KETONOIR

Privacy Policy

Version 1.7 · Effective 2026-08-13

Version 1.7 is a substantive correction, not a clarification. Earlier versions described what KetoNoir collects and shares less completely and, in several places, inaccurately. Version 1.7 does not authorize anything new: everything it describes was already happening. It expands what we disclose reading from Apple Health and Health Connect from three measurements to eleven, and states where each of those signals goes. It replaces the single line about “meal and body photos” with the full list of photograph and document types we send to our AI provider, and what the model is asked to infer from them. It corrects what our analytics, crash-reporting, email and key-value providers actually receive. It names the advertising, font and content-delivery services that were in use but not previously listed. It states our lawful basis for processing health data under Article 9 of the GDPR. It corrects claims about controls that do not work the way earlier versions said they did. Where an earlier version of this policy, or any in-app text, conflicts with this version, this version is correct. Because it widens the description of health-data processing, we treat this as a material change for the purposes of Article 9 of the GDPR. It does not re-open the in-app consent you have already given, because no processing has been added.

This Privacy Policy describes how Ketonoir LLC (“KetoNoir,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use the KetoNoir mobile application, web application, and related services (collectively, the “Service”).

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use the Service.

1. Information We Collect

1.1 Information You Provide Directly

Account Information. Name, email address, and password (encrypted). In the mobile app we ask for your date of birth to confirm you are 18 or older. The full date is evaluated on your device for that check alone and is never transmitted to or stored by KetoNoir. We retain only your birth year, which is used to calculate your macro targets. On the web, age is confirmed by a self-declared statement that you are 18 or older, and no date of birth is collected.

Profile Information. Height, weight, sex, body composition (if you provide it), activity level, dietary preferences, and health goals you voluntarily enter.

Health Screening Responses. Answers you provide during onboarding screening regarding pregnancy, organ disease, eating disorder history, medication use, gallbladder issues, type 1 diabetes, recent cardiac events, SGLT2 inhibitor use, and active cancer treatment. The screening determines whether AI coaching features are enabled or restricted to general tracking mode.

Food and Nutrition Data. Meals logged, macronutrient intake, water consumption, exercise, ketone or glucose readings (if you choose to log them), and any other data you enter into tracking features.

Biomarker and Health-Measurement Data. Measurements you choose to log, or that the AI coach records at your request and with your confirmation. These include body weight and body composition, blood ketones (BHB), blood glucose, blood pressure (systolic and diastolic), and a blood lipid panel (total cholesterol, LDL, HDL, and triglycerides). You may enter these manually. Where you have connected a health platform and granted permission, weight, blood glucose and blood pressure are also read from Apple Health or Health Connect and stored here alongside the readings you entered. Section 1.3 lists everything we read from those platforms. Blood ketones and blood lipid values are entered manually only and are not read from either platform.

Photographs and Documents You Upload. KetoNoir captures or accepts images and documents in several distinct places, not only meal snaps. In every case you may either take a new picture or pick an existing file from your device’s photo library or file picker, so a file you upload need not be one you took for KetoNoir. In every case listed below except the two barcode paths noted at the end, the file is uploaded to KetoNoir’s backend and forwarded to Anthropic’s Claude API for analysis. An image is transmitted and read by the model before we can tell whether it is the kind of image you meant to send, so your image is analyzed even in the cases where KetoNoir then declines the scan and asks you for a different picture.

