top of page

Privacy Policy

Last updated: 12 July 2026

This Snax Privacy Policy explains how we collect, use, disclose and protect personal data when you use Snax, our subscription-based native iOS wellness application, and associated websites, services and communications (together, Snax). It applies to processing subject to the UK GDPR and the EU GDPR and is governed by English law.

Snax allows users to create an account; log meals; search foods; scan barcodes; scan nutrition labels; photograph meals; record symptoms; record wellbeing check-ins; analyse nutrition; and generate personalised observational food–symptom associations. Snax is a wellness product. It is not a medical device, diagnostic tool, and is not intended to diagnose, prevent, monitor, predict, treat or cure disease.

If you have any questions, please contact us at contact@thesnaxapp.com.

1. Who we are and how to contact us
Snax is the controller of your personal data for the purposes of the UK GDPR and, where applicable, the EU GDPR.

You can contact us at:
Email: contact@thesnaxapp.com

2. Scope
This policy covers personal data processed through:
a) the Snax iOS mobile application built in SwiftUI;
b) our backend services hosted on Firebase (including Firebase Authentication, Firestore, and Firebase Storage);
c) our API layer;
d) third-party services integrated to provide Snax features, as described below; and
e) our communications and support channels.

3. About Snax and the data we process
Snax helps you record and reflect on your nutrition and wellbeing and to generate personalised, observational food–symptom associations. To deliver these features we process the following categories of personal data:

a) Account and identification data: email address; authentication credentials; subscription status; device identifiers required for security; crash reports; support correspondence.

b) Wellness and usage data: food diary; meal photographs; nutrition label photographs; optional profile photographs; symptoms; daily reflections; wellbeing check-ins; energy; stress; sleep quality; activity; food search history.

c) Payment and subscription data: processed through Apple In‑App Purchases. We receive limited subscription status information from Apple to operate your access. We do not receive your full payment card details.

d) Technical data: device and app identifiers, IP address, operating system and version, app version, logs required for security, reliability and diagnostics.

e) Future wearable integrations (optional): if and when enabled by you in future versions, authorised metrics from providers such as Oura, WHOOP, Apple Health, Garmin or Fitbit, which may include sleep, recovery, heart rate variability, resting heart rate, activity, workout information, readiness, body temperature and other wellness metrics you explicitly authorise.

Special category data: Health-related information, including information about food intake, symptoms, wellbeing information, and wearable wellness metrics, constitutes special category data under the UK GDPR and EU GDPR.

Children: Snax is intended for users aged 16 and over. We do not knowingly collect personal data from individuals under 16. If you believe a person under 16 has provided personal data to us, please contact us so that we can delete it.

4. Third-party services and integrations
To provide Snax, we use the following services:

a) Firebase (Google): authentication, cloud storage and database (Firebase Authentication, Firestore, Firebase Storage).

b) Cloudflare Workers: API layer that holds API secrets, provider credentials and routing logic. No API secrets are stored in the mobile application.

c) Edamam: meal photo recognition, food identification and nutrition estimation. Meal photographs and minimal necessary metadata are transmitted to execute the requested feature.

d) Anthropic Claude: optical character recognition of nutrition labels and extraction of structured nutrition information from photographs of food packaging. Only the minimum required content is sent to perform the requested feature. No AI-generated medical advice is provided.

e) MyFood24: food search database and barcode lookups. FatSecret may be used temporarily during migration, but MyFood24 is intended to become the permanent provider.

f) Apple: subscriptions, payments and App Store distribution. Apple processes payments made via In‑App Purchases and provides subscription status signals to Snax.

Future integrations: From time to time we may integrate additional providers to support optional features, for example Oura, WHOOP, Apple Health, Garmin and Fitbit. We will only retrieve metrics you authorise, and we will request separate consent where required for special category data.

