Eat & Exercise

Privacy Policy

Effective date: 27 August 2026 · Last updated: 27 August 2026

This policy describes what the Eat & Exercise mobile app actually does with your data, based on an audit of the app, its server and its database as they run today. It does not describe features that do not exist.

1. Who is responsible

Eat & Exercise is developed and operated by Yumei Zhu, an individual developer, who is the data controller. It is not a company.

2. Summary

  • The app works offline-first. Everything you log is stored in a local database on your device.
  • Creating an account (Sign in with Apple or Continue with Google) is optional. It enables backup/sync and AI features.
  • AI features run only after your separate, explicit consent, and only send data when you actively use an AI action.
  • Photos you attach are stored on your device and are never included in backup/sync. Separately, if you submit a photo to an AI action, its image content is transmitted to Google Gemini for that one analysis — so photos are not entirely device-only when you use AI on them (see section 6, including Google's retention).
  • There are no advertising or analytics SDKs, no trackers and no cookies in the app, and none on this website.
  • AI estimates are informational only and not medical advice.

3. Data stored on your device

The app keeps its working data in a local SQLite database inside the app's private storage on your phone:

  • meals and drinks you log, including per-food nutrition values and fluid volume for hydration;
  • workouts and sleep records (start/end times, duration, your time zone identifier at the time of logging);
  • menstrual-cycle events you choose to log;
  • body-weight entries;
  • “food decision” records (foods you chose to skip, with an optional money amount and currency symbol);
  • exercise plans, generated insight reports, and derived daily statistics (targets, streaks, reward-ledger entries);
  • your profile (nickname, height, age, optional target weight, optional biological sex) and settings (goals, activity level, weight objective, currency symbol);
  • photos you attach to records — the image file and its local reference (URI) live on the device, and backup/sync never uploads them (both the app and the server strip the photo reference from every sync payload). This covers storage and sync only: if you submit a photo to an AI action, its image content is transmitted to Google Gemini for that analysis, as disclosed in section 6 (including Google's retention).

This local data stays on your device until you delete the records, delete the app, or choose to delete it during account deletion.

4. Account and authentication (optional)

You can use manual logging forever without an account. If you sign in:

  • Continue with Google (Android) or Sign in with Apple (iOS) is verified on our server against the provider's public signing keys.
  • We store only the provider's stable account identifier (the token “subject”) linked to an internal random user ID. We do not store your e-mail address or name, and we never use e-mail to link or merge accounts.
  • The server issues a signed session token (valid up to 90 days), which the app keeps in the operating system's secure storage. Deleting your account invalidates all outstanding sessions.
  • On iOS, where Apple's revocation interface is configured, an Apple refresh token may be stored solely so your Apple authorisation can be revoked when you delete your account.

5. Backup and sync (signed-in users)

When you are signed in (and only then), your structured records — the items listed in section 3 except photos — are synced to our server database so they survive reinstalls and follow you across devices. Sync also carries your profile fields (nickname, height, age, target weight, biological sex) and settings (calorie/protein/hydration goals, activity level, weight objective, currency symbol), because the app's calorie model needs them. Deletions are propagated with deletion markers (“tombstones”), which are retained so that a deleted record stays deleted on every device. Generated insight reports are also stored server-side so a report you are entitled to can be recovered if the app crashes or you change device.

Records created before you signed in stay local until you explicitly choose “Use with this account”; nothing is claimed silently.

6. AI processing (separate opt-in)

AI features require your explicit AI-processing consent in addition to signing in. Consent is versioned; you can revoke it at any time in Settings, and revoking it stops all future AI processing without affecting your account or data. Data is sent only at the moment you use an AI action:

  • Analyse a meal — the description and/or photo you submit;
  • Analyse exercise/sleep — the text and/or screenshot you submit, plus your current local clock reading (a plain date-time with no time zone);
  • Estimate a skipped food — the description and/or photo, your configured currency symbol, and your device's time zone identifier and language/region setting (coarse, device-configured market context used to price the item; the app has no location permission and never uses GPS or precise location);
  • Generate an insight — a summary of your recent logged days and your goal profile.

These requests go to our server, which forwards them to Google's Gemini API for processing and returns the result. Every AI result is a prefill that you review and can edit before anything is saved; a value you enter yourself always overrides an AI estimate, and nutrition read from a visible label outranks an AI guess.

