The Company is committed to protecting Your privacy. This
Privacy Policy explains how We collect, use, and safeguard
Your information when You use the Service.
By using the Service, You agree to the collection and use of
information in accordance with this Privacy Policy.
TL;DR: BulkMode is designed exclusively
for healthy weight gain—not weight loss. We use
third-party AI services for food photo analysis. We
treat Your Health Data with extra care and do not sell
or share it for advertising purposes. Your nutrition
data stays private in Your Account.
1. Definitions
"Account" means the unique profile created
for You to access the Service.
"Application" means the mobile application
titled "BulkMode," designed exclusively to help users gain
weight in a healthy manner. The Application is not intended
for weight loss, calorie restriction, or maintaining a
caloric deficit.
"Company," "We," "Us," or "Our" means
Simplify Possible LLC, an Illinois limited liability
company, with mailing address 4235 N Mobile Ave, Chicago, IL
60634, United States.
"Device" means any device used to access
the Service.
"Health Data" means information You provide
relating to Your physical characteristics, health,
nutrition, or goals, including weight, height, date of
birth, gender, food logs, calorie targets, and body metrics.
"Personal Data" means information that
identifies or can reasonably be linked to an individual,
including identifiable health information.
"Usage Data" means data collected
automatically through use of the Service, including device
information, activity logs, IP addresses, and analytics
data.
"User Content" means photos, images, text,
food entries, or other inputs You upload or submit through
the Service.
"Website" means bulkmode.app.
"You" means the individual using the
Service or the organization on whose behalf the Service is
used.
Important Health Disclaimer
The Service is NOT medical advice. The
Application is an educational nutrition tracking tool,
NOT a substitute for professional medical advice,
diagnosis, or treatment.
For complete health and safety information—including
metabolism system disclaimers, AI accuracy limitations,
eating disorder resources, and guidance for minors—please
review Our
Health Disclaimer and
Terms of Service.
If You or someone You know is struggling:
Contact the National Eating Disorders Association (NEDA) at
1-800-931-2237 or text "NEDA" to 741741. In crisis, call
988.
2. Information We Collect
Personal Information
When You create an Account or use the Service, We may
collect:
-
Display name and avatar emoji (optional, for
personalization)
-
Sign in with Apple: If You choose to
sign in with Apple, Apple may share Your name and email
address (or a private relay email) with Us, depending on
Your Apple ID settings. We do not store
passwords—authentication is handled entirely by Apple.
-
Sign in with Google: If You choose to
sign in with Google, Google may share Your name and
email address with Us, depending on Your Google Account
settings. We do not store passwords—authentication is
handled entirely by Google.
-
Anonymous accounts: You can use the
Service without signing in or providing contact
information such as Your name or email address.
Anonymous accounts are authenticated through a secure
session stored in Your Device's keychain. Your data
syncs to Our servers and can typically be restored if
You reinstall the Application, but cannot be recovered
if Your keychain is cleared (e.g., new device or factory
reset).
Health and Nutrition Data
When You use the Service's calorie tracking features, You
provide Health Data:
- Food logs and meal entries
- Calorie and macronutrient intake
-
Weight and body metrics (body fat percentage is required
during onboarding to calculate personalized targets)
-
Date of birth — Used to calculate Your age for accurate
calorie and nutritional recommendations. This is
collected during onboarding.
-
Food photos for AI analysis: Photos are
resized and compressed before being sent to Our AI
providers for analysis. These processed images are used
in real-time to identify food items and estimate
nutritional content, then immediately discarded from Our
servers—only the nutritional results are stored in Your
Account. We do not perform facial recognition, biometric
scanning, or any identification of individuals who may
appear in photos.
Thumbnail storage: Compressed,
low-resolution thumbnail previews are stored locally on
Your Device to display Your food log entries. These
thumbnails are deleted when You delete the corresponding
food log entry, Your Account, or the Application.
We reserve the right to retain anonymized, de-identified
versions of food photos to improve Our AI food
recognition technology in the future. If We begin
retaining photos on Our servers, We will update Our App
Store privacy labels accordingly. See Section 4 (AI
Providers) for details on how photos are processed.
