Privacy Policy
Effective date: July 22, 2026 · BuonApp is currently in private testing (pre-release). · Recent changes: Jul 22 — softened the minors sentence (a blanket clinical claim became a product statement; the 18+ gate is unchanged); disclosed the on-device coach-conversation resume storage (kept about two hours, cleared automatically); aligned the waitlist retention wording with practice (details kept until the beta programme concludes or you ask us to delete them). Jul 19 — disclosed that profile dietary preferences, allergies and dislikes ride coach/menu/meal-idea requests (the new Food rules feature), with an explicit caution that AI suggestions cannot verify allergens; clarified that every distributed build routes AI requests through the relay; disclosed the planned paid Pro tier; qualified the storage summary bullet (no storage on BuonApp's servers — AI providers retain as per the AI section). Jul 18 — clarified that automatic sync means a private iCloud copy begins building from day one (wording only); described the waitlist confirmation step and the 7-day auto-delete of unconfirmed signups. Jul 17 — precision pass on the AI, Apple Health and wearable sections; storage claims made exact. Jul 16 — added iCloud sync, the AI-features rewrite, and the 18+ minimum age.
BuonApp is a photo-based nutrition tracker. This policy explains what data the app handles and where it goes. The short version: your diary is stored on your device and, whenever iCloud sync is on, your private iCloud — not in any BuonApp account (sync is on automatically for new diaries; one tap turns it off). AI features send only what each request needs to the providers named below; we keep limited technical records to run the service; and we never sell your data or use it for advertising.
Data stored on your device
Everything you create in BuonApp is stored locally on your device — and, whenever the iCloud sync described below is on, in your own iCloud. Those are the only places your diary is stored; what individual AI requests transmit (and for how long Anthropic holds them) is spelled out in the AI section:
- Your profile (age, sex, height, weight, body composition, goals, macro targets)
- Meal logs, including meal photos you take or select
- Weight entries, progress photos, and history
- App settings and subscription state
- Your most recent coach conversation, kept on the device for about two hours so an accidentally closed chat can resume, then cleared automatically (never synced; what coach requests transmit is described in the AI section)
If you add the optional home-screen widget, today’s totals are shared with it inside the app’s own protected container on your device — nothing about the widget leaves your phone.
We operate no accounts. If you delete the app, the data on that device is deleted with it (data you chose to sync to your iCloud stays in your iCloud until you remove it — see the iCloud sync section).
Backups stay yours too. Your diary is included in your iPhone’s normal backup (iCloud or computer — controlled by your Apple settings, stored in your Apple Account, not with us). You can also export everything to a single file from Settings → Backup and restore from it later; that file goes wherever you choose to save it and never passes through us.
Crash diagnostics stay on your phone — unless you choose to send them. If the app crashes, Apple’s MetricKit gives the app a diagnostic report on the next launch. BuonApp never sends these reports anywhere by itself; whether anonymised crash data is separately shared with Apple and developers is governed by your own iOS Analytics settings. The optional “Report a problem” button prepares an email to us with the app’s technical event log and crash reports attached — no meal photos, no body data — and you see that email and its attachments before deciding to send it.
iCloud sync (optional)
When Sync with iCloud is on — automatically for a brand-new diary, or once you enable it on an existing installation (Settings) — your diary — meals including their photos, weigh-ins, daily check-ins, progress photos, achievements and your plan profile — is stored in your own iCloud account, in a private database associated with your Apple Account. BuonApp’s servers and operator never receive, read or store this data — the app itself accesses it only on your device, through the Apple Account signed in there. It never touches our servers; Apple stores it for you under your own iCloud agreement, and synced photos count toward your iCloud storage allowance.
Sync exists so a new or second device can restore your diary. On a fresh install the app checks your iCloud and, if it finds your diary, offers to restore it; on a brand-new diary with iCloud available, sync starts on automatically, so a private iCloud copy begins building from day one — the Settings toggle shows it plainly, and one tap turns it off. Existing installations keep sync off until you enable it.
Removing synced data: Settings → “Remove my data from iCloud” deletes everything BuonApp has stored in your iCloud while leaving the diary on your device untouched. Deleting the app from one device does not delete data already synced to your iCloud — use the in-app control, or iOS Settings → your name → iCloud → Manage Account Storage.
The AI features — photo analysis, refine, menu advisor, and the coach
BuonApp is an AI nutrition tracker — the AI is the point of the app, so this section describes exactly what leaves your phone. Nothing is sent in the background: data travels only at the moment you use an AI feature, and only what that feature needs.
- Meal photo analysis: the photo you snap or pick (and any caption you type) is sent to Anthropic’s Claude API to estimate the dish, portions and nutrition. A photo you never analyze never leaves your device.
- Refine & adjust: the correction text you type (e.g. “oat milk, 30 g whey”) is sent with that meal’s estimate so the numbers can be recalculated.
- Menu advisor: the menu photo is read on your phone (Apple’s on-device text recognition) and normally only the recognized menu text is sent, together with your remaining targets for the day. If a menu is too stylized to read, the app falls back to sending the menu photo itself.
