Privacy Policy
Last updated: August 4, 2026
This Privacy Policy describes how Vibe Palm (“Vibe Palm”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects information when you use the Palmi mobile application and related websites, support channels, and services (collectively, the “Service”).
By downloading, accessing, or using Palmi, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
Tracking only — not health advice. Palmi is solely a personal tracking application for logging nutrition, fasting, weight, and optional GLP-1 routines. It does not provide health advice, medical recommendations, diagnosis, or treatment. Palmi is not a medical device. Always consult a qualified healthcare professional for any health or medical decisions.
Plain-Language Summary
- Palmi is a nutrition, fasting, weight, recipe, Apple Health, and optional GLP-1 tracking application for adults age 18 or older.
- Palmi creates an anonymous Firebase account. We do not require a name, email address, or phone number for sign-in in the current version.
- Information you enter—such as profile details, goals, food logs, weight, fasting sessions, health-condition selections, allergens, maternity status, and optional GLP-1 records—may be stored in Google Firebase under your anonymous account identifier.
- AI meal scanning sends a meal photo and app language through Firebase to OpenAI GPT-4o only after explicit consent. AI estimates may be wrong and must be reviewed by the user.
- With permission, Palmi can read weight, active energy, and dietary energy from Apple Health and write Palmi weight entries to Apple Health. Imported weight may be synced to Firebase; active and dietary energy are used for charts and are not currently uploaded to Firebase.
- We do not sell personal information or consumer health data, share it for targeted advertising, or use HealthKit data for advertising, marketing, or use-based data mining.
- You can withdraw optional permissions, revoke future AI sharing, delete your account in the app, or contact us to exercise applicable privacy rights.
This summary is provided for convenience. The complete policy below controls and explains important limitations.
1. Who We Are
Palmi is operated by Vibe Palm. For privacy questions, data-subject requests, or account deletion help, contact us at:
- Email: business@vibepalm.com
- Support page: Support
We process personal data as a controller for the purposes described in this policy, except where a third-party provider processes data as an independent controller (for example, Apple or Google for App Store billing).
2. Scope
This policy applies to:
- The Palmi iOS and Android apps
- Our legal and support web pages (including this site)
- Customer support communications you send us
- Subscription and entitlement systems connected to Palmi Pro
It does not apply to third-party websites or services that we do not control, even if linked from the Service.
2.1 Key terms
- Personal information means information that identifies, relates to, describes, or can reasonably be linked to a person or household.
- Health data means information about health, wellness, nutrition, weight, pregnancy or breastfeeding status, fasting, medication tracking, dose logs, injection sites, side effects, allergies, health conditions, Apple Health records, and similar information processed through Palmi.
- Consumer health data means health-related information protected by applicable consumer health privacy laws, including information that may identify a consumer's physical or mental health status.
- Sensitive personal information includes health data, account credentials, and health- or body-related photos where protected by law.
- Processing includes collecting, using, storing, transmitting, organizing, deleting, or otherwise handling information.
- Service provider means a company that processes information to provide infrastructure or functionality to Palmi under its own terms and applicable contractual obligations.
- De-identified or aggregated data means information processed so it is not reasonably linked to an identifiable user, or combined into group-level statistics.
3. Categories of Data We Collect
The data we process depends on how you use Palmi. We do not require more information than needed to operate the features you choose to use.
3.1 Account and identity data
- An anonymous Firebase Authentication user identifier
- Account creation, session, and authentication metadata generated by Firebase
- A RevenueCat app-user identifier linked to the Firebase user identifier for subscription entitlement management
The current version does not require your name, email address, phone number, or social-login profile to create an account. If you contact support by email, we receive the email address and information you choose to send.
3.2 Profile, goals, and lifestyle inputs
- Gender, date of birth / age-related inputs, height, weight
- Goal type (lose / maintain / gain), target weight, pace, activity level, step goals
- Lifestyle answers such as water habits, cravings, late-night snacking, and diet history
- Unit preferences (metric / imperial) and language preference
3.3 Health-related information you choose to provide
Some features ask for information that may be considered health-related. You control whether to provide it. Examples include:
- Optional GLP-1 medication name, dose, injection day, weeks on therapy, injection sites, and check-ins
- Fasting plan and eating window
- Allergens / foods to avoid, digestion answers, and selected health conditions
- Maternity status and pregnancy week (when applicable)
- Weight logs and progress history
We use this information only to provide the feature you choose, store and display your records, calculate the limited estimates described in Section 16, and support reminders where enabled. Health-condition and allergen entries are not medical screening and must not be relied on to prevent exposure or determine treatment. We do not use these inputs to sell advertising profiles.
3.4 Nutrition and usage logs
- Meals, foods, servings, calories, macros, water intake, and manual burned calories
- Daily notes and challenge / streak related activity
- Feature usage events needed to operate and improve the product
3.5 Meal photos and AI scan inputs (optional)
If you choose meal scan and provide explicit in-app consent, your selected food photo is sent through our Google Firebase backend to OpenAI, our third-party AI provider, to identify foods and estimate portions, calories, and nutrients. Palmi currently uses OpenAI's GPT-4o vision-capable model for this feature. The model receives the selected image, the app language, and instructions needed to perform the meal analysis, and returns structured food and nutrition estimates. It does not receive your name, email address, complete profile, health history, or other meal records as part of the model request.
