KETONOIR

Consumer Health Data Privacy Policy

Version 2.0 · Effective 2026-08-13

This policy applies to consumer health data and is provided under the Washington My Health My Data Act (RCW 19.373) and Nevada SB 370. It is a separate document from our general Privacy Policy, which continues to apply to all other information.

Ketonoir LLC is the entity responsible for the consumer health data described here. If anything in this policy conflicts with the general Privacy Policy in respect of consumer health data, this policy governs.

Version 2.0 is a substantial expansion of version 1.0. It names every category of consumer health data the product collects and every third party that receives any of it, including categories and recipients that version 1.0 did not list. Where this version and an earlier one differ, this version is the accurate one. Nothing here is a new practice being announced; it is a fuller description of what the product does.

The descriptions in this policy are true for every user. The rights in section 6 are given to Washington and Nevada residents by statute, and we honour them for anyone who asks.

1. Consumer Health Data We Collect, and Why

This section lists every category of consumer health data we collect. Because the statute makes this document a ceiling on what we may collect, use and share, the list is written to be exhaustive rather than illustrative. If a category is not named here, we do not collect it.

We do not collect consumer health data in order to advertise to you. We do use it beyond delivering the feature you are using at the time, in one way, and it is set out below rather than buried: we analyse it internally to operate the business (section 1.9).

1.1 Health screening responses

During onboarding we ask whether any of the following apply to you: pregnancy or nursing, kidney, liver or pancreatic disease, a history of eating disorders, medication for diabetes, blood pressure or blood thinners, gallbladder issues, type 1 diabetes, a heart attack, stroke or major cardiac event in the last six months, use of an SGLT2 inhibitor, and active cancer treatment.

Purpose. To decide whether AI coaching is made available to you or whether the app operates in tracking-only mode, and to give the AI coach the safety context it needs so its guidance accounts for your declared conditions. This is a safety control, not a marketing input.

What else happens to it. Your declared conditions are sent to Anthropic on every AI coach turn, so that the coach can take them into account. We separately record the outcome of the screening: how many conditions you flagged and the fact that your account is in restricted mode. That outcome is sent to our analytics provider against your account identifier, is visible to our operators, and is included in the operator analysis described in section 1.9. Your answers and the outcome are also written into the consent record described in section 7, which survives account deletion.

1.2 Biomarker and measurement data

Body weight and body composition, blood ketones (BHB), blood glucose, blood pressure (systolic and diastolic), blood lipid panel values (total cholesterol, LDL, HDL and triglycerides), and any free-text note you attach to a reading.

Where a reading was imported from Apple Health or Health Connect rather than typed in, we store two further things with it. One is the health platform’s own record identifier for that sample. The other is the name of the app or device that originally produced the reading — for example a continuous glucose monitor, a smart scale or a blood-pressure cuff. A device name can itself indicate a condition, so we treat it as consumer health data. It is kept permanently in the reading’s note field, and it is included in the biomarker history sent to Anthropic on an AI coach turn.

Purpose. To display your trends, to inform coaching guidance you ask for, to avoid importing the same reading twice, and to show you where a reading came from.

1.3 Diet, exercise and body profile

Meals and foods logged (name, portion, calories, protein, fat, carbohydrate, net carbs, fibre, meal slot and time), water intake, exercise, height, weight, goal weight, sex at birth, activity level, dietary preferences and diet type, allergies and sensitivities (both the standard allergen list and anything you type in yourself), health goals, and your birth year.

We also collect the food search terms you type, the product barcodes you scan — including barcodes of dietary supplements, which we look up against the NIH Dietary Supplement Label Database — and the restaurant chains and menu items you choose. Search terms and barcodes are sent to outside food databases, listed in section 4.1, so that we can return nutrition facts.

Purpose. To calculate your macro targets, produce your logs and forecasts, warn you when a logged food contains an allergen you listed, look up what you are eating, and confirm you are 18 or older. Only your birth year is retained; the full date of birth is evaluated on your device and is not transmitted to us.

1.4 AI coach conversations

Every message you send to the AI coach and every reply it sends you, kept verbatim. In the mobile app the whole conversation thread is stored under your account identifier. In the web beta, each exchange is stored with your message truncated to 500 characters and the coach’s reply to 800 characters.

We also keep coach memory: short free-form facts about you that the coach extracts from your conversations so it does not have to ask again. These are written by the model from whatever you told it, so they can contain any health information you have mentioned.

