EatSleep Privacy Policy
Effective date: September 13, 2026
EatSleep is operated by Pinotech LLC ("Pinotech," "we," "us"), a company organized in California, USA. This policy explains what EatSleep collects, why, where it goes, and how to delete it.
The short version
EatSleep is built to keep your data on your phone. Your food log, weight, sleep, exercise, medication records, and progress photos are stored locally. They leave your phone only when a feature needs them: for example, when you ask AI to analyze a meal or recipe, request an AI exercise estimate, scan a barcode, use dictation, connect a Health service, or contact support. We also record a limited amount of account, subscription, usage, and import-diagnostic data to operate the service. The details are below. We do not sell your data, and we do not use advertising or tracking SDKs.
What we collect, and where it goes
Your diary and Health connections
Your profile (age, sex, height, weight, activity level), food and exercise log entries, weigh-ins, sleep sessions, saved recipes, GLP-1/medication records, and progress photos are stored locally on your phone. Your diary is not uploaded to our servers; the specific feature inputs described below are the exceptions. Your operating system or a backup service you enable may back up app data under its own settings and policy. If you connect Apple Health or Health Connect, the app can read the health data you permit, including body measurements, activity, sleep and available overnight vitals. With your permission and the corresponding sync settings enabled, it can also write nutrition, weight and manually logged sleep to Health. Records already written to Health remain there when you erase EatSleep's data; manage those records in Health separately.
Sent to make a specific feature work
- Meal photos. When you photograph a meal for AI estimation, the photo is sent to our backend, which forwards it to our AI provider (currently Google Gemini) to identify the food and estimate its nutrition. We don't store the image in our application database or file storage. Our infrastructure and Google may retain request data under the provider-retention terms below.
- Progress (body) photos are different: EatSleep does not transmit them. They exist only to compare your own photos to each other over time. Your device's backup service may include app files if you have backups enabled.
- AI text, corrections and recipe imports. Meal and exercise descriptions, corrections, and recipe text, images or video links you submit for AI processing are sent through our backend to Gemini. Importing a recipe link also contacts the source website and may contact a video or caption host to retrieve public content. Those services receive the requested URL or resource identifier and ordinary network information such as an IP address and user agent. A video link may be provided to Gemini for video understanding.
- Barcode scans are looked up against Open Food Facts, a public, crowd-sourced nutrition database, so we can show you the product. This is a read-only lookup. We do not include your EatSleep account or diary data, but Open Food Facts receives the barcode and ordinary network information needed to answer the request.
- Exercise estimates. AI calorie-burn requests include the exercise description, duration and your current body weight when available. This also applies when an imported Health workout needs an AI estimate because its calorie data is missing. These inputs are forwarded to Gemini; our usage records do not store the body-weight value or request text.
- Dictation. When you tap a microphone button, your device's native speech recognition service turns your voice into text. Depending on the device, language, and available speech model, Apple, Google, or the device's selected recognition provider may process the audio over the network. EatSleep does not store the audio recording; it receives the resulting transcript, which is then handled like text you typed.
Recorded on our server
- An anonymous account identifier. On first use, the app creates an anonymous account with Supabase so AI requests can be metered. The app does not ask for or link an email address to this account.
- Usage records. Each AI request records which feature was used, whether it succeeded, how long it took, and token counts, tied to your account identifier. This is how we enforce daily usage limits and understand whether the service is priced and provisioned correctly. It never includes the photo or the text you sent — only the fact that a request happened.
- Recipe-import diagnostics. We record whether an import succeeded, failed, or was refused; which import route was used; counts such as caption length, page count, links found, and video duration; and a broad error category. A failed import may also retain the submitted source URL so we can diagnose sites that the importer cannot read. Successful and deliberately refused imports do not retain the URL, caption, transcript, or recipe text. These records are tied to your anonymous account identifier.
- Subscription information. Apple handles iOS subscription billing. RevenueCat receives your EatSleep account identifier and App Store purchase information to validate purchases and restore access. We mirror subscription status, product identifier and access expiry in Supabase. We do not receive or store your payment card details.
- Service logs. Supabase and other services involved in a request generate routine security and operational logs. Depending on the service, these may include request and response metadata, IP address, user agent, timestamps, status codes, and duration. We do not deliberately write advertising identifiers, photos, or prompt text to our application event tables or console messages.
