Consumer health privacy
Consumer Health Data Privacy Policy
This notice explains the consumer health data Astyq handles, why it is needed, where it goes, and how to exercise your rights.
Effective September 4, 2026
The important boundary.
Your saved diary, profile, and goals stay in Astyq’s local storage on your iPhone. Astyq sends a meal description or short voice recording for AI processing only when you request that feature. Astyq does not sell consumer health data, use it for targeted advertising, or use health-location geofencing. Apple Ads attribution is kept separate and never includes meal, diary, nutrition, profile, goal, or voice data.
1. Scope and operator
This Consumer Health Data Privacy Policy supplements Astyq’s Privacy Policy and applies where consumer health privacy laws, including Washington and Nevada law, provide relevant rights. Astyq is operated by Gennadii Dobretsov, an individual developer established in Kazakhstan (“Astyq,” “we,” “us,” or “our”).
Contact privacy@getastyq.com for a consumer health data request or question.
2. Consumer health data categories and sources
For this notice, Astyq treats the following as consumer health data when it is linked or reasonably linkable to you or your installation:
- Meal and nutrition information: meal descriptions, ingredients, portions, grams or ounces, calories, macronutrients, meal times and dates, time zones, frequent meals, and local usage counts.
- Profile and goal information: height, weight, age, sex, average steps, weight goal, and calorie or macronutrient goals you enter.
- Voice meal information: a short recording and transcript when you choose voice input.
- Derived information: editable ingredients, portions, calories, and macronutrients generated from your submitted description or recording, plus progress calculated from saved entries and goals.
- Related identifiers and context: a Firebase anonymous identifier, random request identifiers, language/locale, country, local date/time context, and subscription or security state when associated with use of these features.
Sources are you; your interactions with Astyq; calculations performed locally in the app; AI drafts and transcripts returned for a request; iPhone language, locale, and date/time settings used for that request; and Apple, Firebase, or App Attest information used to verify an installation and subscription. Astyq does not collect meal photos, precise location, HealthKit data, medical records, medication, symptoms, or diagnoses in the launch product.
3. How Astyq collects and uses this data
| Processing | Data and purpose | Where it happens |
|---|---|---|
| Diary and goals | Save, display, edit, export, and calculate daily progress from meals, nutrition values, profile, and goals | Locally in Astyq’s app container on your iPhone; an Apple-managed device backup may include that container under your backup settings |
| AI meal analysis | Use a meal description plus relevant language/locale and local date/time context to prepare an editable nutrition draft you requested | Astyq’s Google Cloud backend and OpenAI |
| Voice transcription | Transcribe the short meal recording and selected language, then analyze the resulting meal description | Astyq’s Google Cloud backend and OpenAI; Astyq does not write the recording to backend application storage |
| Access and security | Authenticate a pseudonymous guest, enforce included analyses and paid access, prevent duplicate or abusive requests, process restores, and protect the service | Firebase, Google Cloud, Apple, and Astyq’s pseudonymous backend records |
| Support and legal requests | Respond to information you choose to include in an email and comply with applicable law | Astyq’s support mailbox and Cloudflare email routing |
Astyq collects and uses this data to provide a feature you request or after the applicable voluntary choice. AI processing is disabled until you make the in-app choice presented before the first AI request. Manual diary and quick-entry features remain available without AI processing.
Apple Ads attribution is outside the health-data flow
Build 12 may retain allowlisted Apple Ads campaign, ad-group, keyword, ad, conversion, claim, and placement identifiers associated with a pseudonymous guest account and a newly verified Production subscription. Astyq does not place consumer health data in the AdServices token or attribution records, disclose consumer health data to Apple for this measurement, or combine attribution with meal, diary, nutrition, profile, goal, voice, or optional PostHog data. It does not use IDFA or cross-app tracking.
