Most of what you put into Percy never leaves your phone. Your blood sugar, blood pressure, cholesterol, weight, mood, meals, workouts, medication reminders and your routine are stored by the app on your own device. They are not on our server. They are not in our backups. We cannot see them, and neither can Jason.
Version PP-v3.0 · 6 September 2026 · replaces the coaching-era policy in full
Your meal photos are never stored by us — not on a server, not in a backup, not anywhere on our side. A photo is read once, in memory, and thrown away. Only the numbers come back to your phone. (It is read by one of our AI services on the way — what that means is set out under "Percy and AI" below.)
What we do hold is small: your name and email from Google sign-in, and your subscription record from Stripe. We never sell anything you put into Percy. You can ask us to delete what we hold at any time.
The rest of this page is the detail, because "trust us" is not a privacy policy.
Normal Range Club is a health-education brand and a trading name of NRC VANTAGE ENTERPRISE, a sole proprietorship registered in Malaysia (registration 202603193260), business address 12A-10 Plaza Permata, 6 Jalan Kampar, Sentul Selatan, 50400 Kuala Lumpur, Malaysia. Jason Choo is the data controller. For anything privacy-related, contact [email protected].
This policy covers the Percy app at app.normalrangeclub.com. The public website normalrangeclub.com is covered by the same policy — see "The website" below.
Before the detail, here is the whole shape of it. If you read nothing else, read this.
| Where it lives | What is there |
|---|---|
| Your phone, and only your phone | Blood sugar, blood pressure, cholesterol, weight readings. Mood. Meals and what you logged about them. Workouts and your routine. Journey notes. Medication reminders. Your Percy chat history. The numbers that come back from a photo |
| Our server | Your account: name, email, Google account reference. Whether you are on trial, subscribed, or locked. A record of which screens and actions you use, never what you typed. That is very close to all of it |
| Passes through — we keep none of it | A meal photo (in memory, seconds). A barcode's digits. Your typed question and a small context object. A grid square where you are standing |
| A payment company | Stripe holds your card and your payment record. We never see a card number |
What happens to the things in the third row once they reach our AI services is set out under "Percy and AI" below.
The app keeps these in your phone's own local storage:
None of that is sent to our server. There is no copy on our side. The Records screen — the one built for you to open at the clinic instead of carrying paperwork — reads from your phone, not from us.
One switch changes that, and it is off until you turn it on. In Me → Settings, "Let Percy's memory follow you" keeps a copy of the facts you stated to Percy — allergies, foods you don't eat, kit you own, how you work, your home area, your goal, and short day-notes like "flying tomorrow" — on your membership record on our server, so Percy picks up where you left off on a new phone. Never part of it: your readings, weight, medication reminders or your conversations. That copy is included when you ask for everything we hold, it is erased with your account, and switching it off deletes it at once.
Two consequences, and we would rather tell you than have you find out.
Why we built it this way: the safest place for your blood sugar is a place we cannot reach. A server we do not have cannot be breached, subpoenaed, or sold with the business.
(Storing this on your device is what makes the app work at all — it is the service you asked for, which is why there is no consent banner for it. Nothing we store on your device tracks you, profiles you, or is read by anyone but you.)
This is the part people ask about most, so here is the whole path.
The same path applies to a photo of a menu.
The honest limit: while the photo is in flight it passes through our network provider (Cloudflare) and it is read by one of our AI services. Each is a conduit or a reader, not a filing cabinet. Cloudflare keeps no copy. Our AI services are barred by contract from using your content to improve or train their own products, and keep requests only briefly, to police misuse of their service. See "Percy and AI" below.
If you scan a barcode, only the digits leave our server — not the photo, not your account, not anything about you. Our server looks those digits up in Open Food Facts, a free public database of food labels. The request comes from us, not from your phone, so Open Food Facts never sees your IP address or anything that identifies you. If the lookup fails, Percy just uses its own estimate.
When you type a question to Percy — and you have switched Percy's AI helper on in the app — this goes to our AI services:
What does not go: your name, your email, your account, your readings, your weight history, your medication list, your Journey diary, your photos, or your past conversations.
Anything that came back from that service is labelled in the app — the exact labelling promise is under "Percy and AI" below.
In production we do not keep your questions. There is a question log in the software for testing, and it is switched off unless a testing setting is deliberately turned on — it is off in production. If that ever changes, this sentence changes with it, before the change ships.
If you ask Percy what is nearby, your phone sends your position to us over a secure connection. Before our server does anything else with it — before any lookup, before it touches a cache, before it is logged — it is rounded to a grid square roughly 275 metres across. The precise position that arrives is never written to a log or a database, and it is never passed on. The lookup service — Google Places, or the open OpenStreetMap data — is told only the grid square, never your exact position. We keep a shared list of what is in a grid square for about ten minutes so we are not asking the same question over and over; that cache has no account, name or identifier attached to it, and your exact position never reaches it.
