Privacy Policy

Last Updated: September 9, 2026 | Effective Date: September 9, 2026

In Short: fodia is a private food & digestive diary. Your meals, symptoms, and notes are stored locally and encrypted on your device — we never see them. The app works anonymously, with no account or email required. Core diary logging is free. All AI features (meal analysis and insight summaries) are optional premium features (fodia Premium): when used, a minimal, purpose-built payload (meal text/photo, or pre-aggregated, de-identified daily/weekly statistics) is sent to our server, which forwards it to OpenAI to generate a result; nothing is stored on our servers afterwards. We do not use analytics or advertising SDKs, we do not track you across apps or websites, and we do not sell your data. fodia is not a medical device and does not diagnose or treat any condition — see Section 6.

1. Introduction

Welcome to fodia, a minimalist, privacy-first food and digestive symptom diary. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding your personal information.

fodia is a personal project developed and operated by Naim Dridi Podadera as an individual developer. This is not a commercial entity or registered company.

By using fodia, you agree to this Privacy Policy. If you do not agree, please do not use the app.

2. What Data We Collect

2.1 Local Data (Stored on Your Device)

  • Diary Entries: Meals, ingredients, meal photos (thumbnails), symptom logs (e.g. severity, notes), and any free-text notes you write are stored locally on your device in an encrypted SQLite database using SQLCipher encryption. This data never leaves your device except for the minimal, transient payloads described in Section 5 when you explicitly request an AI analysis.
  • Your FODMAP Profile: Any diagnosed or suspected food triggers/intolerances you record are stored locally and are only included in an AI request if you trigger a meal analysis (Section 5.1).
  • AI Report Cache: The results of meal analyses and daily/weekly/monthly digests are cached locally on your device so the same input isn't re-analyzed. These cached reports are not uploaded anywhere.
  • App Settings: Your preferences (reminder times, language, theme, crash reporting opt-in/out, etc.) are stored locally in secure storage.
  • Encryption Keys: Keys used for local encryption and encrypted backup/export files are stored in your device's secure storage (iOS Keychain / Android Keystore) and are never transmitted to our servers.

2.2 Data We Collect on Our Servers

  • Anonymous User ID (UID): We use Firebase Anonymous Authentication to generate a persistent anonymous identifier for your device. This UID does not contain any personal information and is used to enable your account (deletion, subscription entitlement verification, and notification delivery). You may optionally upgrade this anonymous account by linking an email/password, Google, or Apple sign-in — this is never required for core diary features.
  • Meal Analysis Requests (optional, on-demand): When you ask fodia to analyze a meal, the meal's text and/or a downscaled photo, together with your locale and FODMAP profile, is sent to our Cloud Function, which forwards it to OpenAI to generate the analysis. See Section 5 for full detail. We do not persist this payload on our servers after the request completes.
  • Daily/Weekly/Monthly Insight Requests (optional, on-demand): To generate a narrated summary, your device pre-aggregates already de-identified totals and correlations (e.g. "logged 4 dairy meals this week, 3 followed by bloating") locally and sends only that summary — never your raw notes or photos — to our Cloud Function for narration by OpenAI.
  • Push Notification Data: If you enable reminders, a Firebase Cloud Messaging token and Firebase Installation ID are stored so we can deliver reminder notifications to your device. Most reminders are scheduled locally on your device and never touch our servers.
  • App Integrity Signals (Firebase App Check): Used to verify that requests to our Cloud Functions come from a genuine, unmodified copy of the app. This does not identify you personally.
  • Remote Configuration Data: We use Firebase Remote Config to deliver feature flags and settings. This service logs minimal anonymous usage data (device type, app version) to determine which configuration to serve.
  • Anonymous Diagnostic Data: We use Firebase Crashlytics to collect anonymous crash reports and diagnostic data to improve app stability. This includes crash logs, device information (model, OS version), and app state at the time of crashes. No diary content or user-generated text is included in these reports. You can disable crash reporting in the app's Settings at any time.

