Privacy Policy
Last Updated: August 4, 2026
Our Commitment
Causal is owned and operated by Berry Street Research Group LLC ("Berry Street," "we," "us," or "our"), located in New York, New York. Causal uses health and lifestyle data only to provide personal wellness features inside Causal. We do not sell, rent, lease, broker, or use Apple Health data, biometrics, benchmark profile fields, check-in answers, or context notes for advertising, marketing, resale, or unrelated profiling.
1. Information We Collect
Causal collects the following data when you choose to use the related features:
- Apple Health data: You choose which individual records to share for reading, including available heart, activity, sleep, body, mobility, respiratory, hearing, nutrition, mindfulness, State of Mind, symptom, health-alert, characteristic, and other records. Causal stores daily aggregates for broadly supported scalar measurements and alert-event counts; exact supported measurement, food-correlation, mindful-session, State of Mind, and symptom samples; timestamped samples for HRV and resting heart rate; sleep-stage intervals used to derive duration, stages, sleep window, and efficiency; and workout duration, interval, activity type, active calories, distance, average heart rate, source label, and HealthKit workout sample ID when available. Causal separately requests permission to write height, weight, body fat, lean body mass, waist circumference, dietary water, alcoholic beverages, body temperature, blood pressure, reviewed meal nutrition, mindful sessions, State of Mind, and symptoms that you explicitly save in Causal. Date of birth and biological sex can fill compatible missing benchmark fields but are never written to Apple Health.
- Check-in answers: Responses to Causal prompts about mood and selected lifestyle factors such as caffeine, alcohol, sugar, stress, socializing, and workouts.
- Context notes: Optional free text and time ranges you add to a check-in or your transcript, such as illness, travel, or other nuance. Notes are limited to 1,000 characters.
- Food tracking: Catalog searches, barcode values, meal time, written meal descriptions, optional photo descriptions, serving choices, reviewed calories and nutrients, detected-food text, provenance, and reusable personal-food templates. Catalog searches and barcodes are processed against Causal's USDA-backed database; meal photos are not stored by Causal.
- Benchmark profile: Optional age, height, weight, sex assigned at birth, and unit preference, used to make wellness ranges more relevant.
- Account data: Firebase user ID, email address, authentication status, and Google Sign-In account identifiers if you choose Google Sign-In.
- App settings and coach records: Built-in or custom tracked factors, notification and waking-hours settings, AI-analysis consent version, generated finding history, analysis status, reversible analysis views, personal-test instructions, dates, progress and results, and feedback such as useful, off-base, dismissed, or a correction.
2. How We Use Data
- To authenticate your account and keep your Causal data associated with your account.
- To store check-ins, notes, profile settings, HealthKit-derived biometric records, and generated findings for your use in the app.
- When you grant the corresponding write permissions, to save supported measurements, reviewed meal nutrition, mindful sessions, State of Mind, and symptoms explicitly logged in Causal to Apple Health.
- With separate, versioned opt-in consent, to run bounded AI-assisted analysis, return personal wellness patterns and data-quality observations, and evaluate optional 14-day personal tests. These tests describe whether an observed direction repeats; they do not establish causation or provide treatment.
- To retrieve food and serving nutrition from a USDA FoodData Central-backed catalog, save reviewed entries, and reuse your private manual corrections.
- With separate food-analysis consent, to send a meal photo or written meal description to Gemini through Kanonas and return an editable nutrition estimate. When the nutrition catalog is enabled, nutrient values are resolved from USDA-backed records; before catalog rollout, Gemini estimates them and the app labels the source as an AI estimate.
- To schedule local check-in notifications when you grant notification permission.
- To troubleshoot app or backend errors that affect your account.
3. AI Coach Processing and Consent
Notes can be stored and viewed without enabling AI analysis. Before Causal sends raw timestamped biometrics, check-ins, or note text to an AI model, the app asks for separate, versioned consent. You can withdraw that consent in Pulse; withdrawal stops future AI coach runs but does not delete your stored transcript or prior findings.
- Provider: Causal sends pseudonymous signal data directly to Google's Gemini models on Vertex AI. Raw health payloads are not routed through Causal's optional model-tracing proxy.
- Minimization: Account identifiers and obvious email addresses or phone numbers are removed before model calls. Notes are treated as untrusted quoted data, and Causal does not write raw note text or model hidden reasoning into analysis-run logs.
- Retention: Causal retains the transcript, finding versions, analysis views, personal-test records, run metadata, and feedback in Firestore while your account is active. Personal-test reminders, if enabled, are scheduled on your device and use neutral wording. Google Cloud's handling of model request data depends on the Vertex AI feature and production retention controls in use; eligible zero-data-retention controls and any service-abuse exceptions are reviewed as part of production configuration.
- Limits: The coach describes observed personal patterns, including comparisons between earlier Health signals and later Health outcomes. It is not allowed to diagnose, direct medication changes, prescribe treatment, or claim medical causality.
