Snack Privacy Policy
Last updated: October 8, 2026
Snack is a food-logging app. This page explains what data Snack collects, why, and where it goes.
What Snack collects
- Meal photos and descriptions you submit. When you photograph or describe a meal, that image or text is sent to Snack's backend, which forwards it to Google's Gemini API to estimate calories and nutrition. The photo or text itself is not stored permanently on Snack's servers. A failed submission may sit briefly (up to a few hours) in a retry queue before being reprocessed or discarded. Snack does keep the AI's reply to each submission, which is the nutrition estimate and the food names it returned (and, for troubleshooting, the complete reply exactly as Google's Gemini sent it), together with your opaque account identifier, in a private, encrypted store on AWS for up to 7 years. This is used to measure and improve estimate accuracy and to diagnose problems. A reply can include words you typed or text printed on a label in a photo. It never contains the photo itself.
- An opaque per-device account identifier. Snack assigns your device its own API key, derived from Apple's App Store purchase-receipt system (
AppTransaction), so your data is kept separate from other users'. This identifier by itself does not reveal who you are. Each request to Snack's backend also carries your app version number, used to see which versions are still in use and to ask a version too old to keep working to update.
- Your name and email address, via Sign in with Apple. Snack requires signing in with Apple to be used. Apple provides your name and email (which may be an Apple-generated private relay address) and Snack attaches them to your existing account identifier above. This is used purely for internal logging and support: attaching your activity and submissions to your account so issues can be diagnosed and support requests resolved, never for marketing, and never sold or shared with anyone else.
- Health data, read from and written to Apple Health, entirely on your device. If you grant access, Snack reads your active-energy (calories burned) and weight data from Health to show it alongside your food log, and writes the nutrition from meals you log back to Health. None of this ever leaves your device or reaches Snack's servers. It is a direct, on-device connection between Snack and Apple's HealthKit.
- Your food log itself. Stored on your device, and synced across your own devices via your personal iCloud account (Apple's CloudKit), the same way Apple's own apps sync your data. Snack's servers never see the contents of this log. If iCloud sync stops working, Snack reports technical sync-health details (described below), such as how many entries iCloud holds compared with your device, but never what those entries say.
- Crash, error, and technical diagnostic logs, via Sentry, including your name/email if you've provided them. If Snack crashes or hits certain error conditions, technical diagnostic information (a stack trace, your app version and device model, and a UX signal used to catch broken/unresponsive buttons: which on-screen control was involved and how many times it was tapped) is sent to Sentry, a crash-reporting service. Snack also sends Sentry a running technical log of app-lifecycle and troubleshooting events, for example when the app launches, or the status of a background sync, to help us diagnose reported problems in real time. If you've provided a name/email via Sign in with Apple, Snack attaches it to these Sentry reports too, so a specific report can be traced back to a real person while debugging rather than only an opaque device identifier. Beyond that name/email, these logs are limited to technical, non-personal detail by design: they never include your meal photos, descriptions, Health data, or any other content you've entered into the app.
- Server-side error reports, via Sentry. If Snack's own servers hit an unexpected error while handling a request, a technical report is sent to Sentry: which part of the server failed, a stack trace, an opaque job identifier, your app version, and your opaque account identifier. It does not include your meal photos, descriptions, Health data, or API keys.
- Whether your iCloud sync is working. Snack tracks on your device whether its iCloud sync of your food log succeeds. It reports a small status to its backend and to Sentry: when the last successful sync happened, how many app launches in a row the sync failed, the sync error code Apple returned, your app version, and, only when a sync problem has been detected, how many food entries iCloud holds versus your device and the date of the newest one. No entry contents (names, photos, descriptions, nutrition) are included. It is used only to notice and fix sync problems, for example so that a stalled sync does not go unnoticed for days.
- Push notifications, sent through Apple's Push Notification service, if you enable them. If you opt in, Snack sends a device token to its backend and uses it to notify you when a meal analysis you started finishes while you're not actively in the app. That notification's text may name the food items that were recognized (e.g. "Grilled chicken and rice"), so it can tell you what finished processing without having to open the app first. Delivery itself is handled by Apple's Push Notification service, the same infrastructure every iOS app's notifications go through.
What Snack does not do
- Snack does not sell your data or share it with advertisers.
- Snack does not run ads or marketing/engagement-tracking SDKs (e.g. cross-app advertising analytics).
- Snack does not write your meal photos or Health data into its server logs, and does not send them to Sentry. Server logs record technical events and the names of recognized foods; they are searchable for 90 days and are then archived privately on AWS and deleted after 7 years.
Third parties
Meal photos and descriptions are sent to Google's Gemini API solely to generate a nutrition estimate, under Google's own API terms. Snack's backend runs on Amazon Web Services (AWS); AWS stores the pieces described above (your opaque account identifier, and, if provided, your Sign-in-with-Apple name/email) but does not otherwise process your data independently. Crash/error diagnostics (described above) are sent to Sentry, under Sentry's own terms and privacy policy. If you enable push notifications, their delivery goes through Apple's Push Notification service, under Apple's own terms.
Your choices
Sign in with Apple is required to use Snack. You can revoke Health access at any time in iOS Settings → Health, or Settings → Snack. Deleting the app removes your on-device food log (unless synced to iCloud, where Apple's own iCloud data controls apply).
Deleting your data. To have the records Snack holds about you deleted (your account details, the saved nutrition replies, and any support requests you sent), email privacy@trysnack.app from the email address on your account, or tell us from inside the app. We will confirm it is you, delete those records, and reply within 30 days. Server logs contain only the opaque account identifier described above, never your name or email, so once your account record is deleted they can no longer be tied to you; they expire on the schedule described above. Your food log on your own devices and in your own iCloud is yours to delete from your devices and iCloud settings.
Changes to this policy
If this policy changes in a meaningful way, the "Last updated" date above will change to reflect it.
Contact
Questions about this policy or requests about your data (access, deletion) can be sent to privacy@trysnack.app, or through the app's own support option in Settings. General support: support@trysnack.app.