KETONOIR

Privacy Policy

Version 1.7 · Effective 2026-08-13

Version 1.7 is an expanding amendment to version 1.6. It describes health-platform measurements, photograph and document types, and third-party recipients that were already part of the Service but were described too narrowly, or not at all, in version 1.6. It also corrects several statements in version 1.6 that claimed more protection than the Service actually delivers. Version 1.7 adds no new collection, use, or sharing, and it does not reduce any right you had under version 1.6. Every commitment made to you in version 1.6 is still made to you here. Because this version widens what we tell you about health data, we treat it as a material update under Section 12 and will notify you of it through the Service.

This Privacy Policy describes how Ketonoir LLC (“KetoNoir,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use the KetoNoir mobile application, web application, and related services (collectively, the “Service”).

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use the Service.

1. Information We Collect

1.1 Information You Provide Directly

Account Information. Name, email address, and password (encrypted). In the mobile app we ask for your date of birth to confirm you are 18 or older. The full date is evaluated on your device for that check alone and is never transmitted to or stored by KetoNoir. We retain only your birth year, which is used to calculate your macro targets. On the web, age is confirmed by a self-declared statement that you are 18 or older, and no date of birth is collected.

Profile Information. Height, weight, sex, body composition (if you provide it), activity level, dietary preferences, and health goals you voluntarily enter.

Health Screening Responses. Answers you provide during onboarding screening regarding pregnancy, organ disease, eating disorder history, medication use, gallbladder issues, type 1 diabetes, recent cardiac events, SGLT2 inhibitor use, and active cancer treatment. The screening determines whether AI coaching features are enabled or restricted to general tracking mode.

Food and Nutrition Data. Meals logged, macronutrient intake, water consumption, exercise, ketone or glucose readings (if you choose to log them), and any other data you enter into tracking features.

Biomarker and Health-Measurement Data. Measurements you choose to log, or that the AI coach records at your request and with your confirmation. These include body weight and body composition, blood ketones (BHB), blood glucose, blood pressure (systolic and diastolic), and a blood lipid panel (total cholesterol, LDL, HDL, and triglycerides). You may enter these manually. Where you have connected a health platform and granted permission, some of these measurements are read from Apple Health or Health Connect instead of being typed in. Section 1.3 lists in full what we read from those platforms. Blood lipid values and blood ketones are entered manually only and are not read from Apple Health or Health Connect, which do not expose those data types.

Meal Photos. Photographs of food you capture or select through the snap-logging features on mobile and on the web. These are uploaded to KetoNoir’s backend and forwarded to Anthropic’s Claude vision API. The model returns per-item and total macronutrients and, on the mobile path, a list of likely allergens in the dish. That allergen list is an inference drawn from a photograph, not something you told us, and it is stored with the resulting food-log entry.

Body Composition Photos. A full-body, front-facing photograph taken in minimal clothing, which you capture with the camera or select from your photo library. Heavily clothed images are rejected as unusable. The image is sent to Anthropic’s Claude vision API together with your recorded sex, any note you type, and your previous body-fat estimates. The model is instructed to return a body-fat estimate and also to judge whether the person in the image appears to be under 18, whether the person appears severely underweight, and whether your note contains eating-disorder language. Those last three are inferences about age and mental health derived from your photograph, and they are returned to the app. The resulting estimate, range, category and date are stored in your account and in a rolling history of your last 26 estimates, and are sent back to Anthropic as context on later analyses.

Refrigerator, Pantry and Kitchen Photos. Photographs of the inside of a refrigerator, freezer, pantry or cupboard, of a counter, or of a grocery haul, which you capture or select for the fridge-scan and pantry-scan features. These are sent to Anthropic’s Claude vision API. On the pantry path the model is instructed to list every distinct visible item, including mundane ones, and to read package labels. A photograph of a refrigerator or a kitchen commonly contains more than food: refrigerated prescription medication such as insulin, GLP-1 pens or biologics, alcohol, infant formula, other members of your household, and mail or documents on the door. Everything in the frame is transmitted, not only the food. Check the frame before you send it.

Recipe, Meal Plan and Workout Images and Documents. Photographs or screenshots of recipe cards, cookbook pages, handwritten recipes, printed or handwritten meal plans, and training programs, and PDF documents of the same, which you select for the import features. Both images and PDFs are sent to Anthropic’s Claude vision API. A meal plan is frequently a document issued by a clinician or dietitian and may carry your full name and clinical details. A PDF is transmitted in full, including pages you did not intend to send.

