CosmoYum · Effective date August 18, 2026
CosmoYum (“the App”, “we”, “us”) is a calorie-tracking app that estimates the nutritional content of your meals from a photo, a typed description, a dictated description or a barcode. This policy explains what data we handle, where it goes, how long it stays, and what you can do about it.
There is no sign-up. The App does not ask for your name, email address, phone number or location, and it does not collect them.
Meal input. When you scan a meal, the App sends what you gave it — a photo, the text you typed, or the text your dictation produced — to our own server (Google Cloud Functions, hosted in the United States), which forwards it to Google’s Vertex AI to identify the dishes and estimate calories and macronutrients. Everything travels over an encrypted connection. Neither the photo nor the text is stored on our server after the answer comes back.
Allergy words. If you tell the App which allergens to warn you about, that list is sent with each meal request — it is what allows the model to answer “this dish may contain honey”. This includes any words you typed yourself. See section 3, which explains why we treat this as sensitive.
Barcodes. If you scan a product barcode, the barcode number is sent to the public Open Food Facts database to look up the product. No identifier of yours is attached to that request.
Dictation. Voice input is transcribed by your device’s own speech recognition (Apple’s Speech framework on iOS). Depending on your device and its settings, Apple may perform that recognition on its servers rather than on the device; we never receive the audio, only the resulting text — which is then treated as meal input above.
In the cloud, under an anonymous identifier. On first launch the App creates an anonymous account (Firebase Authentication). It is an identifier with no name, email or password attached, and it is what keeps your data yours across launches. Stored under it in Google Cloud Firestore:
On your device only. Meal photos. The App keeps a photo as a local file and stores only the path to it — a photo is never uploaded to our storage, only passed through for the analysis described in section 1. Your theme and language choice, and the fact that you accepted this policy, are also local.
Some of what the App holds says something about your body and your health: allergies, sex, age, height, weight and its history, and your weight goal. We ask for each of them for one visible purpose — allergies to warn you about a dish, the rest to calculate your calorie and macronutrient targets — and we do not use them for anything else, do not sell them, and do not share them with advertisers (there are none in the App).
Two consequences worth stating plainly. Your allergy list leaves the device with every meal request, because a warning is impossible otherwise. And your body metrics sit in the cloud rather than only on your phone, so that a new device shows the same diary and the same plan.
Crash reporting. The App uses Firebase Crashlytics. When it crashes or hits a handled error, a report goes to Google containing the error, a stack trace and technical details of the device (model, OS version). Photos, meal contents and credentials are deliberately kept out of these reports.
Server logs. Our server logs each request it handles for diagnostics: the model used, timings, sizes, and — while the App is still stabilising — the meal description you typed. Photo bytes are never logged, and the allergy words are logged only as a count, never as words. These logs live in Google Cloud Logging and are retained for a limited period (currently up to 30 days), then deleted automatically.
All traffic uses HTTPS/TLS. Your cloud data is readable only by your own anonymous identifier, enforced by server-side security rules. The App ships with no API keys of its own: it can only reach the AI model through our server, which holds the credentials, so nothing sensitive can be extracted from the installed App.
The recognition counter is the one piece of your data the App can read but not write. Only our server may change it — which is what makes the daily limit a limit rather than a suggestion.
Your diary and profile stay until you delete them. Deleting a meal in the App deletes it from the cloud as well.
Uninstalling the App does not delete your cloud data. Because the anonymous identifier lives on the device, uninstalling makes that data unreachable rather than gone. If you want it erased, email us at the address below from the device in question and we will delete it; we are also working on a “delete everything” action inside the App.
Server logs expire on their own, as described in section 4.
The App is not directed at children under the age of 13, and we do not knowingly collect information from them. If you believe a child has provided information through the App, contact us and we will remove it.
We update this policy when the App changes what it does with data, or when the way to reach us changes. This revision records the App’s name — previously SecretCal — and moves the policy to its own address at cosmoyum.app, with a contact address on that domain rather than a personal mailbox. The revision before it recorded the recognition counter of section 2 and the daily limit it enforces; the one before that, that the diary and profile now live in the cloud, that text and dictation are analysed alongside photos, and that crash reporting is enabled. Material changes are announced in the App. The effective date at the top always reflects the latest revision.
Questions, or a deletion request? Email privacy@cosmoyum.app.