Short version: MunchLog requires an account and stores your profile and logs in the cloud so they follow you across devices. Your meal and activity descriptions are sent to OpenAI to produce nutrition estimates. We don't sell your data and we don't use it for advertising. Deleting the app does not delete your account โ request deletion here.
๐ Table of Contents
- Who We Are
- What Information We Collect
- How We Use It & Our Legal Bases
- AI Processing (OpenAI)
- Voice Input
- Apple Health
- Notifications
- Where Your Data Lives & How Long
- Who We Share It With
- International Transfers
- In-App Purchases
- Security
- Children's Privacy
- Your Rights & Choices
- Changes to This Policy
- Contact Us
๐ Who We Are
MunchLog is an AI-assisted nutrition tracking application for iOS and Android. The data controller for the personal data described in this policy is Nitzan Selwyn, trading as MunchLog, based in Israel.
Where this policy says "MunchLog," "we," "us," or "our," it means that controller and the services provided through the MunchLog mobile application.
Privacy contact: privacy@munchlog.net
Postal address: [POSTAL ADDRESS TO BE ADDED BEFORE LAUNCH]
๐ฆ What Information We Collect
Account information
MunchLog requires an account. Authentication is handled by Clerk, which stores:
- Your email address, and a password if you sign up with email
- Your name and email as released by Apple or Google if you sign in with Sign in with Apple or Google. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us.
- A user identifier and session tokens. The session token is held in your device's secure keychain.
Profile and health information you enter
Stored in our cloud database (Convex) and linked to your account:
- Profile: display name, age, gender, height, current weight, starting weight, target weight
- Goals and settings: activity level, goal type (lose / maintain / gain), daily calorie and macro targets, daily water target, metric or imperial units, app language
- Meal logs: your meal description text, the estimated calories, protein, carbs and fat, the per-item breakdown, meal type, and the date and time
- Activity logs: step counts, free-text activity notes, an optional mood rating, and estimated extra calories burned
- Weight logs: every weigh-in you record, with its date
- Water logs: daily intake totals
- AI usage counter: how many AI estimates you have used in the current monthly period, so we can apply the free-tier allowance
- Subscription status: whether an entitlement is active, its product identifier, expiry, store, and when we last checked
Health data notice: weight, body measurements, and nutrition logs are health-related information. Under GDPR this is special category data, and we process it only with your explicit consent, which you give by creating an account and entering it.
Stored on your device only
- Your reminder settings (times and which reminders are on)
- A cached copy of your profile, so the app works during onboarding and before your first sync
- Your authentication session token, in the device keychain
What we do NOT collect
- No analytics or crash-reporting SDK. MunchLog does not currently include any analytics, attribution, or crash-reporting service. We do not build usage profiles.
- No advertising or tracking. No ad networks, no ad identifiers, no cross-app or cross-site tracking.
- No location data.
- No photos. MunchLog does not take, upload, or analyse food photos. Meal logging is text and voice only.
- No contacts, calendar, or files.
- No payment card details. Purchases are processed entirely by Apple and Google.
โ๏ธ How We Use It & Our Legal Bases
We use your information to:
- Create and authenticate your account and keep you signed in
- Calculate your personalised calorie and macro targets using the Mifflin-St Jeor BMR formula
- Produce AI nutrition and activity estimates from what you describe
- Store and display your history, trends, and progress across your devices
- Apply the free-tier AI allowance and recognise an active subscription
- Send the reminders you have switched on
- Diagnose faults, prevent abuse of the AI service, and keep the service secure
- Respond to your support, privacy, and deletion requests
Legal bases (GDPR / UK GDPR)
- Explicit consent โ Article 9(2)(a) โ for processing your health-related data: nutrition, weight, and Apple Health readings. You can withdraw it at any time by deleting your account.
- Performance of a contract โ Article 6(1)(b) โ for running your account, syncing your logs, and administering subscriptions.
- Legitimate interests โ Article 6(1)(f) โ for security, fraud and abuse prevention, and fixing faults.
- Legal obligation โ Article 6(1)(c) โ for tax and accounting records relating to purchases.
We do not sell your personal information, share it for cross-context behavioural advertising, or use your health data for advertising or model training.