  • Plated-meal photographs, to estimate macronutrients. The mobile version also asks the model to list every component it can see plus likely common allergens, hedging toward naming a possible allergen rather than omitting it. That is an inference about your diet and your allergy risk drawn from a picture.
  • Body-composition photographs. These are full-body, front-facing images; the feature is built for minimal clothing and treats a heavily clothed photo as unusable. Your sex, any note you write, and your earlier body-fat estimates are sent with the image. The model is instructed to judge whether the person in the image appears to be under 18, whether they appear severely underweight or otherwise clinically concerning, and whether your note contains eating-disorder language. Those judgments are returned to the app. They are, in substance, age and mental-health inferences drawn from a photograph and from what you wrote.
  • Refrigerator, pantry, freezer, counter and grocery-haul photographs, to identify food you already have. A picture of a refrigerator or a pantry routinely contains more than food: refrigerated prescription medication such as insulin, GLP-1 pens or biologics, alcohol, infant formula, other people in your household, mail and documents on the door, and the interior of your home. The pantry feature instructs the model to list every distinct visible item, including mundane ones, and to read package labels.
  • Recipe cards, cookbook pages, screenshots of recipes, and handwritten recipes.
  • Meal plans, including printouts, screenshots and handwritten plans. A meal plan issued by a clinician or a dietitian commonly carries your name, a clinic letterhead and clinical detail about you.
  • Workout and training programs, in the fitness tools.
  • Product packaging, so the model can read a barcode the scanner could not.
  • PDF documents. The web recipe import, the web meal-plan upload and the workout-program upload accept a PDF as well as an image, and the whole document is sent.
  • Live camera frames. On iOS Safari the web barcode scanner cannot use the browser’s own barcode reader, so while that scanner is open it captures a frame from your live rear camera roughly every 800 milliseconds and sends each frame to Anthropic. Every frame contains whatever the camera is pointed at, including bystanders, the room and any document in view, not only the barcode.

Two exceptions. The mobile barcode scanner reads codes entirely on your device and no frame leaves your phone. The mobile “Upload Photo” barcode option uploads your photograph to KetoNoir’s servers, where we decode it ourselves; it is not sent to Anthropic. That path accepts an image of up to 8 MB.

Metadata Inside the Files You Upload. Most upload paths re-encode your image before sending it, which strips the metadata embedded by your camera. Three do not. The web recipe import, the web meal-plan upload and the workout-program upload send the original file exactly as it is stored on your device. If that file carries embedded metadata, including GPS coordinates, the capture timestamp, and camera or device identifiers, that metadata is transmitted with it.

What Survives the Photograph. The image file itself is not kept in your KetoNoir account. What the model read out of it is kept, in several places and for different periods, some of them indefinite. Section 5 (Data Retention) sets this out.

AI Coach Conversations. Questions, messages, and responses exchanged with the KetoNoir AI coaching feature.

Payment Information. Subscription details processed through Apple App Store, Google Play Store, or Stripe. We do NOT store full credit card numbers on our servers. See Section 14 (Payment Information) for the full disclosure of how subscription payment data is handled.

Subscription State Metadata. When you purchase, renew, cancel, or change a KetoNoir Premium subscription, we receive and store subscription-state metadata associated with your account, including: the subscription tier (free, premium, or grandfathered), the source platform (Apple App Store, Google Play Store, or Stripe), the current subscription status (active, in trial, expired, in billing retry, or cancelled), the renewal or expiration timestamp, and the product identifier of the purchased package. This metadata is used to gate access to Premium features and to honor the entitlement you paid for. We do NOT receive or store the underlying card, bank, or wallet credentials used to make the purchase.

Communications. Feedback, support requests, and correspondence you send to us.

1.2 Information Collected Automatically

Device Information. Device type, operating system, app version, language settings, and a randomly generated 16-character device fingerprint that contains no personal information.

Advertising and Attribution Identifiers. The campaign parameters carried by the link you arrived through (utm_source, utm_medium, utm_campaign), any affiliate code, and, on Android, the Google Play install referrer. We attach these to your checkout session and to analytics events so we can tell which campaign or affiliate an account came from. On our marketing websites, and only after you accept tracking in the consent banner, the Meta and TikTok advertising pixels also set and read their own cookies and browser identifiers. The iOS app declares SKAdNetwork identifiers for Meta and TikTok, which authorizes Apple to send those two networks aggregated install and conversion reports about the app.

Usage Data. Features used, session duration, pages viewed, time stamps, and in-app actions.

Consent and Disclaimer Logs. Records of which disclaimers, terms, and policies you have accepted, including version numbers (e.g., medical_disclaimer v1.0, ai_coach_disclaimer v1.1, health_screening v1.1, terms_of_service v1.4, privacy_policy v1.5), timestamps, app version, and device identifier. When a disclaimer version is materially updated, you will be re-prompted to accept the new version.

Log Data. IP address, access times, and diagnostic data.

