Privacy policy
In plain words
- What you enter in the app (meals, drinks, supplements, weight, body composition, fasts, dietary profile, symptom diary, notes) stays on your iPhone. There is no account, and your diary never reaches our server, so we never see your data.
- The app goes online only when you start it. When you scan a barcode or search for a product, the barcode or the words you typed go to Open Food Facts, a French non-profit food database. When you import a recipe from a link, your phone downloads that page directly. Like any internet request, the database or the recipe site can see your IP address. Apart from this, only AI logging sends data, if you turn it on.
- AI logging (beta, off by default): if you turn it on in Settings and log a meal with a photo or a sentence, the app sends only that one photo (downscaled, without location or other metadata) or the sentence, and the meal slot, to our server, which recognises the foods with Cloudflare's AI service. It sends no name, account, weight or other health data; only a random, anonymous device token to count the daily limit. The photo and the text are not stored. Nothing is added to your diary until you confirm it.
- If you allow it, the app reads your weight and step count from Apple Health and writes the nutrition, water and caffeine you log there. This data also stays on your phone, and we never use it for advertising.
- If your iPhone's iCloud Backup is on, iOS backs up Leanward's data store to your own iCloud account. You switch that on or off, and Apple runs it. The app's automatic backups never go to iCloud; only an export you make yourself can.
- No ads, no tracking, no analytics, no selling of data, no profiling. The website uses no cookies.
- The app is for adults aged 18 and over.
- You can delete everything in the app, automatic backups included. Before it does, the app offers to export your data in case you want to keep it.
- TestFlight beta: the test version does not yet include the Apple Health connection, recipe import, label photos, reminders, fasting, the symptom diary or dietary profiles. In it, the only data that leaves the phone is the Open Food Facts lookup and, if you turn it on, AI logging. What this policy says about those features applies once they ship.
1. Who is responsible for your data
The controller is Leanward's developer:
Nimród Pöőr, a private individual (developer name: RustySleet)
Budapest, Hungary
E-mail: leanward.app@gmail.com
We have not appointed a data protection officer, as the law does not require one for this kind of activity. Send any privacy question to the e-mail address above.
This policy follows the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Hungary's Act CXII of 2011 on informational self-determination (Infotv.).
2. What data, and where it is
Leanward works without an account and has no server of its own. Your iPhone processes the data; we do not receive it.
| Data | Where it is stored | Does it leave the phone? |
|---|---|---|
| Profile: first name or nickname (optional), sex, date of birth, height, activity level, when your day starts, macro preferences | In the app's store on the phone | Only in your own device backup or an export you make (see below) |
| Food diary: foods and drinks (alcohol included), amounts, times, nutrition values, your own foods and recipes, water, supplements and their doses | Same | Same |
| Body: weight and the body composition values your scale measures (body fat, muscle, bone, water, visceral fat, BMR and so on), the calculated trend | Same | Same |
| Goals and calculations: goal direction, goal weight, pace, estimated energy expenditure, calorie and macro targets | Same | Same |
| Fasting: fasts and fasting schedule. Training (the training log comes in a later version; until then data can only arrive here from a restored backup): workouts, exercises, sets, weights | Same | Same |
| Day notes: free text, tags, mood and energy level | Same | Same |
| Dietary preferences (if you set them): vegetarian, vegan, lactose-free, gluten-free; whether calm mode is on | Same | Same |
| Symptom diary (if you turn it on): only what you record, such as abdominal pain, bloating, stools, fatigue, a note and the time. The app does not score, analyse or judge it | Same | Same |
| Imported recipes: name, servings, ingredients, the source page's address and site name | Same | Same |
| Data read from Apple Health (if you allow it): weight, step count | In the app's store on the phone | Only in your own device backup or an export you make |
| Profile photo, if you choose one: only the picture you pick, cropped square and scaled to at most 512 pixels | Same | Same |
| Automatic backups (a full copy of the above) | Only on the phone: Files › On My iPhone › Leanward › Backups | No; they are not in iCloud Backup either |
| Barcode and search words | Not stored; a product you find is saved as a food in your diary | Yes: sent to Open Food Facts (sections 4 and 5) |
| Technical data sent to Open Food Facts: IP address, time, Leanward version and the phone's language setting | Not stored | Yes: part of every internet request |
| Camera image while scanning | Nowhere; frames are not saved | No |
| Settings (units, backup status) | On the phone | Only in the device backup |
Device backup: if your iPhone backs up to iCloud (or to a computer), iOS includes the app's data store and settings in that backup. This is Apple's service, governed by the terms of your Apple account. The app's automatic backups are excluded from the device backup, so they never reach iCloud.
