Ainonymity Calorie Counter · Privacy
Your meals stay on your phone.
The app asks for one permission — the camera — and sends one thing, only when you tap it: a photo you chose to analyze.
What leaves your phone, and when
Just that photo. It goes over an encrypted connection with the analysis mode you picked and an anonymous credit token, and comes back as an estimate. Your name, your email and your location stay where they are, because the app never asks for them at all.
Use the app without the camera and it is a purely local tool: everything you log is written to your device and stays there.
Photographs are reduced to raw pixels before anything else happens. The analysis path takes an image rather than a file, so camera metadata — including GPS coordinates — is already gone by the time our own code sees it.
What we chose to leave out
- An account. There is nothing to sign up for, so you have one less password to remember.
- Analytics. Nothing in the app reports back on how you use it. We find out how it is going the old-fashioned way, when somebody writes to tell us.
- Advertising. The app carries none, and your advertising identifier stays unread.
- Permissions beyond the camera. The camera is the entire list. Your photo library, your location and your contacts stay out of reach, and the app has no way to send you a notification even if we wanted it to.
The barcode scanner is completely silent
It uses the camera, but the product database it consults is a file already on your phone. Point it at a packet and everything happens locally. It is free, it works in aeroplane mode, and the lookup stays on the device.
Where everything lives
On your device, protected by your passcode through iOS Data Protection. Your meals and their history are included in your own backups; the details you give the calculator (age, sex, height and weight) are kept out of them. We have no way to read any of it.