- Dietary goals and preferences
-
Target weekly weight gain rate (to personalize Your
calorie recommendations)
-
Hard gainer status (whether You have difficulty gaining
weight)
-
Individual ingredient breakdowns within meals — When Our
AI analyzes Your food photos, We store the name,
quantity, estimated weight, and nutritional values
(calories, protein, carbs, fat) for each identified
ingredient. You can view and edit these breakdowns in
the Application.
-
Streak repair history — If You use the streak repair
feature, We record when repairs were applied and the
streak values before and after repair. This helps
prevent abuse and provides You with accurate streak
records.
-
Any other health information You choose to enter into
the Application
Automatically Collected Information
We automatically collect certain Usage Data:
-
Device information (device type, operating system,
Application version)
-
Device identifier — Apple-assigned vendor identifier
(IDFV) for device-level sync and fraud prevention. This
identifier is NOT the advertising identifier (IDFA) and
cannot be used for cross-app tracking.
-
IP address — Stored by Our authentication provider
(Supabase) in session logs and audit trails for security
and fraud prevention purposes. Retained for up to 90
days per Supabase's data retention policies. IP
addresses are not stored in general application activity
logs.
-
Usage data (features used, time spent, interactions) -
anonymized
-
Timezone information (to display food logs and streaks
in Your local time, and to adjust for timezone changes
when You travel)
-
Daily usage counts — We track how many food photos You
analyze each day to enforce usage quotas and prevent
abuse of Our Service. This includes timestamps of
analysis attempts for rate limiting purposes.
Referral Program Data
If You use a referral code or refer others to the Service,
We store:
- Your unique referral code
-
The relationship between referrer and referee (if
applicable)
- Referral reward status
This data is used solely to grant referral rewards.
Feedback and Preferences
During onboarding, We may collect:
- Your main challenges with nutrition tracking
- Your desired accomplishments and fitness goals
- Your commitment level (on a 1-10 scale)
-
Your confidence rating in achieving Your plan (plan
achievability rating) — A rating You may provide after
Your first day indicating how achievable You feel Your
nutrition plan is
- How You heard about the Service (optional)
-
Previous nutrition or calorie tracking apps You've used
(optional)
You may also optionally provide feature requests in Your
profile settings. This feedback helps Us improve the Service
and is not shared with third parties.
Derived and Aggregated Data
We automatically generate aggregated summaries of Your daily
nutrition data to power features like streak tracking,
achievements, and progress analytics. This includes:
-
Daily totals of calories, protein, carbohydrates, and
fat
-
Goal achievement status (whether You hit Your daily
targets)
-
Meal type distribution (breakfast, lunch, dinner, snacks
logged)
- Food log counts per day
This data is derived from Your food logs and is used solely
to provide You with progress insights and unlock
achievements.
Technical Sync Data
To ensure reliable data synchronization and prevent
duplicate requests, We temporarily store:
-
Device identifier — Used to coordinate
sync operations across Your devices
-
Idempotency keys — Unique request
identifiers stored for up to 24 hours to prevent
duplicate processing of achievement updates and other
operations
-
Migration identifiers — When You
upgrade from an anonymous Account to an authenticated
Account, We track the migration relationship to ensure
Your data transfers correctly and to prevent duplicate
migrations
This technical data is used solely for operational
reliability and is automatically cleaned up after its
retention period.
On-Device Data Storage
To provide offline functionality and a seamless experience,
We store certain data locally on Your Device:
-
Local database: Your profile, food
logs, weight logs, streaks, and achievements are stored
locally using iOS secure storage (SwiftData). This
enables offline access and syncs with Our servers when
You are online.
-
Secure credentials: Authentication
tokens and session data are stored in the iOS Keychain,
which provides hardware-level encryption.
-
Preferences: Your app settings,
notification preferences, and privacy choices are stored
locally on Your Device.
-
Cached data: Subscription status and
certain settings may be cached locally to ensure the app
works correctly even when offline.