Product Packaging Photos and Live Camera Frames. When you scan a barcode in the mobile app, the code is decoded entirely on your device and no image leaves the phone. If you use the mobile upload-photo barcode option instead, the photograph is uploaded to KetoNoir’s backend and decoded there. On the web, a photograph of product packaging is sent to Anthropic to read the digits. On iOS Safari, where the browser barcode reader is unavailable, the web scanner falls back to capturing a still frame from the live rear camera roughly every 0.8 seconds and sending each frame to Anthropic, for as long as the scanner is open. Each of those frames contains whatever the camera is pointed at, including people, rooms and documents, not only the barcode.

Photos You Select From Your Library. Every photo feature above lets you pick an existing image from your device’s photo library instead of taking a new one. When you do, that image is transmitted and analysed in the same way, whether or not it was taken for KetoNoir.

Photos We Decline to Use. Each mobile scan asks the model to classify what the picture actually is, choosing among a recipe card, a fridge photo, a meal plan, a meal photo, a food label, a menu, or something else. If the picture is not the kind the feature expects, the app declines the scan and asks you to try again. By that point the image has already been transmitted to and read by Anthropic. The refusal happens after analysis, not before.

Location and Other Data Embedded in Image Files. Most photo paths re-encode the image before sending it, which strips the metadata your camera embedded. Three web upload paths do not: recipe import, meal plan upload, and workout program upload send the original file exactly as it sits on your device. If that file carries embedded metadata, including GPS coordinates, capture time and camera serial number, that metadata is transmitted with it.

What We Keep After the Photo Is Gone. The photograph or document file itself is not retained beyond what is necessary to complete the analysis. What the model extracted from it is retained: the food-log entry and its inferred allergen list, the pantry inventory recognised from a fridge or pantry photograph, a saved recipe together with a fingerprint of the specific image it came from, your body-fat estimate and its history, and, on the web import and barcode paths, up to 800 characters of the model’s output written to a conversation log that our staff can read and export. On mobile, a resized copy of the photo you scanned is written to the app’s cache on your own device and remains there until you or the operating system clears it. Section 5 sets out how long each of these lives.

AI Coach Conversations. Questions, messages, and responses exchanged with the KetoNoir AI coaching feature.

Coach Memory. Durable facts the AI coach extracts from your conversations and stores against your account so it can refer to them later. These are written by the coach rather than by you, and they may include health details you mentioned in passing.

Allergies and Sensitivities. The major allergens you select during setup and any additional allergens or sensitivities you type in yourself.

Search, Scan and Menu Selections. The food search terms you type, the food, product and supplement barcodes you scan, and the restaurant chains and menu items you choose. Search terms and barcodes are sent to outside food, product and supplement databases to look up nutrition information. Section 4 names them.

Payment Information. Subscription details processed through Apple App Store, Google Play Store, or Stripe. We do NOT store full credit card numbers on our servers. See Section 14 (Payment Information) for the full disclosure of how subscription payment data is handled.

Subscription State Metadata. When you purchase, renew, cancel, or change a KetoNoir Premium subscription, we receive and store subscription-state metadata associated with your account, including: the subscription tier (free, premium, or grandfathered), the source platform (Apple App Store, Google Play Store, or Stripe), the current subscription status (active, in trial, expired, in billing retry, or cancelled), the renewal or expiration timestamp, and the product identifier of the purchased package. This metadata is used to gate access to Premium features and to honor the entitlement you paid for. We do NOT receive or store the underlying card, bank, or wallet credentials used to make the purchase.

Communications. Feedback, support requests, and correspondence you send to us.

1.2 Information Collected Automatically

Device Information. Device type, operating system, app version, language settings, and a randomly generated 16-character device fingerprint that contains no personal information.

Advertising and Attribution Identifiers. Where you arrive at KetoNoir through a marketing link, an affiliate link, or an app store campaign, we collect and store the campaign parameters carried in that link (source, medium, campaign name) and the affiliate code, and on Android the install referrer string supplied by Google Play. These are attached to your checkout and subscription records and are sent to Stripe and to our analytics provider. Our public marketing pages, where you allow it through the consent banner, load advertising pixels operated by Meta Platforms, Inc. and by TikTok, and the iOS app declares both networks for Apple’s install and conversion attribution postbacks. Section 4 and Section 10 describe what those recipients receive.

Usage Data. Features used, session duration, pages viewed, time stamps, and in-app actions.

