Privacy Policy
Privacy policy, terms of service and the medical disclaimer. These texts were written by the engineering team from what the product actually does, and are awaiting legal review — each document states its own status.
This is a draft, not a final document
The text below was written by the development team. It accurately describes what the product really does with your data, but a lawyer has not reviewed it yet. We publish it openly because collecting an email under a consent that cites "(placeholder)" would be worse. Everything that needs a decision from the owner or a lawyer is listed separately at the end — a gap there is a gap, not an invented answer.
Version 0.3.0-draft · Updated 2026-08-18
In short: we store what you enter yourself (profile, diary, weight, goals) plus the minimum technical data needed to run and secure the service. Payment details never reach us — the App Store and Google Play handle them. Health data is processed only under your separate explicit consent, which you can withdraw. Export, deletion and consent management live in the app under "Privacy" — they work today, they are not a promise.
1. Who processes your data
RESET is a nutrition and habit-change app. The controller is the legal entity providing the service; its name, registration details and address will appear here after legal review — see "What a lawyer or the owner still has to answer" at the end of this page.
RESET is a wellness product, not a medical device. It does not diagnose, treat or prescribe.
2. What we collect
The list below is the full set of categories, not a sample. Almost all of it you enter yourself; we do not buy data about you and do not gather it from third-party sources.
| Category | What exactly | Where it comes from |
|---|---|---|
| Account | Email, a password hash (we never store the password itself), or your Apple / Google identifier if you sign in with them; session tokens. | You — at sign-up |
| Profile | Name, avatar (optional), sex, age, height, current and target weight, activity level, goal and pace, timezone, language, meals per day, dietary preferences, allergen tags, disliked foods, cuisines. | You — during onboarding and in settings |
| Diary and plan | Food, water, weight and body-measurement entries, favourites and templates, saved menus and shopping lists, fasting sessions, your own corrections to food values. | You — as you use the app |
| Progress | Daily progress snapshots, streaks, achievements. | Derived from your entries |
| Progress photographs | Photographs of yourself that you choose to take, with the date and the view (front / side / back). This is off until you switch it on, and there is nothing here if you never do. | You — only if you turn the feature on |
| Friends | Friend links, invitations, shared goals, per-friend sharing settings, support reactions. | You — if you use this feature |
| Support | Your tickets and the messages in them, reports about an inaccurate food card. | You — when you write to us |
| Notifications | Push device token (APNs / FCM), your notification preferences, a log of notifications sent. | Your device — after you allow notifications |
| Subscription | Subscription and entitlement state, billing events from RevenueCat, your answer in the cancellation survey. Card details never reach us at all. | App Store / Google Play via RevenueCat |
| AI features | Your AI coach conversation; a log of your AI calls: feature, time, token count and cost. | You — when you use AI features |
| Product analytics | Events such as "screen opened" or "meal added", with a pseudonymous identifier. Email, passwords, tokens, diagnoses and similar fields are rejected at the ingest boundary — a technical guard, not a promise. | App and website |
| Technical and security data | IP address, device type, app version, timestamps of sign-in and permission changes (audit log). | Automatically, with each request |
| Website | Email and (optionally) a goal from the early-access form, together with the version and time of your consent; your cookie choice. | You — in the form on the site |
What we do not collect: bank card details, diagnoses, prescribed medication, lab results, biometric identifiers, precise location. The product has neither fields nor tables for any of it.
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR) | If you decline |
|---|---|---|
| Create an account, compute your plan, keep your diary and progress | Performance of a contract — Art. 6(1)(b) | Without this the service cannot work |
| Processing health data (weight, measurements, food entries, allergens) | Your explicit consent — Art. 9(2)(a) | You may withdraw it; some features stop, the account remains |
| Keeping progress photographs of you | Your separate explicit consent — Art. 9(2)(a) | The feature stays off and no photograph is ever taken or stored |
| Personalising recommendations and the plan | Consent — Art. 6(1)(a) | Recommendations become generic |
| Product analytics | Consent — Art. 6(1)(a) | We will not see your statistics; the service works as before |
| Emails and pushes with news and tips | Consent — Art. 6(1)(a) | Withdrawal stops delivery immediately |
| Managing your subscription and entitlements | Performance of a contract — Art. 6(1)(b) | Paid access cannot be provided without it |
| Security, abuse prevention, rate limiting | Legitimate interest — Art. 6(1)(f) | — |
| Keeping consent records and audit logs | Legal obligation and accountability — Art. 6(1)(c), Art. 7(1) | — |
4. Health data — separately and explicitly
Weight, body measurements, food entries, allergen tags and goals are health data under Art. 9 GDPR. We process them only under your separate explicit consent, which we record with its type, version, timestamp and the IP address it was given from.
