Remy Mux.

YOUR DATA, IN CONTEXT

Privacy policy

Effective and last updated: October 7, 2026

Remy Mux is a personal nutrition and running journal operated by the maintainer of the Remy Mux project. Journal access at remy-mux.vercel.app is currently restricted to its configured owner. Other Google users may request access when Google sign-in is enabled; submitting a request does not grant access to the journal. This policy describes that application, including optional WHOOP, Strava, Runna and Tredict connections. A connection only supplies data after it is configured and authorized.

Information the app handles

  • Account and profile: sign-in email, account identifier, any supplied display name, timezone, weight, dietary preferences, calorie baseline, running goals and related profile information. If you choose Google sign-in when enabled, Google supplies your basic identity information, including your email, Google account identifier, name and profile picture, to Supabase for authentication.
  • Access requests: if a Google account without journal access signs in, the app records that account's identifier, email, display name, request time, pending status and notification-delivery status so the operator can review the request.
  • Nutrition and journal: meals, nutrient values, Eat to Live categories, timestamps, notes, logging status, journal-helper messages, corrections and revision history.
  • WHOOP, when authorized: cycle, recovery and sleep records, including estimated energy expenditure, strain, recovery scores, heart-rate variability, resting heart rate, sleep timing and duration, identifiers and other fields returned in those API responses.
  • Other connected sources: completed running activities from Strava or optional Tredict, and planned sessions from a Runna calendar. Records can include activity names, dates, distances, durations, heart rate, elevation, descriptions and source identifiers. Original activity responses or uploaded files can also contain route or location information, even when the interface shows only headline numbers.
  • Imports and connection details: selected ChatGPT conversation exports, structured nutrition records, activity or calendar files you submit, retained original import files, access and refresh tokens, private calendar addresses, and synchronization status.
  • Technical information: authentication and interface cookies, browser-stored drafts, and request or error information used to operate the service. Hosting providers may process IP addresses, browser information, request timestamps and security or diagnostic logs.

Why this information is used

The app uses this information to authenticate its owner, save and correct journal records, import authorized activity and recovery data, calculate headline summaries, relate food intake to running goals and training, generate rule-based insights, and provide export, deletion and synchronization controls. Retained source records help reconcile repeated imports and preserve corrections.

Remy Mux does not sell personal data, run advertising, or use connected health data to train AI models. The current journal helper and insights use application rules; the deployed app does not currently send journal or provider data to OpenAI or another external AI model. Nutrition and training information is not used to make medical, insurance or employment decisions.

WHOOP access and your choices

Connecting WHOOP requests read access to cycles, recovery and sleep, plus offline access so the server can refresh authorization and synchronize while the app is closed. Remy Mux does not request permission to change your WHOOP records and does not receive your WHOOP password.

You can decline authorization. In Connections, you can disconnect a source to stop future Remy Mux synchronization and remove its saved credentials. Disconnecting keeps previously imported journal history. To withdraw the provider-side authorization as well, revoke Remy Mux in the provider's connected-app settings. Use the journal deletion controls described below to remove data already stored in Remy Mux.

Storage, service providers and access

Vercel hosts the website and server functions. Supabase provides authentication, the database and private file storage. They process information needed to provide those services under their own policies. Connected providers receive authorization and synchronization requests; logging a meal does not publish it to those providers.

If you choose Google sign-in, Google processes that sign-in under its own privacy policy. Remy Mux requests basic identity access to verify the journal owner. It does not request access to your Gmail messages, Google Drive files or Google Calendar, and does not send your nutrition or training journal to Google as part of sign-in.

When access-request email delivery is enabled, Resend processes the requester's name and email, request time and a reference to the request to notify the operator at info.studio.pinball@gmail.com. Access requests are used to review interest in the app, not for marketing. Request records remain pending until reviewed; an email notification does not itself approve access.

The hosted Supabase database is in the United States. Service providers may process operational information in other locations. HTTPS protects data in transit. Access to the journal is restricted by server-side owner checks and database access policies. Saved provider credentials and private feed addresses are encrypted by the application before storage. Ordinary journal records are not end-to-end encrypted: the application's server and its authorized infrastructure administrators can access them to operate the service.

The source-code repository is public. Your journal, private imports and credentials are not published to it by the app. Remy Mux has no public journal-sharing feature. Information may also need to be disclosed when required by applicable law or to respond to a security incident.

Cookies and information on your device

Authentication cookies keep you signed in; a preference cookie remembers the sidebar state. The app does not install advertising or third-party analytics trackers. Offline meal drafts are stored in this browser's local storage. Signing out hides owner drafts in the app but does not erase those stored drafts. Clear this site's browser storage to remove them from the device.

The service worker caches a small offline page and icon. It does not cache authenticated journal pages or API responses. Exported files that you download are separate copies under your control.

Retention, export and deletion

Saved records, revisions and original imports remain until deleted; the app has no automatic age-based deletion schedule. A rolling synchronization window limits what the app requests from a source, not how long it retains previously imported records. Individual record deletions can retain revision history for correction or undo.

In Your profile, you can export journal records and revision history. The export lists original-file paths but does not include those files' contents or provider credentials. Delete all journal data removes stored journal records, revisions, original imports and saved connection credentials from the active application stores. It stops sources from repopulating the journal until explicitly reconnected.

That action does not delete your Supabase sign-in account, minimal metadata used to prevent stale writes, provider accounts, browser drafts, or copies you downloaded. The operator can remove the sign-in account separately through Supabase administration. Infrastructure logs or backup copies, if any, are subject to the service providers' retention practices; the app does not promise their immediate erasure.

Access requests and notification records are separate from the owner's nutrition journal and are not removed by its journal-deletion control. Requesters may contact the operator to request removal of their access request and sign-in account. Copies of notification emails may remain in the operator's inbox or email provider systems until separately deleted.

Contact and changes

For policy questions, access or deletion assistance, contact the Remy Mux operator at info.studio.pinball@gmail.com. Describe your request without sending passwords, API tokens or complete health exports; any additional information needed to verify or handle the request can be arranged privately.

Changes to these practices will be reflected on this page with an updated date. If the application adds external AI processing, additional data sources or broader account access, this policy should be reviewed before those features are enabled.

← Back to Remy Mux