Privacy Policy
Last updated: 14 August 2026
1. Introduction
This Privacy Policy explains how the Arori mobile application (the "App"), operated by Apeka Group Limited (registered in England and Wales, company no: 17105369), collects, uses, stores and protects your personal data.
Arori contains no advertising; your data is never used for advertising, sold to third parties, or shared with advertising networks.
By using the App you accept this policy. If you do not accept it, please do not use the App.
2. Data We Collect
2.1 Data You Provide
- Account information: Email address, password (stored only in hashed form). If you use Sign in with Apple or Sign in with Google, the name and email shared by your identity provider (with Apple you may choose to hide your email)
- Profile information: First name, last name, username, profile photo, date of birth, gender
- Health and body data (special category under GDPR Article 9): Height, weight, activity level, nutrition goals, daily calorie target, health conditions (e.g. diabetes, hypertension), food allergies, physical injuries or limitations, personal challenges (e.g. emotional eating). When a weight log feature is offered, the historical weight entries you record. When modes sensitive to medication use (e.g. appetite suppressant support) are offered, sharing that information is entirely optional and processed only with your explicit consent
- Nutrition data: Meal logs (food name, calories, protein, fat, carbohydrates, portion), water intake, barcode scan history, favourite foods
- Lifestyle data: Household size, monthly food budget and currency, eating out frequency, whether you cook for yourself or your family
- AI content: Your AI chat and nutrition coach messages, corrections you make to AI results, and the weekly nutrition and fitness plans you generate
- Community content (when community features are offered): Posts, comments, likes and foods you contribute to the community food database
- Bug reports: The report title, description and any screenshots you attach
2.2 Data Collected Automatically
- Device information: Device model, operating system, app version
- Usage data: In-app interactions, feature usage frequency, screen views, streak data
- Notification data: Push notification token, time zone, notification and reminder preferences
- Country: A country code derived from your device's language and region settings. Arori does not request location permission and does not collect GPS or location data
- Crash and error logs: Technical crash reports if the App crashes (see Section 5, Sentry)
2.3 Camera and Photos
Your camera is accessed only while you actively use a feature: food photo analysis, barcode and nutrition label scanning, recipe suggestions from ingredients, and taking a profile photo. There is no background or continuous camera access; the microphone is not used and no audio is recorded.
- Food, label and ingredient photos: Sent to our AI provider for analysis and never stored on our servers (see Section 4)
- Profile photo and bug report screenshots: Stored securely and linked to your account
- Favourite food photos: Kept only on your device, never uploaded
When a voice logging feature is offered, your voice recording will be sent to our AI provider to be converted into food entries; that feature also runs only when you actively use it.
2.4 Data That Stays on Your Device
- App Lock PIN: Stored only on your device, in hashed form, inside the operating system's secure storage. Face ID / fingerprint verification is performed by the operating system; your biometric data never reaches the App or our servers
- Session keys: Stored encrypted in the device's secure storage (iOS Keychain)
- Preferences: Language, theme and similar app preferences
2.5 Apple Health (When Offered)
When Apple Health integration is offered it will be entirely optional. If you grant permission, we may read data such as step count and active energy, and write your meal calories, water intake and weight to the Health app. Data obtained from the Health app is never used for advertising or marketing and is never shared with third parties. You can revoke this access at any time in your iOS Health settings.
2.6 Community Visibility (When Community Features Are Offered)
When community features are enabled, your username, profile photo and posts become visible to other users. Your email address, health data and private information are never shared with other users.
3. How We Use Your Data
- To create and manage your account
- To calculate your daily calorie and macro targets and provide nutrition tracking
- To run and personalise the AI-powered analysis, chat, recipe and plan features
- To send meal reminders and the notifications you choose
- To manage your subscription and verify purchases
- To respond to your support requests and bug reports
- To keep the App secure, stable and performant
- To improve the product: usage statistics and the corrections you make to AI results may be used to improve analysis accuracy
- To comply with our legal obligations
4. Artificial Intelligence and Data Processing
Arori's AI features (food analysis, label reading, recipe suggestions, chat, coach and plan generation) are powered by Google Gemini models.
- Photos: Food, label and ingredient photos are sent to the Google Gemini API for analysis and are not stored on our servers after the analysis completes. Any temporary retention on the provider's side is governed by Google's API terms
- Chat and plans: Along with your messages, profile details such as your name, weight, height, goal, activity level, calorie target and language may be included as context so responses fit you. For nutrition plan generation, your allergies and health conditions may also be included so the plan is safe and suitable
- Never sent: Your email address, date of birth and identity credentials are not sent to the AI provider
- Model training: Under Google's API terms of service, data submitted through the paid API is not used to train Google's models
- Accuracy: AI outputs are estimates; nutritional values may differ from actual values
5. Third Party Service Providers
Your data is shared with the following service providers only to the extent necessary to operate the App. None of your data is ever sold or shared with third parties for advertising or marketing.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United Kingdom (London) |
| Google Gemini | AI analysis (photos, chat, plans) | USA |
| Railway | Backend server hosting | USA/EU |
| RevenueCat | Subscription status management | USA |
| Apple App Store | Payments and subscriptions | Regional |
| Resend | Transactional email (verification codes, account notices) | USA |
| Expo / Apple Push | Push notification delivery | USA |
| PostHog | Product analytics (see Section 10) | EU (Frankfurt) |
| Sentry | Crash and error reporting | EU/USA |
| OpenFoodFacts | Barcode lookup (only the barcode number is sent) | EU (France) |
| Notion | Internal tracking of bug reports | USA |
Barcode lookups are made directly from your device to OpenFoodFacts; no personal information is included in the query, only the barcode number.
