Ori
The idea Features How it works Plans Safety Blogs
The idea Features How it works Plans Safety Blogs Get the app

Privacy

Privacy Policy

Last updated: 7 September 2026.

1. Who we are

Double Quack LTD is the data controller for your personal data in connection with Ori. We are registered in England and Wales under company number 17262143.

Registered address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Privacy contact: hello@heyori.app
Person in charge of the protection of personal information: Privacy Lead, Double Quack LTD — hello@heyori.app
ICO registration number: ZC177587
EU representative (Article 27): Not applicable. EU/EEA distribution is not enabled.

2. What this policy covers

This policy explains how we collect, use, store, share, and protect personal data when you use Ori, including the app, website, and any related services. Because the app processes food, weight, body, and goal information, some of the data we handle is health data or special category data under UK data protection law (UK GDPR).

3. What we collect and why

Data category Examples Why we use it Lawful basis
Account data Email address, authentication ID, account ID, sign-in provider (Apple/Google/Microsoft), legal-document versions accepted, and legal-update release dismissals. Create and secure your account, sign you in, contact you about important account matters, keep evidence of required consent, and avoid repeatedly showing the same informational legal update. Contract; legitimate interests; legal obligation where applicable.
Profile and onboarding data Date of birth, height, biological sex, activity level, goal type, goal rate, unit preferences, health consent acknowledgement, and your setup answers (which listed reasons put you off tracking before and whether you prefer numbers hidden). Estimate starting calorie targets, apply age-based safety rules, personalise the app. Contract; explicit consent (Article 9(2)(a) UK GDPR) for health-related special category data.
Food and calorie data Food log entries, calorie values, saved foods, saved meals, meal edits, quick calorie logs, label scan results, food photo estimates. Power the food diary, saved foods library, AI food estimates, and weekly food-based guidance. Contract; explicit consent for health-related special category data.
Weight and goal data Manual weight logs, Look Away weight readings, trend weight, target calories, adaptive tuning state, weekly snapshots. Track progress, run adaptive calorie target updates, provide guidance in normal or Stealth Health mode. Contract; explicit consent for health-related special category data.
AI request data Prompts, recent conversation context, voice-derived text, images you submit for food/label/scale reading, AI response metadata, usage counters. Power AI chat, food estimates, voice logging, label reading, Look Away, and Weekly Tweaks. Enforce per-user usage allowances and prevent abuse. Contract; explicit consent where health data is involved; legitimate interests for usage and cost controls.
Subscription and payment metadata RevenueCat customer ID, entitlement status, subscription tier, subscription period, renewal dates, platform (App Store / Google Play), payment event metadata. Grant and manage paid access, handle subscription lifecycle events, prevent fraud, support billing queries. Contract; legitimate interests; legal obligation for accounting/tax where applicable.
Technical and security data App version, platform, region, anonymised request logs, error logs, feature usage counters, security event markers, and server-secret hashes of sign-up IP and email for free-taster controls. Keep the app working, secure the backend, enforce feature limits, prevent repeated free-taster misuse, diagnose bugs, and control AI costs. Raw IP and email are not stored in taster claim or cooldown records. Legitimate interests; legal obligation where applicable.
Optional model-improvement data Pseudonymised numerical time series derived from daily calorie totals, weight patterns, logging methods and completeness, broad body-profile ranges, goals, target changes, and adjustment outcomes. Evaluate and improve Ori's calorie-adjustment models. This is optional, off by default, and excludes food names, saved meals, conversations, notes, photos, exact dates, email addresses, and account IDs. Explicit consent.
Website contact data Email address and message content if you contact us via the website. Respond to your enquiry. Legitimate interests; contract or steps before a contract; and explicit consent for health information you choose to include.

If you do not provide this data: account, profile, and onboarding data are required to create an account and to calculate a calorie target, so we cannot provide the Service without them. Food and weight data are what the Service works from — without them the food diary, adaptive targets, and Weekly Tweaks cannot function. Optional model-improvement data is genuinely optional and declining it does not affect your normal use of the app.

Where the information comes from: most information is collected directly from you. We also receive account details from the sign-in provider you choose, and subscription and entitlement details from Apple, Google and RevenueCat. We use that information for the purposes in the table above and share it with the recipients described in section 9. Together with sections 1, 9 and 15, this also explains indirect collection to New Zealand users under Information Privacy Principle 3A.

4. Health data and explicit consent

Food intake, calories, weight, height, biological sex, and goals can reveal information about your health. Under UK GDPR, this is special category data (the highest protection tier). We process it only on the basis of your explicit consent, given at the time you create an account.

