UptakeX Privacy Policy
Effective date: September 10, 2026
Last updated: September 10, 2026
1. Who We Are
UptakeX is a nutrition and body-composition tracking app for iOS and the web.
It is operated by Arhan Barve ("we", "us"), an individual developer based in the
United States.
2. Where UptakeX Is Offered
UptakeX is offered in the United States only. We do not offer the app in the
European Economic Area, the United Kingdom, or Switzerland, and this policy does
not make GDPR or UK GDPR commitments. If you are outside the United States,
please do not create an account.
UptakeX is also Harvard only. Creating an account requires an email address
at one of the Harvard mail domains our database lists, and that check runs on
our server, not only in the app. An address at any other domain is refused at
sign-up, and changing your address later to a non-Harvard one is refused too.
3. The Short Version
- We collect the health and nutrition data you enter, plus two metrics you
choose to share from Apple Health, plus daily metrics from a wearable if you
connect one.
- Signing up requires a Harvard email address, and we keep a record that yours
was verified.
- If you use the Friends features, a friend sees your handle, your display name,
your House, and two weekly counts. They never see your calories, your weight,
your targets or your food log. A meal you choose to share is the one exception,
and only the friend you send it to receives it.
- We do not sell your data, share it for advertising, or use it for advertising,
marketing or data mining. There is no analytics SDK, no crash reporter and no
advertising SDK in the app.
- Health data read from Apple Health is never written to iCloud by us, and we
never write anything back into Apple Health.
- Food text you log, and your Ask conversations, are sent to AI providers
(OpenAI and Groq) so the app can turn them into structured entries.
- You can export your data and delete your account from inside the app.
4. Data We Collect
4.1 Account Information
- Email address and a password. Passwords are handled by our authentication
provider (Supabase Auth) and stored only as a salted hash. We never see your
plaintext password.
- Account timestamps (created, last sign-in, email confirmation, password reset
events) and the session tokens your device holds to stay signed in.
- Your verified Harvard affiliation. When you confirm your email address, we
write one row recording that it was proven: the method (an email domain), the
domain itself, the Harvard school that domain implies where it implies one,
and the time it was verified. That row is readable only by you, and no client
can write it. We do not store a HUID or any other Harvard identifier.
UptakeX does not offer social or third-party sign-in, so we receive no data from
Google, Facebook, Apple ID or any other identity provider.
4.2 Body And Profile Data You Enter
- Sex, age, height, and current weight.
- Neck and waist circumference (used to estimate body fat, see the Health and
Fitness Disclaimer).
- Goal type (cut, maintain or bulk) and target rate of weight change per week.
- Gym days per week, how intense those sessions are, an estimate of your
typical daily step count, and how active your day job is.
- Diet style and dietary restrictions, as free text you write yourself.
- If you use the campus-dining feature, which dining location you eat at.
4.3 Logs And Entries You Create
- Food entries: the food name, quantity, the time you ate, calories,
protein, carbohydrate, fat, saturated fat, fiber, sodium and sugar, a
confidence rating and calorie range, meal grouping and labels, an icon
category, your notes, and the raw text or transcript you originally submitted.
- Saved foods (presets): name, default quantity, nutrition values, barcode
where you scanned one, how often you have used it, and when you last did.
- Weight logs: date and weight.
- Water logs: date, time and volume.
- Step logs and active-energy logs: date, value, and which device or app
measured it.
- Wearable data, if you connect a wearable: we support Garmin, Oura, Fitbit,
Withings and Polar through Terra (see section 6.5). For each day each connected
device reports, we store the device name, steps, distance, active calories,
basal calories, resting heart rate, heart-rate variability, VO2 max, minutes
asleep, and whether the entry was manually uploaded. We also store the
connection itself: the provider, the identifier Terra assigns you, the
permissions you granted, and when it was connected or ended. Connecting a
wearable is optional and you can disconnect it.
- Goals and targets: your calorie, protein, carbohydrate, fat, fiber,
saturated fat, sodium and sugar targets, and the maintenance-calorie estimate
they were derived from.
- App settings and feature state: notification preferences, and the state of
the adaptive-calibration feature (its last check date, its current suggestion,
and whether you dismissed it).
