Last updated: 18 July 2026
This policy explains what Tainy Tracker ("Tainy", "we", "us") collects when you use our mobile app and website, why we collect it, and what control you have over it. We've tried to write it in plain English rather than legalese.
Tainy Tracker is the data controller for the information described here. You can reach us at privacy@tainytracker.com for any privacy question, or to exercise any of the rights described in section 9.
| Data | Why |
|---|---|
| Email address, name, password | To create and secure your account. Passwords are stored only as a bcrypt hash — we never store or see your actual password. |
| Food diary entries (food name, portion, calories, macros, meal, date) | The core function of the app: tracking what you eat. |
| Body details (weight, goal weight, height, age, sex, activity level) | To calculate your calorie and macro targets. Most of this stays on your device; your logged weights are stored on our servers so weight trends work across devices. |
| Phone number (optional) | Only if you verify a phone number to unlock a free trial. Used for the verification code and to prevent repeat trial claims. |
| Photos of meals | Sent for AI analysis to identify food and estimate calories. Not stored by us — see section 3. |
| Messages to the AI coach | To generate a reply. Sent together with your current stats (calories, macros, weight, goal, recent foods and workouts) so the answer is relevant. |
| Friend connections and cheers | To run the friends feature. |
| Preferences (goals, notification and privacy settings, units) | To make the app behave the way you set it up. |
| Email address submitted on our website | Only to notify you when the app launches. Nothing else. |
Meal photos are never stored on our servers. When you photograph a meal, the image is transmitted, held in memory only long enough to be analysed, and then discarded. It is not written to disk, not saved in our database, and not used to train any model. If your device keeps a copy for your own diary, that copy stays on your device.
We also don't collect your contacts, your location, or your browsing activity outside our own app and website.
Under UK and EU data protection law our lawful bases are: performance of a contract (running the app you signed up for), consent (optional analytics, notifications, and health-related information you choose to log), and legitimate interests (keeping the service secure and improving it).
Two features rely on AI provided by Anthropic:
Anthropic processes this data on our behalf as a service provider. Please note that AI estimates are approximations, not measurements — see our Terms of Service.
The friends feature is deliberately restrictive. When someone is your friend, they can see:
They cannot see your calorie numbers, your weight, your food diary, or your goals. If you switch on "Share weight progress", friends see only a direction — up, down, or steady — never a number. Every one of these can be turned off in Profile → Privacy settings, and you can remove a friend at any time.
We share data with a small number of providers strictly so the app can function:
| Provider | Purpose |
|---|---|
| Anthropic | AI meal analysis and coach replies |
| Railway | Server hosting and database |
| PostHog | Anonymous product analytics (opt-out available in the app) |
| Expo | Delivery of push notifications |
| Amazon Web Services | Sending SMS verification codes |
| RevenueCat, Apple, Google | Subscription management and payment processing |
| Our email provider | Sending account emails (welcome, password reset) |
We do not sell your personal information, and we do not share it with advertisers or data brokers.
Our servers and database are hosted in the United States. If you are in the United Kingdom or the European Economic Area, your information is therefore transferred outside your home region. Where such transfers occur, we rely on appropriate safeguards — such as standard contractual clauses offered by our providers — to protect your data.
You can do the most important things yourself, immediately, inside the app:
Depending on where you live, you also have the right to access, correct, or restrict processing of your data, to object to processing, to data portability, and to withdraw consent at any time. UK and EEA residents may lodge a complaint with their local supervisory authority (in the UK, the Information Commissioner's Office). California residents have rights under the CCPA/CPRA, including the right to know and delete personal information, and not to be discriminated against for exercising those rights — note again that we do not sell personal information.
To exercise any right not available in the app, email privacy@tainytracker.com.
We keep your account and diary data for as long as your account exists. When you delete your account, your account record is deleted from our systems. Short-lived items are removed automatically — verification and password-reset codes expire within minutes, and a reset code is destroyed after five incorrect attempts. Anonymous analytics may be retained in aggregate form that cannot identify you.
Passwords are hashed with bcrypt and never stored in readable form. Traffic between the app and our servers is encrypted in transit with HTTPS. Password resets use single-use codes that expire after 15 minutes, are limited to three requests per hour, and are invalidated after five wrong guesses. No system is perfectly secure, but we take reasonable measures appropriate to the data we hold.
Tainy Tracker is not intended for anyone under 16, and we do not knowingly collect personal information from children. Calorie tracking is not appropriate for young people without professional guidance. If you believe a child has provided us with personal information, contact us and we will delete it.
If we make material changes, we'll update the date at the top of this page and, where the change is significant, notify you in the app. Continuing to use Tainy Tracker after a change means you accept the updated policy.
Questions, requests, or complaints: privacy@tainytracker.com.