Data processing for practitioners

Last reviewed: 8 September 2026 · munchwise for practitioners

This page is for coaches, dietitians and clinics deciding whether they can use munchwise with their clients. It describes what we store on your behalf, where it lives, how long we keep it, and what happens when someone leaves. The consumer privacy policy still applies to every individual.

Roles

For the client data a practitioner sees through a club, the practitioner is the controller and munchwise is the processor. We process it to provide the service and for no other purpose: we do not sell it, and we do not use club data to train models.

For a person's own use of the app outside any club, munchwise is the controller.

What a practitioner can see

Nothing by default. A member chooses, per club and per category, what they share. Each toggle is independent, is off unless they turn it on, and can be withdrawn at any time — withdrawal takes effect on the next request, not at the end of a period.

  • Food entries and ratings
  • Daily nutrition and goals
  • Sleep and steps
  • Weight and profile
  • Lab results and vitals
  • Measurements and progress photos

Two of these — lab results and vitals, and measurements and progress photos — were added after the others and default to off on every existing membership. Consent given earlier for anything else does not extend to them.

What a practitioner cannot see

  • Any category the member has not enabled, in that specific club.
  • Data belonging to a member of a different club.
  • A member's data after they leave the club or their membership is ended.
  • Anything at all if the practitioner's own subscription has lapsed.

Where the data lives

  • Structured data (profiles, food logs, plans, measurements, messages) — MongoDB Atlas, encrypted at rest with AES-256 and in transit with TLS 1.2+.
  • Files (meal photos, progress photos, lab reports, shared documents) — Vercel Blob, a private store. Encrypted at rest. Nothing is publicly addressable: every read is a signed URL that expires within the hour, issued only after the same authorization check that guards the record it belongs to.
  • Authentication — Clerk. We never store passwords.
  • Payments — handled by our payment provider. Card details never reach our servers. Coach-to-client fees do not flow through munchwise at all.

Retention and deletion

Data is kept while the account exists. Deleting an account removes, in one operation: the profile, food and nutrition history, sleep and activity, recipes and pantry, lab results and journal entries, body measurements and progress photos, club memberships, messages, feed posts, sessions, payment records and staff rows — together with every stored file those records referenced.

Deleting a practitioner's account also deletes the clubs they owned and everything held inside them, including shared documents and the club's activity log. Members' own data — their food logs, their measurements — belongs to them and survives; only their membership of the deleted club goes.

Deletion is immediate and not recoverable. Backups roll off within 30 days.

Export

A member can export everything we hold about them at any time, as one machine-readable JSON file, without asking their coach. Files are listed by reference rather than embedded.

Practitioner-side export of a client record is not built yet. A coach can read what has been shared with them inside the app, but cannot download it as a file. If a client needs their record out of munchwise today, they export it themselves.

Sub-processors

  • MongoDB Atlas — database hosting
  • Vercel — application hosting and file storage
  • Clerk — authentication
  • Anthropic and OpenAI — meal analysis. Images and text sent for analysis are not used for training.
  • Resend — transactional email
  • Expo — push notification delivery

HIPAA

munchwise does not currently sign Business Associate Agreements and should not be used to process protected health information under HIPAA. The clinical features here are built for coaching contexts. If you are a covered entity, treat munchwise as unsuitable for PHI until we tell you otherwise in writing. We would rather say this plainly than have you find out during an audit.

GDPR

We support the rights that matter operationally: access and portability through export, erasure through account deletion, and withdrawal of consent per category at any time. Consent is recorded with a timestamp and a version, and every grant and withdrawal is logged so a member can see exactly what they agreed to and when.

Consent does not stand indefinitely: a member is asked again after a year, and a category they do not renew lapses rather than continuing.

Data processing agreement

A DPA template covering the above is available on request. Email privacy@munchwise.app with your practice name and we will send the current version.

If something on this page is not specific enough for your review, say what is missing and we will answer it directly rather than pointing you back here.

Reporting a problem

Security issues: security@munchwise.app. We aim to acknowledge within one business day.