Tare Privacy Policy
Application: Tare
Controller / Operator: PLATON APPLICATIONS LLC (“Platon Applications,” “Platon,” “we,” “us,” or “our”)
Effective Date: 6/18/2026
Last Updated: 6/18/2026
PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy explains how Platon Applications collects, uses, discloses, stores, and protects information in connection with the Tare mobile application and related services (the “Licensed Application” or “Tare”). It is incorporated into and supplements the Tare End User License Agreement (the “EULA”). Capitalized terms not defined here have the meaning given in the EULA.
TARE IS A GENERAL WELLNESS PRODUCT FOR USERS 18 YEARS OF AGE OR OLDER. Tare collects health and fitness information, including — only if you affirmatively opt in — menstrual cycle and reproductive health information. We treat this information as sensitive and apply the heightened protections described in Sections 4, 9, and 13. Tare is supported in part by third-party advertising, but we never use your reproductive health data or HealthKit data for advertising, and we do not sell your personal information for money. You can control ad tracking — see Section 6.
1. About This Policy and Who We Are
This Privacy Policy applies to personal information we process when you download, install, access, or use Tare, when you create or manage an Tare account, when you subscribe to Tare Pro, and when you otherwise interact with Platon Applications in connection with the Licensed Application. The data controller responsible for your personal information is Platon Applications LLC, a Delaware limited liability company, located at 8 The Green, STE B, Dover, Kent County, DE 19901, United States.
This Policy does not apply to: (a) Apple Inc. (“Apple”), which processes App Store transactions and certain device data under Apple’s own privacy policies; (b) third-party services you connect to Tare; or (c) any product or website that does not link to this Policy. Your agreement to the EULA does not override this Policy, and where the two address the same subject, this Policy governs questions of data handling.
Age restriction. Tare is intended exclusively for individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18. See Section 15.
2. Summary of Key Points
This summary is provided for convenience and does not replace the full Policy.
- What we collect: account details; weight, calorie, hydration, workout, and activity data; device and usage data; payment-related data (handled by Apple or Stripe); and, only with your separate opt-in consent, menstrual cycle and reproductive health data.
- Why we collect it: to operate Tare, display your progress, generate trend predictions, personalize your experience, improve our features, and provide support. Tare shows third-party ads, but never targeted using your health data, and we do not sell your data for money.
- Who we share it with: service providers acting on our instructions — Supabase (our database and backend host, running on Amazon Web Services), Stripe (direct payments), Apple (App Store payments and HealthKit), and third-party AI providers — advertising partners (Google AdMob) for in-app ads when you allow tracking, and disclosures required by law. Health, menstrual, and reproductive data are always excluded from advertising. We do not sell personal information for money.
- Where it lives: in a database hosted by Supabase (running on AWS) in the region we configure, with encryption in transit and at rest. No system is 100% secure (Section 9).
- Your choices: you can access, correct, delete, and export your data; withdraw consent to reproductive health data processing at any time; limit the use of sensitive personal information; and opt out of advertising-related “sale” or “sharing” (Section 6). See Sections 12–14.
3. Information We Collect
We collect the categories of personal information described below. The categories are also mapped to the statutory categories used under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), in the table that follows.
3.1 Information You Provide
- Account and profile information — such as your email address, password (stored only in hashed form), birth month and birth year (used to verify you are 18+), and profile settings.
- Health and fitness inputs — weight measurements, calorie intake logged manually, hydration intake, and goals you set.
- Reproductive health information (opt-in only) — if and only if you affirmatively opt in, menstrual cycle start and end dates, cycle length, symptoms, and related observations. See Section 4.
- Support communications — information you provide when you contact support@platonapplications.com or legal@platonapplications.com.
3.2 Information from Connected Devices and Apple HealthKit
With your permission, Tare reads workout and activity data and, where you choose, weight and reproductive health data from wearable devices and the Apple HealthKit framework. HealthKit access is controlled by your device Privacy settings, is requested separately for each data type, and can be revoked at any time under Settings > Health > Data Access & Devices. Our use of HealthKit data is governed by Section 8.
