Legal
EveryGram — Privacy Policy
| Effective date | 26 August 2026 |
| Last updated | 26 August 2026 |
| Version | 2.0 |
Novaclare - FZCO ("we", "us", "our") operates the EveryGram mobile applications for iOS and Android, the EveryGram website at everygram.ai, and all related services (together, the "Service"). This Privacy Policy explains what personal data we collect, why, who we share it with, and the rights you have over it.
It should be read alongside our Terms and Conditions of Use.
We are the data controller for the personal data described here.
| Entity | Novaclare - FZCO |
| Registration number | 77886 |
| Commercial licence | 79635, issued by the Dubai Integrated Economic Zones Authority |
| Registered office | Premises DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates |
| Privacy contact | privacy@everygram.ai |
| General support | support@everygram.ai |
THE SHORT VERSION
- EveryGram is for adults only — you must be 18 or over.
- The Service handles health data: what you eat, your weight, your activity, and — if you allow it — data from Apple Health or Health Connect. This is sensitive information and we treat it as such. We process it only with your explicit consent.
- When you log food by voice or photo, that recording or image is sent to Google to be interpreted by an AI model. It is not used to train that model.
- We do not keep your voice recordings — only the transcription of what you said.
- We do not sell your personal data. We do not sell or share your health data. We do not use your health data for advertising.
- You can delete your account and data at any time from inside the app. Deletion is immediate; backup copies are purged within 30 days.
The rest of this policy sets out the detail.
1. Age restriction
The Service is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, we do not offer a parental- or guardian-consent route, and the Service is not directed to children.
If we learn that a person under 18 has created an account, we will terminate it and delete the associated personal data. If you believe someone under 18 is using the Service, contact privacy@everygram.ai.
The reason for this restriction is set out in Section 4.6 of the Terms: the Service is built around energy targets and weight tracking, and calorie restriction carries particular risk during adolescence.
2. What we collect
2.1 Account and identity
| Data | Why |
|---|---|
| Mobile telephone number | To create your account and verify it by one-time passcode (OTP). This is how you sign in. |
| Name | To personalise the Service. |
| Email address (optional) | Support, account recovery and service notices. |
| Date of birth or age | To confirm you meet the 18+ requirement, and because energy requirements depend on age. |
2.2 Profile and goals
Height, weight, sex, activity level, dietary preferences, cuisine preferences, food likes and dislikes, goals, target pace, and the "persona" and preference records the Service builds from your use of it.
2.3 Food and nutrition data
Everything you log: food descriptions, meal photographs, voice recordings and their transcriptions, dates and times of meals, estimated calories and macronutrients, restaurant and menu selections, and any corrections you make.
2.4 Health, fitness and body data
Body weight and weight history, workouts, detected activities, and — only where you grant permission — data read from Apple Health or Android Health Connect: steps, distance, active and total energy burned, floors climbed, exercise sessions, sleep, heart rate and body weight.
See Section 4 for how health-platform data specifically is handled.
2.5 Location
If you permit it, we read your approximate (coarse) location once to set your city and time zone, so that daily targets, insights and reminders follow your local day. We do not track your location continuously or in the background. You can decline this and set your city manually, or revoke the permission at any time in your device settings.
2.6 Device and technical data
Device identifier, device model, operating system and version, app version, language and region, push-notification registration tokens, IP address, and diagnostic and crash information.
2.7 Usage data
Which features you use, when you log, how you respond to notifications and insights, and the behavioural observations the Service derives from that in order to time and select what it shows you.
2.8 Communications
Messages you send to support, and records of service communications we send you.
3. Health data — our commitments
Information about what you eat, your body weight and measurements, your sleep, your heart rate and your physical activity is special category personal data under the EU and UK GDPR (Article 9) and sensitive personal data under UAE Federal Decree-Law No. 45 of 2021.
