Privacy policy
How Zaad handles your information, why it is used, and the choices you have to control it.
01. Who we are and what this policy covers
Zaad is a nutrition logging and daily goal tracking app developed by OrbitCode, the party responsible for processing your data within the Zaad service. This policy covers the app, its account, sync and analysis services, and this website.
For privacy questions and requests, contact support@zaadapp.ai. We do not ask for your Apple or Google password or your full payment card details.
02. What data we process and why
Account and sign-in
Your account identifier, email address and sign-in information shared by Apple or Google, which may include your name depending on the provider and permissions. We use this information to authenticate you, manage your session, and link and restore your account data.
Profile and goals
Information you provide, such as date of birth, biological sex, height, current and target weight, activity level, dietary preferences and answers during plan setup. We use it to calculate nutrition goals and personalize your progress views.
Nutrition and activity records
Meals, drinks, water, exercise, quantities, nutrients, weight measurements, goal history, favorites, private foods and display settings. Data is stored on your device, and account-linked records are synced with Zaad so you can restore them and use them across your devices.
Search and contributions
Search terms, barcodes and food information requests are sent to the nutrition catalog service to return results. If you suggest a food for the public catalog, submit a report or vote, we process the content and your account identifier for review and abuse prevention. Approved food contributions may become available to other users; your diary and favorites are not public contributions.
Subscriptions and feature usage
Subscription status, product, expiry and renewal dates, purchase identifiers and analysis usage counts. We use these to unlock features, verify access, restore purchases and enforce usage limits. Apple processes payments; we do not receive your full payment card number.
Usage and technical information
The app uses Firebase Analytics to measure sessions and interactions, including completing setup, the method used to log food, opening the paywall and subscribing. Analytics are linked to your Zaad account identifier when you sign in. Technical information may include app or installation identifiers, device and operating system, language, approximate region, request times and service errors. We use it to operate and improve the app and understand its use.
Notifications and support
The app uses Apple Push Notification service and Firebase Cloud Messaging to register your device for notifications, including a notification token. It can also schedule local reminders according to your settings. When you contact support, we process your email, message and any attachments you choose to send so we can respond.
Some data is necessary for particular features: sign-in and sync need account data, and analysis needs the content you choose to submit. Camera, microphone, health and notification permissions are managed according to the features you choose to use.
03. Photos and AI analysis
Zaad asks for your consent to photo analysis and text analysis separately. When you analyze a photo, the image and any accompanying note are sent through Zaad to the analysis provider. For a written description, the text is sent to return a nutrition estimate.
The service supports Google Gemini directly and OpenRouter for routing requests to a model provider, including as a fallback when analysis is unavailable. The payload prepared by Zaad does not include your profile, weight history or email address. However, anything you write or that appears in the image is part of the submitted content.
Content processing and retention depend on the provider, service plan and settings. The Gemini terms distinguish paid services, whose content Google does not use to improve its models, from unpaid services, which may use content to improve services and may involve human review. With OpenRouter, retention and model-improvement practices vary by model provider and routing settings; see OpenRouter provider data policies. Submitting content for analysis does not mean it is deleted as soon as the request finishes or that all providers handle it in the same way.
A food photo or description and the details needed to estimate its nutrition are enough. Check that the photo and description do not include personal information unrelated to the analysis.
Meal photos saved in the app remain in its local files and are not included in ordinary nutrition record sync. This does not prevent the photo from being sent when you request analysis. Nutrition results you add to your diary may be saved in synced records.
You can withdraw consent for future analysis in Settings → Privacy & Data. Withdrawal does not automatically recall content already sent.
04. Apple Health, voice and permissions
Optional Apple Health connection
If you enable the connection and grant permission, Zaad reads weight to track it and may read date of birth, biological sex and height to complete your profile during setup. It can write calories, protein, carbohydrates, fat and weight to Apple Health according to your choices.