3.3 Payment-Related Information
If you subscribe through the Apple App Store, Apple processes your payment under your Apple ID; we do not receive your full payment card number. If you subscribe directly through Platon Applications, payments are processed by Stripe, Inc. (“Stripe”), our PCI-DSS-compliant payment processor; Stripe receives and stores your card data, and we receive only limited transaction and subscription-status information (for example, the last four digits, card brand, expiration, and billing status). We do not directly store full payment card numbers.
3.4 Information Collected Automatically
- Device and technical data — device model, operating system version, app version, language, time zone, and similar identifiers.
- Usage and log data — in-app events, feature usage, crash logs, diagnostics, and approximate (non-precise) location inferred from IP address for security and fraud-prevention purposes. Tare does not collect precise geolocation for advertising, and does not use location-based advertising or data collection near healthcare facilities (see Section 13).
- Advertising identifiers — your device advertising identifier (such as the Identifier for Advertisers, or “IDFA”) and related data, collected and shared with advertising partners only if you grant App Tracking Transparency permission (see Section 6).
- Cookies and similar technologies — on any Tare website, as described in Section 16.
3.5 Information Sent to Third-Party AI Providers
When you use features that estimate calorie intake or perform other analyses, the inputs you submit (for example, a meal description or photo) may be transmitted to third-party AI or machine-learning providers for processing. See Section 7.
3.6 Categories Under the CCPA
The following table identifies the CCPA statutory categories of personal information we have collected within the preceding 12 months, with examples.
| CCPA Category | Examples Collected by Tare |
|---|---|
| Identifiers | Email address, account ID, device and advertising identifiers (e.g., IDFA), IP address. |
| Customer records (Cal. Civ. Code § 1798.80) | Name (if provided), email, payment-status information. |
| Commercial information | Subscription tier, transaction and renewal history. |
| Internet/network activity | App usage, feature interactions, diagnostics, crash logs. |
| Geolocation data | Approximate (non-precise) location inferred from IP for security only. |
| Sensitive personal information | Account log-in credentials; health data, including weight, calorie, hydration, and — opt-in only — reproductive/menstrual health data. |
| Inferences | Weight-trend predictions and personalization derived from your data. |
We do not collect: biometric identifiers (e.g., fingerprints or face geometry) for identification, precise geolocation for advertising, or information about your race, religion, or sexual orientation. We do not knowingly collect personal information from minors.
4. Sensitive Personal Information and Consumer Health Data
Tare is a health and fitness application, so much of the information we process is “sensitive personal information” under the CCPA and “consumer health data” under state consumer-health-privacy laws. We apply heightened protections to this information.
4.1 Reproductive Health Data — Opt-In Only
Menstrual cycle and reproductive health data are collected only with your separate, affirmative, opt-in consent, obtained through a dedicated in-app consent screen that is presented apart from general onboarding. You may withdraw consent and delete this data at any time in your account settings or by emailing support@platonapplications.com. Withdrawal does not affect the lawfulness of processing before withdrawal.
We use reproductive health data only for the purposes you consented to: cycle awareness, training planning, and analysis of energy availability and the female athlete triad in the context of athletic preparation. We do NOT use reproductive health data for:
- advertising, marketing, or behavioral targeting;
- profiling for any purpose other than the in-app analytics you consented to;
- sale, lease, or licensing to any third party, regardless of consideration;
- disclosure to law enforcement, except pursuant to a valid, enforceable legal process and consistent with applicable state privacy laws; or
- any purpose outside the scope of the consent you provided.
4.2 Right to Limit Use of Sensitive Personal Information
We use sensitive personal information only to provide the features you request, to secure our services, and for the other limited purposes permitted under Cal. Civ. Code § 1798.121. Because we do not use sensitive personal information to infer characteristics about you or for purposes outside those permitted purposes, the CCPA “right to limit” does not require a separate link; nonetheless, you may restrict our processing by withdrawing consent and deleting your data as described above. You may also contact legal@platonapplications.com with any request to limit use.
5. How We Use Information
We use personal information to:
- provide, operate, and maintain Tare and your account;
- display your progress and generate weight-trend predictions and visualizations;
- personalize your experience within the Licensed Application;
- improve the accuracy, reliability, and functionality of our features;
- for users who opt in, support cycle awareness, training planning, and female-athlete-triad analysis;
- process subscriptions, renewals, and free-trial conversions (through Apple or Stripe);
- verify that you are 18 or older and enforce the EULA;
- detect, prevent, and respond to fraud, abuse, security incidents, and unlawful activity;
- provide customer support and respond to your requests; and
- comply with legal obligations and enforce our agreements.