No meal photo is submitted for AI analysis before you consent. You may decline and add food manually, or withdraw consent later from Profile > Legal & Support > AI Data Sharing. The temporary image data placed in the Firebase scan job is designed to be removed after processing succeeds or fails. If you choose to add the analyzed meal to your log, a separate copy of the photo may be stored in your Firebase account with the meal record. We do not use submitted photos to train a Palmi-owned AI model. OpenAI's handling of API data is governed by its own privacy policy and business/API data controls. You should review and edit all results before logging because AI estimates can be incomplete or inaccurate. Do not upload photos of other people without permission, or images containing sensitive content unrelated to food logging.
We may replace or update the model as the feature evolves. If a change materially affects how personal data is processed, we will update this policy and, where required, request consent again.
3.6 Subscription and purchase data
- Entitlement status for Palmi Pro (active, expired, trial, etc.)
- Product identifiers and restore-purchase signals
- Purchase processing is handled by Apple App Store / Google Play; we do not receive your full payment card number
3.7 Device, diagnostics, and technical data
- Device type, OS version, app version, locale / language, timezone
- Crash logs, performance diagnostics, and basic analytics events
- Network request metadata required to sync data securely
3.8 Support communications
If you submit a problem, complaint, or suggestion through the in-app Help & Support form, Palmi stores the message in Firebase Firestore together with your anonymous Firebase User ID, message status, app version, build version, platform, app language, and submission time so we can investigate and respond operationally. If you contact us separately by email, we also process your email address, message content, and any attachments you choose to send.
3.9 Apple Health data (optional)
On iOS, Palmi may request permission to read body mass (weight), active energy burned, and dietary energy consumed, and to write body-mass entries that you log in Palmi. Weight imported from Apple Health may be stored in your Firebase account and used to update your weight history and current weight. Active-energy and dietary-energy samples are currently read for progress charts and are not written to Firebase by Palmi. You can revoke access in Apple Health or iOS Settings.
3.10 Local device data
Onboarding answers before account setup, app language, food-search preferences, Apple Health connection status, and a local copy of AI meal-scan consent may be stored on your device. The current AI-consent status is also recorded in Firebase under your anonymous account identifier so the backend can enforce it before processing a scan. You may need to consent again after account deletion or if a new consent version is required.
| Data Type | Examples | Typical Storage |
|---|---|---|
| Account identifiers | User ID, auth tokens | Firebase |
| Profile & goals | Height, weight, goal, pace | Device + Firebase |
| Health-related inputs | GLP-1, fasting, allergens | Device + Firebase |
| Apple Health | Weight, active energy, dietary energy | Weight: device + Firebase; energy samples: device memory for charts |
| Nutrition logs | Meals, macros, water | Device + Firebase |
| Meal photos | Optional scan images | Firebase + OpenAI GPT-4o; optional saved copy in Firebase |
| Subscriptions | Pro entitlement | Apple / Google + RevenueCat |
| Diagnostics | Technical logs and crash/performance data if collection is enabled | Device + Firebase/Google provider systems |
| Preferences | Language, units | Device (local) |
4. How We Collect Data
- Directly from you: onboarding answers, profile edits, food logs, photos, support emails
- Automatically: device and diagnostics data when the app runs
- From store / billing partners: subscription status via Apple, Google, and RevenueCat
- From AI providers: structured scan results returned after you submit a meal photo
We do not buy personal data from data brokers for advertising.
5. Why We Use Data (Purposes)
- Provide core features: calorie targets, meal logging, fasting timers, GLP-1 tracking, progress charts
- Sync your plan and history across devices when signed in
- Calculate and display the limited nutrition estimates described in Section 16 and apply your UI language
- Process and restore subscriptions
- Detect bugs, prevent abuse, and improve reliability
- Respond to support and privacy requests
- Comply with legal obligations and enforce our Terms of Use
6. Legal Bases (Where Applicable)
Where laws such as the GDPR or UK GDPR apply, the legal basis depends on the specific purpose:
| Purpose | Typical legal basis |
|---|---|
| Create the anonymous account, store requested logs, synchronize data, provide recipes, charts, and subscription features | Performance of the service contract or steps requested by you |
| Process optional health entries, Apple Health data, and AI meal photos where explicit permission is legally required | Consent or explicit consent for health data, as applicable |
| Secure the Service, prevent abuse, debug failures, and maintain reliability | Legitimate interests, balanced against your rights |
| Keep legally required billing, tax, fraud-prevention, or dispute records | Legal obligation or legitimate interests |
Health information may receive additional protection as special-category data. Where consent is the basis, you may withdraw it at any time without affecting processing completed before withdrawal. Withdrawal may disable the optional feature that requires the data. We do not rely on consent where another lawful basis is required or more appropriate.
