Legal
Privacy Policy
Astyq is designed to keep your saved nutrition diary on your iPhone while using cloud services only for the AI features you choose to use.
Effective August 8, 2026
The short version.
Your saved diary, frequent foods, goals, and profile are stored locally in the app. If you enable AI processing, the meal text or short voice recording needed for that request is sent through Astyq’s backend to OpenAI. Astyq does not sell personal data or use it for targeted advertising.
1. Who we are
Astyq is operated by the developer identified as the seller of the Astyq application on its Apple App Store product page (“Astyq,” “we,” “us,” or “our”). This policy applies to the Astyq iOS application, the website atgetastyq.com, and support communications.
For privacy questions or requests, emailprivacy@getastyq.com.
2. Information handled by Astyq
Information stored on your iPhone
Astyq stores the following inside the app’s local container:
- meals, ingredients, weights, calories, macronutrients, meal times, and the time zone recorded with a meal;
- frequently used meals and their local usage counts;
- nutrition goals and profile details you enter, such as height, weight, age, sex, average steps, and weight goal;
- language, country, regional formats, appearance, onboarding status, and AI-processing permission;
- a draft of an interrupted AI request, when needed to offer retry after the app restarts.
Astyq does not sync this saved diary, profile, or goal data to the Astyq backend. Apple may include the app’s local container in an iPhone or computer backup depending on your Apple backup settings.
Information used for AI meal analysis
If you explicitly enable AI processing and submit text, Astyq sends the meal description, input type, language/locale, time zone, request time, a random request identifier, a Firebase authentication token, and an App Check token to the Astyq backend. The backend sends the meal description and relevant locale/date context to OpenAI to prepare an editable draft. Firebase tokens, your saved diary, profile, goals, and open request identifier are not sent to OpenAI.
Information used for voice transcription
If you explicitly enable AI processing and record a voice entry, Astyq sends the temporary M4A audio recording, selected language, a random request identifier, a Firebase authentication token, and an App Check token to the Astyq backend. The backend passes the audio and language to OpenAI for transcription. The recording is held in memory by the Astyq backend only for the synchronous request and is not written to Astyq application storage.
Anonymous account and security data
Astyq uses Firebase Anonymous Authentication. Firebase assigns a persistent random user identifier without asking for your name, email address, or password. Firebase App Check and Apple App Attest help confirm requests come from a genuine Astyq installation. Astyq’s backend creates pseudonymous request-control records for duplicate prevention, rate limiting, fraud prevention, and cost protection. These records use keyed hashes rather than raw Firebase identifiers, meal text, audio, or AI results.
Diagnostics and network information
Google Cloud may process standard request metadata such as IP address, user agent, route, response status, and timing when delivering the backend. Astyq application logs include server-generated request IDs, route/status, timing, model/provider, and token counts, but do not intentionally log Firebase tokens, meal text, audio, prompts, transcripts, or AI drafts.
Website and support
The public website is delivered by Cloudflare. Astyq does not use advertising pixels, cookies, forms, or web analytics at launch. Cloudflare may process basic network and security information to deliver and protect the site. If you email support or privacy, we receive your email address, message, and any attachments you choose to send. Please do not send medical records or information that is not needed to answer your request.
3. Why we use information
- to store and display your nutrition diary locally;
- to transcribe voice and create an editable meal draft when you request AI processing;
- to authenticate requests and protect the service from abuse, duplicates, and excessive use;
- to operate, secure, troubleshoot, and improve reliability;
- to answer support, privacy, and legal requests; and
- to comply with law and protect users, Astyq, and others.