This local data remains on Your Device and syncs with Our
servers when connected to the internet. Deleting the
Application from Your Device removes all locally stored
data. To delete Your data from Our servers, use the Account
deletion feature before uninstalling.
Background Data Synchronization
The Application uses an offline-first architecture, meaning
Your data is saved locally first and then synchronized to
Our servers in the background. This ensures You can use the
Application even without internet connectivity. When You
regain connectivity:
-
Your data automatically syncs in the background without
requiring any action from You
-
We use intelligent sync throttling to minimize battery
usage and cellular data consumption
-
If conflicts occur (e.g., You edited data on multiple
devices while offline), Our servers are treated as the
source of truth and the most recent server version is
used
-
Sync operations include unique request identifiers to
prevent duplicate data processing
Push Notifications
Notification Permissions: With Your
consent, We may send push notifications for meal reminders,
streak maintenance, subscription status, and progress
updates. You can disable notifications in iOS Settings at
any time.
If You enable push notifications, Apple provides Us with a
device token to deliver reminders and updates. This token:
-
Is specific to Our Application and cannot be used to
identify You personally or track You across other apps
-
Is used solely to deliver notifications You have opted
into (meal reminders, streak reminders, progress
updates)
-
Is not sold, shared, or used for advertising purposes
-
Can be revoked at any time by disabling notifications in
iOS Settings or in the Application settings
Meal Timing Pattern Learning
To provide personalized meal reminder notifications, the
Application learns from Your meal logging habits:
-
We analyze when You typically log breakfast, lunch,
dinner, and snacks to determine Your personal meal
schedule
-
After sufficient logging history (typically 21+ entries
over 7+ days), We adjust reminder times to match Your
actual patterns
-
Pattern data (median meal times, clustering information)
is stored locally on Your Device and is not shared with
third parties
-
Patterns are re-evaluated periodically to adapt to
changes in Your schedule
-
Reminder times are adjusted within reasonable bounds
(±60 minutes of defaults) to prevent disruptive timing
This feature helps ensure You receive reminders at times
that work for Your lifestyle rather than generic times that
may not fit Your routine.
Biometric Information
Illinois BIPA Compliance: The Service does
NOT collect, capture, purchase, receive through trade, or
otherwise obtain biometric identifiers or biometric
information as defined under the Illinois Biometric
Information Privacy Act (740 ILCS 14/1 et seq.). Our AI food
analysis technology identifies food items in photographs
only and does not perform facial recognition, facial
geometry analysis, fingerprint scanning, voiceprint
analysis, iris scanning, retina scanning, or any other
biometric identification of individuals who may appear in
photographs.
Home Screen Widget
The Service offers iOS Home Screen widgets that display Your
daily calorie progress, macro breakdown, and streak
information at a glance.
Widget Data Sharing
-
Widget data is shared between the main Application and
widget extension using iOS App Groups (a secure,
on-device data sharing mechanism)
-
Data shared with widgets includes: daily calorie totals,
macro totals, calorie goal, current streak count, and
Your top saved foods for quick logging
-
This data never leaves Your Device—it is shared locally
between the Application and widget only
-
Widget data is refreshed when You log food or when iOS
requests an update
Social Sharing Features
The Service may offer features that allow You to share Your
progress on social media platforms, including:
-
Weekly Summary sharing: A shareable
card showing Your weekly statistics (streak, average
calories, achievements unlocked)
What You Control When Sharing
-
Sharing is always initiated by You—We never
automatically post to social media
-
Weight data is opt-in: Your weight
change is NOT included in share cards by default. You
must explicitly choose to include it.
-
Share cards display relative changes (e.g., "+2 lbs this
week") rather than absolute weights
-
You can preview and customize share cards before sharing
Share cards include BulkMode branding and Our website URL.
When You share to external platforms (Instagram, Twitter,
etc.), those platforms' privacy policies govern how the
shared content is handled.
