Your diary, on your device

Privacy information for the local diary edition of Munch Metrics. Updated 18 September 2026.

Older versions that use email login and cloud diaries use our previous account-based privacy statement.

What stays on your phone

Your profile, meals, photos, saved foods, saved meals, portion corrections, completed-day choices and unfinished meal drafts are stored on your device. The local diary requires no sign-in and has no automatic cloud backup or cross-device sync. You can start without entering body measurements or setting targets.

Optional scanning

Before the first photo upload, the app asks you to allow AI photo processing by our Linode service and OpenAI. Camera permission alone does not enable this sharing. You can pause future photo uploads, including queued scans, in You → Privacy. An analysis already sent may finish. Your local diary and manual logging remain available without photo sharing.

When you choose AI photo scanning, a resized meal photo is sent over HTTPS to our scan service hosted on Linode and then to OpenAI to estimate its ingredients. Our service removes the upload after a successful analysis. Unused uploads expire after ten minutes and are removed by a cleanup job that runs each minute. A scan result may be cached on our service for 24 hours so a retry does not require another analysis. OpenAI applies its own API data-handling and retention policies.

The service uses a random device credential and a separate billing identifier to check scanning access. It keeps billing identifiers, trial usage and scan accounting to enforce allowances and prevent abuse. These records are separate from your diary. AI estimates may be wrong; you can review and correct them before saving.

Other services

Google sign-in is optional for the diary and identifies your scanning subscription. We verify the Google sign-in token, then retain a protected hash of your Google account ID linked to a random billing ID. We do not retain your Google email, name or sign-in token on our server. Your email and name are shown on your device alongside a separate session credential, which expires after 30 days and is excluded from diary backups.

Google also processes data through its sign-in service. Its iOS SDK privacy manifest declares account-linked name, email address, phone number, approximate location and user identifiers for sign-in functionality, and identifiers, usage data and other data for analytics. Google may infer approximate location from your IP address to prevent fraud; this does not require GPS access. These provider declarations do not mean that our app requests your phone number or that our server stores it. See Google's sign-in data disclosures and Google's privacy policy.

RevenueCat and Apple or Google process subscription status and purchases. RevenueCat also uses purchase history and billing identifiers for subscription reporting and analytics; this is not advertising tracking or analysis of your meal diary. Using the same Google account lets you access your subscription on Android and iPhone. Billing and cancellation remain with the original store. Restoring a purchase is an explicit action using the original store account. Signing out keeps your diary and does not cancel your subscription. When you use online food search or barcode lookup, the food search terms or barcode are sent to Open Food Facts. Our servers and these providers receive ordinary connection information needed to deliver their services. The app contains no advertising tracker.

Sign in with Apple is an equivalent subscription option on iPhone and supports Hide My Email. It requests only email, not your name. We verify Apple's signed identity and a single-use challenge, and keep only a protected account-ID hash linked to a random billing ID. Provider tokens are not retained. The same Apple account accesses its subscription on Apple devices. Apple and Google accounts are separate and are never combined by email.

Backups and exports

You can create a JSON diary backup or export meals as CSV from You. The JSON file includes available meal photos and can restore a diary. These files contain personal information: save them privately. Opening the share sheet does not guarantee the file was saved, so check your saved copy. Subscription credentials and unfinished scans are not included. Without a saved backup, we cannot recover a lost device diary.

Erasing your diary

You → Subscription → Delete subscription account removes its sign-in identity mapping, signs out all its devices and removes its uploaded photos and cached results. Apple accounts require a new Apple confirmation so we can revoke authorization. The local diary is kept. Limited billing, trial-use and scan-count/spend records remain to prevent fraud. This does not cancel a subscription: manage billing through the original store.

Use You → Erase this diary and type the requested confirmation to remove the open diary from this device. Other local diaries are preserved. Files you exported elsewhere remain wherever you saved them. Erasing the diary does not cancel a subscription or remove RevenueCat, store or scan-allowance records. Manage subscriptions through Apple or Google. Contact us if you need help with service-held data.

Diagnostics

The app keeps a small local history of error categories and timestamps. You can choose to export it for support. It does not include meal descriptions, photos, personal measurements or scan credentials. It is not automatically uploaded.

Contact

Email support@parktechsystems.com for privacy or data requests. Return to Munch Metrics.