Privacy policy

Effective 5 August 2026

Summary

ParseNutrition is a calorie and diet tracker. What you eat and what you weigh is sensitive information, and this page explains exactly what we do with it. In plain English: your logs are written to your phone first. Optional account sync is configured for an EU data region. Your health data is never sold or used for ad targeting, and deletion controls are available at any time. Optional AI tools send only the meal, label, or recipe photo, or pasted recipe text, that an adult explicitly submits after turning the feature on.

1. Who we are

ParseNutrition is developed and operated by Lucas Ekström, Sweden, who is the data controller for the processing described on this page. For any privacy question or request, write to support@parsenutrition.com. This address is the official contact for data protection matters.

2. What data the app handles

To count calories and adapt your targets, the app needs to know some things about you and your days. The categories it may collect are:

The app does not collect your contacts, precise location, or microphone. The camera is used only for barcode scanning and, if you enable it, AI photo scans — frames are processed for those purposes and nothing is captured in the background.

3. Offline-first: data on your device

Every log is written to a local database on your phone first, so the app works fully without an internet connection. Your device copy is kept until you uninstall the app, clear its storage, or use Settings → Account & data → Delete all local data. Deleting an account removes its cloud copy but deliberately leaves this local copy in place unless you delete it separately.

A local wipe can retain one minimal, local-only consent-withdrawal receipt: the Firebase account identifier, revoked state and server epoch, plus a random request identifier and request time while delivery is pending. It is used only to keep processing off and retry the same withdrawal after an offline restart. It contains no diary, food, weight, body, or photo content. It is removed after confirmed account deletion; uninstalling the app or clearing app storage also removes it.

4. Sync and backup (Firebase, EU region)

When production sync is available and you sign in, the app can mirror your data to Google Firebase (Authentication and Cloud Firestore) for account backup and restore. The repository configures the database and server functions for the European Union region europe-west1 (Belgium); deployment readiness is checked separately before release. Each user's data is scoped under their own identifier. We do not sell your data or use your account, body profile, diary, food searches, weight, fasting, pregnancy, breastfeeding, or other health data for advertising or retargeting. The limited ad-related data described in Section 6 may be processed by Google for the purposes stated there.

Before sign-in, the production app initializes Firebase App Check and reads non-personal feature configuration. Google may create a Firebase installation identifier and process a Play Integrity attestation token, device and app-integrity signals, IP address, and request metadata for security, abuse prevention, and safe rollout controls. This traffic does not include your diary, body profile, health metrics, or AI inputs.

5. Food database lookups (Open Food Facts)

General food search runs against a curated database that ships inside the app and never touches the network. A barcode lookup can query the Open Food Facts API with the barcode. Remote Store search sends the text you choose to search for and language preferences derived from the app locale to Open Food Facts' Search-a-licious API using an HTTPS POST. It does not send a country parameter. Requests identify the app through ParseNutrition's public User-Agent and reveal your IP address to Open Food Facts, a French non-profit. No account data, body profile, health metrics, or diary content is included. Products you select are cached on your device so repeat use works offline. Open Food Facts may retain and use request IPs for security, technical analysis, and popularity or usage statistics under its own privacy terms. When a request does not include a country parameter, it may also infer your approximate country from the IP address.

Nutrition data for branded products comes from Open Food Facts and is licensed under the Open Database License (ODbL). The same attribution appears in the app under Settings → Data sources & licenses.

6. Advertising and independent consent choices

The 1.0.0+40 production candidate includes Google Mobile Ads and Google's User Messaging Platform (UMP). Eligible free users may see one fixed, clearly labeled banner at the bottom of the Diary screen. ParseNutrition does not use app-open, interstitial, rewarded, or native ads. Signed-out local use is free and may be ad-supported after UMP permits requests and every remote/runtime gate passes; signing in does not itself remove ads, while an active monthly/yearly subscription or historical lifetime ad-free entitlement does. An unresolved sign-in transition, a Firebase anonymous identity, or unknown or stale signed-in purchase, restore, or entitlement state remains fail-closed, so no ad is requested.

Where required, UMP asks for your advertising privacy choice before an ad request. When UMP requires it, you can review or change that choice at Settings → Ad privacy choices. Advertising privacy is independent from health-data consent and AI consent: changing one does not grant or withdraw either of the others. Withdrawing or changing an advertising choice stops or limits later ad processing according to the choice and applicable law.

Google's European regulations message uses the IAB Europe Transparency and Consent Framework (TCF) to communicate your choices through TCF consent signals, including the TCF string, and presents the current advertising-partner list and processing purposes. The current configured partner set contains Google Advertising Products only; automatic inclusion of common or mediation partners is disabled. If that partner set or its purposes change, we must review this policy and the message configuration and re-prompt affected users where the change or applicable law requires it.

For eligible ad requests, Google may process your IP address and derive approximate location, record ad views or interactions and diagnostics, and use a device or other identifier such as App Set ID. These categories may be collected and shared with Google for advertising, analytics, and fraud prevention or security. The merged Android app permanently removes com.google.android.gms.permission.AD_ID; ParseNutrition does not collect the Advertising ID. No food log, search, weight, body metric, fasting record, pregnancy or breastfeeding status, account profile, or other health data is supplied as an ad keyword, targeting signal, or content URL. Ad requests use a G-rated maximum content setting.

7. AI meal, label, and recipe input (AI tier, 18+)

AI scanning is optional and available only to supported adult accounts that give a separate, explicit consent before the first scan. Access may come from a limited signup allowance or a Google Play offer when one is active. Nothing is sent anywhere until adult eligibility and consent are recorded.

