Legal

Adaptin: Privacy policy

Effective date: 13 June 2026 · Last updated: 19 August 2026

This policy explains what data Adaptin ("we", "our", "the app") collects, why we collect it, who we share it with, and the controls you have. Adaptin is a nutrition and expenditure tracker for iOS and Android.

Contact for any privacy question or request: [email protected].

1. Data we collect

1.1 Account information

  • Email address and password when you create an account with email/password, or
  • Apple Sign-In or Google identity if you choose those providers. We receive the email address and a stable user identifier from the provider; we do not receive your provider account password.

Authentication is handled by Supabase Auth (see §5). Sessions are stored encrypted on your device using the operating system's secure storage (Keychain on iOS, Keystore on Android).

1.2 Profile and preferences

  • Date of birth, sex assigned at birth, height, current weight, activity level, weight goal.
  • Timezone (synced from your device).
  • App preferences: language, energy unit (kcal/kJ), theme, reminder settings.

We use these inputs to compute your basal metabolic rate, recommended daily allowances for nutrients, and adaptive expenditure (TDEE). No coverage of sensitive categories beyond what you enter for the nutrition calculations.

1.3 Activity and log data

  • Food logs (food item, portion, timestamp, meal slot).
  • Weight logs (weight value, date).
  • Supplement logs (supplement, dose, timestamp).
  • User-created custom foods and recipes.
  • Favorites and meal-slot configuration.

1.4 User-submitted product photos

If you contribute a barcode submission (nutrition label, ingredients list, or product photo), those images are uploaded to a Supabase Storage bucket so other reviewers can verify them. Submission photos are deleted from storage once a submission is finalized.

Automated label extraction (OCR). Before you finalize a submission, you can ask Adaptin to pre-fill the nutrition fields by reading the photo. To do this, our backend sends the public submission-photo URL (not your email, user ID, or any other account identifier) to OpenRouter, which routes the request to a vision-capable large language model (currently Google Gemini or Anthropic Claude; the active model may change as we tune for accuracy). The model fetches the photo, returns structured nutrition fields, and the response is cached on our backend for up to one hour so a retry does not re-bill the model. OpenRouter, Google, and Anthropic process the photo as our subprocessors and do not, per their published API terms, use API content to train their models. You can still submit a contribution without using the automated extraction. The fields are editable either way.

1.5 Profile photo

If you set a profile photo from Settings → Edit profile, the image is resized on your device and uploaded to a separate Supabase Storage bucket (profile-avatars). Unlike barcode submission photos, your profile photo persists for as long as you choose to display it: it is replaced when you upload a new one, and deleted when you remove it or delete your account.

Your profile photo, where set, may appear to other Adaptin users on user-facing surfaces such as the leaderboard, the contributor profile, and the peer-verification screen. The storage URL is unguessable but the bucket is readable to anyone with the URL; treat your profile photo as public.

We do not run face recognition, biometric analysis, automated content moderation, or machine learning of any kind on your profile photo.

1.6 Reports and blocks

If you report another user's profile photo, display name, or other community content for abuse or infringement, we store the report (reporter user ID, reported user ID, free-text reason, timestamp) so we can review and act on it. If you block another user, we store the (blocker, blocked) pair so we can hide that user's content from your view across Adaptin.

1.7 Diagnostics and crash reports

We use Sentry to collect crash reports and unhandled errors. When you are signed in, error events are tagged with your Supabase user ID and the email address on your account so we can correlate problems to your sessions. We do not capture screen contents or food/weight values in error reports. Request bodies for natural-language logging (typed meal text, audio, and correction payloads) are stripped before an event is sent.

