OFood Calories — Privacy Policy
v1. English is the governing language. Effective upon publication at this URL. Keep consistent with the App Store privacy questionnaire and PrivacyInfo.xcprivacy.
Controller: OFOOD LLC · Contact: info@ofood.org
What we collect, and why
When you use the food-recognition features, we collect:
- Food photos you confirm (each photo is checked on-device for people first);
- the food name you confirm and, where you provide it, the portion size,
together with the app's recognition results for that photo;
- technical capture data from the camera and motion sensors — never your
location;
- a random device identifier and basic device information (model, OS,
app version);
- anonymous usage statistics — counts and timings only (for example how fast
recognition ran, or which way you confirmed a food), sent to our own servers.
These never include your photos, food names, or diary contents, and never go
to any third party.
We use this to improve food recognition and portion estimation for everyone, to
keep the service reliable, and to prevent abuse. That is what keeps OFood free.
What we deliberately do NOT collect
- Photos containing people. An on-device check runs before any analysis;
if a person is detected, the photo is not analyzed, not stored, not uploaded.
- Your food diary and calorie history (on-device only).
- Names, emails, phone numbers, contacts, precise or coarse location.
- Embedded photo metadata: uploads are re-encoded pixel data without EXIF/GPS.
- Apple Health data (written to Health locally with your permission; never read
back except our own entries for delete-sync; never uploaded).
- Advertising identifiers. No ads, no tracking, no third-party analytics SDKs.
Storage, review, retention
Uploads land in a quarantine queue in private cloud storage (Wasabi, us-west-1) reviewed by us. Rejected items are deleted. Accepted
items become part of our research datasets permanently (see Terms §3).
Pending (not yet accepted) items are deleted when you use
Settings → Delete my uploads, or on our routine queue cleanup.
Your choices and rights
- Consent regions (EU/EEA, UK, CH): uploads happen only after explicit consent;
withdraw anytime in Settings — recognition keeps working on-device.
- Anyone: Settings → Delete my uploads removes pending contributions tied to
your device identifier.
- Questions or requests: ofoodllc@gmail.com.
Security
Transport encryption (TLS) for all uploads; hardware-backed app attestation
(Apple App Attest) so only genuine copies of the app can submit; private,
access-controlled storage.
Children
The service is not directed at children under 13 (or the applicable age in your
region).
Changes
Material changes will be shown in the app and reflected at this URL
(https://api.ofood.org/legal/privacy) with a new effective date.