Privacy Policy

Effective date: September 1, 2026
Last updated: October 5, 2026

This policy covers the MealSnap iOS app and the mealsnap.app website, including share.mealsnap.app.


The short version

MealSnap is a photo food diary. To do its job it has to hold some genuinely personal things: pictures of your meals, sometimes pictures of you, what you weigh, how hungry you were. We take that seriously.

  • Signing in asks Apple for nothing. No name, no email address, no contacts, no calendar.
  • Your meal photos go to Google's Gemini to be described and estimated, and your diary entries (as text, without photos) go to OpenAI for the weekly and monthly reviews. None of it is used to train AI models, by us or by them.
  • If you connect Apple Health, what you import joins your diary, and it reaches the AI reviews only if you switch that on.
  • There are no ads, no ad networks and no tracking SDKs in the app.
  • We do not sell your data. Not to anyone, not in any form, not ever.
  • You can delete your account from inside the app, and we tell you below exactly what that does.

The rest of this page is the detail. It is written to be read, not to be survived.


1. Who we are

MealSnap is built and run by Petr Rusanov, an independent developer based in the Netherlands, under the registered trade name MealSnap. For data protection law, that is your data controller.

ControllerPetr Rusanov (trading as MealSnap)
Trade nameMealSnap (registered trade name of Petr Rusanov, KvK 83724141)
AddressPetr Rusanov
Box C0971
Keurenplein 41
1069 CD Amsterdam
Netherlands
Emailsupport@mealsnap.app

There is no support department. You are emailing the person who wrote the app.

Because we are established in the EU, the EU General Data Protection Regulation (GDPR) applies to everything described here, wherever in the world you use MealSnap. If you are in the UK, the UK GDPR gives you the same rights. If you are in California or another US state with a privacy law, see Section 15.


2. What we collect, and why

We hold what the app needs to work, and the records we use to support, protect and improve it. Here is the whole list.

Your account

Signing in uses Sign in with Apple with no scopes requested. That is the smallest thing Apple lets an app ask for. We do not receive your name, your Apple ID, your real email address, or your relay email address. What we receive and store is the app-specific identifier Apple generates for you. It identifies your diary and nothing else. It cannot be used to find you anywhere outside MealSnap.

Your diary

Everything you log, because a diary that does not keep what you write is not a diary:

  • Meals, including your photos, the meal type, descriptions, calorie ranges and tags
  • Drinks, activities and measurements (height, body mass, waist, wrist, hips, body fat)
  • Body shot photos, if you choose to take them
  • Hunger before a meal and fullness after it
  • Day ratings
  • The dates and times of your entries
  • AI-generated descriptions, tags, calorie estimates and the weekly and monthly review texts written about your diary
  • Share links you have created
  • If you connect Apple Health: the workouts and measurements you choose to import, and the name of the app or device that recorded each one (see Section 3), and a record of when you gave or withdrew consent for Apple Health
  • Your app settings, so they follow you to your other devices: reminder times, statistics preferences, your last drink amount, and your Apple Health switches
  • Your time zone, which is stored with each weekly and monthly review so that its days line up with yours

Your camera stores metadata inside photo files, including the time and sometimes the place a photo was taken. The app reads the timestamp on your device to date your entry automatically, and that is all it reads. Every photo is re-encoded before upload, which strips the metadata: no location and no other camera metadata reaches our servers. MealSnap does not collect your location, and the app never asks for location permission. The closest it comes is your time zone (for example Europe/Amsterdam), which goes with the reviews, as above.

Your subscription

If you buy MealSnap Pro, the purchase happens in the App Store. We never see your card, your billing address or your Apple ID. A subscription service tells us whether a subscription is active, so it receives the App Store receipt data tied to the app user identifier it holds for you. The app also tells it each time the Pro screen is shown.

If you email us

We get your email address and whatever you write. We keep the thread so we can follow up and remember the context if you write again.