Siri and Voice Commands
The Service supports Siri Shortcuts, allowing You to log
food and check Your progress using voice commands. When You
use Siri with the Application:
-
Voice commands are processed by Apple according to
Apple's privacy practices
-
The Application receives only the interpreted command
(e.g., "log 500 calories"), not Your voice recording
-
Food logged via Siri is treated identically to food
logged manually within the Application
-
You can view and manage Siri Shortcuts in iOS Settings →
Siri & Search → BulkMode
3. How We Use Your Information
We use Your information to:
- Provide and maintain the Service
-
Process User Content through AI to estimate nutritional
information
- Calculate calorie goals and track Your progress
- Manage Your subscription and process payments
- Send important Service updates and support messages
-
Improve the Service through anonymous analytics (see
Section 8 for details)
- Detect and prevent technical issues or abuse
We do NOT use Your data for:
Advertising, selling to third parties, or cross-app
tracking.
Service Improvement
We may use anonymized and aggregated data, including food
photos and meal information, to improve Our AI food
recognition technology. This data is de-identified before
use and is not linked to Your identity. Photos submitted for
analysis may be used for these improvement purposes in an
anonymized form.
Progress Photos: If the Service offers
progress photo features in the future, these photos will
never be used for AI model training. Progress photos are
personal and remain private within Your Account.
We may also integrate with third-party nutrition databases
and update Our analysis methods, data sources, and AI
providers at any time to enhance accuracy and Service
quality.
Automated Decision-Making
Our AI-powered nutritional analysis involves automated
processing of Your food photos to estimate calorie and
macronutrient content. This is automated decision-making as
defined under GDPR Article 22.
Personalized Target Calculations: The
Service uses automated algorithms to calculate Your calorie
and macro targets based on Your profile data (height,
weight, age, gender, activity level, body fat percentage,
exercise frequency, training experience, weight history, and
recent weight trend). These calculations use established
nutrition science formulas with adjustments based on Your
individual characteristics.
Adaptive Learning: Over time, the Service
learns Your actual metabolic rate by analyzing Your food
intake and weight changes. This learned data is blended with
formula-based estimates to provide increasingly personalized
recommendations. You can view and override these
calculations at any time in Your profile settings.
You have the right to:
-
Edit or override: Manually edit any
AI-generated nutritional estimates directly in the
Application
-
Delete: Remove any food logs containing
estimates You disagree with
-
Manual entry: Enter nutritional data
manually instead of using photo analysis
-
Request review: Contact Us to request
human review of how automated decisions affect Your
Account
AI estimates are approximations based on visual analysis and
may vary from actual nutritional values. You are responsible
for verifying nutritional information, especially for
medical dietary requirements. The Service does not make
automated decisions that have legal or similarly significant
effects on You—nutritional estimates are informational tools
only.
4. Information Sharing and Disclosure
We do not sell, trade, or rent Your Personal Data. We only
share data with trusted service providers who help Us
operate the Service:
Service Providers
-
Supabase - Cloud hosting and database
(stores Your Account and Health Data securely)
-
PostHog - Anonymous analytics (no
person profiles, IP addresses discarded; see Section 8
for full details)
-
RevenueCat & Apple App Store -
Subscription and payment processing. RevenueCat helps Us
manage subscriptions across platforms. When You
subscribe or make a purchase, We share the following
data with RevenueCat:
-
Your anonymous user identifier (to link
purchases to Your Account)
-
Purchase receipts and transaction identifiers
from Apple
-
Subscription status (active, expired, trial,
etc.)
- App version and platform information
RevenueCat does NOT receive Your name, email, Health
Data, food logs, or any personally identifiable
information unless You choose to provide it during
support requests. All payment processing is handled
securely by Apple—We never see or store Your credit card
information.
RevenueCat SDK Automatic Collection:
The RevenueCat SDK automatically collects certain device
information to process subscriptions and prevent fraud,
including: device model, operating system version, app
version, locale/language, and approximate location
derived from IP address. This data is collected by
RevenueCat's SDK independently of Our Application code.