Export: in Settings › Backup and restore you can export all your data to one file and save or send it wherever and to whomever you choose (iCloud Drive, AirDrop, e-mail and so on). The app never sends this file anywhere on its own.
Camera and photos: the camera is used to read barcodes and to photograph a nutrition label. The phone reads the label without going online; the photo is not kept after reading, only the values you confirm. For a profile photo, Apple's system photo picker opens, so the app gets no access to your photo library and sees only the picture you pick. The app asks you first.
Notifications: the app sends reminders (for example for a fast or a weigh-in) only if you turn them on, and asks for permission only then. The phone schedules them; nothing is pushed from a server.
Apple Health (HealthKit): only if you turn it on in Settings and approve iOS's permission request. The app reads your weight (so your scale's readings need no typing) and your step count (to show on Today), and writes the energy, protein, carbohydrate, fat, fibre, sugar, sodium, water and caffeine you log, so other apps can use them. Health data moves between Apple Health and the app on your phone; it does not leave the phone because of the app, never reaches us, and is never used for advertising, marketing or data mining. You can withdraw the permissions at any time in the Health app or in Settings.
Bluetooth: Leanward does not connect to Bluetooth devices.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Running the app on your phone: logging, trend, calorie and macro targets, fasting and training records | The app data in section 2 | Providing the service you ask for (GDPR Art. 6(1)(b)); for health data, your explicit consent (Art. 9(2)(a)), see section 4 |
| Reading weight and step count from Apple Health | Weight, step count | Explicit consent (Art. 9(2)(a)), given by turning the feature on and in iOS's permission request; can be withdrawn at any time |
| Writing the nutrition, water and caffeine you log to Apple Health | Energy, protein, carbohydrate, fat, fibre, sugar, sodium, water, caffeine | Explicit consent (Art. 9(2)(a)), as above |
| Importing a recipe from a link you give | The link, IP address, technical data (to the recipe site) | Providing the service you ask for by giving the link (Art. 6(1)(b)) |
| Finding a product by barcode or name | Barcode or search words, technical data | Providing the service you ask for by scanning or searching (Art. 6(1)(b)) |
| AI logging from a photo or a sentence (beta) | The photo or the sentence, the meal slot; for a correction, the correcting sentence and the names and grams of the foods recognised before; anonymous device token, technical data | Explicit consent (Art. 6(1)(a), Art. 9(2)(a)), given with the AI logging (beta) switch in Settings; you can turn it off at any time |
| Profile photo | The picture you pick | Consent, given in the screen before the picker (Art. 6(1)(a)); you can switch to a generated figure or initials at any time |
| Protection against data loss: a daily backup and one before every risky operation | All app data | Providing the service (Art. 6(1)(b)); for health data, the consent in section 4 |
| Export and restore, when you ask | All app data | Providing the service and your right to data portability (Art. 6(1)(b), Art. 20) |
| Answering your e-mails and requests to exercise your rights | E-mail address, name, message content | Legal obligation to handle requests (Art. 6(1)(c), Art. 12); for other e-mail, our legitimate interest in replying (Art. 6(1)(f)) |
| Serving the website securely | IP address, time, browser data in the host's logs | Legitimate interest in running and protecting the website (Art. 6(1)(f)) |
The app makes no automated decision about you that has legal or similarly significant effects (GDPR Art. 22). The calorie target is a calculated suggestion that you accept, change or ignore.
4. Health data
Weight, body composition, food, alcohol, supplement, fasting and training data, step count, your dietary preferences (such as lactose-free or gluten-free), your symptom diary and your day notes may count as health data under the GDPR, which gets special protection (Art. 9).
