TrimByte is a calorie- and nutrition-tracking app made by Consort Tech ("we", "us"). This policy explains what information the app handles, where it goes, and what stays on your device. The short version: your food log lives on your device, meal photos are sent only to generate a nutrition estimate, and we keep the minimum needed to run accounts and purchases. We do not sell personal data and we do not show ads.
1. Information stored on your device only
The following is stored locally on your phone (or in your browser on the web version) and is not uploaded to our servers:
- your meal log — photos, thumbnails, recognised food items, calories and macros;
- exercise log, water intake and weight history;
- the profile you enter during onboarding — goal, height, weight, birth year, sex and activity level — and the calorie/macro targets calculated from it;
- streaks, celebrations and reminder settings.
Deleting the app, or using Settings → Reset all data, erases this information. Because it never leaves your device, we cannot recover it for you.
2. Meal photos
When you photograph a meal, the photo (resized to about 1024 px) is sent over an encrypted connection to our API server, which relays it to Anthropic's Claude API to produce the nutrition estimate. The photo is used only to produce that estimate. It is not stored on our servers, not used for advertising or profiling, and — under Anthropic's commercial API terms — not used to train AI models. The photo and the resulting entry are then kept only on your device.
3. Account information we store
TrimByte starts you with an anonymous guest account so that your free trial or purchase can be recognised. You may optionally attach an email address and password so your access follows you to a new phone or the web. Using Supabase as our infrastructure provider, we store:
- your account ID and, if you added one, your email address — passwords are held only in hashed form by the authentication service; we never see them;
- your entitlement: free-trial start and end dates, your current plan (weekly, monthly, yearly or lifetime), its renewal date, and whether it auto-renews;
- purchase records: payment provider, plan, amount, currency, date, and any promo code used. We never see or store card numbers.
4. Payments and subscriptions
In the iOS and Android apps, purchases and subscriptions are processed by the App Store or Google Play through RevenueCat, which sends us a confirmation of the purchase and subscription status. On the web, payments are processed by Stripe. These providers handle payment details under their own privacy policies. We receive no card data.
5. Notifications
Meal and water reminders are scheduled locally on your device. We do not send push notifications from a server, and no notification data leaves your device.
6. Technical data
Like any internet service, our API server and hosting provider record standard request logs (IP address, request time, device type) for security and to prevent abuse; meal analysis requests are rate-limited per account. These logs are retained for a short period and are not linked to your food log. If you join a beta programme or opt in to share crash reports with Apple or Google, those companies forward anonymised crash data to us.
7. Summary of data and purposes
| Data | Where it lives | Purpose |
|---|---|---|
| Food, exercise, water, weight log; body profile and goals | Your device only | Tracking and calculating your targets |
| Meal photos | Transit only (our server → Anthropic), not stored | Generating the nutrition estimate |
| Account ID, email (optional) | Supabase (our provider) | Sign-in, recovering access on a new device |
| Entitlement and purchase records | Supabase; App Store / Google Play / Stripe | Unlocking the app, receipts, support, fraud prevention |
| Request logs | API hosting provider | Security, abuse prevention |
8. What we don't do
- No advertising and no ad networks.
- No sale or sharing of personal data for marketing — to anyone, ever.
- No third-party analytics or tracking SDKs, and no cross-app tracking.
- No use of your data to train AI models.
9. Service providers
We use a small number of processors to run TrimByte, each receiving only what its function needs: Supabase (accounts and entitlements), Anthropic (nutrition estimates from photos), Apple, Google Play and RevenueCat (store purchases and subscriptions), Stripe (web payments) and Expo (EAS Hosting) for our API server. These providers may process data in the United States or other countries with safeguards required by applicable law.
10. Data retention and deletion
Account and purchase records are kept while your account exists, plus any period we are legally required to keep transaction records. You can delete your account at any time in Settings → Account → Delete account; this permanently removes your account, entitlement and purchase records from our systems and erases the data on that device. You can also email us to request deletion. Payment records held by Apple, Google or Stripe are governed by their policies. Active subscriptions must be cancelled through the App Store or Google Play; deleting your account does not cancel them.
11. Your rights
Under the Philippine Data Privacy Act of 2012 and, where applicable, laws such as the GDPR and the CCPA, you may have the right to access, correct, export, restrict or delete your personal data, to object to processing, and to lodge a complaint with your data protection authority (in the Philippines, the National Privacy Commission). Because almost everything lives on your device, most of this is already in your hands; for anything we hold (account and purchase records), contact us and we will respond within 30 days. We do not discriminate against anyone for exercising these rights.
12. Children
TrimByte is not directed at children under 13. Onboarding requires a birth year of 13 or older, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Security
All connections use HTTPS. Server-side data is protected with row-level security and access-controlled keys; anything that grants access to the app runs only on our server. No system is perfectly secure, so we keep the amount of data we hold deliberately small.
14. Changes
If we change this policy — for example, if we add optional cloud sync for your meal history — we will update this page and the effective date, and note material changes in the app.
15. Contact
Consort Tech, Philippines
Privacy questions or requests: andyr@consorttech.com