The paperwork

Privacy
Policy.

Most of what you put into Percy never leaves your phone. Your blood sugar, blood pressure, cholesterol, weight, mood, meals, workouts, medication reminders and your routine are stored by the app on your own device. They are not on our server. They are not in our backups. We cannot see them, and neither can Jason.

What changed in v3.0: the coaching-era privacy policy is retired — this page describes the Percy app as it works today.

Version PP-v3.0 · 6 September 2026 · replaces the coaching-era policy in full

The short version

Your meal photos are never stored by us — not on a server, not in a backup, not anywhere on our side. A photo is read once, in memory, and thrown away. Only the numbers come back to your phone. (It is read by one of our AI services on the way — what that means is set out under "Percy and AI" below.)

What we do hold is small: your name and email from Google sign-in, and your subscription record from Stripe. We never sell anything you put into Percy. You can ask us to delete what we hold at any time.

The rest of this page is the detail, because "trust us" is not a privacy policy.

Who we are

Normal Range Club is a health-education brand and a trading name of NRC VANTAGE ENTERPRISE, a sole proprietorship registered in Malaysia (registration 202603193260), business address 12A-10 Plaza Permata, 6 Jalan Kampar, Sentul Selatan, 50400 Kuala Lumpur, Malaysia. Jason Choo is the data controller. For anything privacy-related, contact [email protected].

This policy covers the Percy app at app.normalrangeclub.com. The public website normalrangeclub.com is covered by the same policy — see "The website" below.

The map, in one place

Before the detail, here is the whole shape of it. If you read nothing else, read this.

Where it livesWhat is there
Your phone, and only your phoneBlood sugar, blood pressure, cholesterol, weight readings. Mood. Meals and what you logged about them. Workouts and your routine. Journey notes. Medication reminders. Your Percy chat history. The numbers that come back from a photo
Our serverYour account: name, email, Google account reference. Whether you are on trial, subscribed, or locked. A record of which screens and actions you use, never what you typed. That is very close to all of it
Passes through — we keep none of itA meal photo (in memory, seconds). A barcode's digits. Your typed question and a small context object. A grid square where you are standing
A payment companyStripe holds your card and your payment record. We never see a card number

What happens to the things in the third row once they reach our AI services is set out under "Percy and AI" below.

What stays on your phone, and what that means

The app keeps these in your phone's own local storage:

None of that is sent to our server. There is no copy on our side. The Records screen — the one built for you to open at the clinic instead of carrying paperwork — reads from your phone, not from us.

One switch changes that, and it is off until you turn it on. In Me → Settings, "Let Percy's memory follow you" keeps a copy of the facts you stated to Percy — allergies, foods you don't eat, kit you own, how you work, your home area, your goal, and short day-notes like "flying tomorrow" — on your membership record on our server, so Percy picks up where you left off on a new phone. Never part of it: your readings, weight, medication reminders or your conversations. That copy is included when you ask for everything we hold, it is erased with your account, and switching it off deletes it at once.

Two consequences, and we would rather tell you than have you find out.

Why we built it this way: the safest place for your blood sugar is a place we cannot reach. A server we do not have cannot be breached, subpoenaed, or sold with the business.

(Storing this on your device is what makes the app work at all — it is the service you asked for, which is why there is no consent banner for it. Nothing we store on your device tracks you, profiles you, or is read by anyone but you.)

Meal and menu photos — the honest detail

This is the part people ask about most, so here is the whole path.

  1. On your phone, the picture is shrunk down before it is sent. Shrinking it re-draws the image, which drops the hidden data your camera attaches — including where the photo was taken.
  2. It arrives at our server and is opened in memory. We check it really is an image, strip any metadata that survived — including GPS — and shrink it again.
  3. It is passed to one of our AI services to be read — only if you have switched Percy's AI helper on in the app (see "Percy and AI" below) — so Percy can tell you what is on the plate and roughly what is in it.
  4. It is released. The photo is never written to a disk, a database, a file store, a backup or a log — by us, at any point. There is no photo library in Percy. On our side there is nothing to leak, nothing to hand over and nothing to delete, because there is nothing there.
  5. Only the result comes back to you — the dish names and the numbers. Those live on your phone.

The same path applies to a photo of a menu.

The honest limit: while the photo is in flight it passes through our network provider (Cloudflare) and it is read by one of our AI services. Each is a conduit or a reader, not a filing cabinet. Cloudflare keeps no copy. Our AI services are barred by contract from using your content to improve or train their own products, and keep requests only briefly, to police misuse of their service. See "Percy and AI" below.

Barcodes

If you scan a barcode, only the digits leave our server — not the photo, not your account, not anything about you. Our server looks those digits up in Open Food Facts, a free public database of food labels. The request comes from us, not from your phone, so Open Food Facts never sees your IP address or anything that identifies you. If the lookup fails, Percy just uses its own estimate.

Asking Percy a question

When you type a question to Percy — and you have switched Percy's AI helper on in the app — this goes to our AI services:

What does not go: your name, your email, your account, your readings, your weight history, your medication list, your Journey diary, your photos, or your past conversations.

