Privacy Policy
This policy explains what the Chou app ("Chou", "we", "us") collects, why, who it is shared with, and the choices you have. Chou is operated by Eureka Software Factory. If you have questions, contact support@getchou.com.
- We collect what you put into the app (meal photos, foods, symptoms, chat messages) plus the email and name from sign-in.
- Meal photos, food names and chat context are sent through OpenRouter to AI model providers (such as OpenAI and Google) to identify foods, estimate nutrition and answer questions. We ask OpenRouter to use only providers that do not keep or train on your data.
- We don't sell your data, show ads, or track you across other apps or websites.
- You can delete your account and all of its data in the app: Stats → Daily targets (target icon, top right) → Delete account.
- Chou is not a medical service and doesn't diagnose anything.
1. Information we collect
Account information
- Email and password sign-in: your email address and a password. The password is stored only as a salted hash. To verify your email or reset your password we email you a one-time code; we keep a record of each code email (the address and time) for 24 hours to prevent abuse.
- Sign in with Google: your Google account identifier, email address, name and profile picture link, as shared by Google.
- Sign in with Apple: your Apple account identifier, your email address (or Apple's private relay address if you chose to hide it), and your name if you chose to share it.
- Sign-in sessions and tokens needed to keep you signed in. On your phone, the session token is kept in the device's secure storage.
Content you add
- Meal photos you take or pick from your photo library. Photos are resized and compressed on your phone before upload. When you pick a photo from your library, the app reads the time it was taken, on your phone, to set the meal time. We don't use photo location.
- Meals and foods: meal title, time eaten, each food's name, portion and weight, nutrition values, food tags (for example "dairy"), any notes, and whether you edited the AI's suggestions.
- Symptoms: the symptom type (a preset such as bloating, or your own label), severity from 1 to 5, when it started, and optional notes. This can be health information, and you choose whether to log it.
- Chat messages you send and the replies the app generates.
- Settings: optional daily nutrition targets and your time-zone offset (used to group meals into your local days).
Usage and technical information
- AI usage records: for each AI request, the feature (photo analysis, nutrition estimate or chat), the model used, token counts, cost, response time, success or error code, and the time. We use these to enforce daily limits, control costs and fix problems.
- Daily counters of photo analyses, chat messages and nutrition estimates, used for daily limits.
- Server logs kept by our hosting provider, which may include error messages and request metadata.
- Crash and error reports (sent to Sentry): technical details about crashes and errors, such as the stack trace, app version, device model and OS version, and your account identifier.
We don't collect your precise location, contacts, advertising identifiers, or payment information, and we don't use analytics or advertising SDKs.
2. How we use information
- To run the app: identify foods in your photos, estimate nutrition, save your meals and symptoms, show your history and totals, and answer your chat questions.
- To compute patterns between foods and symptoms. This is done with fixed statistics on our server from your own data only.
- To keep the service working and safe: daily limits, cost control, preventing abuse, and fixing errors.
- To contact you about your account or support requests.
We don't use your data for advertising, and we don't use it to train AI models.
3. Who we share it with
We share information only with the service providers that run Chou, and only what each needs:
| Provider | Purpose | What they receive |
|---|---|---|
| Convex | Backend hosting, database and file storage. | All of the information above, stored on our behalf. Servers are located in the United States. |
| OpenRouter | Routes AI requests to model providers. | Meal photos with the analysis instructions; food names (with the brand, if one was identified) to estimate nutrition, for example "grilled chicken"; and for chat: your question, recent messages, and a short summary drawn from your log (recent daily totals, symptom counts, top foods, detected patterns and up to 8 relevant meals). Not your email or name. |
| AI model providers (for example OpenAI and Google), via OpenRouter | Identify foods in photos, estimate nutrition and write chat replies. | The same request content that OpenRouter forwards. We set OpenRouter's data-collection preference to "deny", which limits routing to providers that, under their policies with OpenRouter, don't store or train on request data. |
| Resend | Sends transactional email: sign-up verification and password reset codes. | Your email address and the one-time code in the email. Nothing else from your account. |
| Google or Apple | Sign-in, if you choose it. | The standard sign-in request. We receive the account details listed above. |
| Sentry | Crash and error reporting for the app and the backend. | Technical details about an error: stack trace, app version, device model and operating system version, and an account identifier so we can follow up. We configure it not to include your photos, meals, symptoms or chat messages. |
We may also disclose information if required by law, to protect the rights and safety of users or others, or as part of a merger or sale of the service (in which case this policy continues to apply to your data). We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
4. How long we keep it
- Your account data (meals, photos, symptoms, chats, settings and usage records) is kept while your account exists, until you delete it.
- Deleting a meal or symptom in the app removes it, including the meal's photo. Photos from scans you discard are deleted immediately, and uploaded photos that never become part of a scan are deleted automatically within a few hours. Chats stay with your account until you delete the account.
- When you delete your account, the data is removed from our database and file storage. Copies in our hosting provider's routine backups or logs are overwritten on their normal schedule.
- If a photo upload finishes but its analysis can't be started (for example, because a daily limit was reached), the photo isn't linked to your account and is deleted automatically within a few hours.
- Records of code emails (email address and time) are deleted after 24 hours.
- Nutrition estimates are cached by food name (for example "banana") in a shared table that is not linked to any account, so it is not personal information and is not deleted with your account.
5. Deleting your account
In the app, go to Stats → Daily targets (target icon, top right) → Delete account and confirm. This permanently deletes your account and sign-in methods, sessions, meals and meal items, meal photos and scans, symptoms, chat threads and messages, daily targets and settings, and AI usage records and daily counters. It can't be undone.
If you can't access the app, email support@getchou.com from the address on your account and we will delete it. See Support.
6. Your choices and rights
- You can view, edit and delete your meals, symptoms and chats in the app, and delete your whole account.
- Logging symptoms and using chat are optional.
- Depending on where you live (for example the EU, UK or California), you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict processing, and to withdraw consent. To make a request, email support@getchou.com. You may also complain to your local data protection authority.
- Legal bases (EU/UK): we process your data to provide the service you asked for (contract); health information such as symptoms only with your explicit consent, given by choosing to log it, which you can withdraw by deleting it; and for security, abuse prevention and cost control (legitimate interests).
7. Security
Data travels over encrypted connections (HTTPS/TLS). Every request is tied to your signed-in account, and one account cannot read another's data. Passwords are stored as salted hashes. Meal photos are only served to the signed-in account that took them. No system is perfectly secure, and we can't guarantee absolute security.
8. Children
Chou is not intended for children. You must be at least 13 years old to use it, or at least 16 in the European Economic Area and the United Kingdom (or the higher minimum age where you live). We don't knowingly collect data from children below these ages. If you believe a child has created an account, contact support@getchou.com and we will delete it.
9. Not medical advice
Chou is a journal, not a medical device. Food identification, portions and nutrition values are estimates and may be wrong. Patterns are statistical observations from your own entries and do not show cause or diagnose any condition. Chat replies are generated by AI and are not medical advice. Talk to a qualified health professional about symptoms, allergies or diet decisions. In an emergency, contact your local emergency number.
10. International transfers
Our backend is hosted in the United States, and our service providers may process data in other countries. Where required, transfers rely on appropriate safeguards such as the providers' standard contractual clauses.
11. Changes to this policy
We may update this policy. We'll change the effective date above, and for material changes we'll tell you in the app or by email before they take effect.
12. Contact
Eureka Software Factory
Email: support@getchou.com