Legal
Privacy policy
What Intaq collects, why, where it is kept, who else touches it, and the choices you have.
In short: We collect what you type into the app to run the checks for you. It is stored in a managed database in Singapore and processed on servers in the United States. We never sell it, never advertise with it, and you can have it corrected, exported or deleted by asking us.
1. Who we are and who is accountable
Intaq is operated by Intaq Health Inc., 260 - 3631 No. 3 Road, Richmond, British Columbia V6X 2B9, Canada (“Intaq”, “we”). This policy covers the Intaq app at app.intaq.ai and the website at intaq.ai.
We are accountable for the personal information in our care under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act. Our privacy officer is reachable through the contact page on this website.
2. What we collect
Account information. Your email address and a password. The password is stored only as a salted hash by our sign-in provider; we never see or store the password itself.
Health information you give us. The supplements and medicines you list, the conditions, allergies, pregnancy or breastfeeding status, age band and sex you tell us about, meals you log (typed, spoken or photographed), weight entries, lab values you enter, reminders, check-in answers, and any side effects or notes you write. This is sensitive information and is used only to run the checks and features you asked for.
Conversations with the app. Your chat messages and the app’s replies are stored with your account so a conversation can continue where it left off. A short technical trace of each turn (what you asked, a summary of the answer, and which safety checks fired) is kept separately to find and fix errors; those traces are deleted after 90 days.
Household information. If you create a household: the names or nicknames you give to members, the invitations you send, and the sharing choices each adult makes. A child’s profile is created and managed by an adult; a teen who is given a login sees only their own profile, and the adult’s consent is recorded when the login is created.
Payment information. Payments are processed by Stripe. We store your Stripe customer reference, your plan, its billing interval, its status and the renewal date. Card numbers never reach us and we do not store any part of them.
Technical information. Our servers log each request’s path, time, status and network address for security and error handling; these logs are kept for 30 days. We do not run advertising trackers or third-party analytics on the website or in the app, and we do not store your network address with your account.
Messages you send us. If you use the contact form, we keep your name (if given), email address and message so we can reply, and keep them for 12 months after the last reply.
3. Why we use it, and on what basis
We use your information to provide the service you signed up for: screening what you take against your medicines, conditions and each other; computing your plan, schedule and reminders; scoring meals and baskets; running your household; billing your plan; answering your messages; and keeping the service secure. When you create an account you agree to this policy; because health information is sensitive, we ask for that agreement expressly at sign-up, and you can withdraw it at any time by deleting your account.
We also use de-identified, aggregated counts (for example, how often a particular interaction is flagged) to improve the rules. We do not use your information for advertising, and we do not sell it.
Automated processing. The app’s verdicts are produced automatically from written rules with cited sources and from a language model that explains them. No decision Intaq makes about you has a legal or similarly significant effect; the app never diagnoses, treats or prescribes, and you decide what to do with your clinician. If you want a person to look at any result, ask us through the contact page.
4. Where it is kept and who else processes it
Your account and app data are stored in a managed PostgreSQL database run by Supabase in Singapore (Amazon Web Services, region ap-southeast-1), with row-level access rules so that one account can never read another’s records. The application runs on Google Cloud in the United States (us-east1). The providers below process information on our behalf; each is bound to use it only to provide its service to us:
| Provider | What for | What it receives |
|---|---|---|
| Supabase (Singapore) | Database, sign-in | Account and app data |
| Google Cloud, Firebase Hosting (United States) | Running the app and serving the website | Requests and app data while being processed |
| Stripe | Payments | Your email, plan and the payment details you enter on Stripe’s own page |
| OpenAI (United States) | The language model that explains verdicts, reads label and meal photos, and transcribes voice | The text, image or audio of that request, including the health details needed to answer it; not your name or email |
| U.S. Department of Agriculture FoodData Central | Nutrient values for foods | The food names you log, as search terms |
| Postmark (United States) | Sending email such as sign-in confirmations, reports and reminders | Your email address and the message |
| Sentry (United States) | Error monitoring | Technical error details; the integration is configured not to send personal data |
Because these providers operate outside Canada, your information may be accessed under the laws of Singapore or the United States while it is there. We choose providers that commit contractually to protect it to a standard comparable to Canadian law.
5. Your choices and rights
- Access, correction, export. Everything you have given us is visible and editable inside the app. To receive a copy of your data, open your account menu and choose Your data & account, then Download my data: the file is prepared at once and contains every record we hold under your account. To correct something the app does not let you change, or if you cannot sign in, write to us through the contact page; we answer within 30 days.
- Deletion. To delete your account and its data, open your account menu, choose Your data & account, then Delete my account and type your email to confirm. Your records are removed from the live database at once, a paid plan is cancelled with no further charge, and the records age out of backups within 7 days. If you cannot sign in, write to us through the contact page from the email address on the account and we do the same within 30 days.
- Email. Product email carries a one-click unsubscribe. Turning email off stops everything except messages about your account or a safety notice we are required to send.
- Sharing. In a household, each adult chooses what the organizer can see and can change it at any time.
- Withdrawing consent. You may withdraw consent at any time by deleting your account; some features cannot work without the information they need, and we tell you which.
- Complaints. Write to our privacy officer first. You may also complain to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.
6. Children and teens
Intaq accounts are for adults aged 18 and over. A child’s profile exists only inside an adult’s household and is managed by that adult. A teen may be given a login by a household adult; the adult’s consent is recorded when the login is created, and the teen sees only their own profile. We do not knowingly collect information directly from anyone under 13.
7. Security
Traffic is encrypted in transit. The database enforces row-level rules so that one account cannot read another’s records, and only the application can reach it. Passwords are held only as salted hashes by our sign-in provider. We keep the programming interface undocumented to the public, send strict browser security headers, and review security before each release step. No system is perfectly secure; if a breach creates a real risk of significant harm to you, we notify you and the Office of the Privacy Commissioner of Canada as the law requires, and keep a record of it.
8. Retention
We keep your account information and health information while your account exists. Per-turn technical traces are deleted after 90 days. Server logs are kept for 30 days. Contact messages are kept for 12 months after the last reply. Database backups are kept for 7 days.
9. Changes
When this policy changes we update the date at the top and, for a change that matters to you, tell you in the app or by email before it takes effect.
10. Contact
Write to us through the contact page on this website, or by post to the address in section 1.
Questions about this document: contact us.