The Company is committed to protecting Your privacy. This Privacy
Policy explains how We collect, use, and safeguard Your information
when You use the Service.
By using the Service, You agree to the collection and use of
information in accordance with this Privacy Policy.
TL;DR: BulkMode is designed exclusively for healthy
weight gain—not weight loss. We use third-party AI services for food
photo analysis. We treat Your Health Data with extra care and do not
sell or share it for advertising purposes. Your nutrition data stays
private in Your Account.
1. Definitions
"Account" means the unique profile created for You to
access the Service.
"Application" means the mobile application titled
"BulkMode," designed exclusively to help users gain weight in a
healthy manner. The Application is not intended for weight loss,
calorie restriction, or maintaining a caloric deficit.
"Company," "We," "Us," or "Our" means Simplify
Possible LLC, an Illinois limited liability company, with mailing
address 4235 N Mobile Ave, Chicago, IL 60634, United States.
"Device" means any device used to access the Service.
"Health Data" means information You provide relating
to Your physical characteristics, health, nutrition, or goals,
including weight, height, date of birth, gender, food logs, calorie
targets, and body metrics.
"Personal Data" means information that identifies or
can reasonably be linked to an individual, including identifiable
health information.
"Usage Data" means data collected automatically
through use of the Service, including device information, activity
logs, IP addresses, and analytics data.
"User Content" means photos, images, text, food
entries, or other inputs You upload or submit through the Service.
"Website" means bulkmode.app.
"You" means the individual using the Service or the
organization on whose behalf the Service is used.
Important Health Disclaimer
The Service is NOT medical advice. The Application
is an educational nutrition tracking tool, NOT a substitute for
professional medical advice, diagnosis, or treatment.
For complete health and safety information—including metabolism system
disclaimers, AI accuracy limitations, eating disorder resources, and
guidance for minors—please review Our
Health Disclaimer and
Terms of Service.
If You or someone You know is struggling: Contact the
National Eating Disorders Association (NEDA) at 1-800-931-2237 or text
"NEDA" to 741741. In crisis, call 988.
2. Information We Collect
Personal Information
When You create an Account or use the Service, We may collect:
-
Display name and avatar emoji (optional, for personalization)
-
Sign in with Apple: If You choose to sign in with
Apple, Apple may share Your name and email address (or a private
relay email) with Us, depending on Your Apple ID settings. We do not
store passwords—authentication is handled entirely by Apple.
-
Sign in with Google: If You choose to sign in with
Google, Google may share Your name and email address with Us,
depending on Your Google Account settings. We do not store
passwords—authentication is handled entirely by Google.
-
Anonymous accounts: You can use the Service without
signing in or providing contact information such as Your name or
email address. Anonymous accounts are authenticated through a secure
session stored in Your Device's keychain. Your data syncs to Our
servers and can typically be restored if You reinstall the Application,
but cannot be recovered if Your keychain is cleared (e.g., new device
or factory reset).
Health and Nutrition Data
When You use the Service's calorie tracking features, You provide
Health Data:
- Food logs and meal entries
- Calorie and macronutrient intake
- Weight and body metrics (body fat percentage is required during onboarding to calculate personalized targets)
-
Date of birth — Used to calculate Your age for accurate calorie and
nutritional recommendations. This is collected during onboarding.
-
Food photos for AI analysis: Photos are resized
and compressed before being sent to Our AI providers for analysis.
These processed images are used in real-time to identify food items
and estimate nutritional content, then immediately discarded from
Our servers—only the nutritional results are stored in Your Account.
We do not perform facial recognition, biometric scanning, or any
identification of individuals who may appear in photos.
Thumbnail storage: Compressed, low-resolution
thumbnail previews are stored locally on Your Device to display
Your food log entries. These thumbnails are deleted when You delete
the corresponding food log entry, Your Account, or the Application.
We reserve the right to retain anonymized, de-identified versions
of food photos to improve Our AI food recognition technology in the
future. If We begin retaining photos on Our servers, We will update
Our App Store privacy labels accordingly.