You can simply not use the feature. Nothing else in Percy asks for your location.
Billing, cancellation and refunds are governed by our Terms & Conditions.
Separately from anything on your phone, our server keeps a small record of how you use the app — not what you tell it.
Percy sees what you give it: the question you type, a meal or menu photo, and a small slice of context — your allergies, your food rules, the time of day. Your blood pressure, blood sugar, cholesterol and weight are never part of it.
Photos are read once and thrown away. A meal or menu photo goes to one of our AI services, is read in memory, and is never written by us to a disk, a database, a backup or a log. Only the dish names and the numbers come back, and our own server checks them before your phone shows them. Percy only needs the food — snap the plate, not the prescription, and not someone else's face.
That work is done by outside AI services we pay for. They may not use your content to improve or train their own products — that is what their business terms say, and it is why we pay for them. They keep requests briefly, only to police misuse of their service, and nothing else. They never get your name or your account. We never sell what you tell Percy, and we never hand it to advertisers. This is how Percy works for members. A small internal test build, used only by people who work on Percy, may run on different terms while a feature is being built — never the build you use.
Nothing goes to them until you switch it on. One switch in Me → Settings, and it starts off. With it off Percy still works: the built-in decision engine answers your meals, your day, your movement and your reminders on your phone, with no AI involved. The switch links to this page and to the Terms before you decide.
Two more things about the AI, because you should be able to judge it:
Anything Percy gives you that came from those services is labelled in the app — as "AI-assisted", or as read or estimated by an AI service — every time.
AI-generated movement clips. Some of the movement demonstration videos in the app were made with AI tools. They are fixed educational clips — the same file for everybody, made once, labelled in the app. Nothing about you is sent anywhere to generate them or to show them to you.
No cookies, no advertising trackers, no profiling, no cross-site tracking, no analytics service. Nothing we put on normalrangeclub.com stores anything on your device or reads anything from it — which is why there is no cookie banner.
One thing we do not control: the network provider in front of our sites (Cloudflare) asks your browser to keep a short-lived setting so that if a connection to us fails, your browser can report the failure back to Cloudflare. It is technical diagnostics about the connection, not about you, it does not identify you, and we never receive those reports or use them.
Our web server keeps a standard access log — your IP address, the time, the page you asked for, the page you came from, and your browser's description of itself. We keep it to spot attacks, fix what is broken, and count visits in total — never to build a profile of you, never for marketing, and it is never shared. It sits on our own server in Germany, rented from Hetzner, and is deleted after 30 days. Jason is the only person who reads it.
The same short access log covers the app's own requests, and we use the requesting IP address briefly to stop one person burning the service for everyone. It is not linked to your account and it is not used for anything else.
One form on the website: the free-guide request. You give an email address, we send the guide, and we keep the address only to send it and to send the weekly email if you ticked that box. You can unsubscribe from any of them in one click. We never sell or share it. The coaching application and booking forms that used to live here have been retired and no longer collect anything.
These are the companies involved in running Percy, what each one receives, and where they are. We do not add a company that touches your information without updating this page.
| Who | What they get | Where |
|---|---|---|
| Hetzner | Hosts our server — your account record, and nothing else about you | Germany (EEA) |
| Cloudflare | Sits in front of the app. Everything passes through it, including a meal photo in transit. It is a conduit, not a filing cabinet — it keeps no copy of your photos, your logs or your questions. It keeps its own short-lived technical records of each connection, for security | United States and worldwide |
| AI services — read meals and menus, write answers | Your typed question + the small context object; a meal or menu photo, read once. Paid business terms: they may not use your content to improve or train their own products. They keep requests briefly, only to police misuse. See "Percy and AI". | United States and worldwide |
| Google (Places) | A grid square roughly 275m across. No account, no identifier | United States and worldwide |
| Google (sign-in) | Confirms it is you. We get your name, email and an account reference | United States |
| Stripe | Takes the payment and holds your card details | United States and Ireland |
| Open Food Facts | Barcode digits only, asked by our server. They never see your IP address | Open public database, ODbL |
| OpenStreetMap | A grid square, as a fallback when Google is not used | Open public database |
| Resend | Sends service emails — receipts, sign-in links and welcome notices. Carries your name and email; carries no health information | United States |
| Telegram | Pings Jason's phone that something has happened. Content-free or a reference code — never what you wrote | Worldwide |
One honest limit. Jason runs the server himself, which means he can reach the account database directly, the way the person who runs any small service can. What he cannot reach is your readings, your meals, your diary or your photos — because they are not there. Nobody outside has access, and no other person or company is given a login.
