Legal

EveryGram — Privacy Policy

Effective date26 August 2026
Last updated26 August 2026
Version2.0

Novaclare - FZCO ("we", "us", "our") operates the EveryGram mobile applications for iOS and Android, the EveryGram website at everygram.ai, and all related services (together, the "Service"). This Privacy Policy explains what personal data we collect, why, who we share it with, and the rights you have over it.

It should be read alongside our Terms and Conditions of Use.

We are the data controller for the personal data described here.

EntityNovaclare - FZCO
Registration number77886
Commercial licence79635, issued by the Dubai Integrated Economic Zones Authority
Registered officePremises DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates
Privacy contactprivacy@everygram.ai
General supportsupport@everygram.ai

THE SHORT VERSION

  • EveryGram is for adults only — you must be 18 or over.
  • The Service handles health data: what you eat, your weight, your activity, and — if you allow it — data from Apple Health or Health Connect. This is sensitive information and we treat it as such. We process it only with your explicit consent.
  • When you log food by voice or photo, that recording or image is sent to Google to be interpreted by an AI model. It is not used to train that model.
  • We do not keep your voice recordings — only the transcription of what you said.
  • We do not sell your personal data. We do not sell or share your health data. We do not use your health data for advertising.
  • You can delete your account and data at any time from inside the app. Deletion is immediate; backup copies are purged within 30 days.

The rest of this policy sets out the detail.


1. Age restriction

The Service is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, we do not offer a parental- or guardian-consent route, and the Service is not directed to children.

If we learn that a person under 18 has created an account, we will terminate it and delete the associated personal data. If you believe someone under 18 is using the Service, contact privacy@everygram.ai.

The reason for this restriction is set out in Section 4.6 of the Terms: the Service is built around energy targets and weight tracking, and calorie restriction carries particular risk during adolescence.

2. What we collect

2.1 Account and identity

DataWhy
Mobile telephone numberTo create your account and verify it by one-time passcode (OTP). This is how you sign in.
NameTo personalise the Service.
Email address (optional)Support, account recovery and service notices.
Date of birth or ageTo confirm you meet the 18+ requirement, and because energy requirements depend on age.

2.2 Profile and goals

Height, weight, sex, activity level, dietary preferences, cuisine preferences, food likes and dislikes, goals, target pace, and the "persona" and preference records the Service builds from your use of it.

2.3 Food and nutrition data

Everything you log: food descriptions, meal photographs, voice recordings and their transcriptions, dates and times of meals, estimated calories and macronutrients, restaurant and menu selections, and any corrections you make.

2.4 Health, fitness and body data

Body weight and weight history, workouts, detected activities, and — only where you grant permission — data read from Apple Health or Android Health Connect: steps, distance, active and total energy burned, floors climbed, exercise sessions, sleep, heart rate and body weight.

See Section 4 for how health-platform data specifically is handled.

2.5 Location

If you permit it, we read your approximate (coarse) location once to set your city and time zone, so that daily targets, insights and reminders follow your local day. We do not track your location continuously or in the background. You can decline this and set your city manually, or revoke the permission at any time in your device settings.

2.6 Device and technical data

Device identifier, device model, operating system and version, app version, language and region, push-notification registration tokens, IP address, and diagnostic and crash information.

2.7 Usage data

Which features you use, when you log, how you respond to notifications and insights, and the behavioural observations the Service derives from that in order to time and select what it shows you.

2.8 Communications

Messages you send to support, and records of service communications we send you.

3. Health data — our commitments

Information about what you eat, your body weight and measurements, your sleep, your heart rate and your physical activity is special category personal data under the EU and UK GDPR (Article 9) and sensitive personal data under UAE Federal Decree-Law No. 45 of 2021.

We process it only on the basis of your explicit consent, which you give when you create an account and enable the relevant features, and which you may withdraw at any time by disabling a permission, or by deleting your account.

We commit that:

  • we do not sell your health data, and we do not share it for anyone else's marketing;
  • we do not use it for advertising, ad targeting, or profiling for advertising purposes;
  • we do not use it to make decisions about your insurance, credit or employment, and we do not provide it to anyone who does;
  • we do not use your identifiable health data to train artificial intelligence models (see Section 6).

We are not a healthcare provider, and the Service is not a medical service. We are not a HIPAA covered entity or business associate, and the Service is not designed to hold regulated clinical records.

4. Apple Health and Android Health Connect

Where you grant permission, the Service reads health and fitness data from Apple Health (HealthKit) on iOS, or Health Connect on Android.

  • We read only. We never write, alter or delete anything in Apple Health or Health Connect.
  • We read only the categories listed in Section 2.4, and only to calculate your energy balance, targets and insights.
  • Where an insight is generated using artificial intelligence, relevant figures derived from this data may be sent to our AI provider to produce that insight (Section 6). This is solely to deliver health and wellness guidance to you. It is never used for advertising, marketing, data brokerage or use-based data mining, and it is never sold.
  • Data obtained through HealthKit or Health Connect is used solely for health, fitness and wellness management purposes. It is never used for advertising, marketing, ad targeting, data brokerage, or any use-based data mining other than improving health and wellness management — and never for your own health research without your separate express consent.
  • We do not sell, rent or disclose HealthKit or Health Connect data to any third party for their own purposes.
  • You control this permission, and can revoke it at any time in your device settings. Revoking it stops further syncing; it does not by itself delete data already synced, which you can remove by deleting your account.
  • Data held inside Apple Health or Health Connect belongs to those platforms. Deleting your EveryGram account does not delete it there — you control that in the platform's own settings.

