Privacy Policy
Effective September 26, 2026 · Last updated October 1, 2026
The short version: your food diary is yours. We store what you log so it can sync between your devices, we don't sell it, we don't show you ads, and you can export your diary or delete all of it whenever you want. Below is the long version, written to be specific rather than vague.
1. Who we are
Healthy Squirrel is operated by Healthy Squirrel. For anything in this policy, including data access and deletion requests, contact support@minmapo.resend.app.
2. You can use this without giving us anything
Guest mode keeps every byte in your own browser's local storage. If you never create an account, we never receive your diary, your weight, or your profile. There is nothing for us to lose, sell, or hand over. Clearing your browser data deletes it, so guest mode is also the mode with no backups.
3. What we collect when you have an account
We store only what the app needs to work:
- Account: your email address, plus the display name you choose, and a password. Supabase Auth stores the password as a salted hash and manages the login session; we never see or store the password itself.
- Profile: age, sex, height, weight, activity level and goal. These exist solely to calculate your calorie and nutrient targets. Nothing here is required to be accurate, and nothing is shared.
- What you log: foods, portions, meals, dates, water, body weight and body-fat percentage, exercise, mood check-ins, rest days, fasting timers, custom foods, recipes, saved meals, favorites, auto-log schedules, and any targets you change by hand.
- Settings: units, water goal, goal weight, reminder times, timezone, and notification preferences. If you turn on reminders, we also store the push address your browser gives us for this device.
- Usage counters: a timestamp each time you use a metered feature (photo scan, voice or typed meal log, barcode scan), so we can apply the free plan’s weekly allowance and the daily fair-use limit. No content, just the count.
- Teams: if you join a coach’s team, the name you show them and your weekly summary (see section 5a).
- Pro waitlist: if you join it, your email address and the plan you picked.
Your allergen list and ingredient watchlist stay on your device. We do not collect your contacts, your location, your health-app data, or anything from other apps.
4. Food photos and voice logging
When you use photo logging, the photo is resized in your browser, which also removes its location and camera details, and sent to our server. Our server forwards it to Google’s Gemini API to identify what’s on the plate.
A meal you type in the describe-a-meal box is sent the same way, as text. A meal you say out loud is sent one of two ways:
- If your browser turns speech into text itself, only the text is sent to us. Some browsers, Chrome included, do that by sending your audio to their own speech service (Google, for Chrome).
- Otherwise the app records a short audio clip (up to one minute) and sends the audio to Gemini through our server.
Then:
- We do not store your photos or audio. They are held in memory for the length of the request and discarded, never written to our database or to disk.
- What gets saved to your diary is the result you confirm (food names, portions, nutrients), not the picture or the recording.
- Google processes the photo, audio or text to answer the request, under the Gemini API terms. We don’t use it to train anything. Google’s policy is linked below.
Photo and voice logging are optional. If you never use them, no image or audio leaves your device.
5. Barcode scanning and packaged foods
Scanning happens in your browser using your camera. Video frames are processed on your device and never uploaded. Open Food Facts, the public database of packaged foods, is involved in three ways:
- When you scan a barcode, your browser looks it up with Open Food Facts. Re-logging a packaged food from Recents or Favorites can look it up again. They receive the barcode and your IP address.
- Product photos in the app load from Open Food Facts, which sees your IP.
- When a food search finds too little in our own database, our server sends the search text to Open Food Facts. That request comes from our server, so they don’t get your IP.
They never receive anything about you or your diary.
5a. Teams (Coach beta)
Nothing is shared with a coach unless you join their team with the code they give you. When you do, your coach can see:
- the name you chose to show them, and
- a weekly summary: for the last 7 days you logged, your average % of target for protein, carbs, fiber, iron, calcium, magnesium, vitamin D and potassium, and how many of those days you logged.
Your coach never sees your diary, your foods, your weight, your calories or your profile. The summary is worked out on your device, and our database rejects a summary that contains anything else. Leave the team at any time and your summary is deleted straight away; so is deleting your account.
6. Analytics and error reports
We collect a small amount of product analytics so we can tell which features get used and when the app breaks. Specifically:
- Product analytics go to PostHog. They are pseudonymous, not anonymous: events are keyed to a random identifier stored in your browser, and to your account id once you sign in. No third-party cookies, no advertising identifiers, no cross-site tracking.
- We record that something happened ("a food was logged", "the upgrade screen was shown", "this error occurred") and never the food, the weight, or any other content of your diary.
- When the app hits an error, we record the crash itself, the error message, the technical stack trace, and which page you were on, so it can be fixed. This is stored on our own infrastructure, keyed to the same random browser identifier, and kept for 90 days. Web addresses and error text are cleaned of query strings and tokens before a report is sent.