4. HealthKit Boundaries
Causal requests read access to the available scalar measurements, characteristics, and non-quantity records it can graph or use for an incomplete benchmark profile, plus food correlations, sleep analysis, and workouts. It requests write access only when you explicitly save a supported measurement, reviewed meal, mindful session, State of Mind, or symptom. Records retain their timestamps and Causal-authored records are de-duplicated during import. Apple presents separate, fine-grained controls for reading and writing, and you choose each permission. A denied or unshared read type is not available to Causal.
- HealthKit data is not used for advertising, marketing, resale, or unrelated data mining.
- HealthKit data is not shared with advertisers, data brokers, or information resellers.
- You can revoke HealthKit access at any time in iOS Settings or the Health app.
- Revoking write access stops future Causal measurements from being saved to Apple Health without preventing local profile edits or manual logging.
4A. Food Analysis
AI food analysis is optional and uses consent separate from the personal AI coach. When you request an estimate, Causal sends either one compressed meal image with an optional description or a written meal description, plus meal time and time zone, to a Gemini model through the Kanonas gateway. When the nutrition catalog is enabled, Gemini identifies foods and portions and nutrients are resolved from USDA-backed records; before catalog rollout, Gemini returns a bounded nutrition estimate. The app identifies the source and requires review of editable fields before saving. Catalog search, exact barcode lookup, Nutrition Facts entered manually, and private recents work without Gemini consent. Causal does not save meal images in its local records, Firestore, or Firebase Storage.
- Kanonas retention: Kanonas states that it does not offer zero-data-retention and may retain prompts, images or other inputs, outputs, traces, labels, feedback, and usage metadata to operate, secure, evaluate, and improve its service.
- Accuracy: Calories, nutrients, catalog records, serving conversions, written-description or photo identification, and product matches may be incomplete or wrong. Results are editable estimates, not medical advice, allergen detection, or a guarantee that a food is compatible with any diet.
- Withdrawal: Turning off food analysis stops future photo and written-description submissions to Gemini. Catalog search, barcode lookup, manual Nutrition Facts entry, recents, and confirmed food entries remain available.
5. Service Providers
Causal uses the following service providers to operate the app:
- Firebase Authentication: Account creation, email-link sign-in, and account session management.
- Google Sign-In: Optional sign-in method if you choose to continue with Google.
- Firebase Firestore and Google Cloud: Storage and processing for profile settings, check-ins, biometric records, insight records, food entries, private reusable foods, and backend services.
- USDA FoodData Central: Public-domain food, serving, barcode, and nutrient catalog data used for database-backed food logging.
- Google Vertex AI / Gemini: Optional AI-assisted personal wellness analysis after the separate in-app consent described above.
- Kanonas / Gemini: Optional meal-photo and written-description analysis after separate food-analysis consent. Kanonas processes model requests and may retain model-call data under its own privacy and service terms.
Causal does not include third-party advertising SDKs and does not use Firebase Analytics in the iOS app.
6. Retention, Export, and Deletion
We retain account, check-in, context-note, biometric, food-entry, private reusable-food, profile, finding-history, analysis-view, personal-test, run, and feedback records while your account is active so the app can show history and, when consented, generate updated findings. Export and deletion controls are in Pulse under Privacy & Data.
- Deleting Causal data removes local records on the device and supported Firebase/Firestore account records.
- A JSON export includes notes, check-ins, measurements, confirmed food entries, private reusable foods and corrections, profile and source settings, findings, analysis views, personal-test records, run metadata, and feedback associated with your account. Meal photos are not available for export because Causal does not store them.
- Deleting your Causal account removes supported Causal and Firebase records, including confirmed food entries and private reusable foods. It does not guarantee deletion of prior Kanonas photo-analysis traces retained under Kanonas's service terms.
- Deleting Causal data or your Causal account does not delete records already written to Apple Health. You can review or delete those separately in the Health app.
- Account deletion may require recent authentication before Firebase allows the account credential to be deleted.
- Backup copies, logs, or records required for security, fraud prevention, legal compliance, or dispute resolution may persist for a limited period.
7. Your Choices
- You can decline any HealthKit read or write permission and still use manual check-ins. You can also edit profile values locally when HealthKit write access is off.
- You can change notification permission in iOS Settings and change check-in frequency in Causal.
- You can edit benchmark profile fields and tracked factors in Pulse.
- You can store notes while declining AI analysis, withdraw AI consent, dismiss a finding, correct it, require the next run for that finding to use all data, or cancel an active personal test.
- You can decline or withdraw photo food-analysis consent while continuing to search or scan the catalog, log manually, use recents, and view, edit, export, or delete confirmed food entries.
- You can edit or delete your note text and prepare an account-data export in the app.
- You can request help with access or deletion by emailing privacy@causal.fitness.
8. Children
Causal is not intended for children under 13. If you believe a child has provided data to Causal, contact privacy@causal.fitness so we can review and delete it.
9. Contact Us
Causal is operated by Berry Street Research Group LLC, New York, New York. For privacy questions, data access, deletion help, or security concerns, contact privacy@causal.fitness.