ieat — last updated 2 August 2026
ieat estimates the nutrition in your meals from photographs and from what you type, and compares the result against a daily target calculated from details you provide. This policy describes every category of data involved, why it exists, and what happens to it. It is written to be checkable: where a claim is about how the software behaves, the behaviour is the claim.
The data controller is [LEGAL ENTITY NAME], [POSTAL ADDRESS]. For any question about this policy or about your data, write to lets@eait.fit.
| Data | Collected | Linked to you | Why |
|---|---|---|---|
| Health data — dietary restrictions, allergies, and the free-text medical note you may write during onboarding | Yes | Yes | The daily target and the per-meal verdicts are computed from it. Without it the app cannot do the one thing it is for. |
| Fitness data — weight, height, year of birth, sex, activity level, goal and pace | Yes | Yes | These are the inputs to your calorie and macronutrient targets. |
| Meal records — the items, weights and nutrition figures for each meal you log, and any corrections you make | Yes | Yes | This is your diary. It is the product. |
| Apple Health data, if you connect it — a daily summary of your weight, height, body fat, lean mass, energy burned, steps, exercise minutes, workouts, distance, sleep, resting heart rate, heart-rate variability and VO2 max | Yes | Yes | Your weight keeps your calorie target current; the rest is shown to you as a trend. See “Apple Health” below. |
An account identifier — either a random device identifier generated on your phone, or the
opaque subject identifier (sub) supplied by Apple or Google if you sign in |
Yes | Yes | It is what separates your diary from everyone else's. |
| Email address | No | — | Never requested from either sign-in provider. |
| Name | No | — | Never requested from either sign-in provider. |
| Photographs | No | — | See “Your photographs” below — this is the important one. |
| Contacts, location, advertising identifiers, usage analytics | No | — | The app contains no analytics SDK and no advertising SDK. |
| Email address | Not by the app | — | The app never asks for one and cannot reach one. An address given to the form on the website is held separately — see The mailing list on the website below. |
Connecting Apple Health is optional, and nothing is read until you connect it. iOS asks your permission first, and you can change or withdraw it at any time in Settings › Privacy & Security › Health › ieat — you do not need to ask us.
We store daily totals, not your individual readings. Your phone reads the underlying samples, reduces them to one row per day, and sends only that. Every individual measurement — each weigh-in, each night's sleep segment, each heart-rate reading — stays on your phone and is never transmitted to us.
Your most recent weight updates the weight on your profile, which is what keeps your calorie target from going stale. Nothing else changes your target: your activity is already counted once, in the activity level you chose during onboarding.
We also write back. Meals you log are written into Apple Health as nutrition entries, so Health's own figures include what you ate. Those entries are yours and live on your phone — we cannot read them back or reach them from our servers. Deleting your account from the app also deletes the entries we wrote, on that phone. If you have used ieat on more than one device, or you delete the app before deleting your account, entries can remain in Health on the others; you can remove them yourself at any time in Health › Browse › Nutrition, or by deleting all data from ieat under Health › Sources.
None of this data is used for advertising or marketing, is never sold, and is never included in anything sent to the model that analyses your photographs.
A photograph of a meal is read into memory, sent to the model that estimates its nutrition, and discarded. It is never written to disk on our server, never placed in an object store, and no row in the database records a path to an image. On your phone, every photograph the app captures is deleted after the analysis completes — whether the analysis succeeded or failed.
What is kept is the result: the list of foods, their weights, and the nutrition figures. Not the picture.
This is the one place we hold an email address, and it is deliberately not part of the app.
If you enter your address in the form on eait.fit, we store that address, the date, and which link on the page you arrived from. Nothing else. We use it to tell you when the iPhone app is released, and for nothing else — no other mail, no advertising, and it is never shared with or sold to anyone.
