Omni is a 100% advertisement-free and third-party analytics-free health and nutrition tracking application. We do not contain Google AdMob, Firebase Analytics, or any behavioral tracking SDK. The vast majority of your data never leaves your device; the only exception is your profile, which is synchronised through your own private iCloud account so it follows you to a new device (see Section 2.7). Where external processing is required (AI features, weather, subscriptions), we use the minimum data necessary and rely exclusively on Apple's and Google's enterprise-grade infrastructure.
The data controller responsible for your personal data is:
Enes Beyaz
Email: support.omniapp@gmail.com
If you are located in the European Economic Area (EEA) and have questions about how your personal data is processed, please contact the Service Provider at the address above.
The following information is stored locally on your device via Apple SwiftData and, for your profile only, in your own private iCloud account (see Section 2.7). It is never uploaded to the Service Provider's servers:
With your explicit permission, the Application reads the following HealthKit data types:
HealthKit data is governed by strict rules:
The Application uses your device camera for:
Images are transmitted to the Google Gemini API solely for real-time analysis. Your photographs are never stored on the Service Provider's servers. They are discarded immediately after analysis is complete.
For premium users, the Application can generate an illustrative image of a logged dish so that your diary is visual rather than a plain list. To avoid regenerating (and paying for) the same illustration for every user, these AI-generated images are stored in a shared library hosted on Google Firebase Storage and keyed by a generic English dish name (for example, red-lentil-soup).
What this means for your privacy:
The Application accesses your device's approximate location to:
Location data is processed momentarily via Apple's WeatherKit framework. Coordinates are never logged, stored historically, or shared with third parties for advertising. You may restrict location access at any time in your device settings.
Premium subscription validation is managed through RevenueCat. RevenueCat receives anonymized transaction identifiers from Apple's App Store to verify entitlement status. The Service Provider does not have access to your payment card or billing details.
RevenueCat Privacy Policy: https://www.revenuecat.com/privacy
Lock Screen and Dynamic Island (Live Activity): If enabled, your daily water progress can be displayed on your Lock Screen and in the Dynamic Island. This information is rendered on your device only and is never transmitted anywhere. Because a Lock Screen is visible without unlocking your device, anyone with physical access to your phone could see this figure; you can turn the feature off at any time in app settings, or dismiss the activity directly from the Lock Screen.
To spare you from re-entering everything when you get a new device or reinstall the Application, your profile is synchronised through Apple's iCloud Key-Value Store. The following items are covered:
The following are deliberately not synchronised, because they are specific to a single device or day: your meal and supplement intake logs, streaks, notification timing state and your profile photo. Your water and nutrition history already travels with you through Apple Health.
Allergies and medical conditions are included on purpose: if they did not travel with you, the AI safety rules that protect you would silently stop applying on a new device.
This data is stored in your own iCloud account under Apple's encryption. The Service Provider has no access to it, it is not sent to our servers, and it is never used for advertising or analytics. You can turn it off at any time in iOS Settings → [your name] → iCloud, and deleting your account inside the Application also erases the iCloud copy.
The Application uses the Google Gemini API to power:
Data transmitted to Gemini:
Transmitted data falls into two distinct categories, which are governed by different rules:
(a) Safety data — always included when you request an AI feature.
Your food allergies, diagnosed medical conditions, and special conditions (pregnancy or breastfeeding) are included in every food-related AI request — recipe generation, meal photo analysis, and meal suggestions — regardless of whether you have enabled AI health personalization. This is a deliberate safety decision: an AI that does not know your allergy could suggest a dish that harms you. Withholding this data would make the feature unsafe rather than more private. If you do not wish this data to be transmitted, do not enter it in your profile, or avoid using the AI recipe and scanning features.
(b) Personalization data — only with your explicit AI health consent.
Derived wellness signals (heart-rate variability trend, sleep duration, activity level), aggregated behavioural patterns learned on-device (for example, typical logging times), and weekly aggregate nutrition totals are transmitted only when you have enabled AI health personalization. These improve suggestion quality; they are not required for safety.
In addition, the following context may be transmitted when relevant to your request: age range, weight range, health goal type, dietary preference, local weather context (temperature and humidity) used to calculate dynamic hydration goals, and food or supplement images. This list is illustrative and not exhaustive; in all cases the data is de-identified and never accompanied by your name, email address, or account identifier.
Critical safeguards:
This processing is governed by Google's Privacy Policy and the Google Gemini API Terms of Service:
https://ai.google.dev/gemini-api/terms
GDPR — Automated Decision-Making and Profiling (Article 22):
The Application uses automated processing of your data to generate personalized recommendations (recipes, hydration goals, coaching tips). This constitutes profiling under GDPR. These recommendations are informational and do not produce legal effects or significantly affect you in a similarly serious manner. You have the right to object to this profiling at any time by disabling the AI Master Toggle.