- The coach (chat and voice): your messages are sent together with a summary of your tracking, so the advice can be concrete — your goal and targets, today’s meals and totals, weight, device-estimated burn and your wearable’s daily summary (recovery, strain, calories) if one is connected, daily check-ins, pregnancy/breastfeeding mode if set, and the name you asked the coach to call you, if you set one (clear it any time in Settings → Coach). If you’ve set them in your profile, your dietary preferences, allergies/intolerances and food dislikes are also included in coach, menu-advisor and meal-idea requests, so the AI can take them into account. AI suggestions can be wrong and cannot verify ingredients or cross-contamination — always confirm allergens with the restaurant or the product label (edit or clear them any time in Settings → Diet & allergies). Voice notes use Apple’s speech recognition — depending on your device and language, Apple may process that audio on the device or on Apple’s servers. Only the resulting transcript, never the audio, is sent onward; replies are spoken on your device.
- Meal ideas, the fridge chef and nutrition lookups send the food names or ingredients in question.
- Barcode scans are looked up against Open Food Facts, a public food database — the request contains the barcode number, nothing else.
In every TestFlight and App Store build, all Anthropic-bound requests travel through BuonApp’s relay server, which exists solely to keep API credentials off your device and to prevent abuse. The relay does not store your photos, text, or results — it forwards them and returns the answer. What it does keep, for service health and cost accounting only: an anonymous daily request counter (deleted within 48 hours) and a per-request technical record containing a timestamp, a truncated random device identifier (not your name — the app has no accounts), the AI model used, the request’s token counts, and — for failed requests — the error type. These records contain no photos, no text, no results, and are automatically deleted within 7 days.
Anthropic processes this data as a service provider under its commercial terms and privacy policy. Anthropic ordinarily deletes API inputs and outputs within 30 days; retention can be longer only for its safety and legal obligations, and API inputs are not used to train Anthropic’s models. BuonApp attaches no email address, account ID or other direct identifier — none exist. But be clear-eyed about what a request contains: the tracking and health-related context listed above is personal data in its own right, plus the optional first name or nickname you chose for the coach.
Apple Health (optional)
If you connect Apple Health, BuonApp writes the meals you log (calories, protein, carbohydrates, fat) into the Health app, and reads your weight, body fat and active energy to power the energy balance and weight trend. The exchange of raw Health records happens entirely on your device — raw Health records are never sent to BuonApp’s relay, to Anthropic, or to anyone else, and your Health data is never used for advertising or shared with third parties. The one derived exception: when you explicitly ask the AI coach for advice, the request may include limited daily aggregates computed from those records — such as your device-estimated total burn — as part of the coaching context described in the AI section. You control access at any time in the iOS Health app (Data Access & Devices); revoking it stops the exchange immediately.
Connected wearables (optional)
If you connect a wearable service such as WHOOP, BuonApp requests read-only access to daily summary data — recovery, strain, sleep scores, and calories burned. This data is:
- fetched directly from the provider to your device,
- used to display your stats, adjust your daily nutrition targets and — only when you ask the AI coach for advice — provide the daily summary (recovery, strain, calories) described in the AI section,
- never sold, never used for advertising, never shared beyond that.
You can disconnect at any time in BuonApp Settings, and additionally revoke BuonApp’s access from your wearable provider’s own account settings (e.g., your WHOOP app). Disconnecting stops all data access; wearable data already shown is not retained beyond your device.
The waitlist on this website
If you join the waitlist, your first name, surname and email address are received by our own form endpoint (hosted on Cloudflare, our infrastructure provider). Your signup starts as pending: we email you a confirmation link, and if you don’t tap it within 7 days the pending signup is deleted automatically — it never joins the list. Once confirmed, your details are stored until the beta programme concludes, or until you ask us to delete them - whichever comes first. The confirmation email and our copy of your signup are delivered by Resend, a transactional-email processor acting on our behalf. We use your details for two things only: confirming your signup and telling you when the TestFlight beta opens. No marketing mailing list, no sharing beyond the processors named here, and you can ask us to delete them any time at the address below.
What we don’t do
- No advertising, no ad trackers
- No analytics SDKs in the current release
- No sale of personal data, no cross-service tracking
- No BuonApp account, and no storage of your content on BuonApp's servers (the relay keeps only short-lived anonymous counters and technical usage records — never the content itself); AI providers process and retain request content only as described in the AI section above
Payments
A paid Pro subscription is planned for the public release. Subscriptions are processed entirely by Apple through the App Store. BuonApp never sees your payment details.
Deleting your data
Delete the BuonApp app to delete all locally stored data. If you used iCloud sync, also tap “Remove my data from iCloud” in Settings first (or manage it in iOS Settings → iCloud) — deleting the app alone leaves your iCloud copy in place. For wearable connections, also revoke access in the provider’s account settings. Relay counters expire on their own within 48 hours; relay technical usage records within 7 days. For data sent to Anthropic when you use the AI features, see Anthropic’s privacy policy above. And remember what deletion can’t reach: your iPhone’s existing device backups and any backup files you exported yourself remain until you delete them in Apple’s settings or wherever you saved them.
Children
BuonApp is designed for adults. You must be 18 or older to use it — we built BuonApp for adults and don’t offer it to minors, and the app’s questionnaire enforces an 18+ minimum age.
Changes
We’ll update this page when the policy changes and note the new effective date above. Material changes (for example, if a future version introduces accounts) will be called out in the app — as we did for iCloud sync.
Contact
Questions or requests: [email protected]