Anything that came back from that service is labelled in the app — the exact labelling promise is under "Percy and AI" below.

In production we do not keep your questions. There is a question log in the software for testing, and it is switched off unless a testing setting is deliberately turned on — it is off in production. If that ever changes, this sentence changes with it, before the change ships.

Finding somewhere to eat

If you ask Percy what is nearby, your phone sends your position to us over a secure connection. Before our server does anything else with it — before any lookup, before it touches a cache, before it is logged — it is rounded to a grid square roughly 275 metres across. The precise position that arrives is never written to a log or a database, and it is never passed on. The lookup service — Google Places, or the open OpenStreetMap data — is told only the grid square, never your exact position. We keep a shared list of what is in a grid square for about ten minutes so we are not asking the same question over and over; that cache has no account, name or identifier attached to it, and your exact position never reaches it.

You can simply not use the feature. Nothing else in Percy asks for your location.

Your account, and paying

Billing, cancellation and refunds are governed by our Terms & Conditions.

Whether the app is working

Separately from anything on your phone, our server keeps a small record of how you use the app — not what you tell it.

Percy and AI

Percy sees what you give it: the question you type, a meal or menu photo, and a small slice of context — your allergies, your food rules, the time of day. Your blood pressure, blood sugar, cholesterol and weight are never part of it.

Photos are read once and thrown away. A meal or menu photo goes to one of our AI services, is read in memory, and is never written by us to a disk, a database, a backup or a log. Only the dish names and the numbers come back, and our own server checks them before your phone shows them. Percy only needs the food — snap the plate, not the prescription, and not someone else's face.

That work is done by outside AI services we pay for. They may not use your content to improve or train their own products — that is what their business terms say, and it is why we pay for them. They keep requests briefly, only to police misuse of their service, and nothing else. They never get your name or your account. We never sell what you tell Percy, and we never hand it to advertisers. This is how Percy works for members. A small internal test build, used only by people who work on Percy, may run on different terms while a feature is being built — never the build you use.

Nothing goes to them until you switch it on. One switch in Me → Settings, and it starts off. With it off Percy still works: the built-in decision engine answers your meals, your day, your movement and your reminders on your phone, with no AI involved. The switch links to this page and to the Terms before you decide.

Two more things about the AI, because you should be able to judge it:

Anything Percy gives you that came from those services is labelled in the app — as "AI-assisted", or as read or estimated by an AI service — every time.

AI-generated movement clips. Some of the movement demonstration videos in the app were made with AI tools. They are fixed educational clips — the same file for everybody, made once, labelled in the app. Nothing about you is sent anywhere to generate them or to show them to you.

The website

No cookies, no advertising trackers, no profiling, no cross-site tracking, no analytics service. Nothing we put on normalrangeclub.com stores anything on your device or reads anything from it — which is why there is no cookie banner.

One thing we do not control: the network provider in front of our sites (Cloudflare) asks your browser to keep a short-lived setting so that if a connection to us fails, your browser can report the failure back to Cloudflare. It is technical diagnostics about the connection, not about you, it does not identify you, and we never receive those reports or use them.

Our web server keeps a standard access log — your IP address, the time, the page you asked for, the page you came from, and your browser's description of itself. We keep it to spot attacks, fix what is broken, and count visits in total — never to build a profile of you, never for marketing, and it is never shared. It sits on our own server in Germany, rented from Hetzner, and is deleted after 30 days. Jason is the only person who reads it.

The same short access log covers the app's own requests, and we use the requesting IP address briefly to stop one person burning the service for everyone. It is not linked to your account and it is not used for anything else.

One form on the website: the free-guide request. You give an email address, we send the guide, and we keep the address only to send it and to send the weekly email if you ticked that box. You can unsubscribe from any of them in one click. We never sell or share it. The coaching application and booking forms that used to live here have been retired and no longer collect anything.

Who else touches your information

These are the companies involved in running Percy, what each one receives, and where they are. We do not add a company that touches your information without updating this page.

WhoWhat they getWhere
HetznerHosts our server — your account record, and nothing else about youGermany (EEA)
CloudflareSits in front of the app. Everything passes through it, including a meal photo in transit. It is a conduit, not a filing cabinet — it keeps no copy of your photos, your logs or your questions. It keeps its own short-lived technical records of each connection, for securityUnited States and worldwide
AI services — read meals and menus, write answersYour typed question + the small context object; a meal or menu photo, read once. Paid business terms: they may not use your content to improve or train their own products. They keep requests briefly, only to police misuse. See "Percy and AI".United States and worldwide
Google (Places)A grid square roughly 275m across. No account, no identifierUnited States and worldwide
Google (sign-in)Confirms it is you. We get your name, email and an account referenceUnited States
StripeTakes the payment and holds your card details United States and Ireland
Open Food FactsBarcode digits only, asked by our server. They never see your IP addressOpen public database, ODbL
OpenStreetMapA grid square, as a fallback when Google is not usedOpen public database
ResendSends service emails — receipts, sign-in links and welcome notices. Carries your name and email; carries no health informationUnited States
TelegramPings Jason's phone that something has happened. Content-free or a reference code — never what you wroteWorldwide

One honest limit. Jason runs the server himself, which means he can reach the account database directly, the way the person who runs any small service can. What he cannot reach is your readings, your meals, your diary or your photos — because they are not there. Nobody outside has access, and no other person or company is given a login.