Crash Reports and Diagnostics. Stack traces and runtime diagnostic data captured when the application hits an error, plus a sampled share of successful requests for performance monitoring, processed by Sentry. Sentry also receives operational breadcrumbs, which are records of what the app was doing rather than of your data: which endpoint ran, which scan mode was used, how long it took, the HTTP status, how much of your scan quota remains, whether you are a premium user, how many rows a health-platform sync imported, the field names present in a sample, and the serialized text of a sync error. Where the AI returns something we cannot parse, up to 200 characters of that raw model output is included so we can debug it. We scrub health, food, biomarker and coach fields by field name, drop any single value larger than 2 KB, and on the web delete your email address and IP address, before a report leaves the device or the server. We disclose one past failure of that scrubbing: from the introduction of performance monitoring until version 1.19.85, the scrubber did not run on sampled performance traces, and roughly one in ten successful body-composition requests transmitted the uploaded body photograph to Sentry. That defect is fixed.

Analytics Data. Event-level behavioral data (feature usage, screen views, conversion events) processed by PostHog. This data is not aggregated and it is not anonymous: your PostHog profile is keyed to your account identifier and carries your email address. Correcting what earlier versions of this policy said, analytics events are not free of health and food content. They include the calorie, protein, fat and carbohydrate totals of a meal you log and how many entries you logged that day; which biomarker fields you recorded; your daily calorie target and how far a generated plan deviated from it; which biometric chart you opened and which metric you asked the coach about; how many allergies and custom sensitivities you have saved; and the fact that your health screening flagged a condition, with the number of conditions flagged, and that AI coaching was restricted as a result. That last event identifies you to PostHog as someone who declared a condition that disqualifies you from coaching. Analytics events do not carry your biomarker values, the text of your food entries, your allergy names, or AI coach conversation content. On the web we disable autocapture, disable session recording, mask personal data properties, and instruct PostHog not to store your IP address. Mobile session replay is present in the app but is switched off.

1.3 Information From Third Parties

If you choose to connect third-party services (such as Apple Health, Google Fit, or social login providers), we may receive information from those services in accordance with the permissions you grant. We do not receive more than what you authorize.

Where you connect Apple Health or Health Connect and grant the corresponding permissions, KetoNoir reads the following from the platform. This is the complete list.

  • Body weight.
  • Blood glucose.
  • Blood pressure, systolic and diastolic.
  • Sleep: time asleep, time in bed, bedtime, wake time, and the per-night stage breakdown your device records.
  • Active energy burned.
  • Basal or resting energy expenditure.
  • Step count.
  • Resting heart rate.
  • Heart-rate variability.
  • VO2 max, where your device records it.
  • Workouts and exercise sessions: the activity type, when it started, how long it lasted, and on iOS the calories recorded against it.
  • For each reading we import, the name of the app or device that originally wrote that sample to the platform. We store that name with the reading, permanently. It can itself indicate a diagnosis or a treatment, because the name of a continuous glucose monitor, an insulin pump or a blood-pressure cuff says something about why you use one.
  • The platform’s own record identifier for each sample, which we store so that re-running a sync does not duplicate your readings.

We also derive values from the above: your 28-day median resting heart rate, heart-rate variability and sleep duration; a sleep-efficiency ratio and a sleep-quality rating; and a coarse intensity and category for each workout.

KetoNoir currently asks the operating system for three permissions it does not use: height and body-fat percentage on both platforms, and body mass index on iOS. No code reads them. You may decline them with no effect on the app, and we are removing the requests.

Blood ketones are not read from either platform. Apple Health and Health Connect do not expose a blood-ketone type. Ketone readings in KetoNoir are ones you entered, or ones the coach recorded at your request and with your confirmation. Blood lipid values are likewise entered manually only.

Where this data goes. Weight, blood glucose and blood pressure are written into your KetoNoir account and stored on our servers alongside the readings you enter by hand, tagged with the platform and with the source app or device they came from. They are then included in the information sent to Anthropic when you use the AI coach. Sleep, active energy, basal energy, steps, resting heart rate, heart-rate variability and your workouts, together with the 28-day baselines and the derived values above, are sent to Anthropic each time your Metabolic Forecast is generated, and the forecast produced from them is stored on our servers with a rolling history of the last 30. VO2 max is read and shown to you on your device and is the one signal in this list we do not transmit. In-app text stating that these signals are read in flight only, never stored on our servers, and never seen by the coach was wrong on both counts; this paragraph replaces it.

