Privacy Policy
Last updated:
ZomaLog is a calorie and nutrition tracker. This policy explains what we collect, why, where it's kept and for how long. In short, we use your data only to run ZomaLog for you, we never sell or share it, and you can export or delete it at any time, for free.
Before launch: ZomaLog is preparing for its public launch. This policy describes how ZomaLog works from launch. If anything changes before then, we'll update this page and its date.
Who we are
ZomaLog ("we" or "us") is responsible for your personal data (the "controller"). For any privacy question or request, email [email protected].
This policy covers the ZomaLog apps for iPhone and Android, the web app at zomalog.com/app and our website.
Our commitments
- We don't sell your personal information, and we don't share it for cross-context behavioral advertising, as California law defines those terms.
- Our apps and website have no third-party advertising or behavioral-analytics SDKs and no tracking pixels.
- Your health data never goes to advertising or marketing companies.
- Nothing goes to an AI provider until you give permission, once, in the app.
- You can export or delete your data at any time, for free.
- We honor Global Privacy Control.
- ZomaLog is for adults 18 and over.
What we collect, why, and how long we keep it
| What | Why | Where it's kept and who handles it | How long |
|---|---|---|---|
| Your diary and profile: foods and drinks you log, water, weights, recipes, saved meals, favourites, targets, setup answers (such as birth date, height, sex for the calorie equation, activity, goals, eating style and allergies), any health context you share, and your settings | To keep your diary, calculate and explain your plan, and sync your devices | Our database on a US server (Netcup, Manassas, Virginia), with encrypted backups in Cloudflare R2 and a separate encrypted copy. US Hetzner servers may hold a copy during restore tests or recovery, then are deleted. Never sent to analytics, crash reports, RevenueCat, Paddle or the AI provider | Until you delete it or your account |
| Photos: label and product-front photos when you add a product, and meal photos for Snap | To read labels, check added products and estimate meals | Cloudflare R2 private storage. Sent to the AI provider only after you allow AI, with no identifiers and no location or camera data (EXIF) | Meal photos: deleted within 1 hour after the estimate (a 24-hour cleanup is the backstop). Label and front photos: kept as product evidence until you delete your account |
| Describe text you type or dictate | To turn it into editable items | Sent to the AI provider only after you allow AI, with no identifiers | Not stored after the response |
| Searches and barcode lookups | To find foods | Sent without your account or device ID. Cloudflare caches results, and its logs aren't tied to your account | Not stored with your account. We keep daily counts of barcodes we couldn't find, per market, with nothing about who scanned them |
| Email address | Sign-in codes, account emails and, only if you opt in, marketing email | Our database. Resend sends our emails, and Paddle has it if you buy on the web. Never sent to the AI provider or analytics | Until you delete your account |
| Sign-in and devices: your Apple or Google sign-in ID, sessions, a random ID for each device, and basic device details (platform, app and system version, language) | To sign you in, sync your devices and protect your account | Our database. Apple and Google confirm your sign-in | Until you delete your account. Sessions end when you sign out or they expire |
| Purchases: your plan, where you bought it, dates and transaction IDs | To give you Plus on every device, restore purchases and handle refunds | Our database, RevenueCat (which knows you only by a random ID), Paddle, Apple and Google. Never sent to the AI provider | While you have an account, then without your account details, for accounting and tax. Raw payment notifications: 90 days |
| Usage counts | To measure speed and reliability | Our database only: daily totals with no user ID, and a daily "active" flag per account with no content | Totals are kept. Daily flags are deleted with your account |
| Crash reports | To fix bugs | Sentry, scrubbed of content and linked to a random install ID, not to your account | Until Sentry's retention period ends |
| Server logs and uptime checks | To keep ZomaLog running and secure | Grafana Cloud (logs with an internal account ID, never your content, email or searches) and Better Stack (uptime checks) | Until each service's retention period ends |
| App updates | To deliver updates | Expo sees your IP address and device details when the app checks for an update | Under Expo's retention rules |
| Apple Health (iPhone, only if you connect it) | To import your weight and add each entry's energy, protein, carbs and fat to Apple Health | On your iPhone. Imported weights join your diary. Never used for ads, marketing or analytics | Like your other weights. Disconnect anytime in Me → Apple Health |
We don't collect your exact location, your contacts or audio recordings.