See Section 4 (AI Providers) for details on how photos are processed.
- Dietary goals and preferences
- Target weekly weight gain rate (to personalize Your calorie recommendations)
- Hard gainer status (whether You have difficulty gaining weight)
-
Individual ingredient breakdowns within meals — When Our AI analyzes
Your food photos, We store the name, quantity, estimated weight, and
nutritional values (calories, protein, carbs, fat) for each
identified ingredient. You can view and edit these breakdowns in the
Application.
-
Streak repair history — If You use the streak repair feature, We
record when repairs were applied and the streak values before and
after repair. This helps prevent abuse and provides You with
accurate streak records.
- Any other health information You choose to enter into the Application
Automatically Collected Information
We automatically collect certain Usage Data:
-
Device information (device type, operating system, Application
version)
-
Device identifier — Apple-assigned vendor identifier (IDFV) for
device-level sync and fraud prevention. This identifier is NOT the
advertising identifier (IDFA) and cannot be used for cross-app
tracking.
-
IP address — Stored by Our authentication provider (Supabase) in
session logs and audit trails for security and fraud prevention
purposes. Retained for up to 90 days per Supabase's data retention
policies. IP addresses are not stored in general application
activity logs.
-
Usage data (features used, time spent, interactions) - anonymized
-
Timezone information (to display food logs and streaks in Your local
time, and to adjust for timezone changes when You travel)
-
Daily usage counts — We track how many food photos You analyze each
day to enforce usage quotas and prevent abuse of Our Service. This
includes timestamps of analysis attempts for rate limiting purposes.
Referral Program Data
If You use a referral code or refer others to the Service, We store:
- Your unique referral code
-
The relationship between referrer and referee (if applicable)
- Referral reward status
This data is used solely to grant referral rewards.
Feedback and Preferences
During onboarding, We may collect:
- Your main challenges with nutrition tracking
- Your desired accomplishments and fitness goals
- Your commitment level (on a 1-10 scale)
-
Your confidence rating in achieving Your plan (plan achievability
rating) — A rating You may provide after Your first day indicating
how achievable You feel Your nutrition plan is
- How You heard about the Service (optional)
- Previous nutrition or calorie tracking apps You've used (optional)
You may also optionally provide feature requests in Your profile
settings. This feedback helps Us improve the Service and is not
shared with third parties.
Derived and Aggregated Data
We automatically generate aggregated summaries of Your daily nutrition
data to power features like streak tracking, achievements, and progress
analytics. This includes:
- Daily totals of calories, protein, carbohydrates, and fat
- Goal achievement status (whether You hit Your daily targets)
- Meal type distribution (breakfast, lunch, dinner, snacks logged)
- Food log counts per day
This data is derived from Your food logs and is used solely to provide
You with progress insights and unlock achievements.
Technical Sync Data
To ensure reliable data synchronization and prevent duplicate requests,
We temporarily store:
-
Device identifier — Used to coordinate sync operations
across Your devices
-
Idempotency keys — Unique request identifiers stored
for up to 24 hours to prevent duplicate processing of achievement
updates and other operations
-
Migration identifiers — When You upgrade from an
anonymous Account to an authenticated Account, We track the migration
relationship to ensure Your data transfers correctly and to prevent
duplicate migrations
This technical data is used solely for operational reliability and is
automatically cleaned up after its retention period.
On-Device Data Storage
To provide offline functionality and a seamless experience, We store
certain data locally on Your Device:
-
Local database: Your profile, food logs, weight
logs, streaks, and achievements are stored locally using iOS secure
storage (SwiftData). This enables offline access and syncs with Our
servers when You are online.
-
Secure credentials: Authentication tokens and
session data are stored in the iOS Keychain, which provides
hardware-level encryption.
-
Preferences: Your app settings, notification
preferences, and privacy choices are stored locally on Your Device.
-
Cached data: Subscription status and certain
settings may be cached locally to ensure the app works correctly
even when offline.
