Ask Baseline - Privacy Policy
Baseline Privacy Policy
Last Updated: May 8, 2026
Baseline ("Baseline," "we," "us," or "our") collects, uses, and shares personal information through our websites, mobile applications (including the Peak Health iOS app, hereafter "the App"), dashboards, widgets, and APIs (collectively, the "Services"). This Privacy Policy explains what we collect, how we use it, who we share it with, and your rights and choices.
If you have questions, contact our Privacy Contact at privacy@askbaseline.com or by mail at: Baseline, Attn: Privacy, 251 Little Falls Drive, Wilmington, DE 19808.
1. Information We Collect
1.1 Information you provide
- Account & profile: name, email, phone number, username, password, photo, and bio.
- Health profile: height, weight, date of birth, biological sex, dietary preferences, sensitivities (e.g., dairy, gluten, seed oils), allergens, and health goals (e.g., sleep, energy, cardiovascular).
- Household members: you may add household members (e.g., partner, children, parents) with their own health profiles. You are responsible for the legal basis to enter household members' data and for obtaining any required consents.
- Scans & pantry: when you scan a product barcode or label, or search for a product, we process the barcode/label data and store your scan history to power features like your Pantry and personalized suggestions.
- Communications: messages you send to support and feedback you submit.
1.2 Information we collect automatically
- Device & usage: IP address, device type, operating system, browser, app version, language, timestamps, screens viewed, taps and scrolls, and crash diagnostics.
- Approximate location: country/city inferred from IP for content localization and fraud prevention. We do not collect precise GPS location.
1.3 Information from third parties
- Apple Sign-In / Google Sign-In: if you sign in with Apple or Google, we receive a unique identifier and (with your permission) your email. With Sign in with Apple, you may use Apple's email-relay address to keep your real email private.
- Apple Health (optional): if you connect Apple Health, the App reads a limited set of health metrics to personalize your experience. Your raw Apple Health samples are processed on your device and are never uploaded to our servers; only compact summaries of trends may be sent. You can revoke access at any time via iOS Settings > Privacy & Security > Health > Baseline.
2. How We Use Information
- To provide, maintain, and improve the Services (account creation, scanning, scoring, household profiles, personalized suggestions).
- To process subscription purchases through Apple's App Store and to manage entitlements via our subscription provider.
- To send transactional communications (account, security, billing) and, where you opt in, marketing communications.
- To monitor performance, detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations and enforce our Terms of Service.
3. Legal Bases (EU/UK/EEA Users)
Where the EU/UK GDPR applies, we rely on the following legal bases under Article 6:
- Contract performance: to provide the Services you request and to manage your account and subscription.
- Legitimate interests: to operate, secure, and improve the Services, and to prevent fraud and abuse.
- Consent: for optional features that involve sensitive data (see below) and for any non-essential analytics or marketing.
- Legal obligations: to comply with applicable laws, regulations, court orders, and lawful requests.
3.1 Special Category (Health) Data — Article 9 Explicit Consent
We process health-related data — including your dietary preferences, sensitivities, allergens, health goals, and any hormone, sleep, or energy data you provide during onboarding — on the basis of your explicit consent under GDPR Article 9(2)(a). You may withdraw your consent at any time by deleting your account in-app, disconnecting integrations in Settings, or contacting privacy@askbaseline.com. Withdrawal does not affect the lawfulness of processing before withdrawal.
4. Health Data — What We Don't Do
We do not use health data for advertising or marketing, to you or to anyone else. Health data is never shared with third parties for advertising, marketing, or any commercial purpose. This applies to all health profile data, wearable data, Apple Health data, scan history, and health goals. This is prohibited by Apple's App Store rules and is also our own policy.
Not medical / not HIPAA: Baseline is not a HIPAA covered entity or business associate. Health data is used for consumer wellness features only. The App is for educational purposes and is not a medical device.
