Privacy policy
Effective 5 August 2026
Summary
ParseNutrition is a calorie and diet tracker. What you eat and what you weigh is sensitive information, and this page explains exactly what we do with it. In plain English: your logs are written to your phone first. Optional account sync is configured for an EU data region. Your health data is never sold or used for ad targeting, and deletion controls are available at any time. Optional AI tools send only the meal, label, or recipe photo, or pasted recipe text, that an adult explicitly submits after turning the feature on.
1. Who we are
ParseNutrition is developed and operated by Lucas Ekström, Sweden, who is the data controller for the processing described on this page. For any privacy question or request, write to support@parsenutrition.com. This address is the official contact for data protection matters.
2. What data the app handles
To count calories and adapt your targets, the app needs to know some things about you and your days. The categories it may collect are:
- Account data: your email address, display name, and sign-in method when you create an account for sync and backup.
- Support and request correspondence: when you email us for early access, support, privacy, deletion, portability, or refund help, we receive your sender address, name if supplied, subject, message body, attachments you choose, and normal email-routing metadata. We use only the account email or identifiers needed to answer or verify the request. Never send a password, payment-card details, or unrelated health information or photos.
- Body profile: birth year or age, biological sex, height, weight history and goal weight, activity level, pregnancy or breastfeeding status and due date when relevant, your chosen diet preset, and optional body-composition measurements such as waist, neck, hip, estimated body fat, and derived FFMI. Height, weight, activity, and goal inputs can be used to compute and adapt calorie and macro targets. Body-fat and FFMI are informational estimates and do not silently change those targets.
- Food diary: meals, logged foods and portions, custom foods you create, recipes, and daily calorie and macro totals.
- Activity and fasting: workouts you log from the activity library (type, intensity, duration), fasting sessions and schedules, and water intake.
- AI inputs (AI tier only): meal, nutrition-label, and recipe photos, plus recipe text you paste, when you actively submit them for an estimate. Our Cloud Function does not persist these inputs, but the AI provider may retain them under its terms — see section 7.
- AI usage accounting: the month, number of AI requests, and remaining allowance associated with your account. This enforces the plan limit and helps prevent abuse. We do not put photo contents, recipe text, food names, or barcodes in that usage record.
- Preferences: units, theme, meal structure, notification settings, and your consent choices.
- Optional usage analytics: only after you turn on the separate analytics switch, Google Firebase Analytics receives a pseudonymous Analytics app-instance identifier; coarse app actions such as setup progress, a saved food entry and its broad logging method, an AI attempt/result, and paywall, checkout, or restore steps; and basic technical context such as app version, device category and model, operating-system version, language, session timing, acquisition source, and IP-derived country or region. We never send food or search text, diary or nutrition values, weight or body measurements, health conditions, photos, email, account ID, barcodes, notes, or raw error text.
- Advertising data for eligible free users: Google Mobile Ads may process an IP-derived approximate location, ad views and interactions, diagnostics, and a device or other identifier such as App Set ID for advertising, analytics, and fraud prevention or security. ParseNutrition permanently removes the Android Advertising ID permission and does not collect the Advertising ID.
- Purchase state: if a Google Play offer is available and you use it, the product purchased, its entitlement status, and the remaining AI scan allowance.
- Diagnostics: crash reports and technical logs. These are configured and scrubbed to exclude account details and health or food content such as weight, calorie totals, food names, barcodes, and photos.
The app does not collect your contacts, precise location, or microphone. The camera is used only for barcode scanning and, if you enable it, AI photo scans — frames are processed for those purposes and nothing is captured in the background.
3. Offline-first: data on your device
Every log is written to a local database on your phone first, so the app works fully without an internet connection. Your device copy is kept until you uninstall the app, clear its storage, or use Settings → Account & data → Delete all local data. Deleting an account removes its cloud copy but deliberately leaves this local copy in place unless you delete it separately.
A local wipe can retain one minimal, local-only consent-withdrawal receipt: the Firebase account identifier, revoked state and server epoch, plus a random request identifier and request time while delivery is pending. It is used only to keep processing off and retry the same withdrawal after an offline restart. It contains no diary, food, weight, body, or photo content. It is removed after confirmed account deletion; uninstalling the app or clearing app storage also removes it.
