EatWell

EatWell Privacy Policy

Version: privacy-2026-07-26-draft.4 · Effective: 21 July 2026 Status: In force — approved by legal counsel Last updated: 16 September 2026 — sharing your dietitian's program with the assistant and anonymous usage analytics (TelemetryDeck) added

If you create an account, we may process your name, e-mail and account identifier. When you use the app, we may process nutrition, water, weight, goal and preference records. App Store product and transaction-verification data is processed when you purchase. HealthKit categories are accessed only with permission. Camera, audio, lab and AI data is not collected while those features are disabled.

We use data to operate your account and diary, provide insights, deliver purchase entitlements, synchronise records, maintain security and answer support requests. We do not sell health data or use it for advertising.

Anonymous usage analytics are on by default. To improve the app, usage events such as which screens were opened, at which step you left, whether an action succeeded and session length are sent to our own servers and to our analytics provider TelemetryDeck GmbH (Germany, EU). This data contains no name, e-mail, account identifier, text you write, photos or health value. A random identifier generated for the device is one-way hashed on your device before it is sent and is not linked to your account; technical details such as device model, OS and app version, language and region are added. You can turn this off any time with the “Anonymous analytics” switch in Profile › Privacy; sending stops and pending events on the device are deleted.

iOS permissions for camera, Photos, microphone, speech recognition, notifications, Face ID and HealthKit are requested only for relevant features and can be revoked in Settings. Apple and Google/Firebase may be used for identity, Apple processes in-app purchases, and Google's Gemini API powers the AI features (explained below). The final processor list and data regions must be published before launch.

Your health data is shared with no one unless you connect to a dietitian. When you connect you pick the categories individually, and the dietitian sees only the last 28 days. Connecting also makes your previous 28 days visible — we state this on the connect screen before you connect. Stopping sharing closes access immediately, including the past. A dietitian cannot edit or delete your records.

When you ask the AI assistant a question, log a meal or water by typing, or send a meal photo for recognition, the content goes through our server to Google's Gemini API: your question; your sentence with your device's date, time and time zone; or the photo (metadata including location is removed on your device). If “Allow AI Assistant to use this profile” is on in your health profile, your age, height, weight, diet preference, condition and allergy categories are added to questions. If the separate “Let the assistant see my dietitian's program” option is on, the eat and avoid lists and the calorie, protein and water targets of your dietitian's program running that week are added too. Both options are off by default. Your name, e-mail, medications, supplements, your dietitian's name and program note, and earlier messages are not sent. Google does not use this content to improve its products or train models; it may log it for a limited period only to prevent abuse. The Gemini API runs outside Türkiye. Your question, sentence and photo are not stored on our server. The generated answer (assistant reply, meal draft, recognition result) is kept against your account for 30 days so a repeated request is not processed twice, and is deleted when that period ends or when you delete your account. The AI never logs a meal on its own; you confirm each draft.

Your AI chat history — conversation, typed-logging drafts and photo result cards — is stored on your device only, in a protected area reserved for your account, excluded from device backups and not sent to our server. The newest 300 items are kept, and the small photo previews in cards are deleted after 14 days. You can delete the history any time in Profile › “Clear AI chat history” or from the chat menu; it is also deleted when you delete your account. Meals already in your diary stay.

If you log a meal with a photo, the image stays on your device for 14 days and is deleted the next time you open the app after that; the meal record stays. You can delete any photo at any time. While dietitian sharing is off, photos do not leave your device; once you enable nutrition sharing the image is also stored on our server for 14 days and your dietitian views it through a short-lived link. Stopping sharing and deleting your account both delete the server-side images. Audio and lab document images are never retained after processing.

If you prepare a weekly check-in for a dietitian, the progress photos (up to three angles), your weight and waist measurement, your mood, the private note for your dietitian and the log-adherence preview calculated on the device are stored on your device only, in a protected area marked to be excluded from device backups. This content is not sent to our server and is not shared with your dietitian. Photo metadata is removed on save. When a new week starts the previous week's photos are deleted from your device, and replacing a photo deletes the old one. Remaining drafts are deleted when you delete your local drafts or your account. The 14-day rule for meal photos does not apply here: check-in photos are not deleted by a timer, only by the events above.

We use data minimisation, transport encryption, protected local storage, account isolation and access controls. You may delete your account in the app, revoke optional sharing and health consent, and manage system permissions. The app is not directed to anyone under 18 and blocks under-18 registration.

Privacy: privacy@geteatwell.app · Support: support@geteatwell.app · Controller: Harun Yardımcı, Esentepe Mah. Anadolu Cad. And Pastel Sitesi B3/84, Kartal/İstanbul, Türkiye