You can withdraw consent at any time by deleting your account or contacting us at hello@heyori.app. Because health-related data is central to Ori's functionality, withdrawing consent will mean we cannot continue providing the Service and your account will be closed.

We never use special category data for advertising or share it with data brokers.

Consent needed to operate Ori is separate from the optional Help improve Ori choice shown after your first target check. If you agree, eligible existing and future numerical patterns are available to our protected model-evaluation process. Turning sharing off immediately excludes your records from future training and does not affect normal use of the app. Model versions already released and anonymous overall statistics cannot be individually rolled back.

5. AI features and data processing

When you use AI features (food chat, photo logging, voice logging, Look Away, or Weekly Tweaks), your request is sent to our backend and processed by our AI provider (Google AI services). This includes any text, image, or voice-derived text you submit and relevant recent conversation context. The new Chat with Ori experience introduced in version 1.0.2 (build 24) sends at most six recent user or assistant messages from the active conversation, together with the latest suggestion records. Other AI features and earlier app versions use the context needed for their particular request.

For same-day food suggestions, we may also send calories remaining, your local hour and timezone offset, foods and practical portions logged today, a small selection of recent or regular saved foods and meals, and the latest suggestions shown in the active session. In the new chat experience, we do not automatically include your weight, target weight, goal, full diary history, or account identifiers in these suggestion requests. Information you choose to include in your message or image is still part of the request sent to the provider.

For Weekly Suggestions, we use your calculated adjustment and a limited selection of measured food and meal patterns to prepare practical options. We also use compact descriptions of food and action concepts from up to four recent completed suggestion results to reduce repetition. These describe food ideas, not your browser or device, and do not include previous suggestion prose or a chat transcript. A bounded selection of these concepts and food options is sent to Google to help word suggestions and propose a related food idea, which may include a food you have not logged. Suggestions and their associated rotation information are saved with your account until account deletion.

Google's handling of data submitted via Google AI services is governed by Google's API terms and data processing agreements. We maintain a Data Processing Agreement with Google covering AI processing on our behalf.

Please do not include faces, other people, children, addresses, prescription labels, medical records, or sensitive personal information unrelated to food logging in any image, voice note, or prompt you submit.

6. Photos, voice, and Look Away

Camera and microphone access is used only when you actively trigger a feature that requires it (photo logging, voice log, or Look Away). We do not access your camera or microphone in the background.

Voice logging: Speech-to-text transcription runs entirely on your device using your device's built-in speech recognition. Only the resulting text is sent to our backend; audio is never transmitted to our servers or any third party.

Look Away: Images submitted via Look Away are processed transiently to extract the scale reading. They are not stored in your Ori account after the reading is recorded. Temporary server-side processing artefacts and standard security logs may exist briefly as part of request handling, consistent with our retention policy.

Food photos and nutrition labels: Images are sent to our backend and AI provider for estimation. In the new chat experience, images are resized and re-encoded on your device before upload, and an estimate is added to your food diary only when you confirm it. Ori does not retain the original image in your cloud account. Temporary device copies may exist during processing; this does not delete an original photo from your gallery.

7. Apple Health and Google Health Connect

Ori does not currently read from or write to Apple Health or Google Health Connect. If we add health platform integrations in a future build, we will update this policy, explain the data involved, and ask for your explicit permission before activating any integration.

8. Local device storage

The app stores some data locally on your device: preferences, saved food and meal data, local food logs, and feature state. In the new Chat with Ori experience introduced in version 1.0.2 (build 24), the active Ori conversation is held in account-scoped memory only while the app process is running. It is cleared when you tap Start fresh, sign out, change account, delete your account, or restart the app. New chat messages and attached-photo paths are not written to the local chat history database.

Earlier app versions may store conversation history locally on your device. Updating the app does not mean all previously stored local history has been erased. Clearing the app's local data or uninstalling it removes that local history, but may also remove other local-only data.

Clearing app data or uninstalling the app may remove local-only data. It does not automatically cancel your subscription or delete your cloud account data.