Other records
- Permissions. We record each permission you give or withdraw (health data, AI, marketing email, Open Food Facts), with its version and time, until you delete your account.
- Products you add. We keep the details you confirm. After checks, confirmations or our review, a product can join the shared food catalog as open data, with its front photo shown publicly (see our Terms). We never show who added it. When you confirm someone else's product, we keep salted one-way codes of your device and network for 90 days, so no one can confirm a product twice.
- Security counters. To stop sign-in abuse, we count attempts per email and IP address using one-way codes, and erase the counts after 40 days.
- Support messages. If you email us, we use your message to help you and keep it only as long as needed.
AI features, only with your permission
ZomaLog has three optional AI features: Describe (type or dictate what you ate), Snap (a photo of your meal) and label reading when you add a missing product.
- We ask once. Before your first AI request, a permission screen names the provider, what is sent and how long it's kept. Choose Allow or Not now. Not now takes you to manual entry, and nothing is sent. You can change your answer in Me → Privacy & consents.
- What we send: only the text or photos you chose, with your language and food market. Never your name, email, account ID, device ID or IP address. Photos are resized and stripped of location and camera data.
- Dictation happens in your phone's keyboard. We receive text, never audio.
- Results are always labelled Estimate, and you can edit everything before you log it.
Our AI provider. We'll choose it in October 2026, after testing candidates. Before any AI feature is available, we'll name it on this page, together with the backup provider we switch to if the first is unavailable. Both will be paid services that don't train on our data and receive no user identifiers, and for each one we'll publish here the retention period in our contract. We don't train AI models on your data either.
Companies that handle data for us
These companies handle data for us, only to provide their service and under data processing terms:
- Netcup, US (Manassas, Virginia): hosts our server and database.
- Hetzner, US for anything with your data, EU only for tests with made-up data: short-lived servers for restore tests, recovery and load tests, deleted after each run.
- Cloudflare, including R2, worldwide network with R2 storage in eastern North America: secure connections, content delivery, attack protection, bot checks on web sign-in and cookieless analytics. R2 stores photos, exports and encrypted backups.
- Resend, US: sends sign-in codes and account emails, and marketing email if you opt in.
- Our AI provider, named here with its location before any AI feature is available: turns Describe text and photos into estimates, only after you allow AI.
- RevenueCat, US: manages App Store and Google Play purchases, knowing you only by a random ID.
- Paddle, United Kingdom: sells Plus on the web as merchant of record, handling payment, tax, receipts and refunds.
- Apple, US: Sign in with Apple, App Store downloads and purchases, and Apple Health on your iPhone if you connect it.
- Google, US: Sign in with Google and Google Play downloads, and purchases once they're available on Android.
- Sentry, US: crash and performance reports, scrubbed of content.
- Grafana Cloud, US: server logs and metrics, with no content.
- Better Stack, EU: uptime checks, alerts to our team and our status page.
- Expo, US: builds our apps and delivers app updates.
Apple, Google and Paddle also act as independent businesses under their own privacy policies. As merchant of record, Paddle keeps transaction records for web purchases as the law requires.
Open Food Facts, only if you say yes
When you first add a product, we ask, with nothing preselected, whether to share products you add with Open Food Facts, an independent open food database. If you say yes, we may send your confirmed products and their photos, with a code that doesn't reveal who you are. Your diary is never included. Photos become public there under CC BY-SA, and shared data can't be recalled. You can change your answer in the app's settings.
Other disclosures
We disclose personal data to authorities only when the law requires it, and only what's required. If ZomaLog's operator changes, for example through a sale, your data would move to the new operator under this policy, and we'd tell you first.