See
RevenueCat's Privacy Policy
for complete details on their data practices
-
AI Providers - AI-powered features
including food photo analysis and personalized
recommendations. Our AI features are currently powered
by:
For food photo analysis, We send only
the following minimal data to these providers:
- The compressed food photo image
- Your timezone (for meal timing context)
-
A unique request identifier (idempotency key) to
prevent duplicate processing
We do NOT send Your user ID, account
information, name, email, or any other personally
identifying information to AI providers during food
photo analysis.
For personalized meal recommendations,
We may send the following data to these providers:
-
Your current day's calorie and macronutrient
totals
- Your calorie and macro goals
-
Your dietary preferences and restrictions (e.g.,
vegetarian, gluten-free)
- Your timezone
This data is used solely to generate personalized food
suggestions and is not stored by AI providers beyond
their standard processing retention periods.
AI Provider Data Retention: Our
third-party AI providers (OpenAI, Google) may
temporarily retain submitted data for up to 30 days for
abuse monitoring and safety filtering, after which it is
automatically deleted. Per their API terms, Your data is
NOT used to train their AI models. This retention is
governed by each provider's privacy policy linked above.
BulkMode AI Improvement: Currently, We
do not retain food photos after processing—only the
nutritional analysis results are stored. We reserve the
right to retain anonymized, de-identified versions of
food photos in the future to improve Our own AI food
recognition technology. If implemented, photos would be
stripped of all identifying information (user IDs,
timestamps, location data) before being added to
training datasets and could not be linked back to You or
Your Account. We will update Our App Store privacy
labels if We begin retaining photos.
We may change AI providers at any time to improve
accuracy and service quality, and will update this
policy accordingly.
Data Processing Agreements
We have executed Data Processing Agreements (DPAs) with Our
primary sub-processors as required by GDPR, including
Supabase (database hosting), RevenueCat (subscription
management), and PostHog (analytics). These agreements
ensure that Our service providers process Your data in
compliance with applicable data protection laws.
Important: Only anonymous analytics
data is shared with PostHog. Your Health Data (food
logs, weight, photos) is never sent to analytics
services and remains in Your private Account.
Legal Requirements
We may disclose Your information if required by law or in
response to valid legal requests from public authorities.
Business Transfers
If the Company is acquired or merged with another company,
Your data may be transferred. We'll notify You before this
happens.
5. Data Security
We implement strong security measures to protect Your
information:
-
Encryption of data in transit (HTTPS/TLS) and at rest
-
Secure authentication with industry-standard hashing
- Regular security assessments and updates
- Access controls limiting who can view data
- Automatic security monitoring and alerts
However, no method of transmission over the internet is 100%
secure. While We strive to protect Your information, We
cannot guarantee absolute security.
Data Breach Notification
If We discover a security breach affecting Your Personal
Data, We will:
-
Notify affected users within 72 hours via email (if
provided) and/or in-app notification
-
Describe what data was affected and the nature of the
breach
-
Explain steps We are taking to address and remediate the
breach
-
Provide guidance on protective measures You can take
(such as monitoring Your accounts or changing passwords)
-
Report the breach to relevant data protection
authorities as required by applicable law (including
GDPR supervisory authorities within 72 hours where
required)
6. Your Rights and Choices
You have the following rights regarding Your Personal Data:
-
Access: Request a copy of Your Personal
Data
-
Correction: Update or correct
inaccurate information
-
Deletion: Delete Your Account and all
associated data
-
Portability: Export Your data in a
machine-readable format. Your exported data is provided
as a ZIP archive containing JSON files:
profile.json (Your account and profile
information), food_logs.json (all meal
entries with ingredients and nutritional data), and
weight_logs.json
(all weight entries). This format can be opened with
standard tools or imported into spreadsheet
applications.
-
Opt-out: Disable analytics sharing in
Application settings
How to Delete Your Account
You can delete Your Account at any time:
- Open the Application and go to Profile
- Tap "Account Settings"
- Tap "Delete Account"
- Confirm deletion
Important: Account deletion is
immediate and permanent. When You delete Your Account,
all data is removed from Our active systems immediately.
Automated backup systems may retain encrypted copies for
up to 7 days for disaster recovery purposes, after which
all copies are permanently deleted. Your data (food
logs, photos, weight history, achievements, streaks)
cannot be recovered after deletion.
