Summary
Plateful is built to keep your information on your iPhone. Meals are estimated on the phone when it can. Your body profile, weigh-ins and everything read from Apple Health stay on it. Your food log leaves it only if you sign in, and then only to your own account. A meal's words or photo go to a cloud model only while cloud estimation is on. If the app crashes, it sends us a technical report that is not linked to you, which you can turn off. We do not sell your information, and Plateful contains no advertising and no third-party analytics or tracking.
Who we are
Plateful is developed and operated by Asad Ansari, an individual developer in Ontario, Canada (“we”, “us” or “our”). We are responsible for the personal information described in this policy, which covers the Plateful app for iPhone, its widgets and Siri shortcuts, and the online service behind them. You can reach us at support@platefulhq.com.
Apple's services that Plateful uses — the App Store, Sign in with Apple, Apple Health, notifications and Private Cloud Compute — are covered by Apple's privacy policy (https://www.apple.com/legal/privacy/).
What stays on your iPhone
Your body profile (weight, height, age, sex, activity level and target weight), your goal, your weigh-ins, anything read from Apple Health, your meal photos, the corrections you make to estimates, your settings and reminders, and a diagnostic log the app keeps. None of it is sent to us, and we cannot see it.
Meal photos are stored on the phone next to the entry they belong to, and are deleted with it.
What we collect
We collect only what Plateful needs to work, and what we receive depends on the features you use:
- Account information. If you sign in with Apple, we receive an identifier Apple creates for Plateful and, if you choose to share it, your email address, which may be a private relay address from Apple. We never receive your password, and Plateful does not store or send your name, even if Apple's sign-in sheet offers to share it. We also record when your account was created.
- Your food log. When you sign in, the meals already on your iPhone and those you log afterwards are stored under your account so they can be backed up and synced to your other devices: each meal's name, time, calories and nutrients, its parts and where the numbers came from, whether you starred or edited it, and the file name of its photo. The photo itself is not uploaded. Your daily calorie and macro targets are stored too. When you delete a meal, a blank placeholder remains so your other devices delete it as well.
- Cloud estimation requests, described in the next section. Plateful's server passes them on and does not store them.
- Usage counts. The number of cloud estimates your account has used this month, so your allowance can be applied. Each cloud request also carries a random install identifier the app created and keeps on this iPhone. The server keeps a one-way hash of that identifier, and of your Apple identifier, with a count for the current and previous month, so deleting and recreating an account does not reset the allowance. The install identifier's hash is never stored with your account.
- Purchases. If you subscribe to Plateful Pro, the purchase is made through Apple, and Apple's privacy policy covers your payment details. Plateful never sees your payment method. So that a larger allowance can follow a subscription, Plateful's server keeps a record of it received from Apple: whether you have an active subscription, its product, transaction number and expiry, and whether it was refunded, with the one-way hash of your Apple identifier so the purchase can only return to the Apple Account that made it. When you subscribe while signed in, the app gives Apple your account's random identifier with the purchase, so Apple's renewal notices reach the right account. This information is not used for advertising or analytics.
- Meal reports. If you use Report an Issue on a meal, we receive your note and the estimate you are reporting — the meal's name, nutrients, parts, where its numbers came from, whether you edited it and whether it had a photo (never the photo itself) — with the time you logged it and your app and iOS versions.
- Notifications. While you are signed in, the app sends Plateful's server your iPhone's notification token, with the app version, iPhone model, iOS version and time zone, so a notification can reach you at a sensible local time. We keep a record of each notification we send you, whether it was delivered, and whether and when you opened it. The token is removed when you sign out.
- Account labels. We may label an account, for example as a tester, to decide who receives a notification.
- Barcode lookups. When you scan a barcode that is not in the app's built-in table, the barcode number is sent to Plateful's server, which may look it up in Open Food Facts and save the product for everyone who scans it. We do not link barcode lookups to your account.
- Crash reports. If Plateful crashes, iOS gives the app a technical report the next time it opens, and the app sends it to Plateful's server: the kind of crash, where in the app's code it happened, the app and iOS versions, the iPhone model, and whether it was a test build. It carries no account, no identifier, no meals and nothing you typed, and we do not link it to you. You can turn crash reports off under Settings, About & Data Sources.