Our own server is in Germany, inside the EEA, rented from Hetzner. The database is not reachable from the internet.
We back that server up every night. The backup is scrambled on our own machine before it leaves, and only then copied to Google Drive — so what Google holds is a file it cannot read. We have tested that a backup actually restores.
Because we use Cloudflare, Google and Stripe, technical data and the narrow things described above may be processed outside your country, including in the United States. Wherever your information travels, the protections described in this policy apply, and we use each provider's standard data protection terms. The thing people worry about most — your readings — does not travel at all, because it never leaves your phone. Your photos travel once, to be read, and are kept by us nowhere — what our AI services may do with them is set out under "Percy and AI".
Honest about the method: we do the deleting by hand, so treat these as the periods we work to rather than a stopwatch. If the schedule changes, we change it here.
| What | How long |
|---|---|
| Meal and menu photos | Never stored by us. Seconds in memory, then gone |
| Barcode digits | Not stored by us |
| Your typed questions to Percy | Not retained by us in production |
| Your exact location | Never sent — your phone rounds it to the grid before any request exists. The grid-square cache holds no identifier and clears in about 10 minutes |
| Everything on your phone — readings, meals, workouts, mood, diary, medication reminders, Percy chats | For as long as you keep it. We hold no copy and cannot delete it for you — clearing the app's data on your device removes it |
| Your account (name, email, Google reference) | While your account is open, then about 30 days, then deleted. One honest overlap: if you have paid us, your name, email and payment reference also sit inside the payment record below |
| Trial and subscription dates | While your account is open, then about 30 days |
| Payment and tax records | 7 years, because Malaysian tax law requires it |
| The record of what you consented to and when | 6 years, so we can always show you what you agreed to |
| Email delivery records at our email provider | 12 months |
| Website access log | 30 days |
| Automation logs | 90 days |
| What you did in the app, not what you typed — which screen you opened, which action you took, which version and when | No more than 180 days, cleared by hand for now. If you delete your account it goes then, with everything else |
| Backups | These rotate. Anything deleted is gone from the live system straight away and works its way out of the backups within about 12 months |
Wherever you live, we work to one standard. You can:
Email [email protected]. We will check it is really you, do it within 30 days, and confirm when it is done. We never charge for this and we never make it difficult.
Deleting your account is done from Settings in the app ("Delete what NRC holds"), or by that same email. When we delete your account, the record itself is removed from our database — not hidden, not flagged, removed. And because your readings, meals and diary were never on our server to begin with, most of your personal information never reached us at all: what is on your phone, you clear yourself by clearing the app's data on your device.
If you sent us a coaching application before becoming a member, that record is deleted the same way when you delete your account — only a fixed marker that an application once existed is kept, the same as for a member account.
Your local law wins if it gives you more. If you are in the UK or EU these are your rights under UK GDPR / GDPR; in Malaysia under the Personal Data Protection Act 2010 as amended in 2024; in Indonesia under Law No. 27 of 2022 on Personal Data Protection; in California under the CCPA/CPRA; and in other US states under your own state's law. Where any of those gives you more than this page does, you get the more. We do not ask anyone to accept a lower standard because of where they live.
Two honest exceptions to deletion, and they are the only two:
And a third thing that is not an exception but looks like one: we cannot delete what is on your phone, because we cannot reach it. Clear the app's data on your device and it is gone.
Complaining. In the UK, the Information Commissioner's Office (ico.org.uk). In Malaysia, the Personal Data Protection Commissioner. In the EU, your national supervisory authority. You do not have to come to us first — though we would rather you did, because we can usually fix it faster.
For readers in the UK and EU, and useful everywhere:
Nothing in Percy makes an automated decision that has a legal or similarly significant effect on you. Percy suggests; you decide.
Percy is for adults. It is not directed at anyone under 18 and we do not knowingly take anyone under 18. If we find out we have, we close the account and delete what we hold.
If something goes wrong and your information is affected, we will tell you, and we will tell the regulators the law requires us to tell — in Malaysia, the Personal Data Protection Commissioner within 72 hours of the breach; in the UK and EU, the relevant supervisory authority within 72 hours of becoming aware. We have a written response plan and we have tested our backups.
If this policy changes, we update this page and the date at the top, and we keep the old versions. If a change is material — anything about what we collect, who receives it, or what we do with it — we will tell you before it takes effect, not after. A change that would need a fresh yes from you gets a fresh yes from you. It never gets a quiet edit to this page.
Normal Range Club · a trading name of NRC VANTAGE ENTERPRISE · Malaysia registration 202603193260 · 12A-10 Plaza Permata, 6 Jalan Kampar, Sentul Selatan, 50400 Kuala Lumpur, Malaysia · [email protected]