RiceCal
← Back to RiceCal

Privacy Policy

Last updated 14 August 2026

A food diary is a record of your body and your day. This page says exactly what RiceCal collects, why, who else touches it, and how to get rid of it.

Who we are

RiceCal is a calorie and nutrition diary for iPhone and Android, operated by Nelson Gan (“RiceCal”, “we”, “us”, “our”). We are the data controller for the personal data described in this policy.

This policy covers the RiceCal mobile app, this website, and the servers behind them. It does not cover the App Store, Google Play, Apple Health, Health Connect, or anything else you use alongside RiceCal, each of which has its own privacy policy.

Questions about anything here go to support@ricecal.app and reach a person, not a queue.

The short version

  • We collect what the app needs to count your calories: your account, the body figures your daily budget is worked out from, and what you log.
  • Plate photos are stored privately and are only readable through short-lived links issued to your own account.
  • A photo or a written description of a meal is sent to an AI provider so it can be identified. Your name, email and account identifier are not sent with it.
  • Health and activity readings are only read if you connect Apple Health or Health Connect, and only to show your activity and extend your daily calorie budget.
  • We never use your diary, your photos or your health data for advertising. We do not sell your personal data, and we do not share it with data brokers.
  • You can ask us to delete your account and everything in it at any time. See the Data Deletion page.

What we collect

Account and identity

  • Your email address, and the name your provider gives us when you sign in with Apple or Google. If you use Apple’s “Hide My Email”, we only ever see the relay address Apple gives us.
  • An account identifier we generate, which is what everything else in your diary is keyed on.
  • The dates your account was created, onboarded and last used.

Your profile and your goal

  • Height, weight, target weight, sex and age. These are the inputs to your daily calorie budget and are used for nothing else.
  • How active your day is, and the food style tags you pick during setup (for example halal, mamak, kopitiam, vegetarian), which are used to rank search results.
  • Your daily calorie and macro goals, kept as a dated history so that changing your target tomorrow does not rewrite yesterday.
  • Your display, unit, reminder and privacy settings, and the times you eat your meals.

Your diary

  • Every meal you log: what it was, how much of it, when, and the calories and macros attached to it.
  • Photographs of meals you choose to scan, and the ingredient breakdown produced from them.
  • Recipes you create, including their ingredients, steps and serving counts. A recipe stays private unless you choose to publish it.
  • Water, day notes, weigh-ins and the streak worked out from your logging.

Health and activity, only if you connect it

  • From Apple Health (iOS) or Health Connect (Android): steps, distance, workouts and sessions, active and total calories burned, heart rate where a workout carries it, weight and body fat readings.
  • Nothing is read until you grant permission on the device, and reading stops the moment you revoke it or disconnect in Settings.
  • Readings are stored on our servers so that your budget, your charts and your weekly reviews can be worked out in one place rather than only on the handset that read them.

Purchases

  • Whether you have an active trial, subscription or lifetime purchase, which store it came from, and when it renews or expires. This mirror is written by RevenueCat from the store’s own reports.
  • We never see or store your card, bank details or billing address. Payment is taken by Apple or Google, not by us.

Diagnostics and product analytics

  • Crash and error reports, including the device model, operating system version, app version and the technical trace of what failed.
  • Product analytics events, such as which screens are opened and which features are used, with a device identifier, app version, and coarse locale and timezone.
  • Counts of how many AI requests your account has made in the current month, which is how the fair-use ceiling is enforced.
  • The app blocks the advertising identifier on Android and carries no advertising SDK on either platform.

What we do not collect

  • Your precise location. RiceCal does not ask for location permission.
  • Your contacts, your calendar, your microphone recordings or your camera roll at large. The camera is used only for the plate you point it at and the barcode you scan.
  • Payment card details.
  • Special category data beyond the health and body figures listed above, which you provide or connect yourself.

How we use it

What we doWhat it uses
Create and run your accountEmail, account identifier, sign-in provider
Work out your daily calorie and macro budgetHeight, weight, age, sex, target weight, activity level
Identify a meal from a photo, a sentence or a barcodeThe photo or description, and the barcode you scanned
Keep and show your diary, charts, streaks and reviewsYour logged entries, weigh-ins, water and recipes
Extend your budget with movementSteps, workouts and calories burned from Apple Health or Health Connect
Remind you at the times you eatYour meal times and reminder settings, scheduled on the device itself
Unlock the features you paid forYour subscription status from RevenueCat
Keep the app working and fix what breaksCrash reports, error traces and product analytics
Widen the food catalogueDishes and barcodes we could not match, recorded without your account identifier
Answer your support messageThe email you send us and what you put in it

We do not use your diary, your photos, your body figures or your health readings to target advertising, and we do not build advertising profiles.

How photos and descriptions are processed

Photo and text meal logging works by sending what you gave us to an AI model, through our own servers. Your phone never talks to the model directly.

