Last reviewed: 8 September 2026 · munchwise for practitioners
This page is for coaches, dietitians and clinics deciding whether they can use munchwise with their clients. It describes what we store on your behalf, where it lives, how long we keep it, and what happens when someone leaves. The consumer privacy policy still applies to every individual.
For the client data a practitioner sees through a club, the practitioner is the controller and munchwise is the processor. We process it to provide the service and for no other purpose: we do not sell it, and we do not use club data to train models.
For a person's own use of the app outside any club, munchwise is the controller.
Nothing by default. A member chooses, per club and per category, what they share. Each toggle is independent, is off unless they turn it on, and can be withdrawn at any time — withdrawal takes effect on the next request, not at the end of a period.
Two of these — lab results and vitals, and measurements and progress photos — were added after the others and default to off on every existing membership. Consent given earlier for anything else does not extend to them.
Data is kept while the account exists. Deleting an account removes, in one operation: the profile, food and nutrition history, sleep and activity, recipes and pantry, lab results and journal entries, body measurements and progress photos, club memberships, messages, feed posts, sessions, payment records and staff rows — together with every stored file those records referenced.
Deleting a practitioner's account also deletes the clubs they owned and everything held inside them, including shared documents and the club's activity log. Members' own data — their food logs, their measurements — belongs to them and survives; only their membership of the deleted club goes.
Deletion is immediate and not recoverable. Backups roll off within 30 days.
A member can export everything we hold about them at any time, as one machine-readable JSON file, without asking their coach. Files are listed by reference rather than embedded.
Practitioner-side export of a client record is not built yet. A coach can read what has been shared with them inside the app, but cannot download it as a file. If a client needs their record out of munchwise today, they export it themselves.
munchwise does not currently sign Business Associate Agreements and should not be used to process protected health information under HIPAA. The clinical features here are built for coaching contexts. If you are a covered entity, treat munchwise as unsuitable for PHI until we tell you otherwise in writing. We would rather say this plainly than have you find out during an audit.
We support the rights that matter operationally: access and portability through export, erasure through account deletion, and withdrawal of consent per category at any time. Consent is recorded with a timestamp and a version, and every grant and withdrawal is logged so a member can see exactly what they agreed to and when.
Consent does not stand indefinitely: a member is asked again after a year, and a category they do not renew lapses rather than continuing.
A DPA template covering the above is available on request. Email privacy@munchwise.app with your practice name and we will send the current version.
If something on this page is not specific enough for your review, say what is missing and we will answer it directly rather than pointing you back here.
Security issues: security@munchwise.app. We aim to acknowledge within one business day.