Back to Hepatix

Privacy

Last updated 30 July 2026. This describes exactly what Hepatix stores, where, and for how long. If something here does not match what the app does, the app is wrong and we want to know.

Who is responsible

Hepatix is operated by WickedSelf LLC, 7171 E Paradise Ln, Unit 693, Scottsdale, AZ 85254, United States. WickedSelf LLC is the data controller. For anything on this page, including a request to see or delete your data, email support@wickedself.com.

The short version

  • You can use the daily loop without an account. Nothing leaves your device until you add an email.
  • We do not sell your data, and we do not share it for advertising.
  • There are no third-party trackers, no advertising pixels and no analytics SDKs.
  • Photos you scan are not stored by us.
  • Hepatix is for people 16 and over.

If you never sign in

Everything the app knows sits in your browser under two keys: hepatix.state.v1 and hpx_sid. That includes your onboarding answers, your year of birth, what you have marked done, your saved foods and recipes, your display preferences, and the free-text answer to "what brought you here" if you gave one. None of it is sent anywhere. Clearing your browser storage erases it, and we cannot recover it because we never had it.

What we store when you do sign in

Signing in is by emailed magic link. There is no password to store.

WhereWhat is in itWhy
Supabase AuthYour email address, and sign-in timestampsTo identify your account and send the magic link
user_stateYour whole app state as one record: onboarding answers, year of birth, the "what brought you here" text, completed actions with timestamps, focus cycles, saved foods and recipes, display preferencesSo your progress survives a lost phone and follows you across devices
subscriptionsStripe status, plan, customer id, current period endTo know whether you have full access. Written by Stripe's webhook, not by the app
push_subscriptionsThe browser push endpoint and its keys, your chosen slot, your timezoneOnly if you turn reminders on. Deleted when you turn them off
care_circleA random share token, the first name you chose to displayOnly if you create a Care Circle link
feedbackWhat you typed, whether you consented to it being quoted, a random session idOnly if you send feedback. Not linked to your account
ab_eventsWhich landing version you saw (a or b), whether you finished onboarding, and a random id generated in your browserTo tell whether one version of the page works better. No IP address, no profile

Health information, stated plainly

Using Hepatix at all suggests something about your health, and the "what brought you here" box often contains more. We handle that text as sensitive. It is stored in your own record, it is never used for advertising, it is never sold, and the only place it is ever shown to another person is a Care Circle link you create yourself.

Under Washington's My Health My Data Act and comparable state laws, that text and your use of the app are consumer health data. We do not collect it beyond what is listed above, we do not share or sell it, and you can have it deleted at any time by emailing us.

What happens to a photo you scan

Explore Foods sends the image to Anthropic's Claude API to identify the dish. The image is reduced in size in your browser first. We do not store the photo, it is not written to any database of ours, and the score and calories you see are computed on our server from a nutrition table and the USDA FoodData Central database rather than taken from the model. The dish name is the only text the model produces that you see.

Care Circle, precisely

If you create a Care Circle link, anyone holding that link can see three things: the first name you entered, the first 200 characters of your "what brought you here" text, and how many small actions you have completed. It shows nothing else, and there is no sign-in on that page, so the link works like a key: anyone holding it gets in. You can revoke it at any time, which takes effect immediately.

Who else processes your data

ProcessorWhat they getWhere
VercelHosting and request logs, which include IP addressesUS and global edge
SupabaseEverything in the tables aboveUS
AnthropicScanned images and menu text; onboarding answers when generating your action poolUS
StripePayment details, which go to Stripe directly. We never see or store a card numberUS and global
USDA FoodData CentralA food name, to look up nutrition values. No personal dataUS
Apple, Google, Mozilla push servicesThe push endpoint for your device, if reminders are onVaries

If you are in the UK, the EEA, or another region with transfer rules, note that these processors are largely US-based and your data is transferred there under their standard contractual clauses.

How long it is kept

  • Your account and state: until you ask us to delete it, or you delete it yourself in Settings.
  • Reminder subscriptions: until you switch reminders off, or until a push service reports the endpoint as gone, at which point it is removed automatically.
  • Care Circle tokens: until you revoke the link.
  • Payment records: as long as tax and accounting rules require, which is typically seven years.
  • Feedback and A/B events: kept in aggregate. They are not linked to your account and cannot be traced back to you by us.

Your rights

Wherever you are, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Email support@wickedself.com and we will respond within 30 days. You do not need a reason and we will not ask for one.

  • UK and EEA: access, rectification, erasure, restriction, portability and objection under the UK GDPR. Our lawful bases are contract for running the app, consent for reminders and for the Care Circle, and legitimate interests for keeping the service working and secure. You can complain to the ICO.
  • Canada: access and correction under PIPEDA, and you may complain to the Office of the Privacy Commissioner.
  • Australia: access and correction under the Australian Privacy Principles, and you may complain to the OAIC.
  • United States: where state law gives you rights of access, deletion, correction or opt-out of sale and sharing, you have them here. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of.

You can erase everything on your device at any time from Settings, without contacting us. If you have an account, tell us and we will remove the server copy too.

Cookies and similar

We set one cookie, hpx_v, which remembers which of two versions of the landing page you were shown so it stays consistent. It carries a single letter. There are no advertising or tracking cookies, so there is no consent banner to click through.

We also use browser storage rather than cookies for the app itself, as described above, and a service worker so the app keeps working offline.

Age

Hepatix is for people 16 and over, and onboarding asks for your year of birth to enforce that. If you are under 16 nothing is stored. If you believe someone under 16 has an account, email us and we will delete it.

Security, and its limits

Traffic is encrypted in transit. Server-side tables are default-deny: they carry no public access policies at all, so only our server routes can read them. Payment details never touch our servers. Care Circle links are unguessable tokens, but anyone who has the link can open it, which is the point of them and also their weakness.

No service is perfectly secure. If we ever discover a breach affecting your data we will tell you and the relevant regulator within the timeframes the law requires.

Changes

If this page changes materially we will say so in the app rather than quietly reposting it. The date at the top is the version you are reading.


Hepatix is a nutrition, movement and education app. It does not diagnose, treat or change any condition. Not a substitute for care from a qualified clinician. See our Terms.