Privacy Policy
Last Updated: August 22, 2026
This Privacy Policy explains how Food Signals ("we", "us", or "our") collects, uses, discloses, and protects your personal information when you use our web or mobile application (the "Service"). We are committed to handling your data with transparency and care.
1. What Data We Collect
We collect only the minimum information necessary to provide the Service:
Data you provide directly:
- Body Measurement Data: We collect and store the body measurements you provide — your height, body weight, and (optionally) waist — as part of your nutrition profile and weight tracking. Your current height, weight, and waist are stored on our servers against your account so they are available across your devices, and each weight/waist entry you record is kept with its date so we can show you your trend over time. Providing waist is optional, and you can update or delete these values.
- Profile Inputs: Your age, sex, and activity level, if you provide them. These are stored on our servers against your account, alongside your height and weight, because they are the inputs your nutrition targets are calculated from and we recalculate those targets when any one of them changes. You can update them at any time, and they are deleted with your account.
- Meal and Food Logs: What you log eating or drinking — logged by photo, description, or selecting a previous meal — plus the nutrient values we calculate from it.
- Symptom Logs: Which symptoms you record (for example nausea, fatigue, bloating) and the severity you select, only if you have opted in to health-data collection.
- Injection-Event Logs: The date/time of injections you log and, where you choose to record it, a relative dose-change category — First Dose, Increased, Same, Reduced, or Restarted After Break — only if you have opted in to health-data collection. We do NOT collect the name, brand, type, active ingredient, or identity of any medication, and we do NOT collect a numerical dose amount or dose multiplier. We do not know what drug you are taking or how much of it you take.
- Injection Interval: If you set one, your preferred number of days between injections — a scheduling preference used to help the app plan around your routine. This is a cadence you choose, not a dose.
- Observed Patterns: Where you use the Patterns feature, statements describing correlations we observe between your own logged data (for example, between a symptom and foods logged nearby in time). These are generated from your other logged data, shown only to you, and treated as consumer health data — see Section 9.3 and our Consumer Health Data Privacy Policy.
- Usage preferences: Settings and preferences you configure within the application.
Data collected automatically:
- Technical Data: Device identifiers, operating system version, application version, and usage logs collected to operate and maintain the Service.
- Product Analytics Data: A record of how you interact with the Service — screens you open, features you use, actions you complete or abandon, and errors you hit. This is first-party: it is collected by us, stored on our own infrastructure, and never sent to any third-party analytics provider. It records that you logged a meal and which recipe it referred to — never what the meal was. Your food entries, symptom entries, journal text, and any other free text you write are never included, and we do not record your IP address or location. You can turn this off at any time (see Section 9).
What we do NOT collect:
- We do NOT collect the name, brand, type, classification, or identity of any GLP-1 medication or any other medication.
- We do NOT collect a numerical dose amount or dose multiplier for any medication.
- We do NOT collect diagnoses, medical records, prescriptions, or health conditions.
- We do NOT collect your precise GPS location.
- We do NOT collect financial information.
2. How We Use Your Data
We use the information we collect exclusively for the following purposes:
| Purpose | Description |
|---|---|
| Injection Cycle Scheduling | Your injection timing, relative dose-change category, and injection-interval preference are used solely to calculate your GLP-1 injection schedule and cycle timing. This is the only purpose for which this data is used. |
| Service Operation | Technical data is used to operate, maintain, and improve the reliability and performance of the Service. |
| Support | If you contact us for support, we may use your account and technical information to diagnose and resolve issues. |
We do NOT use your data for:
- Advertising, profiling, or marketing to you or any third party.
- Building behavioural profiles.
- Selling, licensing, or commercially exploiting your information.
- Any purpose other than those listed above.
3. Third-Party Processing and International Transfers
This section names the categories of third party that process any part of your data, what they do with it, and where they do it. We do not permit any third party to use your data for their own advertising or unrelated purposes, and we do not have an undisclosed secondary use for any data we collect. This list reflects the processors in use as of the date of this policy; if we add a new category of processor, we will update this section and notify you before that processor receives your data.
By using the Service, you acknowledge and expressly consent to the following:
To generate meal suggestions, answer questions about GLP-1 medication management, and provide the AI-assisted features of the Service, your queries and the contextual data necessary to respond to them are transmitted to a third-party artificial intelligence model provider. The current provider is:
- OpenAI (openai.com) — provider of the GPT family of AI models
This is the only AI model provider currently integrated into the Service, and it is kept in sync with our internal processor register. Depending on the AI feature you use, a future version of the Service may add or change providers; if that happens, we will update this section and notify you before the new provider receives any data.