Purpose. To generate the coaching response you asked for and to give the coach continuity between sessions. Coach conversations are also read by our operators and used for internal analysis; see sections 1.9 and 4.

1.5 Photographs, camera frames and documents

All of the following leave your device and are sent to Anthropic for analysis. This is the complete list of image and document paths in the product.

  • Body-composition photographs. A full-body, front-facing photograph in minimal clothing. The analysis treats a heavily clothed subject as unusable. Sent together with your sex, any note you write with it, and your previous body-fat estimates.
  • Plated-meal photographs, taken with the camera or chosen from your photo library.
  • Refrigerator, pantry, freezer, counter and grocery-haul photographs. These show the inside of your home. A refrigerator in particular commonly holds refrigerated prescription medication such as insulin, GLP-1 pens or biologics, and the pantry analysis is instructed to list every visible item, mundane ones included, and to read package labels.
  • Recipe cards, cookbook pages, screenshots and handwritten recipes.
  • Meal-plan printouts, screenshots and photographs. A meal plan is often a document issued by a clinician or dietitian and can carry your name and clinical details.
  • Workout and training-program images.
  • Product-packaging photographs, used to read a barcode when the scanner cannot.
  • PDF documents. The recipe import, meal-plan upload and workout upload accept any image or PDF from your device and send the original file unchanged, including embedded metadata such as GPS coordinates, capture time and camera serial number.
  • Live camera video frames. In the web app on iOS Safari, the barcode scanner falls back to capturing a frame from the live rear camera roughly every 0.8 seconds and sending each frame to be read, for as long as the scanner is open. Those frames capture whatever the camera is pointed at, not only the barcode.

Two things about this are easy to miss, and we would rather state them than let you discover them. First, you may select any existing photograph from your device library rather than taking one for KetoNoir, and we cannot tell the difference. Second, an image is transmitted and analysed before we decide whether it is the right kind of image, so a photo the app then refuses has already been sent.

On mobile, a resized copy of the photograph is written into the app’s cache folder on your phone so it can be shown on the review screen. It stays on your phone until you or the operating system clears the app’s storage. We do not upload that copy again.

Purpose. To produce the nutrition estimate, body-composition estimate, recipe, pantry list, meal plan or barcode reading you asked for.

1.6 What we infer from your photographs

Analysing an image produces new health data about you that you never typed in. We treat all of it as consumer health data:

  • From a body photograph: an estimated body-fat percentage, range and category; a judgement of whether the subject appears to be under 18; a judgement of whether the subject appears severely underweight; and detection of eating-disorder language in the note you wrote. The age and eating-disorder findings exist to stop the feature running, but they are inferences about you, and they are returned to the app.
  • From a meal photograph: an estimated ingredient list including likely allergens, which the analysis is instructed to over-include rather than miss.
  • From a fridge or pantry photograph: a list of the items recognised inside your home, with quantity, category and storage location, saved to your pantry.
  • From a recipe photograph: the recipe, saved to your account together with a fingerprint of the specific image it came from.
  • From any scanned image: a classification of what the picture actually is, chosen from recipe card, fridge photo, meal plan, meal photo, food label, menu, or other.

Purpose. To produce the result you asked for, to keep your pantry and recipes usable afterwards, and to refuse an analysis that should not run.

1.7 Data read from Apple Health and Health Connect

If you connect Apple Health or Google Health Connect, we ask the platform for permission to read the following, and we read all of them:

  • Body weight.
  • Blood glucose.
  • Blood pressure, systolic and diastolic.
  • Sleep: minutes asleep, minutes in bed, bedtime, wake time, and per-night stage data (light, deep, REM, awake).
  • Active energy burned.
  • Basal or resting energy expenditure (BMR).
  • Step count.
  • Resting heart rate.
  • Heart rate variability.
  • VO2 max, or cardiorespiratory fitness.
  • Workouts and exercise sessions: activity type, start time, duration, and on iOS the calories burned.

We additionally request permission to read height and body-fat percentage on both platforms, and body mass index on iOS. We do not read any of those three. They appear on the operating system’s permission sheet only because we asked for them, and you can decline them without losing anything.

Blood ketones are not read from either platform — Apple Health has no blood-ketone type and we do not read a substitute for one. Every ketone reading in your account was entered by you or logged for you by the coach. Blood lipid values are likewise entered by hand only.

How far back we read. Weight, glucose and blood pressure are imported over the window you choose for the first import, which can be up to 365 days, and then re-imported on an ongoing basis. The Metabolic Forecast reads the last 28 days of sleep, activity, heart and workout data each time it runs. The Trends screen reads up to 365 days of those same signals each time you open it.

