Privacy Policy

Short, because there'snot muchto disclose.

We can't sell your data, because we don't have it. AlisLog has no accounts, so there is nothing to log into and nothing to breach. What you log stays on your phone.
Effective August 2026

What leavesyour phone.

Only these, and only when you do the thing that triggers them. Nothing else in AlisLog makes an outbound request.

When you…
What is sent
Who handles it
Search a food or describe a meal
the text you typed
Google Gemini, via our server
Scan a barcode
the barcode digits
Open Food Facts, USDA FoodData Central, UPCitemdb, via our server
Import a recipe
the URL or text you pasted
Google Gemini, via our server
Create a share link
the recipe or cookbook contents
our server only
Sync a household pantry
encrypted ciphertext only
our relay, which cannot read it
Open the app
nothing about you
our server (feature flags)
Buy Premium
an anonymous ID and the receipt
Apple, RevenueCat
Every third-party lookup is proxied through our own server. Your device never contacts Google, Open Food Facts, USDA or UPCitemdb directly, so none of them ever see your IP address.
The policy · 9 clauses
01

Data on your device

Everything you log — food entries, weights, goals, recipes, cookbooks, pantry, shopping list, streaks, supplements, mood and energy notes, settings, themes — is stored locally on your phone. It is not uploaded to any server, and we have no way to access it. Deleting the app deletes this data. Backups you export yourself are files you control.

02

Food lookups

When you explicitly search for a food, describe a meal, scan a barcode, photograph a meal, or import a recipe, what you provided — the text you typed, the barcode you scanned, the photo you took, or the recipe page URL — is sent to our server, which looks it up and returns the result. Meal photos are analyzed in memory and never stored: not by us, not in any cache — the estimate comes back and the image is gone. Depending on the lookup that means Google's Gemini API for nutrition estimates, and Open Food Facts, USDA FoodData Central or UPCitemdb for packaged products.

These requests include a random installation identifier used only for abuse prevention and rate limiting. It is generated on first launch, is not derived from any device identifier, and is not linked to your name, email, or identity, because the app never asks for any. Request contents are not used to build profiles.

Lookup results are cached on our server for about 180 days, keyed by the query itself rather than by who asked, so a common food isn't re-billed to the AI every time someone logs it. A lookup that found nothing is kept for 2 days. Recipe imports use a separate cache, keyed by a hash of the page URL or the pasted text and kept for 30 days.

03

Household sync

Household pairing is peer-to-peer via QR codes or links. Optional automatic pantry sync passes through our relay server end-to-end encrypted: the encryption key is exchanged only between your phones inside the pairing code, so the relay stores ciphertext it cannot read, and that ciphertext expires automatically within 7 days.

04

Shared recipes & cookbooks

If you create a share link, its contents (name, ingredients, nutrition) are stored on our server so the link works for the recipient. Share links contain no personal information, but don't put anything private in a recipe you share. Anyone holding the link can open it.

A share link and its contents are deleted automatically 180 days after creation, after which the link stops working. There is currently no way to revoke a link early from inside the app: email the link to support@alislog.com and it will be deleted.

05

Apple Health

If you connect Apple Health, AlisLog reads steps and active energy only, read-only, to display them in the app. It never writes to Health, never reads anything else, and this data stays on your device. It is never transmitted anywhere.

06

Purchases

Premium purchases are processed by Apple. Receipt validation is handled by RevenueCat using an anonymous identifier; see RevenueCat's privacy policy. We never see payment details: not your card, not your name, not your billing address.

07

Automatic backups

Off by default. If you turn automatic backups on, AlisLog writes a daily snapshot of your full dataset into the app's Documents folder on your phone. That snapshot never touches our servers, but two things follow that you should know.

Documents is included in your iPhone's normal iCloud device backup, so if iCloud Backup is on, the snapshot reaches Apple's servers. Apple encrypts it, and end-to-end if you have Advanced Data Protection enabled. And because file sharing is enabled, the folder is visible in the Files app, so anyone holding your unlocked phone can read it.

So: "never touches our servers" is true. "Never leaves your phone" would not be.

08

Server logs

Our server writes structured events for errors and rate limits. Installation identifiers are hashed to eight characters before they are logged, and error text is truncated. No user-typed content is logged deliberately, with one honest exception: if a recipe import fails, the URL you pasted can appear inside the error message.

Vercel's own function logs retain roughly an hour. Where extended retention is configured, it is 30 days.

09

App integrity

Requests that cost us money are protected with Apple's App Attest, which proves a request came from a genuine copy of AlisLog rather than a script. This exchanges a cryptographic assertion with Apple. It identifies the app installation, not you.

How long anythingis kept.

Data
Lifetime
Everything on your device
until you delete it, or delete the app
Household relay box
7 days, automatic
Household verification key
30 days from the last write; a public key, not contents
Share links (recipe / cookbook)
180 days, automatic
Nutrition lookup cache
~180 days, keyed by query, not by user
Failed nutrition lookups
2 days
Recipe import cache
30 days, keyed by a hash of the URL or text
Server log events
~1 hour, or 30 days where extended retention is on

A short listof nevers.

Every item here was verified against the shipping code, not aspirational.

Analytics or tracking SDKs Ads of any kind Selling or sharing your data Email lists or marketing push Profiles or fingerprinting Crash-reporting SDKs Accounts or passwords Dark patterns
This website matches. It sets no cookies, runs no analytics, and loads its fonts from our own server, so reading this page doesn't announce you to anyone either.

Children

AlisLog is rated 13+ and is not directed at children under 13. It does not knowingly collect information from them, and it collects almost nothing from anyone. If you believe a child has provided us information, email us and we'll delete it.

Where the food data comes from

Packaged-product data is contributed by Open Food Facts under the Open Database License. Generic foods come from USDA FoodData Central, with UPCitemdb as a fallback. Estimates for described meals are generated by Google Gemini. Any of it can be wrong; you can correct a food's numbers by hand and AlisLog will remember the correction.

Changes& contact.

If this policy changes, the update will be posted here with a new effective date. Questions, or want a share link deleted early?

support@alislog.com ↗