When you submit a photo of a meal, a recipe, or a nutrition label, or paste recipe text, that input travels from your phone to our Cloud Function (configured for europe-west1) and from there to Anthropic, the provider of the Claude AI model, in the United States. Anthropic returns an estimated calorie and macro breakdown. Our Cloud Function handles the input in memory and does not persist it. The returned estimate is saved in your diary like any other entry and is always editable — treat it as a fast starting point, not a measurement.

Anthropic may retain submitted photos or text under its provider terms, including for safety, abuse detection, or legal obligations. Unless a verified zero-data-retention arrangement applies to the production account, these inputs are not treated as ephemeral in our Google Play disclosure. Avoid including people, documents, or anything private in a photo, and remove unrelated personal details from recipe text before submitting it.

8. Purchases (Google Play and RevenueCat)

When a purchase offer is active, it is sold through Google Play, which handles billing; we never see your card details. RevenueCat then processes the purchase token and subscription status so the app can show the corresponding entitlement. RevenueCat is activated when you open Plans, restore purchases, or when the app has a local record that this device previously used a paid entitlement; it is not contacted merely because a non-buyer launches or signs in to the app. To link purchase state to your account, RevenueCat may receive your account identifier and email address as a subscriber attribute. We may store the entitlement state and remaining scan allowance on your account. An offer shown in app code is not a promise that Google Play has made it available in your country.

9. Diagnostics and optional usage analytics

Required crash reporting uses Sentry and has no in-app opt-out. Reports contain technical information such as the device model, OS version, and stack traces. Performance tracing and product-interaction breadcrumbs are disabled, and reports are scrubbed before sending to remove account, health, and food content. Our retention policy caps reports at 90 days; verification that the production Sentry setting enforces that cap is a release gate.

Product analytics is separate and optional. On first use it starts off, and native Analytics collection and storage default to denied before app code runs. No product event is sent until you enable Share limited usage analytics; on later launches the app reapplies a current saved choice. Event-level data is pseudonymous while it carries the app-instance identifier; it is not anonymous. You can change that choice at any time under Settings → Account & data, including from the restricted privacy screen. Turning it off stops future collection and asks Firebase Analytics to reset its identifier and local Analytics data on that device. Small local-only markers recording whether a one-time milestone was already sent, and the last logging day sent, remain only to prevent duplicate events if you opt in again; they contain no food, nutrition, body, or account content and are removed by Delete all local data, uninstall, or clearing app storage. Turning analytics off does not delete events already received by Google; those remain subject to the retention period below. The choice does not change health-data, AI, or advertising consent. Analytics is not linked to your ParseNutrition account, and we do not set a Firebase Analytics user ID or use these events for health-based advertising or remarketing. Server-side AI quota counting remains separate operational activity whether or not optional analytics is enabled.

10. Legal bases for processing (EU / UK users)

11. How long we keep data

12. International data transfers

Your synced data lives in the EU (europe-west1). Some providers process data in the United States or other countries: RevenueCat (subscription status), Anthropic (AI scans, only if you use them), Google Firebase Analytics (only after the separate opt-in), Google Mobile Ads and UMP (eligible free-tier advertising and privacy choices), and parts of Google's global infrastructure for sign-in and billing. For each, we rely on the provider's data-processing terms and transfer safeguards, including the European Commission Standard Contractual Clauses and adequacy decisions such as the EU-US Data Privacy Framework where the provider relies on one. The full processor list is on the GDPR rights page.

Email to support@parsenutrition.com is routed through Porkbun email forwarding to a monitored Google Gmail inbox. Porkbun and Google therefore process the sender address, message content, attachments, and routing metadata needed to deliver and retain the correspondence. Their infrastructure may process data outside the EEA under their applicable data-processing terms and transfer safeguards; the private destination address is not published.

13. Security

Sign-in uses Google's authentication system. All traffic is encrypted in transit, cloud data is access-controlled per user, and our server functions verify app integrity and a valid session before accepting requests. Feature entitlements are verified server-side, so a modified client cannot read another user's data. No online service can promise perfect security; keep your sign-in credentials private and sign out on shared devices.

14. Adult-only release and legacy profiles

The closed-test release is for people aged 18 and over. New under-18 users cannot complete onboarding. If an existing profile is identified as under 18, tracking, calorie targets, fasting, body composition, and AI remain unavailable; export, account deletion, sign-out, and support/legal access remain available so the person can exercise their data rights. We preserve existing data until the person exports or deletes it rather than silently erasing it. If you believe a minor has provided data, contact us for help.

15. Your choices, export, and deletion

From Settings → Account & data → Export data (CSV), you can export diary entries and weigh-ins. For a full access or portability copy, contact support. Turn off future AI processing from the same panel with Turn off AI processing. The separate usage-analytics switch is also in this panel and remains available on the restricted privacy screen. Account deletion is under Settings → Account & data → Delete account and uses two confirmation dialogs; it erases the cloud account while keeping the device copy. Because Analytics is not linked to that account, account deletion does not identify or erase earlier Analytics events. Delete the device copy separately with Delete all local data to turn analytics off and reset its device identifier. You can also request account deletion by email without the app installed. The Delete your account page explains both routes and the available record-level deletion controls.

16. Changes to this policy

We update this page when the app changes meaningfully; the effective date at the top always reflects the current version. For material changes we also tell you inside the app, and consent-gated features re-ask when the policy version they rely on changes.

17. Contact

Privacy questions or data subject requests: support@parsenutrition.com. See the GDPR rights page for the full list of rights available to you.