Privacy Policy
Effective date: July 23, 2026
Bamboo is a local-first nutrition app. Your food logs, profile, goals, and wellness data live on your phone. This policy explains what stays on the device, what leaves it, and how to remove your data.
The short version
- Everything you log is stored on your device. If you turn on optional cloud backup, a copy of your data (including food, weight, cycle, workouts, sleep, and wellness entries) is also stored on our server so you can restore it. You can delete that copy at any time.
- You get an anonymous account automatically. No name or email required. You can optionally add email or Sign in with Apple to back up your account.
- We run lightweight analytics (event names and counts, no food content) to understand how the app is used. Analytics are tied to your account ID. If you never add an email or Sign in with Apple, that ID is anonymous. Analytics never contain your name, email, or food content, and you can opt out in Settings.
- We do not sell your data, and we do not use it to train AI models.
- Photo meal analysis sends a compressed image, and the Describe feature sends your typed meal text, to DeepInfra via our secure server. Anthropic (Claude) may be used as a backup provider. Neither is stored on our end.
- Bao's optional daily insight sends a small derived summary of your day (calorie and protein progress, logging streak, goal, and gut score, and for cycle-tracking users the current cycle phase, cycle day, and the labels of that day's logged symptoms) to the same AI providers, only after you consent. No food names or raw entries are sent, and you can turn it off in Settings.
- Food search goes to USDA FoodData Central. Barcode scans go to Open Food Facts.
- You can delete your cloud backup, or your whole account and all associated data, at any time from Settings.
What we store and where
On your device only
All of the following is saved in on-device storage. It reaches our server only if you turn on cloud backup (see below):
- Food logs: foods you add, amounts, meal types, and timestamps.
- Profile and goals: name, body details, activity level, and goal.
- Scores and trends: nutrition estimates computed on the device.
- Wellness data: mood entries and any sleep, recovery, or activity numbers you enter by hand or import from Apple Health.
- Workouts: exercises you log by hand, including strength sets, reps, and the weight you lift.
- Water and weight: daily water count and weight entries.
- Cycle and menstrual data: period dates, cycle lengths, and symptom entries.
- Settings: theme choice, notification preferences, and feature flags.
On our server (Supabase)
- Your anonymous account ID (a UUID), created automatically on first launch.
- Behavioral analytics events: event names and non-PII metadata. No food names, calorie values, or free text leave the device.
- Session metadata: app version, session ID, and timestamp.
- Your cloud backup, if you turn it on: a snapshot of your app data (food logs, profile and goals, water, weight, cycle and menstrual entries, workouts including strength sets, reps, and weight, sleep entries, wellness entries, and settings), keyed to your account. Backup is optional and user-initiated. It is encrypted in transit and at rest but is not end-to-end encrypted. Only your signed-in account can read its backup, enforced by database row-level security. You can delete the server copy at any time from Settings, Cloud backup, Delete cloud backup, without deleting your account.
If you add email or Apple sign-in, your email is stored in Supabase Auth. Your app data stays on-device unless you turn on cloud backup.
What leaves your device
1. USDA FoodData Central
When you search for a food by name, the search text is sent to USDA. Nothing about your identity or logs is sent.
2. Open Food Facts
When you scan a barcode, the barcode number is sent to retrieve nutrition facts.
3. DeepInfra and Anthropic (via our server)
DeepInfra is our primary AI provider, with Anthropic Claude as a backup. These are the only two AI providers we use. Three features send data to them through our secure server, each behind a one-time consent prompt. Processing is transient and we do not retain any of it. Both providers state they do not use API data to train models.
Camera meal analysis: the photo is compressed and forwarded to DeepInfra's vision model for food identification. Only the photo is sent.
Describe (text meal analysis): when you type what you ate, that description is forwarded to a DeepInfra text model to estimate foods and amounts. Only the text you typed is sent. Photo and Describe share a limit of 20 AI analyses per day.
Bao's daily insight: a small derived summary of your day (calorie and protein progress, logging streak, goal, and gut score, and for cycle-tracking users the current cycle phase, the cycle day number, and the labels of that day's logged symptoms) is sent so the model can write one encouraging sentence. No food names, raw entries, or period dates are sent, and free text is never sent. A consent prompt appears before the first time this runs, and you can turn it off in Settings.
4. Supabase (analytics and auth)
Anonymous behavioral analytics and your anonymous account ID are sent to Supabase. No food content or health data is included.
5. Sentry (crash reporting)
Crash reports include device type, OS version, app version, error message, and anonymous UUID. No food names or health values are included.
What we do not do
- We do not sell, rent, or share your personal data.
- We do not use your data to train AI or machine-learning models.
- We do not run advertising or third-party tracking.
- We do not build a profile of you linked to your real identity.
- We never write to Apple Health, and we do not use Apple Health data for advertising.
Data deletion
Every user gets an anonymous account automatically. You can:
- Export your data from Settings, Manage Data, Export.
- Clear all on-device data from Settings, Manage Data, Delete all data.
- Delete your account from Profile, Account, Delete account. This is permanent.
- Uninstall the app to erase all on-device storage.
Apple Health
If you connect Apple Health, Bamboo reads your steps, active minutes, workouts, and sleep to show your daily activity and wellness. Access is read-only: we request read permission only, and Bamboo never writes to Apple Health. This data is treated like your other wellness data, so it stays on your device and reaches our server only if you turn on cloud backup. We never use Apple Health data for advertising and we never sell it. Connecting is optional, and you can review or revoke access at any time in the Apple Health app. Activity, sleep, and workouts can also be entered by hand.
Cycle and menstrual data
Your period dates, cycle lengths, and symptom entries are stored on your device. This raw data stays on your device unless you turn on cloud backup, which uploads a copy to your own account so you can restore it. If you enable Bao's daily insight, the derived summary can include your current cycle phase (for example "luteal"), the cycle day number, and the labels of the symptoms you logged that day, only after you consent, and never the underlying dates or any free text. You can turn off the daily insight, and delete your cloud backup, at any time in Settings.
Children
This app is not directed to children under 13. We do not knowingly collect data from children.
Changes to this policy
If we change how the app handles data, we will update this policy and the effective date.
Contact
Questions about privacy: bamboobaoapp@gmail.com