Where it goes. Weight, glucose and blood pressure are written into your KetoNoir account as biomarker rows, stored until you delete them or your account, and sent to Anthropic as part of your biomarker history on an AI coach turn. Sleep, active energy, basal energy, steps, resting heart rate, heart rate variability and workouts are not written into your account, but they are sent to Anthropic as part of the Metabolic Forecast, and the forecast produced from them is stored on our servers. VO2 max is read but stays on your device.

Turning it off. Switching the connection off inside KetoNoir stops the app presenting the connection as active, but it does not by itself revoke the permission you granted at the operating-system level, and imports can resume. The setting that actually governs is the one in Apple Health or Health Connect; revoke KetoNoir’s access there and reading stops. We are fixing the in-app control, and until that ships this is the accurate instruction.

Per-type control. The forecast signals listed above can each be turned off individually in the app. Weight, glucose and blood pressure are currently imported together whenever the connection is active: there is no working per-type switch for those three, and blood pressure has no switch at all. We would rather say so than let the settings screen imply otherwise.

We never write anything back to Apple Health or Health Connect. We hold read permission only, on both platforms.

1.8 Data we derive from all of the above
  • Macro targets; 7- and 14-day macro trends; adherence to the 20 g net-carb cap; the list of days you went over it; streaks; and the Glucose Ketone Index (GKI).
  • A count of days in ketosis, produced by applying a 0.5 mmol/L threshold to your ketone readings. That is a metabolic-state inference we make about you, not a value you gave us.
  • The Metabolic Forecast: a written projection generated by Anthropic from your food log, weight, ketones and the health-platform signals in section 1.7, together with a rolling history of its headline, confidence, projected ketone level and projected 72-hour weight change.
  • Sleep quality and sleep efficiency buckets; workout intensity and activity-type classifications; and 28-day median baselines for resting heart rate, heart rate variability and sleep.
  • Adherence measures: days active, days food logged, weigh-in count, food-log count, coach-message count, and first and last active day.
1.9 Operational and internal analysis

Our operators can see, and use to run the business, your account identifier, your engagement and cost figures, your consent and screening outcome, your adherence measures, and your coach conversations in readable form. Operators can also write free-text notes about an account.

When an operator uses the AI panel in our internal tools, the contents of that screen are sent to Anthropic for the operator’s analysis. That can include your account identifier, your outcome data, the operator’s notes about you, and up to ten verbatim turns of your coach conversation. This is a different purpose from answering a question you asked, and section 4.1 lists it separately for that reason.

Our analytics provider holds a profile identified by your account identifier and your email address. Against it we send the calories, protein, fat and carbohydrate totals of each meal you log, which biomarker fields you log, your calorie target and how far a plan deviates from it, the fact that you edited your allergies, your screening outcome, which health chart you were looking at, and your subscription events. It does not receive your biomarker values, your declared conditions, your photographs or your coach conversations.

2. Where the Data Comes From

  • Directly from you, when you type, log, answer the screening, speak to the coach, or take or upload a photograph or document. This is the source for most of the consumer health data we hold.
  • From your device, where you have granted the permission: the camera (including the continuous camera frames described in section 1.5) and your photo library, which gives the app access to photographs you did not take for KetoNoir.
  • From Apple Health or Health Connect, where you have connected the platform and granted permission at the operating-system level. Section 1.7 lists exactly what we read, how far back, what leaves the device and what happens when you disconnect. Blood ketones and blood lipid values are never read from a health platform.
  • Derived by us, or by the AI models we use, from all of the above: macro targets, streaks, averages, forecasts, ketosis inferences, and the inferences drawn from your photographs in section 1.6, including apparent age, apparent severe underweight, eating-disorder signals and likely allergens.
  • From our own operators: any free-text note an operator writes about your account.

We do not buy consumer health data, and we do not obtain it from data brokers, advertising networks, or public records.

3. What We Do NOT Do

  • We do NOT sell the consumer health data described in section 1. Under RCW 19.373.060 a sale would require your written authorization on a specific statutory form. We have never sought one and do not intend to.
  • We do NOT target advertising to you using consumer health data, and we do not send your biomarkers, food log, coach conversations, photographs, screening answers or health-platform data to any advertising network.
  • We do NOT use your data to train AI models. Our AI provider processes our traffic under commercial terms that exclude training.
  • We do NOT write anything back into Apple Health or Health Connect.
  • We do NOT operate a geofence around any health care facility.