Anonymous Accounts
If You use the Service without signing in (anonymous
account), Your account is authenticated through a secure
session stored in Your Device's keychain. This session
typically persists even if You delete and reinstall the
Application, allowing Your data to be restored from Our
servers.
You can delete Your anonymous account and all associated
data at any time using the "Delete Account" option in
Account Settings—no sign-in required.
However, if Your Device's keychain is cleared (e.g., factory
reset, new device, or certain backup restoration methods),
You will permanently lose access to Your anonymous
account
and will not be able to recover, export, or request deletion
of it.
To ensure You never lose access to Your data, We strongly
recommend signing in with Apple, which allows account
recovery on any device. Orphaned anonymous data will be
automatically deleted after 3 years of inactivity per Our
retention policy.
Orphaned Anonymous Account Data
If an anonymous Account becomes inaccessible (e.g., keychain
cleared, device lost without backup), We cannot identify or
contact You. Such orphaned data will be automatically
deleted after 3 years of inactivity.
We cannot fulfill data access, correction, or deletion
requests for orphaned anonymous accounts
as We have no way to verify ownership without the original
session credentials.
State-Specific Privacy Rights
California Residents (CCPA/CPRA)
If You're a California resident, You have additional rights:
-
Right to know what Personal Data is collected and used
- Right to delete Personal Data
-
Right to opt-out of sale of Personal Data (We do not
sell Your data)
-
Right to non-discrimination for exercising Your rights
Do Not Sell or Share My Personal Information
We do not sell Your Personal Data. We do
not share Your Personal Data for cross-context behavioral
advertising. Because We do not sell or share Personal Data
as defined by California law, there is no need to opt
out—but if You have questions, contact Us at
support@bulkmode.app.
Sensitive Personal Information
Under the California Consumer Privacy Act (CCPA) and
California Privacy Rights Act (CPRA), Health Data—including
Your weight, food logs, calorie intake, and nutritional
information—is classified as "Sensitive Personal
Information." We collect and process this data solely to
provide the core functionality of the Service (tracking Your
nutrition and progress toward Your weight gain goals). We do
not use Sensitive Personal Information for purposes other
than providing the Service, and We do not sell or share it
for advertising or profiling purposes.
Virginia, Colorado, Connecticut, and Utah Residents
You have similar rights including access, deletion,
correction, and data portability. You can also opt-out of
targeted advertising and profiling (We do not engage in
these practices).
Washington and Nevada Residents (Consumer Health Data)
Under the Washington My Health My Data Act and the Nevada
Consumer Health Data Privacy Law, "consumer health data"
includes information related to Your physical health,
nutrition, body measurements, and fitness. The following
describes how We handle consumer health data as defined by
these laws:
Categories of Consumer Health Data We Collect:
-
Body metrics (weight, height, body fat range, date of
birth, gender)
-
Nutrition data (food logs, calorie and macronutrient
intake, dietary preferences)
-
Fitness-related inputs (exercise frequency, lifting
experience, NEAT level)
- Weight history and recent weight trend
-
Metabolism Intelligence System outputs (TDEE estimates,
calorie targets)
-
Food photos (processed in real-time for AI analysis,
then immediately discarded)
Purpose: We collect this data solely to
provide personalized nutrition tracking, calorie target
calculations, and progress insights through the Service.
Processors: Consumer health data is
processed by Supabase (cloud hosting), OpenAI and Google
Gemini (AI food analysis — photos only, immediately
discarded), and stored locally on Your Device. RevenueCat
and PostHog do not receive consumer health data.
Your Rights: You may access, correct, or
delete Your consumer health data at any time through the
Application (Profile → Account Settings → Delete Account) or
by contacting Us at
support@bulkmode.app.
Appeals: If We deny a deletion or access
request, You may appeal by emailing
support@bulkmode.app
with the subject line "Consumer Health Data Appeal." If You
are unsatisfied with the outcome, You may contact the
Washington Attorney General
or the
Nevada Attorney General.
