Privacy Policy
Effective date: 26 June 2026 · Last updated: 29 August 2026
Eatrace helps you find restaurant dishes nearby that fit your nutrition goals. Because Eatrace works with health and fitness information — your weight, body metrics, calorie and macro goals, and the meals you log — we take what we collect, and what we don't, seriously. This policy explains exactly what data Eatrace processes, why, who we share it with, and the controls you have.
1. Who we are
Eatrace (the "app", "we", "us") is operated by Cleolead Corp. of Alberta, Canada. We are the data controller for the personal data described here. For any privacy question or request, contact us at info@eatrace.app.
2. What we collect & why
We only collect what the app needs to function. The table below lists every category of personal data we process, why, and the purpose it serves.
| Data | What it is | Why we use it |
|---|---|---|
| Account identity | Your email address and a Supabase Auth user ID. If you choose "Continue with Apple" or "Continue with Google", we receive the email (or Apple relay email) from that provider. | To create and secure your account, sign you in, and send password resets and essential service emails. |
| Health & fitness profile | Sex, age, weight, height, activity level, and your goal (lose / gain / maintain). From these we compute your calorie and macro (protein / carbs / fat) targets. | To calculate your daily nutrition targets and score how well dishes fit them. This is health data and is treated with extra care. |
| Logged meals & macros | Dishes and foods you add to your tracker, their calories and macros, barcodes you scan, and your saved meals and tracker history. | To show your daily progress, history, and weekly reports, and to power Smart Pick recommendations. |
| Precise location | Your device GPS coordinates, only while the app is in use, and only after you grant the OS permission. Used in the moment and not stored on our servers. | To find restaurants near you and rank dishes by distance. See section 5. |
| Approximate country | A coarse country code derived from your network connection (Cloudflare's cf-ipcountry header) when your app calls our backend. We do not store your IP address for tracking. |
To choose region-appropriate content and meet regional legal requirements. |
| Meal photos | Photos you choose to take of a meal. Sent for AI identification, and — when you log the meal — kept in private storage attached to that meal, readable only by your account. See section 5. | To recognise a dish or food and estimate its macros so you can log it, and to show the meal’s own photo in your log. |
| Purchases & entitlements | Your subscription status and entitlement. On iOS/Android this is handled by Apple/Google via RevenueCat (we never see your card). | To unlock Eatrace Plus features, restore purchases, and handle renewals, refunds, and support. |
| Usage analytics | First-party product events — e.g. screens viewed, onboarding steps, paywall views, food and barcode actions — stored in our own database and Google Analytics. See section 6. | To understand which features are used, fix drop-off points, and improve the product. No advertising identifier is used. |
| Crash & error diagnostics | Crash reports, error stack traces, device model, OS version, and app version, collected by Sentry. | To detect, diagnose, and fix bugs and crashes. |
3. Legal bases for processing (EEA / UK users)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR / UK GDPR:
- Performance of a contract — to provide the app you signed up for: your account, fitness profile, meal tracking, and subscription.
- Consent — for precise location and camera access (which you grant through the operating system prompt and can revoke at any time), and, where required, for analytics. Health and fitness data is processed on the basis of your explicit consent given when you provide it during onboarding.
- Legitimate interests — for first-party product analytics, crash diagnostics, security, and preventing abuse, balanced against your rights.
- Legal obligation — to keep transaction records for tax and accounting where the law requires it.
You can withdraw consent at any time (for example, by turning off location or camera permission in your device settings, or by deleting your account). Withdrawing consent does not affect processing already carried out.
4. Third-party processors
We use a small set of trusted vendors to run Eatrace. Each acts as our processor under a data-processing agreement and may only use the data to provide their service to us.
| Processor | What it does | Data it sees |
|---|---|---|
| Supabase | Authentication, database, and backend (edge functions). | Email, user ID, fitness profile, logged meals, analytics events. |
| RevenueCat (with Apple App Store / Google Play) | Manages in-app subscriptions and entitlements on iOS and Android. | An anonymous app user ID and your purchase / entitlement status. Apple/Google process the actual payment. |
| Google Analytics (GA4) | First-party product analytics. | Usage events and a first-party analytics identifier. Not linked to ad profiles; no advertising ID. |
| Sentry | Crash and error monitoring. | Crash reports, stack traces, device/OS/app version. |
| Anthropic | AI analysis of meal photos and menu text to identify dishes and estimate macros. | The meal photo or menu text you submit, sent for that request. Not used to train their models. A photo for a meal you log is kept in our private storage (section 5); Anthropic does not retain it. |
| Nutrition data providers | Supply restaurant menus, food items, and nutrition/macro values. | We send a query (e.g. a dish name or barcode); these lookups are not tied to your identity. |
5. Location & meal photos
Precise location
Eatrace requests location access only "While Using the App" — never in the background. We use your coordinates at the moment you look for nearby restaurants to find and rank dishes by distance, and then discard them. We do not store your precise location on our servers and do not build a location history. You can deny or revoke this permission at any time in your device settings; the app still works, you'll just need to set a location manually.
