Privacy Policy
Last updated: July 24, 2026
Porsi is a food diary that estimates calories from a photo. It is built around a simple principle: your diary stays on your device, and a photo leaves it only when you ask for a scan and have agreed to it.
Who we are
Porsi is published by an individual developer. There is no account and no sign-in. We do not run a database of users and we cannot look up "your data" by name or email - we do not have either.
Contact: vika.abr71@gmail.com
What data we process and where it lives
Your diary and profile - on device only
- Your profile (sex, age, height, weight, goal and pace), your meals, and your weigh-ins are stored only on your device, in an encrypted database (SQLite3MultipleCiphers; the encryption key is held in the device Keychain).
- This data is never uploaded to us. We have no copy of your diary and cannot read it. It may be included in your own device backup (for example iCloud Backup), which is under your control and which we cannot read either.
Photo scans - only with your consent
- Before the first photo scan, Porsi asks for your explicit consent and names every recipient. Without that consent, photo scanning stays off - manual entry and barcode lookup keep working.
- When you scan a meal, the photo is sent to the Porsi server, which passes it to Google's Gemini model through our API providers (kie.ai; if it is unavailable, OpenRouter) to recognise the dish and estimate the calories.
- The Porsi server does not keep your photo after the analysis. It is held in memory for the request only and is not written to disk.
- The server does keep two things: a SHA-256 hash of the image together with the text result of the analysis (so that re-scanning the same photo is instant and does not use up a free scan), and an anonymous device identifier with a daily scan counter (so the free limit of 3 scans a day can work). The hash cannot be turned back into your photo.
- Along with the photo, the app sends only your interface language and that anonymous device identifier (on iOS: the identifier for vendor, which resets once you remove all of this developer's apps from your device). No name, no email, no account is attached - Porsi has none.
- You can withdraw consent at any time in Settings → Photo analysis by AI.
Barcode lookup - product code only
- When you scan a barcode, the numeric product code is sent to Open Food Facts, an independent open food database, to fetch nutrition data. Nothing about you is sent with it.
Apple Health - write only, and only if you turn it on
- If you enable Health sync, Porsi writes what you log into Apple Health: the calories, the macros, the name you gave the meal, and your weigh-ins.
- Porsi never reads your Health data, and Health data is never used for advertising or marketing.
- You can stop the writing at any time with the toggle in Porsi's settings. The Health permission itself is managed in the Health app.
Subscriptions
- Payment is handled by Apple. We never see your card or billing details.
- Subscription status is managed through RevenueCat, which receives an anonymous subscriber identifier and the App Store receipt so the app knows whether Pro is active.
Diagnostics - no diary content, no photos
- Crash and performance reports: we use Sentry to receive anonymous crash and performance diagnostics (app version, device model, OS version) so we can fix stability problems.
- Product analytics: we use PostHog to see which parts of the app are used - for example that a scan started or a meal was logged. Events never contain your photos, dish names, diary entries, weight or profile values. IP-based geolocation is disabled.
How your data is used
- Diary and profile: to run the app's core functions on your device - your daily target, your ring, your trend.
- Photos: solely to return one calorie estimate for that meal.
- Device identifier: solely to enforce the free daily scan limit and to prevent abuse of the scanning service.
- Diagnostics: solely to keep the app stable and to improve it.
We do not sell your data, we do not show ads, and we do not use your photos or health data for advertising.
Your controls
- Photo analysis: turn it on or off at any time in Settings → Photo analysis by AI.
- Delete everything: deleting the app from your device removes the encrypted diary with it. The scan counter kept on the server holds nothing but that anonymous device identifier, a date and a number; write to us if you want it removed.
- Health: entries Porsi wrote to Apple Health are managed in the Health app.
- Questions or a request: write to vika.abr71@gmail.com.
Legal bases (EEA/UK users)
Where GDPR applies: processing of your diary happens on-device under your control; sending a photo for analysis relies on your explicit consent (which you can withdraw); the daily scan counter and diagnostics rely on our legitimate interest in running a stable service and preventing abuse.
Children
Porsi is not directed to children and is intended for adults.
Not medical advice
Porsi is a food diary, not a medical or diagnostic tool. Calorie targets and estimates are approximations - see Terms of Use.
Changes
We may update this policy. The "Last updated" date above will change when we do.
Contact
Questions about this policy: vika.abr71@gmail.com