The short version
Thaya uses your information to create a nutrition plan, analyze meals, track progress, sync optional health data, send reminders, and manage subscriptions. We do not sell your personal or health data and do not use it for third-party advertising.
1. Who we are and what this covers
Thaya ("Thaya," "we," "us," or "our") provides an AI-assisted nutrition, meal logging, and progress-tracking application. This Privacy Policy applies to the Thaya mobile app, related support communications, and backend services used to operate the app.
For privacy questions or requests, contact [email protected]. Thaya is the controller of personal data described here, except where a service provider acts as an independent controller under its own terms.
Important: Thaya is a general wellness tool, not a medical device or healthcare provider. Nutrition and AI outputs are estimates and are not medical advice.
2. Information we collect
Information you provide
- Account and identity: email address, password credentials handled by our authentication provider, name, sign-in provider, provider user ID, avatar, and authentication metadata.
- Profile and goals: date of birth or age, gender, height, current and desired weight, activity level, nutrition or weight goal, target pace, dietary preferences, biggest challenge, language, and how you heard about Thaya.
- Meals and nutrition: meal names, dates and times, food items, portions, calories, protein, carbohydrates, fat, fiber, sugar, sodium, manual edits, scan results, and confirmations or corrections.
- Progress and habits: weight entries, step goals, water logs, fasting preferences and records, streaks, progress measurements, optional progress photos, and optional meal photos.
- Communications: information you include when contacting support or making a privacy request.
Information collected from your device or use
- Health data, only with permission: steps, active calories burned, and weight read from Apple Health or Health Connect. See Section 4.
- Camera and photo access: an image you capture or select for meal analysis or progress tracking. The app does not need continuous camera access.
- App and device data: app version, operating system/platform, device or app instance identifiers used by integrated services, language, time zone, push notification token, permission state, and basic network/request metadata.
- Usage and diagnostics: feature interactions, onboarding and paywall events, subscription state, scan quota and performance information, model/provider version, token and cost telemetry, crash logs, error context, and app performance.
- Purchase information: product ID, entitlement and subscription status, platform, transaction or purchase identifiers/tokens, renewal/expiry time, and store event data. Apple or Google processes your payment details; Thaya does not receive your complete card number.
We obtain information directly from you, automatically when you use the app, from Apple Health or Health Connect after you grant permission, and from Apple, Google, authentication providers, and subscription infrastructure when you sign in or purchase a plan.
3. Why we use information
| Purpose | Examples of data | Basis, where required |
|---|---|---|
| Provide and personalize Thaya | Account, profile, goals, meal logs, progress data | Perform our contract; your request |
| Analyze meal images and estimate nutrition | Meal photo, scan metadata, meal result | Your request and permission; perform our contract |
| Optional health sync | Steps, active calories, weight | Your explicit permission/consent |
| Subscriptions and entitlement | Product, platform, transaction and subscription status | Perform our contract; legal obligations |
| Reminders and notifications | Push token, time zone, preferences, relevant activity | Your permission; your request |
| Security, abuse and quota controls | Account, scan usage, request and error metadata | Legitimate interests; protect the service |
| Analytics, reliability and improvement | Feature events, diagnostics, crashes, de-identified corrections | Consent where required; legitimate interests |
| Legal compliance and disputes | Relevant account, transaction and support records | Legal obligation; legal claims |
We do not use health data, meal photos, or progress photos for targeted advertising. We do not sell personal or sensitive data.
4. Health and sensitive data
Connecting Apple Health or Health Connect is optional. If you choose to connect it, Thaya asks for permission to read steps, active calories burned, and weight so the app can show activity and weight context and support your nutrition and progress tracking. Current app functionality does not write health records.
- You can use core meal logging without connecting a health service.
- You can deny or revoke permissions at any time in Apple Health, Health Connect, or your device settings. Previously imported data may remain in Thaya until you delete it or your account.
- Health data is not used for advertising, sold, or shared with data brokers.
- Thaya does not use HealthKit or Health Connect data for credit, employment, insurance, or eligibility decisions.
Camera and photo-library access is also optional and requested only when you choose a photo feature. You can log a meal manually if you prefer not to provide a photo.
