Thalify Privacy Policy
1. Who we are
Thalify is a nutrition, activity, meal-planning and wellness app operated by the independent developer of Thalify ("Thalify," "we," "us," or "our").
App and service: Thalify
Official website: https://thalify.app/
Privacy contact: thalify.admin@gmail.com
2. Information Thalify may handle
Depending on the version and features you use, Thalify may handle:
- Profile and goals: name or nickname, age, sex, height, weight, goal weight, units, diet, cuisines, activity level, goals, conditions, allergies, dislikes and preferences.
- Nutrition and meal-planning records: foods, portions, calories, protein and other nutrition estimates, meal slots, pantry items, grocery items, planned meals, recipes and nutrition targets.
- Activity and fitness records: exercises, duration, sets, repetitions, weights, estimated calories, muscle groups and locally recorded workout history.
- Health Connect data in the native Android app: step count and exercise sessions, but only after you grant the corresponding Android Health Connect permissions.
- Weekly behavioral summaries: locally calculated seven-day summaries such as nutrition averages and target adherence, meal-timing patterns, commonly logged foods, workout/training counts, muscle-coverage summaries, weight trend, and—when Health Connect permission is available—aggregate movement values such as average steps, exercise minutes and session count.
- AI request data: the information needed for an AI-assisted action you start, such as a food or exercise description, profile and goal information, diet/cuisine choices, allergies, dislikes, calorie/protein targets, meal-planning context, or a compact weekly behavioral summary.
- Barcode values: a UPC/EAN or other supported barcode value decoded when you choose Scan package or entered manually for a product lookup.
- Web/TWA voice feature data where available: text produced by browser or operating-system speech recognition.
- Technical request information: ordinary network metadata such as IP address, device/browser type, timestamps, and security or diagnostic information that hosting or network providers may receive when a network request is made.
Thalify does not currently require a Thalify user account and does not intentionally request contacts, precise location, photos, or an advertising identifier as part of its core functionality.
3. Local storage
Native Android app
The native Android app stores profile, nutrition, workout, pantry, grocery, planned-meal, preference, approved personalization-context versions and related app state in private Android app storage on your device. This information is not automatically synchronized to a Thalify cloud account.
Web/TWA
The web/TWA version stores its local records in browser or installed-web-app storage on your device unless a feature you choose requires a network request.
Removing the native app or clearing its app data removes its local app data from that device. Clearing browser/site data removes local web/TWA data from that browser profile.
4. Health Connect
The native Android app can request permission to read Steps and Exercise sessions from Health Connect. Thalify uses those records to show movement context alongside nutrition and workout progress and to calculate local movement summaries.
- Health Connect access is optional and permission-controlled.
- Thalify does not write, edit or delete Health Connect records.
- You can deny or revoke Health Connect access at any time, and the rest of the app remains available.
- Missing Health Connect data is treated as unavailable, not silently converted to zero.
- Raw Health Connect step and exercise-session records remain on your device and are not sent to Thalify's AI service.
- If you explicitly run a weekly AI review, the app may include locally calculated aggregate values such as seven-day average steps, exercise minutes and exercise-session count in the compact weekly summary sent to AI.
- Thalify does not sell Health Connect data or use it for advertising.
Android and Google may separately process Health Connect and Play-distribution information under their own terms and privacy policies.
5. AI features and weekly personalization
AI requests run only after you choose an AI-assisted action, such as describing a food, requesting a recipe or meal suggestion, building a profile plan, looking up an exercise, or starting a weekly review. The native app uses local and deterministic processing where practical before making a network request.
Weekly intelligence
For a weekly review, Thalify first calculates a compact seven-day summary on your device. Depending on available data, that summary can include nutrition averages, target-adherence counts, meal timing, frequently logged foods, workout and training counts, strength/cardio summaries, muscle groups trained and low recent coverage, weight change, and aggregate Health Connect movement values.
The AI service receives the compact summary, not your raw food-log rows, raw workout records, or raw Health Connect records. AI may return coaching text, a focus habit, training guidance, and optional calorie or protein target recommendations. Thalify applies local safety bounds to numeric recommendations. AI recommendations do not silently change your approved personalization context or targets: the native app requires you to approve the weekly context, and target changes require an explicit apply action.