1.8 Device permissions we request

  • Camera: to scan barcodes and to photograph nutrition labels when you contribute a missing product. Frames are processed on your device; only the photos you explicitly attach to a submission are uploaded.
  • Photo library: only to attach a label photo or a profile photo that you pick. Adaptin does not scan or upload the rest of your library.
  • Save to photo library: only when you tap "Save image" on a shareable streak/score card.
  • Notifications: for the local meal, weigh-in, streak, and supplement reminders you enable in Settings. Reminders are scheduled on-device; we do not operate a push-notification server and do not collect a push token.
  • Microphone: only when you tap Adi (or the mic on the natural-language meal screen) to log by voice. Audio is recorded on your device, sent to our backend, then to OpenRouter for speech-to-text (see §1.10). We do not record in the background. If you deny the operating-system permission you can still type the description.
  • Apple Health / Health Connect: see §2.

1.9 What we do not collect

  • We do not run third-party advertising SDKs or share data with ad networks.
  • We do not use product analytics SDKs (no PostHog, Amplitude, Mixpanel, etc.).
  • We do not access your contacts, calendar, or precise location.
  • We do not operate push notifications and do not collect a device push token.
  • We do not sell your data.

1.10 Natural-language meal matching

If you use Adi (the in-app mascot) to log a meal by typing or speaking, you first see a consent prompt. Until you accept, we do not send the description anywhere. You can withdraw that consent later from Settings → Account & data, and you can hide Adi from Settings → Appearance (Adi is the primary way into this feature).

Typed descriptions. Our backend sends the meal text (not your email, user ID, or any other account identifier) to OpenRouter, which routes it to a large language model (currently Google Gemini or Anthropic Claude; the active model may change as we tune for accuracy). The model returns search queries and portion descriptors. We match those against our food catalog. The model does not invent calorie or nutrient numbers.

Spoken descriptions. If you use the microphone, the recording (capped at 5 MB / 60 seconds) is sent to OpenRouter's transcription API (currently OpenAI gpt-4o-mini-transcribe, with whisper-large-v3 as fallback). The transcript then takes the same parse path as typed text. Audio is not stored on our servers after the request completes.

Parse and transcription responses are cached in backend process memory for up to one hour, keyed by a hash of the text or audio, so a retry does not re-bill the model. The cache is not written to disk and does not survive a backend restart.

If you swap or reject a matched food on the confirm screen, we store that utterance and search query on your account as training data for personalization. Those rows are scoped to your user ID and are deleted when you delete your account. We do not keep a full history of everything you ever typed or said.

OpenRouter, Google, Anthropic, and OpenAI process this content as our subprocessors and do not, per their published API terms, use API content to train their models.

2. Apple HealthKit and Android Health Connect

With your explicit permission, Adaptin reads your body weight from Apple HealthKit (iOS) or Android Health Connect (Android), and on iOS may also write weight entries you log inside Adaptin back to HealthKit so your scale, Apple Health, and Adaptin stay consistent.

The following commitments are specific to Apple HealthKit and apply to all data we receive from it:

  • Data received from HealthKit is used solely to provide the in-app features you see: trending your weight, computing adaptive expenditure (TDEE), and keeping your weight history in sync with what you log inside Adaptin.
  • We will not use HealthKit data for advertising or any similar services.
  • We will not disclose HealthKit data to third parties for advertising or data-mining purposes.
  • We will not sell HealthKit data to anyone.
  • HealthKit weight readings are stored on our backend only as part of your weight log, scoped to your account.
  • You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Adaptin.

On Android, equivalent controls live in Health Connect → App permissions → Adaptin. We request the minimum permissions needed: read and write Weight.

3. How we use your data

  • Provide the calorie and nutrient tracking, expenditure, and goal features.
  • Match typed or spoken meal descriptions to foods in our catalog (see §1.10).
  • Compute personalized RDAs, ULs, and target calories from your profile.
  • Authenticate you and keep your session secure.
  • Sync your data across your devices (when signed in).
  • Diagnose crashes and fix bugs (via Sentry).
  • Detect and prevent abuse of community features (barcode submissions, peer review).
  • Comply with legal obligations.

