Updated 2026-08. HepaPal is a non-medical drinking-habit tracker with Heppa the liver companion. It does not provide medical advice, diagnosis, or treatment and never encourages drinking.
Only what you provide: daily logs (date, status, optional amount and note), optional nickname and preferences, plus a pseudonymous identifier used to keep accounts separate. If you choose email or Apple sign-in, we store the corresponding email or Apple account identifier. For Sign in with Apple, we securely retain an encrypted refresh token so your authorization can be revoked if you delete the account. For subscriptions, we process subscription status supplied by Apple and RevenueCat. We do not collect location history, health records, or advertising identifiers.
Only to show your records, trends, gentle feedback, cross-device sign-in, and subscription access. No ads, profiling, medical analysis, or data sales.
Infrastructure processors are Supabase (database), Render (hosting), Resend (only to send a sign-in email you request), RevenueCat (subscription status), and Apple (sign-in and subscriptions). When used inside ChatGPT, conversation handling is governed by OpenAI's policies.
HepaPal data is kept until you delete it. In-app “Delete HepaPal account and data” requests revocation of a saved Sign in with Apple authorization, then removes the account, records, profile, reminders, sign-in links, tokens, and our subscription-entitlement mirror; infrastructure backups roll off on provider schedules. If an older account has no revocation token, HepaPal deletion still completes and Apple access can be removed in Apple Account settings. Deleting HepaPal data does not cancel an Apple subscription, and Apple retains its own transaction records.
At any time you can view and edit records, delete a day, export everything free (JSON), or delete your account and data in My HepaPal → Data & privacy. Contact: support@hepapal.net.