We process it only on the basis of your explicit consent, which you give when you create an account and enable the relevant features, and which you may withdraw at any time by disabling a permission, or by deleting your account.
We commit that:
- we do not sell your health data, and we do not share it for anyone else's marketing;
- we do not use it for advertising, ad targeting, or profiling for advertising purposes;
- we do not use it to make decisions about your insurance, credit or employment, and we do not provide it to anyone who does;
- we do not use your identifiable health data to train artificial intelligence models (see Section 6).
We are not a healthcare provider, and the Service is not a medical service. We are not a HIPAA covered entity or business associate, and the Service is not designed to hold regulated clinical records.
4. Apple Health and Android Health Connect
Where you grant permission, the Service reads health and fitness data from Apple Health (HealthKit) on iOS, or Health Connect on Android.
- We read only. We never write, alter or delete anything in Apple Health or Health Connect.
- We read only the categories listed in Section 2.4, and only to calculate your energy balance, targets and insights.
- Where an insight is generated using artificial intelligence, relevant figures derived from this data may be sent to our AI provider to produce that insight (Section 6). This is solely to deliver health and wellness guidance to you. It is never used for advertising, marketing, data brokerage or use-based data mining, and it is never sold.
- Data obtained through HealthKit or Health Connect is used solely for health, fitness and wellness management purposes. It is never used for advertising, marketing, ad targeting, data brokerage, or any use-based data mining other than improving health and wellness management — and never for your own health research without your separate express consent.
- We do not sell, rent or disclose HealthKit or Health Connect data to any third party for their own purposes.
- You control this permission, and can revoke it at any time in your device settings. Revoking it stops further syncing; it does not by itself delete data already synced, which you can remove by deleting your account.
- Data held inside Apple Health or Health Connect belongs to those platforms. Deleting your EveryGram account does not delete it there — you control that in the platform's own settings.
5. Voice recordings and photographs
Voice. When you describe a meal out loud, the app records audio using your microphone, and that recording is transmitted to be transcribed and interpreted so a food log can be created.
We do not store your voice recordings on our servers. The recording is used to produce a transcription and is not retained by us; only the transcription is saved as part of your food log. The recording is held temporarily on your own device while it is processed, and is removed from our systems once transcription is complete.
Please do not record other people without their consent.
Photographs. When you photograph a meal, or select an image from your photo library, that image is transmitted to be analysed so the food can be identified. Please do not photograph other people, or anything you do not have the right to capture.
Both features are optional and permission-based. You can decline them, revoke the permission at any time in your device settings, and log food by typing instead.
6. Artificial intelligence
Food identification, nutrition estimation and the generation of insights use artificial intelligence, including large language and multimodal models operated by Google ("Gemini").
- Your voice recordings, meal photographs and food descriptions are transmitted to Google for the sole purpose of generating that output and returning it to you.
- When the Service generates personalised insights, relevant health and activity figures are also included — for example your step count, sleep duration, energy balance and recent food logs — so that the insight reflects your actual day. This is done only to produce guidance for you, never for advertising, marketing or data mining.
- These are processed under our commercial agreement with Google, which restricts use of the data to providing the service to us.
- We do not permit your identifiable data to be used to train Google's models, and we do not use it to train models of our own.
- We may use aggregated and de-identified data — data from which you cannot be identified and which will not be re-identified — to measure and improve accuracy and to develop features.
Nutrition values produced this way are estimates and may be wrong. See Section 5 of the Terms.
