EatSleep Privacy Policy
Effective date: September 20, 2026
EatSleep is operated by Pinotech LLC ("Pinotech," "we," "us"), a company organized in California, USA. This policy explains what EatSleep collects, why, where it goes, and how to delete it.
The short version
EatSleep is built to keep your data on your phone. Your food log, weight, sleep, exercise, medication records, and progress photos are stored locally. They leave your phone only when a feature needs them: for example, when you ask AI to analyze a meal or recipe, request an AI exercise estimate, scan a barcode, use dictation, connect a Health service, or contact support. We also record a limited amount of account, subscription, usage, and import-diagnostic data to operate the service, and keep reports you choose to send about AI output. The details are below. We do not sell your data, and we do not use advertising or tracking SDKs.
What we collect, and where it goes
Your diary and Health connections
Your profile (age, sex, height, weight, activity level), food and exercise log entries, weigh-ins, sleep sessions, saved recipes, GLP-1/medication records, and progress photos are stored locally on your phone. Your diary is not uploaded to our servers; the specific feature inputs described below are the exceptions. Your operating system or a backup service you enable may back up app data under its own settings and policy. If you connect Apple Health or Health Connect, the app can read the health data you permit, including body measurements, activity, sleep and available overnight vitals. With your permission and the corresponding sync settings enabled, it can also write nutrition, weight and manually logged sleep to Health. Records already written to Health remain there when you erase EatSleep's data; manage those records in Health separately.
Your choice to enable AI
Before sending inputs for AI processing, EatSleep asks you to allow sharing with Google Gemini through EatSleep. This covers selected food and recipe photos, text and video links, plus exercise descriptions, duration and body weight used for estimates, including estimates for imported Health workouts. Declining keeps manual tracking available. You can withdraw permission in Profile → Data & privacy. Withdrawal stops new AI requests; requests already sent may finish, and withdrawal does not delete data already received by a provider. Erasing EatSleep data resets this permission.
Sent to make a specific feature work
- Meal photos. When you photograph a meal for AI estimation, the photo is sent to our backend, which forwards it to our AI provider (currently Google Gemini) to identify the food and estimate its nutrition. We don't store the image in our application database or file storage. Our infrastructure and Google may retain request data under the provider-retention terms below.
- Progress (body) photos are different: EatSleep does not transmit them. They exist only to compare your own photos to each other over time. Your device's backup service may include app files if you have backups enabled.
- AI text, corrections and recipe imports. Meal and exercise descriptions, corrections, and recipe text, images or video links you submit for AI processing are sent through our backend to Gemini. Importing a recipe link also contacts the source website and may contact a video or caption host to retrieve public content. Those services receive the requested URL or resource identifier and ordinary network information such as an IP address and user agent. A video link may be provided to Gemini for video understanding.
- Barcode scans are looked up against Open Food Facts, a public, crowd-sourced nutrition database, so we can show you the product. This is a read-only lookup. We do not include your EatSleep account or diary data, but Open Food Facts receives the barcode and ordinary network information needed to answer the request.
- Exercise estimates. AI calorie-burn requests include the exercise description, duration and your current body weight when available. This also applies when an imported Health workout needs an AI estimate because its calorie data is missing. These inputs are forwarded to Gemini; our usage records do not store the body-weight value or request text.
- Dictation. When you tap a microphone button, your device's native speech recognition service turns your voice into text. Depending on the device, language, and available speech model, Apple, Google, or the device's selected recognition provider may process the audio over the network. EatSleep does not store the audio recording; it receives the resulting transcript, which is then handled like text you typed.
Recorded on our server
- An anonymous account identifier. On first use, the app creates an anonymous account with Supabase so AI requests can be metered. The app does not ask for or link an email address to this account.