5. Meal photos, progress photos, and AI
Meal analysis
When you ask Thaya to scan a meal, the selected image is sent securely to our backend and then to a configured AI provider (Google Gemini or a model provider accessed through OpenRouter) to identify likely foods, portions, and estimated nutrition. AI providers receive the image and an analysis instruction, plus technical request metadata. Do not include faces, documents, or unrelated sensitive information in meal photos.
Meal photos you save are stored in private cloud storage linked to your account so they can appear with your meal history. Progress photos are stored separately in private account-scoped storage and are used only for your progress-tracking feature.
Improving scan quality
If you confirm or correct a scan, Thaya may create a training-quality sample containing the original model output, your corrected values, dish/portion information, model version, locale, and an image reference. We use these samples to evaluate and improve meal recognition. If you delete your account, personal identifiers and account/meal links are removed and image paths are deleted; strictly de-identified nutrition examples may be retained where they can no longer reasonably be linked to you.
AI estimates can be wrong. Always review the result before saving it, especially if accurate intake information matters for allergies, medication, pregnancy, a medical condition, or a therapeutic diet.
7. Retention and account deletion
We keep personal data only as long as needed to provide Thaya, satisfy the purposes above, meet legal or accounting requirements, resolve disputes, and protect the service. Retention depends on the record:
| Data | Typical retention approach |
|---|---|
| Account, profile, meals, water/fasting logs, photos, devices and preferences | While your account is active; deleted when account deletion completes, subject to limited legal exceptions. |
| Subscription and transaction records | While needed to manage access, reconcile store events, prevent fraud, and meet legal/accounting duties. |
| Crash, security and operational logs | For a limited period based on operational and provider settings, then deleted or aggregated. |
| Confirmed/corrected scan samples | Account links and image paths are removed on deletion; strictly de-identified food and nutrition values may be kept to improve accuracy. |
| Backups | Deleted data may remain temporarily in protected backups until ordinary backup rotation completes. |
Delete your account
In the app, go to Profile → Delete account and confirm. This deletes your authentication account, profile, meal and progress records, private meal and progress photos, device tokens, preferences, and other account-linked app data. It also removes your identifiers from retained training, notification, and RevenueCat event records.
Deleting Thaya does not cancel an active subscription. Cancel it separately in your Apple App Store or Google Play account settings. If you cannot access the app, request deletion at [email protected]. We may ask you to verify account ownership.
We may retain a narrowly limited record when required by law, necessary for security/fraud prevention, or needed to establish or defend legal claims. Any retained data remains protected and is not used for other purposes.
8. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, download, delete, restrict or object to processing, withdraw consent, or receive a portable copy of personal data. You may also have a right to complain to your local data protection authority.
- Edit profile, goals, language, reminder, and notification settings in the app.
- Revoke camera, photo, notification, Apple Health, or Health Connect permissions in device settings.
- Cancel or manage subscriptions through the store where you purchased.
- Delete your account from Profile or contact us for a privacy request.
Withdrawing consent does not affect processing already completed lawfully. Some features will not work without the information they require. We will not discriminate against you for exercising applicable privacy rights.
9. Security and international transfers
We use reasonable administrative, technical, and organizational safeguards, including encrypted network connections, access controls, private storage buckets, row-level database permissions, and provider security controls. No online service can guarantee absolute security, so keep your credentials confidential and contact us if you suspect unauthorized access.
Thaya and its providers may process information in countries other than the one where you live. Where required, we rely on lawful transfer mechanisms and contractual safeguards. The MVP backend is configured for an EU region, while some providers may process data globally under their service terms.
10. Age requirements
Thaya is not directed to children under 13. Users who are under the age of legal majority where they live must use Thaya only with permission and supervision of a parent or legal guardian. If you believe a child provided personal data without required consent, contact us so we can investigate and delete it.
11. Changes to this policy
We may update this policy when Thaya, our providers, or legal requirements change. We will post the revised version with a new effective date and provide additional notice in the app when a change is material. Your continued use after the effective date is subject to the updated policy, except where the law requires renewed consent.
12. Contact us
For access, deletion, consent, or other privacy questions, contact the Thaya privacy team.
[email protected]