Platelight privacy policy

Last updated: 9 October 2026

Platelight is a calorie tracker that runs on your iPhone. It has no account and no analytics. This policy explains what happens to your information.

What Platelight keeps, and where

Your meals (including their photos), weigh-ins, profile (birth date, height, sex, goal), preferences, check-ins, meal plans and settings are stored on your iPhone, inside Platelight's own storage, and — unless you turn off iCloud sync in Settings — in your own iCloud account, so they're on your other devices and come back on a new iPhone. Your iCloud data is in your private database, encrypted by Apple; we, the developer, cannot see it and never receive any of it.

Delete all data in Settings removes everything Platelight stored on this iPhone and, when iCloud sync is on, in iCloud (so on your other devices too). Deleting the app removes the copy on that iPhone. The Plus server holds none of your meals; what little it holds expires on its own (see below). Export my data in Settings gives you your meals and weigh-ins as a CSV file.

How your meals are analyzed

Photos, descriptions and corrections are analyzed by Apple's on-device language model, on your iPhone, unless you turn on Platelight Plus (below). Weekly check-ins and meal plans (including new meal ideas) are always worked out on your iPhone.

If you turn on Private Cloud Compute in Settings (off unless you turn it on), a meal the iPhone isn't sure about, a written correction, or what you write about how you eat may be sent to Apple's Private Cloud Compute, which processes it and keeps nothing. We never see it. See Apple's description of Private Cloud Compute for details.

Platelight Plus (optional subscription)

If you subscribe to Plus and agree to it (the app asks first), some meals are analyzed by a larger AI model in the cloud: the meal's photo, what you wrote, or a correction you made is sent to our server, which passes it to OpenRouter (openrouter.ai), which sends it to Google's Gemini 3.8 Flash model, or, when that's unavailable, to OpenAI's GPT-6 Luna (run by Microsoft Azure). The text of the result (never the photo) then goes the same way to TypeSafe's Jev model, which judges how certain the estimate is. Requests go only to providers that keep no data and don't train on it, and our server doesn't store photos, descriptions or results either. Nothing about you is sent: no name, no account, no health data.

To make sure requests come from the genuine app, your iPhone proves it with Apple's App Attest. Our server keeps:

  • the resulting device key (a random key, not linked to you), deleted after 180 days without use;
  • which App Store subscription switched Plus on for which device keys, and when each last used Plus, deleted after 180 days without use;
  • how many meals were checked per day and month, and what they cost us per month, to apply the limits (the counts expire after a few days or weeks, the monthly cost after about a year).

When Apple tells our server about a refund, Plus is switched off for that subscription. Our server doesn't log IP addresses; its firewall counts requests per address for a few minutes to stop abuse, and keeps nothing. None of this is linked to you or used for advertising. You can stop sending meals to the cloud at any time in Settings › Platelight Plus.

Barcodes

Barcode lookups are part of Plus. When you scan a barcode Platelight doesn't know and Look up barcodes online is on (Settings), Platelight sends only that barcode number to Open Food Facts (openfoodfacts.org), an open food database, and to our server, which looks it up in USDA FoodData Central's product data. Nothing else is sent: no identifier, no account, no other data. Our server checks the request comes from the genuine app with the same random App Attest device key described above, on an active Plus subscription, and keeps no record of which barcodes were looked up. If a database knows a product's name but not its nutrition, Platelight estimates it from the name, on your iPhone or, with Plus's cloud model switched on, with that model; only the product's name is sent. You can turn online lookups off; then scanning the product's label once teaches Platelight the product instead. Without Plus, nothing about a barcode is sent; scanning the label works on your iPhone.

Apple Health

If you allow it, Platelight reads your height, weight, body fat and lean body mass from Apple Health, and saves the weigh-ins you add (weight, body fat, lean mass, BMI) and the calories and macronutrients of the meals it counts. You choose what to share in the Health app and can change it any time (Health › Sharing › Apps › Platelight). Data from Apple Health is never used for advertising or shared with anyone, and never leaves your iPhone through Platelight.

Other permissions

  • Camera: to photograph meals, nutrition labels, barcodes and scale displays. Photos are processed on your iPhone (or, with Plus on, as described above).
  • Photos: only the single photo or screenshot you choose in the system picker. Platelight never looks through your library.
  • Microphone and speech: only while the microphone in "Describe" is on (tap to start, tap to stop), to turn your words into text on your iPhone. Audio isn't recorded or kept.
  • Notifications: only if you turn on reminders.
  • Age range: where the law requires it, Platelight asks the system for your age range (not your birth date) to keep diet programs to adults. You can decline.

Children

Platelight isn't for children under 13 and doesn't offer weight-loss programs to anyone under 18.

Changes and contact

If this policy changes, the new version will be published here with a new date. Questions: contact@platelight.app.