EU AI Act Compliance:
The AI features in this Application are classified as low-risk under the EU AI Act. All AI outputs are clearly presented as informational suggestions and do not replace professional medical or nutritional advice.
The Application does not contain any advertising. There are no third-party advertising SDKs (including Google AdMob), no behavioral tracking pixels, and no advertising identifiers collected. Neither free nor premium users are shown advertisements.
The Application does not use any third-party behavioral analytics SDKs (including Firebase Analytics, Flurry, Mixpanel, or similar services). In-app data visualizations (charts, trends) are computed locally on your device using Apple's native frameworks.
| Data Type | Where Stored |
|---|---|
| Profile, logs, recipes, streaks | Your device (Apple SwiftData); profile also in your own iCloud |
| HealthKit metrics | Apple Health app (Service Provider has no server copy) |
| Weather data | Momentary — not stored |
| Camera images (your photographs) | Momentary — discarded after Gemini analysis |
| AI-generated dish illustrations | Your device, plus a shared library on Google Firebase Storage keyed by a generic dish name (no user identifier) |
| Subscription status | RevenueCat (anonymized transaction ID) |
| Payment details | Apple App Store (Service Provider never accesses these) |
The Service Provider does not operate any servers that store personal user data.
| Processing Activity | Lawful Basis |
|---|---|
| Health, nutrition, and dietary data | Explicit consent — Article 6(1)(a) and Article 9(2)(a) |
| Allergy and medical condition data sent to the AI as a safety constraint | Explicit consent — Article 6(1)(a) and Article 9(2)(a), given when you enter this data after being informed that it is used to filter AI-generated food suggestions |
| Camera image analysis via Gemini | Explicit consent — Article 6(1)(a) |
| Location data for WeatherKit | Explicit consent — Article 6(1)(a) |
| Core app functionality | Performance of a contract — Article 6(1)(b) |
| Subscription and payment records | Legal obligation — Article 6(1)(c) |
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal does not prevent you from continuing to use the Application's core features.
Google LLC (Gemini API and Firebase Storage) and RevenueCat process data on servers located in the United States. Where such transfers occur from the EEA, the Service Provider relies on:
You may request a copy of applicable transfer safeguards by contacting: support.omniapp@gmail.com
| Data Type | Retention Period |
|---|---|
| Profile and health data | Duration of app use + 12 months, unless you delete the app or request erasure |
| Notification history | 90 days (local, on-device) |
| Camera images | Zero — discarded immediately after analysis |
| HealthKit data | Accessed in real time; no copy retained by Service Provider |
| Subscription and payment records | 7 years (tax and accounting legal obligation) |
| Anonymized and aggregated data | Indefinitely (contains no personal data) |
Uninstalling the Application immediately and permanently deletes all locally stored data from your device.
If you are located in the EEA, you have the following rights:
To exercise any of these rights, contact: support.omniapp@gmail.com
The Service Provider will respond within 30 days. This period may be extended by two further months where necessary. You also have the right to lodge a complaint with your national data protection supervisory authority. A directory of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Regardless of your location, you may at any time:
Contact: support.omniapp@gmail.com
If you are a California resident, you have the right to:
The Service Provider does not sell or share personal information with third parties for cross-context behavioral advertising.
To exercise your CCPA/CPRA rights, contact: support.omniapp@gmail.com
In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, you will also be notified directly without undue delay, as required by GDPR Article 34.
The Application is not directed to children under the age of 16. The Service Provider does not knowingly collect personal information from children under 16. If the Service Provider becomes aware that a child under 16 has provided personal information, that information will be deleted promptly. If you are a parent or legal guardian and believe your child has provided personal information to the Application, please contact: support.omniapp@gmail.com
The Service Provider implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. All data transmitted to external services (Gemini API, RevenueCat, WeatherKit) is encrypted in transit using industry-standard TLS. Locally stored data is protected by Apple's iOS Data Protection framework.
The Service Provider may update this Privacy Policy from time to time. For material changes, you will be notified via an in-app notification and the updated policy will be posted with a new effective date. Where required by applicable law (including GDPR), your consent will be sought before material changes take effect. Previous versions are available upon request at: support.omniapp@gmail.com
Enes Beyaz
Email: support.omniapp@gmail.com
For complaints that cannot be resolved directly, EEA users may contact their national data protection supervisory authority:
https://edpb.europa.eu/about-edpb/about-edpb/members_en