Privacy Policy

Version date: August 12, 2026
Effective date: Upon publication in the Services

1. About This Policy

ShinYiLian Co., Ltd., referred to in this Policy as “Healthy Plate,” the “Company,” “we,” “us,” or “our,” respects your privacy. This Policy explains how we collect, process, use, retain, disclose, and protect information when you use the Healthy Plate mobile application, website, enterprise wellness programs, and related services (collectively, the “Services”), as well as the choices and rights available to you.

Our contact information is:


2. Scope of This Policy

This Policy applies to Services provided directly by us. Third-party websites, payment providers, logistics providers, app stores, and other external services may have their own privacy policies. Please review their policies when you leave our Services or interact directly with them.

Enterprise- or organization-sponsored wellness programs may also be governed by an enterprise services agreement or data processing agreement. For an individual user, an enterprise customer may receive only the account, registration, participation, completion, reward, and contact information reasonably necessary to administer the applicable program. The data boundaries for enterprise programs are described in Sections 4.2 and 6.2.


3. Information We Collect

Depending on the features you use, we may collect the following information.

3.1 Account and Basic Information

3.2 Information You Provide Directly

We do not collect heart rate, blood pressure, blood oxygen, electrocardiogram data, or other physiological measurements through the Services.

3.3 Information Generated by the Services

Based on information you provide and your use of the Services, we may generate:

These outputs are estimates and may not be accurate or suitable for medical or clinical purposes.

3.4 Information Synchronized from Apple HealthKit or Google Health Connect

When you choose to connect Apple HealthKit or Google Health Connect and grant the relevant permission, we may read only the following categories needed for user-facing features:

We do not read heart rate, blood pressure, blood oxygen, electrocardiogram data, or other physiological measurements from Apple HealthKit or Google Health Connect. We do not access a connected category until you grant the applicable permission, and you may revoke access through your device settings.

Information in this Section, and outputs derived from it, are subject to the strict purpose limitations in Section 7.

3.5 Camera, Photo, Notification, and Device Permissions

When you choose to use a feature involving the camera, photo library, notifications, or health-data synchronization, we access only the information reasonably necessary to provide that feature and only after obtaining the applicable system permission. You may change these permissions through your device settings at any time, but certain features may no longer function.

3.6 Device, Usage, and Diagnostic Information

3.7 Customer Support and Program Information


4. How We Use Information

We process information for disclosed purposes and on grounds permitted by applicable law, including to perform or prepare a contract with you, with your consent, to comply with legal obligations, to maintain security, to prevent harm or misuse, and for other purposes that applicable law permits.

4.1 Providing and Maintaining the Services

We may use information to:

4.2 Administering Enterprise Wellness Programs

We may use information to:

For an individual user, an enterprise customer may receive the user's name, employee number, necessary contact information, registration status, participation status, completion status, reward eligibility, or reward-distribution record where reasonably necessary to administer the program.

Enterprise customers do not receive an individual's meal photographs, dietary records, nutritional estimates, Healthy Asset metrics, Apple HealthKit or Google Health Connect information, sleep records, step records, activity records, or other personal wellness information. Related program outcomes may be presented only in aggregate or cohort form. This boundary may be changed for specified information and a specified purpose only where the user separately gives express consent and the disclosure is permitted by applicable law and platform policy.

4.3 Service Analytics, Improvement, and Security

We may use information to:

4.4 AI and Algorithm Improvement

We may use meal photographs, dietary records, nutritional estimates, usage information, and other feature-related information to train, test, validate, tune, and improve food-recognition, portion-estimation, recommendation, analytics, and other models or automated features used to provide and improve the Services. Depending on the nature and risk of the processing, we may apply data minimization, separation, access controls, de-identification, pseudonymization, or other appropriate safeguards.

Information synchronized from Apple HealthKit or Google Health Connect, and outputs derived from that information, are used only to provide or improve user-facing health, fitness, nutrition, or wellness-management features. They are not used to train or develop advertising, marketing, or other commercial data-mining models.