4. Service providers, recipients, and data disclosed
Astyq has no affiliates and does not disclose consumer health data to third parties for their own independent marketing or commercial purposes. The following service providers or platform recipients may handle data only for the described Astyq or user-requested service:
| Provider or recipient | Data involved | Purpose |
|---|---|---|
| OpenAI | Submitted meal text with relevant locale/date context, or submitted audio and language; resulting transcript or editable draft | The meal analysis or transcription you request |
| Google Cloud and Firebase | The AI request in transit, Firebase anonymous identifier and tokens, app-verification data, standard network metadata, and pseudonymous request/quota records | Backend hosting, authentication, app verification, security, rate limits, and subscription access |
| Apple | App and device attestation, subscription status and Apple-signed purchase information; local app data only if included in a backup you control through Apple settings | Platform security, App Store purchases and restores, and optional device backup |
| Cloudflare | Website request/security metadata and information you choose to send by support or privacy email | Website delivery, security, and email routing |
| PostHog EU Cloud, only in a later build that offers Usage Analytics and only after opt-in | Random install-scoped identifier and selected content-free product-interaction events; no meal, audio, nutrition, profile, or goal data | Optional measurement of Astyq’s own product flows after your separate opt-in |
We require providers that process personal information for Astyq to protect it consistently with this notice and applicable agreements, and we do not authorize unrelated uses. A provider may also perform limited security, abuse-prevention, or legal processing described in its applicable terms. Retention details are in the generalPrivacy Policy.
5. Product analytics remains disabled
This release leaves product analytics entirely disabled and sends no PostHog events. If a later build offers Usage Analytics, it will be separate, voluntary, and off by default. Only after you turn it on may Astyq send a random install-scoped identifier and selected product-interaction events to PostHog EU Cloud to understand Astyq’s own onboarding, meal entry, paywall, purchase, restore, and retention flows.
PostHog does not receive meal text or names, ingredients, portions, audio or transcripts, calories or macros, diary dates, weight, profile or goal values, Firebase identifiers, Apple transaction identifiers, advertising identifiers, or precise location. Session replay, automatic capture, GeoIP enrichment, advertising use, and cross-site tracking are disabled. Unless the setting is available and you turn it on, Astyq sends no PostHog events.
6. No sale, targeted advertising, or geofencing
- Astyq does not sell or offer to sell consumer health data.
- Astyq does not share consumer health data for targeted or cross-context behavioral advertising.
- Astyq does not use an advertising identifier or permit third-party ad tracking.
- Apple Ads attribution measures Astyq’s own App Store advertising without receiving or using consumer health data.
- Astyq does not use precise location or a geofence to identify, track, collect data from, or advertise to people at health-care locations.
- No third party collects consumer health data over time across unrelated websites or online services through Astyq.
7. Your choices and rights
Depending on applicable law, you may ask Astyq to:
- confirm whether we collect, share, or sell consumer health data about you and provide access to it;
- provide a list of relevant third parties or service providers;
- stop future collection or disclosure and withdraw a prior consent;
- delete consumer health data, including by notifying relevant providers where required;
- review or correct consumer health data; and
- appeal a refusal to act on a request.
You will not be unlawfully discriminated against for exercising these rights. Astyq does not require you to create a new account to submit a request.
Direct controls in Astyq
- Edit or delete meals, profile values, and goals directly in the app.
- Turn off AI processing in Settings to stop future AI requests.
- If Usage Analytics is available, turn it off to stop future events and clear the local queue and analytics identifier.
- Use Delete Account and Data in Settings to delete the current Firebase guest account and Astyq’s local data.
Because your diary is local and the backend guest account is anonymous, Astyq cannot normally locate your local diary from an email address. The in-app controls are the most direct, secure method. Apple-managed device backups remain subject to your Apple backup settings.
Email requests and appeals
Email privacy@getastyq.comwith “Consumer Health Data Request” in the subject. For an appeal, use “Privacy Appeal.” Do not email meal content, medical records, passwords, tokens, or payment details. We may ask for the minimum additional information needed to authenticate a request and will explain when data cannot reasonably be linked to the requester.
We respond without undue delay and within 45 days. When reasonably necessary, we may extend once by up to 45 days and explain the extension during the initial period. Authenticated Nevada deletion requests are completed within 30 days when that law applies. A legally permitted delay for archived or backup systems depends on the applicable jurisdiction: Washington permits only a necessary delay of up to six months, while Nevada may permit up to two years. We answer an appeal in writing within 45 days and, if an appeal is denied, provide the appropriate state attorney general contact method.
8. Security and retention
Astyq limits access to what is reasonably necessary and uses HTTPS, Firebase Authentication, App Check/App Attest, restricted service accounts, secret management, body-size limits, pseudonymous backend records, and content-safe application logging. No security measure is perfect. The detailed retention schedule—including OpenAI, backend, log, subscription, and optional analytics retention—is in the Privacy Policy.
9. Material changes
We will update the effective date and provide additional notice in the app when required. Before collecting, using, or disclosing a new category of consumer health data, using it for a materially new purpose, or adding a materially different recipient, Astyq will update this notice and obtain affirmative permission where required.
10. Contact and official state information
Official sources: Washington My Health My Data Act and Nevada consumer health data law.