We do not use your data to train machine-learning models. The third-party providers we use to read nutrition labels and to match meal descriptions (OpenRouter, Google, Anthropic, OpenAI; see §1.4, §1.10, and §5) likewise commit, per their published API terms, not to use API content to train their models.

If you are in the European Economic Area or the UK, we rely on:

  • Contract (Art. 6(1)(b) GDPR): to provide the service you signed up for.
  • Consent (Art. 6(1)(a), Art. 9(2)(a) GDPR): for HealthKit / Health Connect data, which is special-category health data, and for sending typed or spoken meal descriptions to AI subprocessors (see §1.10). You give HealthKit / Health Connect consent through the operating-system permission prompt, and NL consent through the in-app prompt. You can withdraw either at any time (OS settings for Health; Settings → Account & data for meal matching).
  • Legitimate interests (Art. 6(1)(f) GDPR): for crash reporting and abuse prevention, where the impact on you is minimal and necessary to keep the service running.
  • Legal obligations (Art. 6(1)(c) GDPR): when we have to respond to lawful requests.

5. Who we share data with

We do not sell or rent your data. We share it only with the subprocessors below, each of which provides infrastructure Adaptin runs on. All access is authenticated and limited to what each provider needs to perform its function.

Provider Role Region
Supabase (Supabase Inc.) Authentication, Postgres database, Storage for barcode submission photos and profile photos. EU (Frankfurt, eu-central-1)
Fly.io (Fly.io, Inc.) Hosting of the Adaptin API. EU
Sentry (Functional Software, Inc.) Crash and error reporting. EU (configurable)
Cloudflare R2 (Cloudflare, Inc.) Encrypted weekly database backups. EU
Cloudflare Pages (Cloudflare, Inc.) Hosting of this privacy / terms site. Global edge
Apple (Apple Inc.) Sign in with Apple, App Store, TestFlight, push delivery, HealthKit. Per Apple's policies
Google (Google LLC) Google Sign-In, Google Play, Health Connect. Also a vision-LLM provider (Gemini) reached through OpenRouter for OCR (§1.4: public submission-photo URL) and natural-language meal matching (§1.10: utterance text). No Adaptin account identifier. Per Google's policies
OpenRouter (OpenRouter Inc.) Routes OCR (§1.4: public submission-photo URL) to the active vision-LLM, and natural-language parse / speech-to-text (§1.10: utterance text or audio) to the active text or STT model. No Adaptin account identifier. United States
Anthropic (Anthropic, PBC) Vision-LLM provider (Claude) reached through OpenRouter for OCR (§1.4: public submission-photo URL) and natural-language meal matching (§1.10: utterance text). No Adaptin account identifier. United States
OpenAI (OpenAI, Inc.) Speech-to-text provider reached through OpenRouter for natural-language voice logging (§1.10), receives the audio clip only, no account identifier. United States

External nutrition data sources (USDA FoodData Central and Open Food Facts) are queried only from our server, and only with the food name or barcode you searched. We do not send your account identity to these services.

6. Retention

  • Account and log data is kept while your account is active. When you delete your account, all rows tied to your user ID are removed from our primary database within a few minutes (see §8).
  • Encrypted weekly backups on Cloudflare R2 are retained for up to 90 days, after which they are rotated out. Deletion requests do not rewrite historical backups, but those backups are not used to restore deleted-by-user data, are encrypted at rest, and roll off automatically.
  • Sentry events are retained for up to 90 days per Sentry's default policy.
  • Barcode submission photos are deleted from Supabase Storage as soon as a submission is finalized (approved or rejected).
  • OCR responses from the vision-LLM provider (see §1.4) are cached on our backend for up to one hour, keyed by the photo URL, so that retrying a contribution does not re-bill the model. The cache is in-process memory; it does not survive backend restarts and is not written to durable storage.
  • Natural-language parse and transcription responses (see §1.10) are cached the same way: in-process, up to one hour, keyed by a hash of the text or audio. We do not store a full history of meal descriptions. If you swap or reject a match, that utterance and search query are kept on your account until you delete it. Quota counters for this feature store only a user ID and timestamp, are pruned after about seven days, and are deleted with your account.
  • Profile photos are retained while you keep them set. They are replaced (and the previous file deleted) when you upload a new one, removed when you clear your profile photo from Settings → Edit profile, and removed when you delete your account. We may also remove a profile photo in response to a valid report (see §1.6) or a copyright notice (see Report & copyright).
  • Reports and blocks are kept while your account is active. Reports may be retained for up to 12 months after resolution to enforce the repeat-infringer policy in the Terms §12.

