FreeCals

Privacy

This is the canonical wording: the in-app Privacy screen, the App Store privacy label and this page say the same thing. If one changes, all three change.

Where your data lives

On your phone. Diary entries, meals, portions, weight, goals, body data, custom foods, recipes, water, and settings are stored in a database on the device, and that database is the only copy. No FreeCals server holds a record of you, there is nothing to sign in to, and nothing is uploaded in the background.

Some of it does go out to be looked up or read, and never on its own initiative: the next section is the complete list of what, and when.

Deleting the app deletes the data. Export it first from Settings if you want to keep it.

What leaves your device

Seven things, and only when you ask for them:

DataWhenGoes to
The barcode you scannedAt the moment you scanFreeCals backend, then Open Food Facts
The text you searched forAt the moment you searchFreeCals backend, then Open Food Facts and USDA FoodData Central
The meal you describedAt the moment you tap Look it upFreeCals backend, then OpenAI
The workout you describedAt the moment you tap Look it upFreeCals backend, then OpenAI
A photo you take or choose to identify foodAt the moment you submit itFreeCals backend, then OpenAI
A recipe URL you paste, or a photo of a recipeAt the moment you import itFreeCals backend, and the page itself; OpenAI only if the page's own data was not enough
Your question, and the recent diary it is aboutAt the moment you tap AskFreeCals backend, then OpenAI

Those requests carry no account, no device identifier, no install ID, and no cookies. The backend sees the barcode, the search text, the description, the photo or the question, and the IP address the request came from, the same as any web request. None of them is ever written to a log. Search text and meal descriptions are never written to disk either: each is cached under a hash of itself, so the words you typed are not stored. A photo is handled the same way: it is cached under a hash of the image bytes, not the image itself, so what you photographed is not stored either. A scanned barcode is stored, for seven days, as part of the cached product record. It identifies a product. The cache holds nothing about who asked for it.

Describing a meal or a workout in words, or submitting a photo to identify food, involves a company other than Open Food Facts. The description or the photo is forwarded to OpenAI, which reads it and answers with figures. Nothing identifying you goes with it, and the answer is all that comes back. The photo is downscaled on your device before it is sent, the same reduction in size and detail a messaging app applies before sharing a picture.

A workout description carries no figure about your body. “45 minutes bouldering” cannot become an energy figure without a weight, so the server does not produce one: it answers with the activity, the duration and an intensity value, and your phone does the multiplication itself. Your weight is not part of that request. Nothing else you have logged is sent with either kind of description, or with a photo: no diary, no history, no goals, no body data. Asking a question about your numbers does send some of those, and the next section says exactly what.

Importing a recipe from a URL works differently from every other request in this table. The backend fetches the page itself, on your behalf, and most recipe sites publish their recipe as structured data the backend can read directly — no model, no OpenAI, nothing beyond the FreeCals backend and the page you pointed it at. Only when a page carries none of that does the backend fall back to a model, sending the page's own visible text to OpenAI the same way a description is. A recipe photo always goes to OpenAI, the same way a food photo does. Either way, nothing about you goes with it: no diary, no account, no device identifier.

A search asks two databases, not one. Open Food Facts answers for packaged products and USDA FoodData Central answers for generic foods, and the words you typed go to both. A scanned barcode goes only to Open Food Facts, because a generic food never had one.

The app also downloads product images from Open Food Facts to show them in search results. A food from USDA FoodData Central has no photograph, and none is shown for it.

Asking about your numbers

To answer “I went 800 over yesterday, should I eat less today?”, a model has to see what you ate. So that one request carries your recent diary: the last 28 days of daily calories and macros against the targets each of those days had, the active energy your device recorded on each of them if you read energy from Health, your current weight and the trend it is on, your goal and the rate you set, your current targets, and today's entries and workouts by name. Real food names and real dates, because an answer written without them is a worse answer, and a worse answer is the only thing being protected by withholding them.

It happens when you tap Ask on the “Ask about your numbers” screen, and at no other time. Nothing in the app opens that screen for you, and no question is ever answered that you did not type.

The backend forwards it to OpenAI and keeps nothing. This request is not cached, not logged and not written to disk at any point. There is still no account, no device identifier and no copy of your diary on any server: the request exists for as long as it takes to answer it, and then it is gone.

The answer is prose and is shown as prose. It is a model's opinion, it is labeled as one, no number is parsed out of it, and nothing it says is written to your diary. The questions you asked are kept in memory while the app is running and are gone when you close it.

The camera

The camera is used for four things, and two of them work the opposite way from the other two.

Reading a barcode and reading a printed nutrition table both happen entirely on your device. No picture the camera takes for either is saved: it is held in memory for as long as it takes to read, then discarded. It is not written to a file, not added to your photo library, and never uploaded. A scanned nutrition table is never sent anywhere at all: the numbers it produces go straight into an editor for you to check. The barcode is the only thing a scan ever sends, and only to look the product up.

Taking or choosing a photo to identify food — a plate, a menu, a printed label, or a receipt — is deliberately the opposite: nothing on your device can look at a plate and say what is on it, so that photo is sent, the same way a typed description is. It is downscaled first, then sent once and answered. The backend does not save the photo itself: what it keeps is the answer — a list of foods and some numbers — filed under a hash of the photo for 24 hours, so the same file submitted twice does not cost a second lookup. It is never written to a log and never added to any photo library but your own.

A photo taken or chosen to import a recipe is handled the same way as a food photo — downscaled, sent once, answered, never saved — because reading a recipe off a cookbook page or a handwritten card needs the same model a plate of food does.

What is never collected

No analytics. No crash reporting. No advertising identifier. No device fingerprint. No third-party SDK of any kind is compiled into the app.

Apple Health

Health integration is off until you turn it on, apart from copying a workout you log into Health, which iOS asks you to allow the first time. Reading and writing are separate switches. Health data stays on your device and is handled by Apple there.

One number read from Health does leave, and only on the request above. If you have turned on reading energy from Health and you ask a question about your numbers, each day in the window carries the active energy your Watch or phone recorded for it, because a question about eating enough on a hard training day cannot be answered without it. It is one calorie figure per day. No workout Health recorded is named, and no heart rate, step count, sleep or other Health sample of any kind is ever sent.

Reminders

Reminders are off until you turn them on, and nothing is scheduled until you set a time. They are scheduled by iOS on this device. FreeCals is not registered for push notifications, never asks for a device token, and no server is involved in a reminder at any point.

A reminder never names a food, a weight or a number. It says the name of the meal, or “Log your weight”, or “Fasting window ended”, because a notification is read on a locked screen.

Attribution

Product data comes from Open Food Facts, licensed under the Open Database License. Product images are licensed CC-BY-SA by their contributors.

Generic foods come from USDA FoodData Central, published by the US Department of Agriculture. It is a work of the US federal government and is in the public domain, which asks for nothing; the app names it anyway, because where a figure was measured is part of the figure.