How far back we read. A sync imports weight, glucose and blood pressure over a window you choose, up to 365 days. Separately, the Trends screen reads up to 365 days of sleep, steps, energy, resting heart rate, heart-rate variability, VO2 max and workouts from the platform each time you open it, and the Metabolic Forecast reads a 28-day window to compute your baselines. The reach is therefore not limited to a choice you make once at the first import.

Controls, stated accurately. The per-signal switches in KetoNoir’s health settings work for the Metabolic Forecast: a signal switched off is blanked out of the forecast request and does not reach Anthropic. They do not control the import of weight, blood glucose and blood pressure into your account. Those three are imported together whenever a sync runs, and blood pressure has no switch of its own. “Disconnect” in the app turns the connection off in KetoNoir’s own settings, but it does not revoke the permission you granted to the operating system, and the automatic sync that runs when the app starts does not check that setting, so importing continues. To stop KetoNoir reading your health platform, revoke its access in Apple Health or in Health Connect. We are fixing Disconnect so it does what its name says; until then, revoking at the operating-system level is the control that works.

KetoNoir reads from these platforms and never writes back to them, so your operating-system health store is never modified by us. We do not sell this data and we do not share it with any advertising or marketing network. Biometric values are excluded from analytics and crash reporting. Facts about the sync are not: that a sync ran, how many rows it imported, the field names present in a sample, the text of a sync error, and which biometric chart you opened reach Sentry and PostHog as described in Section 1.2.

You can delete individual readings, and deleting your account deletes the imported readings with it.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service and its features.
  • Process subscriptions, payments, and renewals.
  • Personalize your experience, including macro targets, meal tracking, and AI coaching responses.
  • Determine eligibility for AI coaching based on your health screening responses, and route you to general tracking mode if your responses indicate elevated risk for ketogenic dietary intervention.
  • Send your AI coach conversations to our AI service provider (Anthropic) to generate responses.
  • Communicate with you about updates, features, security alerts, and customer support.
  • Send marketing and promotional materials (only with your consent, where required by law).
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms of Service.
  • Conduct analytics to improve the Service, using aggregated data where possible.

3. AI Coaching Feature and Third-Party AI Processing

The KetoNoir AI coach is powered by Anthropic’s Claude API. When you interact with the AI coach:

  • Your messages are transmitted to Anthropic’s servers for processing.
  • Anthropic processes your messages under its commercial terms and privacy policy.
  • We do not put your name, email address or payment information into the coach request. Two qualifications, both of which we state rather than leave to the general wording. First, the web recipe import, meal-plan upload and workout-program upload send your file exactly as it is stored on your device, so if it carries your name, a clinic letterhead, or GPS coordinates embedded by your camera, those are sent with it. Second, on the internal administration surface described in section 3 above, your account identifier is included in what an operator sends to Anthropic; for accounts created in the mobile app that identifier is your account’s primary key, which we are able to join to your email address.
  • Conversation content may include health and dietary information you choose to share with the AI coach, including biomarker values (such as ketones, glucose, weight, blood pressure, cholesterol and other lipid values, and macronutrient intake) used to personalize coaching responses.
  • Photographs and documents you upload are forwarded to Anthropic’s Claude API. This is not limited to meal photographs. It includes body-composition photographs, refrigerator and pantry photographs, recipe cards, meal plans, workout programs, product packaging, PDF documents, and, in the iOS Safari barcode fallback, frames captured from your live camera. Section 1.1 lists each of them and what the model is asked to infer from them. All are processed under Anthropic’s commercial terms and privacy policy.
  • Your Metabolic Forecast is generated by Anthropic. The request carries the health-platform signals listed in Section 1.3, meaning your sleep, energy expenditure, steps, resting heart rate, heart-rate variability and workouts together with your 28-day baselines, alongside your food log, weight log and ketone and glucose readings. Earlier versions of this policy described the forecast only as something KetoNoir generates and did not disclose this transfer.
  • Anthropic also receives information about you for a purpose other than answering a question you asked. On our internal administration surface, an operator can send your account identifier, your biomarker series and excerpts of your AI coach conversations, up to the last ten exchanges with your message truncated to 600 characters and the coach reply to 400, to Anthropic so the model can help that operator analyze them.
  • When you ask the AI coach to log a meal or a health measurement and you confirm the entry, the coach creates the corresponding record in your account (a food-log entry, or a biomarker entry such as weight, glucose, ketones, blood pressure, or a lipid value). No record is created unless you confirm it. You are responsible for the accuracy of the values you provide; the coach records the data you give it and does not independently measure, verify, or clinically interpret it.