Legal bases (where applicable). Where data-protection law requires a legal basis, we rely on: your consent (including for reproductive health data and HealthKit access); performance of our contract with you (the EULA); our legitimate interests in operating and securing Tare; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time.
6. How We Disclose Information
We do not sell your personal information for monetary consideration. When you grant tracking permission, we disclose advertising identifiers and related device data to advertising partners for personalized advertising — which California law may treat as a “sale” or “sharing.” You can opt out at any time (Section 6.2). We never share Apple HealthKit data, menstrual cycle data, or other reproductive health data with advertising partners.
6.1 Service Providers and Other Disclosures
We disclose personal information as follows:
- Service providers / processors — vendors that perform services on our behalf under written contracts that restrict them to processing data on our documented instructions and prohibit them from using it for their own purposes. These include Supabase (database and backend hosting, which runs on Amazon Web Services as a sub-processor), Stripe (direct payment processing), Apple (App Store payments and HealthKit), and third-party AI providers (calorie estimation and analysis). Each is engaged as a “service provider” under the CCPA or a “processor” under other applicable laws, and its processing is also governed by its own terms and data processing addendum, which apply in addition to this Policy.
- Advertising partners — as described in Section 6.2.
- Legal and safety — to comply with a valid, enforceable legal process; to protect the rights, property, or safety of Platon Applications, our users, or the public; and to enforce the EULA. Reproductive health data is disclosed to law enforcement only pursuant to valid, enforceable legal process and consistent with applicable state privacy laws.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and applicable law; we will not use this exception to circumvent the protections that apply to reproductive health data.
- With your direction — when you ask us to share information with a third party you select.
6.2 Advertising and Tracking
Tare is supported in part by third-party advertising delivered through Google AdMob and similar advertising networks and mediation services. To deliver, measure, frequency-cap, and report on advertising, certain device data, usage data, and advertising identifiers may be collected and shared with these advertising partners, whose use of that data is governed by their own terms and privacy policies.
App Tracking Transparency (ATT). Where required by Apple’s ATT framework, we display a permission prompt before tracking your activity across other companies’ apps and websites for personalized advertising. If you grant permission, we may share your IDFA and related data with advertising partners to deliver personalized ads. If you decline, you will still see advertising, but it will be non-personalized (contextual), your IDFA will not be shared, and cross-app or cross-site behavioral profiling will not occur.
What may be shared for advertising: device and advertising identifiers (e.g., IDFA), IP address and coarse (non-precise) location, device and app information, and app-interaction events. The advertising partner is Google LLC (AdMob), together with any mediation networks integrated into the Google Mobile Ads SDK.
Never shared for advertising. Regardless of your tracking choice, the following are never used for advertising or marketing, never shared with advertising partners, and never sold: Apple HealthKit data; menstrual cycle and other reproductive health data (regardless of opt-in status); and any other sensitive personal information, except as you separately and explicitly authorize. We do not use location-based advertising or data collection near healthcare facilities (see Section 13).
“Do Not Sell or Share My Personal Information” / your opt-out. Because our disclosure of advertising identifiers for personalized advertising may constitute a “sale” or “sharing” under the CCPA and similar laws, you may opt out at any time by: (a) declining or revoking the ATT permission in your device settings; and (b) using the “Do Not Sell or Share My Personal Information” control available in the app settings and in the footer of our website. We also honor recognized opt-out preference signals, including the Global Privacy Control (GPC).
7. Third-Party AI Models
Tare uses proprietary and third-party artificial-intelligence and machine-learning systems, including large language models, to estimate calorie intake and assist with other analyses. Data you submit for AI processing may be transmitted to third-party AI service providers and processed under their terms and privacy policies. AI outputs may contain errors, may be incomplete or biased, and are provided for informational purposes only — they are not medical, nutritional, or dietary advice. We do not transmit your reproductive health data to AI providers unless that processing is within the scope of your opt-in consent and permitted by the provider’s terms.