Service providers may assist us with model operation or improvement only under our instructions and appropriate confidentiality, security, and data-protection obligations.

4.5 Service Communications and Marketing

We may use account information, contact information, stated preferences, and non-health program interactions to provide product updates, program information, offers, content recommendations, marketing communications, and service personalization where permitted by law.

We do not use individual meal photographs, individual dietary records, individual nutritional estimates, or information synchronized from Apple HealthKit or Google Health Connect for targeted advertising, advertising measurement, or third-party marketing.

You may manage marketing preferences through the unsubscribe mechanism in a communication, your app settings, or by contacting us. Necessary account, security, transaction, and service notices are not affected by a marketing opt-out. When we first use personal information for direct marketing, we will provide a method to reject such marketing without charge and will bear any associated cost. After you reject direct marketing, we will stop using your personal information for that direct-marketing purpose.


5. Aggregate Statistics and Program Reporting

We may create aggregate statistics, cohort-level metrics, trends, and other outputs that do not reasonably identify a specific user for internal analytics, Service improvement, enterprise wellness-program reporting, and evaluation of program participation, completion, rewards, and overall outcomes.

Enterprise customers and program sponsors may receive only the aggregate or cohort-level reports described in this Section, together with the limited administrative information described in Sections 4.2 and 6.2. They do not receive individual meal photographs, individual dietary records, individual nutritional estimates, Healthy Asset metrics, Apple HealthKit or Google Health Connect information, or other personal wellness information.

Apple HealthKit and Google Health Connect information, and outputs derived from that information, are excluded from third-party reporting, advertising, marketing, and commercial data-mining workflows. Aggregating or de-identifying that information does not remove its original purpose restrictions.

We apply safeguards appropriate to the nature, identifiability, sensitivity, context, and re-identification risk of the information. These safeguards may include aggregation, cohorting, generalization, data separation, access controls, contractual restrictions, and review of reasonably foreseeable re-identification risks. Recipients must not attempt to identify a user from aggregate or cohort-level outputs or combine those outputs with other information for that purpose.


6. How We Disclose Information

We may disclose information to the following recipients for the purposes described in this Policy, to provide the Services, or as otherwise permitted by applicable law.

6.1 Service Providers

Service providers may include cloud-hosting, data-storage, authentication, notification, customer-support, analytics, cybersecurity, and other providers that assist us in delivering the Services. They may process information only according to our instructions and must be subject to appropriate confidentiality, security, and data-protection obligations.

6.2 Enterprise Customers and Program Sponsors

For an individual user, an enterprise customer or program sponsor may receive the name, employee number, necessary contact information, registration status, participation status, completion status, reward eligibility, or reward-distribution record where reasonably necessary to administer the program.

They do not receive an individual's meal photographs, dietary records, nutritional estimates, Healthy Asset metrics, Apple HealthKit or Google Health Connect information, sleep records, step records, activity records, or other personal wellness information. Program results may be provided only in aggregate or cohort form, except where the user separately gives express consent for specified information and a specified purpose and the disclosure is permitted by applicable law and platform policy.

6.3 Legal Requirements and Protection of Rights

We may disclose information where required by law or a valid order from a competent authority, or where reasonably necessary and legally permitted to protect the rights, safety, or property of our users, the Company, or others.

6.4 Corporate Transactions

If the Company is involved in a merger, acquisition, restructuring, financing, or transfer of assets or business, information may be disclosed or transferred to relevant transaction parties subject to appropriate safeguards and legally required notice.


7. Apple HealthKit and Google Health Connect Information

We access Apple HealthKit or Google Health Connect information only after you choose to connect the platform and grant permission for the specific categories described in Section 3.4.

We use this information, and outputs derived from it, only to provide or improve user-facing health, fitness, nutrition, or wellness-management features that directly benefit the user. We do not:

We maintain source-based access and downstream-use controls intended to keep this information separate from prohibited workflows. De-identifying or aggregating this information does not change these restrictions.

