Skip to content

Privacy Policy

How Heyberry handles your data, in plain words.

Version 2026-09-28Last updated September 28, 2026

Heyberry is an iPhone app that estimates the calories and nutrients in your food from a photo, a barcode or a recipe, keeps a daily food diary and builds a weight plan. This policy explains what personal data the app and our website getheyberry.com process, why, who helps us process it, how long we keep it and what you can do about it. It applies to everyone who uses Heyberry, including people testing it through TestFlight.

Summary

  • Your food diary, meal photos and body measurements are health data. We process them only to provide Heyberry, and the current app asks for your explicit consent first (section 3 also covers earlier beta versions).
  • You can use Heyberry without an account, but what you log is still stored on our servers, linked to a random ID.
  • Meal photos, notes and recipes are analyzed by Google’s Gemini AI model, which we reach through a service called OpenRouter. OpenRouter keeps a copy of each request, including your photos and notes, for at least 3 months. To check the quality of the results we also keep monitoring records in a service called Langfuse, photos included. Neither is deleted automatically or when you delete your account, but you can ask us to have them deleted.
  • We don’t sell your data and we don’t show ads. The app and this website contain no advertising or analytics trackers.
  • You can delete your data in the app, in Settings, or by emailing us.
  • Heyberry is operated from Poland, so the EU General Data Protection Regulation (GDPR) applies to all of our processing, wherever you live. Our servers and most of our service providers are in the United States.

1. Who we are

Heyberry is operated from Poland, in the European Union (“we”, “us”). We are the controller of your personal data: we decide why and how it is processed.

Email: support@getheyberry.com. We have not appointed a data protection officer.

You may notice two of our domains: getheyberry.com (this website, and hello@getheyberry.com, the sender of our emails) and jjjlabs.com (the address of the server the app talks to, cal-tracker-api.jjjlabs.com).

2. What we collect and why

2.1 Your account

  • A random user ID. The first time you open Heyberry, the app creates an anonymous account for you. You don’t need to give a name or an email address. Everything you log is stored on our servers under this ID.
  • Your email address, if you save your progress or sign in with email. We send a 6-digit code to confirm it. There is no password.
  • Your Apple sign-in, if you use Sign in with Apple. We ask Apple only for your email address, which can be an Apple relay address if you choose Hide My Email. We don’t ask for your name.
  • Moving guest data. If you sign into an account you already have, the app asks whether to bring what you logged as a guest into it. If you choose not to, we delete it from our servers at that moment, together with the guest ID, and the question tells you so. When you do bring it over, the empty guest ID is deleted too. If the question is left open for more than an hour, the guest data stays on our servers under the guest ID.

2.2 Your profile (health data)

To build your plan, the app asks for your goal (lose, maintain or gain weight), your sex (female or male, because the calorie formula needs it), your date of birth, height, weight, goal weight, how fast you want to reach it, your activity level and your preferred units. It also sends your phone’s time zone. It optionally asks where you heard about Heyberry.

We use these answers to calculate your daily targets for calories, protein, carbohydrates and fat and the date you could reach your goal. We calculate the targets whenever you open the app and don’t store them. The app also shows your BMI, calculated from your height and weight. Your starting weight and every weight you log later are stored as weigh-ins, one per day.

2.3 Your food diary (health data)

  • Meals: what you log from a photo, a barcode, a recipe, the list of common foods or a quick calorie entry; when you ate; the foods, amounts and nutrient estimates; your answers to the app’s follow-up questions; your changes; dishes made of several parts; and meals you log again. Drafts you haven’t logged yet are stored too.
  • Meal photos. Before uploading, the app shrinks each photo to at most 1024 pixels and saves it as a new JPEG file, which doesn’t carry the location or camera details of the original. We keep photos in a private cloud storage bucket, and the app shows them through links that expire after one hour.
  • Notes you add to a photo, up to 500 characters (for example “2 tablespoons of olive oil”).
  • Analysis records: for each AI analysis, the model and prompt version, the model’s answer, your note, and technical details such as timing and cost. We use them to show and correct estimates and to find errors.
  • Saved recipes. When you import a recipe from a link or pasted text, we save its title, an English name for the dish, the number of servings, the ingredient lines with amounts and nutrient values, the link (without tracking parameters) and the address of the recipe’s picture. We don’t save the web page itself. We also save a numeric representation (an “embedding”) of the dish name, so we can suggest your recipe when you later photograph a similar dish.

