Privacy Policy
Last updated: 2 July 2026
TummyTally ("TummyTally", "we", "us") is a calorie and macro tracking app for iOS and Android. This policy explains what data the app handles, where it is stored, and the choices you have. TummyTally is local-first: by default your information stays on your device and is not sent to us.
1. Data stored on your device
Most of what you do in TummyTally is stored locally on your device: your food diary, logged meals and water, goals, profile details (such as height, weight, age, sex and activity level), and app settings. If you never sign in, this data is not transmitted to us or anyone else, and we cannot see it.
2. Optional cloud sync (accounts)
If you choose to create an account and enable cloud sync, your diary and related app data are stored in our backend (hosted on Supabase) so you can access them across devices and back them up. To run accounts we process:
- your email address (and, if you use Sign in with Apple, the identifier Apple provides);
- the app data you choose to sync — diary entries, foods, goals, profile, and body metrics such as weight and weight history;
- if you use the social features, your friend/partner connections and a display name (see §4);
- basic technical data needed to operate the service (e.g. timestamps).
Cloud sync is optional. If you do not sign in, none of this applies.
3. Health & fitness data
With your explicit permission, TummyTally can integrate with Apple Health (iOS) or Android Health Connect. This lets the app read data such as weight, date of birth, sex and activity to set up your profile and goals, and write the meals, nutrition and water you log back to Health. This data is exchanged directly between the app and the platform's health store on your device under the permissions you grant, and is only included in cloud sync if you have enabled sync. We never use your health data for advertising or marketing, never share it with ad networks or data brokers, and never use it to train AI models. You can revoke health permissions at any time in your device settings.
4. Friends & accountability partners
TummyTally has optional social features. These only operate when you have an account and choose to use them, and the connections require mutual agreement:
- Friends. You can connect with friends by sharing a friend code or QR code. Connected friends can see a display name and your derived adherence score (a 0–100 summary of how you tracked against your rings). Friends cannot see your underlying food diary, weight, goals or other details.
- Accountability partners. If you and another user both accept a partnership, you may log food entries into each other's diaries and share meal logs whose food details and portions both partners can see and edit. This is the only feature that lets another user write to or read parts of your diary, and it works only between partners who have explicitly accepted each other.
You can remove a friend or end a partnership at any time in the app, which stops further sharing.
5. Notifications
With your permission, TummyTally sends notifications such as reminders and (if you use accountability partners) an alert when a partner adds an item to your diary. To deliver these we register a device push token and send the notification through the platform's push service — Apple Push Notification service on iOS (and Google's equivalent if/when Android push is offered). Notification content is kept minimal (for example, "a partner added an item to your diary") and does not include the food details. You can turn notifications off in the app or your device settings; doing so removes your device's push token.
6. AI features
TummyTally offers optional AI features (for example, generating meals, recognising food photos, and parsing meals you type or speak). When you use an AI feature, the relevant input (such as the text you entered or the photo you captured) is sent through our secure backend to Anthropic (the provider of the Claude AI model) to produce a result. AI features are optional and only run when you trigger them.
7. Advertising
TummyTally may show ads to users on the free tier using Google AdMob. Premium users do not see ads. To serve ads, AdMob may process device identifiers and similar data. Where required (for example in the EEA, UK, and on iOS), you will be asked for consent through Google's consent prompt and, on iOS, Apple's App Tracking Transparency prompt; if you decline, non-personalised ads are shown instead. You can learn more in Google's policy on how it uses data from sites and apps that use its services.
8. Analytics
To understand how the app is used and to improve it, we collect a small amount of first-party product analytics — named usage events (for example, that a food was logged), a random identifier for your app installation, and, if you are signed in, your account id. These analytics do not include your food, health or profile details, are not used for advertising, and are not sold. We use them only to operate, secure and improve TummyTally.
If the app encounters an error, we also collect crash diagnostics: the technical error name, message and stack trace, the app and OS version, and the same random installation identifier (plus your account id if signed in). Crash reports never include your food, health or profile details, are retained for at most 12 months, and are covered by the same Settings → Data → Share usage data switch — turning it off stops both analytics and crash reports.
9. Purchases
Premium subscriptions are sold through the Apple App Store and Google Play and managed using RevenueCat, which helps us validate purchases and manage entitlements. The app store and RevenueCat process the purchase information needed to provide and restore your subscription. We do not receive or store your full payment card details.
10. How we use data
- to provide the core tracking features;
- to sync and back up your data when you enable an account;
- to operate the social features (friends and accountability partners) you choose to use;
- to send notifications you have enabled;
- to provide AI features you request;
- to operate premium subscriptions and (for free users) advertising;
- to maintain, secure and improve the app.
We do not sell your personal information.
11. Improving food matching
To improve how the app matches the foods you search or quick-add to our food database, we may log the food query you typed or spoke, the match our system chose, and whether an AI estimate was used. This helps us correct poor matches for everyone. It is on by default and is governed by the same Settings → Data → Share usage data control (§8), so turning that off also stops this logging and these food queries are not sent to our servers. This logging covers only your food searches and quick-add entries — not your diary, weight, or health data. These records are tagged with a random identifier that is not linked to your name or account (used only to group searches so we can study common patterns); if you delete your account, that link is removed and the remaining records can no longer be traced to you.
12. Data retention & deletion
Local data remains until you delete it or uninstall the app; you can erase on-device data at any time in Settings → Data. If you use an account, you can delete your account and all synced data directly in the app (Settings → Data → Delete account & data), or by emailing us; we will delete it within a reasonable period, subject to any legal retention obligations. Limited operational analytics may be retained in a de-identified form (no longer linked to your account) for aggregate reporting. Removing data held by the app stores, Apple/Android Health, or third parties is governed by their own controls and policies.
13. International data transfers
We and our service providers may process your information in countries other than your own, including the United States (for example Anthropic and Apple's push service) and the region where our backend is hosted. Where required by law, such transfers are covered by appropriate safeguards (for example the European Commission's Standard Contractual Clauses). By using features that send data off your device, you understand it may be processed in these locations.
14. Children
TummyTally is not directed to children and is not intended for use by anyone under the age required by their local law to consent to data processing (for example, under 13 in the US, or the relevant age in your country). We do not knowingly collect data from children, and the app asks for a date of birth during setup to enforce a minimum age.
15. Your rights
Depending on where you live (for example under the EU/UK GDPR or South Africa's POPIA), you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.
16. Third-party services
This policy references third parties that may process data on our behalf or under their own policies:
- Supabase (cloud sync & backend)
- Anthropic (AI features)
- Google AdMob (advertising)
- RevenueCat (purchases)
- Apple (app store, health platform & push notifications) / Google (app store & health platform)
17. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through an in-app notice.
18. Contact
Questions or requests about this policy or your data? Email support@tummytally.com.