4. Sync and backup (Firebase, EU region)
When production sync is available and you sign in, the app can mirror your data to Google Firebase (Authentication and Cloud Firestore) for account backup and restore. The repository configures the database and server functions for the European Union region europe-west1 (Belgium); deployment readiness is checked separately before release. Each user's data is scoped under their own identifier. We do not sell your data or use your account, body profile, diary, food searches, weight, fasting, pregnancy, breastfeeding, or other health data for advertising or retargeting. The limited ad-related data described in Section 6 may be processed by Google for the purposes stated there.
Before sign-in, the production app initializes Firebase App Check and reads non-personal feature configuration. Google may create a Firebase installation identifier and process a Play Integrity attestation token, device and app-integrity signals, IP address, and request metadata for security, abuse prevention, and safe rollout controls. This traffic does not include your diary, body profile, health metrics, or AI inputs.
5. Food database lookups (Open Food Facts)
General food search runs against a curated database that ships inside the app and never touches the network. A barcode lookup can query the Open Food Facts API with the barcode. Remote Store search sends the text you choose to search for and language preferences derived from the app locale to Open Food Facts' Search-a-licious API using an HTTPS POST. It does not send a country parameter. Requests identify the app through ParseNutrition's public User-Agent and reveal your IP address to Open Food Facts, a French non-profit. No account data, body profile, health metrics, or diary content is included. Products you select are cached on your device so repeat use works offline. Open Food Facts may retain and use request IPs for security, technical analysis, and popularity or usage statistics under its own privacy terms. When a request does not include a country parameter, it may also infer your approximate country from the IP address.
6. Advertising and independent consent choices
The 1.0.0+40 production candidate includes Google Mobile Ads and Google's User Messaging Platform (UMP). Eligible free users may see one fixed, clearly labeled banner at the bottom of the Diary screen. ParseNutrition does not use app-open, interstitial, rewarded, or native ads. Signed-out local use is free and may be ad-supported after UMP permits requests and every remote/runtime gate passes; signing in does not itself remove ads, while an active monthly/yearly subscription or historical lifetime ad-free entitlement does. An unresolved sign-in transition, a Firebase anonymous identity, or unknown or stale signed-in purchase, restore, or entitlement state remains fail-closed, so no ad is requested.
Where required, UMP asks for your advertising privacy choice before an ad request. When UMP requires it, you can review or change that choice at Settings → Ad privacy choices. Advertising privacy is independent from health-data consent and AI consent: changing one does not grant or withdraw either of the others. Withdrawing or changing an advertising choice stops or limits later ad processing according to the choice and applicable law.
Google's European regulations message uses the IAB Europe Transparency and Consent Framework (TCF) to communicate your choices through TCF consent signals, including the TCF string, and presents the current advertising-partner list and processing purposes. The current configured partner set contains Google Advertising Products only; automatic inclusion of common or mediation partners is disabled. If that partner set or its purposes change, we must review this policy and the message configuration and re-prompt affected users where the change or applicable law requires it.
For eligible ad requests, Google may process your IP address and derive
approximate location, record ad views or interactions and diagnostics,
and use a device or other identifier such as App Set ID. These categories
may be collected and shared with Google for advertising, analytics, and
fraud prevention or security. The merged Android app permanently removes
com.google.android.gms.permission.AD_ID; ParseNutrition does
not collect the Advertising ID. No food log, search, weight, body metric,
fasting record, pregnancy or breastfeeding status, account profile, or
other health data is supplied as an ad keyword, targeting signal, or
content URL. Ad requests use a G-rated maximum content setting.
7. AI meal, label, and recipe input (AI tier, 18+)
AI scanning is optional and available only to supported adult accounts that give a separate, explicit consent before the first scan. Access may come from a limited signup allowance or a Google Play offer when one is active. Nothing is sent anywhere until adult eligibility and consent are recorded.
When you submit a photo of a meal, a recipe, or a nutrition label, or paste recipe text, that input travels from your phone to our Cloud Function (configured for europe-west1) and from there to Anthropic, the provider of the Claude AI model, in the United States. Anthropic returns an estimated calorie and macro breakdown. Our Cloud Function handles the input in memory and does not persist it. The returned estimate is saved in your diary like any other entry and is always editable — treat it as a fast starting point, not a measurement.
