FitGlass

Consumer Health Data Privacy Policy

Effective July 2, 2026 · Last updated September 14, 2026

This policy is provided by Nisarg Chaudhary, the independent developer who operates the FitGlass iOS app, to satisfy the Washington My Health My Data Act (RCW 19.373) and Nevada SB 370. It describes how FitGlass collects, uses, and shares consumer health data. FitGlass’s general privacy practices are described in our Privacy Policy.

Categories of consumer health data we collect

  • Nutrition and dietary intake data: the foods you log, including food names, portion details, meal type, timestamps, calories, macronutrients (protein, carbohydrates, fat, fiber), micronutrients, and derived daily and monthly nutrition totals.
  • Hydration data: the drinks you log, including the amount and the time you logged them.
  • Body measurements and characteristics: sex, age, weight, height, and (optionally) a target weight.
  • Health-related goals and preferences: activity level, motivation (e.g., lose fat, maintain), dietary preferences, meal schedule, and daily calorie/macronutrient and water targets.
  • Photographs of food you choose to submit for AI analysis, and text descriptions of what you ate — whether you typed them or spoke them. Spoken descriptions are converted to text by your own device; the audio is never collected, transmitted, or stored.
  • Barcodes of packaged foods you scan. Your device reads the number off the label itself and sends only that number to Jar, our own food database. No image of the product is collected, transmitted, or stored. A food you log from a scan then becomes an ordinary food entry, covered by the first bullet above.
  • Food searches you type. A copy of Jar inside the app answers first, with no network request. If you type two or more characters and pause, the words are sent to our Jar service to find branded products. Our own logs record counts and timings, not the words — but the words travel in the request address, and Google Cloud’s request log for our service records that address and keeps it 30 days. Search text is never sent to Google’s AI and is never stored against your account.
  • Bodily-activity data read from Apple HealthKit with your permission (active energy, resting energy, steps, exercise minutes, workout history). This data is displayed on your device only and is never transmitted to our servers or any third party.

Sources of consumer health data

  • Directly from you — profile entries, foods and drinks you log, text and photos you submit to the AI food logger, descriptions you speak (your device transcribes them on-device; only the resulting text is submitted), barcodes you scan (your device decodes them; only the number is submitted), and food searches you type.
  • From your device with your permission — Apple HealthKit readings (kept on-device).
  • Derived by us — computed nutrition targets and aggregated daily/monthly totals of the entries you logged.

Why we collect and use it

We collect and use consumer health data only to provide the services you request:

  • Calculating your nutrition targets and displaying your dashboard, charts, and widget.
  • Analyzing food descriptions and photos you submit so you can log them.
  • Looking up a food in Jar, from a barcode you scan or words you type.
  • Answering the Siri and Shortcuts actions you invoke. “Today’s Calories” speaks your logged calories and requires an unlocked device; Apple handles your voice under Apple’s privacy policy when you use Siri.
  • Scheduling meal and water reminders. The times are derived on your device from when you log, and never leave it.
  • Changing or removing an entry you already logged, when you ask the AI to.
  • Generating a meal plan when you ask for one, using your nutrition targets and your dietary constraints.
  • Summarizing what you have already logged when you ask about your history.
  • Writing the nutrition and water you log to Apple Health, if you enable it.
  • Measuring and improving the accuracy of the AI food logger (records of what the AI proposed versus what you saved).
  • Securing the service (authentication, per-user data isolation, rate limiting).

We do not use consumer health data for advertising or marketing, and we do not sell it. FitGlass does run an opt-in marketing email list, and consumer health data has nothing to do with it: the list holds an email address and a first name, it is never segmented or targeted using health data, and none of the data described on this page is exported to our email provider. See “Marketing emails” in the Privacy Policy. We do not process consumer health data for any purpose beyond those listed above without asking for your consent first.

Who we share it with

Affiliates: none. FitGlass is operated by a single individual developer with no affiliated companies.

Categories of third parties (processors acting on our instructions):

Both bullets below are the same company. Since August 15, 2026, Google is our only processor of consumer health data.

  • Google LLC (Firebase / Google Cloud) — hosts our database and backend; stores your profile and food log in the United States. This includes the FitGlass food catalogue, which is our own service running on Google Cloud. A barcode you scan reaches only that service; it holds public USDA nutrition data and no user data, and its records carry no account. Google Cloud’s own request log for that service records the address of each request, which for a search includes the words you typed. It is kept 30 days and carries no account. Google also keeps automatic encrypted backups of our database: a 7-day rewind window, a daily backup kept 7 days, and a weekly backup kept 14 weeks. So a copy of your consumer health data can persist in a backup for up to 14 weeks after you delete it. A restore re-applies every deletion made since the backup was taken.
  • Google LLC (Google Cloud Vertex AI) — receives what you submit through the AI logger, solely to generate the analysis you asked for. That is: the food descriptions (typed, or transcribed from your speech on your device), photos, your daily targets, and a summary of your recent entries. If you ask for a meal plan it also receives your dietary constraint tags, including any allergy tag and the halal and kosher tags. If you ask about your history it also receives your daily and monthly nutrition totals for the past 7 days and 3 months. If you ask it to change or remove something you already logged, it also receives today’s saved entries — up to 25, with food names, meal types and macros, plus the internal record IDs that let it name the right row. Google’s cloud terms state it does not use this content to train its models and does not keep it beyond producing the response, except that requests its automated safety classifiers flag may be kept up to 90 days. No audio is shared with Google or with anyone else. Until August 15, 2026 this processing was performed by Anthropic PBC, which no longer receives anything.

No other third party receives consumer health data. We do not share consumer health data with advertisers, data brokers, analytics providers, or our email provider. Our analytics events contain no health data content, and the marketing list contains no health data at all.

Your rights

If you are a Washington or Nevada resident, you have the right to:

  • Access your consumer health data, including a list of the third parties with whom we have shared it.
  • Withdraw consent to our collection and sharing of consumer health data.
  • Delete your consumer health data.

How to exercise your rights

  • In the app: Profile → Export my data (access), Profile → Delete account (deletion of your account and health data), and iOS Settings → Privacy & Security → Health → FitGlass (withdraw HealthKit access). Voice input is turned off by withdrawing Microphone or Speech Recognition access in the same Settings → Privacy & Security screen.
  • By email: privacy@fitglass.app, from the email address on your account (this is how we verify your identity). We will respond within 45 days.

Withdrawing consent for the AI logger is as simple as not using it — no health data is sent to Google’s AI except when you submit a request. The same is true of voice input: declining or withdrawing the Microphone or Speech Recognition permission disables it and nothing else, and you can still log food by typing, by photo, by searching Jar, with a quick add, or by hand. To withdraw consent for all collection, delete your account; the app cannot function without processing the food you ask it to track.

Appeals

If we decline a request, you may appeal by replying to our response with the word “appeal.” We will review and respond within 45 days of receiving the appeal. Washington residents who are unsatisfied with the outcome may contact the Washington State Attorney General.

Contact

Nisarg Chaudhary · privacy@fitglass.app