8. Apple HealthKit
To the extent Tare reads from or writes to Apple HealthKit, Apple’s HealthKit rules apply in addition to this Policy. Accordingly:
- we will not use HealthKit data for advertising, marketing, or other use-based data-mining purposes, other than for improving health management or for health research with your prior authorization;
- we will not disclose HealthKit data to third parties without your consent, except as required by law or as necessary to provide Tare’s core functionality (for example, secure cloud storage);
- we will not sell HealthKit data or use it to inform decisions outside the health-and-fitness context you authorized; and
- HealthKit access is requested separately for each data type and may be revoked by you at any time in your device settings.
Tare does not use the Apple HomeKit framework.
9. Data Hosting, Security, and the Supabase Environment
9.1 Where Your Data Is Stored
Your account and app data are stored in a PostgreSQL database and backend hosted by Supabase, our database and backend-as-a-service provider, which runs on Amazon Web Services (AWS) infrastructure in the geographic region we configure for the project (a United States region for U.S. users). In this relationship, Platon Applications is the data “controller” (and a “business” under the CCPA); Supabase acts as a “processor” (and a “service provider” under the CCPA), processing data only on our documented instructions under the Supabase Data Processing Addendum; and AWS acts as Supabase’s sub-processor. Supabase is contractually restricted from using your data for its own purposes, and its handling of your data is further governed by the Supabase Terms of Service and Data Processing Addendum, which apply in addition to this Policy.
9.2 Security Measures
We maintain commercially reasonable and industry-standard administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit (TLS) and at rest, access controls and least-privilege permissions, database row-level security, network and application security controls available through Supabase and its underlying AWS infrastructure (which maintains industry-recognized certifications such as SOC 2), logging and monitoring, and routine review of our security practices. Responsibility for security in the cloud is shared: Supabase and AWS are responsible for the security of the underlying platform and infrastructure, and Platon Applications is responsible for secure configuration in that environment (for example, access management, row-level security policies, key handling, and data segregation).
No method of electronic storage or transmission is 100% secure. While we take commercially reasonable measures to protect your information, we cannot and do not guarantee absolute security. You are responsible for keeping your account credentials confidential and for promptly notifying us of any unauthorized use of your account.
10. Data Retention and Deletion
We retain personal information only for as long as necessary to provide Tare, to fulfill the purposes described in this Policy, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Retention periods vary by data type and the criteria we use to determine them include: the duration of your account, the nature and sensitivity of the data, legal and tax requirements, and security needs. Reproductive health and other health data are retained only while your account is active or until you withdraw consent or request deletion, whichever is earlier, after which we delete or de-identify the data within a commercially reasonable period, subject to limited backup-retention and legal-hold exceptions.
When you delete your account, we delete or de-identify your personal information except where retention is required by law or for legitimate, narrowly limited purposes such as fraud prevention, dispute resolution, and the enforcement of our agreements.
11. Security-Incident and Breach Notification
We maintain an incident-response process designed to detect, investigate, and respond to security incidents. If we determine that a breach of the security of the system has compromised your personal information, we will notify affected individuals and, where applicable, the relevant regulators and the Attorney General, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system, as required by applicable breach-notification laws (including Cal. Civ. Code §§ 1798.29 and 1798.82). Where Supabase, AWS, or another processor notifies us of a security incident affecting your data, we will assess and provide any legally required notifications. Our provision of, or response to, a notice is not an acknowledgment of fault or liability.
12. Your California Privacy Rights
If you are a California resident, the CCPA provides you the following rights. We do not discriminate against you for exercising any of them.
- Right to know / access — to request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to delete — to request deletion of personal information we collected from you, subject to statutory exceptions.
- Right to correct — to request correction of inaccurate personal information.
- Right to opt out of sale/sharing — we do not sell personal information for monetary consideration, but our disclosure of advertising identifiers to advertising partners for personalized advertising may constitute a “sale” or “sharing” under the CCPA. You may opt out as described in Section 6.2, and we honor opt-out preference signals (including the Global Privacy Control) where required.
- Right to limit use of sensitive personal information — as described in Section 4.2.
- Right to non-discrimination and, where applicable, the right to designate an authorized agent and to appeal a denial of a request.
How to exercise your rights. Submit a request through your in-app account settings or by emailing legal@platonapplications.com. We will verify your identity before responding, typically by confirming control of your account email. You may use an authorized agent with proof of authorization. We respond within the timeframes required by the CCPA (generally 45 days, extendable once).
Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.