- Messages to us. If you email us, we receive your email address and what you write.
- Technical logs. Our hosting provider records technical details of each request to Plateful's server, such as the IP address, the time, the part of the service used and any error, which can include your account's identifier or part of a model's reply. These logs are deleted automatically after seven days.
Cloud estimation
Plateful estimates meals on your iPhone when it can. Some meals need a cloud model: on an iPhone without Apple Intelligence, a photo on an iPhone whose on-device model reads only words, a second opinion you ask for, and, with Plateful Pro, every meal if you choose Claude as the model. Cloud estimation needs a Plateful account and your permission. Signing in during setup, on the screen that lists what leaves your iPhone, gives that permission; otherwise the app asks the first time a meal would go to the cloud. You can change or withdraw this choice at any time under Settings, Cloud Estimation.
When cloud estimation is on, the words you type or say about a meal and, for a photo, a downscaled copy of the meal photo with location and camera details removed, are sent to Plateful's server and on to Anthropic's Claude for an estimate, with nutrition facts from the app's food table and, when you correct an estimate, the estimate being corrected. Your account is used only to count the request against your allowance; nothing that identifies you is sent to Anthropic. Plateful's server does not store it. Anthropic does not use it to train models. Content flagged by Anthropic's safety systems may be retained by Anthropic for up to two years.
On an iPhone with Apple Intelligence that supports it, a second opinion can instead go to Apple's Private Cloud Compute. The meal's words, or a downscaled photo with location and camera details removed, go from your iPhone to Apple, not to Plateful's server, and no Plateful account is needed. Apple states that information sent to Private Cloud Compute is used only to fulfil the request and is not stored or made accessible to Apple. The app shows where a second opinion will go before you ask for it.
Apple Health
With your permission, Plateful writes dietary energy, protein, carbohydrates, fat and weigh-ins to Health, and reads body mass. If you also turn on activity, it reads workouts and active energy. It never reads dietary data from Health.
Everything read from Health is used only on this iPhone, to show weigh-ins and to estimate your energy balance. It is never sent to Plateful's server or to anyone else, and it is never used for advertising, marketing or data mining. Change these permissions in the Health app, or disconnect under Settings, Apple Health.
How we use information
- To provide Plateful: to sign you in, back up and sync your log, estimate the meals you send to the cloud, apply your allowance and subscription, and send the notifications you allow.
- To keep Plateful working and fair: to prevent abuse of the free allowance, keep the service secure, and find and fix faults, including from crash reports.
- To improve estimates: we read meal reports and messages to find and fix wrong estimates. We do not use your meals or photos to train machine-learning models.
- To communicate with you: to send notifications about your log and about Plateful, when your iPhone allows them, and to answer your messages. To choose who receives a notification, we may use an account's sign-up date, labels, whether it has Pro, its app version and iPhone model, when the app last checked in, and when it last logged a meal.
- To meet legal obligations, and to protect our rights and those of our users.
We do not sell your personal information, share it for targeted advertising, or use it to make decisions about you that have legal or similarly significant effects.
Legal bases
Where the law asks for a legal basis, such as in the European Economic Area and the United Kingdom, we rely on:
- Contract: providing the features you ask for — sync, cloud estimates, your allowance and your subscription.
- Consent: cloud estimation, notifications, Apple Health, and storing your food log when you sign in, to the extent it reveals information about your health. You can withdraw consent at any time, as described under Your choices; that does not affect what was done before.
- Legitimate interests: preventing abuse of the allowance, keeping the service secure, fixing faults, deciding who receives a notification, and answering reports and messages. You can object to these, as described under Your rights.
- Legal obligation: keeping or disclosing information when the law requires it.
Where information is stored
We are based in Canada, and Plateful's server and database are hosted by Supabase in Canada. Cloud estimation requests are processed by Anthropic in the United States, and Apple processes information in the United States and elsewhere. Those countries' laws may differ from those where you live. Where the law requires, these transfers rely on the safeguards in our providers' data-processing terms, such as standard contractual clauses.