This local data remains on Your Device and syncs with Our servers when
connected to the internet. Deleting the Application from Your Device
removes all locally stored data. To delete Your data from Our servers,
use the Account deletion feature before uninstalling.
Background Data Synchronization
The Application uses an offline-first architecture, meaning Your data
is saved locally first and then synchronized to Our servers in the
background. This ensures You can use the Application even without
internet connectivity. When You regain connectivity:
-
Your data automatically syncs in the background without requiring
any action from You
-
We use intelligent sync throttling to minimize battery usage and
cellular data consumption
-
If conflicts occur (e.g., You edited data on multiple devices while
offline), Our servers are treated as the source of truth and the
most recent server version is used
-
Sync operations include unique request identifiers to prevent
duplicate data processing
Push Notifications
Notification Permissions: With Your consent, We may
send push notifications for meal reminders, streak maintenance,
subscription status, and progress updates. You can disable
notifications in iOS Settings at any time.
If You enable push notifications, Apple provides Us with a device
token to deliver reminders and updates. This token:
-
Is specific to Our Application and cannot be used to identify You
personally or track You across other apps
-
Is used solely to deliver notifications You have opted into (meal
reminders, streak reminders, progress updates)
-
Is not sold, shared, or used for advertising purposes
-
Can be revoked at any time by disabling notifications in iOS
Settings or in the Application settings
Meal Timing Pattern Learning
To provide personalized meal reminder notifications, the Application
learns from Your meal logging habits:
-
We analyze when You typically log breakfast, lunch, dinner, and
snacks to determine Your personal meal schedule
-
After sufficient logging history (typically 21+ entries over 7+
days), We adjust reminder times to match Your actual patterns
-
Pattern data (median meal times, clustering information) is stored
locally on Your Device and is not shared with third parties
-
Patterns are re-evaluated periodically to adapt to changes in Your
schedule
-
Reminder times are adjusted within reasonable bounds (±60 minutes
of defaults) to prevent disruptive timing
This feature helps ensure You receive reminders at times that work
for Your lifestyle rather than generic times that may not fit Your
routine.
Biometric Information
Illinois BIPA Compliance: The Service does NOT
collect, capture, purchase, receive through trade, or otherwise obtain
biometric identifiers or biometric information as defined under the
Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.).
Our AI food analysis technology identifies food items in photographs
only and does not perform facial recognition, facial geometry
analysis, fingerprint scanning, voiceprint analysis, iris scanning,
retina scanning, or any other biometric identification of individuals
who may appear in photographs.
Home Screen Widget
The Service offers iOS Home Screen widgets that display Your daily
calorie progress, macro breakdown, and streak information at a glance.
Widget Data Sharing
-
Widget data is shared between the main Application and widget
extension using iOS App Groups (a secure, on-device data sharing
mechanism)
-
Data shared with widgets includes: daily calorie totals, macro
totals, calorie goal, current streak count, and Your top saved
foods for quick logging
-
This data never leaves Your Device—it is shared locally between
the Application and widget only
-
Widget data is refreshed when You log food or when iOS requests
an update
Social Sharing Features
The Service may offer features that allow You to share Your progress
on social media platforms, including:
-
Weekly Summary sharing: A shareable card showing
Your weekly statistics (streak, average calories, achievements
unlocked)
What You Control When Sharing
-
Sharing is always initiated by You—We never automatically post to
social media
-
Weight data is opt-in: Your weight change is NOT
included in share cards by default. You must explicitly choose to
include it.
-
Share cards display relative changes (e.g., "+2 lbs this week")
rather than absolute weights
-
You can preview and customize share cards before sharing
Share cards include BulkMode branding and Our website URL. When You
share to external platforms (Instagram, Twitter, etc.), those
platforms' privacy policies govern how the shared content is handled.