Consent and Disclaimer Logs. Records of which disclaimers, terms, and policies you have accepted, including version numbers (e.g., medical_disclaimer v1.0, ai_coach_disclaimer v1.1, health_screening v1.1, terms_of_service v1.4, privacy_policy v1.5), timestamps, app version, and device identifier. When a disclaimer version is materially updated, you will be re-prompted to accept the new version.

Log Data. IP address, access times, and diagnostic data.

Crash Reports and Performance Traces. Stack traces and runtime diagnostic data captured when the application encounters an error, processed by Sentry, our crash-reporting provider. A report carries the page or endpoint involved, timing, breadcrumbs describing what the app was doing, and the request data associated with the error. Before a report leaves your device or our server, a filter removes fields whose names indicate health, food, biomarker or coach content, and removes any single value larger than 2 kilobytes. Your email address and IP address are removed. Sentry also receives a 10 percent sample of successful, non-error performance traces, and our browser security-policy violation reports, which carry the page address and the blocked resource.

Two qualifications, because the plain claim of “stack traces only” is not accurate. First, reports about scanning and syncing carry operational detail: the feature used, how long it took, the HTTP status, your remaining scan quota, the model’s confidence, whether the wrong kind of image was detected, how many health-platform rows were imported, the field names present in a sample, serialized error details when a sync fails, and, when the model returns output we cannot parse, up to 200 characters of that raw output. Second, until app version 1.19.85 the filter did not run on the sampled performance traces, and as a result roughly one in ten successful body-composition analyses transmitted the body photograph to Sentry. That defect has been fixed and the filter now applies to both errors and traces.

Analytics Data. Event-level behavioral data processed by PostHog, our analytics provider. It is not anonymous and it is not only aggregated. Your events are attached to a profile identified by your account id and carrying your email address.

Analytics records which screens you open and which features you use. It also records content, and you should know which: the calorie, protein, fat and carbohydrate totals of a meal you log and how many entries you have logged today; which biomarker fields you logged, by field name and not by value; your daily calorie target and how far a generated plan deviated from it; how many allergens are on your profile; which biometric chart you viewed or asked the coach about; the usable-or-not result and confidence score of a body-composition analysis; the brand of a scanned or restaurant item; and subscription and checkout events with product, price, promotion code, campaign parameters and affiliate code. Analytics also records that you declined health screening because you reported a condition that restricts coaching, and how many such conditions you reported, which identifies you to our analytics provider as a person who reported a disqualifying medical condition.

Analytics does not receive biomarker values, photographs, or AI coach conversation content. On the web we disable autocapture and session recording, instruct PostHog not to store your IP address, and mask personal data in page addresses.

1.3 Information From Third Parties

If you choose to connect third-party services (such as Apple Health, Health Connect, or social login providers), we may receive information from those services in accordance with the permissions you grant. We do not receive more than what you authorize.

What we read from Apple Health and Health Connect. Where you connect Apple Health or Health Connect and grant the corresponding permission, the measurement types KetoNoir reads are: body weight; blood glucose; blood pressure, systolic and diastolic; sleep, including asleep minutes, in-bed minutes, bedtime, wake time and the per-night breakdown into light, deep, REM and awake stages; active energy burned; basal or resting energy expenditure; step count; resting heart rate; heart rate variability; VO2 max; and workouts or exercise sessions, including the activity type, start time, duration and, on iOS, the calories recorded for the session. That list is complete. We do not read blood lipid values or blood ketones from these platforms, which do not expose those data types.

Permissions we ask for but do not use. The Apple Health permission sheet also asks for height, body fat percentage and body mass index, and the Health Connect sheet also asks for height and body fat percentage. No part of the Service reads those types. You may decline them and nothing in the app will behave differently. We are removing them from the request.

What we derive from those readings. From the readings above we calculate a sleep efficiency ratio and a sleep quality band, a workout intensity band and a coarse activity category, and 28-day median baselines for your resting heart rate, heart rate variability and sleep. We treat these derived values the same way we treat the readings they came from.

What is stored, and what is used only in flight. Weight, blood glucose and blood pressure readings are written permanently into your KetoNoir account, alongside the readings you enter by hand, because your trends and your coach are generated from your logged history and that history has to persist. Each stored reading carries the time of measurement, the value, the record identifier the health platform assigned to it, and a note naming both the platform and the specific third-party app or device that originally recorded the sample, for example the name of a continuous glucose monitor, a scale or a blood pressure cuff. That device name can itself suggest a condition, and we store it so you can tell your readings apart. Sleep, active and basal energy, steps, resting heart rate, heart rate variability and workouts are not written into your biomarker history. They are read at the moment your Metabolic Forecast is generated and sent to Anthropic for that purpose, as described in Section 3. The forecast produced from them is stored in your account, together with a rolling history of your last 30 forecasts, so the forecast text itself reflects those signals even though the underlying readings are not kept. VO2 max is read and shown to you on the Trends screen on your device only, and is not transmitted anywhere.

