Privacy Policy

Last updated: July 2026

Who We Are

OmniPlate (“we,” “our,” or “us”) is operated by Amir Dora, Wolfringstr. 1, 90768 Fürth, Germany, the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, use, store, and share your personal information when you use the OmniPlate mobile application and related services.

Data We Collect

  • Device identifier: A random identifier generated on your device. OmniPlate works without registration — this identifier is what links your logs to your anonymous account on our servers.
  • Photos: Images of meals you capture or upload for AI calorie analysis.
  • Voice transcripts: Text generated from voice descriptions of meals. Speech-to-text uses Apple’s speech recognition service (audio may be processed on-device or by Apple); only the resulting text is sent to our servers.
  • Health and profile data: Weight, height, age, biological sex, activity level, and nutrition goals you provide, plus the meals, water, and weight entries you log.
  • Food searches and barcodes: Search terms and barcodes you scan when looking up foods.
  • Subscription status: Whether you have an active subscription. Payment is handled entirely by Apple — we never see your payment details.

How We Use Your Data & Legal Bases

  • AI analysis (contract, Art. 6(1)(b) GDPR): Photos and meal descriptions are processed to estimate calories and macronutrients.
  • Progress tracking (contract): We store your daily logs to show trends and calculate your goals.
  • Camera, microphone, and photo access (consent, Art. 6(1)(a)): Requested only when you use the corresponding feature; you can withdraw consent at any time in iOS Settings.
  • Service security and abuse prevention (legitimate interest, Art. 6(1)(f)).

We do not use third-party advertising or analytics services, we do not track you across other companies’ apps or websites, and we never sell your personal data.

Third Parties

  • OpenAI (USA): Meal photos and descriptions are sent to OpenAI for calorie and macro estimation. This involves a transfer outside the EU, safeguarded by the EU–US Data Privacy Framework and standard contractual clauses. OpenAI does not use this data to train its models.
  • Open Food Facts: When you scan a barcode, the barcode is sent from your device to Open Food Facts (a non-profit food database) to look up the product. Your IP address is visible to them as part of the request.
  • USDA FoodData Central: Food text searches are looked up via our servers in the USDA food database; your identity is not shared.
  • Apple: Handles subscription billing through the App Store and provides the speech-recognition service used for voice logging, under Apple’s own privacy policy.

Data Storage & Retention

All data is transmitted over encrypted connections (TLS) and stored on our servers hosted in the European Union (Hetzner). We do not store your meal photos: they are forwarded for analysis, and only an anonymous fingerprint (hash) of the image together with the nutritional result is cached for up to 30 days to avoid re-analyzing identical photos. OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring and then deletes them; it does not use this data to train its models. Your logs and profile data are kept for as long as you use the app and deleted immediately when you delete your data. Authentication tokens are stored securely in the device Keychain.

Your Rights (GDPR)

If you are in the European Union, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Request portability of your data in a machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, without affecting prior processing
  • Lodge a complaint with a supervisory authority (in Germany, your state’s data protection authority)

You can delete all your data yourself at any time in the app via Settings → Delete Data — this permanently removes your account and all logs from our servers and your device. For any other request, contact us at the email below. We respond within 30 days.

Children

OmniPlate is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to This Policy

We may update this policy as the app evolves (for example, if we add new features or service providers). Material changes will be reflected in the “Last updated” date above and, where appropriate, announced in the app.

Contact

If you have any questions about this Privacy Policy or your data, please contact us at privacy@figoodle.com.