Privacy Policy
Last updated: October 4, 2026 (applies to Protein Diary 1.0.0)
The short version: Protein Diary stores your food, weight, medication and side-effect entries locally. No account is required and the app has no diary cloud-sync service. You control exports and sharing. Optional crash reporting, enabled purchase services, device backups and messages you send us are described below.
1. Who we are
Protein Diary ("we," "our," or "us") is a personal food, weight, and medication diary. It launches on iOS first; this policy also covers the Android version when it is released. This policy explains what data the app handles, where it lives, and what, if anything, leaves your device. Questions are welcome at [email protected].
2. What the app stores on your device
When you use Protein Diary, the app stores the following in a local database on your device:
- Food and nutrition entries: what you log, including protein in grams and hydration
- Weight entries: weights and dates you record
- Medication shot logs: medication name, dose (recorded as the text you typed), injection site, and date, exactly as you enter them
- Side-effect tags: the day-level tags you choose
- An optional onboarding answer about whether you use a GLP-1 medication (you can answer "prefer not to say"), used only to personalize defaults
- Goals, preferences, and settings
Diary logging and local reports work offline. The app does not automatically upload your diary to us. Exports, device backups and information you send to support can contain your logged data; purchase, restore and entitlement checks use network services when purchases are enabled.
JSON backups include your diary entries, custom foods, weights, logged shots (medication name and dose exactly as you typed them), side-effect tags, goals and most settings. A backup can contain medication information. Backups do not include your optional GLP-1 profile answer, crash reporting choice, notification permission or subscription state. Reports may also contain sensitive entries. Check exported files before sharing them.
3. Exports, backups and support
The app does not use advertising SDKs or send diary entries for behavioral analytics. In addition to the diagnostic and purchase services below, information can leave your device through:
- Your exports. You can export your diary as a JSON backup file or generate a PDF report. You choose when to create these and who receives them. (We recommend sharing PDF reports only with people you trust, such as your healthcare provider.)
- Your device's own backups. If you have iCloud Backup (iOS) or Google Backup (Android) enabled, your device may include the app's data in its backups. That is controlled by your device settings, not by the app, and the data goes to Apple or Google under their policies, never to us.
- Email you send us. If you email [email protected] (including joining the waitlist), we receive what you send. We receive your email address, message and any attachments you choose to send. We use them to handle your request or send a launch note you requested. Please avoid sending health information unless you intend us to receive it.
4. Optional crash reporting
Firebase Crashlytics is integrated in Protein Diary. Crash-report collection is off by default and controlled by your Settings preference. If enabled, it sends technical diagnostics such as crash traces, device and operating-system details, app version and installation identifiers to Google so we can investigate bugs. You can turn collection off in Settings.
We do not deliberately attach diary entries or the onboarding profile to crash reports. Technical diagnostics can contain contextual information, so we do not promise that every report is anonymous or incapable of containing personal information. Google describes processing and retention in its Firebase privacy documentation. Turning collection off does not itself delete reports already sent.
5. Purchases
In builds where purchases are unavailable, the app does not connect to RevenueCat. If the version you use offers paid features, Apple or Google processes payment. We do not receive your payment-card details. The app uses RevenueCat when its purchase service is enabled to check access, process purchases and restore access; these operations require a network connection.
RevenueCat receives purchase and entitlement information and uses a generated App User ID without requiring a Protein Diary account. This is more than a purchase token and does not require you to provide a name or email. The app does not attach diary entries to RevenueCat. See RevenueCat's privacy policy. Purchase services may communicate when the app starts, even before you purchase. If you have a subscription, manage or cancel it through your store account.
6. We do not sell data
We do not sell your personal information or use diary entries for advertising. Service providers process the diagnostic, purchase and support information described in this policy.
7. Data security and retention
Because your data is stored locally, its security depends primarily on your device. We recommend using a device passcode or biometric lock, keeping your operating system updated, and being thoughtful about where you send exported files.
Your data stays on your device until you delete it. You can delete individual entries or all data in the app at any time; uninstalling the app removes its locally stored data from your device. Exports and device backups can remain after you delete local entries. Support correspondence and information held by the diagnostic and purchase providers are separate from the local diary; contact us about information you have sent us and consult the linked provider policies for their retention practices.
8. Your privacy rights (GDPR, CCPA, and similar laws)
Privacy laws such as the EU/UK GDPR and the California Consumer Privacy Act give you rights over personal data that organizations hold about you. Your diary is stored locally, and the app provides these controls:
- Access: all your data is visible in the app, on your device
- Portability: export your records, goals and most settings as a JSON backup from inside the app. The items listed in Section 2 as not included are excluded from JSON backups; purchase information and crash reports are described in Sections 4 and 5.
- Deletion: delete entries or everything from inside the app, or uninstall it
- Rectification: edit any entry directly
- Sale opt-out (CCPA): we do not sell personal information, so there is nothing to opt out of
- Non-discrimination: nothing in the app changes based on exercising these rights
For requests concerning support correspondence or other information processed by us or our providers, contact us below. Provider processing and support correspondence may occur outside your country, including in the United States. Information you choose to send can include health data.
9. Children
Protein Diary is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information by email, contact us and we will delete it.
10. Third-party services, summarized
- Apple App Store / Google Play: distribute the app and process any subscription payments under their own privacy policies
- Firebase Crashlytics: optional diagnostics and installation identifiers (see Section 4)
- RevenueCat (when purchase services are enabled): purchase information, entitlements and a generated App User ID (see Section 5)
This website is hosted by Cloudflare Pages. Visiting it involves network requests to the hosting provider. We do not add analytics or advertising scripts to this page. Email services also process messages you send us.
11. Changes to this policy
If we change this policy we will update this page and the "Last updated" date, and note the app version a change applies to. Material changes will also be noted in the app's release notes.
12. Contact
Questions, concerns, or requests: [email protected]. We will respond within a reasonable timeframe.