When you search for recipes, we receive the words you type, your phone’s language and region setting, and the country of your IP address, which Google’s load balancer adds to the request. We send the words, the country and its language to our search providers (section 5) without your user ID. Identical searches are kept in our server’s memory for 60 seconds so we don’t pay for them twice. We don’t store your search words with your account, and your recent searches are saved only on your phone.

The current app sends the words in the body of the request, so they don’t appear in our server’s request logs. Earlier versions of the app send them in the request address, and our request logs keep that address for 30 days.

2.5 Barcodes, and pictures from other websites

  • Barcodes. Our server looks up the barcode in Open Food Facts, a public food database. Open Food Facts receives only the barcode from our server, not who you are. We keep the product data in a cache shared by all users.
  • Pictures and pages from other sites. Product pictures load on your phone directly from Open Food Facts, and recipe pictures load directly from the recipe websites. Recipe pages open in an in-app browser. These sites see your IP address, as with any website you visit, and their own privacy policies apply.

2.6 Technical data

  • Requests to our server. Our cloud provider, Google Cloud, logs your IP address, your device and app version (the user agent), the time and the address requested, which can include a date, your time zone, a barcode or, from earlier versions of the app, search words. These request logs are kept for 30 days. Our own logs record errors and short technical notes, never your photos.
  • Sign-in. The app talks directly to our sign-in provider, Supabase, which logs your IP address and device information for security.
  • App updates. The app checks Expo’s servers for updates. These requests include your phone’s operating system, the app version, a random installation ID and your IP address.

We use this data to run Heyberry, keep it secure and fix problems.

2.7 Data stored on your phone

The app stores on your phone only what it needs to work: your sign-in session, your setup answers until you finish setup (then they are cleared), a copy of the app’s texts, your recent recipe searches, a few settings (for example whether we already asked you to save your progress) and cached pictures. Deleting the app removes them. The app uses no cookies, no advertising identifiers and no third-party trackers.

  • Camera and photos. The app uses the camera only to photograph meals and scan barcodes. When you pick a photo from your library, iOS gives the app only the photo you choose.
  • Clipboard. To offer “Paste link”, the app checks whether your clipboard holds a link without reading it. It reads the clipboard only when you tap Paste.

2.8 Emails with us

If you email support@getheyberry.com, we receive your email address and your message. Cloudflare forwards these emails to our mailbox, which is hosted by Google (Gmail).

2.9 Payments

Heyberry doesn’t sell anything yet, and nothing is charged during the beta. When subscriptions start, Apple will sell and bill them through In-App Purchase, so we will never see your payment card details. We will update this policy before then.

2.10 TestFlight

If you test Heyberry through Apple’s TestFlight, Apple shares with us the crash reports and feedback you choose to send and, if we invited you by email, your name and email address. Apple’s privacy policy applies to TestFlight. Everything else in this policy applies to beta testers in the same way.

2.11 Our website

When you visit getheyberry.com, our hosting provider, Vercel, processes your IP address and browser details to deliver the pages and keep the site secure. The website sets no cookies and uses no analytics or advertising trackers. Its fonts and pictures are served from the site itself; the links to TestFlight and the App Store take you to Apple.

2.12 What we don’t collect

We don’t collect your precise location, contacts, microphone input or Apple Health data, and we don’t use advertising identifiers. The app contains no analytics tools, and we don’t track you across other companies’ apps or websites.

PurposeDataLegal basis
Create and run your account, sign you in, move guest data into your accountuser ID, email address, Apple sign-inPerforming our contract with you (art. 6(1)(b))
Your plan, targets, weigh-ins and food diary, including the AI analysis of photos, notes and recipesprofile, weigh-ins, meals, photos, notes, recipesContract (art. 6(1)(b)) and, because this is health data, your explicit consent (art. 9(2)(a))
Checking the quality of AI estimates and fixing errors (analysis records, monitoring records)the data above and technical dataOur legitimate interest in an accurate, working service (art. 6(1)(f)); for health data, your explicit consent (art. 9(2)(a))
Recipe search and barcode lookupsearch words, country, language, barcodeContract (art. 6(1)(b))
Security, preventing abuse, server logsIP address, device data, request logs, IDs sent to our AI providerLegitimate interest in a secure service (art. 6(1)(f))
Where you heard about Heyberry (optional question)your answerLegitimate interest in knowing which channels work (art. 6(1)(f))
App updatesinstallation ID, app version, IP addressLegitimate interest (art. 6(1)(f))
Delivering this websiteIP address, browser detailsLegitimate interest (art. 6(1)(f))
Beta feedback and crash reports from TestFlightwhat you choose to send, name and email address if we invited youLegitimate interest in improving the app (art. 6(1)(f))
Answering your emailsemail address, messageContract or legitimate interest (art. 6(1)(b) or (f))
Establishing or defending legal claimsthe data neededLegitimate interest (art. 6(1)(f)); for health data, art. 9(2)(f)

Giving us data is voluntary, but without your health data and your consent we can’t provide the plan or the food diary.

We treat the following as health data: your height, weight and weigh-ins, goal weight and pace, activity level, the targets and BMI we calculate from them, and your food diary (meals, photos, notes, the recipes you log and their nutrition estimates). Your sex and date of birth are not health data on their own, but we protect them the same way because we use them together with your measurements.

Your explicit consent. Before the first question about your body, the app asks you to agree that we process your health data as described in this policy, including the AI analysis in section 4 and processing in the United States, and to confirm that you’re 18 or older. If you log meals without going through setup, the app asks the same question before your first meal. We record when you agreed and which version of this policy you saw.

Earlier beta versions. Versions of the app released before 28 September 2026, which some TestFlight testers still use, didn’t ask for this consent. When your app updates, it asks before you log anything new. Until then, and at any time, you can have your data deleted (section 10).

Withdrawing consent. You can withdraw your consent at any time in Settings: Withdraw consent and erase my data, or Delete account (Erase my data if you use Heyberry as a guest). Every feature of Heyberry uses health data, so withdrawing consent means we delete your data (section 10). Withdrawal doesn’t affect processing that took place before it.

Consumer health data

Some US state laws, such as Washington’s My Health My Data Act and a similar law in Nevada, give extra protection to consumer health data. For those laws, this section is our consumer health data privacy policy.

  • What we collect: the health data listed above. It comes from you: what you enter, the photos and notes you send and the recipes you import, and the estimates our AI provider makes from them.
  • Why: only to provide Heyberry, as described in sections 2 to 4, and only with your consent.
  • Who receives it: the service providers in section 5, which process it for us, and nobody else. We don’t sell it and we don’t use it for advertising.
  • Your rights: you can access it, delete it, withdraw your consent and ask us which of our providers received it, in the app or by email (sections 9 and 10).

Not medical advice. Heyberry gives estimates for general wellness. It isn’t a medical device and doesn’t give medical advice.

4. AI processing of your photos, notes and recipes

How a photo becomes an estimate:

  1. The app shrinks the photo and sends it, with your note, to our server.
  2. Our server stores the photo in our private storage bucket and sends the photo and your note to OpenRouter, which passes the request to Google’s Gemini model (currently Gemini 3.8 Flash). The request runs on our own Google Cloud account, through Google AI Studio or, as a backup, Vertex AI.
  3. The model returns the foods it sees, estimated amounts, nutrient values, a title, the assumptions it made and, when something is unclear, questions for you. We store the result with your meal.

Recipes you import are read the same way: the text of the recipe page, or the text you pasted, goes to the model. To suggest your saved recipes for later photos, we also send English dish names, without your user ID, to Google’s Gemini embedding service.

  • Identifiers. With each request we send OpenRouter your random user ID and the meal’s ID. OpenRouter uses them for abuse monitoring and its activity log.
  • No training. We tell OpenRouter to route our requests only to providers that don’t collect data for training, and Google’s terms for paid services say it doesn’t use such requests to improve its products. We don’t use your photos, notes or corrections to train AI models, and we won’t without asking for your separate consent.
  • Abuse monitoring. Google may keep copies of requests for a limited time to detect abuse: up to 55 days for the Gemini API, and up to 90 days for requests that Vertex AI’s safety systems flag.
  • Where. OpenRouter processes requests on servers in the United States. Google may process requests in any of its data centers, because we haven’t limited the AI to one region.
  • OpenRouter’s log. OpenRouter keeps a copy of each request and answer, including photos, notes, recipe text and your user ID, for at least 3 months and possibly longer. Deleting your account doesn’t delete it. OpenRouter deletes it when we ask; email us if you want this.
  • Monitoring records. To check the quality of estimates and fix errors, we record each AI action in Langfuse, a monitoring service: your user ID, the meal’s ID, your note, the photo, what we sent to the model and what it returned. For recipe searches we record the length of the search, your language setting and your country, not the words. These records aren’t deleted automatically, and deleting your account doesn’t delete them. Email us if you want yours deleted.
  • Estimates can be wrong. You can change amounts, answer the app’s questions, add a note and run the analysis again, or delete the meal. The analysis doesn’t make decisions about you that have legal or similarly significant effects.
  • Photograph food only. Photos can show more than food. Please keep people, documents and screens out of the picture. We don’t use photos to identify anyone.

5. Who processes your data

These providers process data for us, to run the parts of Heyberry listed next to them.

ProviderWhat they do for usData involvedWhere the data is
SupabaseDatabase and sign-inall account, profile and diary data; email address; sign-in logsAmazon Web Services us-east-1 (Virginia, USA)
Google CloudServers (Cloud Run), photo storage (Cloud Storage), secrets, server logsrequests, photos, IP addresses in logsus-east4 (Virginia) and us-east1 (South Carolina), USA; logs in Google Cloud’s global logging storage
Google (Gemini API and Vertex AI)AI analysis; dish-name embeddingsphotos, notes, recipe text, dish namesNot limited to one region
OpenRouter, Inc.Routes AI requests to Google and keeps a log of them (section 4)photos, notes, recipe text, user ID, meal IDUSA
LangfuseMonitoring AI quality and errorsuser ID, meal ID, photos, notes, AI inputs and outputs, recipe links (without query), search country and languageLangfuse’s US cloud region, USA
TinyFishPictures and backup results for recipe search; reading recipe pages that block our serversearch words, country and language; recipe linksNot stated by the provider
Treg (treg.to), which passes searches to Serper (serper.dev)Google search results for recipe searchsearch words, country and languageNot stated by the providers
ResendSends sign-in code emailsemail address, codeAmazon Web Services us-east-1, USA
CloudflareDomain name service; forwards emails sent to getheyberry.comemails you send usGlobal network
Google (Gmail)Our support mailboxyour emails to usGoogle’s data centers
VercelHosts this websiteIP address and browser details of visitorsGlobal network
Expo (650 Industries)Delivers app updatesIP address, device platform, app version, installation IDUSA-based service

Companies that process data under their own policies, and not as our processors: Apple (App Store, TestFlight, Sign in with Apple, In-App Purchase); Open Food Facts (it receives barcodes from our server and serves product pictures to your phone); and the websites whose pictures or pages you open.

We don’t sell personal data, we don’t share it for advertising, and we don’t give it to data brokers. We disclose data to authorities only when the law requires it.

6. Transfers outside the EU

We are in the EU, and most of our providers store or process data in the United States or don’t limit processing to one region, so your data leaves the European Economic Area. Where a provider is certified under the EU-U.S. Data Privacy Framework, the transfer relies on it; otherwise we rely on the European Commission’s standard contractual clauses where the provider’s terms include them. You can ask us which safeguard applies to a provider.

7. Security

  • The app talks to our server and to Supabase only over encrypted HTTPS connections, and our server calls its AI and search providers over HTTPS.
  • Our database (Supabase), our photo storage (Google Cloud Storage) and OpenRouter’s log are encrypted at rest by those providers.
  • Photos are kept in a private bucket with public access blocked, and the app receives links to them that expire after one hour.
  • Every request is checked against your sign-in, and our server returns only your own data.
  • Server keys and passwords are kept in Google Secret Manager, not in the app.
  • Recipe links you paste are checked before our server fetches them, so they can’t reach private networks.
  • Your sign-in session is stored in the app’s storage on your phone, so keep your phone locked.

If a data breach puts your rights at risk, we will notify the Polish data protection authority within 72 hours and tell you when the law requires it.

8. How long we keep data

DataHow long
Account, profile, weigh-ins, food diary, photos, saved recipes, analysis recordsUntil you delete them or your account. We don’t delete inactive accounts automatically, including guest accounts.
A meal you deleteDeleted at once with its photo, items and analysis records. A deleted photo stays recoverable in our storage for 7 days, then it’s gone.
Guest data you choose not to bring into your accountDeleted when you choose, together with the guest ID (section 2.1).
Monitoring records (Langfuse)Until we delete them. They aren’t deleted automatically or when you delete your account; email us to have yours deleted.
OpenRouter’s log of AI requestsAt least 3 months, possibly longer. Not deleted with your account; OpenRouter deletes it when we ask.
Google’s abuse-monitoring copies of AI requestsUp to 55 days (Gemini API); up to 90 days for requests Vertex AI flags
Server request logs (Google Cloud)30 days
Sign-in logs (Supabase)Kept by Supabase for a short period under its own policies; on our plan we can see them for 1 day
Database backups (Supabase)Supabase may keep daily backups of our database for up to 7 days
Sign-in code emails (Resend)30 days
Website request data (Vercel)Kept by Vercel for a short period under its own policies
Your emails to supportUntil we delete them; ask us and we will
Recipe search memory on our server60 seconds
Data on your phoneUntil you delete the app; setup answers until you finish setup

9. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • have it corrected;
  • have it deleted;
  • restrict how we use it;
  • receive it in a portable format (we send you a JSON file, which today we prepare by hand);
  • object to processing based on our legitimate interests;
  • withdraw your consent at any time (section 3);
  • complain to a data protection authority: in Poland, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl, or the authority where you live or work.

US residents. Depending on your state, you may have the right to know about and access your data, correct it, delete it, get a portable copy, and opt out of its sale, targeted advertising and certain profiling; for consumer health data, also to withdraw consent and to learn which third parties receive it. Some of these laws apply only to businesses above a certain size; we honor these requests from everyone. We don’t sell personal data, use it for targeted advertising, or profile you in ways that have legal or similarly significant effects, so there is nothing to opt out of. You can use an authorized agent; we’ll confirm the request with you. We won’t treat you differently for using your rights. If we decline a request, you can appeal by replying to our answer, and if you disagree with the outcome of the appeal, you can contact your state attorney general.

How to use your rights. In the app you can view and edit your meals and delete meals, your data or your account. For anything else, email support@getheyberry.com. We answer within one month under the GDPR, or 45 days under US state laws, and tell you if we need more time where the law allows it. We may ask you to confirm a request from the email address of your account. If you use Heyberry as a guest, we can’t tell from an email alone which data is yours, so please use the options in the app; if your version of the app doesn’t have them yet, email us and we’ll help you find your data.

10. Deleting your account

  • In the app: Settings (the person button on Today) → Delete account, or Erase my data if you use Heyberry as a guest. Withdraw consent and erase my data, under Privacy, does the same. Earlier beta versions of the app don’t have Settings; it comes with the next update, or you can email us instead.
  • Deleted at once: your meals with their photos, items and analysis records, your saved recipes, weigh-ins and profile, and your sign-in account (email address or Apple sign-in).
  • Not deleted by it: the monitoring records in Langfuse and OpenRouter’s log (section 4), which you can ask us to have deleted; Google’s abuse-monitoring copies, server and sign-in logs and backups, which expire on their own (section 8); deleted photos, which stay recoverable in our storage for 7 days; and your emails to support (ask us to delete them).
  • Subscriptions: deleting your account won’t cancel an Apple subscription. Cancel it in your Apple ID settings.
  • Sign in with Apple: deleting your account doesn’t remove Heyberry from the apps that use your Apple ID. You can do that in your Apple ID settings, under Sign in with Apple.
  • Uninstalling the app doesn’t delete your data on our servers, and signing out doesn’t delete anything.

You can also ask us by email to delete your data.

11. Children

Heyberry is for adults. The current version of the app asks you to confirm that you’re 18 or older before you give it health data, and its setup accepts only ages 18 to 100. We don’t knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We will publish any new version on this page with a new date. If a change affects how we use your health data or adds a new kind of recipient, we will tell you in the app before the change applies and ask for your consent again where it’s needed.

13. Contact

Heyberry, operated from Poland, European Union. Email: support@getheyberry.com