Only these, and only when you do the thing that triggers them. Nothing else in AlisLog makes an outbound request.
Everything you log — food entries, weights, goals, recipes, cookbooks, pantry, shopping list, streaks, supplements, mood and energy notes, settings, themes — is stored locally on your phone. It is not uploaded to any server, and we have no way to access it. Deleting the app deletes this data. Backups you export yourself are files you control.
When you explicitly search for a food, describe a meal, scan a barcode, photograph a meal, or import a recipe, what you provided — the text you typed, the barcode you scanned, the photo you took, or the recipe page URL — is sent to our server, which looks it up and returns the result. Meal photos are analyzed in memory and never stored: not by us, not in any cache — the estimate comes back and the image is gone. Depending on the lookup that means Google's Gemini API for nutrition estimates, and Open Food Facts, USDA FoodData Central or UPCitemdb for packaged products.
These requests include a random installation identifier used only for abuse prevention and rate limiting. It is generated on first launch, is not derived from any device identifier, and is not linked to your name, email, or identity, because the app never asks for any. Request contents are not used to build profiles.
Lookup results are cached on our server for about 180 days, keyed by the query itself rather than by who asked, so a common food isn't re-billed to the AI every time someone logs it. A lookup that found nothing is kept for 2 days. Recipe imports use a separate cache, keyed by a hash of the page URL or the pasted text and kept for 30 days.
Household pairing is peer-to-peer via QR codes or links. Optional automatic pantry sync passes through our relay server end-to-end encrypted: the encryption key is exchanged only between your phones inside the pairing code, so the relay stores ciphertext it cannot read, and that ciphertext expires automatically within 7 days.
If you create a share link, its contents (name, ingredients, nutrition) are stored on our server so the link works for the recipient. Share links contain no personal information, but don't put anything private in a recipe you share. Anyone holding the link can open it.
A share link and its contents are deleted automatically 180 days after creation, after which the link stops working. There is currently no way to revoke a link early from inside the app: email the link to support@alislog.com and it will be deleted.
If you connect Apple Health, AlisLog reads steps and active energy only, read-only, to display them in the app. It never writes to Health, never reads anything else, and this data stays on your device. It is never transmitted anywhere.
Premium purchases are processed by Apple. Receipt validation is handled by RevenueCat using an anonymous identifier; see RevenueCat's privacy policy. We never see payment details: not your card, not your name, not your billing address.
Off by default. If you turn automatic backups on, AlisLog writes a daily snapshot of your full dataset into the app's Documents folder on your phone. That snapshot never touches our servers, but two things follow that you should know.
Documents is included in your iPhone's normal iCloud device backup, so if iCloud Backup is on, the snapshot reaches Apple's servers. Apple encrypts it, and end-to-end if you have Advanced Data Protection enabled. And because file sharing is enabled, the folder is visible in the Files app, so anyone holding your unlocked phone can read it.
So: "never touches our servers" is true. "Never leaves your phone" would not be.
Our server writes structured events for errors and rate limits. Installation identifiers are hashed to eight characters before they are logged, and error text is truncated. No user-typed content is logged deliberately, with one honest exception: if a recipe import fails, the URL you pasted can appear inside the error message.
Vercel's own function logs retain roughly an hour. Where extended retention is configured, it is 30 days.
Requests that cost us money are protected with Apple's App Attest, which proves a request came from a genuine copy of AlisLog rather than a script. This exchanges a cryptographic assertion with Apple. It identifies the app installation, not you.
Every item here was verified against the shipping code, not aspirational.
AlisLog is rated 13+ and is not directed at children under 13. It does not knowingly collect information from them, and it collects almost nothing from anyone. If you believe a child has provided us information, email us and we'll delete it.
Packaged-product data is contributed by Open Food Facts under the Open Database License. Generic foods come from USDA FoodData Central, with UPCitemdb as a fallback. Estimates for described meals are generated by Google Gemini. Any of it can be wrong; you can correct a food's numbers by hand and AlisLog will remember the correction.
If this policy changes, the update will be posted here with a new effective date. Questions, or want a share link deleted early?
support@alislog.com ↗