4.4 The Friends Features
UptakeX has a small social layer. Nothing in it gives another person access to
your logs. These are the rows it creates, and exactly who can read each one.
- Your social profile: a handle you choose, a display name, and your House
if you pick one. Your handle, display name and House are visible to people you
are already friends with, and to someone who types at least the first three
characters of your handle in search. You can turn that discovery off, after
which typing your handle exactly is the only way to find you. The profile also
holds two switches only you can see: whether you take part in the weekly
board, and whether the app hides calorie numbers from you and scores you on
consistency alone.
- Your friendships: one row per pair of people, holding who asked, whether
the request is pending, accepted or blocked, and whether either side has
hidden the other. Only the two people named in a friendship can read it.
- Your daily score: one row per day, holding whether you logged a complete
day, whether your calories landed inside your band, an adherence figure from
0 to 100, whether you were over or under on a day you missed, how many meals
you logged, and whether you hit your protein target. It holds no calorie
amount, and no other account can read it.
- The weekly board: a friend you have not hidden, and who has not turned
competition off, sees your display name, your handle, your points for the
week, how many days you hit protein, and how many days you logged anything.
Nothing else about you is in it. Your calories, your targets, your adherence
figure and whether you missed over or under are all deliberately left out, so
that nothing on the board rewards eating less.
- Meals you share: when you send a meal to a friend, we copy the food name,
the quantity, the calories, the protein, the carbohydrate, the fat, an icon
and a meal label into a separate row addressed to that one friend. It is a
copy rather than a link, so the friend never reads your food log, and the
share survives you editing or deleting your own entry. Only you and that
friend can read it, and you can only share with a friend who has accepted you.
- Your eating-disorder screening result: a single yes or no, stored on your
social profile. The individual screening answers are not stored. The result is
never shown to anyone but you: no function or view in our database returns it
to another account, and it appears in no board, no friend list and no search.
- Safety flags: a nightly job reads your own daily scores for patterns that
suggest restriction or disengagement, and may write a private flag with a
short plain-language reason. Flags are visible only to you, no client can
create one, and no other account can read them.
4.5 Voice, Camera And Text Input
- Voice: when you dictate a food log, the audio clip is uploaded to Groq
for speech-to-text and the resulting transcript is stored with your entry. See
section 6.
- Camera: the camera is used only to read barcodes on food packaging. The
barcode is decoded on your device, and only the digit string leaves it. No
image is ever uploaded, stored or transmitted, and we do not use the camera
for body photos or progress photos.
- Ask chat: your messages and the assistant's replies are stored on your
device. See section 4.7.
4.6 Apple Health (HealthKit) Data
With your permission, UptakeX reads exactly two HealthKit data types, and
nothing else:
| HealthKit type | What it is | Why we read it |
|---|
HKQuantityTypeIdentifierStepCount | Daily step count | Feeds the daily hydration target and the activity-based calorie bonus |
HKQuantityTypeIdentifierActiveEnergyBurned | Active energy burned, in kcal | Used in place of the step model to compute the activity-based calorie bonus when a wearable has measured it |
Facts about our HealthKit use, stated explicitly because Apple's App Review
Guideline 5.1.3 requires it:
- We read only. We never write to HealthKit. UptakeX requests no HealthKit
write permission and contains no code that writes health data back to Apple
Health.
- HealthKit data is never used for advertising, marketing, or data mining.
We run no advertising, we have no advertising or marketing partners, and we do
not analyze, aggregate, resell or mine HealthKit data for any purpose other
than showing you your own numbers and computing your own targets.
- HealthKit data is never stored in iCloud. We do not use CloudKit, iCloud
Documents, iCloud Drive or iCloud Key-Value storage for any data. HealthKit
data read by UptakeX is stored on your device and in our database (see section
5). The small day summary shared with the home-screen widget is written to the
device keychain without the iCloud-synchronizable attribute, so it stays on
that one device.
- HealthKit data is never disclosed to a third party for their own purposes.
Step and energy values are not included in what we send to OpenAI or Groq. Step counts do influence the numbers you see (targets and bonuses), and
those computed targets can appear in an Ask conversation.
- HealthKit access is optional. Declining it, or turning individual types off in
the Health app, disables the features that depend on them and nothing else.
