Protein Ring Privacy Policy
Effective date: 2026-09-07
Overview
Protein Ring is an iPhone app, with an Apple Watch companion, that helps you set a protein target, log meals in your own words, check the estimate, and see what your days add up to. We collect the minimum data needed to sign you in, save your meals and plan, estimate nutrition, process your subscription, understand how the app is used, and fix crashes.
Data We Collect
Account Data
- The email address or sign-in provider account (Apple or Google) you sign in with.
- Your Supabase user id and sign-in session data.
- Account status, sign-in and sign-out events, and deletion status.
Plan Data
- The goal you choose and how many days a week you train.
- The body details used to size your plan: weight, height and age. You can type them or import weight, height and date of birth from Apple Health. Your date of birth stays on your iPhone; only the age derived from it is used.
- The plan the server builds from them: calories, protein, carbs, fat and fiber targets, and your later adjustments.
- Reminder settings. Reminders are local notifications scheduled on your device; nothing about them is sent to us.
Meal And Nutrition Data
- The meal text you type or dictate. Dictation uses the keyboard’s own microphone on iPhone and the system keyboard on Apple Watch; we receive the words, never the audio, and Protein Ring stores no recordings.
- The estimate built from that text: food items, quantities, calories, protein, carbs, fat, fiber and other nutrients, FoodData Central food identifiers, confidence, and your answers to clarifying questions.
- Your meal history and the reads built from it on our servers: daily totals, which days reached the target, and averages over the last 28 days.
- Unsent meal drafts and a queued Watch transfer, stored on the device until they are sent.
Apple Health Data
Only with your permission, given in Apple’s own prompt:
- Reads: weight, height and date of birth, to prepare your plan; active and resting energy, to show your activity context. You review imported values before they are used. Date of birth is never sent to our servers.
- Writes: weight and height after you confirm them; and, if you turn on “Add saved meals to Apple Health”, each saved meal’s calories, protein, carbs, fat and nutrients. When you correct or remove a meal in Protein Ring, the matching Apple Health entry is replaced or removed.
- Apple Health data is used only to provide these features. It is never used for advertising or marketing, never sold, and never shared with third parties, in line with Apple’s HealthKit rules.
- Deleting your Protein Ring account does not remove data already written to Apple Health; you can remove it in the Health app.
Widgets And Live Activities
Today’s ring, the protein left, and your recent meals are stored on your device in a container shared with Protein Ring’s widgets and Lock Screen activity. This data does not leave the device for those features.
Purchase And Entitlement Data
- Subscription plan selection, product identifiers, purchase status, restore status and entitlement status, as returned by RevenueCat and the App Store.
- We never see your payment card details; Apple handles payment.
Analytics Data
- An anonymous id before sign-in and your Supabase user id after.
- App events such as setup progress, plan views, purchase start and result, meals logged, estimate success or failure, clarifying questions, reminders and Apple Health connection, with sanitized properties such as platform, local date, latency, item counts and plan identifiers.
- Meal text and email addresses are blocked from analytics.
- If you allow tracking when Protein Ring asks (after your first meal, never on the welcome screens), Singular receives the advertising identifier to learn which ad or link brought you here. If you decline, no advertising identifier is read; Singular still counts the install and sessions by a vendor identifier that stays within Protein Ring.
- On the production Protein Ring website, we collect page paths, selected calls to action, selected app store, broad device platform, referring website host, and allow-listed campaign tags, under an anonymous id that lasts only for the current browser tab. We do not send URL query strings, raw browser user-agent text, email addresses, or person profiles from website analytics. Website analytics is off on local, development and preview deployments.
Crash And Performance Diagnostics
- App errors and crashes, app version and release, environment, device and OS information, and performance spans for app start, sign-in, entitlement loading and meal estimation.
- The only user identifier sent to Sentry is your Supabase user id.
- Meal text, prompts, emails, tokens, secrets, cookies, authorization headers and API keys are stripped before diagnostics are sent.
