Skip to content

Privacy Policy

Last updated: July 21, 2026

Overview

Lean Engineering ("we") operates a HIPAA-conscious wellness platform. This policy explains what we collect, how we use it, and the choices you have.

Information We Collect

  • Account info: name, email, phone, emergency contact.
  • Health data: body composition, medications, diagnoses, lab results, progress photos, wellness goals, treatment plans, clinical notes.
  • Communications: secure messages between you and your care team.
  • Device data: information you elect to share from connected wearables, scales, and health apps.
  • Usage data: basic logs required to run and secure the Service.

How We Use It

  • To deliver care and personalized recommendations.
  • To operate, maintain, and secure the Service.
  • To communicate with you about your care and account.
  • To comply with legal obligations, including medical recordkeeping.

Sharing

We share protected health information with your care team and with sub-processors bound by HIPAA-appropriate agreements (hosting, email delivery, AI processing). We do not sell your data.

Security

Data is encrypted in transit and at rest. Access is limited by role-based controls and row-level security. Progress photos and medical documents are stored in a private bucket accessible only via short-lived signed URLs.

Your Rights

You may access, correct, or export your data from your profile page, or request deletion by contacting us. Retention of medical records is subject to applicable law.

Children

The Service is not directed to children under 13. Do not create an account on behalf of a minor without parental consent and clinic approval.

Changes

We may update this policy; material changes will be communicated in-app or by email.

Contact

Privacy inquiries: andrew@leanengineering.io.

See also our Terms of Service.