For more information about how Anthropic handles data, please review Anthropic’s Privacy Policy at anthropic.com/legal/privacy.

You should not share highly sensitive information (such as Social Security numbers, financial account details, or specific medical diagnoses) with the AI coach. The coach does not diagnose conditions, prescribe medications, recommend supplement dosing, or adjust insulin doses. Per the AI Coach Disclaimer (v1.1), coach output is not reviewed by a licensed clinician on a per-message basis and you must independently verify any guidance with a qualified healthcare provider.

4. How We Share Your Information

We do NOT sell your personal information. We share information only as follows:

Service Providers. Trusted third-party service providers who help us operate the Service. These providers are contractually required to protect your information and process it only on our instructions:

  • Cloud hosting: Vercel (application backend) and Netlify (marketing pages).
  • Account database and authentication: Supabase, Inc. Supabase hosts our primary database and authentication service. This is where your account, profile, food log entries, biomarker readings, coach memory, saved recipes and executed affiliate agreements are stored. Supabase holds the mapping between your account identifier and your email address. Your browser and the mobile app connect to Supabase directly, so Supabase also sees your IP address.
  • Key-value storage and rate limiting: Upstash, Inc. Upstash is not merely a counter store; it is one of our primary stores of health data. It holds your daily food log, the full text of your AI coach conversation thread, the verbatim question-and-answer records of the web coach, the medical conditions you declared in health screening, your generated Metabolic Forecasts with a rolling history of the last 30, the pantry inventory recognized from your refrigerator and pantry photographs, your body-fat estimate history, AI output extracted from images and PDFs, consent records, usage counters and rate-limit state.
  • Cloudflare, Inc., in two roles. Cloudflare provides DNS for KetoNoir domains and does not host or proxy application traffic for the Service. Separately, Cloudflare Web Analytics runs on pages of our marketing websites, where it receives the page address, the referring page, your user agent, connection and page-performance measurements, and your IP address. That beacon is not behind the tracking consent banner and runs on those pages regardless of the choice you make in it. It does not run inside the KetoNoir app.
  • Payment processing: Apple App Store, Google Play Store, and Stripe.
  • Subscription state orchestration: RevenueCat, Inc. (San Francisco, CA). RevenueCat receives subscription-state events from Apple and Google on our behalf, validates them, and forwards subscription-state metadata (tier, status, expiration, source platform, product identifier) to our backend. RevenueCat does not receive or process the underlying card, bank, or wallet credentials used to make purchases. See Section 14 (Payment Information) for the full payment flow.
  • Analytics: PostHog, Inc. Receives the identified event data described in Section 1.2, including your email address on your analytics profile, meal macro totals, daily calorie targets, which biomarker fields you log, which health charts you view, your allergy counts, and the fact that your health screening flagged a condition. It does not receive biomarker values, the text of your food entries, your allergy names, or AI coach conversation content.
  • Crash reporting and diagnostics: Sentry (Functional Software, Inc.). Receives what Section 1.2 describes, including sampled performance traces, operational breadcrumbs, and up to 200 characters of raw AI output when a response cannot be parsed. Biomarker values, food entries and coach conversation content are scrubbed by field name and by value size before transmission. Section 1.2 also records one past failure of that scrubbing.
  • AI processing: Anthropic, PBC (Claude API). Receives your coach messages with the context described in Section 3; every photograph and document category listed in Section 1.1; the Metabolic Forecast payload described in Section 1.3; and, on our internal administration surface, account identifiers, biomarker series, operator notes, and verbatim coach conversation excerpts, for operator analysis rather than to answer a question you asked. Processed under Anthropic’s commercial terms and not used to train Anthropic’s models.