You can revoke access at any time in Settings, then Privacy and Security, then
Health.
4.7 Data Stored On Your Device
- Your signed-in session token.
- Your recent Ask conversation history.
- Two timestamps recording whether the first-run Apple Health backfill has
completed.
- A small snapshot of today's numbers (the date, calories eaten and your calorie
target, water drunk and your water target, whether you have weighed in, your
steps, your recent meal names with their icon and calories, and the title and
time of your next reminder) so the home-screen widget can render without
launching the app. This is stored in the device keychain, restricted to
UptakeX, and not synchronized to iCloud. Signing out overwrites it with an
empty day.
Data in the app's own storage may be included in an encrypted backup you choose
to make of your iPhone. That backup belongs to you and is made by Apple at your
direction, not by us.
4.8 What We Do Not Collect
Being specific about absences matters more than being vague about presence. We
do not collect:
- Precise or coarse location, and the app requests no location permission.
- Your contacts, calendar, photo library, microphone audio outside an explicit
dictation you start, or camera images.
- The Advertising Identifier (IDFA). We do not use the App Tracking Transparency
framework because we do not track you across apps or websites.
- Any advertising, marketing or attribution SDK, any analytics SDK, and any
crash-reporting SDK. There are none in the app. We collect no usage data and
no diagnostics.
- A device push token. Reminders are local notifications scheduled on your own
phone, and no notification content leaves it.
- Biometric identifiers, face or fingerprint data. If you use Face ID or Touch
ID to unlock your phone or authorize a purchase, that happens entirely within
iOS and we never see it.
- Payment card numbers, bank details or billing addresses. See section 6.6.
- Clinical records, lab results, prescriptions, diagnoses, blood pressure,
glucose, menstrual or reproductive health data, or any HealthKit type beyond
the two named in section 4.6. We do receive a resting heart rate and a
heart-rate variability figure if you connect a wearable that reports them, and
that is described in section 4.3.
- Browsing history, search history outside the app, or any data purchased from a
data broker. We do hold a social graph, which is the friendships you create
yourself and nothing else. We do not read your phone's contacts, and we do not
import a social graph from anywhere.
We do not sell your personal information, we do not share it for cross-context
behavioral advertising, and we do not use it to build advertising profiles.
5. Where Your Data Lives
Your account and all of your logs are stored in a Postgres database hosted by
Supabase in the United States. Rows are protected by row-level security so
that a signed-in account can read and write only its own data. Data is encrypted
in transit (TLS) and at rest by the hosting provider.
6. Third Parties Who Receive Data
We use a small number of processors. Each one is listed below with exactly what
it receives and why. None of them is permitted to use your data for their own
advertising or marketing.
6.1 Supabase (Database, Authentication, Serverless Functions)
- Receives: everything in section 4.1 through 4.4. Supabase is the hosting
provider for our database and authentication, so it holds all of it.
- Why: it is where your account and your logs live.
- Location: United States.
- Privacy policy: https://supabase.com/privacy
6.2 OpenAI (Food Parsing, Nutrition Research, Ask Chat)
OpenAI receives text, never audio, never images, and never your email address or
account identifier. Three separate flows send data to OpenAI:
- Food log parsing. The raw text of the food you logged, your saved foods
list, your recent food entries (used to group items into meals), and your
saved portion conventions.
- Nutrition research. For food that cannot be matched to a label database,
a description of the dish, its brand or restaurant chain, and its components
are sent to a model that uses OpenAI's hosted web-search tool. This means a
description of what you ate is used to run web searches through OpenAI.
- Ask chat. Each time you send a message, we send your message history plus
a snapshot of the last 30 days of your data: every food entry with its
nutrition and each day's totals against your target, your calorie and
macronutrient targets, your profile (age, sex, height, weight, your goal type
and rate, and your diet style and restrictions), and your weight logs. Your
friends, your shared meals, your weekly board and your screening result are
not in it.
- Why: turning free text into structured nutrition data, and generating the
Ask answers.
- Retention, stated honestly: OpenAI's standard API terms state that API
data is not used to train their models by default, and that API inputs and
outputs may be retained for up to 30 days for abuse and misuse monitoring
before deletion, unless a Zero Data Retention arrangement is in place. The Ask
chat requests are sent with storage disabled, which keeps them out of
OpenAI's dashboard logs, but that is not the same thing as zero retention.