If you write to us from the app (Settings, Help & Support, Contact support) while signed in, the subject line carries your account identifier so we can find your account. The email can also carry a diagnostics file. The file is on by default, and you can switch it off before the email opens. It holds a short summary and a log, and Preview shows you both. The summary lists your account identifier; the app and iOS version and the device model; your language, region and time zone; your App Store country, whether your purchases are real or test ones, and your subscription state; how many entries and photos are waiting to sync, when a sync last worked and how the last one went; how many photos shared from other apps are waiting to import, and any uploads in progress; whether Apple Health is connected; why the app last signed you out; and whether Share analytics is on. The log is the app's own technical log from the last three days: times, status messages, and internal identifiers of entries and uploads. The file also carries the diagnostic reports iOS collected for MealSnap in the last 14 days, such as crashes, hangs and heavy CPU or disk use, and iOS's daily performance summaries for the app. Preview does not show these. They go as iOS wrote them. Nothing in the file is the content of your diary: no meals, notes, photos, Health readings or anything you typed. Nothing is sent until you send the email yourself or, on a device without a mail account, share the file yourself. The app deletes the attached file when you close the screen. We keep it with the email thread.

If moving your diary from an older version of MealSnap ran into problems, Settings offers to prepare a support file so we can fix the move. It holds a report on the move and the app build and, when the old database is still on your device, that database too. The database holds your old diary entries and references to their photos, but not the photos themselves. Nothing is sent until you send the email yourself or, on a device without a mail account, share the file yourself. The app deletes its copy when you close the screen. If you send it, we keep it with the email thread.

The website

mealsnap.app uses our website host's analytics. It is cookieless, it sets nothing on your device, and it does not follow you to other sites. It tells us how many people visited a page and roughly where in the world they were. It cannot tell us who you are.

The app itself contains no analytics SDK, no attribution SDK and no advertising SDK. It sends its own analytics events to our server, described under Operational records below, and tells the subscription service when the Pro screen is shown. Separately, if you have turned on "Share with App Developers" in your iPhone's Analytics settings, Apple may give us aggregated, anonymous crash and usage statistics. That is Apple's mechanism, it is off unless you turned it on, and we cannot identify anyone from it.

Operational records

When the app talks to our server, the server keeps a short record of the request with a log service in the EU. A record holds your account identifier, what the request did and whether it worked, the version of the app and of iOS, your app language, whether you have Pro, and usage counts for the features that cost us money. When you log something, it notes the kind of entry and its rough size, never the photo, the text or a measurement's value. When an automatic check flags an AI review, it keeps the flagged piece of the AI's text, which is text the AI wrote, not you. The server's own event and error log goes to the same place, with the same kind of content. No IP address is stored there.

The app also reports when one of its key steps fails: signing in, syncing, uploading a photo, importing photos shared from another app, reading from or writing to Apple Health, or exporting a PDF. These failure reports skip failures caused by a missing connection or a locked device, and report the same failure at most once a day. A failed sign-in waits on your device and goes out after your next successful sign-in, if that comes within 14 days. Separately, the app reports when loading the Pro plans fails, and when you buy or restore a subscription it reports the result every time, whether it worked or not. A report holds your account identifier, which step it was, the error code if there was one, and the version of the app and of iOS you are on. Some reports add a rough count or age, such as "6 to 50 entries, waiting for more than a day". Purchase reports also note the plan, where you opened the Pro screen from, your App Store country, whether your device allows purchases, and whether the subscription service knew your account.

When the app moves your diary over from an older version of MealSnap, which happens once, it reports whether the move worked. The report holds your account identifier and, if known, the old database version. When the move worked, it also says how long it took, how many entries moved, how many still had to sync, and how many were skipped and why.

The app also sends analytics events, short notes on how parts of the app are used: for example, when you open or close a Pro screen or a Pro offer and what you tap there, which plan you pick, when you open or finish a new meal, and when a weekly or monthly review opens. An event holds your account identifier, what happened, and a few details about it, such as the offer and plan shown, whether an offer was available to you, how many times a promotion had been shown, roughly how long a screen was open, how many meals you have saved, how many free recognitions you have left, your App Store country, and the version of the app and of iOS.

None of these reports include the content of your diary: no meals, notes, photos, Health readings or anything you typed. Share analytics, in the app's Settings under Help & Support, turns off the failure reports, the purchase reports and the analytics events. It does not affect the server's own records described above, the one-time report about moving your old diary, or the notice to the subscription service when the Pro screen is shown. The failure reports, purchase reports, analytics events and the report about moving your old diary are operational records like the ones above and are kept the same way. The subscription service handles the notice with the subscription data described under Your subscription and in Section 6.

We use these records to spot outages and problems an update brings, to watch a new version roll out, to keep the free tier from being abused, and to see how people use the app so we can improve it, the Pro screens and offers included. Nothing in them is used for advertising or profiling, and they are not tied to anything outside MealSnap. They are kept for 30 days and then deleted (Section 9).