How We Use Data
- Sign you in and keep your session.
- Save and sync your meals, plan, and settings.
- Turn your meal text into food items and nutrition estimates.
- Match foods against FoodData Central and cache shared nutrition references.
- Build your plan and your 28-day reads on our servers.
- Unlock your subscription and restore purchases.
- Read from and write to Apple Health when you have allowed it.
- Answer support, export, privacy and deletion requests.
- Improve setup, meal logging, the plans page and retention.
- Understand which website pages and install actions help visitors reach the App Store.
- Find and fix crashes and slow paths in TestFlight and production.
Processors And Service Providers
| Provider | Role | Data Processed |
|---|---|---|
| Supabase | Sign-in, database and Edge Function runtime for your account data. | Account identifiers, plan, meals, settings, session metadata, deletion and export operations. |
| OpenAI | Best-effort multilingual meal parsing, called only from our Edge Functions. | The meal text you submit and the context needed to return food items or a clarifying question. |
| USDA FoodData Central | Nutrition reference lookup, called only from our Edge Functions. | Food search terms, FoodData Central food ids, and public nutrition reference data. |
| RevenueCat | Subscription entitlement and purchase state. | App user id, product identifiers, subscription status, restore status, and store transaction and entitlement metadata. |
| Singular | Marketing attribution: which ad or link brought an install, and whether it led to a subscription. | Advertising identifier only if you allow tracking, vendor identifier, app user id, install and session events, subscription events from RevenueCat. Never meal text, health values or your plan. |
| Apple (App Store, StoreKit, Sign in with Apple, HealthKit) | Billing and subscription management; sign-in; Health storage on your device. | App Store purchase and subscription data handled by Apple; Sign in with Apple identifiers; Health data stays in Apple Health on your device. |
| Google (Sign-In) | Optional sign-in provider. | The Google account identifier and email you sign in with. |
| PostHog | Product and website analytics, and recordings of the app’s screens during a session (typed meal text, foods and body values are masked before capture). | Sanitized event names and properties, anonymous id, Supabase user id after sign-in, anonymous browser-tab id, page path, broad platform, timestamps. |
| Sentry | Crash reporting and performance monitoring. | Errors, crash diagnostics, release and environment tags, sanitized performance spans, Supabase user id. |
API keys for OpenAI and FoodData Central live server-side in our Edge Functions and are not shipped in the app. Singular’s measurement SDK is the one attribution SDK in the iPhone app; it receives no meal text, health values or plan, and reads the advertising identifier only if you allow tracking. If an Android app ships, this policy will be updated for Google Play billing first.
Data Sharing
We do not sell personal data. We share data with the processors above only as needed to operate the app, process purchases, estimate meals, perform analytics, diagnose errors, or comply with your requests and the law.
Data Retention
Your account, plan and meals are kept while your account is active. Shared FoodData Central reference foods may remain after account deletion because they are not your records. After a successful account deletion the app clears its local state on the device: unsent drafts, the shared widget container, reminder settings and preferences. Data you asked us to write into Apple Health stays in Apple Health.
Account Deletion
Delete your account from You › Delete account. Deletion removes your meals, meal items, goals and profile from Supabase, then deletes your Supabase user. Your subscription is billed by Apple and does not end with your account: cancel it in your Apple Account settings or it keeps renewing.
Data Export And Support
You › Request your data starts an email to support@proteinring.com with
your account noted; we fulfil it from your user-owned records. You › Export
on-device data gives you a file of what is on this iPhone.
For privacy, deletion, support or export questions, write to
support@proteinring.com.
Security
Protein Ring uses Supabase authentication, row-level access rules, server-side Edge Functions for private API keys, and on-device storage only for the state the app needs on the device. No security system is perfect, but production secrets stay out of the app bundle and the repository.
Changes
We may update this policy as the app changes. The published policy shows the current effective date and stays linked from You and from the App Store listing.