[OWNER TO CONFIRM: whether a Zero Data Retention agreement has been arranged
with OpenAI for this account. If it has not, this section must say so plainly
and state the 30-day abuse-monitoring retention as the operative position. If
it has, state the effective date and drop the 30-day language. Do not publish
this document with this placeholder unresolved.]
- Privacy policy: https://openai.com/policies/privacy-policy
6.3 Groq (Speech-To-Text)
- Receives: the audio clip you recorded, and a short list of your recent
food names used to bias the transcription toward the brands and words you
actually use. No account identifier, no email address, no body metrics.
- Why: converting dictation into text you can log.
- Retention: [OWNER TO CONFIRM Groq's current data-retention and
training-use position for API audio, and state it here. Do not publish a claim
about Groq retention that has not been checked against their current terms.]
- Privacy policy: https://groq.com/privacy-policy/
6.4 Food Databases
When you scan a barcode, the lookup is made by your phone directly, not by
our server. That means the host sees your device's IP address alongside the
barcode digits. No account identifier, no email address and nothing else about
you is attached.
- Open Food Facts (a nonprofit open database) receives a barcode number,
from your phone.
- USDA FoodData Central (an agency of the United States Department of
Agriculture) receives a barcode number from your phone. It separately
receives a food search string (for example a brand and product name) from
our server while a log is being parsed. That second request comes from us, not
from your phone, and carries no identifier either.
- Why: to read the published nutrition panel for a packaged product so we do
not have to guess it.
6.5 Terra (Wearable Connections)
Terra is the service that connects a Garmin, Oura, Fitbit, Withings or Polar
account to UptakeX. It is used only if you connect one.
- Receives: your Supabase account identifier, sent as a reference so that
reconnecting the same wearable updates your existing connection rather than
creating a second one, and the list of providers we offer. No email address,
no name, and none of your logs are sent to Terra.
- Sends us: the daily metrics listed in section 4.3, delivered to our server
as webhooks. We keep the raw webhook body for 30 days for replay protection
and for debugging a backfill, and we delete it sooner than that if you
disconnect the provider or delete your account. See section 8.
- Why: reading a wearable's numbers without asking you for that vendor's
password.
- Privacy policy: https://tryterra.co/privacy-policy
6.6 Apple And Subscription Purchases
- Apple processes all subscription purchases. Apple, not us, collects and
holds your payment details. We receive from Apple only the fact that a
subscription is active, its product identifier, and its renewal or expiry
date. We never see your card number, billing address or Apple ID password.
- There is no third-party subscription or receipt-validation service in the
app. No purchase SDK of any kind is bundled with it.
6.7 Campus Dining Menus
The app can show published dining-hall menus and their nutrition information.
Those menus are pulled from Harvard University Information Technology's dining
API by our own server on a daily schedule. Each request carries one dining
location number and our API key, and nothing else. No user data is sent to the
dining provider. We do not tell them who you are, what you ate, or that you
looked at a menu, and your phone never contacts them directly.
6.8 Apple App Store And Expo
- Apple provides aggregate, non-identifying App Store analytics (downloads,
crashes, retention) to us as the developer. This comes from Apple, not from
code in our app.
- Our app is built with the Expo toolchain. Expo's build service handles our
source code and build artifacts, not your data.
7. Why We Process Your Data
We process your data only to:
- Operate your account and keep you signed in.
- Store the logs you create and show them back to you.
- Compute your targets, trends and analytics.
- Turn your text and dictation into structured entries.
- Answer your questions in the Ask tab.
- Confirm that you are at Harvard, which is who the app is currently for.
- Show you and the friends you have added the weekly board, and deliver a meal
you choose to send to a friend.
- Notice patterns in your own logging that suggest calorie tracking is going
badly for you, and show you resources.
- Send you the reminders you have turned on.
- Determine whether your subscription is active.
- Detect and prevent abuse, and keep the service running.
We do not process your data for advertising, marketing, profiling for
third parties, or resale, and we do not use your content to train AI models of
our own.
8. How Long We Keep Your Data
- Your logs and profile are kept until you delete them. We run no automatic
expiry on your data, because a nutrition history is only useful over time.
