TabetAI Privacy Policy
Last updated: 19 August 2026
This policy explains what TabetAI ("the app", "we", "us") collects, how it is used, and the choices you have. Contact: support@tabetai.app.
Summary (the short version)
- Your food diary (meals, macros, exercise, weight) lives on your device. If you create an account, an encrypted-in-transit backup copy is stored with our backend so you can restore it.
- Meal photos you choose to capture are uploaded to our servers for AI analysis and stored in your account. Photos and text meal descriptions may also be used to train AI/machine-learning models and may be included in datasets that we license or sell, as described below.
- Health data from Health Connect (Android) or Apple Health (iOS) (steps, calories, exercise, body weight, body fat) is read only with your permission, used on your device only, is never uploaded to our servers, never sold, and never used to train AI. If you opt in, TabetAI can also write your finished TabetAI workouts back to Health Connect / Apple Health (off by default), and the written records also never leave your device. See "Health Connect / Apple Health" below.
- Cycle tracking (optional) stays on your device only: excluded from cloud backup and OS backups, never uploaded, never sent to AI. See "Cycle tracking" below.
- Location is optional and off by default. If you opt in, your approximate area powers nearby food suggestions and your private saved "spots". Your location is never shown to other users and never used to train AI.
- Basic (free) accounts may see rewarded ads (you choose to watch one to earn scan energy), served by Google AdMob, which uses an advertising identifier to show and measure ads. EX/Max accounts see no ads. We do not sell your identity.
What we collect and why
- Meal photos and text descriptions: used to (1) estimate nutrition with AI, (2) show your meal history, (3) share meals with groups you join, and (4) improve TabetAI, including AI training and dataset creation (see the next section). Uploaded to our backend (Supabase) and processed by Anthropic, our AI provider.
- Voice input (microphone, optional): if you use the microphone button to talk to your companion, your speech is converted to text by your device's operating-system speech service, which for some languages may process the audio on the OS vendor's own servers (e.g. Apple's or Google's) under their privacy policy. TabetAI itself does not record, store, or upload the audio; only the resulting text is used, exactly as if you had typed it. The microphone is used only while you are actively dictating, and you can deny or revoke the permission at any time; the app keeps working, you just type instead.
- Companion chat (Max): the messages you send your companion are sent through our backend to Anthropic to generate a reply. A short running summary of your chats may be kept so the companion remembers earlier conversations; you can erase it any time from Settings ("clear what she remembers"), and it is deleted when you delete your account. Chat content is used only to run the feature, not for advertising, and not included in the meal-photo datasets described below.
- Health & fitness data via Health Connect (Android) / Apple Health (iOS) (steps, active/total calories, exercise sessions, body weight, body fat): read only after you grant permission; used solely on your device to show your activity, weight and body-composition trends, and to adjust your calorie budget. If you turn on the optional workout write-back (off by default), TabetAI also writes the workouts you finish in the app to Health Connect / Apple Health under the separate "write exercise" permission; see "Health Connect / Apple Health" below for exactly what is written. Never uploaded, sold, shared, or used for AI training or marketing. This data is handled in line with Google's Health Connect permissions policy on Android and Apple's HealthKit guidelines on iOS.
- Location (optional, off by default): two separate opt-ins. (1) If you enable "Suggest things available near me", your approximate area (rounded to about 1 km) is included in that one AI request so suggestions match what's around you; it is not stored. (2) If you pin a location to a saved food "spot" or tag it to a restaurant/store, the coordinates are stored privately in your account so the app can resurface that spot when you're nearby. Spot locations are visible only to you (never to other users or groups) and are never used for advertising or AI training.