Two limits on the above, so that it is not read more widely than we mean it. Our analytics provider does receive some health-related event data tied to your account, and our public marketing websites do carry advertising pixels that fire if you accept marketing cookies. Both are described in section 4, in sections 4.1 and 4.4 respectively. Neither involves your biomarker values, your coach conversations, your photographs or your screening answers.

4. Who We Share It With

Below is every third party that receives consumer health data, or data derived from it, and what each one receives. Most of them act only on our instructions, to run the Service. One does not, and we have separated it out rather than blend it in: section 4.3, advertising and web analytics on our public websites.

Washington law treats a disclosure to a service provider as something other than a “share” only where that provider is bound by a contract setting out our processing instructions. We are putting those contracts in place and do not yet have all of them signed. Until we do, read everything in section 4.1 as a disclosure we are telling you about, rather than as something the processor exception removes from the conversation.

4.1 Service providers that receive consumer health data
  • Anthropic, PBC: artificial intelligence. Receives, in order to answer you: your coach messages and the coach’s replies; your declared medical conditions; up to 14 days of biomarker readings including the note naming the source device; your body profile; your food log and macro trends; your coach memory; and every photograph, camera frame, image and PDF listed in section 1.5. Receives, as part of the Metabolic Forecast: your sleep, active and basal energy, steps, resting heart rate, heart rate variability, workouts and 28-day baselines read from Apple Health or Health Connect. Receives, for our operators rather than for you: account identifiers, operator free-text notes, and verbatim excerpts of coach conversations. Processed under Anthropic commercial terms and not used to train models.
  • Supabase, Inc.: database and sign-in. Stores your account and credentials, profile, biomarkers, food log, coach memory, saved and scanned recipes including the image fingerprint, scheduled meals, allergies and your screening outcome. Holds the link between your account identifier and your email address.
  • Upstash, Inc.: key-value storage. This is a primary health-data store, not only a counter store. It holds your daily food log, your full coach conversation thread, the verbatim web-beta coach transcripts, your declared conditions inside the consent record, your body-fat estimate history, your pantry inventory, and your generated Metabolic Forecast and its rolling history.
  • Vercel, Inc.: application hosting. Every request and response passes through Vercel, including photographs, PDFs, coach messages and biomarker uploads. Vercel holds the request logs.
  • Netlify: marketing website hosting. Hosts ketonoir.ai, ketonoir.com and our science site, including the published copy of this policy. Sees the IP address, browser and page path of every visitor to those pages.
  • Sentry: crash and error reporting. Receives stack traces, the page or endpoint involved, timing, and diagnostic breadcrumbs, which include which scan you ran, how long it took, your quota state, the confidence of a result, and up to 200 characters of raw model output when a response cannot be parsed. Health, food, biomarker and coach fields are removed by field name and by size before the report is sent, and your email address and IP address are stripped. It would not be accurate to say Sentry receives stack traces only.
  • PostHog: product analytics. Holds a profile identified by your account identifier and your email address, carrying the events described in section 1.9, including per-meal macro totals and your health-screening outcome. Does not receive biomarker values, declared conditions, photographs or coach conversations.
  • Postmark: email delivery. Receives your email address and, inside the weekly and monthly progress report, your days logged, average calories, average net carbs, average protein, average fat, weight change in pounds, and average blood ketone reading in mmol/L. It would not be accurate to say our email provider never receives consumer health data.
  • MailerLite: email delivery and marketing lists. Receives your email address, the time you opted in and the IP address you opted in from, and which list you are on, which distinguishes free from paying users. No biomarkers, food log or coach content.
  • FatSecret, USDA FoodData Central, Open Food Facts, Open Products Facts, and the NIH Office of Dietary Supplements Dietary Supplement Label Database: food, product and supplement catalogues. Receive the food search terms you type and the barcodes you scan, including supplement barcodes. We send these from our servers, so your IP address is not passed on and the query is not tied to your account.
  • wger.de: exercise catalogue. Receives the exercise filters you choose, sent from our servers with no identifier and no IP address.
  • Apple and Google. Apple Health and Health Connect are the source of the data in section 1.7 and not recipients of it; we hold read permission only. Apple and Google do receive your purchase, subscription and sign-in information. Google additionally receives your IP address, browser and the KetoNoir page you are on every time a page of the web app loads, because our fonts are served from Google’s font servers rather than our own.
  • Stripe and RevenueCat: payments and subscription state. Receive your account identifier, email address, purchase, price and subscription status. No consumer health data.
  • Cloudflare, Inc. Provides DNS for our domains, and also runs a web-analytics beacon on several pages of our marketing websites. Where that beacon runs, it reports the page address, referrer, browser and performance timings together with your IP address, and it is not behind the cookie banner.
  • Expo / EAS: mobile build service. Builds the mobile app. No runtime user data.
  • Hugging Face: model hosting. If you use the coach voice feature in a browser other than Safari on iOS, your browser downloads a speech model directly from Hugging Face, which discloses your IP address and the page you are on. No conversation content is sent.
  • ElevenLabs: speech synthesis, operator-facing only. Receives narration text derived from aggregated business metrics on our internal dashboard. No individual health records.
4.2 What these providers do not receive