5. Sub-Processors and Third-Party Services
We rely on the following sub-processors and service providers to operate the App. Each is contractually bound to protect your data and process it only as we instruct:
| Sub-processor | Purpose | Data accessed |
|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Cloud Storage; Google LLC) | Account authentication, primary backend database, profile photo storage, server-side functions. | Email, Firebase user ID, password hash, profile data, scan history, household profiles, profile photos. |
| RevenueCat (RevenueCat, Inc.) | Subscription management, receipt validation, entitlement provisioning across devices. | Anonymous app user ID, subscription status, purchase history, originating app store, device platform. |
| PostHog (PostHog Inc.) | Product analytics: understanding which features are used, where users get stuck, and how to improve onboarding and the scanning flow. | Anonymous user identifier linked to your Firebase user ID, app screens viewed, taps, and event names (for example, onboarding_step_completed, paywall_viewed, scan_completed). We do not send your health profile, dietary preferences, sensitivities, allergens, health goals, hormone/sleep/energy answers, or any other health-related data to PostHog. |
| Sentry (Functional Software, Inc.) (if enabled) | Crash and error reporting to help us diagnose and fix bugs. | Device/OS version, app version, stack traces, breadcrumb logs (with PII scrubbing enabled). |
| Apple App Store / StoreKit (Apple Inc.) | Processing in-app purchases and subscriptions on iOS. | Apple ID-derived purchase tokens (we do not see your Apple ID password or full Apple ID). |
| Google Sign-In (Google LLC) | Optional sign-in with a Google account. | Google account ID, name, email (only if you sign in with Google). |
| Sign in with Apple (Apple Inc.) | Optional sign-in with an Apple ID, including private email relay. | Apple-provided unique identifier and, if you choose, your email or relay address. |
| Shopify (Shopify Inc.) | Hosting our marketing website and content pages (including this Privacy Policy and our Terms of Service). | Standard web server logs (IP address, user agent, referrer) for users who visit the marketing site. |
We may use additional vetted third-party providers for limited tasks such as customer support, anti-fraud, and AI-assisted features. Where any such provider would receive personal information, we will list them in this Privacy Policy or otherwise notify you.
6. Analytics
We use PostHog to understand how the App is used so we can improve it. The data we send to PostHog is limited to anonymous usage events (for example, which screens you view, what you tap, when you complete onboarding steps, and when you scan a product) and an account identifier so we can correlate sessions for a single user.
We do not send your health profile data, dietary preferences, sensitivities, allergens, health goals, hormone/sleep/energy answers, or any other health-related data to PostHog or any other third-party analytics provider. Health data stays inside our own infrastructure (Firebase) for the purpose of providing the Services to you.
7. International Transfers
Baseline is based in the United States, and our sub-processors are primarily located in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with cross-border transfer requirements, your personal information may be transferred to and processed in the United States and other countries that may have different privacy laws than your region.
For these transfers we rely, where applicable, on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent safeguards. Our key sub-processors (including Firebase, RevenueCat, PostHog, and Sentry) are bound by SCCs or operate under recognized adequacy decisions. You may request a copy of the relevant safeguards by contacting privacy@askbaseline.com.
8. Data Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, and pursue legitimate business needs. Retention varies by data type and context:
- Account & profile data: retained while your account is active, and for up to 30 days after account deletion (in backups) before purge.
- Scan history & pantry: retained while your account is active.
- Health wearable data: retained only while the connection is active. Disconnecting stops syncing; you may request deletion of historical data at any time.
- Analytics events: retained for up to 24 months on a rolling basis.
- Crash logs: retained for up to 90 days.
- Billing records: retained for up to 7 years to meet tax and accounting obligations.
9. Your Choices & Rights
You can:
- Access & update your account information in your Profile.
- Disconnect integrations (Apple Health, Google) in Settings.
- Opt out of marketing emails using the unsubscribe link in any marketing email.
- Delete your account in-app: Settings > Manage Account > Delete Account. Deletion removes your account, profile, household members, and scan history from our active systems within 30 days. Certain information may be retained where required by law, for security/fraud prevention, or for legitimate business needs.
Depending on your jurisdiction, you may also have the right to: access, correction, deletion, restriction, objection, portability, and withdrawal of consent. To exercise any of these rights, email privacy@askbaseline.com. We honor browser-based Global Privacy Control (GPC) signals where required.