This data is private by default: it is not published, not shown to other users unless you separately choose to share it, and not passed to third parties for their own purposes.
In their console, RESET administrators see only counts for your account (how many entries, when the last one was) — never the weight or diary entries themselves. That is a limit in the code, not an internal understanding.
Progress photographs are held to a stricter standard again, because a picture of your body is not the same kind of thing as a number. The feature is off until you turn it on, and turning it on asks for its own consent. Before a photograph is stored, the app strips the metadata the camera writes into the file — including where it was taken. It is then encrypted with a key generated for that single photograph, and that key is itself stored wrapped by a master key kept outside the database, so a copy of the database alone will not open it. Photographs are never shown in the administrators' console, never sent to an AI provider, and never shared with your friends or anyone else. Delete a photograph and the file itself is deleted, not hidden; delete your account and all of them go with it.
One consequence worth saying plainly: your data export contains the details of each photograph — when it was taken, which view it is — and not the image files. That keeps megabytes of your body out of an export file and out of every backup of it. The pictures themselves you download from the gallery in the app, which is the only place they are shown.
5. Who processes data on our behalf
Each of the following is a processor: it acts on our instructions and may not use your data for its own purposes. Each integration is enabled separately; where one is not configured, no data goes there at all.
One entry in the table below is deliberately not a processor, and is marked as such. Product photographs for branded groceries are published by Open Food Facts and are shown by loading them from their servers, which means your device — not ours — makes that request. Open Food Facts therefore sees the technical details any web server sees when a device asks it for an image: your IP address, the time, and your device/browser identification. They receive nothing about your account, your diary or anything you have logged, and we do not tell them who you are. We are naming it because it is a connection your device makes on our behalf, and you should not have to read our source code to find that out.
| Processor | Purpose | What it receives |
|---|---|---|
| RevenueCat | Subscriptions and entitlements | A pseudonymous account identifier and purchase events from the store. Card details pass neither through us nor through it to us. |
| Apple, Google | Sign-in, push notifications, subscription billing | A sign-in identifier; a device token for push; all payment data stays with the store. |
| OpenAI (primary), Anthropic (fallback) | Optional AI features | Only what section 6 describes. Never your email, name or weight history. |
| Sentry | Crash diagnostics | Technical crash data: stack trace, app version, device type. |
| PostHog | Product analytics | A pseudonymous identifier and event names, without sensitive fields. |
| Google Analytics 4 | Website measurement only | Nothing — until you accept analytics cookies. Before consent the script is not loaded at all. |
| Open Food Facts — NOT a processor | Photographs of branded grocery products | Your device loads the image directly from their servers, so they see your IP address, the time and your device identification — the same as any website you visit. Nothing about your account or your food diary. Foods we illustrate ourselves are served from our own servers and involve no third party. |
| Cloud provider (compute, database, file storage) | Hosting the service | All service data, in encrypted storage. |
6. AI features: what actually leaves your device
AI in RESET is an optional layer. Every AI feature can be switched off independently and nothing breaks: the plan, the diary, food search and recommendations run on rules, not on a model.
We send the provider the minimum needed for an answer:
- AI coach: your question, your daily targets (calories, protein, water) and goal, plus the titles of your current recommendations and of approved articles. Not sent: your name, email, weight history or diary.
- Photo recognition: the photo itself. We do not store that photo on our servers — only a hash of it, so a retry is not billed twice.
- Meal generator: the ingredients you said you have, your diet and allergen tags (so the recipe respects them), and your free-text note if it passes the medical-scope check.
- You confirm every AI result before it is saved: nothing lands in your diary automatically.
- We do not use AI for decisions with legal or similarly significant effects on you.
If your question moves into medical territory, the AI does not answer it — the app points you to a clinician. That check happens before the model is called, not after.
