CalorieSnap Privacy Policy
Last updated: September 6, 2026
CalorieSnap is operated by Reymans Technologies LLC.
What CalorieSnap collects
- Before public launch, the website collected waitlist email addresses, consent text and version, signup time, and browser user agent. The public website no longer accepts waitlist signups.
- Account email and password hash. If you use Sign in with Apple or Google where offered, the provider's sign-in identifier instead
- Profile data such as height, weight, age, gender, activity level, goal, language, bedtime, and report preferences
- Your optional Nutrition Focus preference, including the watch areas you choose during personalization (for example, less added sugar or sodium awareness). CalorieSnap treats it as a general-wellness preference, not a medical condition, and uses it to shape in-app nutrition guidance.
- Food or Nutrition Facts label photos you choose from the camera or photo library for AI estimation or transcription
- Meal records, estimated calories, macros, portions, and correction history
- Apple Health data you choose to share, synced to your CalorieSnap account as summary values: steps, active energy (estimated calories burned), exercise minutes, workouts (count, minutes, and calories), heart rate (daily average and resting), sleep totals, and weight. Active energy includes hourly totals and the identifiers of contributing Health sources so CalorieSnap can compare the same time window and avoid duplicate sources. CalorieSnap reads only the categories you allow in the Health app, never adds, changes, or deletes Apple Health data, and does not upload individual Health samples or sample identifiers; those stay on your device.
- Manual workout/activity, hydration, and weight entries
- Daily journal signals such as hunger, energy, mood, sleep quality, stress, and notes
- Optional medication timing and check-in information if you choose to use metabolic-care tracking
- Historical Friends & Challenges records from earlier app versions if your account used those retired features. The current app does not collect new friend requests, challenges, or streak-sharing activity. CalorieSnap does not access your device contacts or address book.
- Coach messages you enter and the relevant profile and diary context used to answer them, including calorie and macro targets, logged meals, activity, sleep, and weight when available
- Stable food, schedule, budget, cooking, wellness, or coaching-style preferences that you explicitly ask the coach to remember. Coach memory is designed for preferences, not diagnoses, symptoms, medications, test results, pregnancy, allergies, or other medical facts. Do not use Coach memory as a medical record or ask it to retain sensitive health information.
- Feedback category, message, app surface, reason, and any optional 1 to 5 ratings you submit in an in-app report. Basic app, build, platform, operating-system, and Help-screen diagnostics are included only if you opt in, and are stored with your account so we can respond to the report.
- Food-search terms you enter when looking up a meal or ingredient
- Optional voice recordings when you use coach dictation or voice activity logging. The CalorieSnap server processes the recording for transcription and does not retain the raw audio after the request.
- A device-scoped Expo push token when you enable remote reminders
- Your network address for short-lived abuse-prevention rate limits. The current per-address limits expire within one hour.
- Crash and performance diagnostics (app version, OS version, device type, and a stack trace), plus categorical product-event breadcrumbs (for example app open or account creation method), sent via Sentry only with a crash or performance report. Sentry is configured without default PII collection.
- Categorical product analytics events (for example app open, account creation method, meal logged, and subscription funnel steps), app version and build, and SDK-generated random installation and session identifiers sent via PostHog. CalorieSnap does not send a CalorieSnap account identifier, meal photos, food names, health samples, email, receipts, or device installation identifiers to PostHog.
- Subscription status, App Store purchase history and receipt data, and the internal account identifier used to keep RevenueCat records separated by CalorieSnap account
- Apple Ads attribution data, such as campaign, ad group, keyword, and impression or click details, when Apple reports that information
How data is used
- Documenting any App Store launch notice requested before public launch
- Estimating food calories and macros, and recording corrections you choose to save
- Calculating daily calorie targets and showing daily and bedtime balance reports
- Estimating calorie burn and bedtime balance by comparing the active energy you share with your usual same-time activity pattern, while preventing duplicate Health sources
- Showing the heart rate, sleep, and weight trends you allow in your daily reports and progress views
- Tailoring Coach and Meal Review nutrition guidance to your optional Nutrition Focus preference
- Powering coach answers and proactive reminders with your own numbers
- Personalizing coach answers with the relevant preferences you explicitly asked the coach to remember
- Turning optional coach dictation into an editable transcript before you choose whether to send it
- Sending reminders you control from the app's settings
- Maintaining account access, validating subscription status, and diagnosing differences between Apple purchase state and CalorieSnap access
- Reviewing and resolving feedback you choose to submit
- Measuring which Apple Ads campaigns lead to CalorieSnap accounts and subscriptions
- Understanding which product flows people complete, using categorical analytics events only
Health and nutrition notice
AI processing and your permission
In app versions that include these permissions, CalorieSnap asks when you first use each AI feature. Before a meal or label photo is sent, the app asks whether to Analyze this photo and identifies the photo data, recipients, and purpose. Choosing Not now keeps the photo on your device and leaves manual meal logging available. Before Coach, insights, or voice processing sends data, the app separately asks whether to Use Coach and voice and identifies the messages, audio, account context, recipients, and purposes. Choosing Not now leaves manual meal and activity logging available.