AI estimates — calories, nutrients, exercise intensity, prices, insights — are informational estimates only. They are not medical, nutritional or other professional advice, and the app is not a medical device.

When an AI action includes a photo or screenshot, its image content is transmitted for that one analysis — from the app to our server and on to the Gemini API. Eat & Exercise does not persist uploaded image content or AI prompts in its own server (Worker) or database (D1). AI outputs are handled in two ways on our side: generated insight reports are stored durably server-side for delivery and recovery (section 5); and AI-derived values — the estimated nutrition of an analysed meal, workout/sleep fields, or a food decision's estimated calories and price — become part of an ordinary record once you review and save them, stored on your device and, when you are signed in, synced like any other record (marked as AI estimates until you edit them).

Retention by Google: once an AI request reaches the Gemini API, it is handled under Google's own API policies. Unless a verified Zero Data Retention configuration applies to our API project, Google may retain prompts, contextual information and outputs for a limited period — currently up to 55 days — for abuse monitoring, after which they expire under Google's retention policy. We make no claims here about how third-party AI providers train models; see Google's own terms for the Gemini API. We do not send your photos or records to any AI service outside the specific actions listed above.

7. Feature allowances and closed-test membership

The server stores timestamps of your free insight generations (to operate the weekly allowance) and, if you receive the closed-test Founding Access entitlement, the grant's start and expiry dates. This is complimentary; the app contains no payment, billing or purchase flow and collects no payment data.

8. Service providers actually in use

Verified against the running app and server, the only third parties that process data are:

  • Cloudflare — hosts our API server (Workers) and server database (D1) on its global network, and would host this website (Pages).
  • Google — verification of Google sign-in tokens; the Gemini API for the AI features described above; Google Play for app distribution on Android.
  • Apple — Sign in with Apple verification on iOS.
  • Expo (EAS Update) — delivers over-the-air app-code updates; when the app checks for an update, that request goes to Expo's update service.

No advertising networks, analytics providers, crash-reporting services, data brokers or other processors are used. We do not sell data, and we do not share your records with any party not listed here.

9. Device permissions

The app requests camera and photo library access only when you choose to attach a photo, and uses them for nothing else. It requests no location permission of any kind.

10. Retention

  • On your device: until you delete individual records, the app, or (your choice) the local copy during account deletion.
  • On the server: while your account exists — synced records, deletion tombstones (so deletions stick everywhere), stored insight reports, allowance timestamps and any Founding Access grant.
  • At Google (AI requests only): as described in section 6, absent a verified Zero Data Retention configuration, prompts, contextual information and outputs of AI requests may be retained by Google for abuse monitoring for up to 55 days under its current Gemini API policy, then expire.
  • Account deletion removes the Eat & Exercise server-side data described in section 11.

11. Deleting your account and data

Settings → Account → Delete account permanently removes, on the server: your account row, your sign-in identities, all synced records (including stored insight reports) and any Founding Access grant, and invalidates every signed-in session. Where Apple's revocation interface is configured, the Apple authorisation is revoked too. You choose separately whether the copy on your phone is kept (as local-only data) or deleted with it. No hidden identifier tied to you is retained after full deletion; the only remnant is an anonymous campaign counter that contains no user reference.

You can also request deletion without the app — by e-mail to [email protected]. The account deletion page explains both routes and exactly what is removed.

Deletion removes the associated Eat & Exercise server records. It may not immediately erase processor-held abuse-monitoring records of past AI requests at Google (section 6); those expire under the processor's own retention policy.

12. International processing

The providers above operate global infrastructure. Your synced data and AI requests may therefore be processed on servers outside your own country.

13. Security

Data in transit between the app, our server and the providers above uses HTTPS/TLS. Sessions are server-signed tokens kept in the device's secure storage, and server-side secrets (signing and API keys) are stored in the hosting platform's secret storage, never in the app. The local database lives in the app's private, OS-sandboxed storage. No security measure is perfect; we describe here only the measures actually in place.

14. Your choices and rights

In the app you can: use it entirely without an account; view, edit and delete any record; revoke AI consent; sign out; and delete your account and synced data as described above. Depending on where you live, you may also have statutory rights regarding your personal data (such as access, correction, deletion, portability or objection); for any request the in-app controls do not cover, write to [email protected].

15. Children

The app is not designed for or directed at children. It performs no age verification.

16. Changes to this policy

If the app's actual behaviour changes, this policy will be updated first and the “Last updated” date changed. The current version always lives at this address.