How far back we read. The first import, and each manual sync afterwards, covers a window you choose, which may be up to one year. The Metabolic Forecast reads a 28-day window each time it runs. The Trends screen reads up to 365 days of sleep, steps, energy, resting heart rate, heart rate variability, VO2 max and workout data from the platform each time you open it. The reach is therefore wider than the choice you make at first import.

Turning it off. KetoNoir reads from these platforms and never writes back to them, so your operating system health store is never modified. Turning the connection off inside KetoNoir stops the app from offering to sync, but it does not revoke the permission you granted at the operating system level, and on the current release it does not reliably prevent a further automatic import the next time you sign in or reopen the app. To stop all reading with certainty, revoke KetoNoir’s access in Apple Health or in Health Connect. We are correcting the in-app control; until that ships, the operating system control is the one that governs. You can delete individual readings at any time, and you can delete your account, which deletes the imported readings with it.

Per-type controls. The in-app settings offer switches for the individual signals that feed the Metabolic Forecast. On the current release, weight, blood glucose and blood pressure are imported together whenever a health platform is connected, regardless of those switches, and there is no separate switch for blood pressure. We are fixing that. If you do not want a type read at all, decline it on the operating system permission sheet, or revoke it there afterwards.

Selling, advertising, analytics and crash reporting. We do not sell health-platform data, and we do not share it with any third party for advertising or marketing. No biometric value read from a health platform is sent to our analytics provider or our crash-reporting provider. Those providers do receive operational records about syncing: whether a sync started and succeeded, how many rows were imported, the field names present in a sample, serialized error details when a sync fails, and, from analytics, which biometric chart you opened or asked the coach about, for example that you viewed the sleep chart or the glucose chart. Those records identify the metric, not the reading.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service and its features.
  • Process subscriptions, payments, and renewals.
  • Personalize your experience, including macro targets, meal tracking, and AI coaching responses.
  • Determine eligibility for AI coaching based on your health screening responses, and route you to general tracking mode if your responses indicate elevated risk for ketogenic dietary intervention.
  • Send your AI coach conversations, the photographs and documents you upload, and the health-platform signals that feed the Metabolic Forecast to our AI service provider (Anthropic) to generate the result you asked for. Section 3 sets out exactly what is sent.
  • Communicate with you about updates, features, security alerts, and customer support.
  • Send marketing and promotional materials (only with your consent, where required by law).
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our Terms of Service.
  • Conduct product analytics to improve the Service.

3. AI Processing by Anthropic

KetoNoir uses Anthropic’s Claude API. Anthropic is the largest single recipient of your health information. This section sets out everything we send there and why.

3.1 When You Use the AI Coach
  • Your messages are transmitted to Anthropic’s servers for processing, under Anthropic’s commercial terms and privacy policy. They are not used to train Anthropic’s models.
  • Every coach turn also sends context we assemble about you: the medical conditions you reported during health screening; up to 14 days of biomarker readings, meaning the time of measurement, weight, ketones, glucose, systolic and diastolic blood pressure, total cholesterol, LDL, HDL, triglycerides, and the free-text note on each reading, which for an imported reading names the app or device that recorded it; your profile, meaning height, weight, goal weight, activity level, sex at birth, birth year, goal type, diet type and any macro overrides; today’s food log; your 14-day macronutrient trends and how closely you kept to the carbohydrate cap; the durable facts the coach has remembered about you; your saved recipes and foods; and the last 20 turns of the conversation.
  • When you ask the AI coach to log a meal or a health measurement and you confirm the entry, the coach creates the corresponding record in your account (a food-log entry, or a biomarker entry such as weight, glucose, ketones, blood pressure, or a lipid value). No record is created unless you confirm it. You are responsible for the accuracy of the values you provide; the coach records the data you give it and does not independently measure, verify, or clinically interpret it.
3.2 Photographs and Documents

Every photograph and document category listed in Section 1.1 is sent to Anthropic, with two exceptions: the mobile barcode scanner, which decodes on your phone, and the mobile barcode photo upload, which is decoded on our own servers. So meal photographs, body-composition photographs, refrigerator and pantry photographs, recipe cards and cookbook pages, meal plans, workout programs, product packaging, live camera frames from the web barcode fallback on iOS Safari, and PDF documents of recipes, meal plans and workout programs are all transmitted to Anthropic. Three of the web upload paths send the original file rather than a re-encoded copy, so any location or camera metadata embedded in that file is transmitted with it.