10. U.S. State Privacy Rights
California, Colorado, Connecticut, Virginia, Utah, Oregon, Texas, and other state residents: you may have the right to access, correct, delete, port, and restrict use of your personal information, and to opt out of targeted advertising and "sales" or "sharing" of personal information.
We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
Consumer health data (Washington, Nevada, Connecticut and similar state laws): synced wellness metrics and your health profile data may qualify as "consumer health data" under state law. We process this data only for the purposes you enable, do not sell it, do not use geofencing to target healthcare facilities, and do not share it for advertising or marketing.
Appeals. If we deny a privacy rights request, you may appeal by emailing privacy@askbaseline.com with "Appeal" in the subject line.
11. Children
The Baseline App account is intended for individuals aged 13 and older. Children under 13 cannot create their own Baseline accounts.
A parent or legal guardian may add a child under 13 as a household member within their own Baseline account, providing verifiable parental consent through their authenticated parent account, consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and EU GDPR-K. The parent controls all data associated with that household member.
If you believe a child under 13 has created an independent account, contact us at privacy@askbaseline.com and we will take appropriate steps to delete the account and associated data.
12. Security
We use administrative, technical, and physical safeguards to protect your information, including encryption in transit (TLS) and at rest, role-based access controls, secure secret storage on-device (iOS Keychain via Apple-provided APIs), and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top. If changes are material, we will notify you in-app or by email before they take effect.
14. Contact Us
Privacy Contact: privacy@askbaseline.com
Support: support@askbaseline.com
Mail: Baseline, Attn: Privacy, 251 Little Falls Drive, Wilmington, DE 19808
Ask Baseline iOS App — Additional Notice
This section supplements the Privacy Policy above and applies specifically to the Ask Baseline iOS application. Where this section conflicts with the general PeakLink Privacy Policy above, this section controls for users of the Ask Baseline iOS app.
Ask Baseline is a consumer app that lets you scan barcodes and product labels on food, supplements, and personal-care products. The app analyzes ingredients and returns a healthfulness score based on your household preferences. Ask Baseline is an educational tool. It is not a medical device, does not provide medical advice, and does not diagnose, treat, or prevent any disease.
Information the Ask Baseline app collects
- Account: email address, Firebase user ID, sign-in provider (email, Apple, or Google)
- Profile & preferences: household composition, dietary preferences, allergens, health goals, additives you wish to avoid
- Scan activity: products you scan (UPC, name), images you capture of product labels, scan timestamps, score results
- Subscription: purchase events, trial status, subscription tier, anonymous App User ID
- Diagnostics & usage: screen views, button taps, onboarding completion events, app version, device platform, anonymous distinct ID
- Optional photo: profile photo you choose to upload
We do not access your Apple Health data, GPS location, contacts, microphone, or advertising identifier (IDFA) in the Ask Baseline iOS app.
Permissions we request
- Camera — required to scan product barcodes and capture label photos for scoring. You can decline; the in-app Search tab works without camera access.
- Photo Library — optional; used only if you choose to set a profile photo.
- Notifications — optional; used for trial reminders and important account updates. You can change this at any time in iOS Settings.
Sub-processors for the Ask Baseline iOS App
The iOS app uses the following service providers. Each receives only the data necessary to perform its role.
Google LLC (Firebase & Google Cloud)
- Services: Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Cloud Messaging, Google Cloud Run + App Hosting (backend), Google Sign-In OAuth
- Data received: Email, Firebase user ID, household composition, dietary preferences, allergens, scan history, profile photos, scanned label images, push notification tokens, server request logs
- Purpose: Account authentication, primary data storage, file storage, transactional notifications, backend compute
- Location: United States (multi-region)
- Transfer mechanism (EU users): EU Standard Contractual Clauses + Google’s Data Processing Addendum
- Policy: policies.google.com/privacy
Apple Inc.
- Services: Sign in with Apple, Apple StoreKit (subscription receipts), Apple Push Notification service
- Data received: Apple ID (or relay email if you hide your email), subscription purchase receipts, anonymous device push tokens
- Purpose: Authentication, subscription billing, push delivery
- Location: United States
- Policy: apple.com/legal/privacy
RevenueCat, Inc.