6. Data Security
- All data transmission is encrypted with TLS; the mobile app additionally uses server certificate pinning
- Passwords are stored only in hashed form
- Row level security (RLS) and authenticated API access (JWT) are enforced in the database
- Session keys are kept in the device's secure storage (iOS Keychain)
- Server side rate limiting, input validation and redaction of personal data from logs are applied
- In the event of a data breach, the relevant authorities and affected users are notified within the legally required timeframes
7. Data Retention and Account Deletion
- Your data is retained for as long as your account is active
- Photos sent for AI analysis are never stored on our servers
- Your AI chat history and plans are retained until you delete them or your account is deleted
- Account deletion: You can delete your account from the Profile screen in the App. A 30 day grace period applies after the request; logging in again during that period cancels the deletion. When the period ends, your profile, meal and water logs, plans, chats, favourites, scan history, bug reports and uploaded files are permanently deleted
- Deletion is propagated to third parties: your RevenueCat subscriber record and PostHog analytics data are deleted, and Notion bug report entries are archived
- Before deleting, you can download a copy of your data as JSON from within the App (see Section 8)
8. Your Rights
Under the UK GDPR, EU GDPR and Turkish KVKK you have the right to:
- Access: Obtain the data we hold about you
- Rectification: Have inaccurate or incomplete data corrected (you can also update your profile in the App)
- Erasure: Have your data deleted (including in-app account deletion)
- Portability: Receive your data in a structured format. The Download My Data option on the Delete Account screen exports all your data as a JSON file
- Objection and restriction: Object to certain processing activities
- Withdraw consent: Withdraw consent for consent-based processing (for analytics see Section 10)
Send requests to privacy@arori.app; they are answered free of charge within 30 days at the latest. You also have the right to complain to the ICO (Information Commissioner's Office) in the UK, or to the Personal Data Protection Authority in Turkey.
9. Turkish KVKK Notice
For users in Turkey, the data controller under Law No. 6698 on the Protection of Personal Data ("KVKK") is Apeka Group Limited, registered in England and Wales (company no: 17105369). Data categories, processing purposes and transfers are as described in this policy. Processing is based on the establishment and performance of a contract (Art. 5/2-c), legitimate interest (Art. 5/2-f) and, for special category health data, your explicit consent (Art. 6), which you may withdraw at any time by deleting your account or contacting us. Cross-border transfers to the providers listed in Section 5 are carried out with appropriate safeguards under Art. 9. You may exercise your rights under Art. 11 (access, information, rectification, erasure, notification of recipients, objection to automated analysis and compensation) by writing to privacy@arori.app.
10. Analytics and Tracking
10.1 App Analytics
We use first-party product analytics on PostHog (EU, Frankfurt) to improve the App. We collect: screen views, feature usage, device model and operating system, app version, language, country derived from device settings, session durations and subscription status. This data is associated with your account.
10.2 What We Do Not Collect
- No advertising identifier (IDFA/GAID) is used, and no "tracking" as defined by Apple's App Tracking Transparency takes place
- No in-app session recording (session replay) is used
- The content of your food photos, your health questionnaire answers and your AI chat messages are not sent to the analytics tool
- No GPS or location data is collected
10.3 Opting Out
Product analytics is on by default. You can request that collection stop and existing data be deleted at any time by writing to privacy@arori.app. When an analytics toggle is added to the in-app settings, you will also be able to manage this preference directly in the App.
10.4 Website
The arori.app website uses Google Analytics (GA4). Analytics cookies are activated only with your consent via the cookie notice; the default state is denied. No advertising cookies are used on the website.
11. Children's Privacy
Arori is not directed at children under 13. We do not knowingly collect personal data from individuals under 13. If we discover that a child under 13 has provided data, we delete it immediately.
If you believe your child has provided data to Arori, please contact privacy@arori.app.
12. International Data Transfers
Our primary database and file storage are hosted in the United Kingdom (London). Some providers listed in Section 5 (Google Gemini, RevenueCat, Expo, Resend, Notion) may process data in the USA or other regions. These transfers are made with safeguards compliant with the UK GDPR and KVKK (standard contractual clauses and equivalent mechanisms).
13. Changes to This Policy
We may update this Privacy Policy from time to time. New features (e.g. Apple Health integration, voice logging, community features) will operate under the terms of this policy when they launch; for material changes we will notify you in the App or by email. The current policy is always available on this page.
14. Contact
Data Controller: Apeka Group Limited
Country: Registered in England and Wales
Company No: 17105369
Privacy requests: privacy@arori.app
General support: support@arori.app
General enquiries: info@arori.app