European Union Residents (GDPR)
If You're in the EU/EEA, You have rights under GDPR
including all the above, plus the right to lodge a complaint
with Your local data protection authority.
Legal Basis for Processing (GDPR)
For users in the European Union, European Economic Area, or
United Kingdom, We process Your data under the following
legal bases:
-
Personal Data: Performance of contract
(to provide the Service You requested) and legitimate
interests (to improve and secure the Service)
-
Health Data: Your explicit consent,
which You provide through Our GDPR consent screen before
any health data is collected (GDPR Article 9(2)(a)).
This includes Your weight, food logs, nutritional data,
and body metrics.
-
Analytics Data: Legitimate interests
(data is fully anonymized and aggregated, containing no
personal information)
You may withdraw consent at any time by deleting Your
Account. However, withdrawal of consent does not affect the
lawfulness of processing based on consent before its
withdrawal. Withdrawing consent will prevent Us from
providing the Service to You.
Important: Due to the nature of the
Service, withdrawing consent for health data processing
requires Account deletion, as the Service cannot function
without processing this data. The core purpose of the
Application is to track and analyze Your nutrition and
health metrics—without consent to process this information,
We cannot provide any meaningful functionality.
When You provide consent, We record the date and time of
Your consent for Our compliance records.
To exercise these rights, contact Us at
support@bulkmode.app. We'll respond within 30 days.
7. Data Retention
We retain Your data only as long as necessary:
-
Account data: Until You delete Your
Account or after 3 years of inactivity
-
Health Data: Until Account deletion,
plus up to 7 days for disaster recovery backups
-
Anonymous analytics: 1 year
(automatically deleted via PostHog)
-
Support messages: Up to 3 years for
quality assurance
-
Food photos: Currently processed in
real-time by AI and immediately discarded—only
nutritional results are stored. We reserve the right to
retain anonymized, de-identified photos for AI
improvement in the future; if implemented, such photos
would not be linked to Your identity.
-
Authentication logs: Security-related
logs (login attempts, session data) are retained for up
to 90 days for fraud prevention and security monitoring,
then automatically deleted.
-
Streak repair history: Retained for the
lifetime of Your Account to maintain accurate streak
records and prevent abuse of the repair feature.
-
Daily usage quota data: Retained for 30
days for rate limiting and quota enforcement, then
automatically deleted.
Account Inactivity
Accounts that have been inactive for 3 years are
automatically deleted. An Account is considered "inactive"
if there has been no activity for 3 years, including:
- Logging in to the Application
- Logging any food or weight entries
- Modifying Account settings or profile information
To prevent deletion, simply log in to Your Account before
the 3-year inactivity period expires. We recommend exporting
Your data periodically if You anticipate extended periods of
non-use.
8. Analytics and Performance Monitoring
Privacy-First Analytics
The Service uses PostHog, an analytics
service configured for anonymous usage, to understand how
people use the Application. This helps Us fix bugs and
improve features.
What We Collect (Anonymous)
All analytics data is completely anonymous and cannot be
linked to Your identity:
-
App usage: Which screens You view, tab
changes, and navigation patterns
-
App lifecycle: App launches, foreground
events, and session duration
-
Onboarding funnel: Which onboarding
steps You start, complete, or abandon (no specific
answers recorded)
-
Authentication events: Sign-up and
login attempts and outcomes (success/failure, no
credentials)
-
Subscription events: Paywall views,
purchase outcomes, trial starts (no exact prices or
payment details)
What We DON'T Collect
-
Your identity: No names, emails, phone
numbers, or user IDs
-
Your Health Data: No specific food
names, exact calories, exact weights, or meal details
-
Your location: No GPS coordinates or
location tracking
-
Your payment details: No credit card
numbers or exact prices
-
Your photos: No images or photo content
-
Exact timestamps: All metrics are
bucketed (e.g., "0-5 seconds") to prevent tracking
Opting Out of Analytics
You can disable anonymous analytics collection at any time
via
Settings → Privacy & Data → Share Analytics
toggle in the Application. When disabled, no Usage Data is
sent to Our analytics provider.
