Intake — Privacy Policy
Last updated: October 1, 2026
Aksoy Labs (“we”, “our”, or “us”) operates the Intake nutrition and training app (“Intake”). This policy covers released Intake versions 1.1.3, 1.2, and 1.3, and the planned measurement changes for forthcoming version 1.3.1. Version 1.3.1 is being prepared for testing and is not yet released on the App Store. The sections below distinguish existing processing from the upcoming changes.
1. Information stored on your device
Intake stores your food and nutrient logs, water, caffeine and supplement records, goals, profile information, and preferences on your device. Version 1.2 also stores training plans and imported workout records locally. Version 1.3 also stores body measurements and your weekly check-in and daily-target decisions locally. These local records are included when you choose to create a user-directed backup; resetting local app data removes them from the device. The app does not automatically sync these records to an Intake account or cloud journal. You can edit or delete entries and share a backup to a destination you choose. The destination’s privacy practices apply to any copy you share.
2. Optional AI food analysis
Photo and text food analysis is an optional feature. In version 1.1.3, the app sends a submitted photo or description to Google Gemini directly or through Vibecode’s Gemini proxy, depending on its build configuration. That version does not use the Intake Cloud Run analysis service described below. Google’s processing terms and, when the proxy is used, Vibecode’s handling practices apply to that request.
In versions 1.2 and 1.3, AI analysis is an optional Intake Pro feature. When you choose to analyze a meal, Intake sends the photo or description to our Google Cloud Run analysis service and the paid Google Gemini Developer API to estimate foods, portions, and nutrition. Intake’s analysis service does not save a meal journal, photo, or analysis response. Body measurements and Apple Health sleep or recovery readings are not included in AI analysis requests.
For the managed analysis service in versions 1.2 and 1.3, Google’s paid-service terms say prompts and responses are not used to improve Google products. Google logs prompts and responses for a limited period for prohibited-use enforcement and service safety. The terms do not state an exact duration, and the information may be stored or cached in countries where Google or its agents operate. Google may also process technical and usage information needed to operate the service, such as request counts, token usage, safety events, errors, identifiers, and IP addresses.
The analysis service used in versions 1.2 and 1.3 keeps technical request logs, such as the request time, route, status, and processing duration, to operate and protect the service. These application logs exclude your food description, photo, and analysis result. Google Cloud also records HTTP request metadata. Our ordinary request logs are retained for 30 days; required administrative and audit logs are retained for 400 days. The longer administrative retention does not apply to meal photos or descriptions sent for analysis.
For versions 1.2 and 1.3 database matching, our server may send proposed food names to USDA FoodData Central. It does not send the photo, full meal description, or Firebase identifier to USDA in this lookup. USDA’s own terms and handling practices apply. AI nutrition estimates can be wrong; review and edit them before saving. Intake does not use them as a medical diagnosis.
3. Account protection and request limits
You can use Intake without creating a named account. Versions 1.2 and 1.3 use an anonymous Firebase Authentication identifier and Firebase App Check to protect the analysis service. The same pseudonymous Firebase identifier is used as the RevenueCat App User ID and by our service to check Intake Pro access and enforce daily AI request limits.
For versions 1.2 and 1.3, Firestore stores daily request counters, not meal content or photos. Each counter is assigned an expiry timestamp seven days after it is written; the production deletion policy is enabled, and deletion can occur after that expiry time rather than at an exact instant.
4. Purchases
Apple handles payment for Intake Pro. RevenueCat receives an App User ID and purchase information, such as product, transaction, and subscription or entitlement status, so Intake can unlock and restore Pro. Version 1.1.3 uses the identifier generated by the RevenueCat SDK; versions 1.2 and 1.3 link RevenueCat to the app’s pseudonymous Firebase identifier. RevenueCat’s App Privacy guidance describes purchase-history use for app functionality and its analytics and customer-history features. Aksoy Labs does not receive your payment card number through the app. You can manage or cancel your subscription in your Apple Account settings. See the RevenueCat Privacy Policy.
Since September 30, 2026, RevenueCat is configured to send production purchase and subscription lifecycle events to Amplitude for subscription and revenue analytics. These events include the pseudonymous RevenueCat App User ID, which is the Firebase identifier in versions 1.2 and 1.3, subscription product information, currency, and revenue information, including estimated net revenue. Sandbox events and custom subscriber attributes are not forwarded by this integration.
5. Apple Health
In version 1.1.3, enabling Apple Health requests permission to read active energy, step count and body mass, and to write water and protein entries. When Health is enabled, logged water and protein can be written to Apple Health; the latest body mass can update your local profile.
In version 1.2, with your permission, Intake reads workout records, including available workout energy, and, if you choose, body mass from Apple Health. Imported records are stored on your device. Intake does not upload the workout or body-mass records to its analysis service. Amplitude receives limited training metadata, such as workout category, entry source, completion status, and import events or record counts. It does not receive the complete workout samples, exact workout times or durations, or body-mass value through this analytics path. Version 1.2 requests read access only and does not write data to Apple Health. You can revoke Health access in iOS Settings.
