Privacy Policy
Last updated: September 6, 2026
LipidHelm is a cholesterol diary, and lab results are health data — we treat them accordingly. LipidHelm is built local-first: your lipid panels and meals live on your phone, not on our servers. This policy explains what data the LipidHelm app and this website handle, what leaves your device and why, and the controls you have. If anything here is unclear, email support@lipidhelm.com.
Health data comes first
Your lipid panels — total cholesterol, LDL, HDL, triglycerides and any optional ApoB or Lp(a) values you enter — together with your cholesterol status, your broad treatment category and the meals around them, are health information: in many places a specially protected category of personal data (for example under GDPR Article 9). Our design rule for it is simple: health data is stored on your device, is sent off it only when a feature you invoked needs it for the moment of processing, is never retained on our servers, and is never used for advertising or sold — to anyone, ever. The sections below spell out exactly where that rule applies.
Data that stays on your phone
The app stores the following in a database on your device only:
- Your lipid panels — the date of the blood draw, whether the sample was fasting, total cholesterol, LDL (and whether it was measured or calculated), HDL, triglycerides, optional ApoB and Lp(a), and a note. Everything is stored in mg/dL and shown in the unit you chose.
- Your profile: date of birth, sex, height, weight, your cholesterol status (for example "prevention" or "high cholesterol") and a broad treatment category such as "a statin" or "not sure" — never specific medication names or doses, which the app does not collect — plus your LDL and non-HDL goals, your saturated-fat budget, fiber goal and lab interval. Goals and budgets are applied on your phone.
- Your logged meals with their nutrition estimates (including saturated, unsaturated and trans fat, fiber, soluble fiber and dietary cholesterol), weights, water intake, exercise entries, kitchen ingredients, saved recipes and coach chat history.
- Meal photos. Photos are kept on your device; they are transmitted only at the moment you request AI analysis (see below) and are not stored by us afterwards.
- Settings, including your language choice and reminder times. Reminders — including the reminder that your next panel is due — are scheduled locally on the device; no push-notification service is involved.
Deleting the app, or using Profile → Clear all data, removes this local data. Profile → Export lipid panels writes a CSV file that you choose where to share; we never receive it.
AI features: what is sent, and what happens to it
When you use an AI feature, the app sends the minimum needed to our server, which forwards it to an AI provider (Google Gemini, with OpenAI as an automatic fallback) to produce the result:
- Meal photo analysis / fridge scanning: the photo you chose and an optional note you typed.
- Quick text estimates: the food description you typed.
- Recipes: your ingredient list, food preferences, cholesterol status, and your remaining saturated-fat, fiber and calorie budget for the day.
- Coaching (tips and chat): your goals, unit and cholesterol status, your treatment category (never a medication name or dose), a summary of your latest lipid panel — its date, values and the app's reference labels — and the change since the previous one, today's meal totals, your 7-day and since-last-panel diet averages (saturated fat, fiber, fat quality), weight change, activity summaries, the foods behind your saturated fat this month, and your chat messages. This is health data, and it is sent only when you open the coach or ask for tips — never in the background. Individual panels beyond the latest summary are not sent.
- Language: the app's display language, so answers come back in your language.
Our server processes these requests in memory and does not store their contents — no photos, descriptions, lab values or coaching context are retained after the response is returned. Requests are processed by the AI providers under their API terms; we do not use your data for advertising and we do not sell it to anyone. The coach is instructed, as a hard rule, never to advise on medication, supplements, diagnosis or risk; we test those refusals before every release.
Optional cloud backup
Cloud backup is off until you sign in and use it. If you enable it:
- Account: we store your email address (verified by a sign-in link, or provided via Sign in with Apple / Google) and a sign-in token so your backup is yours.
- Backup contents: a snapshot of your lipid panels, profile and goals, meals, weights, water, exercise, ingredients and settings, plus your profile photo if you set one. Meal photos and your coach chat are not included in backups. Because the snapshot contains your health data, enabling backup is the one place you choose to put that data on our server — it stays encrypted in transit, is used for nothing except restoring your own data, and you can remove it at any time.
- Storage: one snapshot per account, kept on our server and replaced each time you back up.
- Deletion: in the app, Delete cloud backup removes the snapshot, and Delete account & all cloud data removes the snapshot and the account, immediately. Signing out revokes the device's token.
Subscriptions and purchases
LipidHelm offers an optional Premium subscription, purchased through the Apple App Store or Google Play. Payments are handled entirely by the store: we never see or store your card number or billing details.
- RevenueCat: the app uses RevenueCat, a subscription-management service, to check whether your subscription is active. RevenueCat receives the store's purchase receipt and, when you are signed in, your LipidHelm account id (a number — not your email, and never any health data), so an active subscription can follow your account onto a new phone. See the RevenueCat privacy policy.
- What we store: nothing. Our own server holds no record of your subscription — entitlement is checked in the app.
- Cancelling: subscriptions are managed and cancelled in your App Store or Google Play account settings, and deleting your LipidHelm account does not cancel a subscription — see our account deletion page.
Apple Health and Health Connect
With your permission, LipidHelm reads from Apple HealthKit or Android Health Connect: workouts and steps only. It does not read, and does not ask permission for, any blood or lab data — your lipid panels are typed by you, never imported from a health platform. Everything read is stored on your device like data you typed yourself. LipidHelm never writes to your health store, and health-platform data is never used for advertising or sold — on Android we additionally comply with the Health Connect permissions policy, which prohibits exactly that. Summaries of this data (for example today's step count or workouts per week) reach our server only inside the coaching requests described above, when you invoke them.
This website
lipidhelm.com is a static site. It sets no cookies and runs no analytics or third-party trackers.
The contact form is the one exception, and only when you choose to use it. The name, email address and message you type are passed to Web3Forms, a form-delivery service, which forwards them to our support inbox. We use them only to reply to you, and we never add you to a mailing list. If you would rather not use the form, write to support@lipidhelm.com instead.
What we don't do
- No advertising, and no advertising SDKs in the app.
- No selling, renting or sharing of your data — health data explicitly included.
- No third-party analytics or tracking SDKs.
- No collection of medication names or doses: the app records only a broad treatment category you choose, and its coach refuses medication, supplement and diagnosis questions by design.
- No risk scores: LipidHelm does not compute or send a cardiovascular-risk estimate.
Children
LipidHelm is not directed at children under 13, and we do not knowingly collect data from them.
Changes
This policy may be updated as LipidHelm evolves; the date above always reflects the current version, and material changes will be noted in the app.
Contact
Questions or requests about your data: support@lipidhelm.com.