  • What is sent: the plate photo or the sentence you wrote, plus the prompt that tells the model what to look for. For a recipe read, the recipe text or photo you supplied.
  • What is not sent: your name, your email, your account identifier, your body figures or the rest of your diary.
  • Requests are routed through OpenRouter to the model provider that serves them. We select providers on API terms that do not permit your content to be used to train their models.
  • The result comes back as a list of items, portions and nutrition figures, which is written into your diary and which you can correct line by line before or after saving.
  • We keep the model’s working notes for a scan, so that a wrong result can be investigated and the catalogue improved. These are held against your entry, are never published, and go when your account goes.
  • Where a dish or a barcode could not be matched, the search term or the code is recorded on a backlog so that we can add it. That backlog does not carry your account identifier.

Calorie and macro figures produced this way are estimates. RiceCal is a wellness tool, not a medical device, and nothing it shows you is medical advice.

Health and fitness data

Health and fitness data gets stricter treatment than anything else in the app, both because it deserves it and because Apple and Google require it.

  • Data read from Apple HealthKit or Android Health Connect is used only to show your activity inside RiceCal and to extend your daily calorie budget.
  • It is never used for advertising, marketing, or any similar purpose.
  • It is never sold, rented, or disclosed to data brokers or information resellers.
  • It is not shared with any third party except the infrastructure providers listed below that store it on our behalf, and only ever to deliver the app to you.
  • Disconnecting the health store in RiceCal’s settings stops all further reading and deletes the activity we synced from it.
  • Weight readings you type yourself and weight readings synced from a health store are kept apart, so disconnecting a store never removes something you entered by hand.

Who else touches it

We do not sell your personal data. We share it only with the providers that make the app run, each under a contract that limits them to processing it on our instructions.

ProviderWhat it handles
SupabaseAccounts, authentication and your diary database
CloudflareMeal photos in private object storage, the food catalogue, and the network in front of both
OpenRouter and its model providersIdentifying a meal from a photo or a description
RevenueCatSubscription state, reported from the App Store and Google Play
Apple and GoogleSign-in, payment, and the app stores themselves
SentryCrash and error reports
MixpanelProduct analytics

We may also disclose data where the law requires it, to establish or defend legal claims, or to protect the safety of our users. If RiceCal is ever sold or merged, your data may pass to the buyer under this same policy, and we will tell you before that happens.

A recipe is the one thing you can choose to make public. When you publish one, its name, ingredients, steps and pictures become visible to other users. Your email address is never shown. Making it private again removes it from the community shelf.

How long we keep it

  • Your account, diary, recipes, photos and health history are kept for as long as your account exists.
  • When you ask us to delete your account, everything above is erased within 30 days, and immediately from the live systems.
  • Encrypted backups may hold a copy for up to a further 30 days before they roll off.
  • Crash reports and product analytics are kept for up to 12 months.
  • Records we must keep for tax or accounting are kept as long as the law requires, and hold no diary content.
  • The catalogue backlog of unmatched dishes and barcodes is anonymous and is kept indefinitely.

Your rights

Wherever you are, you can ask us for any of the following and we will answer within 30 days.

  • A copy of the data we hold about you, in a portable format.
  • Correction of anything that is wrong.
  • Deletion of your account and everything attached to it.
  • Restriction of, or objection to, a particular use.
  • Withdrawal of a consent you gave, including the health connection and notifications.
  • A complaint to your data protection authority, if we have not put something right. In the UK that is the ICO, in Malaysia the Personal Data Protection Department, and in the EU your national authority.

If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against you for exercising any right. If you are in Malaysia or Singapore, the rights above are how we meet the PDPA in each.

Write to support@ricecal.app from the address on your account and say which of these you want.

How it is protected

  • Everything travels over TLS, and everything at rest is encrypted by our providers.
  • Your diary is separated from every other diary at the database level, so one account cannot read another’s rows.
  • Meal photos are held in a private bucket with no public URLs. A picture is served through a link that is signed for your account and expires shortly after it is issued.
  • Sign-in is Apple, Google, or a single-use link sent to your email address. RiceCal has no passwords, so there are none of yours for us to lose.
  • Access to production data is limited to what support and debugging require, and is logged.

No system is perfect. If a breach affects your data we will tell you and the relevant regulator as the law requires.

Where your data goes

Our providers run in several regions, including Singapore, the European Union and the United States, so your data may be processed outside the country you live in.

Where data leaves the UK or the EEA, we rely on the UK and EU Standard Contractual Clauses, or on an adequacy decision covering the destination.

Children and suitability

RiceCal is not directed at children and is not for anyone under 16. We do not knowingly collect data from a child. If you believe a child has created an account, write to us and we will delete it.

Calorie tracking is not appropriate for everyone. If you are pregnant, under 18, or have a history of disordered eating, please speak to a health professional before using an app like this one.

Changes, and how to reach us

When this policy changes we update the date at the top of this page. If the change is significant, we will tell you in the app or by email before it takes effect.

To ask anything, to exercise a right, or to complain, write to support@ricecal.app. You can also use the contact form on this site.

Talk to a person

Anything on this page, and anything not on it, goes to support@ricecal.app. There is also a contact page if you would rather fill something in.