Siri and Voice Commands
The Service supports Siri Shortcuts, allowing You to log food and
check Your progress using voice commands. When You use Siri with the
Application:
-
Voice commands are processed by Apple according to Apple's privacy
practices
-
The Application receives only the interpreted command (e.g., "log
500 calories"), not Your voice recording
-
Food logged via Siri is treated identically to food logged manually
within the Application
-
You can view and manage Siri Shortcuts in iOS Settings → Siri &
Search → BulkMode
3. How We Use Your Information
We use Your information to:
- Provide and maintain the Service
-
Process User Content through AI to estimate nutritional information
- Calculate calorie goals and track Your progress
- Manage Your subscription and process payments
- Send important Service updates and support messages
-
Improve the Service through anonymous analytics (see Section 8 for
details)
- Detect and prevent technical issues or abuse
We do NOT use Your data for: Advertising, selling
to third parties, or cross-app tracking.
Service Improvement
We may use anonymized and aggregated data, including food photos and
meal information, to improve Our AI food recognition technology. This
data is de-identified before use and is not linked to Your identity.
Photos submitted for analysis may be used for these improvement
purposes in an anonymized form.
Progress Photos: If the Service offers progress
photo features in the future, these photos will never be used for
AI model training. Progress photos are personal and remain private
within Your Account.
We may also integrate with third-party nutrition databases and update
Our analysis methods, data sources, and AI providers at any time to
enhance accuracy and Service quality.
Automated Decision-Making
Our AI-powered nutritional analysis involves automated processing of
Your food photos to estimate calorie and macronutrient content. This
is automated decision-making as defined under GDPR Article 22.
Personalized Target Calculations: The Service uses
automated algorithms to calculate Your calorie and macro targets based
on Your profile data (height, weight, age, gender, activity level,
body fat percentage, exercise frequency, training experience, weight
history, and recent weight trend). These calculations use established
nutrition science formulas with adjustments based on Your individual
characteristics.
Adaptive Learning: Over time, the Service learns Your
actual metabolic rate by analyzing Your food intake and weight changes.
This learned data is blended with formula-based estimates to provide
increasingly personalized recommendations. You can view and override
these calculations at any time in Your profile settings.
You have the right to:
-
Edit or override: Manually edit any AI-generated
nutritional estimates directly in the Application
-
Delete: Remove any food logs containing estimates
You disagree with
-
Manual entry: Enter nutritional data manually
instead of using photo analysis
-
Request review: Contact Us to request human review
of how automated decisions affect Your Account
AI estimates are approximations based on visual analysis and may vary
from actual nutritional values. You are responsible for verifying
nutritional information, especially for medical dietary requirements.
The Service does not make automated decisions that have legal or
similarly significant effects on You—nutritional estimates are
informational tools only.
4. Information Sharing and Disclosure
We do not sell, trade, or rent Your Personal Data. We only share data
with trusted service providers who help Us operate the Service:
Service Providers
-
Supabase - Cloud hosting and database (stores Your
Account and Health Data securely)
-
PostHog - Anonymous analytics (no person profiles,
IP addresses discarded; see Section 8 for full details)
-
RevenueCat & Apple App Store - Subscription and
payment processing. RevenueCat helps Us manage subscriptions across
platforms. When You subscribe or make a purchase, We share the following
data with RevenueCat:
- Your anonymous user identifier (to link purchases to Your Account)
- Purchase receipts and transaction identifiers from Apple
- Subscription status (active, expired, trial, etc.)
- App version and platform information
RevenueCat does NOT receive Your name, email, Health Data, food logs,
or any personally identifiable information unless You choose to provide
it during support requests. All payment processing is handled securely
by Apple—We never see or store Your credit card information.
RevenueCat SDK Automatic Collection: The RevenueCat SDK
automatically collects certain device information to process subscriptions
and prevent fraud, including: device model, operating system version, app
version, locale/language, and approximate location derived from IP address.
This data is collected by RevenueCat's SDK independently of Our Application
code. See
RevenueCat's Privacy Policy
for complete details on their data practices
-
AI Providers - AI-powered features including food
photo analysis and personalized recommendations. Our AI features are
currently powered by:
For food photo analysis, We send only the following
minimal data to these providers:
- The compressed food photo image
- Your timezone (for meal timing context)
- A unique request identifier (idempotency key) to prevent duplicate processing
We do NOT send Your user ID, account information,
name, email, or any other personally identifying information to AI
providers during food photo analysis.
