Privacy Policy
Last updated: June 29, 2026
Bao ("we", "us", "our") is operated by Digital Publishing Co. This policy explains what data the Bao mobile app collects, how we use it, and your choices.
1. Data We Collect
Account information. Email address and password when you create an account (authenticated via Supabase).
Profile information you provide. Height, weight, health goal, dietary preferences, cuisine preferences, health conditions, and activity level. All of this is optional and stored locally on your device unless you choose to sync.
Meal and nutrition data. Food logs, photos you scan, barcode scans, menu scans, and nutrition information. Meal data is synced to your account so you can access it across sessions.
Health data (Apple HealthKit). If you grant permission, Bao reads and writes calorie, protein, carbohydrate, fat, and step data from Apple Health. This data is used solely to display your daily summary and sync logged meals. We never sell or share HealthKit data with third parties, and it is not used for advertising.
Photos. When you use the camera or photo library to scan food or menus, images are sent to our server for AI analysis, then discarded. Meal photos you choose to save are stored securely and tied to your account.
Usage analytics. We use PostHog to collect anonymous usage events (e.g., screens viewed, features used) to improve the app. No personal information is attached to these events.
Crash reports. We use Sentry to collect crash and error reports. These may include device model, OS version, and stack traces. No personal data is included.
Purchase information. Subscription status is managed by RevenueCat. We do not see or store your payment method. RevenueCat receives only the information Apple provides through the App Store receipt.
2. How We Use Your Data
- To provide nutrition tracking, meal logging, and AI-powered food analysis
- To personalize recommendations based on your health goals and dietary preferences
- To sync your data across sessions via your account
- To improve the app through aggregated, anonymous analytics
- To diagnose and fix crashes and bugs
3. AI Processing
When you scan food photos, menus, or use the AI coach, your data is sent to OpenAI's API for analysis. OpenAI processes this data according to their API data usage policy — API inputs and outputs are not used to train their models. We send only the minimum data needed: the image, your language preference, and relevant profile context (goal, dietary restrictions).
4. Data We Do Not Collect
- We do not sell your data to third parties.
- We do not serve ads or share data with ad networks.
- We do not track you across other apps or websites.
5. Data Sharing
We share data only with the following service providers, solely to operate the app:
- Supabase — authentication, database, and file storage
- OpenAI — food and menu image analysis, AI coaching
- RevenueCat — subscription management
- PostHog — anonymous usage analytics
- Sentry — crash reporting
- Apple App Store — app distribution and in-app purchases
6. Data Storage & Security
Your data is stored in Supabase (hosted on AWS). We use row-level security so each user can only access their own data. All communication is encrypted via HTTPS.
7. Your Rights
You can:
- View and edit your profile data within the app at any time
- Delete individual meals from your log
- Delete your account and all associated data by contacting us
- Revoke HealthKit permissions in iOS Settings at any time
- Opt out of analytics by contacting us
8. Children's Privacy
Bao is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has provided us personal information, please contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes through the app or by email. Continued use after changes constitutes acceptance.
10. Contact
Questions or requests? Email us at [email protected].