Submitting the form does not put you on the list. We send one email asking you to confirm that the address is yours, and only the link in that email adds it. If you do not follow the link — because it was not you who typed it, or because you changed your mind — the address is deleted within seven days and you hear nothing further. The lawful basis is your consent (GDPR Art. 6(1)(a)), given by following that link rather than by filling in the form, and you may withdraw it at any time.
Every message we send carries an unsubscribe link. Following it deletes the address immediately — it is not flagged, hidden or retained in a suppression list — and it requires no account, no password and no confirmation step. You can also write to lets@eait.fit and ask us to remove it.
The list is separate from your account, and that cuts both ways. No record connects an address on this list to an ieat account, which is what lets the app go on never asking for an email and never storing one. The consequence is that deleting your ieat account does not remove your address from this list — the two are different things and have to be undone separately. Use the unsubscribe link, or write to us.
A confirmed address is held until you unsubscribe. If the app ships and the list has served its purpose, we will delete it in its entirety rather than keep it for something else.
The web server records each request it receives: the time, the path, the response code and the size. On eait.fit that is all it records. On the API the record also includes the IP address the request came from, which we keep in order to detect and limit abuse — the lawful basis is our legitimate interest in keeping the service available and its costs bounded (GDPR Art. 6(1)(f)). These logs are capped in size and rotate continuously, so an entry survives days rather than months, and nothing joins them to an account.
| Processor | What reaches them | Why |
|---|---|---|
| OpenRouter (OpenRouter, Inc.) and, through it, the model provider that serves the model we use | The photograph or the text you typed, together with the dietary restrictions and targets needed to interpret it. No account identifier, no name, no email. | This is what performs the nutrition estimate. |
| Apple / Google, only if you choose to sign in | The sign-in exchange itself. We request no scopes from either
(requestedScopes: []), so we receive an opaque identifier and nothing else. |
So your diary survives losing your phone. |
| Resend (Resend, Inc.), only if you use the form on the website | The email address you typed, and the confirmation message sent to it. Nothing from the app ever reaches them, because the app holds no address to send. | It delivers the one email this product sends. |
| Hetzner Online GmbH (Germany) | Hosting for the server and its database. | The data has to live somewhere. |
Your data is not sold, and it is not shared with anyone else. There are no advertisers and no data brokers involved, because there is no advertising in this app.
On servers in Germany. The model provider processing your photographs may operate outside the European Economic Area; where that is the case, the transfer relies on the European Commission's Standard Contractual Clauses.
Open Settings in the app and choose Delete everything. This erases your account, your profile, your meal history and your sign-in link, immediately and permanently. What remains is a genuinely new, empty anonymous account — not your old one with the diary hidden. There is no recovery afterwards, including by us.
You may also write to lets@eait.fit to request deletion, a copy of your data, correction of it, or a restriction on how it is used.
Your diary is kept until you delete your account. Sign-in tokens are revoked when you sign out. A meal proposed in chat but never confirmed expires automatically within the hour. Encrypted database backups are retained for 14 days and then destroyed.
If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation gives you the right to access your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Health data is processed on the basis of your explicit consent, which you give by entering it and may withdraw at any time by deleting your account. You also have the right to complain to your national data protection authority.
ieat is not for anyone under 16, and onboarding refuses an age below it. The reason is safety rather than paperwork: a calorie target computed for a growing body is a target that should not be computed by an app.
All traffic between the app and the server is encrypted with TLS. Every read and write in the database is scoped to your account identifier, which is resolved from your credentials and never taken from a request. Error messages are logged on the server and never returned to the app, because an error from deep in the stack can carry the text of the prompt, and the prompt can carry what you wrote about your health.
The numbers are estimates from photographs, not measurements, and the app says so on every screen that shows one. Calorie targets never go below a fixed floor regardless of what the arithmetic produces. None of it is medical advice. Talk to a doctor before making a significant change to what you eat, particularly if you have a medical condition.
If this policy changes materially, the updated version is published here with a new date before the change takes effect in the app.