1. The current product stage
Cost Plus PT currently provides a public product preview, an anterior-knee information checklist, account authentication, a personal-tracking interface, a personal workout log, a personal food log, and a guided-session interaction prototype. It provides self-guided movement education and personal tracking, not physical therapy, medical care, dietary advice, or nutrition counseling. No clinician, dietitian, or other professional reviews or monitors a user’s account, answers, sessions, logs, or messages, and that oversight is not planned as part of this service. Checklist results, goals, check-ins, progress entries, session responses, workout entries, and food entries are product-study and app-activity records, not a patient record, clinical record, professional assessment, or treatment decision.
2. Information we collect
Account information may include your email address, authentication identifiers, account timestamps, and a profile name you choose to add. Security systems may record login, authorization, rate-limit, device/browser, and network information needed to prevent abuse and investigate incidents.
If you submit the public anterior-knee research screen, we collect the coded answers you confirmed, the rule-based result and reason codes, your email address, the U.S. state where you are physically located, your selected recovery goal, an optional goal detail of up to 160 characters, and the versions of the screen and consent you accepted. We do not use the screen to record a diagnosis, and we do not store your raw IP address or a browser fingerprint with the research submission. Avoid adding names or unnecessary health details to the optional goal field.
If you are signed in and explicitly ask us to build a topic we have not released, we store a roadmap demand request: your account identifier, the pathway you asked for, the consent version, and timestamps — nothing about your symptoms, and no separate email address (your address already exists on the account). One standing request is kept per pathway; asking again updates it, and withdrawing it is a deletion. These requests exist only to decide what to build next and are read by the operator as counts.
The authenticated recovery preview can save a recovery episode, goal, repeatable function measure, structured assessments and confirmed summaries, consent records, assigned plan versions, symptom intensity, confidence, delayed activity response, optional short notes, check-ins, structured session responses, weekly reassessments, deterministic decision reasons, and safety or escalation records. Shared account storage is default-off while its database migration, privacy review, and operational checks are completed; until it is enabled for an account, the existing preview records remain in that browser. When shared storage is enabled, these structured records are scoped to the signed-in account in Supabase and can follow the account across supported devices. They are not represented as a clinician-reviewed clinical record or treatment decision. Avoid including names or details that are not needed for the preview.
If you use the personal workout log, we store what you type: the exercises you name, your sets, reps, percentages of a maximum you entered yourself, absolute weights, completed reps, effort ratings on the RPE or RIR scale you pick, rest-timer settings, bar and plate settings, and the workout templates you save and reuse. If you use the personal food log, we store the food you selected, the portion and quantity you chose, the date, the nutrition values our server copied from the food record at the moment you logged it, any foods you create yourself, and the calorie and macronutrient targets you type along with the date each takes effect. We do not collect body weight, height, age, sex, activity level, or a goal weight for these logs: the product has nowhere to store them and calculates no target, load, or portion from them. The searchable food catalog is public reference data from the U.S. Department of Agriculture’s FoodData Central and is not personal to you. Both logs are personal tracking, not dietary advice, nutrition counseling, exercise prescription, or a clinical record, and they are structurally separate from the educational content — nothing you log in them selects, changes, doses, or unlocks anything else in the product.
If you choose to attach a photo to a dated meal, your browser decodes the image and re-encodes it as a JPEG before upload so embedded camera metadata such as EXIF and GPS is not retained. We store the re-encoded image in private account-scoped storage along with its date and meal association, byte size, media type, and verification timestamps. We do not retain the original image bytes or original filename.
The homepage product illustration does not submit answers. The guided session can open a local camera preview after you choose to enable it. A default-off internal camera-assessment build can also process frames in the browser to check bounded visibility conditions and count broad supported sit-to-stand phases. Cost Plus PT does not retain or upload camera frames, continuous pose landmarks, raw voice, recognized transcripts, or the temporary session event trail. If the internal assessment is used, the saved structured record may include observed or user-confirmed rep counts, manual/not-observed status, bounded quality reason codes, retry count, and protocol/model/adapter versions.
3. Voice and camera
Camera and microphone permissions are denied across the site except on the focused guided-session route. Permission is still requested only after you act. The internal camera observer lazy-loads a pinned TensorFlow.js MoveNet model from Google’s TensorFlow Hub and performs inference in the browser; the model request may disclose ordinary connection information such as an IP address to that asset host, but camera frames and pose results are not sent with the request. The observer stays default-off unless a database flag and versioned technical, privacy, accessibility, and product-review references are present. It counts broad rep phases only and does not grade form, determine safety, diagnose, or infer pain. Spoken guidance uses the browser’s text-to-speech feature. Optional speech recognition may be processed by your browser or operating-system provider under its own terms; the current prototype does not send recognized transcripts to Cost Plus PT or save them.