3.3 The Metabolic Forecast

When your Metabolic Forecast is generated, we send Anthropic the health-platform signals described in Section 1.3: your sleep hours, sleep quality band, bedtime, wake time and sleep efficiency; your active and basal energy burned; your step count; your resting heart rate; your heart rate variability; each workout with its type, duration and intensity; and your 28-day median baselines for resting heart rate, heart rate variability and sleep. We send those alongside your food log, your weight log, and your ketone and glucose readings. VO2 max is read from the platform but is not sent.

3.4 Analysis by Our Staff

Anthropic also receives data for a purpose that has nothing to do with answering your question. When our staff use the AI analysis panel in the internal administrative console, the contents of that screen are transmitted to Anthropic. Depending on the screen, that includes account identifiers, verbatim excerpts of coach conversations (your message truncated to 600 characters and the coach reply to 400 characters, for the last ten turns), per-account cost and engagement records, staff-written notes about an account, and survey comments and cancellation reasons. Staff notes are free text and are not restricted in content, so they can contain a staff member’s observations about you. You may ask us for a copy of anything written about you.

3.5 What We Do Not Send, and Where We Have to Qualify That

We do not send your name, your email address, or your payment information to Anthropic, and we do not send your device location. Two qualifications, which we would rather state than let you assume away. First, the three web upload paths named in Section 1.1 transmit the original image or PDF file, so if that file carries embedded GPS coordinates they go with it, and a document you upload may itself carry your name on its face. Second, on the internal administrative screens described in Section 3.4, the raw account identifier is included in what is sent, and for mobile accounts that identifier is the primary key of your account record, which we are able to join to your email address.

For more information about how Anthropic handles data, please review Anthropic’s Privacy Policy at anthropic.com/legal/privacy.

You should not share highly sensitive information (such as Social Security numbers, financial account details, or specific medical diagnoses) with the AI coach. The coach does not diagnose conditions, prescribe medications, recommend supplement dosing, or adjust insulin doses. Per the AI Coach Disclaimer (v1.1), coach output is not reviewed by a licensed clinician on a per-message basis and you must independently verify any guidance with a qualified healthcare provider.

4. How We Share Your Information

We do NOT sell your personal information. We share information only as follows:

Service Providers. Trusted third-party service providers who help us operate the Service. These providers are contractually required to protect your information and process it only on our instructions:

