Section 01 · The short version
If you remember nothing else
FoodFat helps you scan packaged foods and drinks, read labels with AI, and track calories and diet. To do that it needs an account and it stores your data in the cloud so it follows you across devices. We collect only what the features need, we don't sell your data, and we don't load third-party advertising or cross-app tracking SDKs.
- An account is required to use the app (email, phone number, Google or Apple).
- We never sell, rent or trade your personal data.
- No third-party ad networks and no cross-app advertising trackers.
- You can request deletion of your account and all associated data at any time (see Section 06).
Section 02 · Who we are
The publisher
FoodFat is published by Arju Singh ("we", "us"). The app is distributed as com.arjusingh.fatfood on iOS (App Store) and com.arju.fatfood on Android (Google Play). Privacy questions, data requests and account-deletion requests: connect@arjusingh.com.
Section 03 · The data we handle
What's collected, why, and where it goes
users/ collection.Section 04 · What we deliberately don't do
The list of things we avoid
- No selling or renting of your data. Ever, to anyone.
- No third-party advertising networks. Any promotional cards in the app are our own first-party content, not personalised ad-network inventory.
- No cross-app tracking. We do not use your Advertising ID (IDFA / GAID) or third-party analytics/attribution SDKs to follow you across apps.
- No location. We never request location permission.
- No microphone. Camera is used for scanning; the mic is not.
- No contacts, calendar or health-app data. The only images we read are the label or meal photo you explicitly capture or pick.
Section 05 · Third-party services
Who else processes a slice of the data
Google Firebase · Authentication, Firestore, Cloud Messaging, Cloud Functions
Handles your sign-in, stores your profile, health/diet data, history and subscription status, and delivers push notifications. Subject to Google's privacy policy and Data Processing terms.
Google Gemini · AI label & meal reading
Invoked only when you photograph a label or scan a meal. The image and a fixed prompt are sent through our secure server to Google's Gemini API, which returns the extracted ingredients / nutrition / calorie estimate. Governed by Google's API terms.
In-app subscriptions (App Store · Google Play)
Processes your free trial and the yearly subscription. Google handles all payment details; we only receive a purchase token and your subscription status. Manage or cancel anytime in your App Store (iOS) or Google Play (Android) subscriptions.
Open Food Facts · product database
Public, community-curated database. We send the barcode you scanned and receive the product entry. Open Food Facts logs the lookup anonymously; no account ID is sent.
Section 06 · Your rights and controls
How to see, fix or delete your data
- See it. Open the History and Calorie tabs to view your scans and entries; Settings shows your account and plan.
- Delete a record. Remove individual scans or diary entries in-app; this deletes both the local and cloud copies.
- Manage your subscription. Open your store account (App Store on iOS, Google Play on Android) → Subscriptions to cancel or manage. Cancelling before the trial ends avoids any charge.
- Delete your account & data. Email connect@arjusingh.com from the address/number on file, subject "FoodFat · Delete my account". We remove your user document, health/diet profile, history and push token within 30 days. (Records the app store keeps for purchase/tax history are retained per its policy.)
- GDPR / CCPA. Residents of the EU, UK and California have the right to access, correct, port and delete their data. We honour these requests free of charge.
- Children. FoodFat is not directed at children under 13 (under 16 in the EU). If you believe a child has given us data, email us and we'll delete it.
Section 07 · Permissions, on each platform
What the OS dialogs really mean
Camera
Used to scan a barcode or photograph a label / meal. Barcode frames stay on device; a label or meal photo is sent for AI reading only when you take it.
Photo library (optional)
Requested only when you choose "Pick from gallery" instead of the camera. We read the one image you select; we never browse your library.
Notifications (optional)
Requested so we can send you alerts and updates. Decline it and the app works normally, minus notifications.
Internet
Standard. Used to reach Firebase, our AI server, the app store and Open Food Facts over HTTPS.
Section 08 · Security
What protects the data
Firestore access is gated by the rules in firestore.rules: each user can only read/write their own documents; only members of the admins/ collection can read aggregate data. Sensitive local values are stored using the OS's secure storage (Keychain on iOS, encrypted preferences on Android), and all network calls are over HTTPS / TLS 1.2+.
No system is perfectly secure. If you believe you've found a vulnerability, email connect@arjusingh.com.
Section 09 · International transfers
Where the data physically sits
Firebase and Google data are stored in Google's US multi-region by default. If you access the app from the EU / UK, your data is transferred to the US under the EU-US Data Privacy Framework and Google's Standard Contractual Clauses.
Section 10 · Changes to this policy
What happens when this page changes
If we change how the app handles data in any material way, we'll update the "Last updated" date at the top and, where appropriate, surface an in-app notice. We won't silently broaden what we collect.
Section 11 · Contact
Reach a human
Privacy questions, data requests, account deletion, security issues, GDPR / CCPA invocations — the same inbox:
connect@arjusingh.com
We try to reply within 7 days. Please mention "FoodFat · Privacy" in the subject.