Effective 27 August 2026 · Last updated 27 August 2026
This policy explains what Thali collects, why, who else sees it, and how long it is kept. It is written to be read. Where a detail is awkward, it is stated plainly rather than left to a phrase like "and other similar data".
Thali ("Thali", "the app", "we", "us", "our") is an iOS calorie and nutrition tracking app. It is operated by Upwan Chachra, an individual developer based in Calgary, Alberta, Canada. For the purposes of the EU and UK GDPR, Upwan Chachra is the data controller for the information described in this policy, and can be reached at krish.aerialmedia@gmail.com.
This policy covers both the Thali mobile application and this website. Section 15 describes what the website itself does, which is much less than the app.
Thali is for adults 18 and older. During onboarding the app asks for your date of birth and blocks account creation if the date you enter indicates you are under 18. By creating an account you confirm you are 18 or older. We do not knowingly collect information from anyone under 18, and if we learn that we have, we will delete it.
We do not collect your name, phone number, address, contacts, precise location, or advertising identifier. The app does not ask for them and has no code that reads them.
When you photograph a meal, the image is resized on your device and sent to Google's Gemini API to identify the food and estimate its nutrition. We do not store your meal photos. The image is held in memory only for as long as it takes to answer that one request, and is then discarded. There is no photo storage in our backend, and no code path anywhere in the app that uploads a photo to a file store.
We do not use your photos, food logs, or any other content to train our own models, and our agreements with our AI providers do not permit them to use your content to train theirs. When you log food by typing instead, the text of your query is sent to the AI and nutrition database services listed in section 7.
If you are in the EU, the UK, or another region with similar law, we must have a lawful basis for each use. Here they are, mapped one to one.
| Information | Why we use it | Legal basis |
|---|---|---|
| Email and password | Create your account, sign you in, let you reset your password | Performance of a contract, Art. 6(1)(b) |
| Profile and body metrics | Calculate and display your calorie and macro targets | Performance of a contract, Art. 6(1)(b) |
| Date of birth | Confirm you are 18 or older | Legitimate interests, Art. 6(1)(f): operating an adults-only service responsibly |
| Food logs, meal photos, weight history, streaks | Provide the tracking features you signed up for | Performance of a contract, Art. 6(1)(b) |
| Subscription status | Give you access to paid features and honour your purchase | Performance of a contract, Art. 6(1)(b) |
| IP address and usage records | Enforce rate limits, prevent abuse, keep the service available and affordable to run | Legitimate interests, Art. 6(1)(f) |
| Server error logs | Diagnose and fix faults | Legitimate interests, Art. 6(1)(f) |
One row of that table deserves plainer words than a category label. Your weight, height, goal weight and what you eat are measurements of your body, and tracked over time they can say something about your health. We treat them accordingly. They are used for exactly one thing: calculating your calorie and macro targets and showing you your own history. We do not use them to infer anything else about you, we do not use them for advertising, and we do not share them beyond the providers listed in section 7. Where we rely on legitimate interests you can object, and section 11 explains how.
Asking an AI model the same question twice costs money and returns the same answer, so we keep a shared cache of food lookups. When anyone looks up a food by typing, the text of that query and the nutrition result are stored in a single cache that all users share.
The cache is keyed by the query text itself, for example "3 eggs two toast" or "chicken shawarma". It has no user column. Nothing in it records who typed a query, when, or from which account, and it cannot be searched by user.
The consequence is worth stating plainly rather than leaving you to discover it: the cache is not designed to hold anything about you - no entry records who typed it - so deleting your account does not remove entries from it. What remains is the query text and its nutrition values, indistinguishable from the same query typed by anyone else. Because the key is the text you typed, please do not put personal details - your name, a health condition, anything about yourself - into a food search. If a query you typed contains something personal, or you would like any entry removed for any reason, email us and we will remove it.
We do not sell your personal information, and we never have. We share data with the following service providers only as needed to run the app. Each one receives the minimum that its job requires.
| Provider | What it receives | Why |
|---|---|---|
| Supabase | Your account and all app data | Our backend, database and authentication provider |
| Google (Gemini API) | Meal photos and typed food queries | Identifies the food and estimates nutrition |
| Google (Gmail SMTP) | Your email address and the message body | Delivers account email such as password resets and confirmations |
| Anthropic (Claude API) | Typed food text only, never photos | Splits a multi-item meal into separate items |
| USDA FoodData Central | Food search terms | Authoritative nutrition data for single foods and packaged products |
| Open Food Facts | The barcode you scanned, sent directly from your device | Looks up a packaged product |
| RevenueCat | Purchase and entitlement information, and your user ID | Manages subscription status across devices |
| Apple | Your purchase, through your Apple ID | Merchant of record. Apple processes payment; we never see your card |
| Netlify | Standard web server logs when you visit this website, including your IP address | Hosts this website. It receives nothing from the app |
We may also disclose information if required by law, or where necessary to protect rights, safety, or the integrity of the service.