4. Service providers and disclosures
We use the following providers to operate Astyq:
| Provider | Purpose | Information involved |
|---|---|---|
| OpenAI | Meal analysis and voice transcription | Submitted meal text, locale/date context, or submitted audio and language |
| Google Cloud and Firebase | Backend hosting, authentication, app verification, request controls, logs, and secrets | Anonymous user ID, security tokens, request metadata, pseudonymous control records, and the AI request in transit |
| Apple | App distribution, App Attest, device permissions, purchases, and optional device backup | App/device attestation data and information Apple handles under your Apple account and settings |
| Cloudflare | Website delivery, DNS, security, and email routing | Website request/security metadata and routed email metadata/content |
We may also disclose information when required by law, to respond to valid legal process, to protect safety or rights, or in connection with a business reorganization. We do not sell personal information, share it for cross-context behavioral advertising, or permit third-party ad tracking in Astyq.
5. AI processing and your permission
AI processing is optional. Before the first AI request, Astyq identifies OpenAI and describes the categories sent. You may choose not to enable it and continue using the local diary and manual/quick entry features. You may turn it off later in Settings. Turning it off prevents new AI requests and cancels local handling of an in-flight response, but cannot recall information already sent for processing.
AI output is an estimate and remains an editable draft. It is never saved without your confirmation and cannot independently edit or delete existing diary entries.
6. Retention
| Information | Retention |
|---|---|
| Local diary, frequent meals, profile, goals, and settings | Until you delete the information, delete your account and data in Astyq, or remove the app; device backups follow your Apple settings |
| Temporary voice and export files | Deleted by Astyq after the operation and during later cleanup; iOS may also clear temporary storage. Copies you share follow the recipient app’s rules |
| Firebase anonymous account | Until you use Delete Account and Data, or Firebase removes it under applicable service settings |
| Pseudonymous request-control records | Completed/failed request states expire logically from 10 minutes to 24 hours; rate-limit counters in less than 3 days. Firestore’s asynchronous physical deletion may take approximately another day, so allow up to 4 days |
| Astyq operational logs | 30 days. Provider-required administrator/audit logs may be retained up to 400 days and are not intended to contain meal text or audio |
| OpenAI meal-analysis data | Astyq sends Responses API requests with storage disabled. Under OpenAI’s default controls, content may still appear in abuse-monitoring logs for up to 30 days, or longer when legally required or reasonably necessary to prevent harm |
| OpenAI transcription data | OpenAI’s published default table lists no application-state or abuse-monitoring retention for the Audio Transcriptions endpoint; service/system metadata may still be processed under OpenAI’s policies |
| Support and privacy emails | For as long as needed to respond and keep necessary support, fraud, or legal records, ordinarily no longer than 24 months |
More information about OpenAI API data controls is available in theofficial OpenAI documentation. Third-party retention may change; we update this policy when a change materially affects Astyq users.
7. Your choices and rights
- AI choice: enable or disable AI processing in Astyq Settings.
- Edit and delete meals: manage saved entries directly in the local diary.
- Export: create a Markdown copy and choose where to send it through Apple’s share sheet.
- Delete Account and Data: remove the Firebase guest account and Astyq local data from Settings.
- Privacy request: contact us to ask about access, correction, deletion, or other rights available where you live.
Because the account is anonymous and the diary remains on your device, we may be unable to locate or verify local diary data from an email address. In-app deletion is the direct method. SeePrivacy Choices for instructions.
8. Children
Astyq is not directed to children under 14, and the current profile flow does not accept an age below 14. Astyq does not knowingly collect personal information from a child below the minimum age permitted by applicable law. A parent or guardian who believes a child provided information may contact us.
9. Security and international processing
Astyq uses encrypted HTTPS connections, Firebase Authentication, App Check/App Attest, restricted service accounts, secret management, body-size limits, and pseudonymous request-control records. No system is completely secure. Service providers may process information in the United States and other countries under their applicable safeguards and terms.
10. Health and medical information
Food, weight, activity, and nutrition information may be treated as consumer health data in some jurisdictions. Astyq handles it as described in this policy. Astyq is a nutrition logging tool, not a healthcare provider, and is not represented as a HIPAA-covered service. Do not use Astyq for emergencies, diagnosis, or treatment decisions.
11. Changes to this policy
We may update this policy as Astyq changes. We will update the effective date and provide additional notice in the app when required. If a material change affects AI recipients or purposes, Astyq will request permission again before a new AI request where required.