7. How We Share Data
We do not sell your personal information. We share data only as needed to operate Palmi:
- Service providers that process data on our instructions (hosting, analytics, crash reporting, AI inference, subscription tooling)
- App stores and payment platforms for distribution and billing
- Professional advisors (legal, accounting) under confidentiality where required
- Authorities when required by law, court order, or to protect rights, safety, and security
- Business transfers if we are involved in a merger, acquisition, or asset sale (your data may transfer as part of that transaction, subject to this policy or a successor policy)
7.1 Consumer Health Data Privacy Notice
This subsection is intended to provide additional notice for consumer health data laws, including Washington's My Health My Data Act and Nevada consumer health data requirements where applicable.
Categories collected: profile and body measurements; nutrition, food, water, weight, activity, and fasting records; selected conditions, allergens, digestion answers, and maternity status; GLP-1 medication, user-entered prescribed dose, schedule, injection site, side-effect, and check-in records; meal and recipe photos; AI-generated meal estimates; and Apple Health data you authorize.
Sources: directly from you; from your device and Apple Health with permission; from AI scan results you request; and from subscription providers for entitlement status. We do not purchase consumer health data from data brokers.
Purposes: to provide the tracking, logging, synchronization, charting, reminder, recipe, AI meal-estimation, personalization, subscription, security, support, and account-deletion functions you request. Palmi does not use these records to diagnose, prescribe, determine insurance or employment eligibility, or make legally significant decisions.
Recipients: Google Firebase processes account, database, storage, and server-function data; OpenAI processes meal photos and language instructions only for AI scans you authorize; RevenueCat processes the account identifier and subscription entitlement information; Apple processes Apple Health and App Store information under Apple's rules; Google Play may process Android purchase information. We do not intentionally send dose logs, conditions, side effects, allergens, maternity status, Apple Health samples, or private notes to advertising or attribution networks.
Sale and targeted advertising: Palmi does not sell consumer health data or share it for targeted advertising. We do not use geofencing to identify or target people at healthcare facilities. If this practice ever changes, we will first provide the notice, consent, authorization, and opt-out mechanisms required by applicable law; this policy alone would not constitute authorization.
Your health-data rights: where applicable, you may ask whether we collect or share your consumer health data, request access or deletion, request a list of relevant recipients, withdraw consent for future collection or sharing, or appeal a denied request. Use the request process in Section 12. Withdrawal does not affect processing already completed and may prevent an optional feature from functioning.
8. Third-Party Services
Palmi relies on the providers below. They may process technical metadata such as IP address, device, request time, and security logs as part of providing their services. Their own policies also apply.
| Provider | Purpose | Data involved | Policy |
|---|---|---|---|
| Google Firebase / Google Cloud | Anonymous authentication, Firestore database, file storage, Cloud Functions, security, and technical infrastructure | Account identifier, profile, tracking records, saved photos, transient AI jobs, and technical metadata | Firebase Privacy |
| OpenAI (GPT-4o) | Meal-photo analysis requested after explicit consent | Selected meal image, app language, and analysis instructions; not the complete Palmi profile or log history | Privacy · API data controls |
| RevenueCat | Subscription entitlement, offering, purchase restoration, and server-side Pro verification | Firebase-linked app-user identifier, product and entitlement status, and purchase metadata supplied by app stores | RevenueCat Privacy |
| Apple App Store / Google Play | Distribution, purchases, billing, refunds, and subscription management | Store account, transaction, product, territory, and billing information controlled by the store; Palmi does not receive full card details | Apple Privacy · Google Privacy |
| Apple HealthKit | Optional health-data read/write requested by the user | Authorized weight, active-energy, and dietary-energy samples as described in Sections 3.9 and 18 | Apple Health Privacy |
| Expo / EAS | Application build and update infrastructure | Build-time project and technical information; not used by Palmi as an advertising provider | Expo Privacy |
| Netlify | Hosting this privacy, terms, and support website | Standard web request and security metadata | Netlify Privacy |
Palmi does not currently integrate Mixpanel, AppsFlyer, Google Gemini, Meta/Facebook SDK, Sentry, or third-party advertising SDKs. Some Firebase modules may be linked in the native build for platform infrastructure; we do not intentionally send private health entries to analytics, attribution, or advertising services.
9. International Transfers
Vibe Palm and its providers may process information in Türkiye, the United States, the European Economic Area, and other locations where they operate. Those countries may have different data-protection laws. Where required, transfers rely on mechanisms made available by applicable law, such as adequacy decisions, approved contractual protections, or provider data-protection terms. Contact us for information relevant to your circumstances.