- Community sharing (optional, off by default): if you tick "Share anonymously with the community" on a saved spot, that one spot's dish name, nutrition numbers and the venue you tagged become visible to other TabetAI users near that venue, inside the app's meal-suggestion features (part of the EX tier today). Shared rows carry no name, no username, no account ID, your private note is never included, and no time finer than the month. They cannot be traced back to you or joined into a picture of what you eat. Only spots tagged to a real business can be shared, never a bare location. It is per spot, never retroactive, and you can withdraw it at any time (untick the spot in Your Spots, or Settings → "Stop sharing everything"). The row leaves other people's suggestions immediately, because we keep no separate copy of it; deleting your account removes it too. Sharing earns you nothing in the app's economy. If someone reports a shared dish as objectionable we keep a moderation record of the venue and dish name; it never names whoever shared it. If you report a dish (here or anywhere else in the app) we do record that your account made that report, so we can act on it, stop showing you that dish, and detect abuse of the reporting tools; that record is never shown to the person reported, and it is deleted with your account. Community rows are shown to people exactly as stored and are never sent to an AI model.
- Place searches: if you tag a food to a restaurant or store, your search text and approximate area are sent through our server to Google's Places service to find the place; we store the chosen place's name, address, and location with your private spot.
- Food, exercise, and weight logs: stored on your device; included in your cloud backup if you create an account.
- Account identifiers: you start with an anonymous account (a random ID). If you link an email, we store it for sign-in, backup, and recovery.
- Usernames and social features: your username, friend connections, and the meals you share into a group feed are visible to the friends/groups you choose.
- App economy and usage: energy, TabeGems, missions, streaks, and AI-usage counters, kept server-side to run the app fairly. We also record a last-active date and a per-day active marker for your account so we can measure aggregate active-user numbers (roughly how many people use the app each day and month). This is a simple activity flag, not screen-by-screen tracking of what you tap.
- Advertising (Basic tier only): when you choose to watch a rewarded ad, Google AdMob processes an advertising identifier and basic device info to serve and measure the ad. You can reset or limit this ID in your device settings. Where required (EEA/UK and some US states), an in-app consent form lets you choose between personalised and non-personalised ads. EX/Max accounts see no ads and this doesn't apply.
- Feedback and bug reports: if you send feedback or a bug report from the app, we store the message you write plus basic technical context (app version, platform, device model) to fix problems. This content is deleted when you delete your account.
- Automatic crash reports: if the app crashes, the error, its stack trace, and basic device/app info (device model, OS version, app version) are sent to Sentry, our crash-reporting provider, so we can fix the problem. Crash reports are linked only to an internal account ID (never your email or name) and never include your meals, photos, messages, or health data.
- Purchases and subscriptions: if you subscribe to a paid tier (EX or Max), the payment is handled entirely by Google Play Billing (on Android) or Apple's App Store (on iOS). We never see or store your card or bank details; we receive only your purchase and subscription status (which plan, active or expired) and use it solely to unlock the features of your tier. Cancellation and refunds are managed through Google Play or the App Store.
- Diagnostic basics: server logs (timestamps, request outcomes) to keep the service running and prevent abuse.
Meal photos: AI training and datasets
This is the part to read carefully.
By uploading a meal photo or text meal description, you grant us the right to use that content (including the full-resolution image) to:
- provide the service (nutrition analysis, your history, group sharing);
- train, fine-tune, and evaluate AI and machine-learning models, ours or those of partners we work with; and
- create, license, and sell datasets that include this content, for example food-image datasets used for research or commercial AI development.
Before including photos in datasets we apply de-identification measures: content is separated from your account identity, and we do not include your name, email, or account ID. Please avoid photographing people, documents, or other personal information along with your food; the subject of the photos should be the meal.
If you delete a photo or your account, we delete the content from the live service. Content already incorporated into trained models or datasets that have been distributed may not be retrievable; where feasible we exclude deleted content from future dataset versions and training runs.
Label scans: when you scan a packaged product's label, the two package photos and the printed nutrition numbers may be saved to a shared food library so the product can be recognized instantly next time. These entries contain no personal information and are not linked to your identity in the library. You can turn this off in Settings › Privacy, and deleting your account removes the link between you and any entries you added.
If you do not want your content used this way, note that typed and dictated meal descriptions are covered by the same licence as photos. The complete alternatives are logging meals manually (no AI), or using your own API key in Developer mode (content then goes directly from your device to Anthropic and is not stored by us).
Third parties (sub-processors)
- Anthropic: processes meal photos/descriptions to estimate nutrition, and companion-chat messages to generate replies, subject to Anthropic's terms and privacy policy.