Other AI requests
Meal-planning requests can include diet and cuisine preferences, allergies and dislikes, calorie/protein targets, calories/protein already logged, pantry/grocery names and reviewed meal candidates. Exercise lookup can send the exercise name you enter and an optional preferred activity type. Recipe requests can send the planned meal name, nutrition summary, cuisine and food preferences. Natural-language food lookup can send the food or meal description you enter.
The Thalify AI gateway is operated through Cloudflare and may route a request to a configured AI provider. Configured providers may include OpenAI, Anthropic, or Moonshot AI/Kimi. These services may process request content and security metadata according to the production configuration and applicable service terms. Thalify does not send your complete on-device database with every AI request.
6. Barcode scanning and web voice
Native Android barcode scanning
If you choose Scan package in the native Android app, the scan UI is provided through Google Play services' code-scanning capability. With the current implementation, Thalify itself does not request the Android CAMERA permission. Thalify receives the decoded barcode value from the scanner; Thalify does not receive or store scanner camera frames.
The decoded barcode value, or a barcode you enter manually, is sent to Open Food Facts to request public product and nutrition information. Thalify then shows the returned product information for review before anything is added to your food log. If product nutrition is incomplete, Thalify identifies the lookup as incomplete rather than inventing missing nutrition values.
Web/TWA barcode scanning
Where barcode scanning is available in the web/TWA version, browser camera access may be requested. Camera frames are used to detect a barcode and are not intentionally stored by Thalify. The detected barcode value may be sent to Open Food Facts for product information.
Web/TWA voice input
If you choose web voice input, your browser or operating system may process microphone audio through its speech-recognition service. Thalify receives the resulting text. If you then submit that text to an AI feature, it is handled like text you typed.
7. Service providers and disclosures
Information is transferred only as needed to provide a feature, deliver the service, maintain security, comply with law, or protect users. Depending on the feature, recipients or processors can include:
- Cloudflare for the Thalify AI gateway, network delivery and security.
- Configured AI providers for AI requests you initiate.
- GitHub Pages for delivery of the Thalify website and privacy/support pages.
- Open Food Facts for barcode-based public product and nutrition information.
- Google/Android services for Google Play distribution, the native barcode scan UI, Health Connect and other Android platform functions.
- Your browser, operating system or speech provider when you choose a web voice feature.
Thalify does not sell or rent personal data and does not share personal data for targeted advertising.
8. How information is used
- To save and display the records, goals, trends, settings and approved personalization context you request.
- To calculate nutrition and activity estimates and support meal planning, recipes and workout tools.
- To show Health Connect movement context after permission.
- To prepare an on-device weekly summary and provide AI-assisted weekly coaching when you request it.
- To retrieve public product information after you scan or enter a barcode.
- To answer other AI-assisted requests that you explicitly initiate.
- To operate, secure, troubleshoot and maintain the app, website and related services.
- To comply with applicable legal obligations.
9. Retention and deletion
On-device data remains until you delete entries, clear Thalify app/site data, or remove the app. Thalify does not currently maintain a general user-account database that can restore your local records.
Network, AI and product-information service providers may retain limited request, security or diagnostic information for periods permitted by their service configuration and terms. To ask a privacy question or request deletion of information that may be associated with a service interaction, contact thalify.admin@gmail.com. We may need enough detail to locate the interaction, and in some cases there may be no server-side record that can be linked back to you.
10. Security
Thalify uses HTTPS for network requests, disables cleartext network traffic in the native Android app, and keeps AI-provider credentials on the server rather than embedding provider secrets in the Android app. Local Android data is stored in the app's private storage. No storage or transmission method is completely secure, so protect your device with appropriate device security.
11. Health and medical disclaimer
Thalify provides nutrition, fitness, meal-planning, tracking and general wellness tools. Thalify is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. It is not emergency medical advice and is not a substitute for a qualified healthcare professional.
12. Children
Thalify is not directed to children under 13 and is not intended for independent use by children under 13. If you believe a child has provided personal information through a network feature, contact us so we can review the situation.
13. Changes to this policy
We may update this policy when Thalify's features, data flows, providers or legal obligations change. The effective date at the top will be updated when changes are published, and relevant Google Play or in-app disclosures will be updated when required.
14. Contact
For privacy questions, concerns or requests, email thalify.admin@gmail.com.
Public privacy policy URL for Google Play and in-app disclosure: https://thalify.app/privacy.html