Privacy Policy
Thymi (“Thymi”, “we”, “us”) is a calorie tracker and food diary app. This policy explains what information we collect when you use the Thymi app and website, how we use it, who we share it with, and the choices you have. If you have a question about anything here, email us at fzofficial429@gmail.com.
1. Information we collect
Information you give us
- Account: your email address and password. We store only a secure, salted hash of your password, never the password itself.
- Profile and goals: what you tell us during setup and in settings, such as first name, goal, sex, birth year, height, weight, goal weight, pace, activity level, workouts per week, diet style, coach preference, units and time zone.
- Your food diary: meals and the foods in them, nutrition values, meal photos you choose to save, custom foods, saved meals, water, workouts and weigh-ins.
- Messages to us: if you email us, we keep the conversation so we can help you.
Information collected when you use Thymi
- Subscription status: whether you have Thymi Pro, which plan, when it renews or ends, and the store it was bought from. Payments are handled by Apple or Google; we never receive your card details.
- Usage needed to run the service: for example, how many AI logs you’ve used today, so we can apply plan limits.
- Technical logs: our servers record basic request information such as IP address, time and the endpoint called, to keep the service secure and working.
We don’t use advertising SDKs, and we don’t track you across other companies’ apps or websites.
Apple Health (optional)
If you turn on Apple Health in Me → Apple Health, Thymi reads your steps, workouts (type, time, duration and calories burned) and body weight from Apple Health, starting from the 30 days before you connect. You choose exactly what Thymi may read in Apple’s permission screen, and you can change or withdraw it at any time in iOS Settings → Health → Data Access & Devices → Thymi. Thymi doesn’t write anything to Apple Health.
- We use Apple Health data only to run Thymi for you: showing your steps, adding workouts to your day (and their calories to your budget if you turned that on) and updating your weight trend.
- We never use Apple Health data for advertising or marketing, never sell it, and never share it with third parties, including our AI provider. It is not used to train any AI model.
- Data synced from Apple Health is stored with your Thymi account so it appears across your devices, and it is deleted when you delete your account.
2. How we use it
- To create and secure your account and keep you signed in.
- To calculate your calorie and macro targets, show your days, trends, streaks and stamps, and keep your diary.
- To analyse meal photos, nutrition labels and descriptions you submit (see section 3).
- To look up foods. Searches and barcodes are matched against public databases (USDA FoodData Central and Open Food Facts). These lookups contain food names or barcodes, not your identity.
- To provide Thymi Pro, apply plan limits and restore purchases.
- To answer your messages, fix problems and prevent abuse.
Where data protection law requires a legal basis, we rely on performing our contract with you (running the app you asked for), your consent (for example, for processing the health information you choose to log, and for AI analysis), and our legitimate interest in keeping Thymi secure. You can withdraw consent at any time by deleting the data or your account.
3. AI meal analysis
When you log a meal by photo, nutrition label, description, “Fix it” correction or a workout description, Thymi sends that photo or text to our AI provider to identify the foods and estimate portions. Our AI provider is currently OpenAI. We send only what is needed for that request: the image or text you submitted, plus your diet style, allergies and goal so the estimate fits you. We don’t send your email address or name.
OpenAI states that data sent through its API is not used to train its models by default and may be retained for up to 30 days to monitor for abuse. If we add or change AI providers, we will update this policy.
AI results are estimates. Thymi checks them against food databases where it can and shows which items are verified and which are estimated.
4. Who we share it with
We don’t sell your personal information, and we don’t share it for advertising. We share it only with service providers that help us run Thymi, under contracts that limit how they can use it:
- OpenAI, for AI meal and workout analysis (section 3).
- RevenueCat, which manages subscriptions and restores purchases. It receives an app user ID and purchase information.
- Apple and Google, which process payments and manage subscriptions under their own privacy policies.
- Our hosting and infrastructure providers, which store and serve our database and meal photos.
We may also disclose information if required by law, to protect the rights and safety of our users or others, or as part of a merger or sale of the business, in which case this policy will continue to apply to your information.
5. How long we keep it
We keep your account and diary for as long as your account is open. When you delete your account (Me → Delete account), we delete your profile, diary, photos and weigh-ins from our live systems straight away. Copies in backups, if any, are removed within 30 days. Server logs are kept for a limited period for security. Apple, Google and RevenueCat keep purchase records under their own policies.
6. Your choices and rights
- View and edit: everything you log can be viewed, edited or deleted in the app.
- Delete: delete your account and all its data from Me → Delete account, or request deletion by email.
- Copy: email us to request a copy of your data.
- Photos and camera: Thymi uses the camera and photo library only when you choose to log a meal. You can change these permissions in your phone’s settings.
Depending on where you live (for example in the EU, UK or California), you may also have the right to access, correct, delete or port your data, to object to or restrict certain processing, and to complain to your local data protection authority. Thymi does not sell or share personal information as those terms are defined under California law. To make a request, email fzofficial429@gmail.com; we’ll respond within the time the law requires.
7. Security
Data travels over encrypted connections, passwords are stored only as salted hashes, sessions use short-lived tokens, and access to our systems is restricted. No service can be perfectly secure, so please use a strong password that you don’t use elsewhere.
8. Children
Thymi is not intended for anyone under 16, and we don’t knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.
9. International transfers
Our service providers, including OpenAI and RevenueCat, may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses.
10. Changes to this policy
We may update this policy as Thymi changes. We’ll change the date at the top, and if a change is significant we’ll let you know in the app before it takes effect.
11. Contact
Questions, requests or concerns about privacy: fzofficial429@gmail.com.
Health information. Thymi supports general wellness and healthy habits. It is not a medical device and does not provide medical advice.