7. Your rights and controls

Wherever you live, you can exercise the following through in-app controls or by emailing us:

  • Access: request a copy of the data we hold about you.
  • Rectification: edit your profile fields directly in the app (Settings → Profile). For anything you can't edit yourself, email us.
  • Erasure: delete your account in Settings → Account → Delete account, or email us to do it for you.
  • Portability: request an export of your logs.
  • Withdraw HealthKit / Health Connect consent at any time in the OS settings; Adaptin will stop reading new data immediately.
  • Withdraw AI meal-matching consent in Settings → Account & data. We will stop sending new typed or spoken descriptions to subprocessors. You can also hide Adi in Settings → Appearance.
  • Lodge a complaint with your local data-protection authority if you are in the EEA or UK.

If you are in California, you additionally have the right to know, delete, and not be discriminated against for exercising your rights under the CCPA. We do not sell or share personal information for cross-context behavioral advertising.

8. Deleting your account

Open Settings → Account → Delete account. After you confirm, the app calls our backend, which deletes your authentication record and cascades the deletion to all rows we store about you (profile, food logs, weight logs, supplement logs, favorites, custom foods, recipes, expenditure snapshots, natural-language correction rows, quota counters, reports you filed, and the list of users you blocked). Your profile photo file and any pending barcode submission photos are removed from Supabase Storage at the same time. Encrypted weekly backups age out automatically per §6.

If you signed in with Apple or Google, this deletes the data we hold; it does not affect your Apple or Google account itself.

9. Security

  • All network traffic between the app and our servers is encrypted with TLS 1.2+.
  • Your Supabase session is stored on-device in the OS keychain and never written to plain disk.
  • The Adaptin API enforces row-level scoping: every database query the API issues is constrained to your user_id.
  • Direct database access from public clients is disabled (Supabase Data API off, anon role stripped of all table privileges).
  • Backups are encrypted at rest in Cloudflare R2.

No system is perfectly secure. If you believe you have found a vulnerability, please email [email protected] so we can investigate.

10. International transfers

Our primary database and API run in the European Union. If you use Adaptin outside the EU, the data you submit is transferred to and stored in the EU. Some subprocessors (Apple, Google, Cloudflare, Sentry) may process operational data across multiple regions per their own policies; where transfers leave the EEA, they rely on Standard Contractual Clauses or equivalent safeguards.

The OCR feature in §1.4 sends submission-photo URLs to OpenRouter, Google (Gemini), and Anthropic (Claude), all of which are based in the United States. Natural-language meal matching in §1.10 sends utterance text to the same OpenRouter / Google / Anthropic path, and spoken clips to OpenAI for transcription via OpenRouter. Those transfers rely on the providers' Standard Contractual Clauses for EEA / UK personal data. No Adaptin account identifier, email, or profile data is included in those requests.

11. Children

Adaptin is not directed to children under 13 (or under 16 in the EEA / UK). We do not knowingly collect data from children below those ages. If you believe a child has provided us data, email us and we will delete it.

12. Changes to this policy

If we make a material change, we will update the "Last updated" date at the top and, where the change affects how we handle data you already gave us, surface a notice in the app before the change takes effect.

13. Contact

Email: [email protected]

Operator: Adham (sole developer of Adaptin). A registered business address will be added here once the legal entity is incorporated. Until then, email is the canonical contact channel.