For personalized meal recommendations, We may send
the following data to these providers:
- Your current day's calorie and macronutrient totals
- Your calorie and macro goals
- Your dietary preferences and restrictions (e.g., vegetarian, gluten-free)
- Your timezone
This data is used solely to generate personalized food suggestions
and is not stored by AI providers beyond their standard processing
retention periods.
AI Provider Data Retention: Our third-party AI providers
(OpenAI, Google) may temporarily retain submitted data for up to 30 days
for abuse monitoring and safety filtering, after which it is automatically
deleted. Per their API terms, Your data is NOT used to train their AI models.
This retention is governed by each provider's privacy policy linked above.
BulkMode AI Improvement: Currently, We do not retain
food photos after processing—only the nutritional analysis results are
stored. We reserve the right to retain anonymized, de-identified versions
of food photos in the future to improve Our own AI food recognition
technology. If implemented, photos would be stripped of all identifying
information (user IDs, timestamps, location data) before being added to
training datasets and could not be linked back to You or Your Account.
We will update Our App Store privacy labels if We begin retaining photos.
We may change AI providers at any time to improve accuracy and service
quality, and will update this policy accordingly.
Data Processing Agreements
We have executed Data Processing Agreements (DPAs) with Our primary
sub-processors as required by GDPR, including Supabase (database
hosting), RevenueCat (subscription management), and PostHog
(analytics). These agreements ensure that Our service providers
process Your data in compliance with applicable data protection laws.
Important: Only anonymous analytics data is shared
with PostHog. Your Health Data (food logs, weight, photos) is
never sent to analytics services and remains in Your private Account.
Legal Requirements
We may disclose Your information if required by law or in response to
valid legal requests from public authorities.
Business Transfers
If the Company is acquired or merged with another company, Your data
may be transferred. We'll notify You before this happens.
5. Data Security
We implement strong security measures to protect Your information:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Secure authentication with industry-standard hashing
- Regular security assessments and updates
- Access controls limiting who can view data
- Automatic security monitoring and alerts
However, no method of transmission over the internet is 100% secure.
While We strive to protect Your information, We cannot guarantee
absolute security.
Data Breach Notification
If We discover a security breach affecting Your Personal Data, We will:
-
Notify affected users within 72 hours via email (if provided) and/or
in-app notification
- Describe what data was affected and the nature of the breach
- Explain steps We are taking to address and remediate the breach
-
Provide guidance on protective measures You can take (such as
monitoring Your accounts or changing passwords)
-
Report the breach to relevant data protection authorities as required
by applicable law (including GDPR supervisory authorities within 72
hours where required)
6. Your Rights and Choices
You have the following rights regarding Your Personal Data:
-
Access: Request a copy of Your Personal Data
-
Correction: Update or correct inaccurate
information
-
Deletion: Delete Your Account and all associated
data
-
Portability: Export Your data in a machine-readable
format. Your exported data is provided as a ZIP archive containing
JSON files:
profile.json (Your account and profile
information), food_logs.json (all meal entries with
ingredients and nutritional data), and weight_logs.json
(all weight entries). This format can be opened with standard tools
or imported into spreadsheet applications.
-
Opt-out: Disable analytics sharing in Application
settings
How to Delete Your Account
You can delete Your Account at any time:
- Open the Application and go to Profile
- Tap "Account Settings"
- Tap "Delete Account"
- Confirm deletion
Important: Account deletion is immediate and
permanent. When You delete Your Account, all data is removed from
Our active systems immediately. Automated backup systems may retain
encrypted copies for up to 7 days for disaster recovery purposes,
after which all copies are permanently deleted. Your data (food
logs, photos, weight history, achievements, streaks) cannot be
recovered after deletion.