You can change either permission at any time under Profile → Privacy & data, using the separate AI meal scanning and AI Coach and voice controls. Turning a permission off immediately blocks that feature's AI requests from the consent-capable app. Turning off Coach and voice also disables pending AI-generated coach notifications. For a signed-in account, any withdrawal also revokes the older broad AI permission so an earlier app version cannot bypass the newer choice.
Version 1.4.0 was released before this permission control. During a temporary compatibility period, an untouched version 1.4.0 installation or signed-in account that has never recorded an AI-processing choice may continue using its existing AI features without the new choice. Those requests may send the same data categories to the same providers for the same purposes described below. This compatibility ends only after a consent-capable version is publicly available and adoption is verified.
When permission is on, CalorieSnap collects AI inputs directly from what you photograph, type, or dictate in the app. For coach replies, insights, and optional coach notifications, CalorieSnap also selects relevant information already in your account, such as calorie and macro targets, logged meals, activity, sleep, weight, and explicit coach preferences. The app sends only the input and context needed for the requested feature.
Depending on provider availability, those inputs may be processed by Anthropic, OpenAI, xAI, or Google Gemini. They are used to generate meal estimates, label transcriptions, voice transcriptions, coach replies, weekly insights, or optional coach notification text. CalorieSnap does not authorize these providers to sell the inputs, use them for advertising, or use them for an unrelated purpose. CalorieSnap uses business or API services and remains responsible for requiring privacy protections through the applicable provider terms and data-processing commitments. Provider information is available from Anthropic, OpenAI, xAI, and Google Gemini.
Third-party assistant connections
If you choose to connect CalorieSnap to a third-party assistant, CalorieSnap sends only the nutrition information requested through that connection. This may include meal names and types, calorie estimate ranges, available macro values, saved calorie or macro targets, frequently logged foods, recipe summaries, counts, and calendar dates. The connection is read-only and does not send meal photos, account or record identifiers, Apple Health data, activity, weight, medications, coach history, social data, authentication tokens, or billing information. The assistant provider processes the returned nutrition information under its own terms and privacy policy. You approve the connection in the signed-in CalorieSnap app and can disconnect it at any time under Apps & Health.
Third-party services
Food photos, label photos, typed or dictated meal descriptions, coach conversations, voice activity recordings, and relevant coach context are processed either after the applicable feature permission in a consent-capable app version or, during the temporary compatibility period, through the bounded untouched version 1.4.0 path described above. Anthropic, OpenAI, xAI, or Google Gemini may receive those inputs, depending on configuration and provider availability, solely to produce the requested AI output. Food-search terms and barcode lookups may be sent to Open Food Facts, USDA FoodData Central, or Nutritionix to return matching foods. We do not sell your data.
Optional coach dictation audio and voice activity recordings are sent to OpenAI solely to produce a transcript and, for voice activity, an editable activity estimate. The CalorieSnap server does not retain the raw recording after the request. A coach transcript remains editable and is stored as part of your coach conversation only if you choose to send it.
To keep the app stable, CalorieSnap uses Sentry for crash and performance reporting. When the app unexpectedly crashes or runs slowly, Sentry receives technical diagnostic data such as app version, OS version, device type, a stack trace, and recent categorical product-event breadcrumbs, such as app open or account creation method, used to diagnose the failure. Those breadcrumbs exclude meal categories and other meal details. CalorieSnap configures Sentry without default PII collection and does not intentionally send a CalorieSnap account identifier, meal photos or descriptions, health values, email addresses, authentication tokens, receipts, or device installation identifiers to Sentry. CalorieSnap does not use Sentry to track you across other apps or for advertising. Sentry is a subprocessor based in the United States; see its policy at sentry.io/privacy.