7. Why we use your data, and our legal bases
| Purpose | Data used | Legal basis (EEA/UK) |
|---|---|---|
| Create and operate your account, sign you in | Account, device | Contract — Art. 6(1)(b) |
| Log food; estimate nutrition; calculate targets and insights | Food, health, profile | Contract — Art. 6(1)(b), and explicit consent for health data — Art. 9(2)(a) |
| Read Apple Health / Health Connect | Health platform data | Explicit consent — Art. 9(2)(a) |
| Voice and photo logging | Audio, images | Consent — Art. 6(1)(a) and Art. 9(2)(a) |
| Send reminders, insights and notifications | Usage, device, health | Contract, and consent for push notifications |
| Set your city and time zone | Coarse location | Your consent |
| Support and service communications | Account, communications | Contract; legitimate interests — Art. 6(1)(f) |
| Security, fraud prevention, abuse detection, service integrity | Device, usage, account | Legitimate interests — Art. 6(1)(f) |
| Improve the Service using aggregated, de-identified data | Aggregated only | Legitimate interests — Art. 6(1)(f) |
| Billing and subscriptions | Account, transaction | Contract — Art. 6(1)(b) |
| Comply with law, respond to lawful requests | As required | Legal obligation — Art. 6(1)(c) |
| Marketing, where you have opted in | Contact details | Consent — Art. 6(1)(a), withdrawable at any time |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you may object at any time (Section 12).
8. Who else we share data with
We do not sell personal data. We share it only as follows.
| Recipient | What they receive | Purpose |
|---|---|---|
| Google (Gemini AI) | Voice recordings, meal photographs, food descriptions, and health/activity figures used to personalise insights | Food identification, nutrition estimation and insight generation |
| Google / Firebase | Push tokens, device identifiers | Delivering push notifications |
| Twilio | Mobile number | Sending one-time passcodes by SMS |
| Amazon Web Services | All service data, at rest and in transit | Hosting, database and infrastructure |
| Public nutrition databases (e.g. USDA FoodData Central) | A food search term derived from your log | Retrieving reference nutrition values. No account identifier is sent. |
| Mapping / place lookup providers | A search term you enter | Finding restaurants and places |
| Apple / Google (app stores) | Subscription and transaction data | Processing in-app purchases |
| Professional advisers, auditors, insurers | As necessary | Legal and financial administration |
| Law enforcement, regulators, courts | As required | Where we are legally obliged, or to protect rights and safety |
| An acquirer | As part of the business | In a merger, acquisition or reorganisation. We will notify you and this policy will continue to apply until replaced. |
Our processors act on our documented instructions under written contracts, and may not use your data for their own purposes.
9. Notifications
If you allow them, we send push notifications containing reminders, insights and prompts. To do this we store a device registration token issued by Apple or Google.
Notifications are not medical alerts. Delivery is not guaranteed. You can disable them entirely in your device settings, or adjust categories and timing inside the app. Deleting your account removes your device registrations.
We also send SMS one-time passcodes for sign-in, and essential service and security messages. You cannot opt out of these while you hold an account, because they are how the account works.
10. Cookies, analytics and tracking
The website uses cookies and local storage to operate the site, remember preferences and measure performance. You can control cookies in your browser settings; disabling them may affect some functionality.
The mobile apps do not contain any third-party analytics or advertising SDK. We do not track you across other companies' apps or websites, we do not use advertising identifiers, and the Android app explicitly removes the advertising-ID permissions. Apple App Tracking Transparency does not apply because we do not track.
What we do collect about app usage — which features are used, and diagnostic and crash data — is processed on our own infrastructure to keep the Service working and to improve it, as described in Section 7.
11. International transfers, security and retention
11.1 Transfers. We are established in the United Arab Emirates and use infrastructure and processors located in other countries, including the United States and the European Union. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards — normally the European Commission's Standard Contractual Clauses, together with the UK Addendum where relevant, and supplementary measures where required. Transfers outside the UAE are made in accordance with Federal Decree-Law No. 45 of 2021. You can request details of these safeguards at privacy@everygram.ai.