  • Food, barcode and supplement lookups. When you search for a food, we send the text you typed to USDA FoodData Central, Open Food Facts and FatSecret. When you scan or upload a barcode we send the code to Open Food Facts and, where it is not found there, to Open Products Facts, FatSecret and Spoonacular. Where the code identifies a dietary supplement we also query the NIH Office of Dietary Supplements Dietary Supplement Label Database, which is a lookup of a health product you are holding. Spoonacular is no longer a default destination for food searches but is still used as a barcode fallback, so it is not limited to “when connected.” The fitness tools query wger.de for exercise information using the filters you select. All of these requests are made by our servers, not by your device, so these services receive the query, the barcode or the filter but not your identity and not your IP address.
  • Email and lifecycle messaging: MailerLite. Receives your email address, the time you opted in, and the IP address you opted in from, which we store durably as proof of opt-in. MailerLite also holds your list membership, which is set to either free or premium and is moved automatically when your subscription changes, so MailerLite holds a live record of whether you are a paying subscriber. Images in our emails are served from MailerLite’s content delivery network and forms on our marketing site are served by MailerLite, so it can also observe when you open one.
  • Email delivery: Postmark (Wildbit, LLC) for account email, progress reports and re-engagement messages. Your weekly and monthly progress report is health data carried in an email: it contains how many days you logged, your average calories, net carbohydrates, protein and fat per logged day, your weight change in pounds, and your average blood ketone reading, and the subject line carries your days-logged count. Postmark transmits that message, so Postmark receives that content. Postmark also carries account and password-recovery email, which contains a live recovery link. Every commercial message carries an unsubscribe link.
  • Advertising and measurement: Meta Platforms, Inc. and TikTok (ByteDance Ltd.). Advertising pixels for both run on pages of our marketing websites, including the page you are reading now. Neither loads until you accept tracking in the consent banner. Once you accept, each receives the address of the page you are on, the referring page, your user agent and your IP address, and sets and reads its own cookies; the TikTok pixel additionally reports the path of the page as a named event, so accepting on a policy or clinicians page discloses that path to TikTok. The iOS app declares SKAdNetwork identifiers for both networks, which authorizes Apple to send them aggregated install and conversion reports. Neither receives your biomarkers, food log, photographs or coach conversations, and we do not use consumer health data for advertising or ad targeting.
  • Web fonts: Google LLC. Pages of the KetoNoir web app load fonts from Google’s font servers, which discloses your IP address, user agent and the address of the KetoNoir page you are on to Google on each page load. This is not consent-gated. The mobile app bundles its fonts and does not do this. Google is also our Android payment processor, a sign-in provider if you choose Sign in with Google, the operator of Health Connect, and the source of the Google Play install referrer.
  • Model hosting: Hugging Face, Inc. If you use the coach’s voice output in a browser other than iOS Safari, your browser downloads a speech model directly from Hugging Face’s content delivery network, which discloses your IP address, user agent and the referring KetoNoir page to Hugging Face. No conversation content is sent there.
  • Mobile build tooling: Expo, Inc. Expo’s build service compiles the mobile app and holds our source and build credentials. It does not receive user data at runtime.
  • Speech synthesis: ElevenLabs. Used only on an internal, operator-only dashboard to narrate aggregate business metrics. It does not receive individual user records.

Legal Requirements. When required by law, court order, subpoena, or to protect our legal rights, property, or safety, or that of our users or the public.

Business Transfers. If Ketonoir LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred. You will be notified of any change in ownership or use of your information.

With Your Consent. For any other purpose disclosed to you at the time we collect the information.