10. Retention
We use the periods or objective criteria below. Provider security logs, backups, transaction records, and support systems may follow provider or legal retention schedules that we do not directly control.
| Data | Current retention approach |
|---|---|
| Anonymous account, profile, targets, health inputs, daily logs, weight, fasting, GLP-1, challenge, recipe, and custom-food data | Until you delete individual records where supported or delete the account, subject to legal exceptions |
| Transient AI scan image | Stored temporarily in Firebase Storage and normally deleted immediately after processing succeeds or fails. A scheduled cleanup runs every six hours and removes abandoned temporary images older than 36 hours; account deletion also removes them. |
| Saved meal and recipe images | Until the account is deleted, unless a specific in-app removal control also deletes the stored image |
| Device-local preferences and AI consent | Until revoked, cleared, logout/account deletion, app removal, or device-storage reset, depending on the item |
| Apple Health active and dietary energy used for charts | Held in application memory for the requested chart session; not currently written to Firebase |
| RevenueCat and app-store transaction or entitlement records | According to provider, billing, fraud-prevention, tax, dispute, and legal requirements |
| In-app support tickets and email communications | For the time reasonably necessary to investigate or answer the request, maintain support history, prevent abuse, resolve disputes, and meet legal obligations |
| Technical and security logs | For a limited operational period determined by the relevant infrastructure provider and security need |
| Backups | Residual copies may remain until the relevant provider's backup cycle overwrites or expires them |
Account deletion: Profile > Delete my account initiates deletion of the Firebase user profile, daily logs, weight/dose/fasting/challenge series, custom foods, user recipes, recipe preferences and drafts, AI scan jobs, and user-owned meal and recipe images before deleting the Firebase authentication identity. The operation requires a working network connection and must complete successfully; if it fails, the app reports an error so the user can retry. A new anonymous session may then be created for an unconfigured app state.
Deleting Palmi does not automatically cancel an Apple App Store or Google Play subscription. Subscription cancellation must be completed in the applicable store settings. App stores, RevenueCat, support providers, and infrastructure providers may retain records that they are legally or operationally required to keep. You may contact us regarding associated provider records.
11. Security
We use administrative, technical, and organizational measures designed to protect personal data, such as encrypted transit (HTTPS/TLS), access controls, and provider security features. No method of transmission or storage is 100% secure. You can help by keeping your device updated and protecting access to your phone and accounts.
12. Your Rights and Choices
Depending on your location, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and related data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Data portability (where applicable)
- Lodge a complaint with a supervisory authority
In-app controls: edit profile fields, change language, manage optional features, and use “Delete my account” in Profile where available.
Email requests: write to business@vibepalm.com with the subject “Privacy Request” and state the right you wish to exercise. Include your Palmi user ID when available, but do not send unnecessary health details, passwords, or payment information by email.
Verification: because Palmi uses anonymous accounts, we may ask you to confirm control of the relevant app session, Firebase user ID, or other account information. We will not request more information than reasonably necessary. An authorized agent may submit a request where permitted, but we may require proof of authority and direct user verification.
Response and appeal: we aim to respond within 30 days or the period required by applicable law. If we deny or limit a request, we will explain the reason and available appeal method where required. To appeal, reply to the decision or email the same address with the subject “Privacy Appeal.” You may also complain to your local data-protection authority or state Attorney General where applicable.
Rights are subject to legal conditions and exceptions. We will not discriminate against you for exercising a privacy right.
13. Children’s Privacy
Palmi is intended only for adults age 18 or older and is not directed to anyone under 18. The onboarding date selector does not permit an age below 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information, contact us and we will take appropriate steps to investigate and delete it as required.
14. Cookies and Similar Technologies
The Palmi mobile app does not use browser cookies. Our legal/support website may use essential hosting and security technologies provided by our web host (Netlify). We do not use the mobile app to run third-party advertising trackers or sell advertising IDs.
15. Push Notifications and Permissions
If you enable notifications or grant camera / photo library access, the OS permission dialogs control those capabilities. You can revoke permissions in device settings. Camera/photo access is used for optional meal scanning; we do not access your library without your action.
16. Health, Nutrition, and Scientific Methodology
Important limitation. The methods below produce educational tracking estimates, not medical measurements or individualized clinical recommendations. Palmi does not measure metabolism, diagnose a condition, prescribe calories, recommend medication doses, or determine whether fasting is safe for a particular person. Research findings describe groups and may not apply to you. Consult a qualified healthcare professional before changing nutrition, fasting, activity, pregnancy, breastfeeding, or medication routines.
16.1 What the calculation engine does
Palmi's target engine is deterministic: the same profile inputs produce the same result. It uses the age, height, weight, gender-related input, activity tier, goal, and pace supplied by the user. The engine does not inspect medical records, laboratory values, diagnoses, or genetic information.
