Information We Collect
2.1 Account Data (Stored Securely in the Cloud)
When you create an account, we collect:
• Email address (for authentication and account communications)
• Password (encrypted - we cannot see it)
This data is stored securely using Supabase, our authentication provider, with encryption at rest and in transit.
2.2 Health Profile (Stored in Your Account, in the Cloud)
When you complete your health profile, we collect information you voluntarily provide:
• Basic profile: name, age, gender, region
• Body metrics: height, weight
• Health context: dietary preferences, allergies, food sensitivities, health conditions (e.g. PCOS, diabetes, anxiety)
• Wellness goals: weight loss, better sleep, improved mood, gut health, etc.
• Activity level and kitchen access
Your health profile is stored in your account in our secure cloud database (Supabase), linked to your account ID, and is also cached on your device so the App works offline. It is used to personalise your nutrition and mood recommendations. It is protected by row-level security and is not accessible to any advertiser or third party other than the processors listed in Section 7.
2.3 App Activity Data (Stored in Your Account, in the Cloud)
To sync your experience across sessions and devices, and to power your recommendations, the following data is stored in our secure cloud database (Supabase), linked to your account ID, and cached on your device:
• Mood check-in entries (mood, emotions, energy level, activities, body sensations, journal notes)
• Food consumption logs (foods you logged or that were identified by the AI food scanner)
• Food–mood outcomes (which recommended foods you marked as eaten, the mood recorded just before eating, and your self-reported response afterwards) - these power your Mood Story and the optional "Share with your nutritionist" summary
This data is retained until you delete it or delete your account. When you delete your account, it is permanently removed from our servers immediately (see Sections 5 and 12).
When you choose to create a "Share with your nutritionist" summary, the entries for the period you select are processed by our secure backend (Supabase Edge Functions) to build the PDF or CSV file. The generated summary is not stored on our servers - the file is created on your device for you to share, and we do not retain a copy.
Your AI chat conversations with Mo are not stored - see Section 2.4.
2.4 AI Chat & Search Data
When you use Mo Chat (our AI nutrition advisor) or the AI-powered search and food scanner features:
• Your message, query, or food photo is sent to our AI provider (Anthropic Claude) in real time to generate a response. Requests are routed through our secure backend (Supabase Edge Functions), except the AI food scanner, which sends your photo directly to Anthropic from the App.
• Anthropic operates under a Zero Data Retention policy for our API usage - they do not store your inputs or outputs and do not use them to train AI models.
• We do not store your Mo Chat conversations. Messages exist only during the active session, in the App's memory, and are not written to our servers or saved on your device. Each conversation starts fresh with no memory of previous sessions.
• AI-powered search queries are processed in real time and are not stored on our servers after the response is generated.
2.5 Device-Stored Data (On Your Device Only)
The following data is stored locally on your device only and is never synced to our servers:
• Mood/wellness activity sessions (e.g. breathing, gratitude, and MoCare session history)
• App preferences and settings (accessibility, language, notification, and AI voice settings)
• Cached copies of your profile and activity data for offline use
• Skipped-ingredient and other on-device personalisation preferences
If you uninstall the App or clear its data, this on-device data is permanently deleted.
2.6 AI Voice (Text-to-Speech)
When Mo speaks aloud, the text of Mo's response is sent through our secure backend to our voice provider (ElevenLabs) to generate audio. The audio is streamed back, saved to a temporary cache file on your device to play, and then deleted. We do not send your name or email for voice generation, and the generated audio is not retained on our servers.
2.7 Anonymised Research Data (Only With Your Explicit Consent)
If you choose to opt in to "Help improve nutrition science" during onboarding or in Settings, we collect anonymised usage patterns to advance the science of mood and nutrition. This data:
• Is stored under an anonymous identifier - a random value generated on your device. It is not derived from your account, and no link between this identifier and your account is ever stored on our servers, so research data cannot be traced back to you.
• Uses age bands (e.g. "25-34") instead of your exact age
• Uses region bands (e.g. "South Asia") instead of your exact location
• Includes anonymised health conditions, dietary preferences, and mood-food patterns (mood check-ins, mood-food outcomes, and which recommendations you engaged with)
• Is not linked to your name, email, or account. Because the identifier is random and generated on your device - with no user-to-identifier mapping stored on our servers - this data cannot be traced back to you at any time, whether or not you later delete your account. It is retained on an ongoing basis to support the science (see Sections 5, 11 and 12).
You can opt out of research data sharing at any time in Settings → Data Sharing. If you opt out, no further research data leaves your device.
2.8 Payments & Subscriptions
In-app subscriptions are managed by RevenueCat and the Apple App Store / Google Play. We receive anonymous purchase and subscription-status information. We do not receive or store your full payment card details - these are handled by the app stores' payment systems.
2.9 Notifications
If you enable notifications, we use Expo push infrastructure and store a device push token to deliver reminders and wellness nudges. You can disable notifications at any time in your device settings or in the App.
2.10 Diagnostic & Error Data (to Keep the App Working)
When the App runs into an unexpected error or crash, it sends us a technical diagnostic report so we can find and fix the problem. This report contains only:
• A random per-install identifier - generated on your device, not derived from and never linked to your account, name, or email
• The App version and your device platform (e.g. Android)
• A technical error message and stack trace, automatically scrubbed before sending to remove personal content (we strip email addresses, security tokens, and long number sequences)
This report does not contain your name, email, mood check-ins, food logs, chat messages, or any health data. It is stored in our secure backend (Supabase) and used only to diagnose and fix bugs. It is never used for advertising, profiling, or tracking, and is not sold or shared. This is our own first-party logging - we do not use Google Analytics, Firebase, or any third-party analytics or crash-reporting SDK. Because the report carries only a random per-install identifier and no account details, it cannot be traced back to you. We keep these reports only for as long as needed to investigate issues and clear them periodically.
2.11 What We Do Not Collect
• We do not collect precise GPS location. Regional pricing and regional content are determined from your device's time zone, not your location.
• We do not access your contacts or microphone. We access your camera and photo library only when you actively use the food scanner feature to select or take a photo.
• We do not collect data from other apps on your device
• We do not use device fingerprinting or cross-app tracking
• We do not track you across websites or apps