- One exception, stated plainly: when a food search returns no results at all, we record the search term in analytics (the first 64 characters, and never a term that looks like an email address). That’s the only way to know which foods are missing from the database. Searches that find something are not recorded in analytics, though a search our database can’t answer is passed to Open Food Facts (section 5).
- We also count page views on our own servers: the page, the referring site, country, device type, browser, and the random browser identifier. No IP address and no account link. We keep these counts with no end date.
- Separately, our host Vercel counts page views for the site (Vercel Web Analytics) and measures how fast pages load for real visitors (Vercel Speed Insights, loading, layout-shift and responsiveness timings, per page). Both are cookieless and store no identifier at all, just aggregate counts and timings by page, country and device type. Neither can follow you across sites or sessions.
- We honor Do Not Track and Global Privacy Control automatically, and you can switch analytics off entirely in Settings → Privacy. That switch covers PostHog, our page-view counts, Vercel’s counts and the speed measurements. Turning it off also deletes the random identifier.
Two things happen before any of those settings can apply. Our fonts load from Google Fonts on every page, so Google receives your IP address and browser details when a page loads. And the sign-in page runs Cloudflare Turnstile, a bot check, which receives your IP address and browser signals while that page is open.
7. Payments
If you subscribe, Stripe processes the payment. Card numbers go straight to Stripe and never touch our servers, we store only your Stripe customer id, your subscription status, and when the current period ends.
8. Who else touches your data
We use a small number of service providers, each for one job. We do not sell personal information, and we do not share it for advertising or cross-context behavioral advertising.
- Supabase, Database and authentication hosting (your account and diary). Privacy policy
- Vercel, Web hosting, content delivery, and cookieless page-view counts (opt-out in Settings). Privacy policy
- Google (Gemini API), Reading food photos, voice clips and typed meal descriptions, only ones you choose to submit. Privacy policy
- Google Fonts, Font delivery, receives your IP address and browser details on every page load. Privacy policy
- Open Food Facts, Packaged-food lookups, receives barcodes you scan or re-log and loads product photos (with your IP address), and the text of searches our database can't answer (from our server, without your IP). Privacy policy
- Cloudflare (Turnstile), Bot check on the sign-in page, receives your IP address and browser signals while that page is open. Privacy policy
- Resend, Email, receives what you send to our contact address, and your email address if you join the Pro waitlist. Privacy policy
- Stripe, Subscription payments, Stripe handles card details, we never see them. Privacy policy
- PostHog, Pseudonymous product analytics and error reports, linked to your account id once you sign in (opt-out in Settings). Privacy policy
9. Where your data lives, and how it's protected
Account data is stored in Supabase (Postgres) and isolated per user with row-level security, so one account's queries cannot return another account's rows. Traffic is encrypted in transit. Data may be processed in the United States and other countries where our providers operate; if you're in the UK or EEA, transfers rely on the providers' standard contractual clauses.
No system is perfectly secure, and we won't pretend otherwise. If a breach affects your data we'll tell you and the relevant regulator within the timeframes the law requires.
10. How long we keep it
Your diary is kept as long as your account exists, that’s the point of a food diary. Delete your account and your account, diary, settings, usage counters, team membership and push settings are removed immediately (see the next section). Other records have their own clocks:
- Usage counters are deleted after 30 days.
- Crash reports are deleted after 90 days.
- Page-view counts are kept with no end date. They have no account link, so deleting your account doesn’t touch them.
- PostHog keeps analytics events for its retention period. Deleting your account doesn’t delete them there yet; email us and we’ll delete them by hand.
- Stripe keeps its own payment records (invoices, receipts), as the law requires.
11. Your rights, and the button that honors them
Whatever jurisdiction you're in, you can:
- Export your data, Settings → Data → Export. You get CSV or JSON of your diary and everything you entered, not a summary. When signed in, export needs a connection. It doesn’t include billing records, usage counters, push settings or team membership; email us for a copy of those.
- Delete everything, Settings → Danger zone → Delete account. This cancels any subscription, then runs immediately and cannot be undone: your account, your diary, your weights, your custom foods, all of it.
- Correct anything, every field is editable in the app.
- Opt out of analytics, Settings → Privacy.
Depending on where you live you may also have rights to object to processing, to restrict it, to withdraw consent, or to complain to a regulator, in the US that may be your state attorney general; in the EU or UK, your national data protection authority. Email support@minmapo.resend.app and we'll respond within one month.
12. Children
Healthy Squirrel isn't intended for anyone under 16, and we don't knowingly collect data from children. Calorie-tracking apps are a poor fit for growing bodies. If you believe a child has created an account, email us and we'll delete it.
13. Changes
If we change this policy in a way that materially affects you, we'll tell you in the app before it takes effect. The "last updated" date at the top always reflects the current version.