PostHog Details
PostHog is configured for anonymous, privacy-respecting
analytics:
-
Stores data in the United States (AWS us-east-1,
Virginia)
-
No person profiles are created — the service is
configured with person profiles disabled, so no
individual user profiles exist
-
IP addresses are discarded at ingestion — the
server-side "Discard client IP data" setting ensures IP
addresses are not stored
-
Uses anonymous identifiers, not personal identifiers —
these identifiers cannot be linked to Your name, email,
or identity
- Automatically deletes all data after 1 year
-
Privacy policy:
posthog.com/privacy
Note: We never use analytics for
advertising, cross-app tracking, or selling data. Analytics
is solely for improving Your Service experience.
9. International Data Transfers
Your data may be processed in countries other than Your own.
When We transfer data internationally, We implement
appropriate safeguards to protect it in accordance with this
policy and applicable laws.
Data Storage Locations
-
Supabase (Primary Database): Your
Account and Health Data is stored on servers in the
United States (AWS us-east-2, Ohio region)
-
PostHog (Analytics): Anonymous
analytics data is stored in the United States (AWS
us-east-1, Virginia)
-
AI Processing: Food photos are
processed by OpenAI (United States) and Google Gemini
(United States) but are not permanently stored by these
providers beyond their standard processing retention
periods (up to 30 days for abuse monitoring)
-
RevenueCat (Subscriptions):
Subscription data is processed in the United States
-
Apple (Authentication & Payments): Sign
in with Apple and App Store purchases are processed
according to Apple's data practices
-
Google (Authentication): Sign in with
Google is processed according to
Google's Privacy Policy
International Transfer Safeguards
For users in the European Union, European Economic Area, or
United Kingdom, international data transfers to the United
States rely on Standard Contractual Clauses (SCCs) approved
by the European Commission, as well as supplementary
security measures including encryption in transit and at
rest.
10. Children's Privacy
COPPA Compliance: We comply with the
Children's Online Privacy Protection Act (COPPA). The
Service is not intended for children under 13 years of age.
We do not knowingly collect Personal Data from children
under 13. If We become aware that We have collected Personal
Data from a child under 13, We will delete that information
promptly.
If You believe a child under 13 has provided Us with
Personal Data, please contact Us at
support@bulkmode.app.
Users Ages 13-17
If You are between 13 and 17 years old, We strongly
recommend parental or guardian supervision when using the
Service. Consult with Your parents, guardians, or healthcare
professionals before starting any diet or nutrition program.
Important for Young Users: The Service
is an educational nutrition tracking tool, not medical
advice. If You are under 18, You should talk to Your
parents or guardians and consult a healthcare
professional before starting any diet. Stop using the
Service if it makes You feel anxious or unhealthy about
food.
Eating Disorder Resources: If You or
someone You know is struggling with an eating disorder,
please contact the National Eating Disorders Association
(NEDA) Helpline at 1-800-931-2237 or text "NEDA" to 741741.
11. Changes to This Privacy Policy
We may update this Privacy Policy occasionally to reflect
changes in Our practices or for legal reasons.
When We make changes, We will:
- Update the "Last updated" date at the top
-
Notify You of significant changes through the
Application or by email
-
Give You the opportunity to review the updated policy
Your continued use of the Service after changes indicates
Your acceptance of the updated policy.
12. App Store Privacy Information
Our iOS App Store listing includes a Privacy Nutrition Label
that describes the data We collect and how We use it. This
label is designed to help You understand Our data practices
at a glance before downloading the Application.
We keep Our App Store privacy label accurate and up-to-date.
If Our data practices change (for example, if We begin
retaining food photos for AI improvement), We will update
both this Privacy Policy and Our App Store privacy label
accordingly.
The privacy label reflects that We:
-
Do NOT track You across other
companies' apps and websites
-
Do NOT use the Apple Advertising
Identifier (IDFA)
-
Collect Health & Fitness data (weight,
nutrition) linked to Your Account
-
Collect identifiers (user ID, device
ID) for Account functionality
-
Collect usage data (anonymized) for
analytics