- Supabase: hosts our database, authentication, and photo storage.
- Google Play services (Android): app distribution, Play Integrity (device/app verification), Health Connect (on-device), and Google Play Billing (payment processing for paid tiers; we receive subscription status, never payment details).
- Apple (iOS): app distribution via the App Store, and App Store payment processing for paid tiers (we receive subscription status, never payment details). Apple Health data is read on-device only and is never sent to us or to Apple by TabetAI.
- Google Maps Platform (Places API): when you search for or tag a place, your search text and approximate location are sent via our server to Google to return matching restaurants/stores, subject to Google's privacy policy. Our API key stays on the server; Google does not receive your TabetAI identity.
- Google AdMob: serves rewarded ads to Basic-tier users and measures them, using an advertising identifier, subject to Google's policies.
- Sentry (Functional Software, Inc.): receives automatic crash reports (error, stack trace, device/app info, internal account ID) to help us find and fix crashes, subject to Sentry's privacy policy.
We do not sell your identity (name, email, contact details) to anyone. Dataset licensing described above covers de-identified meal content, not your identity or your health data.
Health Connect / Apple Health
TabetAI reads the listed health data types (steps, active/total calories, exercise, body weight, and body fat), from Health Connect on Android, or from Apple Health (HealthKit) on iOS, only after you grant permission, and uses them solely to display your activity, your weight and body-composition trends, and to adjust your daily calorie budget on-device. You can revoke access at any time in Health Connect settings (Android) or in the Health app's sharing settings (iOS); the app keeps working without it. This health data is never transferred off your device by TabetAI and is never used for advertising, AI training, or data sales.
Writing workouts (optional, off by default). If you turn on "Save workouts to Health Connect" in Settings, TabetAI writes each workout you finish in its Training feature to Health Connect (on iOS, to Apple Health): the activity type, start and end time, and the session name, and on iOS only, the session's estimated calories. This requires the separate "write exercise" permission, which you can revoke at any time; the toggle can be turned off at any time in Settings. Written records live in your on-device health store under your control. TabetAI never reads its own written records back (they are filtered out of everything the app computes from health data), and, like all health data, they are never transferred off your device by TabetAI.
Cycle tracking
If you turn on the optional cycle (period) tracking, that data (logged periods, predictions, and any symptoms you record) is stored only on your device. It is excluded from TabetAI's cloud backup and from the operating system's backup mechanisms by design, it is never uploaded to our servers, never included in anything sent to our AI provider, and never used for advertising, training, or data sales. Deleting the app (or turning the feature off and clearing its data in Settings) removes it. Because it never leaves the device, we could not access, disclose, or sell it even if asked.
Location and places
TabetAI never collects location in the background and never without an explicit opt-in. The app holds only the "approximate location" permission. Nearby-suggestion requests use your area rounded to about 1 km and are not stored. Saved-spot locations are stored in your private account data, shown only to you, and deleted when you remove the spot or delete your account. You can revoke the location permission at any time in your device settings; every feature keeps working without it.
Storage, security, and retention
Data in transit is encrypted (TLS). Photos are stored in a private bucket readable by your account (and, for small shared thumbnails, by group members you share with). Backups and server data are retained while your account is active. Local data stays on your device until you delete the app or clear it.
Your choices and rights
- Delete a meal/photo: removes it from your device, backup, and group feeds (subject to the dataset caveat above).
- Delete your account: Settings → Account → Delete account removes your cloud data (account, backup, photos, wallet, social links). Local data on your device is untouched until you uninstall.
- Revoke health-data access: via Health Connect settings on Android, or the Health app's sharing settings on iOS.
- Export your data: Settings → Export my data gives you a file of your meals, exercises, weights and settings (photos not included), any time, without asking us. The cycle log exports separately, straight to your device's share sheet; it never passes through our servers.
- Data requests: email support@tabetai.app to access or delete your data, or with any privacy question.
Children
TabetAI is not directed at children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect their data.
Changes
We may update this policy as the app evolves. Material changes will be announced in-app, and continued use after the effective date means you accept the updated policy.