Where your information is kept, and international transfers

Our own server is in Germany, inside the EEA, rented from Hetzner. The database is not reachable from the internet.

We back that server up every night. The backup is scrambled on our own machine before it leaves, and only then copied to Google Drive — so what Google holds is a file it cannot read. We have tested that a backup actually restores.

Because we use Cloudflare, Google and Stripe, technical data and the narrow things described above may be processed outside your country, including in the United States. Wherever your information travels, the protections described in this policy apply, and we use each provider's standard data protection terms. The thing people worry about most — your readings — does not travel at all, because it never leaves your phone. Your photos travel once, to be read, and are kept by us nowhere — what our AI services may do with them is set out under "Percy and AI".

How long we keep things

Honest about the method: we do the deleting by hand, so treat these as the periods we work to rather than a stopwatch. If the schedule changes, we change it here.

WhatHow long
Meal and menu photosNever stored by us. Seconds in memory, then gone
Barcode digitsNot stored by us
Your typed questions to PercyNot retained by us in production
Your exact locationNever sent — your phone rounds it to the grid before any request exists. The grid-square cache holds no identifier and clears in about 10 minutes
Everything on your phone — readings, meals, workouts, mood, diary, medication reminders, Percy chatsFor as long as you keep it. We hold no copy and cannot delete it for you — clearing the app's data on your device removes it
Your account (name, email, Google reference)While your account is open, then about 30 days, then deleted. One honest overlap: if you have paid us, your name, email and payment reference also sit inside the payment record below
Trial and subscription datesWhile your account is open, then about 30 days
Payment and tax records7 years, because Malaysian tax law requires it
The record of what you consented to and when6 years, so we can always show you what you agreed to
Email delivery records at our email provider12 months
Website access log30 days
Automation logs90 days
What you did in the app, not what you typed — which screen you opened, which action you took, which version and whenNo more than 180 days, cleared by hand for now. If you delete your account it goes then, with everything else
BackupsThese rotate. Anything deleted is gone from the live system straight away and works its way out of the backups within about 12 months

Your rights

Wherever you live, we work to one standard. You can:

Email [email protected]. We will check it is really you, do it within 30 days, and confirm when it is done. We never charge for this and we never make it difficult.

Deleting your account is done from Settings in the app ("Delete what NRC holds"), or by that same email. When we delete your account, the record itself is removed from our database — not hidden, not flagged, removed. And because your readings, meals and diary were never on our server to begin with, most of your personal information never reached us at all: what is on your phone, you clear yourself by clearing the app's data on your device.

If you sent us a coaching application before becoming a member, that record is deleted the same way when you delete your account — only a fixed marker that an application once existed is kept, the same as for a member account.

Your local law wins if it gives you more. If you are in the UK or EU these are your rights under UK GDPR / GDPR; in Malaysia under the Personal Data Protection Act 2010 as amended in 2024; in Indonesia under Law No. 27 of 2022 on Personal Data Protection; in California under the CCPA/CPRA; and in other US states under your own state's law. Where any of those gives you more than this page does, you get the more. We do not ask anyone to accept a lower standard because of where they live.

Two honest exceptions to deletion, and they are the only two:

And a third thing that is not an exception but looks like one: we cannot delete what is on your phone, because we cannot reach it. Clear the app's data on your device and it is gone.

Complaining. In the UK, the Information Commissioner's Office (ico.org.uk). In Malaysia, the Personal Data Protection Commissioner. In the EU, your national supervisory authority. You do not have to come to us first — though we would rather you did, because we can usually fix it faster.

Why we are allowed to do any of this

For readers in the UK and EU, and useful everywhere:

Nothing in Percy makes an automated decision that has a legal or similarly significant effect on you. Percy suggests; you decide.

Children

Percy is for adults. It is not directed at anyone under 18 and we do not knowingly take anyone under 18. If we find out we have, we close the account and delete what we hold.

Data breaches

If something goes wrong and your information is affected, we will tell you, and we will tell the regulators the law requires us to tell — in Malaysia, the Personal Data Protection Commissioner within 72 hours of the breach; in the UK and EU, the relevant supervisory authority within 72 hours of becoming aware. We have a written response plan and we have tested our backups.

Changes

If this policy changes, we update this page and the date at the top, and we keep the old versions. If a change is material — anything about what we collect, who receives it, or what we do with it — we will tell you before it takes effect, not after. A change that would need a fresh yes from you gets a fresh yes from you. It never gets a quiet edit to this page.

If you share health-related details with us, we treat them as confidential — and please only share what you're comfortable with.

Normal Range Club · a trading name of NRC VANTAGE ENTERPRISE · Malaysia registration 202603193260 · 12A-10 Plaza Permata, 6 Jalan Kampar, Sentul Selatan, 50400 Kuala Lumpur, Malaysia · [email protected]