Anonymous Accounts
If You use the Service without signing in (anonymous account), Your
account is authenticated through a secure session stored in Your
Device's keychain. This session typically persists even if You delete
and reinstall the Application, allowing Your data to be restored from
Our servers.
You can delete Your anonymous account and all associated data at any
time using the "Delete Account" option in Account Settings—no sign-in
required.
However, if Your Device's keychain is cleared (e.g., factory reset,
new device, or certain backup restoration methods),
You will permanently lose access to Your anonymous account
and will not be able to recover, export, or request deletion of it.
To ensure You never lose access to Your data, We strongly recommend
signing in with Apple, which allows account recovery on any device.
Orphaned anonymous data will be automatically deleted after 3 years
of inactivity per Our retention policy.
Orphaned Anonymous Account Data
If an anonymous Account becomes inaccessible (e.g., keychain cleared,
device lost without backup), We cannot identify or contact You. Such
orphaned data will be automatically deleted after 3 years of inactivity.
We cannot fulfill data access, correction, or deletion requests
for orphaned anonymous accounts as We have no way to verify
ownership without the original session credentials.
State-Specific Privacy Rights
California Residents (CCPA/CPRA)
If You're a California resident, You have additional rights:
- Right to know what Personal Data is collected and used
- Right to delete Personal Data
-
Right to opt-out of sale of Personal Data (We do not sell Your data)
- Right to non-discrimination for exercising Your rights
Do Not Sell or Share My Personal Information
We do not sell Your Personal Data. We do not share
Your Personal Data for cross-context behavioral advertising. Because
We do not sell or share Personal Data as defined by California law,
there is no need to opt out—but if You have questions, contact Us at
support@bulkmode.app.
Sensitive Personal Information
Under the California Consumer Privacy Act (CCPA) and California
Privacy Rights Act (CPRA), Health Data—including Your weight, food
logs, calorie intake, and nutritional information—is classified as
"Sensitive Personal Information." We collect and process this data
solely to provide the core functionality of the Service (tracking
Your nutrition and progress toward Your weight gain goals). We do
not use Sensitive Personal Information for purposes other than
providing the Service, and We do not sell or share it for advertising
or profiling purposes.
Virginia, Colorado, Connecticut, and Utah Residents
You have similar rights including access, deletion, correction, and
data portability. You can also opt-out of targeted advertising and
profiling (We do not engage in these practices).
Washington and Nevada Residents (Consumer Health Data)
Under the Washington My Health My Data Act and the Nevada Consumer
Health Data Privacy Law, "consumer health data" includes information
related to Your physical health, nutrition, body measurements, and
fitness. The following describes how We handle consumer health data
as defined by these laws:
Categories of Consumer Health Data We Collect:
- Body metrics (weight, height, body fat range, date of birth, gender)
- Nutrition data (food logs, calorie and macronutrient intake, dietary preferences)
- Fitness-related inputs (exercise frequency, lifting experience, NEAT level)
- Weight history and recent weight trend
- Metabolism Intelligence System outputs (TDEE estimates, calorie targets)
- Food photos (processed in real-time for AI analysis, then immediately discarded)
Purpose: We collect this data solely to provide
personalized nutrition tracking, calorie target calculations, and
progress insights through the Service.
Processors: Consumer health data is processed by
Supabase (cloud hosting), OpenAI and Google Gemini (AI food analysis
— photos only, immediately discarded), and stored locally on Your
Device. RevenueCat and PostHog do not receive consumer health
data.
Your Rights: You may access, correct, or delete
Your consumer health data at any time through the Application
(Profile → Account Settings → Delete Account) or by contacting Us
at support@bulkmode.app.
Appeals: If We deny a deletion or access request,
You may appeal by emailing
support@bulkmode.app with
the subject line "Consumer Health Data Appeal." If You are
unsatisfied with the outcome, You may contact the
Washington Attorney General or the
Nevada Attorney General.
European Union Residents (GDPR)
If You're in the EU/EEA, You have rights under GDPR including all the
above, plus the right to lodge a complaint with Your local data
protection authority.