- Free-access device verification. If you claim 14 days of free AI access, the app asks the platform whether that physical device has claimed before. On iOS it sends a one-time Apple DeviceCheck token through Supabase to Apple. On Android it sends a one-time Google Play Integrity token through Supabase to Google, which reads and sets a device-recall bit. In both cases we do not store the token or use it to track activity. We store only your anonymous account identifier and the server-set start and end times. Apple and Google each retain that state under their own rules — across app reinstall or device erase, and on Android across a factory reset — so those actions do not create another free period. Where a device cannot be verified, for example because Play Integrity is unavailable on it, we grant the free period rather than refuse it.
- Usage records. Each AI request records which feature was used, whether it succeeded, how long it took, and token counts, tied to your account identifier. This helps us understand whether the service is priced and provisioned correctly. These records do not include the photo or text you sent.
- Usage-limit counters. We also keep request and token counts for daily limits, request counts for short-term limits, and separate video-request counts. These are associated with your account or RevenueCat subscription identifier so devices using the same subscription share an allowance. Subscription-linked counters may remain after account deletion to prevent erasing and restoring an account from resetting those limits. They contain counts and time periods, not photos, prompts, or diary entries.
- Recipe-import diagnostics. We record whether an import succeeded, failed, or was refused; which import route was used; counts such as caption length, page count, links found, and video duration; and a broad error category. A failed import may also retain the submitted source URL so we can diagnose sites that the importer cannot read. Successful and deliberately refused imports do not retain the URL, caption, transcript, or recipe text. These records are tied to your anonymous account identifier.
- Subscription information. Apple handles iOS subscription billing and Google Play handles Android subscription billing. RevenueCat receives your EatSleep account identifier and the App Store or Google Play purchase information to validate purchases and restore access. We mirror subscription status, product identifier and access expiry in Supabase. We do not receive or store your payment card details.
- Content reports. If you report something the AI produced, we store the category you chose, anything you write in the box, and the estimate text you are reporting, tied to your anonymous account identifier. Unlike the usage records above, this one deliberately does keep the text — a report we cannot read is one we cannot act on. Nothing else about the entry is copied: not the photo, not the rest of your diary. The report form asks for your consent to this processing, including any health information in the text. Reporting is optional. Contact support@eatsleep.app to withdraw consent or request deletion of a report; erasing your account also deletes its reports.
- Service logs. Supabase and other services involved in a request generate routine security and operational logs. Depending on the service, these may include request and response metadata, IP address, user agent, timestamps, status codes, and duration. Our usage and import-diagnostic tables do not store photos or prompt text. Content reports separately retain the text you choose to report, as described above.
- Support messages. If you email support or use the feedback form, we receive the email address you send from, your message, and anything else you choose to include. Bug reports also prepare the app version, device/system label, diary-entry count, and whether Health is connected; these details are shown in the composer for you to review or remove before sending.
How long data is kept
- Account-linked usage events, import diagnostics, content reports, free-access records, and subscription-status records remain until account deletion or inactive-account cleanup. This includes the note and reported text in a content report. Our weekly cleanup selects anonymous accounts created more than 90 days ago whose last sign-in was more than 90 days ago, unless they have a current free-access period or a subscription entitlement that expires in the future or expired within the past year.
- Usage-limit counters associated with a subscription identifier may survive account deletion. Our weekly cleanup removes short-term counters older than one day and daily request, token, and video-request counters older than 90 days. These ages are cleanup thresholds; deletion occurs when the scheduled cleanup runs, rather than exactly when a threshold is reached.
- Google states that Gemini API prompts, contextual information, and outputs are retained for 55 days for abuse monitoring and legal or regulatory obligations. Content flagged by its safety systems may be reviewed by authorized personnel. EatSleep uses Gemini as a paid API service; under Google's current terms, prompts and responses submitted to paid services are not used to improve Google's products.
- Infrastructure logs and backups are retained according to the applicable provider plan and may remain for a limited period after deletion from the active database. Apple, Google, RevenueCat, Open Food Facts, and speech-recognition providers apply their own retention rules to data they receive.
- Support email is retained as long as reasonably needed to answer the request, maintain a support record, or meet legal obligations.
