Is My Food Data Private? How Nutrition Apps Handle Your Data
Quick answer: A food log is more sensitive than it looks. It contains your weight, your goals, patterns that reveal medical conditions, eating disorders, pregnancy, religion, and a timestamped record of where and when you eat. Most nutrition apps store all of that on their servers; some tie it to an advertising identity; a few have had breaches. Photo-based apps additionally send images of your meals — and whatever is around them — to a server for recognition. Before trusting an app, read its App Store privacy label, check whether it uses data for tracking or advertising, and find out what is stored versus what is processed and discarded. CalMePlease's approach: photos are processed for recognition, and your meal history, weight and statistics are stored on your device; the app does not sell or share your data.
Why a food log is health data
People treat calorie apps like a to-do list. Regulators increasingly do not. A log of what you eat, when, and how much you weigh can reveal, directly or by inference:
- weight and body-composition history
- diabetes, coeliac disease, allergies, kidney disease (from food restrictions and patterns)
- pregnancy (from a sudden change in goals and intake)
- disordered eating (from restriction patterns)
- religious and cultural practices (fasting, dietary laws)
- daily routine — when you wake, work, exercise, sleep
- location, if meals are logged with place data or photos contain background
In the EU this falls under GDPR's "special category" data once health can be inferred. In the US, it mostly does not fall under HIPAA — HIPAA covers healthcare providers, not consumer apps — which means the app's own privacy policy is the main protection you have.
Where the data actually goes
Cloud storage. The default model. Your log lives on the company's servers, tied to your account, and stays there until you delete the account — sometimes longer. This enables sync between devices and web access, and it means a breach or an acquisition changes who holds your history. MyFitnessPal's 2018 breach exposed around 150 million accounts.
Advertising and analytics SDKs. Free tiers are often funded by ads, and ad networks inside the app can receive device identifiers and behavioural signals. Apple's privacy labels distinguish "Data Used to Track You" (shared with third parties for advertising across apps) from "Data Linked to You" (kept by the app). The first category is the one to check.
Acquisitions. When one company buys another, the data goes with it. Cal AI's user base moved under MyFitnessPal's ownership in 2026; the policy that applies is now MFP's.
Photo processing. Every photo-recognition app sends the image to a server; on-device recognition exists but is less capable in 2026. The question is what happens after: is the photo discarded once the result is returned, retained to improve the model, or kept as part of your history? Most policies do not say clearly.
On-device storage. The alternative model: the log lives on your phone and in your own encrypted backup. Less convenient for multi-device sync; far less exposed.
What to check before trusting an app
Five minutes on the App Store page answers most of it:
- Privacy label, "Data Used to Track You". Should be empty. If it lists identifiers or usage data, your behaviour is feeding ad networks.
- Privacy label, "Data Linked to You". Health & fitness, contact info, identifiers and location are the ones that matter. Fewer is better.
- Privacy policy: retention. Search for "retain" and "delete." A good policy says when data is deleted and how you trigger it. A vague policy ("as long as necessary") is a warning.
- Privacy policy: photos. Search for "image" or "photo." Does it say what happens to the image after recognition?
- Ownership. Who owns the company, and were they recently acquired? The policy you agreed to may not be the one that applies now.
- Account deletion. Apple requires in-app account deletion. Check it exists and that the policy says deletion removes the data, not just the login.
How the major apps compare (2026)
Read the current privacy label for any app before deciding — these change with updates.
| App | Storage model | Ads on free tier | Notes |
|---|---|---|---|
| CalMePlease | Meal history, weight and stats on device | No | Photos processed for recognition; data not sold or shared |
| MyFitnessPal | Cloud account | Yes | 2018 breach (~150M accounts); owns Cal AI since 2026 |
| Cal AI | Cloud account | No | Under MyFitnessPal ownership; check current policy |
| Yazio | Cloud account | No | German company, GDPR-governed |
| Cronometer | Cloud account | No | Long-standing clear policy; paid model |
| Lose It! | Cloud account | Yes | Check tracking label |
How CalMePlease handles your data
Three principles, stated plainly so they can be checked:
- Your history lives on your device. Meal history, weight, and the weekly and monthly statistics are stored and built locally on your phone, not on a server you cannot see.
- Photos are processed, not kept. A photo or video is sent for recognition and the result comes back; the recognition is the purpose of the transfer, not building a profile.
- Nothing is sold or shared. No advertising SDKs, no data brokers, no "partners." The AI coach sees what it needs to answer your question and nothing more.
The App Store privacy label is the reference; if the label and this article ever disagree, the label wins and the article needs updating.
Practical steps regardless of app
- Photograph the plate, not the table — background can include documents, screens, faces, locations.
- Do not log with location enabled unless you use the feature.
- Use a strong, unique password or Sign in with Apple for any cloud-account app; food apps are breached like any other.
- Delete accounts you stop using, and confirm deletion in the policy, not just the login screen.
- Re-read the privacy label after any acquisition news.
FAQ
Do calorie counting apps sell your data? Some monetise free tiers through advertising SDKs that share device identifiers and behaviour. Check the App Store label under "Data Used to Track You." CalMePlease does not sell or share data.
Is food tracking data considered health data? Under GDPR, yes, once health can be inferred from it — and it usually can. Under US HIPAA, consumer apps are generally not covered; the app's own policy governs.
What happens to my photos in an AI calorie app? They are sent to a server for recognition. What happens after varies: discarded, retained for model training, or kept in your history. Look for "image" in the privacy policy; if it is not addressed, assume retention.
Is MyFitnessPal safe? It suffered a large breach in 2018 and runs ads on the free tier. Its current privacy label is the reference. It now also owns Cal AI.
Which calorie app keeps data on the device? CalMePlease stores meal history, weight and statistics on the device. Most mainstream apps use cloud accounts.
How do I delete my data from a nutrition app? Use the in-app account deletion (required by Apple), then check the policy for retention after deletion. If deletion is not in the app, that is itself a red flag.
Related: How AI food recognition works · CalMePlease vs MyFitnessPal · Free calorie tracker apps: what you actually get
CalMePlease keeps your food history on your device and does not sell or share your data. Free on the App Store.