Legal Basis for Processing (GDPR)
For users in the European Union, European Economic Area, or United
Kingdom, We process Your data under the following legal bases:
-
Personal Data: Performance of contract (to provide
the Service You requested) and legitimate interests (to improve and
secure the Service)
-
Health Data: Your explicit consent, which You
provide through Our GDPR consent screen before any health data is
collected (GDPR Article 9(2)(a)). This includes Your weight, food
logs, nutritional data, and body metrics.
-
Analytics Data: Legitimate interests (data is
fully anonymized and aggregated, containing no personal information)
You may withdraw consent at any time by deleting Your Account.
However, withdrawal of consent does not affect the lawfulness of
processing based on consent before its withdrawal. Withdrawing consent
will prevent Us from providing the Service to You.
Important: Due to the nature of the Service,
withdrawing consent for health data processing requires Account
deletion, as the Service cannot function without processing this data.
The core purpose of the Application is to track and analyze Your
nutrition and health metrics—without consent to process this
information, We cannot provide any meaningful functionality.
When You provide consent, We record the date and time of Your consent
for Our compliance records.
To exercise these rights, contact Us at
support@bulkmode.app. We'll
respond within 30 days.
7. Data Retention
We retain Your data only as long as necessary:
-
Account data: Until You delete Your Account or
after 3 years of inactivity
-
Health Data: Until Account deletion, plus up to 7
days for disaster recovery backups
-
Anonymous analytics: 1 year (automatically deleted
via PostHog)
-
Support messages: Up to 3 years for quality
assurance
-
Food photos: Currently processed in real-time by
AI and immediately discarded—only nutritional results are stored.
We reserve the right to retain anonymized, de-identified photos
for AI improvement in the future; if implemented, such photos
would not be linked to Your identity.
-
Authentication logs: Security-related logs
(login attempts, session data) are retained for up to 90 days for
fraud prevention and security monitoring, then automatically deleted.
-
Streak repair history: Retained for the lifetime
of Your Account to maintain accurate streak records and prevent
abuse of the repair feature.
-
Daily usage quota data: Retained for 30 days for
rate limiting and quota enforcement, then automatically deleted.
Account Inactivity
Accounts that have been inactive for 3 years are automatically
deleted. An Account is considered "inactive" if there has been no
activity for 3 years, including:
- Logging in to the Application
- Logging any food or weight entries
- Modifying Account settings or profile information
To prevent deletion, simply log in to Your Account before the 3-year
inactivity period expires. We recommend exporting Your data
periodically if You anticipate extended periods of non-use.
8. Analytics and Performance Monitoring
Privacy-First Analytics
The Service uses PostHog, an analytics service
configured for anonymous usage, to understand how people use the
Application. This helps Us fix bugs and improve features.
What We Collect (Anonymous)
All analytics data is completely anonymous and cannot be linked to
Your identity:
-
App usage: Which screens You view, tab changes,
and navigation patterns
-
App lifecycle: App launches, foreground events,
and session duration
-
Onboarding funnel: Which onboarding steps You
start, complete, or abandon (no specific answers recorded)
-
Authentication events: Sign-up and login attempts
and outcomes (success/failure, no credentials)
-
Subscription events: Paywall views, purchase
outcomes, trial starts (no exact prices or payment details)
What We DON'T Collect
-
Your identity: No names, emails, phone numbers, or
user IDs
-
Your Health Data: No specific food names, exact
calories, exact weights, or meal details
-
Your location: No GPS coordinates or location
tracking
-
Your payment details: No credit card numbers or
exact prices
-
Your photos: No images or photo content
-
Exact timestamps: All metrics are bucketed (e.g.,
"0-5 seconds") to prevent tracking
Opting Out of Analytics
You can disable anonymous analytics collection at any time via
Settings → Privacy & Data → Share Analytics toggle in
the Application. When disabled, no Usage Data is sent to Our analytics
provider.