Values imported into your profile or weight history become part of your Zaad data and may be saved and synced with your account. Your Apple Health profile is not sent to the meal analysis provider, and its values are not included in Zaad’s custom analytics events. You can disable the connection in Zaad and manage read and write permissions in Apple Health.
Voice descriptions
With your permission, we use your device’s microphone and Apple’s speech recognition service to turn your description into text. Apple may process audio on its servers depending on the language and on-device availability. If you request analysis, the resulting text is sent to the analysis service; the audio recording itself is not sent to the meal analysis provider.
Camera, photos and notifications
The camera is used to photograph meals and scan barcodes and nutrition labels. Photo saving permission is used when you choose to save an image to your library. You can manage these permissions, microphone and speech recognition permissions, and notifications in iPhone Settings. Denying permission may disable the feature that needs it.
05. Who data is shared with
- Supabase: sign-in, account database hosting, record sync and service APIs. See Supabase’s privacy policy.
- Apple and Google: sign-in and services you choose, including Apple Health and Apple speech recognition according to your permissions.
- Google Gemini, OpenRouter and the model provider it routes to: processing the photo or description you choose to analyze. See analysis details and OpenRouter’s privacy policy.
- Google Firebase: app usage analytics and notification infrastructure. See Firebase’s privacy information.
- RevenueCat and Apple: managing and restoring purchases, subscriptions and access. RevenueCat uses your Zaad account identifier when linking a subscription to your account. See RevenueCat’s privacy policy.
- Email and hosting providers: operating the website, delivering support messages and retaining correspondence needed to respond.
Sharing is limited to data relevant to the stated purpose. Using a provider does not mean all your account data is sent to it. Processing is subject to applicable service terms and data protection agreements. OrbitCode’s obligations concerning provider selection and protection of your data remain in place under applicable law.
We may disclose information needed to meet a legal obligation or valid legal request, investigate fraud or misuse, or protect users’ and the service’s rights, subject to necessity and proportionality. If ownership or operation of the service is transferred, your rights apply to any data transfer, and notice or consent is provided where required.
06. Data retention and account deletion
Retention depends on the type and purpose of the data, service operation, your requests and legal obligations. The following criteria apply where no single period covers every record:
- Account and diary: data needed by the service is retained while your account exists, until you delete the records or account deletion is completed.
- Deletion and sync references: a compact identifier for a deleted entry may remain for the lifetime of the account to prevent it from returning through sync. It does not contain full meal details and is deleted with the linked account data.
- Local photos and files: meal photos remain in the app’s files and are not automatically synced. Copies you export, save to your photo library or include in device backups may remain under your control or that of your backup service.
- Support, security and purchases: retention is determined by the need to handle a request or dispute, prevent fraud, document transactions and meet legal obligations. It may differ from the lifetime of your account.
- Analytics, notifications, analysis content and backups: retention and deletion follow the relevant service’s lifecycle, settings and purpose. Completing an analysis request or deleting a Zaad account does not end all these records at the same moment.
Deleting your account in the app
- Open Settings → Account, choose account deletion and confirm.
- Deletion is scheduled after 30 days, and you are signed out.
- Signing in during that period cancels the deletion request.
- After the period ends, your sign-in account and linked profile and diary records are deleted during the next scheduled deletion job, usually within one additional day.
If exercising a deletion right requires a different procedure or faster handling under applicable law, contact support@zaadapp.ai. The technical waiting period does not limit your rights or any mandatory legal deadline.
Account deletion does not automatically cancel your Apple subscription. Manage it in your Apple account settings. The request also does not automatically delete exported files, photos saved outside the app or data previously written to Apple Health.
Catalog contributions and provider records
Published food data may remain available in the catalog after account deletion. The automatic account deletion flow also does not cover every suggestion, report and vote, and identifiers associated with these records may remain. You can ask support to delete this data or remove its link to your account; requests are reviewed according to your rights and the legal basis for retention.