  • Cloud hosting: Vercel, Inc. (application backend, API routes and server logs) and Netlify, Inc. (marketing pages, including the copy of this policy hosted there). Every request to the Service passes through Vercel, so photographs, documents, coach messages, biomarker readings and food logs all transit Vercel in the course of reaching their destination.
  • Account database and authentication: Supabase, Inc. Supabase hosts our primary database and authentication service. This is where your account, sign-in identity, profile, food log entries, biomarker readings, coach memory, saved recipes and affiliate records are stored. Your browser and your phone connect to Supabase directly, so Supabase also sees your IP address.
  • Key-value storage and rate limiting: Upstash, Inc. Upstash is not only a counter store, and describing it as one in earlier versions of this policy understated it. Upstash holds your daily food log, the full text of your AI coach conversation thread, the verbatim question-and-answer log from the web coach, the medical conditions recorded in your consent record, your Metabolic Forecast and the last 30 forecasts, your body-fat estimate history, your pantry inventory, your saved recipes, your consent records, and usage and cost counters.
  • DNS and web analytics: Cloudflare, Inc. Cloudflare provides DNS for KetoNoir domains and does not host or proxy application traffic for the tracker or the app. Cloudflare Web Analytics also runs on our public marketing pages, including the clinicians page and the copy of this policy hosted there, and receives the page address, referrer, user agent and your IP address for those page views. It is not behind the cookie consent banner.
  • Fonts: Google LLC. Every page of the web tracker, including signed-in pages, loads fonts from Google’s font servers, which discloses your IP address, browser user agent and the KetoNoir page you are viewing to Google on each page load. The mobile app bundles its fonts and does not do this. Google also appears in this list as an app store and payment processor, as the provider of Health Connect, as a sign-in provider if you use it, and as the source of the Play install referrer string.
  • Payment processing: Apple App Store, Google Play Store, and Stripe, Inc.
  • Subscription state orchestration: RevenueCat, Inc. (San Francisco, CA). RevenueCat receives subscription-state events from Apple and Google on our behalf, validates them, and forwards subscription-state metadata (tier, status, expiration, source platform, product identifier) to our backend. RevenueCat does not receive or process the underlying card, bank, or wallet credentials used to make purchases. See Section 14 (Payment Information) for the full payment flow.
  • Analytics: PostHog, Inc. PostHog holds a profile identified by your account id and carrying your email address, against which it records the events described in Section 1.2, including meal macronutrient totals, biomarker field names, daily calorie targets, the fact that you reported a condition that restricts coaching, subscription and checkout events, and which screens and charts you open. PostHog does not receive biomarker values, photographs, or coach conversation content.
  • Crash reporting and diagnostics: Sentry (Functional Software, Inc.). Sentry receives error reports, a 10 percent sample of performance traces, and browser security-policy violation reports, as described in Section 1.2. Health, food, biomarker and coach fields are removed by name, oversized values are removed by size, and your email address and IP address are removed, before a report is sent.
  • AI processing: Anthropic, PBC. Anthropic receives coach conversations and the context we assemble for them, photographs and documents, Metabolic Forecast inputs, and, on our internal administrative screens, account data and verbatim conversation excerpts. Section 3 sets out exactly what is sent and for what purpose.
  • Food, product and supplement databases: USDA FoodData Central, Open Food Facts, Open Products Facts, FatSecret, and the NIH Office of Dietary Supplements Dietary Supplement Label Database. These receive the food search terms you type and the barcodes you scan, including barcodes of dietary supplements. The requests are made by our servers, so your IP address is not passed on, but the search term or barcode is. FatSecret and USDA are queried by default on ordinary searches; Open Food Facts, Open Products Facts and the Dietary Supplement Label Database are queried as barcode fallbacks.
  • Exercise catalog: wger.de. Receives the exercise filters you choose, such as muscle group, equipment and category. No account identifier and no IP address is passed.
  • Speech synthesis: Hugging Face, Inc. and ElevenLabs. On the Coach Voice feature in non-Apple browsers, your browser downloads a speech model directly from Hugging Face’s content delivery network, which discloses your IP address, browser user agent and the referring KetoNoir page to Hugging Face. No conversation content is sent there. ElevenLabs is used only on our internal marketing dashboard, to narrate aggregated business metrics; no individual health record is sent to it.
  • Email and lifecycle messaging: MailerLite (transactional and marketing email delivery, where you have not opted out of marketing communications). MailerLite stores your email address, the time you opted in and the IP address you opted in from, and holds your list membership, which distinguishes free subscribers from premium subscribers and is updated automatically when your subscription changes. Images in our emails are served from MailerLite’s network, so MailerLite sees your IP address when your mail client loads them.
  • Email delivery: Postmark (Wildbit, LLC) for account email, progress reports, and re-engagement messages sent from the app. Every commercial message carries an unsubscribe link. Earlier versions of our policies said Postmark never receives health data. That was wrong: the weekly and monthly progress report is generated from your own data, so the message body contains your days logged, average calories, average net carbohydrates, average protein, average fat, your weight change and your average blood ketone reading, and the subject line carries your days-logged count. Postmark transmits that message. Use the unsubscribe link to stop receiving it.
  • Mobile build service: Expo, Inc. (EAS Build). Expo compiles our mobile application and our configuration keys are present on its build machines. No user data flows to Expo when you use the app.

Advertising Networks on Our Marketing Pages. Our public marketing pages at ketonoir.ai and ketonoir.com carry pixels operated by Meta Platforms, Inc. and by TikTok, which load where you allow them through the consent banner. Once loaded they disclose your IP address, browser user agent, referring page, the address of the page you are on, and their own cookies to those companies. The pages carrying them include the pricing page, the clinicians page, and the copy of this Privacy Policy hosted on the marketing site, which means the fact that you read those pages is disclosed. The iOS app declares both networks for Apple’s attribution postbacks, which permits Apple to tell them an install or conversion occurred. Neither company receives anything from inside the signed-in tracker or the mobile app, and neither receives biomarker values, food log entries, photographs or coach conversations.

Legal Requirements. When required by law, court order, subpoena, or to protect our legal rights, property, or safety, or that of our users or the public.

Business Transfers. If Ketonoir LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred. You will be notified of any change in ownership or use of your information.

With Your Consent. For any other purpose disclosed to you at the time we collect the information.