- Services: Subscription lifecycle management, receipt validation, entitlement state
- Data received: Anonymous App User ID (mapped to your Firebase UID), purchase events, subscription status, device platform, app version
- Purpose: Manage your subscription, validate trial and renewal state, prevent purchase fraud
- Location: United States (AWS)
- Transfer mechanism (EU users): EU Standard Contractual Clauses
- Policy: revenuecat.com/privacy
PostHog, Inc.
- Services: First-party product analytics — event capture, conversion funnels
- Data received: Anonymous distinct ID, screen views, button taps, onboarding completion events
- Purpose: Understand which onboarding paths convert and where users drop off. Aggregate analytics only — never sold, never used for advertising.
- Location: United States (PostHog US Cloud)
- Policy: posthog.com/privacy
Anthropic, PBC (Claude AI)
- Services: Large language model API (Claude) used to generate ingredient explanations, product-score rationales, and personalized product recommendations inside the app
- How data flows: Calls to Anthropic happen server-to-server from our backend, not from your device. When the app needs an ingredient explanation or a personalized recommendation, our backend forwards a minimal request to Anthropic over HTTPS and returns the response to your app.
- Data sent: Your question text or scanned ingredient list, relevant product context (name, UPC, ingredients), and a minimum-necessary slice of your stored preferences used to personalize the response — typically your dietary preferences, allergens, household composition, additives to avoid, and recent scan history. We do not send your email address, Firebase user ID, real name, profile photo, or payment information.
- Purpose: Generate ingredient analysis, score rationales, and personalized product recommendations
- Location: United States
- Training: Anthropic does not train its general models on data submitted through its API. Inputs and outputs may be retained for up to 30 days for trust and safety review, then deleted.
- Transfer mechanism (EU users): EU Standard Contractual Clauses + Anthropic’s Data Processing Addendum
- Policy: anthropic.com/legal/privacy
- Commercial terms: anthropic.com/legal/commercial-terms
Google LLC (Gemini AI via Google AI / Vertex AI)
- Services: Large language and vision model API (Gemini) used for ingredient analysis, label image understanding, score rationales, and personalized product recommendations inside the app
- How data flows: Calls to Gemini happen server-to-server from our backend, not from your device. When the app needs an ingredient explanation, a label parsed from an image, or a personalized recommendation, our backend forwards a minimal request to Google’s Gemini API over HTTPS and returns the response to your app.
- Data sent: Your question text or scanned ingredient list, images of product labels you capture, relevant product context (name, UPC, ingredients), and a minimum-necessary slice of your stored preferences used to personalize the response — typically your dietary preferences, allergens, household composition, additives to avoid, and recent scan history. We do not send your email address, Firebase user ID, real name, profile photo, or payment information.
- Purpose: Ingredient analysis, label image understanding, score rationales, and personalized product recommendations
- Location: United States (multi-region)
- Training: Google does not train its foundation models on data submitted through the paid Gemini API or Vertex AI. Data is processed transiently and is not retained beyond what is necessary to return a response, except for abuse-monitoring purposes consistent with Google’s policies.
- Transfer mechanism (EU users): EU Standard Contractual Clauses + Google’s Data Processing Addendum
- Policy: cloud.google.com/terms/data-processing-addendum
- Gemini API terms: ai.google.dev/terms
Tracking
The Ask Baseline iOS app performs first-party product analytics only. We do not access the iOS Advertising Identifier (IDFA), do not link your data with data from other companies’ apps or websites for advertising purposes, and do not share your data with advertising networks or data brokers. Because we do not engage in tracking as defined by Apple’s App Tracking Transparency framework, the app does not display the ATT permission prompt.
How to delete your account
You can permanently delete your Ask Baseline account, including all associated data, from inside the app: open the app, go to your account settings, and tap Delete Account. Deletion removes your data from our Firebase database, RevenueCat subscription records, and PostHog analytics. We may retain limited records as required by law (e.g., transaction records for tax compliance).
Children
The Ask Baseline iOS app is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information through the iOS app, please contact support@askbaseline.com and we will delete it promptly.
Contact
For Ask Baseline iOS app privacy questions, email support@askbaseline.com.
Last updated for the Ask Baseline iOS app: 19 May 2026.