5. Voice recordings and photographs

Voice. When you describe a meal out loud, the app records audio using your microphone, and that recording is transmitted to be transcribed and interpreted so a food log can be created.

We do not store your voice recordings on our servers. The recording is used to produce a transcription and is not retained by us; only the transcription is saved as part of your food log. The recording is held temporarily on your own device while it is processed, and is removed from our systems once transcription is complete.

Please do not record other people without their consent.

Photographs. When you photograph a meal, or select an image from your photo library, that image is transmitted to be analysed so the food can be identified. Please do not photograph other people, or anything you do not have the right to capture.

Both features are optional and permission-based. You can decline them, revoke the permission at any time in your device settings, and log food by typing instead.

6. Artificial intelligence

Food identification, nutrition estimation and the generation of insights use artificial intelligence, including large language and multimodal models operated by Google ("Gemini").

  • Your voice recordings, meal photographs and food descriptions are transmitted to Google for the sole purpose of generating that output and returning it to you.
  • When the Service generates personalised insights, relevant health and activity figures are also included — for example your step count, sleep duration, energy balance and recent food logs — so that the insight reflects your actual day. This is done only to produce guidance for you, never for advertising, marketing or data mining.
  • These are processed under our commercial agreement with Google, which restricts use of the data to providing the service to us.
  • We do not permit your identifiable data to be used to train Google's models, and we do not use it to train models of our own.
  • We may use aggregated and de-identified data — data from which you cannot be identified and which will not be re-identified — to measure and improve accuracy and to develop features.

Nutrition values produced this way are estimates and may be wrong. See Section 5 of the Terms.

7. Why we use your data, and our legal bases

PurposeData usedLegal basis (EEA/UK)
Create and operate your account, sign you inAccount, deviceContract — Art. 6(1)(b)
Log food; estimate nutrition; calculate targets and insightsFood, health, profileContract — Art. 6(1)(b), and explicit consent for health data — Art. 9(2)(a)
Read Apple Health / Health ConnectHealth platform dataExplicit consent — Art. 9(2)(a)
Voice and photo loggingAudio, imagesConsent — Art. 6(1)(a) and Art. 9(2)(a)
Send reminders, insights and notificationsUsage, device, healthContract, and consent for push notifications
Set your city and time zoneCoarse locationYour consent
Support and service communicationsAccount, communicationsContract; legitimate interests — Art. 6(1)(f)
Security, fraud prevention, abuse detection, service integrityDevice, usage, accountLegitimate interests — Art. 6(1)(f)
Improve the Service using aggregated, de-identified dataAggregated onlyLegitimate interests — Art. 6(1)(f)
Billing and subscriptionsAccount, transactionContract — Art. 6(1)(b)
Comply with law, respond to lawful requestsAs requiredLegal obligation — Art. 6(1)(c)
Marketing, where you have opted inContact detailsConsent — Art. 6(1)(a), withdrawable at any time

Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you may object at any time (Section 12).

8. Who else we share data with

We do not sell personal data. We share it only as follows.

RecipientWhat they receivePurpose
Google (Gemini AI)Voice recordings, meal photographs, food descriptions, and health/activity figures used to personalise insightsFood identification, nutrition estimation and insight generation
Google / FirebasePush tokens, device identifiersDelivering push notifications
TwilioMobile numberSending one-time passcodes by SMS
Amazon Web ServicesAll service data, at rest and in transitHosting, database and infrastructure
Public nutrition databases (e.g. USDA FoodData Central)A food search term derived from your logRetrieving reference nutrition values. No account identifier is sent.
Mapping / place lookup providersA search term you enterFinding restaurants and places
Apple / Google (app stores)Subscription and transaction dataProcessing in-app purchases
Professional advisers, auditors, insurersAs necessaryLegal and financial administration
Law enforcement, regulators, courtsAs requiredWhere we are legally obliged, or to protect rights and safety
An acquirerAs part of the businessIn a merger, acquisition or reorganisation. We will notify you and this policy will continue to apply until replaced.

Our processors act on our documented instructions under written contracts, and may not use your data for their own purposes.

9. Notifications

If you allow them, we send push notifications containing reminders, insights and prompts. To do this we store a device registration token issued by Apple or Google.

Notifications are not medical alerts. Delivery is not guaranteed. You can disable them entirely in your device settings, or adjust categories and timing inside the app. Deleting your account removes your device registrations.

We also send SMS one-time passcodes for sign-in, and essential service and security messages. You cannot opt out of these while you hold an account, because they are how the account works.

10. Cookies, analytics and tracking

The website uses cookies and local storage to operate the site, remember preferences and measure performance. You can control cookies in your browser settings; disabling them may affect some functionality.

