Add One

Add One — Privacy Policy

Last updated: 2026-09-24

Add One suggests one thing you could add beside the meal you already chose. This policy describes what the app actually does with your information.

The short version

What you type stays on your device. Three optional services send limited data off your device: public food-name search, Photo Assist, and purchase checks. They are described below. We have no account system and no product-usage analytics.

What stays on your device

  • the meals you enter
  • any dietary constraint or exclusion you select
  • the suggestions you kept, and your response to them

There is no account, no sign-in, and no sync. Deleting the app deletes that local content. You can also delete individual entries, or everything at once, from Settings.

The Home Screen widget

The optional widget can display the title of today's addition on your Home Screen. Anyone who can see that screen may see the title. It does not display your meal name, dietary exclusions, or responses. Widget data is shared locally with the app through its App Group and is not uploaded.

What leaves your device

Three optional service paths are described below.

1. Food name lookup — only when you ask for it

If you use the name search, the text you typed is sent to Open Food Facts, a public food database, to find matching product names.

  • It is used to find names only. It is not used to determine whether a food is safe for you.
  • It runs only when you explicitly submit a search. It never runs in the background.
  • If it is unavailable, manual entry keeps working exactly as before.
  • Open Food Facts privacy: https://world.openfoodfacts.org/privacy

2. Photo drafting — only when you choose a photo and send it

If you use photo assist, the selected photo is sent to our proxy server, which passes it to Google's Gemini model to produce an editable draft of the meal name.

  • The proxy processes the photo in memory to produce that draft. The proxy does not write the photo to storage.
  • The model is instructed to name only clearly visible food. It does not estimate nutrition, and it does not detect allergens or ingredients.
  • The returned draft is always editable before you accept it.
  • You choose the photo and press send each time. Nothing is uploaded automatically, and your photo library is never scanned.
  • The production Gemini request sets store=false, so it does not create a stored Interactions API object. Google may still keep prompts and responses for a limited period for abuse monitoring under its paid-service terms. Production must use a billing-enabled paid project and keep optional API logging and data sharing disabled; release is blocked until those settings are verified.
  • Google's privacy policy: https://policies.google.com/privacy

3. Purchases

Once you open the purchase screen or Photo Assist, Add One contacts RevenueCat and the Apple App Store to load options and check access. Those purchase checks may refresh when the app returns to the foreground or before a photo is sent so that paid access stays current. Apple and RevenueCat handle payment directly; we never see your payment details.

RevenueCat may receive a pseudonymous App User ID derived from this installation's App Attest key and Purchase History for this app. It uses Purchase History for Analytics and App Functionality, including its purchase dashboard, receipt validation, and entitlement delivery. The identifier contains no name or email. If the private App Attest identity must be replaced, Add One switches to the new pseudonymous ID and synchronizes the Apple receipt before paid Photo Assist resumes.

What we log

Our photo proxy records operational information only — whether a request succeeded, how long it took, fixed error codes, and a salted App Attest key hash. App Attest also keeps the attested public key and assertion counter needed to verify later requests. The proxy never logs image content, meal text, or the suggestion you received. This is enforced by a field allowlist.

The hosting provider, Railway, controls retention of operational logs. We have not verified a fixed deletion deadline for these logs. Hosting infrastructure can also keep separate request and network logs; the proxy's field allowlist does not govern those provider logs. A dashboard's visible log-history window is not a guarantee that older records have been deleted.

App Attest verification records contain a public key, assertion counter and environment, stored under a keyed hash of the installation's key identifier. They contain no photo or meal text. In the current persistent verification store, these records have no automatic expiry and remain until explicitly removed. Clearing local app data or uninstalling Add One does not remove them. Contact support about records we control; removing a verification record can require the app to verify its installation again before Photo Assist works.

The verification store uses persistent disk storage for recovery. Expiry or removal from the active store does not establish when every recovery copy or provider backup is erased. No fixed deletion deadline for those copies has been verified.

To limit automated requests, the proxy also keeps request-count buckets keyed by the connection's source IP address. The rate-limit key includes the address itself, without hashing it. This state is separate from operational logs and contains no photo or meal content.