Evidence labels used below: “Direct” means the cited source supports the equation or value for substantially the same purpose; “contextual” means the source supports a range or general approach but not Palmi's exact implementation; “Palmi rule” means a transparent software heuristic with no claim of clinical validation.
| Feature | Method used by Palmi | Evidence / limitation |
|---|---|---|
| Resting energy estimate | Mifflin–St Jeor: BMR = 10 × weight(kg) + 6.25 × height(cm) − 5 × age + sex constant (+5 or −161). If “other” is selected, Palmi averages the two equation outputs. | Direct: original equation [1]. Systematic-review context [10]. This predicts resting energy for populations; it is not indirect calorimetry and individual error is possible. |
| Total daily energy estimate | BMR is multiplied by a self-selected activity factor: 1.2, 1.375, 1.55, or 1.725. | Palmi rule: this exact multiplier set is not validated by WHO, NASEM, or the original Mifflin study. WHO [6] and NASEM [15] provide general activity context, not validation of these four numbers. |
| Goal adjustment | For loss or gain goals, Palmi converts the selected weekly pace using an app approximation of 7,700 kcal per kg. Loss deficits are capped at 1,000 kcal/day and the result is floored at 1,200 kcal/day for female-equation profiles and 1,500 kcal/day for male-equation profiles. Pace input is capped at 1.5 kg/week. | Contextual: the historical 7,700 kcal/kg approximation [11] is intentionally limited by modern dynamic-model evidence [12, 13]. The deficit cap and calorie floors are Palmi rules informed by gradual-loss guidance [7, 14], not universal safety thresholds or outcome promises. |
| Pregnancy and breastfeeding | Palmi disables a weight-loss deficit, uses maintenance as the base, then adds 0 kcal/day in trimester 1, 340 in trimester 2, 450 in trimester 3, or 400 during breastfeeding. | Direct/contextual: pregnancy values reflect DRI values, with 450 rounding the published 452 kcal value [2, 15]. The breastfeeding value uses the top of CDC's general 330–400 kcal/day range [24]. These fixed additions are not obstetric or lactation advice. |
| Macro estimates | Protein is set to 1.6 g/kg and is not raised when GLP-1 tracking is enabled. Fat uses the greater of 27% of target calories or 0.8 g/kg. Carbohydrates receive remaining calories using general 4/4/9 kcal-per-gram factors. | Contextual: 1.6 g/kg reflects the upper end of proposed active-weight-reduction ranges and resistance-training evidence [16, 17], not a universal requirement. Twenty-seven percent lies within general fat ranges [2, 18]; the 0.8 g/kg floor is a Palmi rule. FDA 4/4/9 factors [20] are averages and can differ for fiber, sugar alcohols, and specific foods. |
| Fiber and water | Fiber is estimated at 14 g per 1,000 kcal and water at 33 ml/kg. | Direct/contextual: fiber follows the DRI 14 g/1,000 kcal basis [2]. The 33 ml/kg water value is a Palmi rule, not an EFSA or NASEM requirement; authoritative water reference values use different population methods [19]. Fluid needs can change with climate, exercise, pregnancy, lactation, kidney or heart disease, and medication. |
| Food and recipe nutrition | Food values are scaled from per-100 g catalog or user-entered values. Recipe values are author-entered estimates per serving and scale with serving count. | Estimate only: not laboratory tested by Palmi. Ingredients, brands, preparation, digestibility, fiber, sugar alcohols, and serving size can materially change results [20]. |
16.2 AI meal-photo estimation
After explicit consent, Palmi sends the selected meal image through Firebase to OpenAI's GPT-4o vision-capable model. The model estimates food identity, portion weight, calories, protein, carbohydrate, fat, and fiber. Palmi does not independently match every result to a clinically validated nutrition database or laboratory analysis. Confidence indicators are model estimates, not accuracy guarantees. Users can edit or reject the result before saving. See Sections 3.5 and 8 for data-processing details.
16.3 Fasting
The fasting feature calculates elapsed time, the selected eating window, progress, and streaks. Any displayed metabolic-stage descriptions are general educational summaries informed by review literature [3]. Palmi does not measure ketosis, autophagy, glucose, insulin, or any personal metabolic state, and fixed hour thresholds may not reflect an individual's physiology. Current systematic-review evidence does not establish intermittent fasting as clinically superior to conventional dietary approaches for every person, and longer-term evidence remains limited [21].
Palmi does not determine whether fasting is appropriate during pregnancy or breastfeeding, for children or adolescents, for people who are underweight or have an eating-disorder history, or for people using glucose-lowering medicines. Those decisions require qualified professional advice.
16.4 GLP-1 tracking
GLP-1 features store information entered by the user, such as medication name, prescriber-provided dose, schedule, injection site, and check-ins. Palmi may calculate the next calendar reminder from the schedule entered by the user. Palmi does not calculate, select, recommend, or increase medication doses and does not provide a titration plan. Medication decisions must come from the user's prescriber.
Medication-name limitation: medication and active-ingredient names appear only so an adult user can identify and track a medication that has already been prescribed or otherwise selected with a qualified healthcare professional. The presence, ordering, or display of a name is not a prescription, endorsement, comparison, recommendation, indication that the product is appropriate for the user, or confirmation that it is approved or available in the user's country. Palmi does not choose a medication, suggest switching products, assess contraindications, or determine whether treatment should start, stop, or change.
Professional guidance and sources: users must follow the instructions supplied by their prescriber, pharmacist, manufacturer-approved label, and applicable regulator—not a Palmi log, reminder, projection, or educational summary. Questions about dose, missed doses, side effects, interactions, pregnancy, breastfeeding, contraindications, or emergencies must be directed to a qualified healthcare professional. Authoritative public drug information and current prescribing information are linked in references [4], [5], [22], and [23]. In an urgent or severe situation, contact local emergency services.
