Privacy Policy
Last updated: 19 August 2026
The short version. Your diary — meals, weight, water, targets — is stored on your iPhone, not on our servers. Photos you send for recognition are read and discarded, never stored. Your answers about health are used to set your targets and are never sent to advertising or attribution partners.
This policy explains what FoodAmigo (“the app”) collects, why, and who else sees it. It is written by Nutri Expert Limited, a company incorporated in the Hong Kong Special Administrative Region, which operates the app and is the data user for the purposes of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).
Contact for anything in this policy, including access and correction requests: [email protected].
1. What stays on your phone
The diary itself never leaves your device unless you choose to back it up through Apple. That includes:
- meals you logged, with their names, calories and macronutrients;
- water and weight entries;
- your profile from the setup questions — sex, year of birth, height, weight, goal, activity level and eating plan — and the daily targets calculated from them;
- your answers about health concerns.
If you delete the app, this data is deleted with it. We have no copy and cannot restore it for you.
2. What is sent for meal recognition
When you photograph a meal, pick a photo, or describe one in words, that photo or text is sent to our recognition service and passed to an AI model provided by Google (Gemini API), which returns an estimate.
| What is sent | What happens to it |
|---|---|
| The photo or your written description | Held in memory while it is being read. Not written to our storage. |
| The model's text answer — dish name, calories, macronutrients, ingredients | Kept for up to 24 hours so that a repeat of the same request does not pay for a second model call. Then deleted. |
| A device identifier and a request identifier | Used to count your daily recognition allowance and to recognise a repeated request. The device identifier is Apple's identifierForVendor: it is specific to our apps and resets when you delete them. |
We do not attach your name, email or Apple ID to these requests, because we do not have them.
3. Analytics and attribution
The app uses three services, each for a different purpose:
- AppsFlyer — measures which advertising campaign led to an install. It receives event names and device-level identifiers, and does not receive your answers to setup questions. When subscriptions become available, it will also pass purchase events to our advertising partners.
- Google Firebase — technical analytics: which features are used and how the setup questions are answered. Crash reporting is not part of the app.
- Amplitude (EU region) — product analytics: which parts of the app are used and where people get stuck.
Health answers stop at the boundary. Answers you give about health conditions are used inside the app to shape your targets and warnings. They are sent to Firebase only, and never to Amplitude or to any advertising or attribution partner. This is enforced in the app's code, not by policy alone.
On first launch iOS asks whether you allow tracking across apps and websites. If you decline, advertising identifiers are not used, and the app continues to work exactly as before.
4. Subscriptions and payment
Subscriptions are sold and processed by Apple through the App Store. We never see your card details, billing address or Apple ID. From Apple we receive only whether a subscription is active, plus anonymous transaction events used for accounting and for measuring advertising.
5. Legal basis and your rights
We process personal data to provide the app you asked for, to keep it working, and to measure our advertising. Under the Personal Data (Privacy) Ordinance you may ask us:
- whether we hold personal data about you, and to receive a copy of it;
- to correct data that is inaccurate;
- to stop using your data for direct marketing.
Write to [email protected]. We answer within 40 days, as the Ordinance requires. Note that most of what you would ask for is on your own device and not accessible to us — for that data, deleting the app is the deletion.
If you are in the European Economic Area or the United Kingdom, you additionally have the rights to erasure, restriction, objection and data portability under the GDPR, and may complain to your local supervisory authority. If you are in California, you may exercise the rights granted by the CCPA. We do not sell personal data.
6. Transfers outside Hong Kong
Our recognition service and our analytics providers operate outside Hong Kong, including in the European Union and the United States. When personal data is transferred, we rely on the providers' own contractual protections and send them no more than is described above.
7. Children
FoodAmigo is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has provided us with personal data, write to us and we will delete it.
8. Retention
- Photos and descriptions — not retained at all.
- Recognition answers — deleted automatically 24 hours after the request.
- Daily allowance counters — a device identifier, a date and a number. These are not deleted on a schedule today; they carry no information about you or your food.
- Analytics events — kept for as long as each provider's own retention settings allow.
9. Changes
If we change this policy in a way that matters, we will update the date at the top and, for significant changes, tell you inside the app. Continuing to use FoodAmigo after a change means you accept the updated policy.
10. How to reach us
Nutri Expert Limited
Unit 8, 7/F, Valiant Industrial Centre,
Fo Tan, Hong Kong SAR
[email protected]