11.2 Security. We use technical and organisational measures designed to protect your data, including encryption in transit, encryption at rest, access controls, authentication and rate limiting. No system is completely secure and no transmission over the internet can be guaranteed, so we cannot promise absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
11.3 Retention. We keep personal data only as long as we need it:
| Data | Retained |
|---|---|
| Voice recordings | Not stored on our servers. Used for transcription, then discarded; only the transcription is kept |
| Account, food, health and profile data | While your account is open |
| After you delete your account | Removed from active systems immediately; encrypted backup copies purged within 30 days |
| Support correspondence | Up to 24 months after the matter closes |
| Billing and tax records | As required by applicable law, typically 5 years |
| Aggregated, de-identified data | Indefinitely — it no longer identifies you |
| Records we must keep by law | For the required period |
12. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data (see Section 13);
- restrict or object to processing, including profiling and processing based on legitimate interests;
- portability — receive your data in a structured, machine-readable format, or have it transmitted to another controller;
- withdraw consent at any time, without affecting processing already carried out; and
- complain to your data protection authority.
To exercise any of these, email privacy@everygram.ai. We will respond within 30 days (or one month in the EEA/UK, extendable by two months for complex requests, in which case we will tell you). We may need to verify your identity first — normally by confirming control of the mobile number on the account. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
13. Deleting your account and data
You can delete your account at any time:
- In the app — open the More tab, go to Privacy & Data, and select Delete account. Deletion takes effect immediately and you are signed out.
- By email — if you no longer have the app, email support@everygram.ai with the subject "Account deletion request", including the mobile number (with country code) used to register so we can locate your account. We verify the request and complete deletion within 30 days, then confirm.
What is deleted: your profile and account details, all food logs, meal photographs and voice-log transcriptions, weight, workout, activity and sleep records including data synced from Apple Health or Health Connect, goals, personas, preferences, notification settings, and device push registrations.
Deletion is permanent and cannot be undone. Data stored on your own device by Apple Health or Health Connect belongs to those platforms and is not affected — you control it in their settings. Deleting your account does not cancel a subscription purchased through an app store; cancel that separately in your Apple or Google account settings.
14. Region-specific information
The Service is available internationally. The following applies to residents of the regions named.
14.1 European Economic Area and United Kingdom
We process your data under the EU GDPR and, for UK residents, the UK GDPR and the Data Protection Act 2018. Health data is special category data processed under Article 9(2)(a) — explicit consent. Legal bases are in Section 7 and transfer safeguards in Section 11.1.
The Service generates insights and notifications automatically. These do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22, and you can disable notification categories at any time.
You may lodge a complaint with your national supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk, 0303 123 1113). A list of EEA authorities is at edpb.europa.eu.
14.2 California
Under the CCPA as amended by the CPRA you may request to know, delete, and correct your personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months.
Health and dietary information is sensitive personal information. We use it only to provide the Service you requested — a purpose for which the right to limit use does not restrict us — and never to infer characteristics about you for advertising.
We do not discriminate against you for exercising your rights. To make a request, email privacy@everygram.ai. You may use an authorised agent, with proof of authorisation.
California residents may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, (800) 952-5210.
14.3 United Arab Emirates
We process personal data under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations. Health-related data is processed on the basis of your explicit consent, which you may withdraw at any time. Where applicable we observe Federal Law No. 2 of 2019 concerning the use of information and communication technology in health fields, including in relation to the storage and transfer of health data, and retain health data within the UAE where required by the competent authority.
14.4 Elsewhere
Where the law of your country of residence gives you rights that go beyond this policy, those rights apply.
15. Changes to this policy
We may update this policy. If a change is material, we will give you reasonable notice — normally at least 30 days — by in-app notice, push notification or email, and update the date at the top. Where a change requires your consent, we will ask for it before it takes effect. Continuing to use the Service after the effective date means you accept the updated policy.
16. Contact us
| Privacy and data protection | privacy@everygram.ai |
| General support | support@everygram.ai |
| Legal notices | legal@everygram.ai |
| Postal | Novaclare - FZCO, Premises DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates |
If you are not satisfied with our response, you may complain to your data protection authority (Section 14.1).
© 2026 Novaclare - FZCO. All rights reserved.