How we collect, use, and protect your personal health information
Last updated: December 27, 2025 | Effective: January 1, 2025
Weight Loss Projection Lab (WLPL) is HIPAA compliant and committed to protecting your personal health information. We never sell your data and only use it to provide you with the best health tracking experience.
We use your information for the following purposes:
🔒 We NEVER sell your personal health information
Your health data is yours. We only share it in the limited circumstances described below.
We share your information when you explicitly authorize us to do so (e.g., sharing with family members, healthcare providers).
We work with trusted third-party service providers who help us operate our platform:
All service providers sign Business Associate Agreements (BAAs) as required by HIPAA.
We may disclose information when required by law, court order, or to protect rights and safety.
In the event of a merger, acquisition, or sale, your information may be transferred. We will notify you and ensure continued protection.
We may share aggregated, de-identified data that cannot be linked back to you for research and analytics.
We implement industry-leading security measures to protect your information:
AES-256 encryption at rest, TLS 1.3 in transit. All PHI is encrypted.
Role-based access, multi-factor authentication, principle of least privilege.
24/7 monitoring, intrusion detection, regular security audits and penetration testing.
Automated encrypted backups, disaster recovery plans, 99.9% uptime SLA.
All employees receive HIPAA and security training. Background checks required.
Comprehensive audit trails for all PHI access and modifications.
Certifications: SOC 2 Type II, ISO 27001, HIPAA compliant infrastructure
You have the following rights regarding your personal information:
Request a copy of all personal data we hold about you. Available through your account settings or by contacting us.
Correct inaccurate or incomplete information through your account settings.
Request deletion of your account and associated data. Some data may be retained for legal compliance (7 years for HIPAA).
Download your data in a machine-readable format (JSON, CSV) from account settings.
Request limitations on how we process your data while maintaining your account.
Opt out of marketing communications, analytics, or AI training data usage.
Withdraw consent for optional features (e.g., biometric authentication, AI analysis) at any time.
Exercise Your Rights
To exercise any of these rights, contact us at privacy@weightlossproglab.com or use the privacy controls in your account settings.
We retain your information for different periods based on type and legal requirements:
| Data Type | Retention Period |
|---|---|
| Account Information | While account is active + 7 years after closure (HIPAA) |
| Health Data (PHI) | While account is active + 7 years after closure (HIPAA) |
| Biometric Data | While feature is enabled + 30 days after opt-out |
| Usage Logs | 90 days |
| Marketing Preferences | Until you opt out or close account |
| De-identified Data | Indefinitely (cannot be linked to you) |
WLPL is not intended for children under 13. We do not knowingly collect information from children under 13.
For users aged 13-17, we require parental consent before creating an account. If you believe we have collected information from a child under 13, please contact us immediately at privacy@weightlossproglab.com.
Your information may be transferred to and processed in the United States and other countries where our service providers operate.
We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission for EU/EEA users.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use after changes become effective constitutes acceptance. If you do not agree, you may close your account.
If you have questions about this Privacy Policy or our privacy practices:
This Privacy Policy serves as our Notice of Privacy Practices as required by HIPAA. For more detailed information about how we protect your Protected Health Information (PHI), please visit our HIPAA Compliance page.
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for filing a complaint.
User