No provider other than Anthropic receives your photographs or the contents of your coach conversations. Analytics, crash reporting, email, payment and subscription providers do not receive your biomarker values, your declared conditions, your photographs or your coach conversations. The exceptions to that sentence are stated in section 4.1 rather than hidden behind it: the meal-macro and screening-outcome events that go to PostHog, and the ketone, weight and macro averages inside the progress-report email that goes through Postmark.

4.3 Advertising and analytics on our public websites

This section is about ketonoir.ai, ketonoir.com and our science site. It is not about the app or your account data. Those pages carry a Meta (Facebook) pixel and a TikTok pixel. Neither loads unless you accept marketing cookies in the banner. If you accept, the pixel reports the address of the page you are on together with your IP address, your browser and that network’s own cookies. The pages carrying the pixels include health-topic pages: our clinicians page, and the page on which a copy of this policy is published. The TikTok pixel reports the page path as a named “ViewContent” event.

A page address on a ketogenic-health site can indicate an interest in a health condition, so we treat this as capable of being consumer health data even though no account, biomarker or health record is involved. Decline the banner and neither pixel loads. The Cloudflare beacon described in section 4.1 is not currently behind that banner.

Our iOS app also carries the advertising-attribution identifiers of these two networks, which authorise Apple to send them install and conversion notifications about the app. Those notifications carry no health data.

5. Consent and Legal Basis

5.1 Washington and Nevada

Washington law requires your consent before we collect consumer health data, a separate consent before we share it, and a signed authorization on a statutory form before any sale. We ask for consent to collection when you accept this policy and the disclaimers during onboarding, and again at the operating-system level before anything is read from Apple Health or Health Connect. We do not sell, and have never sought a sale authorization.

One place where our consent mechanics do not yet match this document. We state it here rather than leave you to find it. We do not yet take a KetoNoir-side consent for health-platform reading that is separate from the operating system’s own permission sheet. Section 1.7 tells you how to stop it. Until that consent step exists in the product, treat this policy as our disclosure of what happens and as your notice of how to refuse.

5.2 GDPR: our lawful basis is your explicit consent

If you are in the United Kingdom or the European Economic Area, almost everything in section 1 is data concerning health, and therefore special-category personal data under Article 9(1) of the GDPR. Our lawful basis for processing it is your explicit consent under Article 9(2)(a), together with Article 6(1)(a). We do not rely on legitimate interests, on contractual necessity, or on the scientific-research condition in Article 9(2)(j), for any health data.

We accept what that basis costs us. Consent must be freely given, specific and informed, so it reaches only what this policy describes: if we want to process a new category, or send it somewhere new, we have to update this policy and ask you again first. Consent is also separable. You can use the app and refuse the health-platform connection, or the photograph features, and the rest keeps working.

Withdrawing consent. You may withdraw at any time, for all of it or any part of it, and it must be as easy to withdraw as it was to consent. Withdrawal operates going forward: it stops the processing, and it does not make what we already did unlawful. When you withdraw consent to a feature, we stop the collection that feature performs, and we delete what it produced if you ask us to. When you withdraw consent to our processing your health data at all, we cannot operate the account, so we treat that as a deletion request and close it. Withdrawal never limits your separate right to have what we already hold deleted.

To withdraw: turn the feature off in the app, revoke KetoNoir’s access in Apple Health or Health Connect, or write to the address in section 8 telling us what you are withdrawing.

Several recipients in section 4 are in the United States. Where we transfer personal data out of the United Kingdom or the European Economic Area we rely on the same explicit consent, and on our providers’ standard contractual clauses where they offer them.