Aggregated Data. We may share aggregated or de-identified information that cannot reasonably be used to identify you.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account Data. Retained while your account is active and for up to 90 days after account deletion to handle refunds, disputes, or legal obligations.
  • Consent Logs. Retained for seven (7) years after account closure to demonstrate compliance with legal and regulatory requirements. Includes all consent versions you accepted.
  • AI Coach Conversations. Retained for up to 24 months or until you delete them from your account. The verbatim question-and-answer log kept for the web coach currently has no automatic expiry and is removed on request or when your account is deleted.
  • Photographs and Documents. The image or PDF file itself is retained only as long as necessary to complete the analysis and produce the resulting entry, then deleted. What was extracted from it is retained separately, as set out in the next entries.
  • Content Extracted From Photographs and Documents. Food-log entries and their inferred allergen lists, pantry inventories recognised from a fridge or pantry photograph, saved recipes together with a fingerprint of the source image, body-fat estimates and the last 26 of them, and up to 800 characters of model output written to the conversation log on the web import and barcode paths, are retained while your account is active and are deleted with your account. Several of these currently carry no automatic expiry.
  • Copies on Your Own Device. The mobile app writes a resized copy of a scanned photograph into its cache on your phone, and that copy remains there after the analysis finishes, until you or the operating system clears it. Deleting the app removes it.
  • Metabolic Forecasts. The forecast generated for a day, and a rolling history of your last 30 forecasts, are retained while your account is active. The health-platform signals the forecast was computed from are not stored on our servers.
  • Health-Platform Readings. Imported weight, blood glucose and blood pressure readings are retained on the same basis as readings you enter by hand, and are removed when you delete them or delete your account.
  • Subscription State Records. Retained for as long as your account is active and for up to seven (7) years after account closure as required by tax, accounting, and consumer-protection regulations.
  • Payment Records. Retained for seven (7) years as required by tax and accounting regulations.
  • Backup Data. May persist in encrypted backups for up to 30 days after primary deletion.

6. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest where supported by our service providers.
  • Secure password hashing (bcrypt or equivalent).
  • Access controls limiting employee access to personal data.
  • API key isolation: third-party API keys (Anthropic, FatSecret, USDA) are held server-side and never shipped to client devices.
  • Regular security audits and vulnerability assessments.
  • Incident response procedures for suspected breaches.

However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Your Privacy Rights

7.1 General Rights

Depending on your location, you may have the following rights:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Request that we correct inaccurate or incomplete information.
  • Deletion. Request that we delete your personal information, subject to certain exceptions (e.g., consent logs retained for legal compliance).
  • Portability. Request a copy of your data in a structured, commonly used format.
  • Objection / Restriction. Object to or request that we limit certain types of processing.
  • Withdrawal of Consent. Withdraw consent where processing is based on consent.
  • Non-Discrimination. We will not discriminate against you for exercising any of these rights.
7.2 California Residents (CCPA / CPRA)

California residents have specific rights under the California Consumer Privacy Act, including the right to know what personal information is collected, sold, or disclosed; the right to delete; the right to correct; the right to opt out of the sale or sharing of personal information; and the right to limit the use of sensitive personal information. We do not sell personal information as defined under the CCPA.

7.3 European Economic Area, United Kingdom, and Switzerland (GDPR)

If you are located in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent laws. Our lawful bases for processing include: your consent; performance of a contract (to provide the Service); compliance with legal obligations; and our legitimate interests in operating and improving the Service.

Special categories of data (Article 9). Most of what the Service handles is data concerning health, and some of it is capable of revealing other special categories. That includes your biomarker readings; your health screening answers and the restriction that follows from them; everything read from Apple Health or Health Connect, together with the name of the device or app that recorded each sample; your food log; your allergies; your body-composition photographs and the age, weight-status and eating-disorder inferences drawn from them; the allergens inferred from a meal photograph; whatever is visible in a refrigerator or pantry photograph, including medication; and your AI coach conversations. Our lawful basis for processing all of it is your explicit consent under Article 9(2)(a), given when you accept this policy and the in-app disclaimers and, for health-platform data, when you grant permission on the operating system sheet. You may withdraw that consent at any time: revoke the health platform permission at the operating system level, delete the data, delete your account, or write to us at legal@ketonoir.ai. Withdrawal does not affect processing that already took place, and where a feature depends on a category you withdraw, we will no longer be able to provide that feature.

7.4 How to Exercise Your Rights

To exercise any of these rights, contact us at legal@ketonoir.ai. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.