How we protect data
Requests to our hosted service and Gemini use HTTPS to protect data in transit. Our hosted endpoints authenticate account requests, and database access rules restrict access to account-linked records. Your local diary and photos use your device's app storage; device access and backup settings also affect their protection.
What we don't do
We don't run advertising or analytics SDKs, we don't sell personal information, and we don't use your data for anything beyond making the features above work.
Who we share data with
- Google (Gemini API) — processes the photos, text, recipe sources and exercise-estimation inputs described above. Google's abuse-monitoring and paid-service rules are described under “How long data is kept.”
- Open Food Facts — receives barcode lookups.
- Supabase — our infrastructure provider; processes AI requests and hosts your account, usage records and counters, import diagnostics, content reports, free-access records, and subscription status on our behalf.
- Apple, Google Play and RevenueCat — handle subscriptions and purchase validation. RevenueCat receives your account identifier and purchase information; Apple or Google handles payment details, depending on where you bought. Apple and Google also verify whether a device previously claimed EatSleep's free-access period. We do not send RevenueCat your diary or health data.
- Apple, Google, or another device speech-recognition provider — may process microphone audio when you choose dictation.
We do not sell personal information or share it for cross-context behavioral advertising. We do not send your diary or health data to advertising services. Independent services you use, including device speech recognition and app-store accounts, also have their own privacy terms and settings. See Apple's privacy policy, Google's privacy policy, RevenueCat's privacy policy, Supabase's privacy policy, and Open Food Facts' privacy policy. Gemini processing is governed by the Gemini API terms and abuse-monitoring rules described above.
Your choices
- Manage subscriptions. Profile → Subscription → Manage subscription opens Apple's or Google Play's controls for managing or cancelling a subscription, depending on where you bought. Deleting the app or your EatSleep account does not cancel an App Store or Google Play subscription.
- Erase EatSleep data. Profile → Data & privacy → Erase all data removes local records and photos and requests deletion of your Supabase account, including account-linked usage events, import diagnostics, content reports and their text, free-access records, and subscription status. If server deletion fails, the app offers a retry. Erasure cannot be undone. Subscription-linked usage-limit counters may remain for the periods described under “How long data is kept,” and residual copies may remain temporarily in provider backups or security logs. This action does not delete Apple, Google Play or RevenueCat purchase records, platform device-verification state, support email, records already written to Health, or data already received by other services, and it does not cancel billing.
- Request help with your data. Email support@eatsleep.app for access, correction, or deletion requests. Include the Support ID available in Profile so we can locate your anonymous account; we may need to verify the request before providing or deleting records. If you no longer have the app, see our account-deletion page.
- Choose what to share. Use manual logging without AI to keep those inputs out of AI requests. You can change Health sync settings or disconnect Health in Profile.
California residents (CCPA/CPRA)
We do not sell or share personal information for cross-context behavioral advertising, so there is no "opt out of sale" to exercise. California residents may request access to, correction of, or deletion of personal information we hold, subject to applicable law and legal exceptions. You can use the controls and contact method under “Your choices.” We do not discriminate against you for exercising applicable privacy rights. The retention exceptions above also apply to the in-app erasure control.
Washington consumer health data
See our separate Consumer Health Data Privacy Policy for health-data categories, sources, recipients, and Washington rights.
Children
EatSleep requires you to confirm you are 18 or older during setup and is not directed at children. We do not knowingly collect data from anyone under 18.
Health information
EatSleep is not a medical device and the guidance it gives — calorie targets, macro breakdowns, exercise estimates — is not medical advice. See the disclaimer shown during setup. Health, medication, and body-measurement data you enter is stored locally, with the feature-specific sharing described above, including body weight and workout details sent for AI exercise estimates when you allow AI processing. Health information you choose to include in AI inputs, content reports, or support messages is handled as described for those features. We do not sell this information. The deletion controls and retention exceptions under “Your choices” apply.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and change the effective date above. Material changes will be surfaced in the app before they take effect.
Contact us
Questions or requests about your data: support@eatsleep.app, or through the feedback form in Profile.