You may change or revoke access at any time through Apple Health or your Android device settings. Revocation does not affect processing that lawfully occurred before revocation. You may also request deletion under Section 10 of information retained by us that we are not legally required to keep.


8. International Data Transfers

Some cloud, analytics, notification, or technology service providers we use may operate outside Taiwan, including in the United States or other countries or regions in which a provider maintains facilities. Where information is transferred internationally, we apply safeguards required by applicable law, which may include contractual protections, access controls, encryption, and other appropriate measures.


9. Data Retention

We retain information only for as long as reasonably necessary to fulfill the stated purposes, perform contracts, resolve disputes, maintain security, and comply with law. Retention periods vary by data category:

Following account or data deletion, limited information may remain in restricted backup systems until the applicable backup-rotation cycle is completed. It will not be returned to ordinary operational use during that period.


10. Your Rights and Choices

Subject to applicable law, you may ask us to:

You may submit a request through the app settings or by emailing support@healthyplate.app. We may take reasonable steps to verify your identity. If we cannot fully comply because of a legal obligation, dispute-preservation requirement, security need, protection of another person's rights, or another lawful reason, we will explain the applicable reason.

For a request to inquire, review, or obtain a copy of personal information, we will generally make an approval or denial decision within 15 days after accepting the request. Where necessary, we may extend that period by up to an additional 15 days and will notify you in writing of the reason. For a request to supplement, correct, stop collecting, processing, or using, or delete personal information, we will generally make an approval or denial decision within 30 days after accepting the request. Where necessary, we may extend that period by up to an additional 30 days and will notify you in writing of the reason.

As permitted by Article 14 of Taiwan's Personal Data Protection Act, we may charge a fee reflecting the necessary cost of responding to a request to inquire, review, or obtain a copy. To the extent permitted by applicable law, for a request that is manifestly unfounded, repetitive, or excessive, we may ask for clarification, consolidate related requests, charge a reasonable fee, or deny the request with an explanation.

Withdrawing consent for non-essential information will not affect features that do not rely on that information. Where information is necessary for a particular feature, withholding or revoking permission may prevent that feature from functioning.


11. Security Measures

We use technical and organizational measures appropriate to the nature and risk of the information, including encryption in transit, access controls, least-privilege access, source separation, logging and monitoring, service-provider management, and incident-response procedures. No method of Internet transmission or electronic storage can be guaranteed to be completely secure.

You should safeguard your account, password, devices, and third-party-platform login information and maintain reasonable security settings. Responsibility for effects caused by your own disclosure or failure to safeguard information, or by a security incident involving a third-party platform, network, device, or provider, will be determined according to the actual cause and applicable law.

If we become aware that personal information has been stolen, altered, damaged, destroyed, lost, or disclosed without authorization, we will take containment, investigation, remediation, recordkeeping, notification, and regulatory-reporting measures as required by applicable law.


12. Minors

The Services are currently available only to individuals who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we discover an account that does not meet the age requirement, we will take appropriate steps to restrict access and delete relevant information as required by law.


13. Changes to This Policy

We may update this Policy to reflect changes to the Services, data practices, technology, legal requirements, or partnership models. We will identify the version date and effective date of an update and provide notice through the app, website, email, or another appropriate method according to the nature of the change, applicable law, and platform policy.

Where a new activity involves an additional category of sensitive information, a materially different purpose, or processing for which separate consent is required, we will provide the required notice or consent mechanism before beginning that activity. Unless applicable law requires otherwise, continued use of the Services after an update takes effect means that you acknowledge the updated Policy.


14. Governing Law and Language

This Policy is governed by and interpreted under the laws of the Republic of China (Taiwan), without prejudice to mandatory privacy, data-protection, or consumer-protection provisions that cannot lawfully be excluded.

This Policy may be made available in English and Traditional Chinese. We intend the versions to remain substantively consistent. The English version controls except where applicable law requires a local-language notice to control, including for users in Taiwan to the extent required by mandatory law.


15. Contact Us

If you have questions about this Policy, our data practices, or the exercise of your rights, please contact us: