Privacy Policy for FoodBalance
Overview
Every sentence below is a statement about the code that ships in the app,
not a statement of intent. This policy covers the Android app FoodBalance —
Calorie Tracker, application ID com.gante.foodbalance.
FoodBalance is published by Gi-Gante s. r. o.; "we" means Gi-Gante s. r. o.,
and "us" and "our" refer to it as well.
FoodBalance is a food diary: meals, weight, targets and reminders. The app has no sign-in screen in this build; the diary, weight, targets and settings are stored in a database on your device. The things that reach the network are: a product lookup in Open Food Facts when you scan a barcode the app does not know or search by name, the product images that come with it, and a weekly background refresh of cached products from your diary; product data, reports of a data error and, from release 1.1, photos of nutrition tables that you choose to send to Open Food Facts, which from release 1.1 go there through our server; a photo of a recipe and, from release 1.1, a photo of a meal or, with FoodBalance Pro, of a nutrition label that you choose to have read, which goes to our server and from there to Google for recognition; downloads of the country food packs; buying FoodBalance Pro through Google Play; the diagnostics that Google's barcode-scanning and text-recognition components report about themselves; and a support letter, if you write one.
FoodBalance gains features release by release, and test builds gain them one at a time. This policy describes release 1.1. What came with release 1.1 is marked "from release 1.1" below; release 1.0 has none of it. When a build does not have one of the features below yet, that feature's data flow does not happen in it either. From release 1.1, the features that send something to our server are switched on one at a time, our server can switch each of them off again, and the ones that send photos are not offered in Russia (see Meal photo and label reading). The list of permissions is the one of the current release build.
Data stored on your device
FoodBalance keeps the following in the app's private storage on your device:
- the diary: meals, the foods and amounts you log and the nutrition values of each entry, and water; from release 1.1 also the place you may type for a meal eaten out, such as the name of a café;
- foods and recipes you create, meal templates and favorites;
- weigh-ins;
- your profile: year of birth, sex, height and activity level, and the targets calculated from them or set by you; from release 1.1 also targets by day of the week, meal budgets and the allergens you mark in Plan and goals;
- from release 1.1, the profiles of other adults you add with FoodBalance Pro, each with its own name and the same kinds of data as yours (see Several profiles on one phone);
- from release 1.1, the active calories of each day that the app reads from Health Connect while "Adjust target by activity" is on (see Health Connect);
- from release 1.1, a short record of each import from a file or from Health Connect (see Importing a diary from another app);
- from release 1.1, the settings of automatic backup and the app's access to the folder you chose for it (see Android backup and phone-to-phone transfer);
- reminder settings;
- a cache of Open Food Facts products you looked up, with small product images;
- the country food packs;
- the state of FoodBalance Pro (see Purchases);
- barcodes waiting for a lookup while the phone was offline, and products, corrections and reports of a data error waiting to be sent to Open Food Facts; from release 1.1 also the label photos you chose to send with them (see Open Food Facts);
- from release 1.1, a mark with the date on each product you reported an error on, kept until a newer record of that product arrives (see Open Food Facts);
- a random identifier that the app creates at your first contribution to Open Food Facts (see Open Food Facts); from release 1.1 also the date our server refused contributions from this device, if it did;
- the date you agreed to send photos for recognition and, from release 1.1, the version of that consent; from release 1.1 also the date you agreed to the publication of label photos in Open Food Facts; and a random installation identifier that the app creates the first time it contacts our server (see Recipe from photo);
- from release 1.1, meal photos waiting to be recognized, each with the note you may have typed, until our server answers; the answer for each meal photo and the portions you saved from it; and, only while you keep thumbnails turned on, a small copy of each saved meal photo (see Meal photo and label reading);
- local usage counters, which the app uses for the daily limits of the free version and to decide when to show a hint; they are used only inside the app;
- entries, foods, recipes and days you delete, kept in the trash for 30 days so you can bring them back;
- up to seven daily copies of the database, kept in the app's storage so that the Data and database screen can restore an earlier day;
- a local error log: when something in the app fails, the error is written to a file in the app's storage after food names, numbers, barcodes and paths are removed from it. It leaves the device only inside a support letter you send (see Support letters).
From release 1.1, the allergens of your profile are used on the device only, to show which foods contain them or may contain them; a support report does not include them. The place of a meal eaten out is used to suggest the places you typed before and to offer "Repeat last order here". Like the rest of the diary it goes into the backup file you export (see Android backup and phone-to-phone transfer), but not into the CSV files, a PDF report, a support report, Health Connect or anything sent to Open Food Facts. Weekly insights, the monthly report, the range of a day's calories and the vitamins and minerals left after cooking are worked out on the device from the data above; the app sends nothing for them.
Uninstalling the app removes all of this from the device. Profile → Data and database → Erase everything removes it while keeping the app installed.
Importing a diary from another app
From release 1.1, you can move your food diary and weight history from a file exported by another app. The file you pick is read on your device, and its entries are added to the diary on your device; importing makes no network requests. The app keeps the imported entries and a short record of each import (its date, the kind of file it recognized, the number of rows and the numbers of the rows it could not read); it does not keep the file or its name. Imported entries are not written to Health Connect.
- Only the files you pick. The app reads the files you choose in the Android file picker and has no access to the rest of the phone's storage. The copy of a picked file that the file picker places in the app's cache is deleted when the import finishes or is cancelled.
- Nothing more leaves the device. Imported entries and weigh-ins are not sent to Open Food Facts, and the text of the file is not written to the local error log or to a support report.
- You can undo it. Before an import the app saves a copy of its database on the device. "Undo import", at the end of the import and on the Data and database screen, moves the entries of that import to the trash and brings back the entries it replaced.
- From Health Connect. The same screen can import the nutrition records and weigh-ins that other apps wrote to Health Connect; that import is described in the section on Health Connect.
Several profiles on one phone
From release 1.1, FoodBalance Pro lets up to six adults keep their own diaries on one phone, each in a profile of its own: Profile → Profiles. Each profile has its own name, year of birth, sex, height, activity level and allergens, targets, diary, weigh-ins, water, streak, reminders and display settings, such as numbers turned off. Foods and recipes you create, meal templates, favorites, the country packs and the product cache are shared by all profiles on the phone. Profiles are kept on the device like the rest of the diary, and switching between them sends nothing.
- Adults only. The app creates no profile, the first or any other, when the entered birth year shows an age under 18.
- Who ate. When you log a dish for several people, the app writes one entry into the diary of each profile you choose.
- Reminders of every profile are scheduled on the device. With two or more profiles, a reminder shows the name of its profile.
- Home-screen widgets show the profile that is active in the app.
- Health Connect is linked to the first profile only (see Health Connect).
- Files and reports. The backup file holds every profile; the CSV files hold the profile that is active when you export them. A support report gives the number of profiles, not their names.
- Deleting a profile deletes its diary, weigh-ins and targets; shared foods and recipes stay. Erase everything deletes every profile. When Pro ends, all profiles stay and can still be used, but a new one cannot be added.
Android backup and phone-to-phone transfer
Backup is switched off in the app's manifest, both for Google Drive backups and for device-to-device transfer. The app has its own backup instead: Profile → Data and database → Export writes a JSON file where you point the system file picker or share sheet, and nowhere else. The same screen exports the diary and weigh-ins as CSV files.
From release 1.1, FoodBalance Pro can also write the same backup file on a schedule. On the Data and database screen you turn on Automatic backup and choose a folder in the Android folder picker; the app gets access to that folder only and needs no storage permission for it. Then, once a day or once a week, by default only while the phone is charging, the app writes a backup file into that folder and deletes the oldest of its backup files there when there are more than you chose to keep (seven by default). When the folder belongs to a cloud storage app, such as Google Drive, that app uploads the file under its own terms: FoodBalance hands the file over on the phone and does not upload it itself. If the folder can no longer be reached, the Data and database screen says so, and the app does not ask for access again until you choose a folder. When Pro ends, automatic backups stop, and the copies already made stay in the folder.
From release 1.1, FoodBalance Pro also makes a PDF report: of a month on the Progress screen, or of a period on the Data and database screen. The PDF is made on the device and leaves it only through the Android share sheet, to the app you pick. It holds what the report on the screen shows: the days, foods and numbers of your diary for those days and the weight trend, but not the places of meals eaten out.
The backup file holds your diary and weight, your profile with its allergens and the places you typed for meals eaten out and, from release 1.1, every profile on the phone. The app does not encrypt it, so keep it where you trust it. It does not contain the Pro purchase, the Open Food Facts cache, the country packs, the marks of errors you reported, the error log, the Open Food Facts identifier, the installation identifier of our server or the records of imports, nor, from release 1.1, the answers, waiting photos and thumbnails of meal photos; the diary entries saved from a meal photo are in it like any other. From release 1.1 the CSV files hold the profile that is active when you export them. On a new phone, "I have a backup" on the first screen restores the backup file, including one written by automatic backup.
Data collection
This build contains no advertising SDK, no analytics SDK and no crash-reporting SDK. The app does not send the diary, weight, targets or profile to a server of ours. Recipe from photo sends a photo you choose to a server of ours and from there to Google. From release 1.1, so do Meal photo and, with FoodBalance Pro, cloud label reading, and contributions to Open Food Facts pass through the same server, which has Google Cloud Vision check a label photo before it is published. Each of these has a section of its own below. Two Google ML Kit components report diagnostics to Google (see below); a support letter reaches us only when you send it.
The barcode scanner and the label text recognizer bring Google's data-transport library with diagnostics reporting enabled; what it reports is listed in the section on Google ML Kit. Everything else that goes out is described in this policy: Open Food Facts, the pack hosting, our server, Google Play and your own mail app. From release 1.1, a backup file that automatic backup writes into a folder of a cloud storage app is uploaded by that app, not by FoodBalance (see Android backup and phone-to-phone transfer); importing a diary and reading Health Connect happen on the device.
After a week in which you logged food on at least five days, and only right after you close a day, the app may ask Google Play to show its rating card, at most once in 90 days. Google Play shows the card and handles any rating or review you leave; the app does not learn what you rated.
Permissions the release build declares
This is every permission in the release build and where it comes from:
- android.permission.CAMERA — the barcode scanner, the photo of a nutrition label, the photo of a recipe and, from release 1.1, the photo of a meal. Android asks you to approve it the first time you tap Scan or add a food from a label, after a screen that explains why, or the first time you take a recipe photo or, from release 1.1, a meal photo. Barcode and label frames are processed on the device; a recipe photo and, from release 1.1, a meal photo, a label photo you choose to send to Open Food Facts and a label you have read in the cloud are sent to our server (see Camera and photos).
- android.permission.POST_NOTIFICATIONS — reminders for meals, water and weigh-ins, the daily summary and, from release 1.1, a quiet notification that a meal photo saved for later has been recognized. Android asks you to approve it at the end of the first-run setup or when you first turn on a reminder.
- android.permission.VIBRATE — vibration of reminders, if you choose one in the reminder settings.
- android.permission.RECEIVE_BOOT_COMPLETED — puts the reminder schedule back after the phone restarts. WorkManager, the Android library that runs the app's background tasks, declares it too.
- android.permission.SCHEDULE_EXACT_ALARM — from release 1.1, the Exact timing option of the reminder settings, which is off until you turn it on: with it, a reminder comes at the minute you chose rather than around it. When you turn the option on, the app opens the system screen "Alarms & reminders", where you allow it; Android 12 and 13 may allow it at install without asking, and Android 11 and earlier have no such permission. Without the option, reminders stay approximate even when the permission is allowed. While it is allowed, the home-screen widget also turns to the new day exactly at the day boundary. You can withdraw it in the system settings at any time; reminders then come around the chosen time again. It sends nothing off the device.
- android.permission.INTERNET — Open Food Facts lookups and contributions, country pack downloads, recipe photo recognition, from release 1.1 meal photo and cloud label recognition, and Google Play purchases. The data-transport component that comes with Google ML Kit and Google Play Billing declares it as well (see Google ML Kit).
- android.permission.ACCESS_NETWORK_STATE — lets the app see whether the phone is online before a lookup and show the "Offline" chip; it reads the connection state only. The same Google data-transport component declares it as well.
- com.android.vending.BILLING — brought by the Google Play Billing library for buying FoodBalance Pro (see Purchases). It gives access only to Google Play's billing service, and Android does not ask you to approve it.
- android.permission.FOREGROUND_SERVICE and android.permission.FOREGROUND_SERVICE_SHORT_SERVICE — declared by WorkManager for a service of its own. FoodBalance does not start a foreground service.
- android.permission.WAKE_LOCK — declared by WorkManager, which uses it internally while a background task such as a pack update runs.
- com.gante.foodbalance.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION — a signature-level permission declared by the AndroidX core library so that the app can register broadcast receivers for itself. Only code signed with our own key can use it, so it grants nothing to any other app.
- android.permission.health.READ_WEIGHT and android.permission.health.WRITE_WEIGHT — the Weight switch on the app's Health Connect screen: weigh-ins from scales and other apps are read into the weight chart and the calorie target, and weigh-ins you enter in FoodBalance are written to Health Connect (see Health Connect).
- android.permission.health.WRITE_NUTRITION — the Meals switch: each meal you log is written to Health Connect (see Health Connect).
- android.permission.health.WRITE_HYDRATION — the Water switch: each glass of water you log is written to Health Connect (see Health Connect).
- android.permission.health.READ_STEPS — from release 1.1, the Steps today switch: the steps of the day are read and shown on the Today screen (see Health Connect).
- android.permission.health.READ_ACTIVE_CALORIES_BURNED — from release 1.1, the Adjust target by activity switch of FoodBalance Pro: the active calories of the day are read, and part of them is added to that day's calorie target (see Health Connect).
- android.permission.health.READ_NUTRITION and android.permission.health.READ_HEALTH_DATA_HISTORY — from release 1.1, the import from Health Connect: nutrition records that other apps wrote to Health Connect, including records older than 30 days, are read into the diary when you start that import (see Health Connect and Importing a diary from another app).
Android asks you to approve two of these, each at the moment you use the feature: the camera and, on Android 13 and later, notifications. From release 1.1, exact alarms are allowed on a system screen that the app opens only when you turn on Exact timing. Health Connect asks you to approve its permissions in its own dialog, only for the switch you turn on or, from release 1.1, for the import you start, and you can withdraw them in Health Connect's settings at any time. The app does not declare background access to Health Connect. It declares history access from release 1.1, and only the import from Health Connect asks for it.
The build declares no location, microphone, contacts, photo library or physical activity permission: steps come from Health Connect, not from the phone's sensors. The country of the food database comes from the settings, not from your location.
Barcode scanner and label text recognition (Google ML Kit)
Barcode recognition and the reading of nutrition tables from label photos run on your device with models bundled in the app. From release 1.1, FoodBalance Pro can also have a nutrition table read in the cloud when the phone reads it poorly; that reading goes to our server and is described in Meal photo and label reading.
Per Google's disclosure, ML Kit reports to Google information about the device (manufacturer, model, Android version and build, and the available machine-learning hardware), the app's package name and version, the API configuration (such as image format and resolution), the size of the input and output, the feature version, the type of event (such as an initialization or a detection), performance metrics such as latency, error codes, and per-installation identifiers that, per Google, are not intended to uniquely identify a user or a physical device. The barcode scanner runs with automatic zoom, so ML Kit also reports an identifier of each scanning session (per Google, likewise not intended to uniquely identify a user or a physical device), the zoom changes and the predicted position of a barcode in the frame. Images are not among the data listed in that disclosure, and the app has no setting that turns this reporting off. Per the same disclosure, Google uses this information for diagnostics and usage analytics of ML Kit, ML Kit sends it over HTTPS, and ML Kit does not pass it to third parties.
This reporting goes to Google, not to us, and is governed by Google's ML Kit data disclosure and Google's Privacy Policy.
Open Food Facts: product lookup and contributions
Open Food Facts is an open database of food products run by a non-profit association in France. FoodBalance reads products from it and, when you choose to, adds products to it, reports errors in its data and, from release 1.1, adds photos of nutrition tables.
Product lookup. When you scan a barcode that is not among
your own foods, the cache or the country pack, or search for a food by name
while the phone is online, the app asks Open Food Facts
(world.openfoodfacts.org and
search.openfoodfacts.org).
- The request carries the barcode or the search text, the country chosen in the settings and the app language, and a User-Agent header with the app version and the address foodbalance@gi-gante.com, so that Open Food Facts can reach the developer. Like any internet request, it also carries your IP address. It carries no identifier of you or of your installation.
- Answers are cached on the device. A cached product older than 30 days is requested again in the background when you open it while online. Once a week, the app also refreshes such products if they appear in your diary over the last 60 days, sending their barcodes to Open Food Facts in batches of up to 20 per request. These requests carry barcodes only, without dates, amounts or anything else from the diary.
- A barcode scanned while the phone was offline waits on the device and is looked up in the same way once the phone is online again: while the app is open, during the weekly refresh, or when you start a check on the Data and database screen.
-
Product images are downloaded from
images.openfoodfacts.orgwhen a food card shows one, and kept in a size-limited cache on the device. - Open Food Facts keeps server logs, including IP addresses, under its privacy policy.
- "Report a problem", in the menu of a food card whose data comes from Open Food Facts, opens that product's page on the Open Food Facts website in your browser. The app itself sends nothing for it.
Contributions. When you save a new product with a barcode, you can tick "Send to Open Food Facts". It is off until you turn it on; the first time you do, the app explains what is published and asks for your consent.
- What is sent: the barcode, product name, brand, quantity, serving size, the nutrition table and the country; the app name and version; and the random identifier that the app creates at your first contribution. The product is sent under the app's own Open Food Facts account, not under your name. Open Food Facts asks apps that contribute through one shared account to send such an identifier: it lets its moderators stop the contributions of a single installation without blocking the app's whole account.
- The same box appears under "Edit details" of a product that comes from Open Food Facts or a country pack. A correction sends only what you corrected: the name or the brand, and the whole nutrition table per 100 g if you corrected any nutrient; with it go the barcode, the app name and version and the random identifier, but not the country.
-
Through our server, from release 1.1. The app no longer
holds the password of its Open Food Facts account. It sends each
contribution to our server
foodbalance-api.gi-gante.com(see Recipe from photo), which writes it to Open Food Facts under the app's account. With it the app sends the random installation identifier of our server and a Play Integrity token, as Recipe from photo does, and, like any internet request, your IP address. Our server passes on to Open Food Facts the fields above, the app name and version and the random identifier of your contributions, adds a fixed English comment, and passes on none of the headers of your phone's request, so neither the installation identifier nor the token. On a device whose Play Integrity check our server refuses, the app clears the queue, hides "Send to Open Food Facts" for 30 days and says so on the screen of a new food; the products stay saved in the app. - What our server keeps about contributions, from release 1.1: for each installation and day (UTC), the number of contributions Open Food Facts accepted, at most 20 a day, and a keyed hash of each barcode contributed that day, so that a label photo is accepted only for a product whose numbers went first. Both are kept under a keyed hash of the installation identifier and deleted after that day and the two days after it. Our server does not keep the product data, and its log line of a contribution holds no barcode.
- In release 1.0 no photos are sent: a label photo is read on your device and deleted once the reading is done. From release 1.1 a photo of the nutrition table can go with a new product or a report, as described under Label photos below.
- Products wait in a queue on the device and are sent in the background, by default over Wi-Fi. The app sends at most 20 contributions a day.
- We can switch contributions off for every installation at once through the signed index file that the app reads from the pack hosting (see Country food packs). The app then hides "Send to Open Food Facts" and clears the queue of unsent products; the products themselves stay saved in the app. From release 1.1 our server can also pause contributions; products then wait in the queue.
- What is published: Open Food Facts publishes product data openly and without a time limit, the database under the Open Database License and its contents under the Database Contents License. The product's edit history shows the app's account and the random identifier; it does not show your name or any account of yours.
- You can withdraw consent on the Data and database screen; the queue of unsent products and reports is then cleared. Products already published stay in Open Food Facts under its terms of use.
Label photos. From release 1.1, when you add a new product from a photo of its label and tick "Send to Open Food Facts", or add a photo of the label to a report of a data error, the app can also send that photo, so that Open Food Facts shows the product's nutrition table. It asks for this consent separately, in a line of its own under the consent to send the numbers.
- Which photo. Only a photo in which the phone found a nutrition table, with at least three of energy, protein, fat, carbohydrates and salt. Before it is sent, the app reduces it to between 640 and 1,024 pixels on its long side and strips its metadata (EXIF), including any location. A smaller photo is not sent; the numbers go alone.
- When and with what. The photo goes to our server only after Open Food Facts accepted the numbers or the report of the same product from this installation the same day (UTC). With it go the barcode, the language of the label, the photo's width, height and SHA-256 fingerprint, the installation identifier and a Play Integrity token; not the random identifier of your contributions and nothing from your diary.
- The check. Our server sends the photo to Google Cloud Vision, which returns what it sees in the photo, such as "nutrition facts label" or "packaging", and whether it looks like adult, violent, racy or medical content. Our server refuses a photo that does not look like a label or looks unsafe, and the app then deletes it. Our server does not ask Cloud Vision to look for faces or documents, so photograph only the table on the package, without people or other things. Per Google's Cloud Vision data usage page, Cloud Vision processes such a photo in memory and does not write it to disk, temporarily logs some metadata of the request, such as its time and size, and does not use the photo to train its models; Google processes it under the Cloud Data Processing Addendum. Our server keeps no copy of the photo, and its log line says only whether the photo passed the check.
- Publication. A photo that passes is uploaded by our server to Open Food Facts under the app's account, as the nutrition table picture of that product in the label's language. Open Food Facts publishes it openly and without a time limit under the Creative Commons Attribution-ShareAlike 3.0 license; under its terms of use the publication cannot be withdrawn.
- On the phone the photo waits with the queued product and is deleted after any answer of our server. Withdrawing the consent to contributions on the Data and database screen also withdraws this one and deletes the photos waiting to be sent; it does not remove photos already published.
- Label photos are not offered when the region of the active profile is Russia, and our server refuses them from IP addresses in Russia; the numbers of a product are sent there as before.
Reports of a data error. From release 1.1, "Report an error", in the menu of a food card whose data comes from Open Food Facts and on the scan result, asks what is wrong from a fixed list: calories and nutrients, wrong product, name, serving size, missing data or other. For some of these you can also type a corrected value. A report adds nothing to your diary.
- A report goes the way of a contribution: with the same consent, through the same queue, under the app's Open Food Facts account, within the same 20 a day, and the same switch on the signed index file stops it. Without your consent the app sends nothing, and a value you typed only corrects the product for you, on the phone.
- What is sent: the barcode, the language, the reason as a fixed English comment such as "FoodBalance user report: name", the app name and version and the random identifier. Only if you typed a corrected value, your corrections of that product go with it, as described under Contributions: the name or the brand, or the whole nutrition table per 100 g with your numbers in it. A report sends nothing from your diary and not the country. In release 1.0 it sends no photo; from release 1.1 a photo of the label you add to it goes as described under Label photos, and a refused photo leaves the report to go without it.
- After you send a report, the product shows "You reported an error on" with the date until a newer record of it arrives from Open Food Facts. This mark stays on the device: it is not in the backup file, and Erase everything deletes it.
Country food packs
Packs are files downloaded from our static hosting; the request carries no data about you beyond the ordinary HTTP request. The packs of countries are derived from Open Food Facts and published under the ODbL.
From release 1.1 there are two more kinds of pack:
- The full database of a country, with FoodBalance Pro. Where the pack of a country holds only its popular products, Pro can download instead a pack with every product of that country that has a nutrition table.
- US branded foods, built from USDA FoodData Central Branded Foods, which is in the public domain (CC0). The app offers it when the region in the settings is the United States or New Zealand. The app does not contact USDA: we build the pack, and it comes from the same hosting as the others.
The app downloads both only over Wi-Fi or another unmetered connection and, when the file is over 20 MB, only while the phone is charging.
The hosting is packs.gi-gante.com, served by Cloudflare. The
app checks for pack updates in the background about once a day, by default
only on Wi-Fi or another unmetered connection, and when you start a check on
the Data and database screen. A request shows which pack is fetched and,
like any request, your IP address; the hosting keeps ordinary access logs,
and the app writes nothing there.
Health Connect
Each data type has its own switch on the app's Health Connect screen: Profile → Settings → Integrations → Health Connect. All switches are off until you turn them on, and turning one on asks Health Connect for that data type only:
-
Weight, read and write
(
android.permission.health.READ_WEIGHT,android.permission.health.WRITE_WEIGHT): weigh-ins from scales and other apps are read into the weight chart and the calorie target, and weigh-ins you enter in FoodBalance are written to Health Connect. -
Nutrition, write only
(
android.permission.health.WRITE_NUTRITION): each meal you log goes to Health Connect with its energy, protein, fat, saturated fat, carbohydrates, fiber, sugar, sodium and meal type, under the name of the meal rather than the list of foods. -
Hydration, write only
(
android.permission.health.WRITE_HYDRATION): each glass of water you log. -
Steps, read only
(
android.permission.health.READ_STEPS), from release 1.1: the Steps today switch. The app reads the number of steps of the day and shows it as a line on the Today screen. -
Active calories burned, read only
(
android.permission.health.READ_ACTIVE_CALORIES_BURNED), from release 1.1, with FoodBalance Pro: the Adjust target by activity switch. The app reads the active calories of the day, adds part of them to that day's calorie target and shows the calculation where it explains the target. It keeps the last value it read with that day, and the day's target is calculated from it. While your target follows your weight trend, nothing is added, because the trend already includes your usual activity.
While a switch is on, the app keeps Health Connect in step with the last 30 days of the app: entries from those days are written when you turn the switch on, an entry you edit is replaced there, and an entry, glass or weigh-in you delete in FoodBalance is removed there as well. Weigh-ins are read from the last 30 days; one within an hour of a weigh-in you entered yourself is not added a second time. Steps and active calories are read as the day's total that Health Connect reports, for the food day that starts at the day boundary set in the app.
From release 1.1, the import screen (Profile → Data and database → Import
from another app) also offers "From Health Connect". Only this button asks
for nutrition reading
(android.permission.health.READ_NUTRITION) and for access to
records older than 30 days
(android.permission.health.READ_HEALTH_DATA_HISTORY); weigh-ins
are read with the weight permission described above. When you start it, the
app reads the nutrition records and weigh-ins that other apps wrote to
Health Connect for the period you choose, leaves out the records FoodBalance
wrote itself, and adds the rest to your diary and weight history. Imported
entries and weigh-ins are not written back to Health Connect (see Importing
a diary from another app).
With several profiles (see Several profiles on one phone), Health Connect is linked to the first profile on the phone: only that profile's meals, water and weigh-ins are written there, and weigh-ins, steps and active calories are read for that profile only. While another profile is active, the Health Connect screen says which profile it is linked to.
The exchange happens on the device, between FoodBalance and Health Connect. FoodBalance reads Health Connect only while the app is open. Weigh-ins it reads become part of the weight history in the app, like weigh-ins you enter yourself; the app uses them only to show them to you and to calculate your target, and does not pass them on to anyone else. In the same way, steps are only shown to you, active calories are used only for the day's target, and imported records become part of your diary. Like the rest of the diary, what the app keeps from Health Connect can leave the device only inside a backup or CSV file that you export or that automatic backup writes to the folder you chose. Turning a switch off stops new reads and writes; records already written stay in Health Connect, where you can delete them. You can withdraw access at any time in Health Connect's own settings, and the app's Health Connect screen shows the current state each time it opens.
Camera and photos
The camera is used to scan barcodes, to photograph the nutrition table on a label, to photograph a recipe and, from release 1.1, to photograph a meal. Barcode and label frames are processed on the device. A label photo is kept in the app's storage only until the reading is finished, and is then deleted; from release 1.1, a label photo you chose to send to Open Food Facts is kept until our server answers, and is then deleted (see Open Food Facts).
A recipe photo and, from release 1.1, a meal photo and a label photo you have read in the cloud are the exception: they are read by Google's recognition service, not on the device, and are sent only after your consent. The app deletes a recipe or label photo once the recognition is finished or cancelled, and keeps a meal photo only while it waits to be sent (see Recipe from photo and Meal photo and label reading).
Choosing a picture from the gallery, for example a screenshot with a barcode or a recipe, goes through the Android photo picker: the app receives only the picture you pick and has no access to the rest of the gallery. The picture is read on the device, except a recipe or, from release 1.1, a meal photo, which is sent for recognition as described in Recipe from photo and Meal photo and label reading.
Recipe from photo
Recipe from photo fills in the recipe builder from a photo of a recipe: a handwritten note, a cookbook page or a screenshot. Unlike the barcode scanner and the label reader, it does not run on your device. The photo goes to our server, and the server passes it to Google's Gemini API, which reads it. This happens only when you choose to fill in a recipe from a photo in the recipe builder.
- Consent first. The first time you use it, the app explains what happens to the photo and asks for your consent; this processing is based on that consent. Until you agree, the app sends no photo and no identifier to our server. The feature needs a profile of age 18 or older. You can withdraw your consent on the Data and database screen, and the app then asks again before the next photo. Building a recipe by hand works without it. From release 1.1 the same consent covers Meal photo and cloud label reading, and the app asks again even if you agreed in release 1.0 (see Meal photo and label reading); from release 1.1 the feature is not offered in Russia either.
- What the app sends with a photo: the photo you took or picked in the Android photo picker, reduced to at most 1,600 pixels on its long side and stripped of its metadata (EXIF), including any location; its width, height and SHA-256 fingerprint; the app language and version; a random installation identifier that the app creates for this server and that a backup does not carry over; a Play Integrity token; and, if you have FoodBalance Pro, the purchase token that Google Play issued and the name of the product. Nothing from your diary, weight, targets or profile is sent. Like any internet request, it carries your IP address.
- Play Integrity. The token lets the server check with Google Play that the request comes from FoodBalance installed from Google Play on a device that passes Google's integrity checks. To create it, Google Play services on the phone report information about the app and the device to Google, as described in Google's Play Integrity data disclosure. The server sends the token to Google to read the verdict and keeps only the yes-or-no result, under a one-way hash of the token, for up to 24 hours. On a device that does not pass the check, Recipe from photo is not available and, from release 1.1, neither are Meal photo, cloud label reading and contributions to Open Food Facts.
-
Our server is
foodbalance-api.gi-gante.com, a Cloudflare Worker that Cloudflare runs for us; from release 1.1 it also serves Meal photo, cloud label reading and contributions to Open Food Facts. It does not save the photo: it streams it to Google and keeps no copy. Your IP address is used only to limit requests to 20 a minute and, from release 1.1, to tell the country a photo is sent from (see Meal photo and label reading), and the server does not store it. Each request leaves one log line with the time, the endpoint, the plan (free or Pro), the model, the duration, the number of model tokens, the result code, whether the answer came from the cache, for a label photo whether it passed its check, and the first eight characters of the hashed installation identifier; the line holds no photo, note, recipe text, food or ingredient name, barcode or IP address. Cloudflare keeps these log lines for seven days. - Google's Gemini API receives the photo, the app language and our instructions from our server, with no identifier of you or your installation. It returns the title, the number of servings, the weight of the finished dish when the recipe states one, and the ingredient lines. Cooking steps are not asked for, and an answer that contains them is rejected. We use Google's paid service: under its terms, Google processes the photo and the answer as our data processor, does not use them to improve its products, and keeps them for 55 days only to detect and prevent abuse of the service (Gemini API terms, abuse monitoring, Google's Privacy Policy).
- What comes back opens in the recipe builder as a draft. Lines the service was unsure of are marked for you to check, and lines without an amount, such as "salt to taste", are listed separately with their original text. Nothing is saved until you tap Save in the recipe builder. The saved recipe stays on your device like any other, without the photo and without the original lines of text. The app deletes the photo once the recognition is finished or cancelled.
For Recipe from photo, our server keeps the following. None of it is the photo, and none of it holds the installation identifier or the purchase token in readable form:
- for each installation, the number of recognitions in the current calendar month, under a keyed hash of the installation identifier. This is how the free limit of two recognitions a month works; a photo that is not a recipe and a failed request are not counted;
- for Pro, the result of the purchase check under a one-way hash of the purchase token, used for up to 24 hours before Google Play is asked again, and the hashed installations that used the purchase, because one purchase works on up to five installations within 30 days;
- the answer read from a photo (the title, servings, weight and ingredient lines), for up to seven days, in Cloudflare's cache under the photo's fingerprint and the hashed installation, so that the same photo sent again is answered at once and is not counted again;
- the day's total spending on recognition, without any identifier.
Monthly counters are deleted after the end of the following month, and purchase check results and the installations of a purchase 30 days after they were last used.
Cloudflare and Google may process this data outside your country, including in the United States, under their data processing terms with us, which include the EU standard contractual clauses.
Meal photo and label reading
From release 1.1, Meal photo estimates a meal from a photo of it: when you add food, you tap Photo next to the search field and take a photo or pick one in the Android photo picker, and the app shows the foods it found, each with a portion to check and a range of calories. With FoodBalance Pro, cloud label reading reads the nutrition table of a label photo for a new food when the phone reads it poorly. Like Recipe from photo, neither runs on your device: the photo goes to our server, and the server passes it to Google's Gemini API. This happens only when you start it.
- One consent for three features. Before the first photo of Recipe from photo, Meal photo or cloud label reading, the app shows one sheet that names the three, says where the photo goes and what is kept, and asks for your consent. This processing is based on that consent; for Meal photo it is your explicit consent, because what you eat can say something about your health. Until you agree, the app sends no photo and no identifier to our server. If you agreed to Recipe from photo in release 1.0, the sheet comes again before the first photo, because the consent now covers more. The features need a profile of age 18 or older. You can withdraw the consent with the switch "Send photos for recognition" on the Data and database screen; the app then deletes the meal photos waiting to be sent and asks again before the next photo. Adding food by search, barcode or a label read on the phone works without it.
- Not in every country. The app does not offer these features when the region of the active profile is Russia, and our server refuses photos from IP addresses in Russia. Our server compares the country of a request with that list and does not store it.
- Which features are on. After you agree to any feature that uses our server, the app asks our server, without any identifier, which of them are switched on. Our server can switch each of them off without an app update.
- What the app sends with a photo: the photo, reduced to at most 1,024 pixels on its long side and stripped of its metadata (EXIF), including any location; its width, height and SHA-256 fingerprint; the app language and version; a short note you may type to clarify the photo; the installation identifier and the Play Integrity token described in Recipe from photo; and, if you have FoodBalance Pro, the purchase token that Google Play issued and the name of the product. Nothing from your diary, weight, targets or profile is sent. Like any internet request, it carries your IP address.
- Our server works as described in Recipe from photo: it checks the Play Integrity token, does not save the photo but streams it to Google, uses your IP address only to limit requests and to tell the country of the request, and writes one log line per request without the photo, the note or any food name. On a device that does not pass the integrity check, these features are not available. Cloud label reading needs FoodBalance Pro: on the free version our server refuses it before it reads the photo.
- Google's Gemini API receives the photo, the note, the app language and our instructions from our server, with no identifier of you or your installation. For a meal it returns the foods it sees, with their estimated grams and range, calories, protein, fat and carbohydrates per 100 g, how sure it is of each, and how each looks cooked; for a label, the values of its nutrition table. Google's terms are those described in Recipe from photo: Google processes the photo, the note and the answer as our data processor, does not use them to improve its products, and keeps them for 55 days only to detect and prevent abuse of the service.
- What comes back is an estimate, not an entry. Where a food matches one in the app's food database, the app takes that food's values and only the grams from the answer. You check the portion of each food, and nothing is written to the diary until you save it; the saved entries are marked as estimated from a photo. A photo without food is answered as such, and nothing is estimated or counted. A label reading opens in the new food form, where you check it as after a reading on the phone.
- Saved for later. Without a connection, you can save a meal photo to be recognized later. The app keeps the reduced photo and your note in its storage, sends them in the background once the phone is online, and deletes the photo after the answer. A card on the Today screen and a quiet notification tell you that the photo was recognized; entries are made only after you check the portions. A photo that waits counts toward the daily limit of the free version.
- On the phone the app keeps, for each meal photo you saved, the answer and the portions you chose, together with the entries made from it, and deletes them once no entry made from that photo is left, in the trash included. A recognized photo waiting for your check keeps its answer until you check or remove it. The app keeps no photo after the answer unless you turn on keeping thumbnails in the settings; then it keeps a 256-pixel thumbnail of each saved meal photo on the device. The backup file does not contain the answers or the thumbnails, and Erase everything deletes them.
For Meal photo and cloud label reading, our server keeps the following. None of it is the photo, and none of it holds the installation identifier or the purchase token in readable form:
- for each installation, the number of meal photos recognized that day and that month, under a keyed hash of the installation identifier. This is how the daily and monthly limits of the free version and the limits of Pro work; a photo without food and a failed request are not counted, and label readings with Pro are not counted either;
- for Pro, the result of the purchase check and the hashed installations that used the purchase, as described in Recipe from photo;
- the answer, for up to seven days, in Cloudflare's cache under the photo's fingerprint, the hashed installation, the language and a hash of the note, so that the same photo sent again is answered at once and is not counted again;
- the day's total spending on recognition, without any identifier.
Daily counters are deleted after their day and the two days after it, and monthly counters after the end of the following month.
Cloudflare and Google, including Google Cloud Vision for label photos sent to Open Food Facts, may process this data outside your country, including in the United States, under their data processing terms with us, which include the EU standard contractual clauses.
Reminders and notifications
Reminders are local notifications. Their schedule is kept and run on the device, and the app restores it after the phone restarts. Setting up, changing or receiving a reminder sends nothing off the device.
From release 1.1, Exact timing in the reminder settings asks Android for exact alarms, so that reminders come at the minute you chose (see the exact alarm permission above). It is off until you turn it on, and the schedule stays on the device either way.
The daily summary shows the day's calories on the lock screen only if you turn that on in the reminder settings. With numbers turned off in the settings, notifications and the home-screen widget show no calorie figures.
Purchases (FoodBalance Pro)
FoodBalance is free to use. Some features and higher daily limits are part of FoodBalance Pro, sold as a subscription with a monthly or a yearly plan, or as a one-time lifetime purchase. The "What's free" screen in the app lists what stays free and the current limits.
- Google Play takes the payment, not us. Buying opens Google Play's own purchase sheet. The app does not ask for and does not see your card number, bank details or billing address, and none of it reaches us.
- What Google gets is what Google gets for any Play purchase: the Google account signed in to the Play Store, the product, the price and country, and the payment method you picked there, under Google's Privacy Policy and the Google Play Terms of Service. The app asks Google Play only about its own products.
- What the app keeps on the device is the state of your Pro access: its status (for example trial, yearly or lifetime), the product, plan and offer, when it was granted and when Google Play last confirmed it, and a one-way hash of the purchase token that lets the app recognize the same purchase again. The order number, the name on the Google account and the payment details are not stored.
- The purchase is checked on your device. Google signs every purchase, and the app verifies that signature with the public licensing key that ships inside the app.
- Recipe from photo checks it on our server as well, and from release 1.1 so do Meal photo and cloud label reading. When you send such a photo with Pro, the app sends the purchase token and the product to our server, which asks Google Play whether the purchase is active (see Recipe from photo). Contributions to Open Food Facts do not carry the purchase.
- Restoring asks Google Play what this Google account already owns for this app. The app does it when it starts, when you come back to it, and when you tap "Restore purchases".
- Pro follows the Google account that bought it. Cancelling a subscription, refunds and payment history are in your Google Play account, where we have no access. Losing Pro does not delete any of your data.
Support letters
The Support screen in the app is for writing to us. A support letter moves only when you send it.
-
The app sends nothing itself. It prepares a
mailto:draft to foodbalance@gi-gante.com and hands it to your mail app; you read it there and send it from your own account. Closing the draft sends nothing. - The whole report is printed on the screen before anything is handed over, so you see every line of it.
- What the report contains: the app version and build and where it was installed from; the app language, system locale, region and units; the database, calculation and country pack versions; the Android version, manufacturer, model and security patch; screen size, density, text size and display settings; free and total storage; counts of diary entries, days with entries, custom foods, recipes, weigh-ins and reminders and, from release 1.1, the number of profiles; the size of the product cache and the length of the lookup and contribution queues; which permissions are granted; whether Health Connect is installed and its version; notification channel versions, the number of scheduled reminders and the battery restriction state; whether Pro is active and whether it comes from the subscription or the lifetime purchase; the date of the last successful Open Food Facts request and the last error code; and the last lines of the local error log.
-
What the report does not contain: food names, barcodes,
weight, targets, year of birth, the allergens of your profile, the names
of profiles, recipe names, notes, the places of meals eaten out, photos,
the contents or names of imported files or the names of other apps on the
phone. In the error log lines, texts, long numbers, barcodes, paths, file
names and email addresses are replaced with placeholders such as
<text>,<barcode>and<path>. - Reminder diagnostics offers "Copy report", which copies a shorter report of the same kind to the clipboard. It goes wherever you paste it.
- Because it is mail, we see the address you send from. We use a letter only to answer it and to fix the problem, and delete it on request to the address below.
Analytics and advertising
This build contains no advertising SDK, does not request the advertising identifier, and contains no analytics SDK. The ML Kit diagnostics described in the section on Google ML Kit are the only usage analytics in the build. The log lines of our server, described in Recipe from photo, serve to run the server and control its costs.
Google Play gives the developer aggregated statistics of crashes and "app not responding" events (Android vitals), which Android collects from devices whose owners allow usage and diagnostics sharing with Google. FoodBalance's own code sends nothing for them.
Data retention and deletion
Your data stays on your device for as long as you keep it. You can delete entries, foods and recipes in the app, and from release 1.1 a profile with its diary. Profile → Data and database → Erase everything first offers to save a backup, then deletes the diary, weight, profile, targets, custom foods, recipes, settings, the product cache, the marks of errors you reported, downloaded country packs, daily copies, photos and scheduled reminders on this device; from release 1.1 it deletes every profile, the records of imports, the settings of automatic backup, the meal photos and label photos waiting to be sent, and the answers and thumbnails of meal photos as well. Uninstalling the app removes all of its data from the device. Backup, CSV and PDF files you exported or shared, and the files automatic backup wrote to the folder you chose, stay wherever they are.
Some data is outside the app's reach, and Erase everything says so on the screen: records written to Health Connect stay there until you delete them in Health Connect; what was already sent to Open Food Facts stays there under its open licenses; the Pro purchase belongs to your Google Play account and comes back with "Restore purchases".
Support letters stay in our mailbox until you ask us to delete them. Open Food Facts and the pack hosting keep their server logs under their own policies, and Google keeps purchase records, ML Kit diagnostics and, from release 1.1, the metadata of Cloud Vision requests under Google's.
For Recipe from photo and, from release 1.1, Meal photo and cloud label reading, our server keeps no photo. Google keeps the photo, the note and the answer for 55 days to detect abuse of its service; the answer stays in Cloudflare's cache for up to seven days, daily counters for their day and the two days after it, monthly counters until the end of the following month, purchase check results for 30 days after their last use, and log lines for seven days (see Recipe from photo and Meal photo and label reading). For contributions to Open Food Facts, from release 1.1, our server keeps the day's count and the hashed barcodes for their day and the two days after it, and neither it nor Google Cloud Vision keeps a label photo; what Open Food Facts published stays there. Erase everything also deletes the installation identifier on the device; the records on the server stay under its hash until they expire.
Security
This is how the app protects your data:
- On the device. The diary, weight (including weigh-ins read from Health Connect), profile, targets and the rest of the data listed under "Data stored on your device" are kept in the app's private storage, which Android does not let other apps read. On a phone that uses Android's storage encryption, this storage is encrypted together with the rest of the phone's data. The database file itself is not additionally encrypted by the app.
- No system backup. Android backup to Google Drive and device-to-device transfer are switched off for the app, so the system does not copy the diary anywhere. You make copies yourself by exporting a backup or CSV file and, from release 1.1 with FoodBalance Pro, by turning on automatic backup to a folder you choose (see Android backup and phone-to-phone transfer). The app does not encrypt these files, so their protection depends on where you keep them.
-
In transit. The app's own requests to Open Food Facts, to
the pack hosting
packs.gi-gante.comand to our serverfoodbalance-api.gi-gante.comuse HTTPS, and our server talks to Google and, from release 1.1, to Open Food Facts over HTTPS. The app accepts product image and pack addresses only over HTTPS, and the build does not enable unencrypted (cleartext) traffic in its Android network settings. Per Google's disclosure, ML Kit sends its diagnostics over HTTPS; purchases go through Google Play's own components. - Signed country packs. The app checks the signature of the pack index with a key that ships inside the app, and uses a downloaded pack only when its checksum matches the one in the signed index. A file that fails either check is discarded, and the pack already installed stays in use.
- Purchases are checked on the device: the app verifies Google's signature of each purchase (see Purchases).
- Logs and reports. Food names, numbers, barcodes and paths are removed from an error before it is written to the local error log, and the support report leaves out food names, barcodes, weight and targets (see Support letters).
- Our servers. No server of ours receives your diary, weight, profile or Health Connect data from the app. Our server receives only what Recipe from photo and, from release 1.1, Meal photo, cloud label reading and contributions to Open Food Facts send, keeps no photo, and stores installation identifiers, purchase tokens and barcodes only as keyed or one-way hashes. The keys to Google's services and, from release 1.1, the password of the app's Open Food Facts account are kept on that server, not in the app. The data that does leave the device is described in this policy, section by section.
To report a security problem in the app, write to the address under Contact.
Children
FoodBalance is designed for adults (18+). The app creates no profile when the entered birth year shows an age under 18; from release 1.1 this applies to every profile added on the phone. Recipe from photo and, from release 1.1, Meal photo and cloud label reading need such a profile as well.
Your rights
Data protection laws such as the EU and UK GDPR, Brazil's LGPD, the California Consumer Privacy Act and Washington's My Health My Data Act give you rights over your personal data, including access, correction, deletion and portability. Because the diary, weight and profile stay on your device and do not reach us, you exercise these rights in the app itself: you see and correct everything on its screens, export it on the Data and database screen and delete it with Erase everything.
Recipe from photo and, from release 1.1, Meal photo and cloud label reading are based on your consent, and so are contributions to Open Food Facts with their label photos. You can withdraw these consents at any time on the Data and database screen. Withdrawing stops what would come next and deletes the photos waiting to be sent; it does not undo what was sent before: Google keeps requests for 55 days as described in Recipe from photo, and what Open Food Facts published stays there under its licenses. Our server holds only the hashed records described in those sections, which we cannot link to a person by themselves, and deletes them on the schedule given there.
For support letters you have sent us, write to the address below and we will answer, send you a copy or delete them. We do not sell personal information and do not share it for advertising. You can also lodge a complaint with the data protection authority where you live.
Changes to this policy
When the app starts handling data in a new way, this policy is updated at the same address with a new effective date before the release that brings the change. A feature that would send your data to a server of ours, such as cloud sync, asks for your separate consent in the app before it sends anything.
Contact
FoodBalance is published by Gi-Gante s. r. o., a company established in the European Union.
Questions about this policy or your data: foodbalance@gi-gante.com