregated, anonymized App Store and crash data (via App Store Connect and opt-in Apple diagnostics) that we use to find and fix bugs.

4. How we use your data

Legal bases (where GDPR applies): performance of a contract with you, your consent (for optional data such as photos, bloodwork, or HealthKit), our legitimate interest in keeping the App secure and functional, and compliance with legal obligations.

5. Apple HealthKit

When you grant HealthKit permissions, the App may read activity calories, weight, and nutrition data, and may write meals you log back into your Health store. Consistent with Apple’s HealthKit policy:

6. Subprocessors & sharing

We use a small number of vetted subprocessors, each of whom processes data only to provide their service to us:

We may also disclose data if required by law, subpoena, or court order, or to protect the rights, safety, or property of Muze Office, our users, or the public. We do not sell your personal information.

7. No ads, analytics, or tracking

The App does not include advertising networks, third-party analytics SDKs, or tracking identifiers such as the iOS Advertising Identifier (IDFA). There is no cross-app or cross-site tracking, and we do not build advertising profiles.

8. Data retention & deletion

Account data (profile, meals, peptide logs, bloodwork, daily logs, and photos) is retained until you delete your account. You can delete your account at any time from inside the App at Settings → Delete Account. That action triggers a cascade delete of all user-owned rows in our Supabase database and removes your meal photos from storage.

Backups and logs containing deleted data are purged within 30 days, except where retention is required by law — for example, tax and purchase records retained for approximately seven (7) years to comply with U.S. tax and accounting rules.

9. Security

Data is transmitted over TLS. Data at rest in Supabase is encrypted. Database rows and storage objects are protected by row-level security policies so that only the authenticated owner can read or modify them. Server-side keys for third-party services (OpenAI, FatSecret) are held by our edge functions and never shipped inside the App.

10. Your rights

Depending on where you live, you may have the right to:

California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, the right to correct, and the right to non-discrimination for exercising these rights. We do not sell or “share” personal information as those terms are defined under the CCPA.

To exercise any of these rights, email zacyoung@muzeoffice.com. We may ask you to verify ownership of the account before responding.

11. Children

Grown is intended for users 18 years of age or older and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

12. International transfers

We are based in the United States, and our primary subprocessors are in the United States. If you use the App from the European Economic Area, the United Kingdom, or other regions with data-protection laws, your data will be transferred to and processed in the United States under appropriate safeguards.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above, and material changes will be announced inside the App or by email.

Note on continuity: Grown was previously released under the name “Stackt.” Any data originally collected under the Stackt name continues to be governed by this Privacy Policy.

14. Contact

Questions, requests, or complaints? Email zacyoung@muzeoffice.com.