Brand independence: Palmi and Vibe Palm are independent and are not affiliated with, sponsored by, endorsed by, or acting on behalf of Novo Nordisk, Eli Lilly and Company, or any other medication manufacturer, distributor, pharmacy, regulator, or healthcare provider. Product names, active ingredients, trademarks, and registered marks belong to their respective owners and are used only for identification and informational reference.
The 1.6 g/kg protein planning value is not medication dosing and is not increased merely because GLP-1 tracking is enabled. The 2025 multisociety advisory discusses proposed protein ranges, uncertainty about which body-weight basis to use, and the need for individualized assessment [17]. Public drug information [4, 5] and current official prescribing information [22, 23] are provided so users can reach authoritative safety information; those sources do not validate Palmi as a treatment tool.
16.5 Apple Health and progress charts
With permission, Palmi may import weight, active-energy, and dietary-energy data for synchronization or display, and may write user-logged weight to Apple Health. Health data is not used to diagnose a condition. Progress charts aggregate recorded values and simple trends; they do not predict clinical outcomes.
16.6 Allergens and health-condition entries
Allergen and health-condition fields are personal tracking inputs. They are not a substitute for checking ingredient labels, contacting a food provider, or obtaining medical advice. Palmi does not guarantee that catalog foods, recipes, user content, or AI results are free from an allergen or suitable for a medical condition.
16.7 What Palmi does not infer
- Health-condition answers do not diagnose disease or automatically determine treatment.
- Allergen entries do not guarantee filtering of every food, recipe, or AI result.
- Digestive-symptom entries do not diagnose a gastrointestinal disorder or automatically prescribe fiber.
- Weight projections are illustrative software estimates, not promised outcomes.
- Calories burned, Apple Health values, and AI confidence values are not used as laboratory measurements.
- References describe the evidence context; they do not certify Palmi as a medical device.
16.8 Numbered references and direct links
- [1] Mifflin–St Jeor equation. Mifflin MD, St Jeor ST, Hill LA, Scott BJ, Daugherty SA, Koh YO. “A new predictive equation for resting energy expenditure in healthy individuals.” American Journal of Clinical Nutrition. 1990;51(2):241–247. DOI: 10.1093/ajcn/51.2.241. DOI record.
- [2] Macronutrient and fiber DRIs. Institute of Medicine, Food and Nutrition Board. Dietary Reference Intakes for Energy, Carbohydrate, Fiber, Fat, Fatty Acids, Cholesterol, Protein, and Amino Acids. National Academies Press; 2005. ISBN 978-0-309-08525-0; DOI: 10.17226/10490. National Academies publication.
- [3] Fasting mechanisms review. de Cabo R, Mattson MP. “Effects of Intermittent Fasting on Health, Aging, and Disease.” New England Journal of Medicine. 2019;381:2541–2551. DOI: 10.1056/NEJMra1905136. DOI record.
- [4] Semaglutide patient drug information. U.S. National Library of Medicine. “Semaglutide Injection: Drug Information.” MedlinePlus, record a618008. MedlinePlus.
- [5] Tirzepatide patient drug information. U.S. National Library of Medicine. “Tirzepatide Injection: Drug Information.” MedlinePlus, record a622044. MedlinePlus.
- [6] Physical activity. World Health Organization. “Physical activity: Key facts and recommendations.” WHO Fact Sheet. WHO guidance.
- [7] Gradual weight loss. Centers for Disease Control and Prevention. “Steps for Losing Weight.” CDC Healthy Weight and Growth. CDC guidance.
- [8] Digestive symptoms. National Institute of Diabetes and Digestive and Kidney Diseases. “Symptoms & Causes of Gas in the Digestive Tract.” NIDDK/NIH.
- [9] Diet and digestive gas. National Institute of Diabetes and Digestive and Kidney Diseases. “Eating, Diet, & Nutrition for Gas in the Digestive Tract.” NIDDK/NIH.
- [10] Resting-energy equation review. Frankenfield DC, Rowe WA, Smith JS, Cooney RN. “Comparison of Predictive Equations for Resting Metabolic Rate in Healthy Nonobese and Obese Adults: A Systematic Review.” Journal of the American Dietetic Association. 2005;105(5):775–789. DOI: 10.1016/j.jada.2005.02.005. DOI record.
- [11] Historical static energy rule. Wishnofsky M. “Caloric Equivalents of Gained or Lost Weight.” American Journal of Clinical Nutrition. 1958;6(5):542–546. DOI: 10.1093/ajcn/6.5.542. DOI record.
- [12] Limitation of the static energy rule. Hall KD. “What is the Required Energy Deficit per Unit Weight Loss?” International Journal of Obesity. 2008;32(3):573–576. DOI: 10.1038/sj.ijo.0803720; PMCID: PMC2376744. Full text at NIH.