The current shared store applies 60-second expiry windows to request-count buckets. Request-verification challenges expire after 120 seconds, and one-use paid photo authorizations expire after 45 seconds or are consumed earlier. These short-lived records contain verification tokens or hashes, not the photo or returned meal draft. Expiry controls their use in the active store; it does not promise erasure from every recovery copy or the hosting provider's logs.

What we do not do

  • No product-usage analytics or telemetry. RevenueCat's limited Purchase History analytics are described above.
  • No advertising or advertising identifiers.
  • No third-party trackers.
  • No location, microphone, motion, or health data.
  • Nothing sold or shared.

Important limits on food information

Add One does not verify ingredients and makes no allergen-safety guarantee. Exclusions you set remove suggestions carrying that tag, but this is a convenience filter, not a safety check. It does not verify labels, does not detect hidden ingredients, and does not address cross-contamination.

Always check the actual product label. If you have a food allergy or a medical condition, rely on your own checks and on qualified professional advice — not on this app.

Add One is not medical or nutritional advice.

Children

Add One is not directed at children under 13 and does not knowingly collect any information from them.

Your control

Your meals, settings, constraints, exclusions, saved moments, and responses are stored on your device. Delete individual saved moments or use Delete All in Settings to clear that local content and cached public searches. Removing the app also removes its local content. These actions do not erase Apple or RevenueCat Purchase History, provider abuse-monitoring records, or the proxy's operational and App Attest verification records described above. Contact support if you want us to address a rights request concerning records we control. Photo and search features are optional; the app works fully with manual entry.

Changes

If the app's data behaviour changes, this policy is updated at the same time.

Purchases and what that means for your data

The app uses RevenueCat to manage purchases through the Apple App Store. Once you open Purchases or Photo Assist, RevenueCat may receive the app's pseudonymous App User ID and Purchase History. It does not receive your name, your email, a meal record, a search query, or a photo.

Add One has no account system. Its App User ID is derived from this installation's App Attest key so the server can verify Photo Assist access without trusting a client-selected customer ID. The pseudonymous ID and Purchase History are not linked to a name or email and are not used for advertising or tracking by Add One.

For Apple's App Privacy disclosure, Add One conservatively treats that User ID, Purchase History, and associated operational diagnostics as linked to the pseudonymous installation identifier. This does not mean Add One has a person's name, email address, advertising identity, or cross-app profile.

The App Privacy disclosure also lists a submitted food-name search and a submitted Photo Assist image as Search History and Photos or Videos used for App Functionality. Neither is used for tracking. This conservative disclosure accounts for the named processors' handling even though Add One's proxy does not retain the photo or returned draft.

Legal basis under GDPR: performance of a contract — we cannot deliver or restore a purchase without it.

Your rights under GDPR

If you are in the EU or UK, you have the right to access, correct, erase, restrict, and port your personal data, and to object to processing.

YIP Labs does not maintain an account, profile, or server-side copy of your meal history. The proxy keeps the limited operational and App Attest records described above; Apple, RevenueCat, Google, and Open Food Facts process the data described in their sections. Contact us to exercise a right and we will address our records or coordinate with the relevant processor where applicable.

For purchase records, Apple and RevenueCat act as our processors. To exercise rights over purchase data, contact us and we will pass the request on.

Data controller: YIP Labs — contact details are shown on our App Store listing as required by the EU Digital Services Act.

Data retention

Local meal content and preferences remain until you delete them or remove the app. The proxy does not persist photos or model output. Operational and infrastructure logs follow the hosting provider's retention controls; we have not verified a fixed deletion deadline. App Attest public-key and counter records have no automatic expiry and need explicit removal. Short-lived request-verification and rate-limit records follow the active-store expiry windows described above. Persistent recovery copies and provider backups have separate lifecycles, with no verified fixed erasure deadline. Apple and RevenueCat retain purchase records under their policies; Google and Open Food Facts apply their own policies to requests sent to them.

International transfers

The Photo Assist proxy and its verification store are currently hosted by Railway in the United States. Apple, RevenueCat, Google, Open Food Facts and Railway may process the data described above outside the EU under their own safeguards. See their policies:

Complaints

If you believe your data has been handled improperly, you may lodge a complaint with your national supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), https://www.gegevensbeschermingsautoriteit.be

Contact

mail.yiplabs@gmail.com