4. How we use information
We use public checklist submissions to apply the disclosed fixed research-description rules, understand interest by broad location and goal, recruit or communicate about product research and early access when you consent, prevent duplicate submissions, and improve the checklist’s usability and boundaries. Submitting does not enroll you, establish a patient relationship, or promise clinician review. When shared storage is enabled, we use app-activity records to apply versioned deterministic display rules, maintain assigned-content history, show the reason for each display-state change, replay recorded decisions for verification, preserve uncertainty, and present stop messages. An automated or template explanation may describe a recorded rule result, but it does not select or invent that result. We use food log entries only to show you your own record, its daily and weekly totals, and the difference from targets you typed yourself. An optional meal photo is used only to display that image back to you beside that dated meal. We do not identify food from it, estimate a portion, calories, or nutrients, score or label the image or meal, make a recommendation, or use the image to change your movement guide. We use workout log entries for those same personal-record displays and to publish a limited exercise census beside account-only research documents: a census cell reports only the number of distinct accounts that recorded one of the specifically authored spellings for that exercise, and reports nothing unless at least 25 accounts are included. The census does not expose account identifiers, entries, sets, loads, dates, or sub-threshold values, and it does not rank, select, reorder, or change the exercise documents. We do not derive a recommended load, calorie target, or meal from either log. We use current account and technical information to create and secure accounts, maintain sessions, provide requested product features, prevent fraud and abuse, respond to support and privacy requests, debug failures, and meet applicable legal obligations. We do not use health-related interactions for targeted advertising.
5. Service providers and disclosure
The current architecture uses specialized providers for hosting, authentication, database infrastructure, and transactional email. They may process limited information on our behalf under their service terms. We may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.
Cost Plus PT does not sell personal information, movement information, camera content, or health information. It does not place advertising pixels or general-purpose session-replay tools inside authenticated health, camera, or voice flows.
6. Cookies
We use first-party session cookies needed for authentication and security. We do not currently use third-party advertising cookies in the authenticated product.
7. Retention
Public research-assessment submissions receive a 180-day retention deadline and are included in the scheduled deletion process after that deadline, unless a shorter or longer period is required for a verified request, security investigation, or legal obligation. Roadmap demand requests receive a 365-day retention deadline under the same scheduled deletion process, and deleting your account removes them immediately. Re-submitting the same email for the same screen version updates that record and its deadline rather than creating unlimited duplicates. Account profile information is generally retained while the account is active and removed through the account-deletion process, subject to narrow legal, security, backup, or fraud-prevention needs. Audit and security records may be retained in de-identified or access-restricted form. Device-held recovery previews remain until the browser clear control succeeds. Enabled shared recovery records remain until the recovery-record or account-deletion control succeeds, subject to the reviewed retention contract. Workout and food log entries, your own saved foods, your workout templates, and the targets you typed remain until you delete them or the account-deletion process removes them; we do not expire them on a clock, because a personal log is only useful if the history stays. A meal photo remains until you remove it or delete the account; those controls explicitly remove its private stored object as well as its metadata, subject to narrow legal, security, backup, or fraud-prevention needs. The current product does not retain raw session video, continuous pose landmarks, or raw audio.
8. Your choices and rights
You can unsubscribe from research or early-access email through the message or contact us to withdraw future contact consent. You may request access to or deletion of a public assessment submission by contacting us from the submitted email address; we will verify the request before acting. Signed-in users can correct profile information, download the server-held account export — which includes the workout and food logs with the values as they were recorded, meal-photo metadata, and not the shared public food catalog — and request account deletion from Account & security. Meal-photo image bytes are not included in the JSON or CSV export; save attached images separately from Nutrition before deleting your account if you want to keep them. The separate You page lets you download or clear the active recovery record: a device-held JSON preview while shared storage is off, or the enabled shared account record after release. If you use a shared device, sign out and clear any device-held preview when you are finished. You may also contact us about access, correction, deletion, or other rights that apply where you live.
9. Security and breaches
We use access controls, encryption in transit and at rest where supported, audit logging, security headers, rate limiting, and restricted administrative access. No system is perfectly secure. If a covered health-information breach occurs, we will investigate and provide notices required by applicable law.
10. HIPAA and other health privacy rules
A direct-to-consumer health app is not automatically covered by HIPAA. Other federal and state privacy, consumer-protection, and breach-notification laws may still apply. The FTC explains that its amended Health Breach Notification Rule reaches many health apps outside HIPAA; HHS also provides a mobile-health-app regulatory tool. See the FTC health breach guidance and HHS mobile health app resources.
11. Adults only
The current account and first proposed pathway are intended for adults 18 and older. We do not knowingly design this preview for children or knowingly collect children’s personal information through it.
12. Changes and contact
We will update this policy as the product, vendors, or legal obligations change and will revise the effective date above. Material changes will receive an appropriate notice. Contact hello@costpluspt.com or use the contact page.