SayMyFoodSayMyFood

Privacy Policy

Last updated: 25 September 2026

SayMyFood helps you track meals and nutrition. This policy explains what we collect, why, where it is stored, and the choices you have. We collect as little as possible and keep you in control.

Who we are

SayMyFood is operated by Mikhail Levman, based in Portugal. For any privacy question or request, contact saymyfood@gmail.com.

Who can use SayMyFood

SayMyFood is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect data from anyone under 18; if you believe a minor has created an account, write to saymyfood@gmail.com and we will delete it.

What we collect and where it lives

Account data: if you create an account, your email address (and, if you sign in with Google, the basic identity Google shares) is stored by our backend provider, hosted in the European Union. Much of the app also works without an account.

Meal data: meals you save while signed in — dish names, weights, calories and macros, date/time, optional tags, meal names and notes — are stored on our backend so your diary follows your account. As a guest, meals are not saved to a server.

Profile data (optional): height, weight, age, sex, activity and goal settings you enter are used only to calculate your calorie and macro targets. For guests this stays on the device; when signed in it is stored with your account.

Meal photos: kept on your device. When you ask for recognition, the photo is sent through our secure gateway to an AI provider and the result is returned to you; we do not store the photo on our servers, unless you have opted in to the dataset contribution described below. If you delete the app or switch devices, locally stored photos are lost — we do not back them up.

Voice input: voice notes are recorded on your device and sent through our gateway to be transcribed. We do not keep the audio after transcription; the resulting text becomes part of the meal note you can see and edit.

Weight and body data: your current weight, height, age, sex and, if you enter them, body-composition figures are part of your profile and are used to calculate your targets. As a guest they stay on the device; when you are signed in they are stored with your account so your targets follow you. Your history of weigh-ins is kept only on your device and is not sent to our servers.

Device identifier: the app creates a random number and keeps it on your device; it is sent to our servers with requests and stored there. The number is needed for the app to work: it is used to count analysis limits without an account, for abuse protection, and to link support requests sent from the app. It is also used for our own statistics. Your meals and other account data are linked to your account, not to this number. The number is not used for advertising or for tracking you across other apps. When you delete your account, the number is deleted from our servers and from the device. If you then keep using the app without an account, it creates a new number that has no connection to the deleted account. If you delete the app itself, the number is deleted from the device along with it.

Diagnostics: to keep the AI pipeline working and to investigate errors, our servers keep technical logs of AI requests. These include timings, request sizes and error codes, and also the content of the analysis itself — the text sent to the model and the result returned, which can include your meal descriptions and the dishes recognised. These logs are linked to your account, are readable only by us, and are deleted when you delete your account.

Product usage events: we record which screens you open and which actions you take (for example, starting an analysis or saving a meal), together with the app version, the language and the random device number from the paragraph above, also before you sign in. The number does not contain your name, email or phone number. The events contain no meal content, photos or text. We collect them ourselves, with no third-party analytics services and no advertising.

What we do NOT do

We do not sell your data. We do not show third-party advertising. We do not use third-party analytics SDKs that profile you. Any product statistics we collect are minimal and not tied to advertising identity.

AI processing

To turn a photo, voice note or text into a recognised meal, the relevant input is sent to our server-side gateway and on to the external AI providers that act as our processors: Google (Gemini models) and OpenAI. The result is returned to your device. Before the first send the app asks for your permission; nothing is sent without it. This transfer is necessary for the core feature to work. We only use providers whose terms state that API inputs are not used to train their general models; if we change providers, we will update this list. Some processors operate outside the European Economic Area; such transfers are made under the safeguards required by the GDPR.

Optional data contribution (off by default)

You can opt in to share meal data (recognized dishes, your corrections, and the related meal photos) to improve recognition quality. This is OFF by default, described in-app before you enable it, versioned (we record which consent text you accepted and when), and you can turn it off at any time. Contributed data is stored without your name or email and is never sold or shared with advertisers.

Legal bases

We process your account and meal data to provide the service you asked for (performance of a contract). We process technical and diagnostic data to keep the service reliable and secure (our legitimate interest). The body data in your profile — weight, height, age, sex and body composition — may qualify as health data; we process it on the basis of your explicit consent, given when you enter it, and you can withdraw that consent by clearing those fields or deleting your account. The optional dataset contribution is processed on the basis of a separate, explicit consent.

How long we keep data

Account, meal and profile data are kept for as long as your account exists. Diagnostic logs are kept for the same period and are deleted together with the account. You can delete individual meals at any time. After account deletion we retain only anonymous usage counters from which every identifier has been removed.

Deleting your account

You can delete your account and all associated data directly in the app: Settings → Delete account. Deletion is immediate and irreversible and covers your meals, profile, information about your limits (test period, promo code), contributed dataset photos, voice transcripts, the AI logs linked to your account, and the device identifier the app sends with the deletion. If you cannot access the app, email saymyfood@gmail.com from your account address and we will delete your account within 30 days.

Your rights

Subject to applicable law (including the EU GDPR), you may request access to, correction of, export of, or deletion of your personal data, and withdraw the dataset-contribution consent at any time. The app includes a data export (Profile → Data). For anything else, contact saymyfood@gmail.com. You also have the right to complain to your data-protection authority.

Changes

We may update this policy. Material changes will be surfaced in-app. Continued use after an update means you accept the revised policy.