Your controls
Privacy Choices
Astyq keeps the important controls in the app, close to the data they affect.
Last updated September 4, 2026
Meal, nutrition, weight, goal, and related AI-generated information may be consumer health data. See the separate Consumer Health Data Privacy Policy for applicable access, withdrawal, deletion, and appeal rights.
Product analytics is disabled at launch
This release sends no PostHog events and does not show a Usage Analytics setting. If a later build offers Usage Analytics, it will be voluntary and off by default, and Astyq will not interrupt meal logging with a product-analytics prompt. Enabling or declining it will not affect AI access, your local diary, or a subscription.
Turning analytics off immediately stops future collection, then clears analytics events waiting on your device and resets the random local analytics identity. If device storage interrupts that cleanup, analytics stays off and cannot be enabled again until cleanup succeeds. It does not automatically erase pseudonymous events already uploaded to PostHog. Those events remain subject to PostHog project retention/deletion controls. Because Astyq does not attach your Firebase account, name, or email address, we may be unable to locate a particular installation’s historical events from an email request.
Apple Ads attribution
Build 12 uses Apple’s first-party AdServices framework to measure whether an Astyq Apple Ads campaign, ad group, or keyword led to a new Production subscription. Astyq does not use IDFA, request ATT permission, track you across other companies’ apps or websites, or put meal, diary, nutrition, profile, goal, or voice data into attribution. The opaque Apple token and any campaign country/date fields are not stored or logged, and allowlisted attribution and conversion records normally expire after 180 days.
Use Delete Account and Data to remove the current guest account’s first-touch attribution record and the details in any conversion record it owns before that normal expiry. Astyq retains only a one-way keyed-hash subscription-lineage marker, without guest, campaign, keyword, ad, or product details, until the conversion’s original expiry (no longer than 180 days) to prevent an immediate restore from being counted twice. This does not cancel an Apple subscription or erase Apple’s own advertising and purchase records, which are governed by your Apple account and Apple’s policies.
Turn AI processing on or off
Open Astyq → Settings → AI processing. Turning it off blocks new meal-analysis and voice transcription requests. Your local diary and quick entry continue to work. Turning it off cannot recall a request already sent to Astyq’s backend and OpenAI.
Edit or delete diary entries
Use the Diary screen to edit or delete a saved meal. AI cannot edit or delete an existing entry. Dismissing an unconfirmed draft or starting another meal does not delete confirmed diary entries.
Export your diary
Astyq can prepare a Markdown export and open Apple’s share sheet. You choose the destination. Once shared, the copy is controlled by the destination app or person.
Delete your guest account and local data
- Open Astyq and go to Settings.
- Tap Delete Account and Data.
- Review what will be removed.
- Confirm the destructive action.
This removes:
- the Firebase anonymous guest account used by this Astyq installation;
- the local diary and frequent meals;
- the local profile, goals, language/country choices, appearance, AI permission, and onboarding state;
- any pending AI retry and Astyq-owned temporary voice/export files.
- the local analytics choice, queued analytics events, and random analytics identity; this also stops future analytics collection.
- the current guest’s Apple Ads first-touch record and the details in any Production-subscription conversion record owned by that guest; only the detail-free one-way dedupe marker described above remains until its original expiry.
Pseudonymous request-control records cannot be linked back through an Astyq user database and expire automatically in up to four days, including Firestore’s asynchronous deletion window. Standard operational logs expire after 30 days; provider-required administrator/audit records may be retained up to 400 days. OpenAI provider data follows the schedule described in the Privacy Policy.
Account deletion does not automatically erase pseudonymous product-analytics events that were already uploaded. They remain subject to the PostHog project’s retention/deletion controls, and the lack of an account or email link may prevent us from locating one installation’s historical events.
If an App Store subscription exists, deleting the guest account does not cancel it. Astyq deletes the free-analysis quota, removes that guest’s owned Apple Ads attribution/conversion details, and detaches only that guest-account binding, while retaining the detail-free dedupe marker and minimum pseudonymous Apple lifecycle record needed for renewals, refunds/revocations, and a legitimate later restore. Other eligible installations linked by a verified restore are not detached. Manage or cancel the subscription in Apple’s subscription settings before or after account deletion.
Request help or exercise a legal right
Depending on where you live, you may have rights to access, correct, delete, restrict, withdraw consent, or object to certain processing, and to appeal a decision. Email us with “Privacy Request” in the subject or “Privacy Appeal” for an appeal. We may need to verify the request while collecting as little additional information as practical.
The local diary is not available to Astyq’s server, so we cannot email it back or erase it remotely. In-app deletion or removing the app from your own device controls that local copy. Device backups are managed through Apple.