PostHog Details
PostHog is configured for anonymous, privacy-respecting analytics:
- Stores data in the United States (AWS us-east-1, Virginia)
-
No person profiles are created — the service is configured with
person profiles disabled, so no individual user profiles exist
-
IP addresses are discarded at ingestion — the server-side
"Discard client IP data" setting ensures IP addresses are not
stored
-
Uses anonymous identifiers, not personal identifiers — these
identifiers cannot be linked to Your name, email, or identity
- Automatically deletes all data after 1 year
-
Privacy policy:
posthog.com/privacy
Note: We never use analytics for advertising,
cross-app tracking, or selling data. Analytics is solely for improving
Your Service experience.
9. International Data Transfers
Your data may be processed in countries other than Your own. When We
transfer data internationally, We implement appropriate safeguards to
protect it in accordance with this policy and applicable laws.
Data Storage Locations
-
Supabase (Primary Database): Your Account and
Health Data is stored on servers in the United States (AWS
us-east-2, Ohio region)
-
PostHog (Analytics): Anonymous analytics data is
stored in the United States (AWS us-east-1, Virginia)
-
AI Processing: Food photos are processed by OpenAI
(United States) and Google Gemini (United States) but are not
permanently stored by these providers beyond their standard
processing retention periods (up to 30 days for abuse monitoring)
-
RevenueCat (Subscriptions): Subscription data is
processed in the United States
-
Apple (Authentication & Payments): Sign in with
Apple and App Store purchases are processed according to Apple's
data practices
-
Google (Authentication): Sign in with Google is
processed according to
Google's Privacy Policy
International Transfer Safeguards
For users in the European Union, European Economic Area, or United
Kingdom, international data transfers to the United States rely on
Standard Contractual Clauses (SCCs) approved by the European
Commission, as well as supplementary security measures including
encryption in transit and at rest.
10. Children's Privacy
COPPA Compliance: We comply with the Children's
Online Privacy Protection Act (COPPA). The Service is not intended
for children under 13 years of age. We do not knowingly collect
Personal Data from children under 13. If We become aware that We
have collected Personal Data from a child under 13, We will delete
that information promptly.
If You believe a child under 13 has provided Us with Personal Data,
please contact Us at
support@bulkmode.app.
Users Ages 13-17
If You are between 13 and 17 years old, We strongly recommend parental
or guardian supervision when using the Service. Consult with Your
parents, guardians, or healthcare professionals before starting any
diet or nutrition program.
Important for Young Users: The Service is an
educational nutrition tracking tool, not medical advice. If You are
under 18, You should talk to Your parents or guardians and consult a
healthcare professional before starting any diet. Stop using the
Service if it makes You feel anxious or unhealthy about food.
Eating Disorder Resources: If You or someone You know
is struggling with an eating disorder, please contact the National
Eating Disorders Association (NEDA) Helpline at 1-800-931-2237 or text
"NEDA" to 741741.
11. Changes to This Privacy Policy
We may update this Privacy Policy occasionally to reflect changes in
Our practices or for legal reasons.
When We make changes, We will:
- Update the "Last updated" date at the top
- Notify You of significant changes through the Application or by email
- Give You the opportunity to review the updated policy
Your continued use of the Service after changes indicates Your
acceptance of the updated policy.
12. App Store Privacy Information
Our iOS App Store listing includes a Privacy Nutrition Label that
describes the data We collect and how We use it. This label is
designed to help You understand Our data practices at a glance
before downloading the Application.
We keep Our App Store privacy label accurate and up-to-date. If
Our data practices change (for example, if We begin retaining
food photos for AI improvement), We will update both this Privacy
Policy and Our App Store privacy label accordingly.
The privacy label reflects that We:
-
Do NOT track You across other companies' apps
and websites
-
Do NOT use the Apple Advertising Identifier (IDFA)
-
Collect Health & Fitness data (weight, nutrition)
linked to Your Account
-
Collect identifiers (user ID, device ID) for
Account functionality
-
Collect usage data (anonymized) for analytics