๐ค AI Processing (OpenAI)
MunchLog's estimates are produced by OpenAI, a third-party AI provider in the United States. Your data is sent to OpenAI only when you tap to analyse a meal or an activity. Nothing is sent in the background.
What we send for a meal estimate
- Your meal description, exactly as you typed or dictated it
- Your app language code, so the response comes back in your language
What we send for an activity estimate
- Your step count for the day
- Your free-text activity notes
- Your body weight in kilograms, which is required to estimate calories burned
- Your app language code
What we never send
We do not send your name, email address, account identifier, age, height, target weight, or your log history to OpenAI. Each request is sent on its own with no user identifier attached.
Please avoid putting personal details in the description field. Whatever you type or dictate is sent verbatim, so describe the food or the activity and nothing else.
What OpenAI does with it
Requests go through the OpenAI API. OpenAI states that data submitted through its API is not used to train its models, and is retained for up to 30 days for abuse and misuse monitoring before deletion. See the OpenAI Privacy Policy and its API data usage policies.
Estimates are approximations. AI-generated calorie and macronutrient figures are estimates based on a text description, not measurements. They should not be the sole basis for medical, dietary, or health decisions. Consult a qualified healthcare professional or registered dietitian for medical nutrition advice.
๐๏ธ Voice Input
You can dictate a meal instead of typing it. When you tap the microphone, MunchLog uses your device's built-in speech recognition โ Apple's on iOS, Google's on Android โ to turn speech into text.
- Audio is never sent to MunchLog's servers. We receive only the transcribed text, after it appears in the input field.
- Depending on your device, model, and language, your operating system may process that audio on-device or on Apple's or Google's servers. That processing is governed by Apple's or Google's privacy policy, not ours.
- You can review and edit the transcribed text before anything is analysed or saved.
- Microphone access is requested only when you first use voice input, and you can decline or revoke it in your device settings. Everything else in the app still works.
โค๏ธ Apple Health (iOS)
Connecting Apple Health is optional and off until you turn it on in Profile. When it is connected:
- We read your daily step count and active energy burned.
- We write the calories, protein, carbohydrates, and fat from the meals you log, so they appear in Apple Health.
Steps and active energy that we read are saved to your MunchLog account as activity entries, so your daily burn is available on your other devices. We read no other health categories.
You can revoke MunchLog's Health access at any time in the iOS Health app โ Sharing โ Apps. Health data is never used for advertising or marketing, and is never sold or shared with data brokers.
๐ Notifications
MunchLog's reminders are scheduled locally by your device on the times you choose. We do not operate a push notification server, we do not collect a push token, and we do not send marketing notifications. Turn them off in the app or in your device's notification settings.
๐พ Where Your Data Lives & How Long
Cloud storage
Your profile and logs are stored in a hosted Convex database, running on infrastructure in the United States. Your account credentials are stored by Clerk. This is what lets you sign in on a new phone and find your history intact.
Deleting the app does not delete your data. Uninstalling removes the local cache from your device, but your account and logs remain in our database until you delete your account. See Delete your account.
Retention
- Profile and logs: kept until you delete them individually or delete your account.
- Account deletion: we delete your profile, meals, activities, weight entries, water logs, and usage counters, and the authentication record, within 30 days of a verified request.
- AI requests: held by OpenAI for up to 30 days under their abuse-monitoring policy, then deleted. We do not keep a separate copy of the request beyond the log entry you saved.
- Purchase and tax records: retained for as long as accounting law requires, typically seven years. These are transaction records, not health data.
- Backups: deleted records may persist in encrypted backups for a short rolling window before being overwritten.
๐ค Who We Share It With
We do not sell, rent, or trade your personal information. We use the following processors to run MunchLog, and each receives only what it needs:
- Clerk (authentication): your email address, name if provided, password hash, and session data. No health data.
- Convex (database and backend hosting): your profile and all your logs. Convex hosts the data; it does not use it for its own purposes.
- OpenAI (AI estimates): the meal or activity text you submit, plus body weight for activity estimates, plus a language code. No identifiers. See the AI section.
- RevenueCat (subscription management): a pseudonymous user identifier and store transaction data. No health data.
