Privacy policy
Your diary stays
on your phone.
Cholesterol Tracker is built so that your food log and health data never need to leave your device. This page explains exactly what does get sent, where, and why.
Effective September 12, 2026
What you should know:
- No account. Your diary, goals, and reminders are stored only on your phone.
- Search and scans use our servers. Search text and food or label photos are sent to produce a result, and nothing else.
- Health data never leaves your device. Apple Health and Health Connect sync is optional, writes nutrition only, and reads back only what we wrote.
- Purchases go through Apple or Google. We never see your payment details.
- No selling, no ads. We do not sell personal information or share it with advertisers.
Section 01
Who we are and what this covers
Cholesterol Tracker is developed and operated by Abhinav Khanger (“we”, “us”). This policy explains what information the Cholesterol Tracker apps for iPhone and Android (the “apps”) and the website at cholesteroltracker.app (the “site”) collect, why, and the choices you have.
The apps do not require an account. We do not ask for your name, email address, or a password to use them, and we do not sell personal information to anyone.
Section 02
Data that stays on your device
Everything you enter in the app is stored locally on your phone in the app’s private storage. This includes:
- Diary entries: food names, serving sizes, quantities, meal, date, and nutrient values such as cholesterol.
- Saved foods, custom meals, and recipes you create.
- Your daily cholesterol goal, reminder times, and settings such as dark mode and Health sync preferences.
We cannot see this data. It is not uploaded to our servers. It may be included in your phone’s normal device backup (iCloud backup on iPhone, Google backup on Android) under the backup settings you control. Deleting an entry removes it from the diary, and uninstalling the app removes all local data.
Section 03
Data sent to our servers
Three features need a network request to work. Each request is sent over HTTPS to servers we operate and contains only what is needed to answer it.
| Feature | What is sent | What happens to it |
|---|---|---|
| Search Food | The search text you type. | Matched against third-party food databases (including USDA FoodData Central and FatSecret) to return results. |
| Snap Food | The photo you take or choose, plus any optional description you add. | Analyzed by an image-recognition service to produce a nutrition estimate that you review before logging. |
| Snap Nutrition Label | The photo of the label. | Processed to extract the printed serving and nutrient values, which you can correct before saving. |
Photos are used only to produce the estimate you asked for. We do not use them to build a profile of you, and we do not use them to train models. Please avoid including people, documents, or other sensitive content in a scan; only the food or label needs to be in frame.
To protect these services from abuse, each request includes an app-integrity token issued by Apple or Google (App Attest, Play Integrity via Firebase App Check). This token confirms the request comes from a genuine copy of the app; it does not identify you personally.
The result of a search or scan is saved to your diary only if you choose to log it, and then it is stored on your device as described above.
Section 04
Apple Health and Health Connect
The app can optionally connect to Apple Health on iPhone or Health Connect on Android. You choose whether to enable this during onboarding or later in Settings, and the app works fully without it.
What we write
When sync is on, each diary entry is written as a nutrition record containing its calories, dietary cholesterol, protein, carbohydrates, fat, and sodium, together with the food name and time. When you edit or delete an entry in the app, the matching record is updated or removed.
What we read
The app requests read access to nutrition records only so it can find and replace records it previously wrote. It does not read nutrition data written by other apps, and it does not read any other health data types.
Where it goes
Health data stays on your device. It is never transmitted to our servers or to any third party, it is not used for advertising or marketing, and it is not sold. Our use of information received from Health Connect and Apple Health is limited to providing the nutrition-sync feature you enabled. Use and transfer of information received from Health Connect adheres to the Health Connect Permissions Policy, including the Limited Use requirements.
You can revoke access at any time from the Health app (iPhone), the Health Connect app (Android), or from Settings › Health in Cholesterol Tracker. Revoking access stops future writes; records already written remain under your control in Health or Health Connect, where you can delete them.
Section 05
Purchases and subscriptions
Cholesterol Tracker Pro is sold through the App Store on iPhone and Google Play on Android. Apple or Google handles payment; we never receive your card number or billing address.
We use RevenueCat to check whether a purchase is active. RevenueCat receives a random identifier generated for your installation, the purchase receipt or token from the store, and basic device information. This lets the app unlock Pro, restore purchases on a new device, and diagnose billing problems. Apple’s and Google’s own privacy policies apply to the transaction itself.
Section 06
Analytics and crash reports
To understand which features are used and to fix crashes, the apps may use Firebase Analytics and Firebase Crashlytics from Google. These collect device model, operating system version, app version, coarse location derived from IP address, a random installation identifier, and events such as which screens were opened or whether a scan succeeded.
Diary contents, food photos, and Health data are never included in analytics or crash reports. We also use Firebase Remote Config to adjust app settings without an update; it sends the same basic device information.
Section 07
Device permissions
| Permission | Why we ask |
|---|---|
| Camera | To photograph food or a nutrition label for Snap Food and Snap Nutrition Label. Photos are captured only when you tap the shutter. |
| Photos | To let you choose an existing picture for a scan. Only the picture you select is used. |
| Notifications | To deliver the meal-logging reminders you schedule. Reminders are created on your device and are not sent through our servers. |
| Health / Health Connect | To write nutrition records and reconcile the ones we wrote, as described above. |
Section 08
The website
cholesteroltracker.app is a static site. It does not set tracking cookies, run advertising, or use analytics scripts. The hosting provider (Cloudflare) keeps standard server logs, such as IP address, browser type, and the pages requested, for security and operational purposes.
Emailing us at metacortexlab@gmail.com shares your email address and message with us so we can reply. We keep support correspondence only as long as needed to resolve your request.
Section 09
Service providers
We share data only with the providers needed to run the features described above, and only for that purpose:
- Apple and Google: app distribution, payments, app-integrity checks, and Health / Health Connect on your device.
- Google Firebase: analytics, crash reporting, remote configuration, and App Check.
- RevenueCat: purchase and subscription status.
- Food database and image-analysis providers: answering search and scan requests routed through our servers.
- Cloudflare: hosting for the website and its server logs.
We do not sell personal information and do not share it with advertisers or data brokers.
Section 10
Retention, deletion, and your rights
Diary and Health data live on your device for as long as you keep them. Search and scan requests are handled in real time and are not linked to a user account. Analytics and crash data are retained by Firebase for up to 14 months by default, and purchase records are kept for as long as needed to honor your purchase and meet accounting obligations.
Depending on where you live, you may have the right to access, correct, delete, or export personal data, or to object to certain processing. Because we hold no account for you, most data can be deleted directly by removing entries or uninstalling the app. For anything else, email metacortexlab@gmail.com and we will respond within 30 days.
Section 11
Children
The apps and site are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
Section 12
Security
All network traffic between the apps and our servers uses HTTPS. Requests carry app-integrity tokens so that only genuine copies of the app can reach the search and scan services, and provider credentials are kept server-side rather than in the app. No method of transmission or storage is completely secure, but we work to protect the limited data we handle.
Section 13
Changes and contact
We may update this policy as the apps change. The effective date at the top shows the latest revision, and material changes will be highlighted in the app or on this page.
Questions or requests: metacortexlab@gmail.com. See also our Terms of Service.