2.3 Data We Do NOT Collect

  • We do not require your name, email address, or phone number for core app functionality (an email is only collected if you voluntarily create an account or contact support).
  • We do not use analytics SDKs or tracking pixels. Our analytics layer is a deliberate no-op — no events, no identification, nothing is sent anywhere.
  • We do not collect location data, contacts, or browsing history.
  • We do not use third-party advertising networks, run ads, or sell your data to anyone.
  • We do not include diary content, notes, or user-generated text in crash reports.
  • We do not store your raw diary text or meal photos on our servers — only the minimal payloads described in Section 5, and only when you actively request an AI analysis.

3. How We Use Your Data

We use the data we collect for the following purposes:

  • Core Functionality: To provide the diary, store your entries securely on your device, and enable optional AI-powered meal analysis and insight summaries.
  • Reminders: To deliver meal-logging reminders you configure in Settings.
  • Feature Flags: Remote Config allows us to roll out new features gradually without requiring app updates.
  • App Stability: Anonymous crash reports help us identify and fix bugs.
  • Account Management: Your anonymous UID lets us honor account-deletion requests and sync premium subscription entitlements across your devices (see Section 14).

We do not use your data for advertising, profiling, behavioral tracking, or any purpose other than those listed above.

4. Data Sharing & Third Parties

4.1 Third-Party Services

fodia uses the following third-party services to operate:

  • Firebase (Google): For authentication (anonymous UID and optional linked sign-in), app integrity checks (App Check), remote configuration (Remote Config), push notification delivery (Cloud Messaging), and crash reporting (Crashlytics). Firebase processes data according to Google's privacy policies. Learn more: Firebase Privacy.
  • OpenAI: When you use meal analysis or AI-generated insight summaries, the minimal payload described in Section 5 is processed by OpenAI's API over an encrypted connection (TLS) via our server. OpenAI does not use API data to train its models and, per our server configuration, requests are sent with storage disabled (store: false). See OpenAI's Privacy Policy.
  • Apple App Store / Google Play Store: For fodia Premium subscriptions, all payment transactions (credit card, billing address) are processed exclusively by Apple or Google. We never collect, see, or store your payment details.
  • RevenueCat: We use RevenueCat to manage in-app purchases and validate subscription entitlements across devices. RevenueCat processes anonymous app user identifiers and purchase receipt tokens. It does not receive your diary entries, health information, or payment details. Learn more: RevenueCat Privacy Policy.

4.2 No Data Selling

We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes.

4.3 Legal Disclosures

We may disclose your data if required by law, court order, or government regulation, or to protect our legal rights, prevent fraud, or ensure the safety of users.

5. AI Usage & Data Transmission

fodia uses artificial intelligence to help you understand possible links between meals and digestive symptoms, and to narrate your logged statistics in plain language. All AI features are premium features (fodia Premium); they are entirely optional and only run when you explicitly request an analysis or digest.

5.1 Meal Analysis

  • What Is Sent: The text you entered for a meal and/or a photo of the meal (automatically resized to a maximum of 1024px and compressed before upload), your recorded FODMAP diagnosed/suspected profile, the meal's local timestamp, and your app language are sent to our Cloud Function, which relays them to OpenAI (GPT-4o / GPT-4o-mini) to estimate nutrition and flag possible FODMAP trigger ingredients.
  • User Responsibility: Avoid including personally identifiable information (names, addresses, phone numbers) in meal notes or photos, since this content is transmitted for processing.
  • Result Handling: The AI's response is returned to your device and cached locally so the same meal isn't re-analyzed; it is not retained on our servers.

5.2 Daily & Statistical Insight Summaries

  • What Is Sent: Your device computes every number itself (counts, symptom correlations, day/week/month totals) from your local diary. Only this pre-aggregated, already de-identified summary — never your raw meal notes, photos, or free-text — is sent to our Cloud Function, which asks OpenAI to narrate it in prose.
  • Purpose: The narration never invents new figures; it only describes the numbers your device already calculated.

5.3 General AI Policies

  • Authentication Required: Every AI request requires you to be signed in (even anonymously); unauthenticated requests are rejected by our server.
  • Encryption in Transit: All data (text, images, aggregated statistics) is transmitted over TLS (HTTPS) encryption.
  • No Server-Side Storage: Our Cloud Functions do not write your meal text, photos, or aggregated statistics to any database — they are processed in memory for the duration of the request and then discarded.
  • API Provider Policy: Requests to OpenAI are sent with model training and response storage disabled. See: OpenAI Privacy Policy.
  • Failure Handling: If the AI service is unavailable, your entry is still saved locally, and a clear "couldn't analyze" state is shown instead of an AI-generated result.