8. Children's Privacy

The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from individuals under 18. The Service includes an age gate requiring confirmation of age 18 or older before use. If we learn that we have collected personal information from a person under 18, we will delete that information promptly. If you believe a minor has provided us with personal information, please contact us at legal@ketonoir.ai.

9. International Data Transfers

Ketonoir LLC is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers. Where required by law, we implement appropriate safeguards (such as Standard Contractual Clauses) for international data transfers.

10. Cookies and Tracking Technologies

Our web application may use cookies and similar technologies to authenticate users, remember preferences, analyze usage, and improve the Service. You can control cookies through your browser settings.

Our public marketing pages carry additional tracking. Cloudflare Web Analytics runs on those pages without a consent gate and receives the page address, referrer, user agent and your IP address. Advertising pixels operated by Meta Platforms, Inc. and by TikTok load only where you allow them through the consent banner, and then report the page address, referrer, user agent, your IP address and their own cookies. The pages carrying these include the pricing page, the clinicians page, and the copy of this Privacy Policy hosted on the marketing site, so the fact that you read a keto health site’s clinician or privacy pages is disclosed to those companies. The signed-in tracker and the mobile app carry no advertising pixels.

Every page of the web tracker, including signed-in pages, loads fonts from Google’s servers, which discloses your IP address, browser user agent and the page address to Google. The mobile application uses device identifiers and SDKs for analytics, crash reporting and subscription management, and declares Meta and TikTok for Apple’s install and conversion attribution postbacks. You can manage tracking preferences through your device settings.

11. Third-Party Links and Services

The Service may contain links to third-party websites, affiliate partners, or services that are not operated by us. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party service you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means. Your continued use of the Service after the effective date of the updated policy constitutes acceptance of the changes. We will log your re-acceptance where required, and disclaimer version bumps will trigger a re-consent prompt for the affected disclaimer.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:

KetoNoir LLC
1145 Santa Fe Drive 1297
Weatherford, TX 76087-3846
United States
Email: legal@ketonoir.ai

14. Payment Information

When you purchase a KetoNoir Premium subscription through the mobile application, the payment transaction is handled entirely by the platform operator that hosts the application (Apple, Inc. for iOS purchases or Google LLC for Android purchases). The web tracker accepts subscription payments through Stripe, Inc. KetoNoir does not see, receive, or store the underlying payment credentials used to complete the transaction.

14.1 What the Platform Operators Collect

Apple, Google, and Stripe collect and process all data required to complete the payment, including but not limited to: the payment card number or wallet identifier, the billing name and address associated with the payment method, the country and tax jurisdiction of the purchase, the currency, the gross amount charged, any taxes or fees collected, and the transaction identifier. The handling of this data is governed by the privacy policy of the applicable platform operator and not by this Privacy Policy.

  • Apple’s privacy practices for App Store and In-App Purchase transactions are described at apple.com/legal/privacy.
  • Google’s privacy practices for Google Play and Google Play Billing transactions are described at policies.google.com/privacy.
  • Stripe’s privacy practices for web subscription transactions are described at stripe.com/privacy.
14.2 What KetoNoir Receives

KetoNoir receives only the subscription-state metadata described in Section 1.1 (“Subscription State Metadata”). This metadata is delivered to our backend through RevenueCat, Inc., which acts as our subscription-state processor and validates receipts on our behalf. The subscription-state metadata is the minimum set of fields required to determine whether your account is entitled to KetoNoir Premium features on a given day, and consists of: subscription tier, status (active, in trial, expired, in billing retry, or cancelled), source platform (Apple, Google, or Stripe), renewal or expiration timestamp, and product identifier.

14.3 What KetoNoir Does Not Receive

KetoNoir does not receive, request, or store: your full payment card number, your card expiration date, your card security code (CVV / CVC), your bank account number, your digital wallet credentials (such as Apple Pay or Google Pay device tokens), the billing address associated with your payment method, or the geographic location at which the purchase was made beyond the country and currency reported by the platform operator. If you wish to update your billing address, payment method, or other account-level payment details, you must do so through your Apple ID account settings, your Google Play account settings, or the Stripe Customer Portal, as applicable to the platform you used to subscribe.

14.4 Refunds and Disputes

Refund requests and payment disputes are handled by the platform operator that processed the original transaction, not by KetoNoir. See the Terms of Service for the specific refund procedure applicable to your purchase channel.

KetoNoir · Privacy Policy · v1.7 · Effective 2026-08-13
Terms of Service·Consumer Health Data Privacy Policy·Back to app