If you explicitly opt in, CalorieSnap uses PostHog for product analytics. PostHog is a US analytics processor and receives categorical product events such as app open, account creation method, onboarding completion, meal scan outcome, meal logged, and subscription funnel steps, along with app version and build and SDK-generated random installation and session identifiers. CalorieSnap does not send a CalorieSnap account identifier, meal photos, food names, health samples, email, receipts, or device installation identifiers to PostHog. Device model, operating system, locale, timezone, screen dimensions, GeoIP enrichment, session replay, lifecycle autocapture, surveys, and error autocapture are excluded or disabled. You can withdraw consent at any time from Privacy & data in the app, including from Profile. Withdrawal stops new capture. CalorieSnap also asks the on-device PostHog SDK to discard pending events before analytics can be enabled again. See its policy at posthog.com/privacy.
On iOS, CalorieSnap uses RevenueCat as a subscription-validation and analytics processor. RevenueCat receives an internal CalorieSnap account identifier and App Store purchase and subscription history, including receipt data, so it can validate purchases and report subscription diagnostics. RevenueCat does not decide whether an account has access; the CalorieSnap server remains authoritative. CalorieSnap does not send meal photos, food details, health samples, coach conversations, email addresses, or authentication tokens to RevenueCat. See its policy at revenuecat.com/privacy.
On iOS, CalorieSnap uses Apple's AdServices attribution token to determine whether an account came from an Apple Ads campaign. The token is stored only as a cryptographic hash. Apple may return campaign, ad group, keyword, placement, and impression or click details, which CalorieSnap links to the account for campaign analytics. CalorieSnap does not use this data for cross-app tracking and does not serve third-party ads.
When you enable remote reminders, CalorieSnap uses the Expo push service to deliver notifications through Apple Push Notification service. Expo receives the device-scoped push token and the notification content needed for delivery.
Data retention
Account-linked data is retained while your account is active so CalorieSnap can provide your history and requested features. CalorieSnap does not set a separate fixed expiration period for active account records. Raw coach dictation audio is processed in memory and is not retained by CalorieSnap. Account deletion removes the CalorieSnap records listed below.
Installation-linked product analytics are retained for 12 months under the CalorieSnap PostHog project's current event-retention setting. Apple classifies these events as linked through a random installation identifier, not through a CalorieSnap account identifier. Because the events do not contain that account identifier, in-app account deletion cannot locate them and they are not part of the account record removed by that control.
RevenueCat retains purchase and subscription records under its privacy and legal-retention terms. In-app account deletion detaches the app from the former RevenueCat customer identity but does not delete Apple's purchase history. Contact support@mycaloriesnap.com if you also want CalorieSnap to request deletion of the associated RevenueCat customer record where deletion is permitted.
Historical website waitlist records are retained only until launch communications conclude or you request removal, whichever comes first. The public website no longer accepts waitlist signups. Email support@mycaloriesnap.com from the address originally submitted to have that record removed.
Historical Friends & Challenges database rows from builds that predated removal remain only for profile export and account deletion. The current app does not add new friend or challenge activity.
Data deletion
You can delete your account from the app (Profile → Privacy & data). Self-service deletion removes the account, profile, meals, meal photos, activity records, steps, synced Apple Health summaries, weight entries, hydration logs, journal entries, medication logs, connected-device records, daily reports, coach conversations, coach memory, historical Friends & Challenges records, feedback reports, push devices, refresh tokens, subscription state, and Apple Ads attribution records from CalorieSnap. App Store server-notification audit rows are retained only without any link to the deleted account. Apple manages subscription billing and purchase history separately. Deleting a CalorieSnap account does not cancel an Apple subscription or remove Apple's transaction records.
Removal of a historical waitlist record is separate from in-app account deletion. Send the request from the email address originally submitted to support@mycaloriesnap.com.
Contact
Reymans Technologies LLC handles CalorieSnap privacy requests. Questions, access requests, or deletion help: support@mycaloriesnap.com