What data is sent to AI providers:
Only the information necessary to respond to your query — the content of your meal/drink photo or description, a portion hint where relevant, and the text of your question or request. We do not send your name, symptoms, injection data, measurements, or any account identifier beyond what is technically necessary to route the request. The name, brand, or type of your medication is not stored by us and therefore cannot be sent, and there is no numerical dose value to send.
Protections under our arrangements with AI providers:
We use the API (application programming interface) offerings of these providers, not their consumer products. Under our API service agreements:
- Your query data is not used by AI providers to train their models.
- Your queries and the AI-generated responses are not retained by the AI provider beyond the time required to process the request and return a response.
- Your data is processed by the AI provider solely on our behalf for the purpose of generating a response.
These protections reflect the commitments made by these providers in their API terms of service as of the date of this policy. If those terms change materially to your detriment, we will update this policy and notify you.
International data transfer:
Because AI providers operate globally, your query data may be processed on servers located outside your country of residence, including in the United States. By using the Service, you consent to this transfer.
Infrastructure sub-processors:
- Cloudflare — The Service runs on Cloudflare's infrastructure: our application servers, our databases (including your food, symptom, injection and measurement logs), and the storage holding your meal photos. Cloudflare processes your data solely to deliver the Service under our instructions. Cloudflare is a United States company operating a global network, and we do not pin our databases or file storage to a specific country — your data may be stored and processed on Cloudflare infrastructure outside your country of residence, including in the United States.
- Brevo — Our transactional email provider, used solely to send account-related emails (email verification, password reset, support responses) and, if you have opted in, our email updates. Brevo processes your email address and the content of these messages under our instructions. We also sync a limited set of lifecycle attributes to Brevo to personalise those messages and measure whether they're useful — for example whether and when you last logged a meal, and how many meals you've logged in total. Brevo never receives the content of any meal, symptom, injection, or measurement entry, only these summary attributes. Brevo is a French company and processes this data in the European Union.
Identity sign-in processors:
- Apple — If you sign in with Sign in with Apple, Apple processes the identifier and, if you choose to share it, the name/email associated with your Apple ID to authenticate you. Apple does not receive any food, symptom, injection, or measurement data.
- Google — If you sign in with Google Sign-In, Google processes the identifier and profile information associated with your Google account to authenticate you. Google does not receive any food, symptom, injection, or measurement data.
Health-professional access (only if you opt in):
- Food Signals dietitian — If, and only if, you turn on dietitian data sharing in Settings, our dietitian can view your food history and your progress toward your targets, read-only, for the purpose of supporting you. Every access is logged. This is off unless you turn it on, you can turn it off again at any time, and the dietitian keeps no separate copy of your data. Our dietitian practice operates in Australia.
Marketing website only (food-signals.com):
These run on our public website — not in the app — and they never receive any of your account, food, symptom, injection, or measurement data. They do not run at all until you accept them; if you decline, no request is made to either provider.
- Meta (Facebook Pixel) — Measures which of our advertisements led to a visit or a sign-up. Processed in the United States.
- Google Analytics (including Google Tag Manager) — Measures website traffic so we know which pages are useful. Processed in the United States.
4. We Do Not Sell or Share Your Data
We do not sell, rent, lease, trade, license, or otherwise transfer your personal information — including your injection-event data, query history, or account information — to any third party for any commercial, marketing, or other purpose. This includes your consumer health data (meal, symptom, and injection-event logs, body measurements, and observed patterns) specifically — we do not sell or share consumer health data, and we do not use it for advertising.
The categories of third party that receive any portion of your data are:
- Our AI model provider as described in Section 3, solely to generate responses to your queries.
- Cloudflare, solely to operate the Service's infrastructure.
- Brevo, solely to send account-related transactional emails and the limited lifecycle attributes described in Section 3.
- Apple and/or Google, solely to authenticate you if you choose to sign in with them.
- If you opt in to dietitian data sharing (Settings), the Food Signals dietitian — solely to view your food history and your progress toward your targets, read-only, for the purpose of supporting you. This is off unless you turn it on, and you can turn it off again at any time.
- On our public website only, and only if you accept them, Meta and Google Analytics — solely to measure website visits and advertising performance, as described in Section 3. These receive nothing from the app: no account, food, symptom, injection, or measurement data ever reaches them.