Notice of financial incentives / California ARL. Subscription auto-renewal, free-trial, cancellation, and renewal-reminder terms are described in the EULA and comply with the California Automatic Renewal Law (Cal. Bus. & Prof. Code §§ 17600–17606). Nothing in this Policy waives, limits, or modifies any non-waivable right you have under California law, including the CCPA, the Confidentiality of Medical Information Act (CMIA) to the extent applicable, and California reproductive-health-data protections.
13. Consumer Health Data — Washington, Nevada, and Connecticut
13.1 Washington — My Health My Data Act (RCW 19.373)
If you are a Washington resident, the My Health My Data Act (“MHMDA”) applies to your “consumer health data,” which includes the menstrual cycle and reproductive health information you opt in to share. Under MHMDA you have the right to:
- confirm whether we collect, share, or sell your consumer health data and access that data;
- withdraw consent to the collection or sharing of your consumer health data;
- request deletion of your consumer health data; and
- request that we cease collecting, sharing, or selling your consumer health data.
We collect consumer health data only with your separate, affirmative consent, and we obtain separate consent before any sharing. We do not sell consumer health data. We do not engage in geofencing around any healthcare facility to identify, track, collect data from, or send notifications to consumers regarding their consumer health data. Requests may be made to legal@platonapplications.com.
13.2 Nevada (SB 370 / NRS 603A) and Connecticut (CTDPA)
If you are a Nevada or Connecticut resident, we provide equivalent protections for your consumer health data: we obtain consent before collecting or sharing it, we do not sell it without your separate authorization, and we honor your rights to access, delete, and withdraw consent. Connecticut residents also have the rights to access, correct, delete, and port personal data and to opt out of targeted advertising, sale, and certain profiling; you may appeal a denied request by replying to our decision.
14. International Users (EU/UK)
Tare is offered from the United States and is intended for U.S. users. If you access Tare from the European Economic Area or the United Kingdom, you acknowledge that your information will be transferred to and processed in the United States. Health and reproductive data constitute “special category” data under Article 9 of the GDPR/UK GDPR, which we process only on the basis of your explicit consent or another lawful basis. Where required, transfers rely on appropriate safeguards such as the Standard Contractual Clauses. Where we serve EEA or UK users, advertising identifiers and cookies are used only after we obtain any required consent through a Consent Management Platform (CMP) integrated with the Google Mobile Ads SDK consent framework.
15. Children’s Privacy
Tare is for users 18 and older. We do not knowingly collect personal information from anyone under 18, and we implement technical measures intended to prevent under-18 individuals from creating accounts. Because Tare is restricted to adults, we do not direct advertising to children, and our advertising integration is not configured for child-directed treatment or for users below the age of consent. If we learn that we have collected personal information from someone under 18, we will investigate and delete the account and associated data. If you believe a minor has provided us information, contact legal@platonapplications.com.
16. Cookies, Analytics, and Do-Not-Track
Any Tare website may use cookies and similar technologies for essential functionality, security, and analytics. You can control cookies through your browser settings. Because there is no common industry standard for “Do Not Track” signals, we respond to legally recognized opt-out preference signals (such as the Global Privacy Control) as required by applicable law. Tare uses advertising technologies as described in Section 6.2, but we never use advertising or cross-site tracking technologies in connection with your health, menstrual, or reproductive data.
17. Third-Party Services and Links
Tare integrates with and may link to third-party services (including Apple, Stripe, Supabase, AWS, Google AdMob, third-party AI providers, and connected devices). Their handling of your information is governed by their own privacy policies and terms, which we encourage you to review and to which we defer where their terms govern their own processing. We are not responsible for the privacy practices of third parties.
18. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new “Last Updated” date and, for material changes, provide additional notice through the Licensed Application or by other reasonable means. For changes that materially expand our use of sensitive or reproductive health data, we will obtain any consent required by law before the change applies to that data. Your continued use of Tare after the effective date of a change constitutes acceptance of the revised Policy to the extent permitted by law.
19. How to Contact Us
Questions, complaints, or privacy requests may be directed to:
PLATON APPLICATIONS LLC
Address: 8 The Green, STE B, Dover, Kent County, DE 19901, United States
Privacy / Legal: legal@platonapplications.com
Support: support@platonapplications.com
Telephone: +1 (302) 617-0122
© 2026 PLATON APPLICATIONS LLC. All rights reserved.