Separately, our database keeps short records of AI use, to enforce the limits on the AI features, and, while the photos of a deleted account are still being deleted, a note of its account identifier (Section 9).

The legal bases, briefly

WhatWhyGDPR lawful basis
Account identifierTo have an account at all and sync it across your devicesContract (Art 6(1)(b))
Diary entries and photosTo be the diary you asked forContract (Art 6(1)(b))
Health-related entries (weight, measurements, body shots, hunger and fullness, food intake)Same, plus these can count as health data in the EUContract, plus your explicit consent (Art 9(2)(a)) - see Section 3
AI descriptions, estimates and reviewsCore features of the appContract (Art 6(1)(b))
Subscription statusTo unlock what you paid forContract (Art 6(1)(b))
Support emailTo answer youContract and our legitimate interest in supporting users (Art 6(1)(b), 6(1)(f))
Website analytics, app analytics events, operational records, abuse prevention, rate limiting, keeping the service standing upRunning a service that works, is not abused, and gets betterLegitimate interests (Art 6(1)(f))
Disclosures the law requiresResponding to a valid court order or binding legal requestLegal obligation (Art 6(1)(c))

3. The sensitive parts

Some of what a food diary holds is, under EU law, data concerning health: your weight and body measurements, body shot photos, hunger and fullness, and a detailed record of what you eat.

We treat it that way. We only ever have it because you chose to type it in or photograph it, after reading this policy. By entering it you are giving your explicit consent for us to store and process it for the purposes described here. You can withdraw that consent at any time by deleting the entry (see Section 9 for what that removes and when), or by deleting your account, and nothing else in the app stops working if you do. Withdrawing does not undo processing that already happened.

Apple Health. Connecting Apple Health is optional, and iOS asks you type by type what MealSnap may read and write. What you let it read (workouts and their effort score, weight, body fat, height and waist) comes into your diary as entries, and is stored and synced like the rest of it. What MealSnap writes to Apple Health (your measurements, water, and the calorie estimates of your meals) is written on your iPhone, by iOS. Entries that came from Apple Health go into the weekly and monthly reviews only if you switch that on in the app; with it off, they are left out before anything is sent. You can turn it off, or stop the import, in the app or in the Health app's settings. Data from Apple Health is never used for advertising and never shared for anyone else's purposes.

We never use this data to infer anything about you beyond the diary itself, and we never share it for anyone else's purposes.


4. AI: what leaves the app, and what happens to it

We use two AI providers, each through its paid API:

  • Recognising a meal: Google's Gemini API. When the app analyses a meal, your meal photos are sent to Gemini, with the language your app is set to. Nothing else about you or the entry goes with them. What comes back is the description, the tags and the calorie range. We are moving recognition to Gemini from OpenAI, and until that is finished some meals are still recognised by OpenAI in the same way.
  • Weekly and monthly reviews: OpenAI's API. When a review is generated, the entries in that period are sent to OpenAI as text, without photos, with your time zone, your app language and your earlier reviews. What comes back is the review text. Entries imported from Apple Health are included only if you switched that on (Section 3).

What we can tell you honestly:

  • Your photos and your data are never used to train AI models. Not by us, not by either provider. This is contractual, not a hope: both providers' paid API terms rule it out.
  • We send what the feature needs, not your whole diary. Your account identifier is not part of the prompt.
  • We are not going to claim the providers keep nothing. Under their standard paid API terms, Google keeps inputs for up to 55 days and OpenAI for up to 30 days, only to detect abuse, and then deletes them. That is normal for API providers, and it is the honest state of things rather than a marketing line.

There is no on-device-only mode for these features. If you would rather no photo left your phone, you can use MealSnap as a manual diary: type your own descriptions, skip the estimates, and no photo goes to an AI provider. The diary is fully usable that way.

The app also does some on-device image work (matching a new photo against your own past meals for Visual Intelligence). That runs on your iPhone and nothing is uploaded for it.


5. Where your data lives

  • Your diary, your photos and the app backend are hosted by a cloud provider in Amsterdam, the Netherlands (EU), so your stored data stays in the EU. What leaves it is what an AI provider is sent for a feature (Section 4) and the subscription data our subscription service receives (Section 11).
  • The website and share pages run on a content delivery network.

Your data is also stored on your own iPhone, and syncs across your devices through your account.