5. Purposes and lawful bases for processing
We process personal data for the following purposes and on the following lawful bases. Where data includes special category data, we rely on your explicit consent, or another applicable condition, as indicated.

a) Create and manage your account; authenticate users; provide and operate Snax features; sync data across sessions and devices; maintain service functionality and reliability. Legal basis: performance of a contract with you (Article 6(1)(b)). For special category data processed for core wellness features: your explicit consent (Article 9(2)(a)).

b) Generate personalised observational insights; analyse nutrition; provide optional pattern recognition and associations between foods and reported symptoms. Legal basis: performance of a contract (Article 6(1)(b)) and/or legitimate interests in improving user experience (Article 6(1)(f)) where appropriate. For special category data: your explicit consent (Article 9(2)(a)). Insights identify possible associations only and are not evidence of causation or medical advice.

c) Process subscriptions and entitlements; manage access rights and eligibility. Legal basis: performance of a contract (Article 6(1)(b)). Payment processing is conducted by Apple acting as its own controller.

d) Provide user support; respond to enquiries; handle complaints. Legal basis: performance of a contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) in resolving issues. For special category data disclosed in support interactions: your explicit consent (Article 9(2)(a)).

e) Ensure security, prevent fraud and abuse, protect accounts and our services; maintain logs and audit trails. Legal basis: legitimate interests (Article 6(1)(f)) and compliance with legal obligations (Article 6(1)(c)) where applicable. For special category data, we limit processing to what is strictly necessary and rely on your explicit consent where needed.

f) Improve reliability, performance, stability and user experience; develop new features; conduct analytics on a de‑identified or aggregated basis where feasible. Legal basis: legitimate interests (Article 6(1)(f)). We take steps to minimise the use of personal data and to use aggregated or de‑identified data where possible. For special category data, we rely on your explicit consent where required and otherwise use aggregated or de‑identified data.

g) Compliance with legal obligations, regulatory requirements, and the exercise or defence of legal claims. Legal basis: compliance with legal obligations (Article 6(1)(c)) and legitimate interests (Article 6(1)(f)). For special category data: the establishment, exercise or defence of legal claims (Article 9(2)(f)) or as otherwise permitted by law.

Where we rely on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal. You can manage certain consents in the app settings and by contacting us.

6. AI processing and automation
Snax uses third-party AI services solely to provide specific requested features:

a) Meal photographs are processed with Edamam to identify foods and estimate nutrition. Only the minimum data necessary is transmitted, and processing is limited to executing your request.

b) Nutrition label photographs are processed using Anthropic Claude to perform OCR and extract structured nutrition information from photographs of food packaging. Only the minimal required data is sent for this purpose.

Snax does not provide medical advice. AI outputs are for wellness and informational purposes only and must not be relied upon for diagnosis or treatment. Snax does not currently train AI models on user data. If this changes, we will update this policy and seek explicit consent where required.

7. Future wearable integrations
If you choose to connect Snax to a wearable or health data provider in the future:
a) separate consent will always be requested before any wearable or health data is accessed;
b) you can disconnect at any time in Snax or via the third-party provider;
c) only the metrics you authorise will be retrieved;
d) wearable data will be used only to provide personalised wellness insights within Snax;
e) wearable data will never be sold; and
f) wearable data will not be used to train AI models without your explicit consent.

8. Disclosures of personal data
We disclose personal data to:
a) service providers acting on our instructions (processors), including Firebase (hosting, authentication, storage), Cloudflare (API layer), Edamam, Anthropic Claude, MyFood24 and, if applicable during migration, FatSecret;
b) Apple, which processes App Store distribution and In‑App Purchases as an independent controller;
c) professional advisers (lawyers, accountants, insurers) under confidentiality duties;
d) prospective buyers, investors or partners in connection with corporate transactions, subject to appropriate confidentiality protections; and
e) authorities, regulators or courts where required by law or necessary to protect our rights or the rights of others.

We do not sell personal data or health data. We do not use your data for advertising.

9. International data transfers
Some of our providers are located outside the UK and the EEA, or process data in multiple regions. Where we transfer personal data internationally, we ensure appropriate safeguards are in place in accordance with the UK GDPR and the EU GDPR, including:
a) adequacy regulations/decisions where applicable;
b) the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
c) the EU Standard Contractual Clauses, as applicable; and
d) additional technical and organisational measures to protect the data, such as encryption in transit and at rest and strict access controls.

Details of specific transfer mechanisms can be provided upon request.

