Effective date: 11 August 2026 · Developer: ShreddedOnion · Contact: privacy@shreddedonion.com
Summary: Food Tracker keeps everything you enter on your device. The developer runs no server, has no user accounts, and never receives your data. There is no analytics, no telemetry and no crash-reporting service in the app. Some data leaves your device only through features you switch on yourself — an online food lookup, an AI photo scan sent to a provider whose key you supply, a backup to a location you choose, or a file you share with your nutritionist — and each of those is described below. On Android and iOS an advertising banner is shown unless you buy its removal.
The app lets you record meals, foods and recipes, body weight, water intake, physical activity, a personal profile (sex, birth date, height, weight, activity level, goals) and any additional profiles you create, weekly meal plans, your pantry (stock and expiry dates), shopping lists, food spending, achievements, health metrics imported from your device's health store, app settings and an internal error log.
All of it is saved exclusively:
This data — including health-related values such as weight, nutrition and activity — is never transmitted to the developer, and there is no server belonging to the developer for it to be transmitted to. It leaves your device only through the optional features in sections 2 to 5, each of which you control and none of which is on by default. Exports and backups are created only when you ask for them and go only where you send them.
You can delete everything at any time by deleting the data files or uninstalling the app. Data in a folder you chose stays in that folder, under your control.
These requests contain no personal data beyond the technical information inherent to any internet request, such as your IP address being visible to the contacted server. Reading a nutrition label with the camera is done entirely on your device and sends nothing.
The app can identify foods from a photo. This feature is disabled until you choose a provider in Options → AI scanner, and it works in one of three ways:
Please note what a photo can contain. You are photographing a plate, but the image may also capture faces, documents, your home or anything else in frame, and it is sent as it is. Review the photo before sending it, and be aware that the receiving provider decides how long it retains it.
API keys you enter are stored in your device's secure keystore where the platform provides one (Android Keystore, iOS Keychain), and in the app's own private settings where it does not. They are never written to your save files, exports or backups, and are never transmitted anywhere except to the provider they belong to.
You can create a backup containing a full copy of your app data — including health-related values. Where it goes is your choice, and the developer never receives it or has any means of reading it:
drive.appdata scope, which gives it no access to the rest of your Drive. The sign-in token is held in your device's secure keystore and you can revoke access at any time from your Google account settings.Automatic backups, if you enable them, run at most once a day and go to the same destination you selected.
The app can export a meal plan or a progress report as a file and share it — through your device's share sheet, or by writing it into a shared folder you have set up. This happens only when you ask for it, once per file. A progress report contains the nutrition, weight and adherence data for the period you select. If the shared folder is synchronised by a cloud service, that service's terms apply to the file, exactly as in section 4. There is no server, no account and no automatic synchronisation between a nutritionist and a client: files move only when a person sends them.
Where your device provides a health store, the app can exchange data with it. This is disabled until you enable it and grant the permissions, and it happens entirely on your device — nothing in this section is transmitted anywhere.
Health data is never shared with the advertising component described in section 7, nor with any analytics or attribution service — none is present in the app. Health data is used only to show you your own information inside the app, and leaves your device only if you yourself put it in a backup or an export, as described in sections 4 and 5.
The mobile versions of the app show a banner provided by Google AdMob. To serve and measure ads, Google and its partners may collect device information such as advertising identifiers, IP address, coarse location derived from it, and ad-interaction data. This collection is governed by Google's Privacy Policy and how Google uses data from partner apps.
The advertising component receives no data you have entered in the app: not your meals, your profile, your weight, your health data or anything derived from them.
The "Remove ads" purchase is processed entirely by Google Play or the Apple App Store. The developer never receives your payment details.
The app is not directed at children under 13 (or the equivalent minimum age in your jurisdiction) and does not knowingly collect data from them.
The developer is not in possession of your data and therefore cannot access, alter or erase it for you: access, rectification and erasure are entirely in your hands within the app, which can export or delete everything it holds. Where you have chosen to send data to a third party — an AI provider (section 3), a cloud storage service (sections 4 and 5), or a person you shared a file with — you exercise your rights directly with them, under their own policies. For anything concerning data processed by Google for advertising, the mechanisms in section 7 apply. For any privacy question you can contact the developer at the address above, and you have the right to lodge a complaint with your data protection authority.
Material changes to this policy will be published at this address and highlighted in the app, which will ask for a new acknowledgement.