Meal photos
When you photograph a meal, the image is sent to our AI photo-identification service (powered by Anthropic) for that single request, used to identify the dish and estimate its macros, and is not used to train AI models.
If you go on to log that meal, a small version of the photo is saved with the meal so your food log shows the plate you actually ate — including after you reinstall the app or sign in on another device. These images are held in private storage that only your own account can read: each file is access-controlled to you, and is served through short-lived links rather than a public address. They are never used for advertising, never sold, and never shared with anyone but the AI service that identified the dish. Deleting the logged meal deletes its photo, and deleting your account deletes all of them (section 8). If you take a photo and do not log the result, nothing is kept.
The camera is also used to scan barcodes; the barcode value, not the camera feed, is what we process.
6. Analytics & diagnostics
To improve Eatrace we record first-party product events (such as "paywall viewed", "meal logged", or "onboarding step completed") in our own database and in Google Analytics. These are tied to a first-party identifier so we can understand flows like sign-up completion and feature use. This is not advertising tracking: Eatrace does not use the iOS advertising identifier (IDFA) or Android advertising ID, does not share analytics with ad networks, and does not track you across other apps or websites. On iOS, if the App Tracking Transparency prompt appears, declining it does not reduce the app's functionality. Crash diagnostics from Sentry help us find and fix bugs.
This website (eatrace.app). The site uses the same Google Analytics property to measure page views and three interactions: a click on a Download-on-the-App-Store button, opening an FAQ question, and whether the pricing line was scrolled into view. Google Analytics sets first-party cookies in your browser (_ga and _ga_<id>, which distinguish visitors and sessions; they expire after up to two years and never leave a first-party context). Advertising storage is switched off by default on every page of this site, so nothing here feeds ad or remarketing audiences. You can block these cookies with your browser's settings or any content blocker — the site works exactly the same without them.
7. How long we keep your data
- Account, profile & logged meals — kept while your account is active. Deleted within 30 days of you deleting your account (see section 8).
- Precise location — not retained; used only for the immediate request.
- Meal photos — a photo attached to a logged meal is kept for as long as that meal is in your log, and is deleted when you delete the meal or your account. A photo you take but never log is not kept.
- Analytics events — retained in aggregate/de-identified form for product analysis; identifiable raw events are kept no longer than needed for that purpose.
- Crash diagnostics — retained per Sentry's default retention, then deleted.
- Transaction records — retained as long as tax and accounting law requires, then deleted.
8. Your rights & choices
You can, at any time:
- Access & export your data — email info@eatrace.app and we will provide a copy of your personal data.
- Correct your fitness profile directly in the app under Profile.
- Delete your account and all associated data — open the app, go to Profile → Delete account. This permanently and irreversibly removes your account, profile, tracker history, saved meals, and every meal photo attached to them. You can also email us to request deletion.
- Withdraw consent for location or camera by changing your device permissions.
- Object to or restrict certain processing, and request data portability, where the law provides these rights.
- Lodge a complaint with your local data protection authority. We'd appreciate the chance to address it first.
If you are a California resident, you have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising these rights. We do not sell or "share" (as defined by the CPRA) your personal information. Exercise any right by contacting info@eatrace.app.
9. Children
Eatrace is not directed to children under 13 (or the minimum age of digital consent in your country, where higher), and we do not knowingly collect personal data from them. Because the app involves weight and body-metric tracking, it is intended for adults and older teens with appropriate guidance. If you believe a child has provided us data, contact info@eatrace.app and we will delete it.
10. Security & international transfers
We protect your data with encryption in transit (HTTPS/TLS), database row-level security so users can only access their own records, and access controls on our systems. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you and regulators of a breach where required.
Our processors may store or process data in countries outside your own, including the United States. Where required, such transfers are protected by appropriate safeguards (for example, the European Commission's Standard Contractual Clauses).
11. Changes to this policy & how to contact us
We may update this policy as the app evolves or the law changes. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use after an update means you accept the revised policy.
Questions, requests, or concerns? Email us at info@eatrace.app. Governing law for this policy is Alberta, Canada.