6. Your Rights

If you are a Washington or Nevada resident, you have the following rights regarding consumer health data. We will not discriminate against you for exercising them. We honour the same rights for any other user who asks.

  • Right to confirm and access. You may ask whether we collect, share or sell your consumer health data, and receive a list of all third parties with whom we have shared it, together with contact information for each. Section 4 is that list, and we will give you an account-specific version on request.
  • Right to withdraw consent. You may withdraw your consent to our collection and to our sharing of your consumer health data at any time, in whole or in part. Section 5.2 sets out what happens when you do.
  • Right to delete. You may ask us to delete your consumer health data. Section 6.2 sets out exactly what deletion reaches and what it does not.
  • Right to appeal. If we decline a request, you may appeal. If we deny the appeal, we will provide you with a way to contact the Washington Attorney General to lodge a complaint.
6.1 How to exercise them

Email legal@ketonoir.ai with the subject line “Consumer Health Data Request” and tell us which right you wish to exercise. We respond within 45 days, and may extend once by a further 45 days where reasonably necessary, in which case we will tell you why before the first period ends.

You may also delete your account and its associated data at any time from inside the app, under Profile, without contacting us.

We will ask you to confirm the request from the email address on your account. If we cannot verify that you are the account holder, we will tell you rather than act on an unverified request.

6.2 What deletion actually reaches

Deleting your account from inside the app removes, from our live systems, your profile, food log, biomarkers, coach conversation thread, coach memory, pantry, saved recipes, body-fat estimate history and forecasts, and closes your sign-in. Your consent records are deliberately kept, for the reason given in section 7.

We also notify service providers and direct them to delete your data, and we tell you which ones, because a blanket promise here would not be accurate. We send a deletion instruction to PostHog, which removes your analytics profile and its event history, to MailerLite, which removes you as a subscriber, and to RevenueCat, which removes your subscriber record. Each result is recorded, and a provider we could not reach is recorded as not notified rather than assumed done. Stripe is deliberately not deleted: payment and invoice records carry their own retention obligations under tax, anti-fraud and chargeback rules, and erasing them to satisfy a privacy request would breach a different law. Sentry, Postmark and Anthropic have no per-user deletion path. Sentry reports are already stripped of health, food, biomarker and coach fields before they leave the device. Postmark keeps suppression records so that an unsubscribe stays honoured. Anthropic holds no per-user store to delete under the commercial terms in force.

Two things that deletion does not reach today. We would rather tell you than let you assume otherwise. If you used the web beta rather than the mobile app, the verbatim coach transcripts from that beta are stored under a separate beta code and the in-app deletion does not remove them either. And the resized copy of a photograph in your phone’s app cache sits on your device, not ours; clearing the app’s storage removes it.

Write to us at the address in section 8 and we will remove any web-beta transcripts by hand and confirm to you when that is done.

7. Retention

We keep consumer health data for as long as your account is active, so that the Service can show you your own history. When you delete your account we delete the associated consumer health data, to the extent set out in section 6.2.

Some specific periods, because “as long as your account is active” is not the whole picture:

  • AI coach conversations: kept until you delete them or your account, and in any event no longer than 24 months.
  • Photographs, camera frames and PDFs: not kept on our servers after the analysis that produced your result. What the analysis produced is kept. See the next three entries. On mobile, a resized copy of the image stays in the app cache on your phone until you or the operating system clears it.
  • Content extracted from a photograph or PDF: the model’s output, up to 800 characters per request, is written into the web coach log with no expiry and is readable by our operators.
  • Body-fat estimates from a body photograph: the estimate, its range, its category and the date are kept indefinitely, together with a rolling history of your last 26 estimates, and are fed back as context into later estimates.
  • Pantry inventories recognised from a fridge or pantry photograph, and recipes scanned from a recipe card together with the fingerprint of the source image: kept until you delete them or your account.
  • Metabolic Forecasts: the generated forecast is kept per day, with a rolling history of the last 30.
  • Consent and disclaimer records: seven years, as described immediately below.

One narrow exception to deletion: records of which disclaimers and policies you accepted, and when, are retained for seven years as a legal compliance record. Those records include the outcome of your health screening and the conditions you declared, because that is the evidence that the safety gate was applied correctly. They are not used for any other purpose.

8. Contact

Ketonoir LLC
1145 Santa Fe Drive #1297
Weatherford, TX 76087-3846
legal@ketonoir.ai

KetoNoir · Consumer Health Data Privacy Policy · v2.0 · Effective 2026-08-13
Privacy PolicyTerms of Service