Cards on the free plan
Free-plan cards come from ZomaLog and are chosen by market and language only, never by your food, weight or health data. We count views and taps as daily totals with no user ID. If we ever add sponsor cards, sponsors will only see totals for groups of at least 100 people.
Cookies
We use only essential cookies and cookieless analytics. See our Cookie Policy.
Deleting data
- Deleted items: when you delete an entry or any other item, we mark it as deleted so your other devices remove it too, and erase it within 180 days.
- Account deletion completes within 24 hours, and you're signed out everywhere at once. See Delete your account.
- Backups are encrypted and roll off within 35 days of a deletion. If we ever restore a backup, we re-apply every deletion before it goes live.
- Export files are erased after 7 days, and the download link works for 24 hours.
Your rights and choices
Wherever you live, you can:
- Access and export your data: Me → Export data emails you a link to it in JSON and CSV.
- Correct it: edit entries, targets and settings in the app, or ask us.
- Delete it: delete any item, or your whole account in Me → Account → Delete account.
- Withdraw a permission in Me → Privacy & consents.
- Unsubscribe from marketing email with the link in each one.
To make a request by email, write to [email protected] from your account's address. We verify requests against your account, for example by replying to that address or asking you to sign in. Someone you authorize can ask for you, and we'll confirm with you directly. We respond within 45 days, requests are free, and using your rights never changes how we treat you.
US state privacy rights
If you live in California or another US state with a privacy law, you can also know, access, correct and delete your personal information, and opt out of its sale or sharing. We don't sell or share it, and haven't in the past 12 months. In that time we collected identifiers (like your email and account ID), commercial information (purchases), internet activity (logs and crash reports) and sensitive personal information (the health information you enter), from you, your devices, Apple Health, Apple or Google sign-in, and the stores or Paddle. We disclose it only to the companies above, for the purposes in this policy, and use sensitive personal information only to provide ZomaLog.
If you live in Washington or Nevada, our Consumer Health Data Privacy Policy also applies, including how to appeal a decision on your request.
Global Privacy Control and Do Not Track. We treat a Global Privacy Control signal as an opt-out of sale and sharing. We don't sell, share or track, so neither signal leaves anything to switch off. No third party collects information about your activity across other websites or apps through ZomaLog.
Security
- Connections to ZomaLog are encrypted.
- Our production server runs only ZomaLog and accepts no direct connections from the internet.
- Backups are encrypted and tested by restoring them.
- Staff access to admin tools requires two-step verification.
- Health data is kept out of our logs, analytics and crash reports.
No system is perfectly secure. If a breach affects your data, we'll tell you without unreasonable delay and notify authorities where the law requires. In the US, we'll notify you within 60 days at the latest.
Children
ZomaLog is for adults 18 and over. We ask for your birth date during setup. If you're under 18, setup stops and nothing is stored. If we learn that someone under 18 has an account, we delete it.
If you're in Georgia
- Where your data goes. ZomaLog's servers, including Hetzner recovery servers that hold your data, are in the United States, so your data is transferred to and stored in the US. Cloudflare may route your connection through a data center near you.
- Why we can transfer it. We rely on your consent, which you give when you create your account and accept this policy. Please know the risks: the US may not protect personal data to the same standard as Georgian law, and your rights may be harder to enforce there. You can withdraw your consent at any time by deleting your account.
- Health data consent. When you create an account, a separate checkbox, unticked by default, asks: "I agree that ZomaLog processes the health information I enter (like food, weight and goals) to run my diary and plan." You can't create an account without it. We store your answer with its version and time.
- Legal bases. Your consent for health data, AI features, marketing email and sharing with Open Food Facts; our contract with you for your account, sync and purchases; our legitimate interests for security and anonymous totals; and legal obligations for tax records.
- Your rights. You can ask for information about your data, a copy of it, and its correction or deletion, and withdraw your consent at any time. We answer within the time Georgian law sets. You can also complain to Georgia's supervisory authority for personal data protection.
Changes to this policy
The date at the top of this page shows when we last changed it. If we make a significant change, we'll tell you by email or in the app before it takes effect.
Contact
Email [email protected].