Privacy Policy
This policy is based on the current codebase integrations. We use data to provide nutrition logging, AI meal analysis, subscriptions, reminders, and app analytics. We do not sell personal data.
1. Information We Collect
- Meal input data: typed meal text, voice recordings you submit for transcription, meal photos you capture/upload, and optional meal notes.
- Nutrition and log data: parsed nutrition values (calories/macros), meal timestamps, meal type, confidence, and related metadata.
- Profile and goal data: gender, age, height, weight, goal weight, activity level, and weekly pace entered during onboarding.
- Sensitive information classes (not collected): we do not collect data about racial or ethnic origin, sexual orientation, pregnancy or childbirth, disability, religious or philosophical beliefs, trade union membership, political opinions, genetic information, or biometric identifiers.
- Weight/calorie history: weight entries and daily calorie entries saved in app state.
- Subscription data: RevenueCat customer info, active entitlements, subscription status, expiration, restore status, and tracking-related attribution signals (for example Facebook anonymous ID when available, platform device identifiers when permitted, and raw device name). We do not send profile attributes like gender, age, height, weight, goal weight, or activity level to RevenueCat.
- Usage/analytics data: Firebase Analytics event names for screen views and selected product interaction actions (for example camera/voice/text log saved, weight inserted, premium button tap, theme changed, and theme color changed). These Firebase events are sent without profile payload fields.
- Device/identifier data: SDK-provided identifiers used for attribution and analytics, including Facebook anonymous ID, SDK-level user/account identifiers where provided by integrated SDK components, IDFV/other device identifiers when available, and IDFA only when iOS ATT authorization is granted.
- Diagnostics data: crash data and other technical diagnostic signals generated by integrated SDKs and platform services.
- Support data: messages you send through email or the support form on this site.
2. Data Stored Locally On Device
The app stores operational data in local storage (AsyncStorage), including:
- Meal logs (
@meal_logs) and related nutrition fields. - Failed background jobs for retry (
@transcription_failed_jobs,@image_processing_failed_jobs,@text_processing_failed_jobs). - Questionnaire/profile state, weight logs, calorie logs, and subscription cache via Redux persist.
- Notification preferences, reminder times, streak counters, and small UI preferences.
3. How We Use Information
- Provide meal logging and AI nutrition estimation features.
- Generate wellness insights, including Body Age, Fitness Age, Metabolic Age, and weight trajectory projections, for motivation and progress awareness; these are non-medical estimates and may change as your logs and Apple Health data change.
- Transcribe voice meal notes and analyze meal images/text.
- Provide and restore premium subscriptions.
- Run local reminders and notification workflows.
- Monitor product usage and improve app reliability.
- Respond to support and legal/data requests.
4. Third Parties and Data Sharing
We share data with service providers only as needed to operate app features:
- OpenAI API: receives meal text, audio transcription requests, and meal images for nutrition analysis.
- Firebase (Google): analytics event-name logging for screen/funnel measurement without profile payload data.
- RevenueCat: subscription entitlement and purchase status management, plus tracking-only attribution signals (for example Facebook anonymous ID, permitted device identifiers, and raw device name).
- Meta/Facebook SDK: App Events integration. Runtime auto event logging is consent-gated, and manual app logging is limited to paywall/subscription conversion events (for example
paywall_viewed,StartTrial,Subscribe, and purchase events when applicable). - Usercentrics: consent collection and preference management based on configured legal rules and regions.
- FormSubmit: support form relay on the contact page.
- Apple App Store: billing and purchase processing.
We do not sell personal data.
5. Permissions and Platform Notes
- Camera / Photos: used when you choose meal photo capture or gallery selection.
- Microphone: used when you record voice meal entries.
- Apple Health (iOS): if you connect Apple Health, the app may read VO2 max, resting heart rate, heart rate variability (SDNN), one-minute heart rate recovery, step count, walking speed, and waist circumference, depending on what you authorize and what is available in Apple Health. These data types are used to improve in-app wellness estimates such as Body Age, Fitness Age, and Metabolic Age. In the current implementation, Apple Health data is processed locally on device and is not uploaded to our servers or third-party processors.
- Notifications: used for reminders you enable.
- Location: the app does not actively request or process precise or coarse GPS location in the current implementation.
- Tracking Transparency (iOS): the app checks ATT status and may request ATT only after consent decisions are resolved and tracking is eligible for the configured Meta/Facebook service in your region.
- Advertising identifiers: iOS includes tracking usage disclosure; Facebook advertiser ID collection/tracking and RevenueCat device identifier collection are ATT-dependent on iOS. If ATT is denied, IDFA is not collected.
- Essential vs non-essential services: Usercentrics service classification is configured in our CMP setup. In the current implementation, attribution sync paths for RevenueCat/Facebook can remain operational as essential flows while non-essential analytics collection remains consent-gated.
6. App Store Privacy Label Alignment
Our App Store privacy labels are configured to match current integration behavior and bundled SDK privacy manifests:
- Data Used to Track You:
Identifiers > Device ID,Identifiers > User ID,Usage Data > Product Interaction. - Data Linked to You:
Identifiers > Device ID,Identifiers > User ID,Usage Data > Product Interaction,User Content > Photos or Videos,User Content > Audio Data, andUser Content > Other User Content. - Data Not Linked to You:
Purchases > Purchase History,Diagnostics > Crash Data, andDiagnostics > Other Diagnostic Data. - Not collected: Apple-defined sensitive information classes, precise/coarse location, and off-device Apple Health data upload.
7. Retention
- Local app data remains until you delete entries in-app, clear app data, or uninstall.
- Failed retry jobs remain locally until retried or removed.
- Provider-side retention (OpenAI/Firebase/RevenueCat/Meta) follows each provider's own policies.
8. Security
We use reasonable safeguards, including encrypted network transport (HTTPS/TLS) and controlled service access. No method of transmission or storage is 100% secure.
9. Your Choices and Rights
- You can manage permissions from iOS settings.
- You can revisit consent preferences in-app from Profile → Privacy & Consent (Usercentrics second layer), when available.
- You can remove local logs/entries in-app where available and uninstall to stop new collection.
- You can request deletion or access inquiries by email at quantumapps25@gmail.com.
For deletion requests, include enough detail for us to locate records (for example app version, platform, and approximate dates of use).
10. Children
The app is not directed to children under 13. If you believe a child provided data, contact us and we will review and delete where applicable.
11. Policy Changes
We may update this policy as features or integrations change. We will update the effective date when changes are published.
12. Contact
Mohammad Rabi
Lahore, Punjab, Pakistan
Email: quantumapps25@gmail.com
Last updated: April 26, 2026