9. Who we share data with

We do not sell your personal data and we do not share identifiable health data with advertisers or data brokers. We share limited data with service providers to operate Ori:

Provider Purpose Data shared
Supabase Authentication, database, Row Level Security, Edge Functions, and all backend operations. Account data, profile data, food and weight logs, AI usage counters, subscription state, security event logs.
Google (Google AI services) AI chat, food estimation, label reading, voice-log interpretation, Look Away scale reading, Weekly Tweaks. Prompts, recent conversation context, submitted images or voice-derived text, AI request metadata.
RevenueCat Subscription management, entitlement verification, webhook event handling. Platform purchase events (from Apple or Google), subscription status, entitlement tier, renewal dates. RevenueCat does not process payment card details; those are handled by Apple and Google.
Apple App Store / Google Play App distribution and in-app purchase processing. Store account, device, purchase, and distribution data handled under Apple and Google's own terms and privacy policies.
Google Workspace User support and privacy or safety enquiries, transactional emails (account, subscription), and, with your consent, marketing communications. We do not use a separate third-party marketing platform — marketing emails are sent by us directly. Email address and message content or attachments you send us, which may include health details you choose to provide after the support page asks you to include them only when needed. For marketing, this also includes your opt-in status, the date it last changed, and the copy version shown when you made that choice. No health data is included in or inferred from marketing segmentation.
Google Analytics Website traffic measurement and search-channel reporting. We use it only after you choose to allow analytics cookies, with Google Signals and advertising personalisation disabled. Online identifiers, device and browser information, pages viewed, referral information, approximate location derived from IP address, and your analytics consent choice. We do not send Ori account, food, weight, goal, or other health information to Google Analytics.

All service providers are subject to Data Processing Agreements with us and are only permitted to process your data as instructed to provide their service.

We may also disclose data where required by law, court order, or regulatory authority; to protect users or the integrity of the Service; to investigate fraud or misuse; or as part of a business transfer such as a merger or acquisition, in which case we will notify affected users.

10. International data transfers

Your account, profile, food, weight and subscription data is stored in our primary database, which is hosted by Supabase in the European Union (Stockholm, Sweden). Supabase's contracting entity is in Singapore; its agreement provides for data to be stored and primarily processed in our selected Stockholm region while permitting support and subprocessor access from other locations. Other providers listed in section 9 — including our AI, subscription-management and email providers — may process data in the United States or through their global operations. The countries in which recipients are currently likely to be located therefore include Sweden, Singapore and the United States, with other locations possible where a provider or its subprocessors operate.

Transfers to the European Economic Area. The UK Government has made adequacy regulations covering all EEA countries, including Sweden. This means personal data can be transferred from the UK to our primary database without additional safeguards being required. Our Data Processing Agreement with Supabase applies in any event.

Transfers to the United States and elsewhere. For providers that process data outside the UK and EEA, we rely on the UK Addendum to the Standard Contractual Clauses (or the Standard Contractual Clauses directly, incorporating the UK Addendum), as reflected in our Data Processing Agreements with Google and RevenueCat. Where a provider is separately self-certified under the UK Extension to the EU-US Data Privacy Framework, that may provide an additional basis for transfers to that provider, but it is not the mechanism we rely on by default.

New Zealand: where an overseas provider stores or processes personal information only on our behalf, we remain responsible for how that information is handled. Where a transfer is a disclosure governed by Information Privacy Principle 12, we will use a permitted basis under the Privacy Act 2020. This may include having reasonable grounds to believe that the recipient is subject to comparable privacy safeguards, requiring comparable safeguards by contract, or obtaining your express authorisation after telling you if comparable safeguards may not apply.

Australia: before disclosing personal information about an Australian user to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, as required by Australian Privacy Principle 8. Depending on the recipient and the information, those steps include assessing its role and processing locations, minimising the data sent, using written provider terms or Data Processing Agreements, reviewing relevant security information, and responding to material changes or incidents. Where Australian law makes us accountable for an overseas recipient's handling of the information, we remain accountable.

11. Retention

We keep personal data only for as long as needed to provide the Service, meet legal obligations, resolve disputes, prevent abuse, maintain security, and support accounting or subscription records. Specific retention periods:

