Legal
Privacy Policy
Last updated: August 12, 2026
This Privacy Policy explains what data Ansyrs collects for the features described below, how that data is used and stored, and the choices you have.
What we collect
Account identifiers. If you use Sign in with Apple, we receive a stable, app-specific Apple user identifier and the email address in Apple's identity token. The email may be an Apple private-relay address. The current app requests email access only; it does not ask Apple for your name or send a profile name to Ansyrs.
Legacy Lifetime Premium records. The current app does not accept new Lifetime Premium reservations or claim links. If you participated in the former reservation program, Ansyrs may retain the limited records described below to preserve an already-granted entitlement, resolve a still-pending record, prevent duplicates or abuse, and honor deletion requests. We do not use a retained address for advertising, marketing, tracking, resale, profiling, or unrelated communication.
Sign in with Apple authorization. The app sends Apple's short-lived, one-use authorization code and a nonce with sign-in. The backend verifies the identity, exchanges the code directly with Apple, discards the returned access token, and stores the Apple refresh credentials in encrypted form. Repeated authorizations can produce more than one distinct credential; Ansyrs keeps them solely to revoke every outstanding grant if you delete your account.
Account-linked settings and saved data. Depending on the features and sync controls you enable, this can include dietary or allergy settings and severity, followed brands, logged meals and journal entries, and recent meal builds. Dietary and meal information may reveal health or other sensitive information.
Product interactions used for personalization. The app records identifiers for products, brands, suggestions, or restaurants you open. These events are used on your device to provide recents and rank suggestions. If you enable Search Activity sync, the app reduces those events to affinity scores and count/recency buckets, encrypts that derived snapshot, and writes it to your iCloud account with your Ansyrs profile identifier. Raw search text is not included in that personalization snapshot.
Anonymous catalog reports and requests. An item-information report includes the brand and item, the fields you select, current and suggested values, the app version, and an optional note. The report record does not contain an Ansyrs account identifier, name, email, or device identifier. A note can still contain personal information if you choose to type it, so please do not include personal information in the note. A missing-brand request stores the brand name you submit.
Empty-brand update requests. If you ask Ansyrs to prioritize a visible brand that has no items, the current app sends the brand and a random identifier created for this installation. The identifier is not derived from your hardware, Apple ID, advertising identifier, or Ansyrs account. The backend replaces it with a keyed hash before storage and uses it only to de-duplicate anonymous demand for that brand. It is not used for tracking or advertising.
Security and request metadata. When you sign in, the service stores a hash of the refresh token, a keyed hash derived from the request IP address, and the request user agent with the session. Submission and other abuse-sensitive routes use short-lived, keyed-hash rate-limit records derived from request IP addresses. Hosting providers also process normal network request metadata to deliver and secure the service.
Deletion continuity records. To make an interrupted deletion safe to resume, the service can retain a pending deletion proof and, after completion, limited receipt metadata. These records use keyed hashes and a random receipt identifier; they do not store your Apple user identifier, email, or raw authentication tokens.
What we do not collect
- We do not request your name through Sign in with Apple.
- Your precise location is not sent to the Ansyrs backend. If you choose Nearby, the app passes a location and search request to Apple through MapKit so Apple can return nearby places. A coarsely rounded location may be cached in the app's sandbox on your device. See Apple's privacy information for how Apple processes MapKit requests.
- We do not access motion or fitness sensors. Visual parallax is driven by scroll position; the app does not read Core Motion or request motion permission.
- We do not embed third-party advertising or analytics SDKs. The app does not contain Google Analytics, Meta/Facebook SDK, Amplitude, AppsFlyer, or similar SDKs, and it does not upload app-performance telemetry to Ansyrs.
- We do not retain raw search text for analytics or suggestion personalization. Search text is sent to the Ansyrs backend as needed to return the result you requested, but the normal search flow does not store it. The separate missing-brand request described above does store the brand name you explicitly submit.
How we use data
We use account and saved data to authenticate you, sync the categories you enable, show your journal and followed brands, and tailor results to your dietary settings. We use product interactions and derived affinity signals for app functionality and product personalization. We use anonymous catalog submissions to review possible errors and prioritize catalog coverage. We use request metadata and keyed hashes to secure accounts, enforce rate limits, and investigate abuse.
We do not sell personal information, use it for cross-app tracking, or serve targeted advertising. We do not use an address retained from the former Lifetime Premium reservation program for advertising or marketing.
