MunchMetrics
What we collect, what we do with it, and how to get rid of it. Written to be read, not to be survived.
Last updated 4 August 2026
Only what the app needs to do its job. Nothing is collected "just in case".
| What | Why we need it |
|---|---|
| Your email address | It's the only way to sign in. We email you a one-time code — there is no password to store or leak. |
| Sex, birth year, height, weight, activity level, goal | To calculate your daily energy and macro targets. Nothing else uses them. |
| Your timezone | So a late dinner lands on the right day in your time, not the phone's. |
| Your meals and corrections | The log itself, and remembering that your usual porridge is 150 g rather than 100 g. |
| Meal photos | Sent once to the vision model to estimate what's on the plate, then deleted. See below. |
| Scan counts and costs | Enforcing fair-use limits and the spending caps that keep scanning affordable. |
We do not collect location, contacts, advertising identifiers or health-app data, and the app contains no third-party analytics, tracking or crash-reporting tools. Your daily logging tallies — the ones behind the gentle "you've been logging a lot today" check-in — never leave your phone.
A photo of a plate also captures whatever else is in the frame, so this is the most sensitive thing the app handles and it gets the shortest life.
Your photo is uploaded to a private folder only you can read, sent once to the vision model, and deleted from our servers as soon as the result comes back. It is never kept for training, quality review, or anything else.
The one exception: if the analysis fails, the photo is held so you can retry. The next successful scan removes it, and deleting your account removes it regardless.
The copy shown in your meal history lives on your phone, not on our servers.
We use a small number of service providers. None of them are advertisers.
| Who | What reaches them |
|---|---|
| Supabase | Hosting, database, sign-in and file storage — everything above lives here. |
| OpenAI | The meal photo, at the moment you scan it. Manual entry never contacts a model. |
| Zoho Mail | Your email address, to deliver the sign-in code. |
| Apple / Google / RevenueCat | Your subscription status, if you subscribe. We never see your card details. |
Logging, your trend, your full history and data export are free forever. Scanning a photo is the paid part.
We keep a count of how many scans a free trial used, so the trial can't be restarted indefinitely. That count is tied to your store account rather than your email — and it is deleted along with everything else when you delete your account.
In the app: You → Delete my account. You'll be asked to type
DELETE, because this cannot be undone and shouldn't be possible by
mis-tap.
On our servers: your profile, every meal, your saved foods and corrections, every stored photo, your subscription record, your scan counts and costs, your trial record, and the account itself.
On your phone: every local table — your log, your saved foods, your onboarding answers, the local scan cache, any queued photos and your usage tallies — plus the queued photo files themselves.
If you'd like a copy first, export it from the same screen. We won't prompt you to reconsider or make you email anyone.
You → Export as CSV or JSON, whenever you like, with or without a subscription. JSON gives you your profile and every meal with its ingredients; CSV gives you one row per ingredient, ready for a spreadsheet.
You can see your data (export), correct it (edit any meal or your profile) and erase it (delete your account) — from inside the app, without asking us. If you'd rather ask a person, or you want to know what we hold about you, write to support@parktechsystems.com.
If you're in the UK, EU or another region with data-protection law, those rights are yours regardless — the buttons above are simply the fastest way to use them.