  • Account and app data: retained while your account is active.
  • Subscription and payment metadata: retained as needed for billing, tax, accounting, dispute resolution, and fraud prevention (typically 7 years for tax records).
  • AI conversation content: the new chat experience keeps active conversation content in account-scoped memory for the running app session and clears it on Start fresh, logout, account change, account deletion, or process restart. Earlier versions may retain local conversation history as described in section 8. Server-side chat usage counters and request-coordination records enforce allowances and prevent abuse without storing the conversation transcript. Confirmed food logs and saved Weekly Suggestions are separate account records.
  • Look Away and photo images: processed transiently and not retained in your account after the estimate or reading is recorded.
  • Security and error logs: retained for up to 12 months unless needed for an ongoing security investigation or legal matter, in which case they may be retained for longer.
  • Support, privacy and safety correspondence: retained until the enquiry is resolved, then deleted unless it is still needed for an active security investigation, complaint, dispute or legal obligation.
  • Free-taster abuse records: a server-secret hash of the sign-up IP is retained for seven days; after account deletion, a server-secret hash of the account email is retained for 365 days so deleting and recreating an account does not reset free tasters. These records contain no food, weight, photo, or conversation data and never prevent sign-up, normal app access, or Premium.
  • Legal consent evidence: when an account is deleted, the accepted document versions and timestamps are retained in a service-only pseudonymous archive for seven years from acceptance, then automatically deleted. This is kept to meet accountability and legal-claims obligations.
  • Legal-update dismissals: if Ori shows an informational legal-update notice, we retain the account ID, release ID, and dismissal time while the account is active so the same notice is not repeatedly shown. This is separate from consent evidence, does not mean that you read or agreed to the documents, is deleted with the account, and is not copied into the seven-year consent archive.
  • Deleted accounts: login, profile, health, food, goal, settings, and model-improvement source data are deleted, subject only to the limited legal and abuse records described above and other minimum legal retention requirements.
  • Optional model-improvement data: used only while your explicit sharing choice is active. Turning sharing off immediately excludes your records from future training. Account deletion removes the consent and all contributing source rows; Ori does not keep a detached health-data time series after deletion. Previously released model versions and anonymous aggregate statistics cannot be individually reversed.

We may retain aggregated or anonymised statistics that cannot identify you. Where data can reasonably be re-linked to you, we treat it as personal data.

12. Automated processing and profiling

Ori uses automated processing to calculate personalised calorie targets, track weight trends, and generate Weekly Tweaks. This is done by applying population-level formulas to the data you enter, combined with statistical smoothing to separate meaningful trends from short-term noise such as water weight fluctuation.

These are algorithmic estimates, not individually tailored medical assessments. The outputs (target calories, trend weight, suggested adjustments) are directional guidance, not determinative decisions. You can always override, ignore, or delete them.

This processing does not constitute "solely automated decision-making with significant legal or similarly significant effects" within the meaning of Article 22 UK GDPR. However, if you have concerns about how automated processing is being applied to your data, you may contact us at hello@heyori.app and request human review of how your targets or guidance are being generated.

13. Marketing communications

We may send you transactional emails about your account, subscription, or service changes. These are not marketing communications and we do not need your consent to send them.

If we send promotional or marketing emails (such as feature announcements or offers), we will only do so if you have given your consent, as required by the Privacy and Electronic Communications Regulations (PECR). You can give or change this preference at any time in the app under Settings > Email Preferences, withdraw consent and unsubscribe using the link in any marketing email, or by contacting hello@heyori.app.

The same consent-first approach applies wherever you are. Marketing emails are sent only with your consent, always identify us as the sender, and always carry a working unsubscribe link, which we action promptly. This is intended to meet the equivalent requirements of the Australian Spam Act 2003, the New Zealand Unsolicited Electronic Messages Act 2007, and Canada's Anti-Spam Legislation (CASL), as well as PECR.

Canada (CASL): we send commercial electronic messages only where you have given express consent. We record the fact of your consent, the date it was given or last changed, and the wording you were shown at the time. Every marketing email identifies Double Quack LTD, gives our contact details, and includes an unsubscribe mechanism that stays valid for at least 60 days and is actioned within 10 business days.

14. Security

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. We review and update these measures as the Service evolves.

No system is perfectly secure. If we become aware of a personal data breach requiring notification under UK GDPR (typically within 72 hours of becoming aware), we will notify the Information Commissioner's Office (ICO) and, where the breach poses a high risk to individuals, affected users as required by applicable law.

Where a privacy breach affects users in New Zealand and it is reasonable to believe the breach has caused, or is likely to cause, serious harm, we will notify the New Zealand Office of the Privacy Commissioner as soon as practicable and notify affected users, as required by the Privacy Act 2020.

Where a data breach affects users in Australia, is likely to result in serious harm, and remedial action has not prevented that likely risk, we will notify the Office of the Australian Information Commissioner and affected users as soon as practicable under the Notifiable Data Breaches scheme in the Privacy Act 1988.

To report a potential security vulnerability, please contact us at hello@heyori.app with a description of the issue. We will acknowledge your report and work to address it promptly.