The app processes this data only on the basis of your explicit consent, which you give during the app's first setup, before you enter any of it. You can withdraw it at any time: delete the data in the app (Settings › Delete all data) or delete the app. Withdrawal does not affect the lawfulness of earlier processing.
You consent separately to the Apple Health connection: you turn it on in Settings and choose in iOS's permission request what the app may read and write. You can withdraw this at any time.
Your health data does not leave your phone, except in your own device backup, in exports you make and in what we write to Apple Health (where Apple manages it, under your settings).
5. Who receives data
We use a processor only for AI logging (Cloudflare, below), and we sell data to no one. Data reaches others only in these cases:
- Open Food Facts (Open Food Facts association, 21 rue des Iles, 94100 Saint-Maur-des-Fossés, France; servers run by Fondation Free and OVH in France). It receives the barcode or search words and the technical data, to find the product. It handles its own logs as an independent controller under its own privacy policy. It does not receive your health data, your name or your diary.
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA), as our processor, if you use AI logging. Our server (
leanward-api, running on Cloudflare Workers) receives the photo or the sentence and has the Meta Llama 3.2 Vision model on Cloudflare Workers AI recognise the foods and estimate grams. Cloudflare does not use the submitted content to train models and does not share it. We handle the photo and the text only in memory while the request runs: they are neither stored nor logged. We keep only daily counts, keyed by a SHA-256 hash of the device token, in a database under EU jurisdiction. We use no other AI provider (such as OpenRouter or Google Gemini) at present; we will update this policy before switching one on. - Apple, if you use iCloud Backup or iCloud Drive. Apple then stores your data as your own service provider under your agreement with it, not on our behalf. Apple's privacy policy: apple.com/legal/privacy.
- Anyone you send an export or a backup to.
- The website's host (Cloudflare, Inc.), see section 13.
- Apple Health, if you turn it on: the Health app stores what we write on your phone and, if you have turned on Health in iCloud, in your iCloud account under Apple's rules (end-to-end encrypted). That is between you and Apple; it gives us no access.
- Our e-mail provider, if you write to us: your message is stored by the provider of our mailbox.
- The recipe site whose link you import (and wherever its recipe image loads from): your phone requests the page directly from it, so it sees your IP address, the time and the app version. It handles these under its own rules and receives nothing from your diary. The app may match imported ingredients through Open Food Facts search, just like a search you type.
- An authority or court, where the law requires it. The app data is not with us, so at most we could hand over our correspondence.
6. Transfers outside the EU
Open Food Facts operates in France. If you import from a recipe site outside the EU, your request goes there; you choose it with the link.
For AI logging, Cloudflare processes the photo or the sentence in a data centre of its network, which may be outside the EU; the transfer rests on the adequacy decision for the EU–US Data Privacy Framework and Cloudflare's data processing agreement. The daily counts are kept in a database under EU jurisdiction.
If you use iCloud, Apple may store your data outside the EU, for example in the United States. Apple decides this under its agreement with you and protects it under the EU–US Data Privacy Framework and the European Commission's standard contractual clauses.
The website's host, Cloudflare, Inc., is a US company. The log data it receives is transferred on the basis of the adequacy decision for the EU–US Data Privacy Framework, in which Cloudflare participates. If our e-mail provider also operates outside the EU, the same framework or the European Commission's standard contractual clauses apply.
7. How long it is kept, and how to delete it
- App data stays on the phone until you delete it. Delete single entries in the app, or everything with Settings › Delete all data.
- AI logging: the photo and the text are not stored. The daily counts (keyed by the device token's hash) are deleted after 30 days.
- Automatic backups: the app keeps the latest 14 daily backups and the latest 10 made before a risky operation, and deletes older ones itself. They exist only on the phone.
- Apple Health: deleting an entry in the app also deletes what it wrote to Health for that entry. "Delete all data" also deletes everything the app wrote to Health; it never touches data from other sources. Manage the Health app's own data there.