6. Who else touches your data

We use a small number of companies to run MealSnap. They process data on our instructions, under contracts that require them to protect it. We do not have any other kind of data sharing, and there is no partner, broker, or advertiser in this list. We name the AI providers, because what they receive matters most; for the others we list the kind of service. Email us if you want to know who a provider is.

WhoWhat they doWhat they get
Cloud hosting providerRuns the app backend and stores your diary and photos, in AmsterdamYour entries, photos and account record
Google (Gemini API)Recognises meals: descriptions, tags and calorie rangesMeal photos and your app language, when you log a meal
OpenAIWrites the weekly and monthly reviews, and recognises some meals until the move to Gemini is finishedThe entries in a review's period; meal photos and entry context for the meals it recognises
Subscription serviceTells the app whether your subscription is activeApp Store receipt data and Pro screen views, tied to the app user identifier the subscription service holds for you
Website hostServes the website and share pages, and provides cookieless analyticsStandard request data, IP address at the network layer
Log serviceStores our operational records (Section 2), in the EUYour account identifier and the operational records described in Section 2, never photos or an IP address
Our email providerCarries support emailWhatever is in your email to us

Two companies are not our processors, because they act on their own account:

  • Apple provides Sign in with Apple and is the seller of every subscription. Apple's own privacy policy governs what Apple does with your purchase and Apple ID data. We never see your payment details.
  • Anyone you send a share link to sees what you shared. That is you sharing, not us.

We also disclose data if the law genuinely requires it: a valid court order or a binding legal request. We would push back on anything overbroad, and we will tell you unless we are legally prohibited from doing so.

If MealSnap were ever sold or handed over to someone else to run, your data would go with the service, this policy's promises would bind the new operator, and we would tell you in the app before it happened, with enough time to export your diary and delete your account if you would rather leave.


7. Share links and PDF export

Share links are optional and Pro-only.

  • Creating one uploads a date range, not the entries. The server hands back a long, random, unguessable link.
  • Anyone who has that link can open share.mealsnap.app and see that stretch of your diary, including the photos in it. There is no password and no sign-in. Treat the link like the contents itself: send it to your coach, not to a public forum.
  • The app sets each link to expire seven days after it is created.
  • The photos on a shared page load from our photo storage, each at its own long, unguessable address. Someone who saves one of those addresses can keep opening that photo after the link has expired, until the photo itself is deleted and any cached copy has expired (Section 9).

PDF export builds a file for you. It is yours, on your device, and we do not receive a copy or know where you send it.


8. What we do not do

Absolute statements, meant absolutely:

  • We do not sell your data, and we never have.
  • We do not share it for advertising, profiling or "partner offers".
  • There are no ad networks, no ad SDKs and no tracking SDKs in the app.
  • We do not track you across other apps or websites, and we do not ask for the App Tracking Transparency permission because we have nothing to ask for.
  • We do not collect your location. The app never asks for location permission, and photo metadata that could reveal a location is stripped before upload. The only hints are your time zone, which goes with the reviews, your App Store country, which some reports and the diagnostics file carry, and your device region, which the diagnostics file carries (Section 2).
  • Your photos and diary are not used to train AI models.
  • We do not read your diary for fun. Access to production data is limited to what is needed to keep the service running or to answer a support request you sent us.

9. How long we keep things, and what deleting does

While your account exists, we keep your diary. A food diary that quietly deleted last year would be useless, and only you know when an entry has stopped being worth keeping.

When you delete an entry, it leaves your diary and your share links at once. On our server, the entry and its photos stay for 30 days, marked as deleted, while your other devices catch up with the deletion. After that, an automatic cleanup that runs every hour deletes its photos and clears the rest of the entry. A photo that another of your entries still uses stays with that entry. If deleting a photo fails, the cleanup tries again once a day for up to a week, and until it succeeds the entry also keeps the photo's details: its date and any recognition results. If it still fails after a week, or the photo cannot be found to delete, the cleanup stops trying: the photo and its details stay until they are removed or you delete your account. Otherwise, what the cleanup leaves is what your devices need to know the entry was deleted: its identifiers, the kind of entry and its type (such as lunch, or weight and its unit), its date, and when it was created, changed and cleared. For an entry imported from Apple Health, the reference to the Health record also stays, so that the next import does not bring the entry back. What is left stays until you delete your account.