- [13] Dynamic body-weight model. Hall KD, Sacks G, Chandramohan D, et al. “Quantification of the Effect of Energy Imbalance on Bodyweight.” The Lancet. 2011;378(9793):826–837. DOI: 10.1016/S0140-6736(11)60812-X. DOI record.
- [14] Adult weight-management guideline. Jensen MD, Ryan DH, Apovian CM, et al. “2013 AHA/ACC/TOS Guideline for the Management of Overweight and Obesity in Adults.” Circulation. 2014;129(25 Suppl 2):S102–S138. DOI: 10.1161/01.cir.0000437739.71477.ee. DOI record.
- [15] Updated energy DRIs. National Academies of Sciences, Engineering, and Medicine. Dietary Reference Intakes for Energy. National Academies Press; 2023. DOI: 10.17226/26818. National Academies publication.
- [16] Protein and resistance training. Morton RW, Murphy KT, McKellar SR, et al. “A Systematic Review, Meta-analysis and Meta-regression of the Effect of Protein Supplementation on Resistance Training-induced Gains.” British Journal of Sports Medicine. 2018;52(6):376–384. DOI: 10.1136/bjsports-2017-097608. DOI record.
- [17] GLP-1 nutrition advisory. Mozaffarian D, Agarwal M, Aggarwal M, et al. “Nutritional Priorities to Support GLP-1 Therapy for Obesity: A Joint Advisory.” Obesity. 2025;33(8):1475–1503. DOI: 10.1002/oby.24336; PMCID: PMC12304835. Full text at NIH.
- [18] Fat reference values. EFSA Panel on Dietetic Products, Nutrition and Allergies. “Scientific Opinion on Dietary Reference Values for Fats.” EFSA Journal. 2010;8(3):1461. DOI: 10.2903/j.efsa.2010.1461. EFSA publication.
- [19] Water reference values. EFSA Panel on Dietetic Products, Nutrition and Allergies. “Scientific Opinion on Dietary Reference Values for Water.” EFSA Journal. 2010;8(3):1459. DOI: 10.2903/j.efsa.2010.1459. EFSA publication.
- [20] Macronutrient energy factors. U.S. Food and Drug Administration. 21 CFR § 101.9(c)(1)(i), general energy factors for protein, carbohydrate, and fat. Official e-CFR.
- [21] Intermittent-fasting systematic review. Garegnani LI, Oltra G, Ivaldi D, et al. “Intermittent Fasting for Adults with Overweight or Obesity.” Cochrane Database of Systematic Reviews. 2026;CD015610. DOI: 10.1002/14651858.CD015610.pub2. Cochrane review.
- [22] Wegovy prescribing information. Novo Nordisk / U.S. Food and Drug Administration. Current U.S. prescribing information for Wegovy (semaglutide). DailyMed Set ID: ee06186f-2aa3-4990-a760-757579d8f77b. Official DailyMed label.
- [23] Zepbound prescribing information. Eli Lilly and Company / U.S. Food and Drug Administration. Current U.S. prescribing information for Zepbound (tirzepatide). DailyMed Set ID: 487cd7e7-434c-4925-99fa-aa80b1cc776b. Official DailyMed label.
- [24] Breastfeeding energy needs. Centers for Disease Control and Prevention. “Maternal Diet and Breastfeeding.” CDC Breastfeeding Special Circumstances. CDC guidance.
How these references are used: References explain the origin, evidence context, or known limitations of selected equations and educational content. A citation does not mean that the source endorses Palmi, validates an individual result, or proves that every app-defined parameter is clinically optimal. DOI, NIH/PMC, government, National Academies, WHO, EFSA, CDC, FDA, and DailyMed links are provided so reviewers and users can inspect the original or authoritative record. The implementation values and references were reconciled on August 4, 2026.
17. Automated Processing
Palmi uses OpenAI's GPT-4o model to analyze meal photos and return estimated foods, portions, calories, and nutrients. Personalized calorie and macro targets are calculated from the profile inputs you provide using the deterministic formulas and app-defined heuristics disclosed in Section 16; they are not generated by the OpenAI model. All outputs are estimates for informational and tracking use, and you can review and edit them before saving. We do not make legally significant automated decisions about you solely by algorithm without human involvement in the sense of credit, employment, insurance, or similar determinations.
18. Apple HealthKit Commitments
If you connect Apple Health, Palmi will request only data types relevant to the features described in this policy and will comply with Apple's HealthKit requirements.
- HealthKit access is optional and requires Apple system permission.
- Palmi does not sell HealthKit data or disclose it to data brokers or information resellers.
- Palmi does not use HealthKit data for advertising, marketing, cross-context behavioral advertising, or use-based data mining.
- Palmi does not use HealthKit data to determine credit, insurance, employment, or similar eligibility.
- HealthKit data is not stored in iCloud by Palmi.
- Weight imported from Apple Health may be synchronized to the user's Firebase account solely for weight history and progress features.
- Active-energy and dietary-energy samples are currently read for progress charts and are not uploaded to Firebase by Palmi.