7. How long we keep it
| What | How long | How it is enforced |
|---|---|---|
| Your account and everything in it | Until you delete the account | Deletion is started from the app |
| A deletion request | 30 days to cancel, then irreversible deletion | An automated job on the server |
| Consent records | 7 years | Policy (Art. 7(1) — the duty to demonstrate consent) |
| Audit logs | 7 years | Policy |
| Security logs | 24 months | Policy |
| Analytics events | 24 months | Policy |
| Early-access email | Until you ask us to remove it | On request |
| A photo sent for recognition | Not stored | Only a hash is kept |
| Progress photographs | Until you delete them or the account | Deleting either removes the encrypted file, not just the row |
Honestly, about the difference: the 30-day cancellation window for account deletion is enforced by an automated job on the server. The remaining periods are our policy, currently honoured operationally; automated expiry against them is still to be built, and it is an open item below.
8. Your rights, and how to use them
Everything below is available in the app: "More" → "Privacy". This is not a description of intent — those screens and the server routes behind them exist and work.
| Right | How | What happens |
|---|---|---|
| Access and portability (Art. 15, 20) | "Privacy" → "Export data" | We assemble a full archive in JSON or CSV: profile, diary, weight, measurements, plan, progress, subscription, tickets, consents, and your own food corrections |
| Rectification (Art. 16) | Profile screens; edit any diary entry | Changes apply immediately |
| Erasure (Art. 17) | "Privacy" → "Delete account" | A request with a 30-day cancellable window, then irreversible deletion |
| Withdrawing consent (Art. 7(3)) | "Privacy" → the consent switches | As easy to withdraw as to give. Withdrawing marketing consent also switches delivery off immediately |
| Restriction and objection (Art. 18, 21) | Turn off personalisation and analytics in the same place | Processing for those purposes stops |
| Complaint to a supervisory authority (Art. 77) | To the authority where you live | The specific authority for our jurisdiction will be named after legal review |
We answer requests within one month (Art. 12(3)). Export and deletion run from the app immediately, with no correspondence.
10. Age
The service is for people aged 18 and over. We do not knowingly collect data from children. Your age confirmation is recorded on the server alongside your other consents.
11. How we protect your data
- Encryption in transit (TLS) and at rest; field-level encryption for the most sensitive values.
- Progress photographs get a key each: every photograph is encrypted under its own key, which is stored wrapped by a master key that is not in the database. Destroying the wrapped key destroys the picture even if the file survives somewhere.
- Passwords are stored only as hashes; the minimum length is 12 characters.
- Staff access is role-based and least-privilege; two-factor authentication is mandatory for administrators and every action is written to an audit log.
- Passwords, payment data and sensitive health data are never written to logs.
12. Transfers outside the EEA
Some processors (AI and analytics providers, for example) may process data outside the EEA. The regions involved and the transfer mechanism (standard contractual clauses or another basis) are fixed during legal review — an open item below, and not something we will invent an answer for here.
13. Changes to this policy
Every document has a version and a date, both shown at the top of this page. When you give consent we record the exact version you were shown, so what you agreed to can always be established. If a change affects a purpose that requires consent, we will ask again rather than treat silence as agreement.
14. Contacting us
The fastest route is the "Privacy" section in the app: export, deletion and consents happen there with no correspondence. For anything else, use the support centre on this site.
A dedicated mailbox for privacy requests will appear once the domain is registered — publishing an address that would bounce your request today would be worse than publishing none.
What a lawyer or the owner still has to answer
- The controller: full legal name, registration number, registered address, country.
- Whether a Data Protection Officer is required, and who it is.
- The supervisory authority for complaints, and an EU representative if one is needed.
- The actual data hosting region and the transfer basis outside the EEA for each processor (analytics and AI providers in particular).
- Data processing agreements (DPAs) signed and filed with every processor in section 5.
- Whether the 7-year / 24-month periods stand, and whether automated expiry is required (today only the 30-day account deletion runs automatically).
- An email address for privacy requests — once the domain is registered.
- Whether the admin console will ever show a user’s weight and food entries (today it shows counts only). If so, it must be described here and separately consented to.
Ready to start your transformation?
Download RESET and get a personal nutrition plan in 90 seconds.
Get early access — be among the first RESET users. Join the list