Anthropic may retain submitted photos or text under its provider terms, including for safety, abuse detection, or legal obligations. Unless a verified zero-data-retention arrangement applies to the production account, these inputs are not treated as ephemeral in our Google Play disclosure. Avoid including people, documents, or anything private in a photo, and remove unrelated personal details from recipe text before submitting it.
8. Purchases (Google Play and RevenueCat)
When a purchase offer is active, it is sold through Google Play, which handles billing; we never see your card details. RevenueCat then processes the purchase token and subscription status so the app can show the corresponding entitlement. RevenueCat is activated when you open Plans, restore purchases, or when the app has a local record that this device previously used a paid entitlement; it is not contacted merely because a non-buyer launches or signs in to the app. To link purchase state to your account, RevenueCat may receive your account identifier and email address as a subscriber attribute. We may store the entitlement state and remaining scan allowance on your account. An offer shown in app code is not a promise that Google Play has made it available in your country.
9. Diagnostics and optional usage analytics
Required crash reporting uses Sentry and has no in-app opt-out. Reports contain technical information such as the device model, OS version, and stack traces. Performance tracing and product-interaction breadcrumbs are disabled, and reports are scrubbed before sending to remove account, health, and food content. Our retention policy caps reports at 90 days; verification that the production Sentry setting enforces that cap is a release gate.
Product analytics is separate and optional. On first use it starts off, and native Analytics collection and storage default to denied before app code runs. No product event is sent until you enable Share limited usage analytics; on later launches the app reapplies a current saved choice. Event-level data is pseudonymous while it carries the app-instance identifier; it is not anonymous. You can change that choice at any time under Settings → Account & data, including from the restricted privacy screen. Turning it off stops future collection and asks Firebase Analytics to reset its identifier and local Analytics data on that device. Small local-only markers recording whether a one-time milestone was already sent, and the last logging day sent, remain only to prevent duplicate events if you opt in again; they contain no food, nutrition, body, or account content and are removed by Delete all local data, uninstall, or clearing app storage. Turning analytics off does not delete events already received by Google; those remain subject to the retention period below. The choice does not change health-data, AI, or advertising consent. Analytics is not linked to your ParseNutrition account, and we do not set a Firebase Analytics user ID or use these events for health-based advertising or remarketing. Server-side AI quota counting remains separate operational activity whether or not optional analytics is enabled.
10. Legal bases for processing (EU / UK users)
- Contract: to run the tracker, sync your account, verify purchases, and provide support.
- Explicit consent for health data (Article 9(2)(a) GDPR): what you eat, what you weigh, your body metrics, and your fasting pattern are health data. We process them only with the explicit consent you give in a dedicated onboarding step, separate from accepting the terms. We record the consent timestamp and policy version, and existing users are asked again before continuing when a new health-consent policy version requires re-consent. You can withdraw at any time in Settings → Account & data → Withdraw health-data consent. Active tracker processing stops immediately and the restricted screen keeps only data-rights, account, support, and legal paths available. Your existing data is retained so you can export or delete it; a signed-in cloud copy remains until you delete the account or request deletion.
- Consent (Article 6(1)(a), and Article 9(2)(a) where a coarse feature-use event can reveal use of a nutrition or health feature): for optional usage analytics, optional AI input (with the additional 18+ confirmation), and advertising uses where applicable law or UMP requires it. Analytics starts off and has its own affirmative switch; it is not bundled with the separate consent required to operate the tracker. Analytics, advertising, health-data, and AI choices are independent. Required scrubbed crash reporting is handled under legitimate interest, not consent.
- Legitimate interest: keeping the service reliable and secure (scrubbed crash reporting, server logs, abuse prevention, rate limiting, and verifying purchases against fraud).
- Legal obligation: where retention or disclosure is required by law, such as bookkeeping records.
11. How long we keep data
- Local device data: until you uninstall the app or clear its storage, or use Settings → Account & data → Delete all local data. Account deletion keeps this local copy unless you erase it separately. The minimal local-only withdrawal receipt described above may remain solely to enforce or deliver a consent revocation. Delete all local data also removes the optional analytics choice and local event markers and resets Analytics on that device.
