# Privacy Policy for Say What U 8 **Last updated: 2026-08-09** This Privacy Policy explains how Say What U 8 ("the App") handles information when you use it. The App is developed by Sasa Kolda ("we", "us"). ## Summary Say What U 8 is designed to keep your meal and diary data on your own device. We don't require you to create an account, and we don't collect your name, email address, or other directly identifying information. The sections below describe exactly what limited data is processed, and why. ## Information We Process ### 1. Meal Diary Data (stored locally only) Meals, calorie/macro totals, goals, and diary history are stored in a local database on your device (SQLite) and are never uploaded to our servers or synced to any account. Deleting the App deletes this data. ### 2. Anonymous Identifier On first launch, the App creates an anonymous, random identifier via Firebase Authentication's anonymous sign-in. This identifier is not linked to your name, email, or any other personal information. It is used solely to: - Enforce a daily limit on AI meal-estimation requests per install - Track your subscription/entitlement status (see "Subscriptions" below) If you uninstall the App, this identifier is not recoverable and any data tied to it (daily quota count, entitlement record) becomes orphaned and unreachable. ### 3. AI Meal Estimation When you describe a meal (by typing or by voice dictation converted to text), that description is sent to our backend (a Firebase Cloud Function), which forwards it to Google's Gemini generative AI API to estimate calories, protein, carbs, fat, and fiber. Only the text of your meal description and your selected measurement system are sent — no name, email, or device identifiers beyond the anonymous ID used for rate-limiting. The estimation result is returned to the App and stored locally; we do not retain a copy of your meal descriptions in our database (our server-side data store only holds a per-anonymous-ID request counter and subscription status — see "Data We Store on Our Servers" below). Because this feature calls Google's Generative Language API, your meal description text is also subject to Google's own data handling for that API. ### 4. Voice Dictation If you dictate a meal using the microphone, on-device or platform speech-recognition services (provided by Apple on iOS, or Google's Speech, Assistant, or Text-to-Speech apps on Android) convert your speech to text within the App. We do not record or store audio; only the resulting text is used, as described above. ### 5. Health Data If you grant permission, the App reads "active calories burned" from Apple Health (iOS) or Health Connect (Android) to help reconcile your calorie balance for the day, and may write activity-related health data back if you use that feature. Health data is used only within the App to display your calorie balance and is not transmitted to our servers, shared with third parties, or used for advertising. ### 6. Subscriptions and Purchases Subscription purchases are handled by Apple's App Store or Google Play Billing, and processed through RevenueCat, our subscription management provider. RevenueCat receives your purchase/transaction data from Apple or Google to validate and track your entitlement status, associated with the App's anonymous identifier (not your personal identity). We receive entitlement status (e.g., "subscription active") from RevenueCat via a webhook, which we store keyed to the anonymous identifier so the App can confirm your subscription across sessions. ### 7. Device Integrity Checks The App uses Google Play Integrity (Android) and Apple App Attest / DeviceCheck (iOS) to verify that requests to our backend come from a genuine, unmodified install of the App, rather than a script or tampered client. This exchanges device integrity signals with Google or Apple but does not involve personal information. ### 8. Analytics The App uses Firebase Analytics to collect standard, aggregated usage data (such as screen views and feature usage) to help us understand how the App is used and improve it. This may include device-level identifiers as provided by the Firebase Analytics SDK, but is not linked to your name or contact information. ### 9. Notifications If you enable notifications, the App may use a device push token (via Expo push notification services) to send you reminders. This token identifies your device/install, not you personally. ## Data We Store on Our Servers Our backend (Firebase/Google Cloud) stores only: - A daily AI-request counter, keyed to your anonymous identifier - Your subscription entitlement status, keyed to your anonymous identifier We do not store your meal descriptions, diary entries, or health data on our servers. Standard cloud-infrastructure operational logs (e.g., Google Cloud Logging) may briefly retain request metadata for debugging and abuse prevention, subject to Google Cloud's standard retention policies. ## Third Parties We Use | Service | Purpose | |---|---| | Google Firebase (Auth, Functions, Analytics, App Check, Cloud Logging) | Anonymous authentication, backend functions, analytics, device integrity, quota/entitlement storage | | Google Generative Language API (Gemini) | AI-based nutrition estimation from meal descriptions | | Apple (App Store, HealthKit, App Attest, DeviceCheck) | Purchases, health data access, device integrity (iOS) | | Google Play (Play Billing, Play Integrity) | Purchases, device integrity (Android) | | RevenueCat | Subscription/purchase management and entitlement validation | Each of these providers processes data under their own privacy policies. ## No Sale of Data, No Advertising We do not sell your data, and the App does not contain third-party advertising or ad-tracking SDKs. ## Children's Privacy The App is not directed at children under 13, and we do not knowingly collect personal information from children under 13. ## Data Deletion Since the App does not use accounts, uninstalling the App removes all locally stored diary data. To request deletion of the anonymous quota/entitlement record associated with a specific install, contact us at info@babynewt.com with any details you can provide (e.g., approximate date of use); note that because the identifier is anonymous, we may not be able to locate a specific record without your help. ## Changes to This Policy We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. ## Contact Us If you have questions about this Privacy Policy, contact us at info@babynewt.com.