Aggregated and De-Identified Data. We may share information that has been aggregated, or stripped of identifiers to the point that it cannot reasonably be used to identify you. We do not describe such data as anonymous and you should not read it as anonymous.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account Data. Retained while your account is active and for up to 90 days after account deletion to handle refunds, disputes, or legal obligations.
  • Consent Logs. Retained for seven (7) years after account closure to demonstrate compliance with legal and regulatory requirements. Includes all consent versions you accepted.
  • AI Coach Conversations. Retained for up to 24 months or until you delete them from your account.
  • Photographs and Documents. The image or document file itself is not retained after the analysis that produced your log entry. What was read out of it is retained, in several places and for different periods, some of them indefinite. AI output generated from an image or a PDF, up to 800 characters, is written to our chat log with no expiry, is readable by our operators and can be exported by them. A recipe saved from a photograph keeps a fingerprint of that specific photograph indefinitely. The inventory recognized from a refrigerator or pantry photograph is kept indefinitely as your pantry list. Body-fat estimates are kept indefinitely, along with the last 26 as a history, and are sent back to the model as context for later estimates. On the mobile app a resized copy of the picture is written to the app’s cache on your own device and is not deleted by us; clearing the app’s storage or deleting the app removes it.
  • Imported Health-Platform Readings. Retained on the same terms as readings you enter by hand, for as long as your account is active.
  • Metabolic Forecasts. The generated forecast is retained per day, with a rolling history of the last 30 forecasts.
  • Subscription State Records. Retained for as long as your account is active and for up to seven (7) years after account closure as required by tax, accounting, and consumer-protection regulations.
  • Payment Records. Retained for seven (7) years as required by tax and accounting regulations.
  • Backup Data. May persist in encrypted backups for up to 30 days after primary deletion.

6. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest where supported by our service providers.
  • Secure password hashing (bcrypt or equivalent).
  • Access controls limiting employee access to personal data.
  • API key isolation: third-party API keys (Anthropic, FatSecret, USDA) are held server-side and never shipped to client devices.
  • Regular security audits and vulnerability assessments.
  • Incident response procedures for suspected breaches.

However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Your Privacy Rights

7.1 General Rights

Depending on your location, you may have the following rights:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Request that we correct inaccurate or incomplete information.
  • Deletion. Request that we delete your personal information, subject to certain exceptions, such as consent logs retained for legal compliance. Two further limits apply today and we state them rather than leave them to be discovered. Account deletion removes records keyed to your account identifier. And for accounts created on the web beta rather than in the mobile app, the automated deletion sweep does not reach the stored coach transcripts, because those are keyed differently. Write to us and we will remove both by hand.
  • Portability. Request a copy of your data in a structured, commonly used format.
  • Objection / Restriction. Object to or request that we limit certain types of processing.
  • Withdrawal of Consent. Withdraw consent where processing is based on consent.
  • Non-Discrimination. We will not discriminate against you for exercising any of these rights.
7.2 California Residents (CCPA / CPRA)

California residents have specific rights under the California Consumer Privacy Act, including the right to know what personal information is collected, sold, or disclosed; the right to delete; the right to correct; the right to opt out of the sale or sharing of personal information; and the right to limit the use of sensitive personal information. We do not sell personal information as defined under the CCPA.

7.3 European Economic Area, United Kingdom, and Switzerland (GDPR)

If you are located in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent laws. Our lawful bases for processing ordinary personal data are: your consent; performance of a contract, to provide the Service; compliance with legal obligations; and our legitimate interests in operating and securing the Service.

Health data (Article 9). Most of what KetoNoir handles is data concerning health, which Article 9 of the GDPR treats as a special category and prohibits us from processing unless a specific condition is met. The condition we rely on is Article 9(2)(a), your explicit consent. We do not rely on legitimate interests, on Article 9(2)(h) health care, or on Article 9(2)(j) scientific research for any of it. This covers your biomarkers, your food log, your health-screening answers, everything read from Apple Health or Health Connect, your body-composition and meal photographs and the inferences drawn from them, and your coach conversations.

You give that consent by the specific step you take: granting the health-platform permission before we read anything from Apple Health or Health Connect, accepting the body-composition disclaimer before that feature will run, choosing to upload a particular photograph, and answering the health screening. You may withdraw consent at any time, by revoking the platform permission, by not using the feature, or by writing to legal@ketonoir.ai. Withdrawal stops the processing going forward and does not make lawful processing already carried out unlawful. We are adding explicit, feature-specific consent screens so that each consent and each withdrawal is recorded inside KetoNoir rather than inferred from the step you took.

7.4 How to Exercise Your Rights

To exercise any of these rights, contact us at legal@ketonoir.ai. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

8. Children's Privacy

The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from individuals under 18. The Service includes an age gate requiring confirmation of age 18 or older before use. If we learn that we have collected personal information from a person under 18, we will delete that information promptly. If you believe a minor has provided us with personal information, please contact us at legal@ketonoir.ai.