Your IP address is not forwarded to the AI or nutrition lookup providers. Requests to Google Gemini, Anthropic and USDA are made by our servers, not by your device, so those three see our server's address and never yours.
Services your device contacts directly do see your IP address, because that is unavoidable in any direct network connection. Those are Supabase (every time the app loads or saves data), RevenueCat (when it checks your subscription), Apple (when you purchase or restore), and Open Food Facts (only when you scan a barcode). Netlify sees it when you visit this website.
Your account and app data are stored in Canada, in Supabase's Canada Central region. Some processing happens elsewhere: the AI and nutrition lookup providers above may process your queries and photos on servers in the United States or other countries. By using Thali you understand that your information may be transferred to and processed in countries other than your own, which may have different data protection laws. Where such a transfer involves personal data from the EU or UK, it is made under the relevant provider's standard contractual clauses.
Retention is enforced by an automated job that runs daily, not by intention alone.
| What | How long |
|---|---|
| IP addresses in abuse-prevention logs | Erased within 7 days. The rate limiter only ever reads the last 60 seconds of them |
| The rest of a usage record: user ID, which feature ran, timestamp | Deleted within 30 days |
| Account and app data: profile, food logs, weight history, streaks, saved dishes | Kept while your account is active, and deleted when you delete your account |
| Meal photos | Never stored. Held in memory for one request, then discarded |
| Server error logs | A short operational period set by our backend provider. These sit outside the account database and are not removed by account deletion |
| Shared food cache entries | Kept indefinitely. Not linked to you or to any account. See section 6 |
Deleting your account removes your usage records immediately, rather than waiting for the windows above to expire.
Every connection between the app and our servers uses HTTPS. Passwords are salted and hashed by our authentication provider and are never stored in readable form. Your login session is held in the iOS Keychain on your device, which is encrypted by the operating system. Access to the database is restricted by row-level security rules, so one account cannot read another's data. Our managed database provider encrypts stored data at rest.
To be precise about what that does not mean: Thali is not end-to-end encrypted. Your food logs and weight history are stored in a form our backend can read, which is what makes features like your history and charts possible. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on where you live you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising any of them. Thali gives every user these controls regardless of location.
Reach us at krish.aerialmedia@gmail.com. We aim to respond within 30 days. If you are in the EU or UK and are not satisfied with our response, you may complain to your local supervisory authority.
This section is for California residents under the CCPA as amended by the CPRA. In the previous twelve months we collected the categories below. We did not sell or share personal information as those terms are defined by the CCPA, and we have no plans to.
| Category | Examples in Thali | Sold or shared |
|---|---|---|
| Identifiers | Email address, account ID, IP address | No |
| Commercial information | Subscription and purchase status | No |
| Internet or network activity | Which AI feature you used and when | No |
| Health information | Height, weight, goal weight, calorie and macro intake | No |
| Visual information | Meal photos, processed in real time and never stored | No |
| Other user content | Dish names, typed food queries, meal notes | No |
The health information in the table above - your body metrics and food intake - is sensitive personal information as California defines that term in section 1798.140(ae). We collect and use it only to provide the service you signed up for: calculating your targets and keeping your logs. We do not use it to infer characteristics about you, and we do not sell or share it. You may exercise your rights to know, delete, correct, and limit the use of sensitive personal information through the app or by emailing us, and we will not discriminate against you for doing so. Because we do not track users across sites, we do not respond differently to Global Privacy Control or Do Not Track signals; there is nothing for them to switch off.
Thali is operated from Alberta and your data is stored in Canada, so Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies. Under PIPEDA you have the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent subject to legal and contractual restrictions. The rights and contact route in section 11 cover all of these.
If you have raised a concern with us and are not satisfied with the outcome, you may complain to the Office of the Privacy Commissioner of Canada.
Thali contains no third-party analytics, advertising, attribution, or crash-reporting software of any kind. There is no Google Analytics, no Facebook SDK, no advertising identifier, and no App Tracking Transparency prompt, because there is nothing to ask you for. Push notifications are scheduled entirely on your device and no notification token ever reaches us. We do not track you across other apps or websites, we do not show ads, and we do not sell or share your personal information for advertising.
This site is a set of static pages. It sets no cookies, runs no analytics, and has no login, no forms, and no way to identify you.
Two things happen anyway, and you should know about both. Netlify, which hosts these pages, records standard web server logs including your IP address. The pages load their two typefaces from Google Fonts, which means Google receives your IP address when the fonts are fetched. Neither is used to identify you, and neither is connected to your Thali account.
We may update this policy from time to time. If we make material changes we will update the date at the top and, where appropriate, tell you in the app. Continuing to use Thali after a change takes effect means you accept the updated policy.
Questions, requests, or a privacy concern: we would rather hear about it than not.
Thali
Operated by Upwan Chachra
Calgary, Alberta, Canada
Data controller for the purposes of the GDPR