Deleting data held by Firebase, RevenueCat or an analysis provider may require a separate procedure from deletion of Zaad’s account database. Contact us to coordinate the request and explain its scope and any retention exceptions required by law or necessary for legal claims or security. Deletion does not cover copies another party independently retains on a lawful basis.
07. Your rights and choices
Depending on applicable law, you may request information about how your data is processed, access and a copy of it, corrections, deletion, and withdrawal of consent to optional processing. Additional rights may include objecting to or restricting processing and complaining to the relevant authority.
- Export: open Settings → Privacy & Data → Export Data. The export is prepared on your device and includes available files such as meals, activity, water, weight, goals and profile information. You choose where to share it.
- Correction: edit your profile, goals and entries in the app.
- Optional permissions: disable photo or text analysis in privacy settings, and disable the health connection or device permissions in the relevant settings.
- Other requests: email support@zaadapp.ai with a description of your request, without unnecessary health information. We may ask for limited information to verify account ownership before acting.
The app currently has no separate switch to disable Firebase Analytics. Contact us about your analytics-related rights, deletion requests or objections to processing where available under applicable law. Disabling notifications does not disable analytics.
We handle rights requests without undue delay and within the periods required by applicable law. If additional information or a permitted extension is needed, we explain this and the reasons. You can contact us to challenge a response or complain to the relevant authority.
Some retention may continue where legally required or necessary to handle an ongoing request. Withdrawing consent does not affect the lawfulness of earlier processing based on valid consent.
08. Security and processing locations
Zaad service connections use HTTPS, and database permissions restrict users’ access to their own account data. Your private records are not published to other users. These measures reduce risk but do not guarantee absolute security. Protect your device and sign-in account, and take care when exporting or sharing data.
Service providers may process data in the United States or other countries outside your place of residence, depending on the service and its infrastructure. An Arabic or English interface does not mean data is stored in a particular country. Transfers are subject to applicable contractual and legal safeguards and obligations. Contact us with questions about how and where your data is processed.
Processing purposes and legal basis
We use your data to provide the features you request and manage your relationship with the service, on the basis of consent where required, and to meet legal obligations. We may process operational and security information to protect the service and prevent fraud where permitted by law. Requirements for health and sensitive data are considered when determining the appropriate basis. Consent to an optional feature is not open-ended consent for other purposes.
Some information you enter or import may reveal information about your health. Apple Health data is used for the health features you choose; we do not use it for advertising or include its values in custom analytics events. Nutrition goals and AI results are automated estimates you can review and edit, not diagnoses or medical decisions.
09. Age requirements and minors
Zaad is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. Users aged 13 to 17 use the service with a parent’s or legal guardian’s consent and supervision.
If we learn that a child under 13 has provided personal information, we review the situation and take the steps required to delete the data and account in accordance with applicable law. A parent or legal guardian can contact support@zaadapp.ai about a minor’s data or to request its review or deletion.
Applicable legal requirements concerning age, consent and the protection of minors’ data continue to apply and may vary by place of residence.
10. Privacy on this website
This website does not require sign-in, contain data collection forms, analytics tools or advertising, or set cookies. Fonts and images are served from its own files. On entry, we use your browser language to choose a supported language without requesting your location. If you choose a language manually, we save only that language value in your browser’s local storage to remember it on later visits. It remains until you change it or clear the site’s data, and is not used for analytics or advertising.
When you visit, the hosting server may process connection information such as IP address, request time, requested page and browser type to deliver pages, secure the service and diagnose errors. Hosting logs are separate from app account data; visiting the website does not require your nutrition or health records.
Following an App Store link or contacting us by email also involves another service governed by its own terms and policies. This page does not control those services’ cookies or logs.
11. Policy updates and contact
We may update this policy when Zaad’s features, providers or processing requirements change. We will state the date of the published version and provide appropriate notice or request new consent when required.
Questions about your data?
Contact OrbitCode at support@zaadapp.ai.
Read the Zaad terms of use or return home.