9. International Data Transfers

Ketonoir LLC is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers. Where required by law, we implement appropriate safeguards (such as Standard Contractual Clauses) for international data transfers.

10. Cookies and Tracking Technologies

The KetoNoir app. The web app uses cookies and similar storage to keep you signed in, remember your preferences and measure usage. The mobile app uses device identifiers and SDKs for the same purposes. It carries no active advertising SDK: the Meta SDK is compiled into the app but is not initialized and sends nothing, and no advertising identifier is collected on the device today. The iOS build declares SKAdNetwork identifiers for Meta and TikTok, which lets Apple send those networks aggregated install and conversion reports without identifying you to them.

Our marketing websites. ketonoir.ai, ketonoir.com and our science site run advertising and analytics trackers behind a consent banner: the Meta pixel, the TikTok pixel and PostHog. Nothing is loaded and nothing is sent to those companies until you accept, and declining takes exactly one click, the same as accepting. If you accept, the TikTok pixel reports the path of the page you are on as a named event; because these policy pages sit on the same site, that includes the path of this page and of our clinicians page. Cloudflare Web Analytics also runs on several marketing pages and is not behind the banner; it receives the page address, the referring page, your user agent, performance measurements and your IP address. Your browser’s tracker blocking will stop it, and we are moving it behind the banner.

You can control cookies through your browser settings and tracking preferences through your device settings.

11. Third-Party Links and Services

The Service may contain links to third-party websites, affiliate partners, or services that are not operated by us. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party service you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means. Your continued use of the Service after the effective date of the updated policy constitutes acceptance of the changes. We will log your re-acceptance where required, and disclaimer version bumps will trigger a re-consent prompt for the affected disclaimer.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:

KetoNoir LLC
1145 Santa Fe Drive 1297
Weatherford, TX 76087-3846
United States
Email: legal@ketonoir.ai

14. Payment Information

When you purchase a KetoNoir Premium subscription through the mobile application, the payment transaction is handled entirely by the platform operator that hosts the application (Apple, Inc. for iOS purchases or Google LLC for Android purchases). The web tracker accepts subscription payments through Stripe, Inc. KetoNoir does not see, receive, or store the underlying payment credentials used to complete the transaction.

14.1 What the Platform Operators Collect

Apple, Google, and Stripe collect and process all data required to complete the payment, including but not limited to: the payment card number or wallet identifier, the billing name and address associated with the payment method, the country and tax jurisdiction of the purchase, the currency, the gross amount charged, any taxes or fees collected, and the transaction identifier. The handling of this data is governed by the privacy policy of the applicable platform operator and not by this Privacy Policy.

  • Apple’s privacy practices for App Store and In-App Purchase transactions are described at apple.com/legal/privacy.
  • Google’s privacy practices for Google Play and Google Play Billing transactions are described at policies.google.com/privacy.
  • Stripe’s privacy practices for web subscription transactions are described at stripe.com/privacy.
14.2 What KetoNoir Receives

KetoNoir receives only the subscription-state metadata described in Section 1.1 (“Subscription State Metadata”). This metadata is delivered to our backend through RevenueCat, Inc., which acts as our subscription-state processor and validates receipts on our behalf. The subscription-state metadata is the minimum set of fields required to determine whether your account is entitled to KetoNoir Premium features on a given day, and consists of: subscription tier, status (active, in trial, expired, in billing retry, or cancelled), source platform (Apple, Google, or Stripe), renewal or expiration timestamp, and product identifier.

14.3 What KetoNoir Does Not Receive

KetoNoir does not receive, request, or store: your full payment card number, your card expiration date, your card security code (CVV / CVC), your bank account number, your digital wallet credentials (such as Apple Pay or Google Pay device tokens), the billing address associated with your payment method, or the geographic location at which the purchase was made beyond the country and currency reported by the platform operator. If you wish to update your billing address, payment method, or other account-level payment details, you must do so through your Apple ID account settings, your Google Play account settings, or the Stripe Customer Portal, as applicable to the platform you used to subscribe.

14.4 Refunds and Disputes

Refund requests and payment disputes are handled by the platform operator that processed the original transaction, not by KetoNoir. See the Terms of Service for the specific refund procedure applicable to your purchase channel.