Disclaimer: AI-generated nutrition estimates, trigger flags, and insight summaries are informational only. They are not medical advice — see Section 6.

6. Health-Related Data & Medical Disclaimer

Your diary may include information about digestive symptoms (e.g. bloating, pain levels) and food intolerances, which can be considered sensitive "health data" under regulations like the EU GDPR (Article 9) or similar laws. We take this seriously:

  • Not a Medical Device: fodia is a personal tracking and reflection tool. It does not diagnose, treat, cure, or prevent any disease or medical condition, including IBS or FODMAP intolerances, and is not a substitute for advice from a qualified healthcare professional, dietitian, or doctor.
  • You Control What You Log: All health-related entries are created voluntarily by you and stored locally, encrypted, on your device. Nothing is uploaded automatically; data only leaves your device when you actively request an AI analysis (Section 5) or generate a CSV/backup export you choose to share (Section 7).
  • Consent: By logging symptoms or dietary information and choosing to use the optional AI features, you consent to the limited processing described in this Policy. You can use fodia's core diary and export features without ever triggering an AI request.
  • Clinical Sharing: The unencrypted CSV export exists specifically so you can choose to share your own records with a doctor or dietitian; we never share this data on your behalf.
  • Emergency Situations: If you are experiencing a medical emergency or severe symptoms, contact a qualified healthcare professional or emergency services immediately — do not rely on fodia.

7. Backups, Export, and Import

7.1 Local Encrypted Backups

fodia lets you create encrypted backup files (JSON format) stored on your device. These backups are encrypted using a key stored in your device's secure storage and can be restored on the same or another device via the Import function.

7.2 Clinical CSV Export

You can export your diary for a given date range as an unencrypted CSV file, intended to be opened and reviewed with a doctor or dietitian. This file includes your meals, symptoms, and optionally AI-estimated nutrition/trigger flags (which you can choose to exclude). The file is saved to your device's local storage and is only shared if and when you choose to share it (e.g. via email, AirDrop, or a file app) — we never receive a copy.

7.3 Import

Importing a backup file replaces your local diary with the contents of that file. Always export a current backup first if you want to keep existing data.

8. Data Retention & Deletion

8.1 Local Data

Your diary entries and settings are stored on your device indefinitely until you delete them. You can delete individual entries at any time, or uninstall the app to remove all local data (uninstalling is irreversible unless you have a backup file).

8.2 Server-Side Data

  • Anonymous UID & Account: Retained while you use the app. If you delete your account (Settings → Delete my account), we permanently delete your account record, any subscription entitlement records, and registered notification devices.
  • Push Notification Registrations: Deleted when you turn off reminders, delete your account, or the underlying token expires.
  • Crash Reports: Stored in Firebase Crashlytics for app stability analysis. You can disable crash reporting in Settings, or request deletion by contacting us.
  • AI Request Payloads: Not retained — see Section 5.3.

8.3 Important: Account Deletion Does Not Erase Your Local Diary

Deleting your account removes your cloud-side identity and entitlements only. Your diary lives on your device and is not automatically erased when you delete your account. Export a backup first if you want to keep your data, and uninstall the app (or delete entries individually) if you also want your local diary removed.

8.4 Right to Deletion

You can request deletion of any data we hold on our servers by emailing appfodia@gmail.com. We will delete your account, device registrations, and crash reports within 30 days.

9. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

  • Right to Access: Request a copy of the data we hold about you (anonymous UID, account status, crash reports).
  • Right to Portability: Export your diary data as an encrypted backup or CSV at any time via the app's Export feature.
  • Right to Correction: Correct or delete any diary entry directly in the app at any time.
  • Right to Deletion: Delete your account in-app, or request deletion of server-side data (see Section 8.4).
  • Right to Restriction: Request that we limit processing of your data.
  • Right to Object: Object to processing of your data for specific purposes (e.g. AI analysis or crash reporting, which can be disabled in Settings).
  • Right to Withdraw Consent: Stop using any optional feature (AI analysis, crash reporting, reminders) at any time in Settings.
  • Right to Lodge a Complaint: If you believe we have mishandled your data, you can file a complaint with your local data protection authority.