We do not permit any processor listed above to use your data for its own advertising or unrelated purposes. If we add a new category of processor, we will update this section and notify you before that processor receives your data.
5. Data Retention
We retain your data only as long as necessary to provide the Service. How long that is depends on the category:
| Category | How long we keep it |
|---|---|
| Meal and food logs, including the nutrient values calculated from them | For as long as your account exists |
| Meal photos | For as long as your account exists |
| Symptom logs, injection-event logs, and observed patterns | For as long as your account exists |
| Body measurements — height, weight, waist, and each dated entry in your trend | For as long as your account exists |
| Profile inputs — age, sex, activity level — and your nutrition targets | For as long as your account exists |
| Injection-interval preference, meal plans, and other preferences | For as long as your account exists |
| Account details and sign-in credentials | For as long as your account exists |
| Consent records — which consents you gave and when | For as long as your account exists; the fact that your deletion request was carried out is kept separately, see below |
| Product analytics — the per-user interaction record described in Section 1 | Deleted automatically 90 days after collection |
| Anonymised, aggregated statistics derived from product analytics | Contain no identifier of any kind; may be retained indefinitely |
| Access logs — a record of who viewed your data and when (not what your data says) | 7 years. These record access events, never a health value. They are kept so that any improper access to your records can be investigated later, including after your account is gone. |
| Proof that a deletion request was carried out | 7 years, identifying you only by a one-way cryptographic hash — enough to prove we deleted your data, not enough to reconstruct who you were |
When you delete your account
Deleting your account deletes it immediately — not as a request queued for later processing. Every category above marked "for as long as your account exists" is erased from our live systems as part of that action, including your meal photos.
A copy of the deleted records is placed in a restricted internal store for 7 days and is then destroyed automatically. That copy exists only so that a deletion made in error or caused by a fault can be investigated within a short window. It is not indexed by your name, email, or account identifier, it is not used for any other purpose, and no part of the Service can read it. After 7 days it is gone. The same disclosure is shown to you in the deletion flow itself, before you confirm.
Residual copies held in our infrastructure provider's automatic point-in-time backups are purged within 90 days. These are platform-level backups of the whole system, not a copy of your account we can search or use. If we ever restore from such a backup, any record covered by a completed deletion request is re-deleted as part of that restore before the restored system is brought back into service — a backup restore never silently brings back data you asked us to delete.
6. Data Security
We implement reasonable technical and organisational security measures to protect your data, including:
- Encryption of data in transit (TLS 1.2 or higher).
- Access controls limiting data access to authorised personnel and systems.
- Regular review of our security practices.
No method of transmission or storage is completely secure. In the event of a data breach likely to cause you harm, we will notify you and the relevant regulator without unreasonable delay and within the timeframes required by applicable law: within 30 days to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, and, for US users, without unreasonable delay and no later than 60 days under the FTC Health Breach Notification Rule. Some US state breach-notification laws may require a shorter timeframe than the FTC rule; where that applies, we will follow the shorter one.
7. Not Medical Advice
The Service is a personal food, water, and symptom logging tool that does not provide medical advice, diagnosis, or treatment. It records what you log and shows you observations drawn from your own logged data. Nothing in the Service — including AI-generated responses — constitutes or should be relied upon as professional medical advice. Always consult your licensed healthcare provider before making any changes to your GLP-1 medication regimen.
8. Children's Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us immediately.
9. Your Rights
This Privacy Policy applies wherever you use the Service. If you are in Australia, the United States, or elsewhere, the sections below describe rights specific to your jurisdiction, in addition to the general rights every user has: to access, correct, delete, and receive a portable copy of your data, and to opt out of product analytics.
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your account and associated data — Settings → Delete account in the app. This deletes your account immediately; you do not need to ask us and you do not need to wait. See Section 5 for exactly what is erased and what is kept.
- Object to or restrict certain processing of your personal information.
- Data portability — Settings → Download my data in the app gives you a copy of everything we hold about you as a machine-readable JSON file, straight away.
- Withdraw a consent you have given — Settings → Your data & consent rights lists each consent, when you gave it, and lets you withdraw it.
- Opt out of product analytics — turn off "Help improve Food Signals" under Settings → Privacy at any time. Doing so stops collection immediately and deletes the interaction record we already hold about you. Anonymised aggregates already derived from it are retained, as they contain no information that identifies you.
The access, deletion, portability and consent-withdrawal rights above are all available directly in the app, without contacting us. If you would rather we handled it, or you want to exercise a right not listed as an in-app action, please contact us.