- "Delete all data" deletes all the app's data and all its automatic backups. Before it does, the app offers to export your data; if you decline, no copy remains in the app after the deletion.
- When you delete the app, iOS removes all its data, settings and local backups from the phone.
- iCloud Backup: copies inside earlier device backups remain under Apple's rules. Delete them on the iPhone: Settings › [your name] › iCloud › Manage Storage › Backups.
- Export files are yours and stay wherever you saved them until you delete them.
- Open Food Facts and recipe sites keep their request logs under their own policies.
- E-mail: we keep your messages for at most one year after the matter is closed. Requests to exercise your rights and our replies are kept for five years, the general limitation period, so we can show what we did.
8. Your rights
Under the GDPR you have the right to:
- access (Art. 15): all your data is visible in the app, and the export gives it to you in one file;
- rectification (Art. 16): you can edit every entry and profile detail in the app;
- erasure (Art. 17): see section 7;
- restriction of processing (Art. 18);
- data portability (Art. 20): the export is a machine-readable JSON file;
- object (Art. 21) to processing based on legitimate interest;
- withdraw consent (Art. 7(3)) at any time, without affecting earlier processing.
How to use them: since the app data is with you, you can exercise most rights directly in the app, straight away. For anything else, write to leanward.app@gmail.com. We reply free of charge within one month; for a particularly complex request this can be extended by up to two further months, and we will tell you if so. If in doubt, we may ask you to confirm your identity.
Note: we have no access to the data on your phone, so we cannot hand it over or delete it for you (GDPR Art. 11). The in-app tools do that.
9. Complaints to the authority
If you think we have infringed your data protection rights, please write to us first so we can put it right. You may also complain to the supervisory authority at any time:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), the Hungarian National Authority for Data Protection and Freedom of Information
Office: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Phone: +36 1 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: naih.hu
If you live or work in another EU member state, you may also go to the data protection authority there. You can also take the matter to court; in Hungary you can bring the case before the regional court (törvényszék) where you live or are staying.
10. Children
Leanward is for adults aged 18 and over. Its calculations are for adults, so during setup the app does not accept a date of birth that makes the user younger than 18. We do not knowingly process children's data.
11. What we do not do
- No ads, and no advertising identifier.
- Data from Apple Health is never used for advertising, marketing or data mining, and never shared with anyone.
- No tracking, across apps or websites.
- No analytics, no crash-reporting service, and no third-party code library that collects data.
- We do not sell or pass on data, for money or otherwise.
- We do not build a marketing profile of you or make automated decisions about you.
- No account and no sign-up.
- The website uses no cookies, tracking code or external scripts.
12. Security
- The app's data sits in iOS's sandboxed storage, which other apps cannot reach. iOS encrypts it: after a restart, it cannot be read until the iPhone is first unlocked.
- Every request to Open Food Facts uses an encrypted (HTTPS) connection.
- We have no server that could be broken into and no central database of users' data.
- Automatic backups are excluded from iCloud Backup and exist only on the phone.
- Apple encrypts iCloud Backup. With Advanced Data Protection switched on, it is end-to-end encrypted.
- Export files and local backups are unencrypted JSON files. Treat them like any sensitive document and send them only to people you trust.
- We recommend protecting your phone with a passcode or Face ID.
13. The website
This website is static: it has no forms, cookies, tracking code or external scripts. We serve the typeface (Sora) ourselves, so your browser does not connect to Google either. The site is served by Cloudflare, Inc., which briefly logs IP addresses, times and browser details to deliver requests and fend off abuse, under its own rules. We do not access these logs or use them to identify visitors.
14. Planned features
We plan features that involve new kinds of processing, such as sharing a nutrition-label photo with Open Food Facts or dietary profiles for medical conditions. (Logging meals from a photo or a sentence is already available as a beta; see section 5.) They are not in the app yet. We will update this policy before any of them ships. Any feature that would send data from your phone will be switched on only if you consent to it separately in the app.
15. Changes to this policy
When we change this policy, we update the date at the top of this page. If a change is material, such as new data leaving the phone or a new recipient, we will say so in the app in advance and, where the legal basis is your consent, ask you again.