Munch Metrics
Privacy
What we collect, what we do with it, and how to get rid of it. Written to be read, not to be survived.
Last updated 19 August 2026
The short version
- Do you sell my data?
- No. There are no advertisers and no data brokers. There is no analytics or tracking SDK in the app at all.
- What happens to my meal photos?
- Deleted as soon as they're analysed. They are never used for training or review.
- Can I get my data out?
- Any time, free. CSV or JSON, from the You screen. Export is never behind the subscription.
- Can I really delete everything?
- Yes — including trial records. Nothing about your account survives deletion.
What we collect
Only what the app needs to do its job. Nothing is collected "just in case".
| What | Why we need it |
|---|---|
| Your email address | Sign in with an email code or Google sign-in. Google can supply a verified email and account identity to Supabase; Munch Metrics stores no password. |
| Connection and browser security signals | When you request an email code, Cloudflare Turnstile checks the connection and browser environment to help stop automated attempts. |
| Sex, birth year, height, weight, activity level, goal | To calculate your daily energy and macro targets. Nothing else uses them. |
| Your timezone | So a late dinner lands on the right day in your time, not the phone's. |
| Your meals and corrections | The log itself, and remembering that your usual porridge is 150 g rather than 100 g. |
| Meal photos | Sent once to the vision model to estimate what's on the plate, then deleted. See below. |
| Scan counts and costs | Enforcing fair-use limits and the spending caps that keep scanning affordable. |
We do not request GPS or precise location, contacts, advertising identifiers or health-app data, and the app contains no third-party analytics, tracking or crash-reporting tools. An IP address can indicate an approximate area; it is used during the sign-in security check described below, not for location features. Your daily logging tallies — the ones behind the gentle "you've been logging a lot today" check-in — never leave your phone.
What the App Store privacy label should show
Munch Metrics does not track you and does not use your data for advertising or analytics. Data linked to your account and used to provide the app includes your email address, nutrition and profile information, food-log content, account ID, subscription status, scan counts and, when you choose photo scanning, the photo.
We include photos in this summary because a failed analysis may be held for a retry, even though a successful analysis is deleted promptly. We do not receive your card details, precise location, contacts, advertising identifier, crash data or performance data. Connection and browser signals used only for the sign-in security check are described below.
Meal photos, specifically
A photo of a plate also captures whatever else is in the frame, so this is the most sensitive thing the app handles and it gets the shortest life.
Uploaded, analysed, deleted
Your photo is uploaded to a private folder only you can read, sent once to the vision model, and deleted from our servers as soon as the result comes back. It is never kept for training, quality review, or anything else.
The one exception: if the analysis fails, the photo is held so you can retry. The next successful scan removes it, and deleting your account removes it regardless.
The copy shown in your meal history lives on your phone, not on our servers.
Who else is involved
We use a small number of specialist providers. None of them are advertisers.
| Who | What reaches them |
|---|---|
| Supabase | Hosting, database, sign-in and file storage — everything above lives here. |
| Google authentication | Used when you choose Google sign-in. Supabase exchanges Google's identity token for your Munch Metrics session. |
| Cloudflare Turnstile | Security for email-code requests. It processes the connection's IP address, TLS and other network characteristics, browser and device signals, and the Munch Metrics page address to distinguish people from bots. |
| OpenAI | The meal photo, at the moment you scan it. Manual entry never contacts a model. |
| Zoho Mail | Your email address, to deliver the sign-in code. |
| Open Food Facts | Just the barcode number, when you scan one — no account, no photo, nothing that identifies you or your phone. They’re a non-profit open food database, not an advertiser. |
| Apple or Google stores / RevenueCat | Your subscription status, if you subscribe. We never see your card details. |
The security check for email-code requests
When you request an email code, a security check opens inside the app in a small web view controlled by Munch Metrics. Cloudflare Turnstile evaluates the IP address and network, browser and device signals, then returns a short-lived result that the app exchanges for a registration ticket with the separate email-code request. Google sign-in is independent of this check.
Cloudflare does not receive your email address, OTP or sign-in code, food or health data, meal photos, or Google identity token through this check. Cloudflare says it uses the security signals to provide bot protection and to improve Turnstile's bot detection. Its Turnstile Privacy Addendum explains that processing in more detail.
Free trial and subscription
Logging, your trend, your full history and data export are free forever. Photo and barcode scanning require a subscription.
- Before you start a trial, the app shows you the exact price and the date you'll first be charged. If a real price can't be loaded from the store, the buttons stay switched off rather than showing you a made-up number.
- A trial converts to a paid subscription automatically unless you cancel first. We send you a reminder 48 hours before that happens — you don't have to remember on your own.
- Cancel any time in your App Store or Google Play subscription settings. It takes the same few taps to cancel as it did to subscribe.
- Cancelling keeps your access until the end of the period you've already paid for.
- Your log, your history and export stay free and fully available after a subscription ends. Nothing you have written is ever held hostage.
We keep a count of how many scans a free trial used, so the trial can't be restarted indefinitely. That count is tied to your store account rather than your email — and it is deleted along with everything else when you delete your account.
Deleting your account
In the app: You → Delete my account. You'll be asked to type
DELETE, because this cannot be undone and shouldn't be possible by
mis-tap.
What "everything" means
On our servers: your profile, every meal, your saved foods and corrections, every stored photo, your subscription record, your scan counts and costs, your trial record, the account itself, and all unused, consumed or expired email-registration tickets for your email. Tickets for other accounts are not affected.
On your phone: every local table — your log, your saved foods, your onboarding answers, the local scan cache, any queued photos and your usage tallies — plus the queued photo files themselves.
If you'd like a copy first, export it from the same screen. We won't prompt you to reconsider or make you email anyone.
Getting your data out
You → Export as CSV or JSON, whenever you like, with or without a subscription. JSON gives you your profile and every meal with its ingredients; CSV gives you one row per ingredient, ready for a spreadsheet.
How it's kept safe
- Every table is access-controlled per user at the database level — not just in the app.
- Photos live in a private bucket readable only under your own account folder.
- There is no password to steal. Sign-in codes are single-use and expire after an hour.
- The keys that could bypass any of this exist only on the server, never in the app.
Your rights
You can see your data (export), correct it (edit any meal or your profile) and erase it (delete your account) — from inside the app, without asking us. If you'd rather ask a person, or you want to know what we hold about you, write to support@parktechsystems.com.
If you're in the UK, EU or another region with data-protection law, those rights are yours regardless — the buttons above are simply the fastest way to use them.