- Weight entered in Palmi may be written to Apple Health only with permission.
- Revoking HealthKit permission stops future access but does not automatically delete weight already synchronized to Firebase; delete those records or the Palmi account to remove them from Palmi systems.
19. Practices We Do Not Currently Perform
Palmi does not currently:
- Sell personal information or consumer health data
- Share personal information or health data for targeted or cross-context behavioral advertising
- Operate third-party advertising networks in the app
- Use HealthKit data, dose logs, side effects, conditions, allergens, maternity status, or private notes for advertising or marketing
- Use personal health data to train a Palmi-owned AI model
- Provide diagnosis, treatment, prescriptions, dosing instructions, or medication titration recommendations
- Use geofencing to identify or target people near healthcare facilities
- Use personal health information for credit, employment, insurance, or other legally significant eligibility decisions
We may use de-identified or aggregated information for security, reliability, and product analysis only where permitted and where the information is not reasonably linkable to a user. Before any materially different use, sale, targeted-advertising disclosure, research partnership, data licensing, or AI-training practice begins, we will update this policy and provide the separate notice, consent, written authorization, or opt-out required by applicable law. Continued use of the app is not a substitute for legally required consent.
20. U.S. State Privacy Disclosures
These disclosures apply only to the extent the relevant law covers Vibe Palm's processing and the requesting resident. Availability of a right may depend on statutory thresholds, exceptions, and verification.
20.1 California
During the preceding 12 months, Palmi may have collected identifiers (anonymous account and device/request identifiers), customer and commercial records (subscription and entitlement status), internet or application activity, approximate location inferred from network or storefront information, user-provided photos, health and wellness information, and limited inferences used to calculate or display requested targets. Sources and purposes are described in Sections 3–8.
We did not sell or share these categories for cross-context behavioral advertising. California residents may have rights to know, access, correct, delete, receive information about categories and recipients, opt out of sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and receive non-discriminatory treatment. Because Palmi does not currently sell or share for targeted advertising, an opt-out link is not presently required for that practice; qualifying Global Privacy Control signals are handled as described in Section 21.
20.2 Oregon
Oregon residents may have rights to confirm processing; access, correct, delete, or receive a portable copy of covered data; obtain categories of third parties; opt out of sale, targeted advertising, or qualifying profiling; and appeal a denied request. Palmi does not currently sell personal data, conduct targeted advertising, or use profiling to make legal or similarly significant decisions.
20.3 Washington
Washington residents may have rights under the My Health My Data Act to confirm collection or sharing of consumer health data, access data and relevant recipient information, withdraw consent for future collection or sharing, request deletion, and appeal a denied request. The categories, sources, purposes, and recipients required for the consumer health data notice are listed in Section 7.1. Palmi does not sell consumer health data or use health-location geofencing.
20.4 Nevada
Nevada residents may have rights concerning covered information and consumer health data, including access, correction where applicable, deletion, withdrawal of consent for future collection or sharing, recipient information, and appeal. Palmi does not currently sell covered personal information or consumer health data.
20.5 Other U.S. states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Rhode Island, Tennessee, Texas, Utah, Virginia, and other jurisdictions may have additional rights as their laws become applicable. Submit requests through Section 12.
21. Do Not Track, Global Privacy Control, and Platform Choices
There is no uniform legal standard for browser “Do Not Track” signals, and Palmi does not currently respond to DNT as a separate instruction. Where required by applicable law, we recognize a user-enabled Global Privacy Control or other qualifying universal opt-out signal as a request to opt out of applicable sale, sharing, or targeted advertising for the browser or device from which the signal is received. Absence of a signal is not treated as consent.
Palmi does not currently sell or share personal information for targeted advertising, so a GPC signal does not change the app's present behavior. Account-wide or offline requests can be submitted through Section 12. Apple system permissions, HealthKit access, photo/camera permissions, notification settings, and subscription controls remain available in device or store settings.
22. Third-Party Links
Palmi and this policy link to publishers, medical references, Apple, Google, OpenAI, RevenueCat, and other third-party resources. Their websites and services are governed by their own privacy practices. A link does not mean that the third party endorses Palmi or that Palmi controls its content.
23. Changes to This Policy
We may update this Privacy Policy as the Service, providers, or legal requirements change. We will revise the “Last updated” date and, where required, provide notice by in-app message, website notice, email if available, or another appropriate method. If a change requires new consent, explicit health-data authorization, or an opt-out opportunity, we will provide that mechanism before the new processing begins. Continued use alone does not replace consent or authorization required by law.
24. Related Documents
- Terms of Use (including Apple Standard EULA reference for App Store subscriptions)
- Support
- Apple Standard EULA
- Apple App Review Guidelines
- Washington My Health My Data Act
- Nevada Revised Statutes, Chapter 603A
- California Privacy Protection Agency rights information
- Oregon consumer privacy information
- General Data Protection Regulation
25. Contact
Vibe Palm — operator of Palmi
business@vibepalm.comPrivacy Request or Privacy Appeal · target response within 30 days