15. Your rights

Depending on your location, you may have the following rights:

  • Access: obtain a copy of your personal data.
  • Correction: ask us to correct inaccurate data.
  • Deletion: ask us to delete your data (subject to legal retention requirements). You can also delete your account directly within the app.
  • Portability: receive a copy of your data in a portable format (e.g. JSON or CSV). Contact us to request an export.
  • Restriction: ask us to restrict processing in certain circumstances.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent for special category data at any time. This will result in account closure as described in section 4.
  • Automated decision-making: rights relating to solely automated decisions that significantly affect you. See section 12 for how automated processing works in Ori.

To exercise your rights, contact hello@heyori.app. We will respond within one month. We may need to verify your identity before acting on a request.

You can also delete your account inside Ori or follow the instructions on our account-deletion page. Renewing Apple or Google subscriptions must be cancelled first because deleting an Ori account cannot stop store-controlled billing.

16. Supervisory authority complaints

To make a privacy complaint, email hello@heyori.app and describe what happened and what you would like us to do. We will acknowledge the complaint, investigate it, ask for any information reasonably needed, and explain our response and any steps we will take. We aim to respond within 30 days; if we need longer, we will tell you why and provide an updated timeframe.

If you are in the UK, you can complain to the Information Commissioner's Office at ico.org.uk. If you are in the EEA, you may complain to your local data protection supervisory authority. If you are in New Zealand, you can complain to the Office of the Privacy Commissioner at privacy.org.nz. If you are in Australia, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in Canada, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca and, if you are in Quebec, to the Commission d'accès à l'information at cai.gouv.qc.ca. We ask that you contact us first so we have the opportunity to resolve your concern.

17. US state privacy notices

We do not sell personal information and do not share personal information for cross-context behavioural advertising. We process health-related information only to provide the Service, maintain security, comply with law, and improve the product as described in this policy.

Washington State (My Health My Data Act, MHMD) and Nevada (Consumer Health Data Privacy Law): If you are a Washington or Nevada resident, you have rights relating to your consumer health data, including the right to access, delete, and withdraw consent. These rights, the categories of consumer health data we collect, and who we share it with are set out in full in our dedicated Consumer Health Data Privacy Notice. We do not sell consumer health data or share it with third parties for marketing purposes. You may also raise a complaint with the Washington State Attorney General at atg.wa.gov or the Nevada Attorney General at ag.nv.gov.

California (CCPA/CPRA), Colorado (CPA), Virginia (CDPA), Connecticut (CTDPA), Texas (TDPSA), and Oregon (OCPA): We do not sell personal information and do not share personal information for cross-context behavioural advertising. There is nothing to opt out of. Even where Ori is below the thresholds for mandatory compliance with these state laws, we aim to honour reasonable access, deletion, correction, and opt-out requests from US residents where feasible. Contact us at hello@heyori.app to exercise any applicable state privacy rights.

HIPAA notice: Ori is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). The Service is a general wellness tool, not a healthcare provider, health plan, or healthcare clearinghouse. Your data is protected under this policy and applicable US state law, but HIPAA does not apply to Ori.

If a security incident involving identifiable health information triggers US breach notification obligations, we will follow applicable notice requirements.

18. Children

Ori is not for anyone under 18. We do not knowingly collect personal data from anyone under 18. We take steps at account creation to detect underage users and will close any account we identify as belonging to someone under 18. If you believe someone under 18 has used Ori, contact us and we will take prompt action.

For users in the United States: Ori is also not directed at children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.

19. Cookies and website analytics

See our Cookie Notice for details of what cookies and similar technologies this website uses.

The Ori website uses Google Analytics only after you choose to allow analytics cookies. It helps us understand website traffic, including how visitors find pages and which pages are useful. Google Signals and advertising personalisation are disabled, and we do not send health information or Ori account data to Google Analytics. You can accept, reject, or later change your analytics choice using the Cookie settings button. See our Cookie Notice for details.

The Ori app does not use advertising cookies or tracking pixels. Locally stored preferences and session state are used only to provide app functionality and are not shared with advertisers.

20. Changes to this policy

We may update this policy. If changes are material, we will notify you via the app, by email, or on the website before or when they take effect. The date at the top of this page always shows when it was last updated.

21. Contact

Privacy contact: hello@heyori.app
Postal address: Double Quack LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

Ori

Your calm calorie companion.

Privacy Terms Health Disclaimer Support Cookies Consumer Health Data Delete account Blogs
Download on the App Store Get it on Google Play