- Synced account data (profile, diary, recipes, metrics, fasting, and account-scoped health/AI consents): kept while your account is active, deleted within 30 days of account deletion. The device-level analytics choice and Analytics events are not part of that account record.
- AI usage accounting: monthly request counts and the remaining allowance are kept with your account while it is active and deleted through the same account-deletion process.
- AI photos and pasted recipe text: not persisted by our Cloud Function, but Anthropic may retain inputs under its provider terms. They are not described as ephemeral unless zero-data-retention is verified for the production account.
- Deletion marker: after account deletion we keep a minimal record of your account identifier and deletion time, so late billing events and sync attempts for the deleted account are safely rejected.
- Billing and tax records: kept by Google Play, RevenueCat, and our bookkeeping for up to 7 years where Swedish accounting law requires it.
- Diagnostic logs: our policy cap is 90 days; production provider enforcement is verified before release.
- Optional usage analytics: Firebase Analytics event-level data is limited by policy to 2 months. Verifying that the production Analytics property enforces that period is a release gate. Google may retain aggregate reports that no longer identify an individual app instance. Turning analytics off resets the identifier and locally stored analytics data on that device, but does not erase previously received event-level data before its retention period ends.
- Support and rights-request correspondence: kept while the request is open and for up to 12 months after it is closed, to handle follow-up and document the resolution. We delete it sooner where appropriate, or keep it longer only when a legal obligation or active dispute requires that.
12. International data transfers
Your synced data lives in the EU (europe-west1). Some providers process data in the United States or other countries: RevenueCat (subscription status), Anthropic (AI scans, only if you use them), Google Firebase Analytics (only after the separate opt-in), Google Mobile Ads and UMP (eligible free-tier advertising and privacy choices), and parts of Google's global infrastructure for sign-in and billing. For each, we rely on the provider's data-processing terms and transfer safeguards, including the European Commission Standard Contractual Clauses and adequacy decisions such as the EU-US Data Privacy Framework where the provider relies on one. The full processor list is on the GDPR rights page.
Email to support@parsenutrition.com is routed through Porkbun email forwarding to a monitored Google Gmail inbox. Porkbun and Google therefore process the sender address, message content, attachments, and routing metadata needed to deliver and retain the correspondence. Their infrastructure may process data outside the EEA under their applicable data-processing terms and transfer safeguards; the private destination address is not published.
13. Security
Sign-in uses Google's authentication system. All traffic is encrypted in transit, cloud data is access-controlled per user, and our server functions verify app integrity and a valid session before accepting requests. Feature entitlements are verified server-side, so a modified client cannot read another user's data. No online service can promise perfect security; keep your sign-in credentials private and sign out on shared devices.
14. Adult-only release and legacy profiles
The closed-test release is for people aged 18 and over. New under-18 users cannot complete onboarding. If an existing profile is identified as under 18, tracking, calorie targets, fasting, body composition, and AI remain unavailable; export, account deletion, sign-out, and support/legal access remain available so the person can exercise their data rights. We preserve existing data until the person exports or deletes it rather than silently erasing it. If you believe a minor has provided data, contact us for help.
15. Your choices, export, and deletion
From Settings → Account & data → Export data (CSV), you can export diary entries and weigh-ins. For a full access or portability copy, contact support. Turn off future AI processing from the same panel with Turn off AI processing. The separate usage-analytics switch is also in this panel and remains available on the restricted privacy screen. Account deletion is under Settings → Account & data → Delete account and uses two confirmation dialogs; it erases the cloud account while keeping the device copy. Because Analytics is not linked to that account, account deletion does not identify or erase earlier Analytics events. Delete the device copy separately with Delete all local data to turn analytics off and reset its device identifier. You can also request account deletion by email without the app installed. The Delete your account page explains both routes and the available record-level deletion controls.
16. Changes to this policy
We update this page when the app changes meaningfully; the effective date at the top always reflects the current version. For material changes we also tell you inside the app, and consent-gated features re-ask when the policy version they rely on changes.
17. Contact
Privacy questions or data subject requests: support@parsenutrition.com. See the GDPR rights page for the full list of rights available to you.