Privacy Policy
Last updated: May 13, 2026
KidneyBite ("we", "our", or "the app") helps users better understand kidney-relevant nutrition from meal photos. This Privacy Policy explains what data is processed, where it is stored, and the choices available to you.
The short version
Your meal history stays on your device.
Meal photos are securely sent to Anthropic's Claude API for food analysis. KidneyBite does not permanently store those photos on our servers.
Apple Health integration is optional and fully controlled by you.
1. Meal photos & food analysis
When you scan a meal, the photo is securely sent to Anthropic's Claude API for food identification and portion estimation.
According to Anthropic's API policies, submitted content is not used to train AI models. Anthropic may temporarily retain API content for safety and abuse monitoring (typically around 30 days) before deletion.
KidneyBite does not permanently store your meal photos on KidneyBite-operated servers.
2. Nutrition lookups
Food names and nutrition-related text may be sent to USDA FoodData Central, a public nutrition database operated by the United States Department of Agriculture (USDA).
We do not attach personal identifiers to those lookups.
3. On-device storage
Meal analyses, nutrient summaries, and related app data are stored locally on your device using Apple technologies such as SwiftData.
This data does not leave your device except through optional Apple device backup systems that you control. If you use iCloud device backup (an Apple system feature, not a KidneyBite product), your meal history may be included in those backups under Apple's terms. KidneyBite does not operate its own cloud backup service.
You can erase all locally stored app data anytime from:
Profile → Privacy & Data → Delete All My Data
4. Apple Health
If you enable Apple Health integration, KidneyBite may read body weight from your Health app to personalize your daily protein target.
KidneyBite may also write daily nutrient totals (sodium, potassium, protein, and energy) back to Apple Health from your logged meals. Phosphorus is tracked inside the app only, since Apple Health does not have a native phosphorus data type.
Health data accessed through HealthKit is not used for advertising, marketing, or data broker activities, and is never written to iCloud by KidneyBite.
You can revoke Health access anytime in:
iOS Settings → Privacy & Security → Health → KidneyBite
5. Subscriptions & payments
Subscriptions are processed by Apple through the App Store and managed using RevenueCat.
We receive anonymous subscription status information, such as whether a subscription is active and which plan is associated with the device.
We do not receive your Apple ID, payment card information, or billing details.
6. Analytics & crash reports
KidneyBite uses Firebase Analytics and Firebase Crashlytics to understand app performance and stability.
Collected analytics are anonymized where possible and may include app launches, screen views, and crash diagnostics.
Crash logs do not include meal photos or nutrition analysis results.
KidneyBite does not use IDFA for advertising tracking.
7. Data we do not collect
We do not intentionally collect:
- Name
- Email address (unless you contact support)
- Phone number
- Precise location
- Advertising identifiers for tracking
- Browsing history
- Contacts
- Biometric templates such as Face ID data
KidneyBite does not maintain a cloud photo storage service.
8. Third-party services
Limited processing may occur through the following providers:
- Anthropic (Claude API): meal photo analysis
- USDA FoodData Central: nutrition reference lookups
- Apple: App Store billing and optional HealthKit services
- RevenueCat: subscription status management
- Google Firebase: analytics and crash reporting
9. Your rights
You may:
- Delete your app data from inside the app
- Revoke Apple Health permissions anytime
- Contact us regarding privacy-related requests
Residents of certain regions, including the European Economic Area (EEA), United Kingdom, and California, may have additional privacy rights under applicable laws such as GDPR or CCPA/CPRA.
10. Children's privacy
KidneyBite is intended only for adults age 18 and older.
We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal data through the app, please contact us and we will take reasonable steps to delete it.
11. Security
Data stored on-device benefits from Apple platform security protections.
Connections between the app and external services use encrypted HTTPS connections.
12. Changes to this policy
If this Privacy Policy changes materially, we will update the "Last updated" date and may provide additional notice inside the app.
13. Contact
Questions about privacy?
KidneyBite is a product of Aura Bionics.