Munch Metrics

Privacy

What we collect, what we do with it, and how to get rid of it. Written to be read, not to be survived.

Last updated 19 August 2026

The short version

Do you sell my data?
No. There are no advertisers and no data brokers. There is no analytics or tracking SDK in the app at all.
What happens to my meal photos?
Deleted as soon as they're analysed. They are never used for training or review.
Can I get my data out?
Any time, free. CSV or JSON, from the You screen. Export is never behind the subscription.
Can I really delete everything?
Yes — including trial records. Nothing about your account survives deletion.

What we collect

Only what the app needs to do its job. Nothing is collected "just in case".

WhatWhy we need it
Your email address Sign in with an email code or Google sign-in. Google can supply a verified email and account identity to Supabase; Munch Metrics stores no password.
Connection and browser security signals When you request an email code, Cloudflare Turnstile checks the connection and browser environment to help stop automated attempts.
Sex, birth year, height, weight, activity level, goal To calculate your daily energy and macro targets. Nothing else uses them.
Your timezone So a late dinner lands on the right day in your time, not the phone's.
Your meals and corrections The log itself, and remembering that your usual porridge is 150 g rather than 100 g.
Meal photos Sent once to the vision model to estimate what's on the plate, then deleted. See below.
Scan counts and costs Enforcing fair-use limits and the spending caps that keep scanning affordable.

We do not request GPS or precise location, contacts, advertising identifiers or health-app data, and the app contains no third-party analytics, tracking or crash-reporting tools. An IP address can indicate an approximate area; it is used during the sign-in security check described below, not for location features. Your daily logging tallies — the ones behind the gentle "you've been logging a lot today" check-in — never leave your phone.

What the App Store privacy label should show

Munch Metrics does not track you and does not use your data for advertising or analytics. Data linked to your account and used to provide the app includes your email address, nutrition and profile information, food-log content, account ID, subscription status, scan counts and, when you choose photo scanning, the photo.

We include photos in this summary because a failed analysis may be held for a retry, even though a successful analysis is deleted promptly. We do not receive your card details, precise location, contacts, advertising identifier, crash data or performance data. Connection and browser signals used only for the sign-in security check are described below.

Meal photos, specifically

A photo of a plate also captures whatever else is in the frame, so this is the most sensitive thing the app handles and it gets the shortest life.

Uploaded, analysed, deleted

Your photo is uploaded to a private folder only you can read, sent once to the vision model, and deleted from our servers as soon as the result comes back. It is never kept for training, quality review, or anything else.

The one exception: if the analysis fails, the photo is held so you can retry. The next successful scan removes it, and deleting your account removes it regardless.

The copy shown in your meal history lives on your phone, not on our servers.

Who else is involved

We use a small number of specialist providers. None of them are advertisers.

WhoWhat reaches them
SupabaseHosting, database, sign-in and file storage — everything above lives here.
Google authenticationUsed when you choose Google sign-in. Supabase exchanges Google's identity token for your Munch Metrics session.
Cloudflare TurnstileSecurity for email-code requests. It processes the connection's IP address, TLS and other network characteristics, browser and device signals, and the Munch Metrics page address to distinguish people from bots.
OpenAIThe meal photo, at the moment you scan it. Manual entry never contacts a model.
Zoho MailYour email address, to deliver the sign-in code.
Open Food FactsJust the barcode number, when you scan one — no account, no photo, nothing that identifies you or your phone. They’re a non-profit open food database, not an advertiser.
Apple or Google stores / RevenueCatYour subscription status, if you subscribe. We never see your card details.

The security check for email-code requests

When you request an email code, a security check opens inside the app in a small web view controlled by Munch Metrics. Cloudflare Turnstile evaluates the IP address and network, browser and device signals, then returns a short-lived result that the app exchanges for a registration ticket with the separate email-code request. Google sign-in is independent of this check.

Cloudflare does not receive your email address, OTP or sign-in code, food or health data, meal photos, or Google identity token through this check. Cloudflare says it uses the security signals to provide bot protection and to improve Turnstile's bot detection. Its Turnstile Privacy Addendum explains that processing in more detail.

Free trial and subscription

Logging, your trend, your full history and data export are free forever. Photo and barcode scanning require a subscription.

We keep a count of how many scans a free trial used, so the trial can't be restarted indefinitely. That count is tied to your store account rather than your email — and it is deleted along with everything else when you delete your account.

Deleting your account

In the app: You → Delete my account. You'll be asked to type DELETE, because this cannot be undone and shouldn't be possible by mis-tap.

What "everything" means

On our servers: your profile, every meal, your saved foods and corrections, every stored photo, your subscription record, your scan counts and costs, your trial record, the account itself, and all unused, consumed or expired email-registration tickets for your email. Tickets for other accounts are not affected.

On your phone: every local table — your log, your saved foods, your onboarding answers, the local scan cache, any queued photos and your usage tallies — plus the queued photo files themselves.

If you'd like a copy first, export it from the same screen. We won't prompt you to reconsider or make you email anyone.

Getting your data out

You → Export as CSV or JSON, whenever you like, with or without a subscription. JSON gives you your profile and every meal with its ingredients; CSV gives you one row per ingredient, ready for a spreadsheet.

How it's kept safe

Your rights

You can see your data (export), correct it (edit any meal or your profile) and erase it (delete your account) — from inside the app, without asking us. If you'd rather ask a person, or you want to know what we hold about you, write to support@parktechsystems.com.

If you're in the UK, EU or another region with data-protection law, those rights are yours regardless — the buttons above are simply the fastest way to use them.