How long we keep it
- Your account and what is synced to it: until you delete the account. We do not delete accounts for inactivity.
- Deleting your account under Settings, Account removes it immediately, with your food log, targets, meal reports, notification tokens, labels and usage count, and asks Apple to end Plateful's access to your Sign in with Apple. Three things stay on the server without your account: recent cloud-estimate counts, under a one-way hash, so the allowance cannot be reset by deleting; any Pro purchase record, so nobody else can claim it; and the notifications sent to you, no longer linked to you. None holds your name, email or meals. Copies in our hosting provider's backups are overwritten within seven days.
- Hashed usage counts: the current and previous month, then deleted automatically.
- A purchase record without an account: as long as the subscription can still be renewed, restored or refunded.
- Cloud estimation requests: not stored by Plateful's server. For Anthropic, see Cloud estimation.
- Technical logs: seven days.
- Crash reports: 180 days, then deleted automatically.
- Messages to us: as long as needed to deal with them.
- On your iPhone: until you delete it or the app. Deleting the app removes everything Plateful stores on the iPhone except two small items iOS keeps in the Keychain after an app is deleted: your sign-in session, if you were signed in, and the install identifier. Erasing the iPhone removes both. Your iPhone's own backups, which Apple manages, may include Plateful's data.
Security
Information travels between your iPhone and Plateful's server encrypted, and our hosting provider encrypts it at rest. Row-level security lets each account read and change only its own data through the app. We can access stored data through our hosting provider's dashboard, and do so only to run and support Plateful, to look into a report, or when the law requires it. The identifiers kept after an account is deleted are salted one-way hashes, and meal photos on the iPhone are protected by iOS file encryption.
No system is perfectly secure. If a breach affects your information, we will tell you, and the authorities, where the law requires.
Your choices
- Cloud estimation: change or withdraw it under Settings, Cloud Estimation.
- Apple Health: change permissions in the Health app, or disconnect under Settings, Apple Health and, if you want, remove everything Plateful wrote to it.
- Notifications: turn them off in your iPhone's Settings, under Notifications, Plateful. Meal reminders have their own switch under Settings, Meal Reminders.
- Crash reports: turn them off under Settings, About & Data Sources, Send Crash Reports.
- Your account: sign out or delete it under Settings, Account.
- Your iPhone: delete a meal from your log, or delete the app to delete everything on the phone except the Keychain items described above.
Your rights
Depending on where you live, you may have the right to know what personal information we hold about you and to get a copy of it in a portable format; to have it corrected or deleted; to object to or restrict how we use it; and to withdraw your consent. Much of this you can do in the app: your log is there to view and correct, and Delete Account removes it from our server. For anything else, email support@platefulhq.com.
We answer within 30 days. We may ask you to confirm that a request comes from you, for example by sending it from the email address on the account. We will not treat you differently for exercising these rights.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or, if you live elsewhere, to your local data protection authority.
California residents
In the past 12 months we collected these categories of personal information, as California law defines them: identifiers (your Apple account identifier, email address, notification token and install identifier); commercial information (subscription records); internet or other electronic network activity (technical logs, and whether you opened a notification); visual information (meal photos sent for cloud estimation, which are not stored); and information about your meals, which may relate to your health. We collected it from you, your iPhone and Apple, used it for the purposes above, and disclosed it only to the service providers named above. We do not sell or share personal information, as those terms are defined in California law, and we use sensitive personal information only to provide Plateful. You have the rights to know, delete and correct your information, and not to be discriminated against for using them.
Children
Plateful is not intended for children under 13, and we do not knowingly collect their information. If you are under the age at which you can agree to this policy where you live, use Plateful only with a parent's or guardian's permission. If you believe a child under 13 has given us personal information, contact us and we will delete it.
Changes to this policy
We will update this policy when Plateful's handling of information changes. The date at the top shows when it last changed. If a change matters, we will tell you in the app and ask you to agree again before you next sign in or connect Apple Health. The current version is always available in the app under Settings, About, and at https://platefulhq.com/privacy/.
Contact
Asad Ansari, Ontario, Canada. Email support@platefulhq.com. For a privacy request, please put “Privacy” in the subject line.