- Apple and Google: app distribution, in-app purchase processing, and โ on iOS โ Sign in with Apple and Apple Health. Their own privacy policies apply to what they collect.
Legal requirements
We may disclose information if required by law, court order, or a lawful request from a public authority, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of MunchLog, our users, or the public.
Business transfers
If MunchLog is ever sold or merged, your data may transfer to the acquirer. We will tell you before that happens and before any new privacy policy applies to you.
๐ International Transfers
MunchLog is operated from Israel, and our processors โ Clerk, Convex, OpenAI, and RevenueCat โ are based in the United States. If you use MunchLog from the EEA or the UK, your personal data is transferred outside your region.
Israel benefits from a European Commission adequacy decision. Transfers to our US processors rely on the European Commission's Standard Contractual Clauses, incorporated into our data processing agreements with each of them. You can ask us for details at privacy@munchlog.net.
๐ณ In-App Purchases
MunchLog has a free tier with a monthly allowance of AI estimates, and an optional paid subscription that removes that limit. Purchases are processed entirely by the Apple App Store or Google Play. We never see or store your payment card details.
We use RevenueCat to check whether your subscription is active. RevenueCat receives a pseudonymous identifier and the transaction data from the store โ never your meals, weight, or other health data. We store the resulting entitlement status on your account so the app knows what you have access to.
๐ก๏ธ Security
- All traffic between the app and our backend uses TLS (HTTPS).
- Every request that touches your data is authenticated; the backend checks that the signed-in account owns a record before reading, changing, or deleting it.
- Your session token is stored in the device keychain (iOS Keychain / Android Keystore), not in plain app storage.
- Data at rest is encrypted by our hosting providers.
- Your device's own lock โ passcode, Face ID, or fingerprint โ protects the cached data on the phone.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.
๐ถ Children's Privacy
MunchLog is not directed at children. You must be at least 13 to use it, or 16 if you are in the EEA or the UK where that is the local age of digital consent. We do not knowingly collect personal information from anyone below that age.
If you are a parent or guardian and believe your child has created an account, email privacy@munchlog.net and we will delete the account and its data.
For users under 18, we recommend involving a parent, guardian, or clinician. Calorie tracking can be harmful for some young people, and MunchLog is not a treatment tool.
โ๏ธ Your Rights & Choices
In the app
- View and edit everything on your profile
- Delete individual meals, activities, weight entries, and water logs at any time
- Clear your logged meals, activities, and weight entries in one step (Profile โ Clear All Meal Data)
- Reset your profile and start setup again (Profile โ Reset Onboarding)
- Sign out, or disconnect Apple Health
- Turn reminders on or off
Deleting your account
You can delete your account and everything attached to it. See munchlog.net/delete-account for how to do it and exactly what is removed.
Your legal rights
Depending on where you live, you have the right to:
- Access a copy of the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data ("right to be forgotten")
- Port your data โ receive it in a structured, machine-readable format
- Restrict or object to certain processing
- Withdraw consent at any time, without affecting processing already carried out
- Not be discriminated against for exercising any of these rights
Email privacy@munchlog.net to exercise any of them. We respond within 30 days and will not charge you for a first request.
EU / EEA and UK residents
You may lodge a complaint with your local data protection authority. In the UK that is the Information Commissioner's Office.
California residents (CCPA / CPRA)
You have the rights to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CPRA, and we do not use sensitive personal information for purposes beyond providing the service. Californian residents may use an authorised agent; we will verify the authorisation.
Israeli residents
Under the Protection of Privacy Law, 5741-1981, you have the right to review and correct the data we hold about you. Email privacy@munchlog.net.
๐ Changes to This Policy
We may update this policy as the app changes. When a change materially affects how we handle your data, we will notify you in the app before it takes effect, and we always update the date at the top of this page. Where the law requires fresh consent, we will ask for it rather than assume it.
๐ฌ Contact Us
Questions, requests, or complaints about this policy:
Privacy: privacy@munchlog.net
Support: support@munchlog.net
Account deletion: munchlog.net/delete-account
Response time: within 5 business days, and within 30 days for formal data rights requests.