How your data is stored
- On your device. Local app data is stored inside the app sandbox in databases, files, and preferences protected by iOS data protection. Authentication tokens and the personalization encryption key are stored in Keychain.
- In iCloud Key-Value Storage. When the corresponding sync controls are enabled, followed and pinned brands, recent meal builds, logged journal entries, and an optional app-encrypted derived personalization snapshot can sync through your iCloud account. The payload is keyed to your Ansyrs profile. Raw search text, exact locations, MapKit results, model weights, prompts, AI responses, and authentication tokens are not included.
- On the Ansyrs service. Account profiles, dietary settings, followed brands, synced journal entries, anonymous catalog submissions, and operational security records are processed by Ansyrs services hosted on Vercel and stored in Supabase/Postgres where applicable. The Apple refresh token used only for deletion-time revocation is encrypted at rest in a service-role-only store.
- Legacy Lifetime Premium records. For an unresolved record from the former reservation program, the service may retain one AES-256-GCM encrypted address, a keyed HMAC used to prevent duplicates, a masked display form, and a short-lived claim proof. The current app does not create new reservation records or accept claim links.
How long we keep it
- Account-linked data is kept while your account exists, unless you remove a record earlier. A journal entry you remove is eligible for permanent cleanup after 30 days.
- Sessions expire after 30 days. Expired or revoked session rows are removed by the service's retention cleanup after 45 additional days. Deleting the account removes its session rows with the account.
- Encrypted Apple refresh credentials are kept while the account exists so Ansyrs can revoke every outstanding app authorization. They are deleted after confirmed revocation as part of account deletion. An unresolved pseudonymous deletion record is kept until the deletion can be safely completed. After completion, a pseudonymous deletion-control record—request and receipt IDs, keyed hashes of the request proof and Apple subject, revocation state, and lifecycle timestamps—is scheduled for cleanup after 30 days (or after related Apple-revocation cleanup finishes, if later). It has no raw Apple identifier, email, authentication token, IP address, or user agent. The app may retain a local, non-secret support summary containing only the receipt ID, request ID, and completion time until app data is cleared.
- Anonymous catalog reports and requests may be retained as catalog quality and demand records until they are resolved or no longer needed. They are not automatically matched to or removed with an Ansyrs account because the records contain no account identifier.
- Legacy Lifetime Premium records are retained only while needed to resolve the former program's outstanding record or preserve an already-granted entitlement. Cancellation deletes any pending encrypted address and claim proof. A successful recoverable grant deletes them in the same database transaction and records the deletion time. Ansyrs may retain the masked form, a keyed HMAC for duplicate prevention, entitlement/reservation status, and safe audit timestamps needed to preserve access and prevent abuse.
- Rate-limit records use keyed hashes; scheduled cleanup deletes rows older than five minutes. Some security and administrative logs have separate operational schedules; for example, content-security-policy reports are cleaned after 14 days and administrative audit records after 180 days.
Account deletion and your rights
You can delete your account in Settings → Delete Account. A successful response means the backend has confirmed revocation of the app's Sign in with Apple authorization and completed one database transaction that removes the profile, encrypted Apple refresh credentials, identities, sessions, followed brands, dietary and user settings, product corrections, journal entries, any historical account-linked scan rows, and supported legacy or archived saved-meal/build data. For shared catalog notes, change-log records, legacy catalog submissions, or product-snapshot attribution, the transaction removes the account link while retaining the non-account catalog/audit content. For an older account without a stored Apple token, Ansyrs may ask you to confirm with Sign in with Apple first. Ansyrs records the pending deletion and revokes its app sessions before that confirmation; if you cancel or the confirmation fails, account content has not been deleted yet and the request remains pending. After backend success, the app removes the profile's iCloud payload and clears local personal-data stores on that device. Account deletion also removes an account-linked legacy Lifetime Premium record, any still-pending encrypted address and claim proof, and the account-bound entitlement.
Anonymous item reports, missing-brand requests, and empty-brand demand records are not account-linked and therefore cannot be found through account deletion. To request removal of an anonymous submission, contact support with enough information to locate it, such as the report ID, brand, item, approximate submission time, or submitted text.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal data, and to appeal or complain to a regulator. To exercise a right, visit Ansyrs Support. We honor applicable rights under laws such as the GDPR, UK GDPR, and CCPA/CPRA.
Children
Ansyrs is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.
Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will update the bundled copy in a subsequent App Store release and update this canonical version. Material changes will be surfaced in the app when you next open it.
Contact
Privacy questions can be sent through Ansyrs Support.