When you delete your account (Settings, in the app), we delete your entries, your share links, your AI reviews, the records of your AI use, your consent records and your user record from our database at once, and that is not a soft delete. The same step deletes the photos stored for your account. If deleting a photo fails, we try again automatically, and the photo stays in storage until it is deleted. Until then, our database keeps a note of your account identifier and the time of the last try, and the note goes when the photos do.

We try to clear cached copies from our content delivery network when deleting photos. Any copies we do not clear can stay reachable at the photo's address until the cache expires.

Operational records (Section 2) are kept for 30 days and then deleted. Deleting your account does not purge them early: the only identifier they carry is your account identifier, which no longer points to a user record in our database once your account is deleted, and they age out on their own.

Limits on the AI features. To enforce them, our database keeps short records of AI use. For each photo counted toward the free recognition limit: your account identifier, the time and an internal request number. For each weekly or monthly review: your account identifier, the time, the period it covers, and what generating it took and cost (the model, the number of calls and tokens, and whether it failed). Review records are deleted automatically after 7 days and recognition records after 14 days. Deleting your account deletes them at once.

Support email threads are kept while they are useful and then deleted. Backups, where our providers keep them, roll over on their own cycle and are overwritten. Anonymous, aggregated website statistics are not tied to you and are kept indefinitely.


10. Security

Everything between the app and our servers travels over TLS. Access to production systems is limited to the developer and protected by strong authentication. Share links use long random identifiers rather than guessable IDs.

No service can promise perfect security, and anyone who does is selling something. If a breach happens that puts your rights at risk, we will notify the Dutch Data Protection Authority within 72 hours as the law requires, and we will tell you directly and plainly if you are affected.


11. Sending data outside the EU

Some of our providers are based in the United States, so your data is transferred there. Where a provider is certified under the EU-US Data Privacy Framework, that certification covers the transfer. Where it is not, we rely on the European Commission's Standard Contractual Clauses in our contract with them. If you want to know which mechanism applies to a specific provider, email us and we will tell you.


12. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and get a copy
  • Correct anything inaccurate
  • Erase your data ("right to be forgotten")
  • Export your data in a portable, machine-readable form
  • Restrict or object to processing based on legitimate interests
  • Withdraw consent for the health-related data described in Section 3, at any time
  • Complain to a supervisory authority

How to actually use them

Most of it is faster in the app than by email:

  • See your data: it is your diary. Open the app.
  • Correct it: edit the entry. AI-written text is editable too, and once you have edited a field the app never overwrites it.
  • Delete it: delete individual entries, or delete your whole account from Settings.
  • Anything else, including a full export or a copy of the data we hold: email support@mealsnap.app. We will answer within one month. The law lets us extend that by two further months for complex requests; at our size we do not expect to need it, but if we ever did, we would tell you within the first month.

We do not charge for any of this, and we will not ask you a lot of questions to make it harder. Because sign-in gives us no name or email address, we may need you to make the request from inside the app or prove control of the account so that we do not hand your diary to somebody else.

Complaints. If you think we have handled your data badly, please tell us first, we would like the chance to fix it. You also have the right to complain to your national data protection authority. Ours is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you can complain to the authority where you live instead.


13. Children

MealSnap is not designed for or directed at children, and we do not knowingly collect data from them. You need to be at least 16 to use MealSnap.

An app about food, weight and body images is not a good place for a child, and that is a judgement about the subject matter, not only about the law. If you believe a child has been using MealSnap, email support@mealsnap.app and we will delete the account and its data.


14. Automated decisions

We do not make any decision about you that has a legal or similarly significant effect, and there is no profiling in that sense. The AI in MealSnap describes your food and writes observations about a period you logged. It does not score you, rank you or decide anything about you.


15. If you are in the US

We give everyone the same treatment described above, which covers most of what state privacy laws require. Specifically: we do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising. There is nothing to opt out of, because we never started. If you want access to or deletion of your data, use the same route as everyone else: the app, or support@mealsnap.app. We do not discriminate against anyone for exercising a privacy right.


16. Changes to this policy

If we change what we do with your data, we will change this page, move the "last updated" date, and, for anything that actually matters to you, tell you before it takes effect, in the app or in the notes of the app update that brings it. We will not quietly widen what we collect and hope nobody rereads the page.


17. Contact

support@mealsnap.app

Privacy questions, requests, complaints, or a sentence in here that reads like nonsense: the same address, and the same person answers all of them.