Policies
Last updated June 2026
What We Collect
Account information: your email address, display name, and a hashed (irreversible) password. Body metrics: height, weight, age, date of birth, and gender, which you provide during onboarding to personalise your calorie and macro targets. These are stored on our servers. Nutrition logs: food items, portion sizes, and caloric values you log in the app. Meal scan photos: when you photograph a plate with the AI food scanner, that photograph is stored on our servers and attached to the meal it produced, so your diary can show it as that meal's thumbnail. Photographs of a packaged product's nutrition label are treated differently — they are sent for analysis and are not stored. Workout data: exercises, sets, reps, weights, session duration, and active calories burned per session. Workout session summaries are stored on our servers to enable history and progress tracking. Health store integration (optional): with your permission, we read step counts, active calorie data, and sleep duration from Apple Health or Google Health Connect. Step and calorie data are used to calculate your daily net calorie deficit on the dashboard, and sleep duration is used to display your average nightly sleep in the weekly report. This data is read-only, used locally for display, and not shared with third parties or used for advertising. Raw health store streams are not uploaded to our servers.
How We Use Your Data
To calculate your personalised daily calorie budget, macro targets, and BMR based on your body metrics and activity level. To store and display your meal and workout history so you can track progress over time. To power the AI food scanner: when you scan a barcode, a plate, or a nutrition label, that image or barcode data is transmitted to Google Gemini (Google LLC) to return nutritional estimates. No personally identifiable information — such as your name or email — is attached to these requests. A photograph of a plate is also kept on our own servers and stored with the meal you log from it, so the diary can show it; a nutrition-label photograph is not kept. To send optional in-app reminders if you have enabled them in Settings.
Third-Party Services
Google Gemini (AI food analysis): food images and barcodes are forwarded to Google's Gemini API solely to return nutritional estimates. We do not share personally identifiable information with Google for this purpose. Google's Privacy Policy applies to their processing of this data. Forwarding a photograph to Google is separate from our own storage of it — a plate photograph is also kept on our servers, as described under What We Collect and Data Retention. Apple App Store / Google Play (payments): subscription billing is handled entirely by Apple or Google. We receive only a subscription status indicator — no payment card data is stored on our servers.
Data Retention
Your account data is retained for as long as your account remains active. If you delete your account, we will remove your personal data from our systems within 30 days, except where we are required to retain it for legal or compliance purposes. Meal scan photographs are kept for as long as the meal they belong to remains in your diary. Deleting that meal deletes its photograph, resetting your health data deletes those photographs along with the meals, and deleting your account deletes every photograph belonging to it. Nutrition-label photographs are not stored in the first place.
Your Rights
Access: you may request a copy of the personal data we hold about you at any time. Correction: you can update your profile details directly in the Settings screen. Deletion: contact us to request complete deletion of your account and all associated data. European users: if you are in the European Economic Area, you have additional rights under the GDPR, including the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority.
Security
Passwords are stored as irreversible hashed values and are never readable by us. All data is transmitted over encrypted HTTPS connections. Authentication tokens are stored in your device's secure storage (iOS Keychain or Android Keystore). No system is completely secure. In the event of a data breach affecting your personal data, we will notify affected users as required by applicable law.
Website Analytics
We measure how this website is used with PostHog, a product-analytics service. Data is processed on PostHog's European Union infrastructure. What we record: the pages you view, how far down a page you scroll, clicks on the download buttons, and the marketing campaign parameters and referring website in the link you arrived from. PostHog additionally records the coarse technical details any web server sees — browser, operating system, screen size, and an approximate location derived from your IP address. Cookies, and how to turn them off. Measurement starts when you arrive, and a notice on your first visit tells you so. This is an opt-out: we do not wait for you to agree, and if you would rather we did not measure your visit, "Decline" on that notice stops it immediately and permanently. What is stored if you do nothing: PostHog places a random identifier on your device, in a cookie and in your browser's local storage. It is what lets us tell that two page views are the same visit rather than two strangers, and that someone returning next week has been here before. It contains nothing about you: no name, no email address, nothing you typed into a calculator, and nothing that connects to an app account if you have one. It is ours alone — it is not a cross-site identifier, it cannot follow you to any other website, and we never sell this data. Turning it off, at any time. "Turn off analytics" at the bottom of every page does it in one click, and the same control reads "Turn on analytics" afterwards if you change your mind. Turning it off stops the measurement on the page you are reading, erases the identifier already stored, and stops any analytics code being sent to your browser on every later visit — we remember a refusal for ten years and do not ask again. Blocking cookies or trackers in your browser has the same effect, and the site works fully either way. If your browser sends a Do Not Track or Global Privacy Control signal we treat that as a refusal before you arrive, and nothing is loaded or recorded at all. Advertising and ad-measurement trackers are a separate matter and are described under "Advertising & Measurement" below. Do Not Track: if your browser sends a Do Not Track or Global Privacy Control signal, no analytics are loaded at all — the analytics code is not sent to your browser, so nothing is recorded and no request to PostHog is made. Blocking it: the site works fully with analytics blocked or unavailable. This section covers inandoutcalories.com only. The mobile app's own analytics are declared separately in its App Store and Google Play privacy disclosures.
Advertising & Measurement
This site currently loads no advertising or ad-measurement trackers. There is no TikTok Pixel, no Meta pixel and no Google Ads tag on inandoutcalories.com, and nothing on this site reports your activity to an advertising network. The only measurement we run is the first-party analytics described above. If we begin advertising and that changes, this section will describe the tracker, what it is sent, and how to block it. We do not sell your data.
Children's Privacy
This app is not directed at children under 13. We do not knowingly collect personal data from anyone under 13 years of age. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
Contact & Privacy Requests
For any privacy questions, data access requests, or deletion requests, please contact us at: support@inandoutcalories.com We will respond to all requests within 30 days.