- Deleting your account deletes your data. See section 9.
- Queued log requests (the raw text of a food log while it is being
processed) are stored alongside your entries and are deleted with them.
- Raw wearable webhooks. The unprocessed body of each webhook Terra sends
us is kept for 30 days and then deleted by a nightly job. The same job
deletes it immediately if you have disconnected that provider or deleted your
account, so in that case it goes on the next nightly run rather than waiting
out the 30 days.
- Dining menu data is a cache of the provider's public menu and is not
personal data. It is pruned on a schedule.
- Backups. Our database provider takes point-in-time backups for disaster
recovery. Deleted data may persist in those backups for up to
30 days before the backups themselves age out.
- Third-party retention is governed by the third party. See section 6.
9. Your Choices And Rights
9.1 Export Your Data
In the app: Settings, then Export Data. It builds a JSON file and hands it to
the iOS share sheet, so you can save it to Files, mail it to yourself, or send
it anywhere else. It covers your whole history, with no date cutoff: your
profile, your goals, your food entries, the raw text of your log requests, your
weight, water, step and active-energy logs, your saved foods, your portion
conventions, your app settings, and your adaptive calorie state. If any part of
it fails to read, the whole export is refused rather than handed to you looking
complete.
On the web: Settings, then Export JSON or Export CSV. The web export is
deliberately narrower than the app's. JSON covers your profile, goals, food
entries, daily totals, weight, water and step logs, and CSV is one row per food
entry for a spreadsheet. Both cover the last 365 days, except weight, which is
exported in full. For a complete backup, use the app.
What neither export covers, stated plainly rather than left for you to
discover: your social profile, your friendships, your daily scores, the meals
you have shared or been sent, your safety flags, your Harvard affiliation
record, and your wearable connections and their daily data. If you want a copy
of any of those, email privacy@uptakex.app and we will produce it.
9.2 Delete Your Account
Settings, then Delete Account. You confirm by typing the word DELETE, because a
single tap is too easy to make by accident. This permanently and irreversibly
deletes your authentication record and, by database cascade, every row of your
data in our database, including your social profile, your friendships, your
shared meals, your safety flags, your Harvard affiliation record and your
wearable data. It is a hard delete, not a flag, there is no grace period and no
recovery window, and you are signed out immediately. The same path is available
on the web at https://uptakex.app/settings without needing the app.
The one thing that is not removed by that cascade is the raw wearable webhook
bodies described in section 8, because they are keyed by the identifier your
wearable provider uses rather than by your account. The nightly job deletes them
on its next run.
Deleting your account does not cancel an active subscription, because Apple
holds the subscription, not us. Cancel it in the App Store first. See the Terms.
9.3 Delete Your Data But Keep Your Account
Settings, then Delete All Data. You confirm by typing DELETE here too. In one
transaction this erases your food entries, the raw text of your log requests,
your adaptive calorie state, your app settings, your active-energy logs, your
goals, your portion conventions, your saved foods, your step logs, your water
logs, your weight logs and your profile, while your account and your sign-in
stay. It is available in the app and on the web.
This is narrower than deleting your account, and here is exactly what it
leaves behind: your social profile including your handle, display name, House
and screening result; your friendships; your daily scores; meals you have shared
or been sent; your safety flags; your Harvard affiliation record; and your
wearable connections and their daily data. If you want those gone too, delete
your account, which removes everything. Two further things are kept on purpose:
your entitlements row, which is the record of what you have paid for, and
today's usage counters, so that erasing your logs does not double as a way to
reset the daily limit on AI features. This cannot be undone.
9.4 Correct Your Data
Every log in the app is editable or deletable individually, and your profile and
goals can be edited in Settings.
9.5 Turn Off Data Sources
- Revoke Apple Health access in iOS Settings, then Privacy and Security, then
Health.
- Revoke microphone or camera access in iOS Settings for UptakeX.
- Disconnect a wearable in Settings, which stops Terra sending us anything more
and makes the raw webhook bodies we still hold eligible for deletion on the
next nightly run.
- Turn off discovery, or turn off competition, on your social profile, and
remove or hide a friend on the Friends tab.
- Turn off notifications in Settings.