The mobile apps do not contain any third-party analytics or advertising SDK. We do not track you across other companies' apps or websites, we do not use advertising identifiers, and the Android app explicitly removes the advertising-ID permissions. Apple App Tracking Transparency does not apply because we do not track.

What we do collect about app usage — which features are used, and diagnostic and crash data — is processed on our own infrastructure to keep the Service working and to improve it, as described in Section 7.

11. International transfers, security and retention

11.1 Transfers. We are established in the United Arab Emirates and use infrastructure and processors located in other countries, including the United States and the European Union. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards — normally the European Commission's Standard Contractual Clauses, together with the UK Addendum where relevant, and supplementary measures where required. Transfers outside the UAE are made in accordance with Federal Decree-Law No. 45 of 2021. You can request details of these safeguards at privacy@everygram.ai.

11.2 Security. We use technical and organisational measures designed to protect your data, including encryption in transit, encryption at rest, access controls, authentication and rate limiting. No system is completely secure and no transmission over the internet can be guaranteed, so we cannot promise absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.

11.3 Retention. We keep personal data only as long as we need it:

DataRetained
Voice recordingsNot stored on our servers. Used for transcription, then discarded; only the transcription is kept
Account, food, health and profile dataWhile your account is open
After you delete your accountRemoved from active systems immediately; encrypted backup copies purged within 30 days
Support correspondenceUp to 24 months after the matter closes
Billing and tax recordsAs required by applicable law, typically 5 years
Aggregated, de-identified dataIndefinitely — it no longer identifies you
Records we must keep by lawFor the required period

12. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data (see Section 13);
  • restrict or object to processing, including profiling and processing based on legitimate interests;
  • portability — receive your data in a structured, machine-readable format, or have it transmitted to another controller;
  • withdraw consent at any time, without affecting processing already carried out; and
  • complain to your data protection authority.

To exercise any of these, email privacy@everygram.ai. We will respond within 30 days (or one month in the EEA/UK, extendable by two months for complex requests, in which case we will tell you). We may need to verify your identity first — normally by confirming control of the mobile number on the account. Exercising your rights is free, unless a request is manifestly unfounded or excessive.

13. Deleting your account and data

You can delete your account at any time:

  • In the app — open the More tab, go to Privacy & Data, and select Delete account. Deletion takes effect immediately and you are signed out.
  • By email — if you no longer have the app, email support@everygram.ai with the subject "Account deletion request", including the mobile number (with country code) used to register so we can locate your account. We verify the request and complete deletion within 30 days, then confirm.

What is deleted: your profile and account details, all food logs, meal photographs and voice-log transcriptions, weight, workout, activity and sleep records including data synced from Apple Health or Health Connect, goals, personas, preferences, notification settings, and device push registrations.

Deletion is permanent and cannot be undone. Data stored on your own device by Apple Health or Health Connect belongs to those platforms and is not affected — you control it in their settings. Deleting your account does not cancel a subscription purchased through an app store; cancel that separately in your Apple or Google account settings.

14. Region-specific information

The Service is available internationally. The following applies to residents of the regions named.

14.1 European Economic Area and United Kingdom

We process your data under the EU GDPR and, for UK residents, the UK GDPR and the Data Protection Act 2018. Health data is special category data processed under Article 9(2)(a) — explicit consent. Legal bases are in Section 7 and transfer safeguards in Section 11.1.

The Service generates insights and notifications automatically. These do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22, and you can disable notification categories at any time.

You may lodge a complaint with your national supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk, 0303 123 1113). A list of EEA authorities is at edpb.europa.eu.

14.2 California

Under the CCPA as amended by the CPRA you may request to know, delete, and correct your personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding 12 months.

Health and dietary information is sensitive personal information. We use it only to provide the Service you requested — a purpose for which the right to limit use does not restrict us — and never to infer characteristics about you for advertising.

We do not discriminate against you for exercising your rights. To make a request, email privacy@everygram.ai. You may use an authorised agent, with proof of authorisation.

California residents may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, (800) 952-5210.

14.3 United Arab Emirates

We process personal data under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations. Health-related data is processed on the basis of your explicit consent, which you may withdraw at any time. Where applicable we observe Federal Law No. 2 of 2019 concerning the use of information and communication technology in health fields, including in relation to the storage and transfer of health data, and retain health data within the UAE where required by the competent authority.

14.4 Elsewhere

Where the law of your country of residence gives you rights that go beyond this policy, those rights apply.

15. Changes to this policy

We may update this policy. If a change is material, we will give you reasonable notice — normally at least 30 days — by in-app notice, push notification or email, and update the date at the top. Where a change requires your consent, we will ask for it before it takes effect. Continuing to use the Service after the effective date means you accept the updated policy.

16. Contact us

Privacy and data protectionprivacy@everygram.ai
General supportsupport@everygram.ai
Legal noticeslegal@everygram.ai
PostalNovaclare - FZCO, Premises DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates

If you are not satisfied with our response, you may complain to your data protection authority (Section 14.1).


© 2026 Novaclare - FZCO. All rights reserved.