9.1 Australia
This Privacy Policy is governed by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The Office of the Australian Information Commissioner (OAIC) is the regulatory authority for the APPs, and we notify the OAIC of an eligible data breach within 30 days under the Notifiable Data Breaches (NDB) scheme, per Section 6.
9.2 California (CCPA/CPRA)
<<<<<<< HEAD If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you additional rights. Your meal, symptom, and injection-event logs are treated as Sensitive Personal Information under the CCPA/CPRA. You have the right to know what Sensitive Personal Information we collect, to delete it, to correct it, and to limit our use of it — though we do not use it for any purpose beyond providing the Service to you (Section 2), so there is nothing additional to limit. We do not sell or share your personal information, including your Sensitive Personal Information, and we never have.
9.3 Washington (My Health My Data Act)
If you are in Washington State, or anywhere else in the United States, your consumer health data (meal, symptom, and injection-event logs) is additionally protected by our standalone Consumer Health Data Privacy Policy, which applies to all US users regardless of state — we do not geofence these protections to Washington or Nevada residents. That policy covers: the affirmative opt-in required before we collect this data, your right to withdraw that consent, our commitment to complete deletion requests within 30 days, and our statement that we do not sell consumer health data. =======
Applicability. Where the CCPA/CPRA applies to Food Signals, California residents may exercise the rights described in this section. Regardless of whether a particular statutory threshold applies to us, Food Signals provides the privacy controls described in this Privacy Policy to all users through the Service.
Notice at collection. The table below identifies, for each category of personal information we collect, examples, our purpose for collecting it, how long we retain it, and whether it is sold or shared.
| Category | Examples | Purpose | Retention | Sold or shared |
|---|---|---|---|---|
| Identifiers | Account ID, email address | Account operation | Account lifetime | No |
| Sensitive Personal Information | Health and body information — meal, symptom, and injection-event logs; body measurements; observed patterns | Provide the food-logging, nutrition, and pattern-insight features you request | Account lifetime | No |
| Meal and food logs | Foods, meals, and drinks you record | Logging and personal insights | Account lifetime | No |
| Injection-event data | Timing and relative dose-change category | Cycle/scheduling functionality | Account lifetime | No |
| Body measurements and profile inputs | Height, weight, waist, age, sex, activity level | Nutrition target calculation | Account lifetime | No |
| Technical information | Device/app version, diagnostics | Security and operation | See Section 5 | No |
| Product analytics | Feature-interaction events (first-party) | Product improvement, opt-out available | 90 days | No |
Sensitive Personal Information. Certain information we collect may constitute Sensitive Personal Information under California law (Cal. Civ. Code §1798.121), including information relating to your health and body measurements. We use Sensitive Personal Information only to provide and improve the services you request, maintain security, and for other purposes permitted by applicable law as described in this Privacy Policy. We do not sell or share Sensitive Personal Information, or any other personal information, for cross-context behavioural advertising, and we never have.
Your rights. Subject to certain exceptions, California residents have the right to: know what personal information we collect and how we use and disclose it; delete personal information we hold about you; correct inaccurate personal information; limit the use of Sensitive Personal Information (we do not use it for any purpose beyond providing the Service to you, so there is nothing additional to limit); and not be discriminated against for exercising these rights.
How to exercise your rights. Use the in-app controls described at the start of Section 9, or contact us. We will verify your request using the information associated with your authenticated account before acting on it.
9.3 Washington (My Health My Data Act)
If you are in Washington State, or anywhere else in the United States, your consumer health data (meal, symptom, injection-event, and body-measurement logs, and the patterns we derive from them) is additionally protected by our standalone Consumer Health Data Privacy Policy, which applies to all US users regardless of state — we do not geofence these protections to Washington or Nevada residents. That policy covers: the categories of consumer health data we collect and where it comes from, the affirmative opt-in required before we collect this data, your right to withdraw that consent and to learn who we've shared it with, our commitment to complete deletion requests within 30 days, and our statement that we do not sell consumer health data. >>>>>>> origin/worktree-refactored-wiggling-blossom
9.4 Other US States
This Privacy Policy applies to all Food Signals users in the United States, whether or not the particular state in which you reside has enacted a consumer-health-data or comprehensive privacy law of its own. We provide the same access, correction, deletion, portability, consent-withdrawal, and analytics opt-out rights described in this Section 9 to every US user, rather than limiting them to residents of states with an applicable statute.
10. Contact
For privacy enquiries, access requests, or complaints, please contact us
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy. The current version is always available at this URL.