10. Security
We take security seriously and implement technical and organisational measures designed to protect personal data:

a) Encryption in transit: All communications between the app and our backend services are protected using TLS. API calls to third-party providers are encrypted in transit.

b) Encryption at rest: Data stored in Firebase Firestore and Firebase Storage is encrypted at rest using industry-standard encryption provided by the platform.

c) Authentication and access controls: We use Firebase Authentication to manage user sign‑in. Access to production systems is limited to authorised personnel on a least‑privilege basis with multi‑factor authentication. Role‑based access controls, audit logging and key separation are applied.

d) Secure API credentials: API secrets and provider credentials are stored and managed in Cloudflare Workers secrets and related secure storage. No API secrets are embedded in or stored within the mobile application.

e) Network and application security: We employ secure coding practices, dependency management, and platform security features. We monitor for anomalies and misuse using server-side logs.

f) Firebase security: Firestore and Storage security rules restrict access to authenticated users and enforce per‑user data segregation, with server-side validation for sensitive operations.

g) Backups and resilience: We maintain backups of critical data within our cloud providers to support continuity and recovery. Backups are encrypted and retained for limited periods described below.

h) Logging and monitoring: We maintain logs for security, reliability and diagnostics, with retention limits and access controls. We review logs in connection with incident response.

i) Incident response: We maintain processes to detect, investigate and remediate security incidents. Where required, we will notify affected users and regulators in accordance with applicable law and within applicable timelines.

No system can be completely secure; however, we endeavour to protect your data using appropriate safeguards commensurate with the risks.

11. Data retention
We retain personal data only for as long as necessary for the purposes set out in this policy:

a) Account data: retained for the life of your account and for up to 6 years after closure to address queries, enforce our terms and comply with legal obligations, unless a shorter period is required by law.

b) Wellness and usage data (including food diary, photographs, symptoms, reflections and check‑ins): retained for the life of your account so you can access your history. Upon account closure or a verified deletion request, we will delete or irreversibly pseudonymise such data within 30 days, subject to technical logs and backups.

c) Technical logs and backups: operational logs are typically retained for up to 90 days unless required longer for security or legal reasons. Encrypted backups containing personal data are retained for up to 90 days, after which they are overwritten. Data in backups cannot be individually edited or deleted, but will be purged upon backup expiry.

d) Support correspondence: retained for up to 3 years from closure of the ticket, or longer where necessary for legal claims or compliance.

Where we rely on consent and you withdraw it, we will cease the processing covered by that consent and, where applicable, delete the data unless another lawful basis applies.

12. Your rights
Subject to conditions and applicable law (UK GDPR and EU GDPR), you have the following rights:

a) Access: to obtain confirmation as to whether we process your personal data and to access a copy.

b) Rectification: to have inaccurate or incomplete personal data corrected.

c) Erasure: to request deletion of your personal data, for example where it is no longer necessary or you withdraw consent and there is no other legal basis.

d) Restriction: to request restriction of processing in certain circumstances.

e) Portability: to receive personal data you provided to us in a structured, commonly used and machine‑readable format and to have that data transmitted to another controller where technically feasible.

f) Objection: to object to processing based on legitimate interests, and to object at any time to processing for direct marketing (Snax does not use your data for advertising).

g) Withdrawal of consent: where processing is based on consent, to withdraw consent at any time without affecting prior processing.

h) Rights relating to automated decision‑making: to request human intervention and to contest decisions where we carry out solely automated decision‑making with legal or similarly significant effects (Snax does not make decisions with legal or similarly significant effects solely by automated means).

To exercise your rights, please contact us at thesnaxapp@gmail.com. We may need to verify your identity before responding. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (www.ico.org.uk) or, if you are in the EU, with your local supervisory authority.

13. How to manage your data
You can access, correct and delete much of your data via the app. You may also:
a) request a copy of your data by contacting us;
b) request deletion of your account and associated personal data via the app or by contacting us;
c) manage permissions and consents, including disconnecting wearable integrations (when available), in the app settings.

14. International users and representative information
If you are located in the EU, Snax will comply with the EU GDPR in respect of processing within scope. We may appoint an EU representative if required as our user base evolves. Details will be published in an updated version of this policy.

15. Changes to this policy
We may update this policy to reflect changes in our practices, technologies, legal requirements or for other operational reasons. We will post the updated policy within the app and update the “Last updated” date. For material changes, we will provide additional notice, and where required by law we will seek your consent.

16. Additional statements
a) No sale of data: Snax does not sell personal data. Snax does not sell health data.

b) No advertising use: Snax does not use user data for advertising.

c) AI model training: Snax does not currently train AI models on user data.

d) Medical positioning: Snax is a wellness application. It is not a medical device or diagnostic tool and is not intended to diagnose, prevent, monitor, predict, treat or cure disease. Always seek the advice of qualified healthcare professionals with any questions regarding a medical condition.

17. Contact
For questions, requests or complaints, please contact:
Email: contact@thesnaxapp.com

bottom of page