- Support messages. If you email support or use the feedback form, we receive the email address you send from, your message, and anything else you choose to include. Bug reports also prepare the app version, device/system label, diary-entry count, and whether Health is connected; these details are shown in the composer for you to review or remove before sending.
How long data is kept
- Our account, usage, import-diagnostic, and entitlement records remain while the anonymous account is active. Inactive anonymous accounts without a recent paid entitlement are scheduled for deletion after 90 days.
- Google states that Gemini API prompts, contextual information, and outputs are retained for 55 days for abuse monitoring and legal or regulatory obligations. Content flagged by its safety systems may be reviewed by authorized personnel. EatSleep uses Gemini as a paid API service; under Google's current terms, prompts and responses submitted to paid services are not used to improve Google's products.
- Infrastructure logs and backups are retained according to the applicable provider plan and may remain for a limited period after deletion from the active database. Apple, RevenueCat, Open Food Facts, and speech-recognition providers apply their own retention rules to data they receive.
- Support email is retained as long as reasonably needed to answer the request, maintain a support record, or meet legal obligations.
What we don't do
We don't run advertising or analytics SDKs, we don't sell personal information, and we don't use your data for anything beyond making the features above work.
Who we share data with
- Google (Gemini API) — processes the photos, text, recipe sources and exercise-estimation inputs described above. Google's abuse-monitoring and paid-service rules are described under “How long data is kept.”
- Open Food Facts — receives barcode lookups.
- Supabase — our infrastructure provider; hosts your anonymous account, usage records and entitlement status. Supabase is a processor acting on our instructions, not an independent recipient of your data.
- Apple and RevenueCat — handle iOS subscriptions and purchase validation. RevenueCat receives your account identifier and purchase information; Apple handles payment details. We do not send RevenueCat your diary or health data.
- Apple, Google, or another device speech-recognition provider — may process microphone audio when you choose dictation.
We do not sell personal information to anyone, and none of the above use your data for their own advertising purposes.
Your choices
- Manage subscriptions. Profile → Subscription → Manage subscription opens Apple's controls for managing or cancelling a subscription. Deleting the app or your EatSleep account does not cancel an App Store subscription.
- Erase EatSleep data. Profile → Data & privacy → Erase all data removes local records and photos and requests deletion of your Supabase account, including usage history and entitlement status. If server deletion fails, the app offers a retry. Erasure cannot be undone. Residual copies may remain temporarily in provider backups or security logs. This action does not delete Apple or RevenueCat purchase records, support email, records already written to Health, or data already received by other services, and it does not cancel billing.
- Choose what to share. Use manual logging without AI to keep those inputs out of AI requests. You can change Health sync settings or disconnect Health in Profile.
California residents (CCPA/CPRA)
We do not sell or share personal information for cross-context behavioral advertising, so there is no "opt out of sale" to exercise. California residents may request to know what personal information we hold and to delete it, subject to legal exceptions; "Erase all data" in the app performs the deletion directly, or you can email us at support@eatsleep.app.
Users in the EU/UK (GDPR)
Our lawful basis for processing is performance of the service you've asked for (delivering AI estimates, enforcing usage limits) and our legitimate interest in operating EatSleep reliably. You may request access to or deletion of your data via the in-app erasure control or by emailing us. Because EatSleep does not collect a name or account email, account deletion is self-served in the app. Contact us to request access to server-side records. You may also have rights to correction, restriction, objection, portability, and to complain to your local supervisory authority.
Children
EatSleep requires you to confirm you are 18 or older during setup and is not directed at children. We do not knowingly collect data from anyone under 18.
Health information
EatSleep is not a medical device and the guidance it gives — calorie targets, macro breakdowns, exercise estimates — is not medical advice. See the disclaimer shown during setup. Health, medication, and body-measurement data you enter is treated with the same handling described above: stored locally, never sold, and included in "Erase all data."
Changes to this policy
If we change what we collect or how we use it, we'll update this page and change the effective date above. Material changes will be surfaced in the app before they take effect.
Contact us
Questions or requests about your data: support@eatsleep.app, or through the feedback form in Profile.