In version 1.3, if you grant permission, Intake can read Apple Health workouts, body mass, body-fat percentage, lean body mass, sleep analysis, heart-rate variability (HRV), and resting heart rate. Workout and body-composition records are stored locally. Body measurements are not sent in analytics or AI analysis requests. Sleep, HRV, and resting-heart-rate readings are cached only in memory while the app is running; they are not persisted in the journal, included in backups, uploaded, or sent to analytics. Version 1.3 requests read access only and never writes to Apple Health. The limited workout metadata analytics described above continues to apply. You can revoke Health access in iOS Settings.
6. Analytics
These versions use Amplitude’s HTTP API for product analytics. Amplitude receives a persistent random device identifier, event names, app version and platform. Version 1.1.3 analytics can also include food names or descriptions and logged calorie and nutrient values.
Versions 1.2 and 1.3 limit event properties sent by the app through a source allowlist. Amplitude receives a persistent random device identifier, event names, app version and platform, and limited event details such as onboarding, screens viewed, food-logging steps, training features, subscription actions, and coarse counts or categories. These events also include whether a supplement was marked as taken and which tracker reached or exceeded a goal; supplement names are excluded. Neither version sends meal descriptions, photos, exact nutrient values, workout energy or body measurements in these events. The app builds described here do not set the Firebase identifier as Amplitude’s user ID for these client events. Version 1.3 sleep, HRV, and resting-heart-rate readings are not sent to analytics. Limited workout metadata remains as described in the Apple Health section.
Separately, the RevenueCat integration described in the Purchases section sends the pseudonymous RevenueCat App User ID to Amplitude with production purchase and subscription events. In versions 1.2 and 1.3, this gives Amplitude the Firebase identifier through the server integration even though the app does not set it on client events. This server integration can process purchases from existing installations without an app update.
Amplitude’s HTTP API documentation says it uses the request IP address by default to infer city, region, country, and DMA. Amplitude can be configured to drop IP addresses after ingestion; we have not confirmed that this is enabled for Intake, so IP-derived location may be processed. Automatic expiry of analytics events is not configured in the account’s TTL settings; we do not promise that events are automatically deleted after a fixed period. Intake uses these events for product analytics, not to target advertising across other companies’ apps. See the Amplitude Privacy Notice.
Forthcoming version 1.3.1: linked analytics and Apple Ads measurement
The planned 1.3.1 update will link client analytics to subscription analytics using the app’s pseudonymous Firebase identifier after RevenueCat confirms the same app user. Intake will send that identifier and its random analytics device identifier to Amplitude, and provide matching identifiers to RevenueCat so app activity and subscription events can be associated. Events will include app-use steps, subscription actions, categories or counts, coarse AI response-time buckets and error categories, event time, app/build information, installation cohort and test/production context. Recent events may be stored on the device and retried when connectivity returns.
On iOS, RevenueCat will collect Apple’s AdServices attribution token and use it to request Apple Ads attribution. Where Apple provides it, RevenueCat will associate campaign, ad-group, keyword and country/region context with the subscription customer. We will use this information to measure our advertising and subscription outcomes. Missing attribution is not proof of an organic install.
These measurement flows will not send meal photos or descriptions, exact nutrient or body measurements, or raw Apple Health samples to Amplitude or as RevenueCat attributes. The limited supplement/goal and workout metadata analytics described above will continue. The existing production RevenueCat-to-Amplitude integration is already active and remains separate from this app update. The linked analytics records are pseudonymous, not anonymous; the retention and international-processing sections of this policy apply. The existing on-device body and Apple Health processing described for version 1.3 will continue in 1.3.1.
7. Notifications
If you enable reminders, Intake schedules them locally on your device. Intake does not send reminder content or schedules to its analysis service. You can change notification permissions in iOS Settings.
8. Retention and your choices
You can edit or delete local entries, reset local app data, or uninstall Intake. These actions do not automatically delete data already held by Apple, RevenueCat, Firebase, Google, USDA, or Amplitude. For versions 1.2 and 1.3, Google’s paid Gemini service logs prompts and responses for a limited safety and policy-enforcement period; Cloud Logging retention is described above, and Firestore quota counters are scheduled for deletion after their seven-day expiry timestamp, which may be delayed. Version 1.1.3 requests follow Google’s and, when used, Vibecode’s handling practices. Amplitude analytics events have no configured automatic TTL expiry; deleting local app data does not delete those provider records.
Contact support@aksoylabs.com to ask about information associated with your Intake identifier. You can manage your Apple Health permissions and subscription through iOS Settings and your Apple Account.
9. International processing
Service providers may process information outside your country. In particular, the Gemini API terms allow limited-period safety logs to be stored or cached in countries where Google or its agents operate. Intake’s Amplitude project uses United States processing, including for the production RevenueCat purchase and subscription events described above. IP handling depends on the Amplitude project configuration, as described in the Analytics section. Versions 1.2 and 1.3 use Firebase Authentication, which runs in the United States. See the Firebase privacy and security information.
10. Children
Intake is not designed for children under 13. If you believe a child has provided information to us, contact support@aksoylabs.com.
11. Health disclaimer
Intake is a personal food journal and planning tool, not medical advice. Nutrition values and AI analysis are estimates. Talk with a qualified healthcare professional about medical or dietary concerns.
12. Changes to this policy
We may update this policy when Intake changes. The date above identifies when this policy was last updated.
13. Contact us
If you have questions about this Privacy Policy, contact Aksoy Labs at support@aksoylabs.com or visit aksoylabs.com.