9.6 California Residents
If you are a California resident, the CCPA as amended by the CPRA gives you the
right to know what personal information we collect and why, to access a copy of
it, to correct it, to delete it, and not to be discriminated against for
exercising those rights. The app's export, edit and delete features are the
fastest way to exercise all of them. You may also email privacy@uptakex.app.
We do not sell personal information and we do not share it for cross-context
behavioral advertising, so there is nothing to opt out of. We collect
categories that California law treats as sensitive personal information: health
data, and the eating-disorder screening result in section 4.4. We use them only
to provide the service you asked for, which is a permitted purpose, and not to
infer characteristics about you for any other end.
You may designate an authorized agent to make a request for you. We will ask for
written proof of authorization and enough information to verify your identity
against your account.
9.7 Other States
Residents of other states with comprehensive privacy laws have similar rights.
Email privacy@uptakex.app and we will honor a request that the law entitles you to,
regardless of where you live in the United States.
10. Security
- All traffic between the app and our servers uses TLS.
- Every table enforces row-level security so an account can reach only its own
rows. The social features do not relax that. A friend reaches nothing of yours
directly; the weekly board and the friend list are narrow database functions
that return a fixed handful of columns, and a meal share is a copy addressed
to one person rather than a window into your log.
- Passwords are stored only as salted hashes by our authentication provider.
- Data is encrypted at rest by the hosting provider.
- API keys for our AI providers are held server-side. The app never carries
them. It calls our own server, which holds the keys and calls the provider on
your behalf. The one exception is the key for the USDA FoodData Central food
database, which ships in the app because it is a free, public, read-only key
that the USDA issues for exactly that purpose. It gives access to a public
government food database and to nothing of yours.
No system is perfectly secure, and we cannot guarantee that a determined
attacker will never succeed. If you believe you have found a vulnerability,
email security@uptakex.app.
11. If There Is A Data Breach
UptakeX handles health information drawn from more than one source, including
Apple Health, so we treat ourselves as a vendor of personal health records under
the Federal Trade Commission's Health Breach Notification Rule (16 C.F.R. Part
318, as amended in 2024).
If we discover a breach of security involving your unsecured individually
identifiable health information, we will:
- Notify you without unreasonable delay and in no case later than 60 calendar
days after discovering it, by email to the address on your account, and by a
prominent notice in the app and on our website.
- Notify the Federal Trade Commission within the time the Rule requires.
- Notify prominent media outlets in a state or jurisdiction if the breach
involves the unsecured health information of 500 or more residents of it.
- Tell you, as best we can determine it, what happened, when, what categories of
information were involved, what we are doing about it, what you can do to
protect yourself, and how to reach us.
We will also comply with any applicable state breach-notification law.
12. Children
UptakeX is not for children. You must be at least 13 years old to create an
account, and we do not knowingly collect personal information from anyone under
13. If you believe a child under 13 has created an account, email
privacy@uptakex.app and we will delete it and its data.
Because the app calculates calorie targets and can suggest a calorie deficit, we
do not consider it appropriate for minors without the involvement of a parent,
guardian or clinician. See the Terms for the age requirement to agree to them.
13. Automated Decisions And AI Content
The app uses AI models to read your text, estimate the nutrition of what you
ate, and write answers in the Ask tab. Those outputs can be wrong. They are estimates and general information, not professional
advice, and they are not a decision about you with legal or similarly
significant effects. See the Health and Fitness Disclaimer.
14. Changes To This Policy
If we change this policy in a way that materially affects how we handle your
data, we will update the date at the top, post the new version at
https://uptakex.app/privacy, and notify you in the app before the change takes
effect. Continuing to use UptakeX after that means you accept the updated policy.
15. Contact
Arhan Barve
privacy@uptakex.app
Appendix: Still Open
Everything else in this document is filled in and factual as of the effective
date above. What remains:
- A postal address. Some state privacy laws and some app stores expect one.
The contact section names privacy@uptakex.app, which reaches a person.
- A lawyer has not reviewed this. It was written from the source code to be
accurate about what the software does, which is a different thing from being
legally sufficient.
- The 30 day backup window in section 8 is our commitment, not a quoted
figure from the database provider's plan. Confirm it against the plan in use.