Privacy Policy
Last updated: 01.09.2026
This policy explains what DeficitAI collects, why, where it goes, and what you can do about it.
Some of what you enter is health data, which receives special protection under data protection law. We treat it that way.
1. Who controls your data
mixis, Timo Flloko, Kosovo, is the data controller.
Contact: suhejbmorina@gmail.com
2. What we collect
Account details, your name and email address, provided by Apple or Google when you sign in. We never see or store your password.
Profile and plan, sex assigned at birth, year of birth, height, activity level, goal, target weight, and pace. These are used solely to calculate your targets.
Food diary, what you log, when, which meal, and the nutrition figures at the time you logged it.
Weight history, the weigh-ins you record.
Meal photos, photographs you take or select for analysis. These are sent for analysis (see section 4) and stored with the entry they belong to, so you can see what you logged. They are deleted automatically after five days (see section 5).
Coach messages, the questions you ask the in-app coach.
Diagnostic data, anonymous technical information about crashes and errors.
We do not collect your contacts, your location, or your browsing activity, and we do not track you across other apps or websites.
3. Why we can use it, and why we do
Most of what you enter concerns your physical health, and we rely on your explicit consent to process it (GDPR Article 9(2)(a)). You give that consent when you accept this policy at sign-up, and you can withdraw it at any time by deleting your account in the app.
We use your data only to:
- calculate and show your nutrition targets;
- store and display your diary, weight history, and progress;
- analyse meal photos you submit, and show them back to you alongside the entry they created;
- answer questions you ask the coach;
- keep the app working and diagnose faults.
We do not sell your data. We do not use it for advertising. We do not share it with data brokers.
4. Where your data goes
Running the app means some data is processed by other companies on our behalf.
Authentication, Google (Firebase Authentication). Handles sign-in and holds your name and email.
Database and file storage, Supabase. Stores your profile, diary, weight history, and your meal photos. Hosted in West EU (Ireland). Photos are held in a private area that only your own account can read.
Photo analysis, gpt-4o-mini. When you use photo logging, the photograph is sent to this provider to be analysed, and their response is returned to your device. Do not photograph anything you would not want processed by a third party.
Coach, gpt-4o-mini. When you ask the coach a question, your question is sent to this provider together with your current targets, what you have logged that day, your recent weight trend, and your goal, so the answer can be about you specifically. Your name and email are never sent.
Nutrition databases — Open Food Facts and USDA FoodData Central. When you search or scan a barcode, the search term or barcode is sent to these services. Nothing about you personally is sent.
Your coach conversation history is stored only on your own device and is never uploaded to us.
These providers process data on our instructions. Some are outside your country, and transfers rely on appropriate safeguards such as standard contractual clauses.
5. How long we keep it
Your diary, weight history, profile and plan are kept while your account exists.
Meal photos are the exception. They are deleted automatically five days after they were taken, by a scheduled job that runs every night. A photo is useful for checking what an entry actually was, which people do within a day or two; keeping images indefinitely is neither necessary for that nor fair to you. The diary entry itself — the name, the calories, the macros — stays as long as your account does.
When you delete your account in the app, we delete your profile, diary, weight history, targets, photos, and badges from our database immediately, and the account is removed from our authentication provider. This cannot be undone.
Anonymous diagnostic data may be retained for a limited period.
6. Your rights
You can:
- access the data we hold about you;
- correct anything inaccurate, most of it is editable in the app;
- delete everything, from Settings, at any time;
- object to or restrict how we process it;
- receive a copy in a portable format;
- withdraw consent, deleting your account does exactly this;
- complain to your local data protection authority.
To exercise any of these, write to suhejbmorina@gmail.com. We respond within one month.
7. Children
DeficitAI is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
8. Security
Data is encrypted in transit. Access to your records is restricted at the database level so that only your own account can read them, and the same applies to your meal photos — they are stored privately and reached only through short-lived links generated for you. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the law requires.
9. Changes
We may update this policy. Material changes will be announced in the app before they take effect, and where the law requires it we will ask for your consent again.
10. Contact
suhejbmorina@gmail.com — mixis, Timo Flloko