To exercise any of these rights, contact us at appfodia@gmail.com.

10. Children's Privacy

fodia is intended for users aged 18 and over. We do not knowingly collect personal information from children under 18. If a parent or guardian becomes aware that their child has provided us with data without consent, please contact us immediately at appfodia@gmail.com and we will delete the data.

If you are under 18 and wish to use fodia, you must obtain parental or guardian consent before using the app.

11. Security Measures

We take the security of your data seriously and implement the following measures:

  • SQLCipher Encryption: Diary entries are stored in an encrypted SQLite database on your device.
  • Secure Storage: Encryption keys and sensitive settings are stored in iOS Keychain / Android Keystore.
  • TLS Encryption: All data transmitted to our servers or third-party APIs is encrypted in transit using TLS 1.2+.
  • App Attestation: Firebase App Check helps ensure requests to our backend come from a genuine copy of the app.
  • No Plain-Text Logs: We do not log diary content or personal information in plain text.
  • Regular Security Review: We periodically review our code and dependencies for security vulnerabilities.

While we strive to protect your data, no method of transmission or storage is 100% secure. You are responsible for safeguarding your device (use a passcode, biometric lock, etc.).

12. Cookies & Website Tracking

This website (fodia.web.app) is hosted on Firebase Hosting and does not use cookies for tracking or analytics. The only cookies used are essential session cookies required for hosting functionality (e.g., CDN caching). We do not use Google Analytics, advertising pixels, or other tracking technologies on this website.

13. International Data Transfers

fodia uses Firebase and OpenAI services, which may store and process data in data centers located in the United States and other countries. If you are located in the European Economic Area (EEA) or other regions with data protection laws, your data may be transferred to countries with different privacy protections. Firebase and OpenAI provide safeguards such as Standard Contractual Clauses for these transfers. Learn more: Firebase Privacy & Security and OpenAI Privacy Policy.

14. Premium Subscriptions & Payment Processing

fodia offers core diary tracking (meals, symptoms, notes, local encrypted storage, data backup, and clinical CSV export) for free. We offer an optional paid subscription ("fodia Premium") that unlocks all AI-powered features (such as AI meal analysis, FODMAP trigger detection, daily AI digests, and monthly insight summaries).

  • Payment Information: All subscription and in-app purchase payments are processed exclusively by Apple App Store (for iOS) or Google Play Store (for Android). We never collect, see, or store your credit card numbers, bank details, or billing address.
  • Subscription Management & Receipts: We use RevenueCat alongside your anonymous UID to verify store purchase receipts and sync your premium entitlements across your devices.
  • Subscription Status: We store minimal entitlement metadata (active subscription status, product identifier, trial status, and expiration timestamp) to determine access to AI features.

Subscriptions auto-renew unless cancelled at least 24 hours before the end of the current billing period through your Apple ID or Google Play account settings. See Section 8 of our Terms of Service for complete subscription and billing terms.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Email: appfodia@gmail.com
Developer: Naim Dridi Podadera
Project Type: Personal/Independent Project

We will respond to your inquiry within 30 days.

Note: As this is a personal project operated by an individual developer, there is no formal Data Protection Officer (DPO). All data protection inquiries should be directed to the email above.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features. When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Notify you via an in-app message or email (if you have provided an email).

Continued use of fodia after changes indicates your acceptance of the updated policy.

17. Summary of Key Points

  • Your diary entries (meals, symptoms, notes) are stored locally and encrypted on your device.
  • fodia works anonymously by default — no account, email, or sign-up is required.
  • Core diary logging, local encryption, backup/restore, and CSV export are free.
  • All AI features (meal analysis, trigger detection, digests, and summaries) are optional premium features (fodia Premium). When requested, they send only the minimal data needed (meal text/photo, or pre-aggregated statistics) to our server, which forwards it to OpenAI. Nothing is stored on our servers afterwards.
  • fodia is not a medical device and does not diagnose or treat any condition.
  • We do not track you, sell your data, or run ads or analytics.
  • You can export an encrypted backup or an unencrypted clinical CSV at any time.
  • Deleting your account removes your cloud identity but not your local diary — export first if you want to keep it.
  • You have full rights under GDPR/CCPA to access, delete, or correct your data.
  • Contact us anytime at appfodia@gmail.com.