DenAI Privacy Policy
Effective date: August 15, 2026 Last updated: August 15, 2026
CodewithRomi LLC ("CodewithRomi," "we," "us," or "our") provides the DenAI mobile application and related services (collectively, "DenAI" or the "Service"). This Privacy Policy explains how information is handled when you use DenAI and the choices available to you.
This Policy describes DenAI version 1.0 as released. If we add a feature that changes how information is handled, we will update this Policy before that feature ships.
1. Privacy at a glance
- Your profile, food diary, weights, body measurements, progress photos, wellness notes, and manual workouts are stored on your device. DenAI has no account system and does not upload them.
- Features that transmit anything, and only when you use them: AI meal scanning (a photo you choose to submit), branded food search and barcode scanning (the text you type or the digits under a barcode), and the recall list (a request for a public FDA file). Nothing else leaves the device.
- Apple Health is read-only and never uploaded, and recall matching happens on your device — your diary is never sent anywhere to check it.
- Reminders are scheduled by your device. DenAI has no push server, requests no push token, and cannot send you a message.
- DenAI contains no advertising SDKs, no behavioral analytics SDKs, and no third-party trackers.
- We do not sell personal information, and we do not use your health, fitness, body, photo, or food information for advertising or marketing.
2. Scope
This Policy applies to DenAI and to CodewithRomi-operated services that link to it. It does not govern Apple, the App Store, or other third-party services. Their own terms and privacy policies apply.
3. Information handled by DenAI
A. Information stored locally on your device
Depending on the features you use, DenAI stores the following in app-local storage on your device:
- Profile and planning information: name or nickname, age, sex used for estimates, height, current and starting weight, goal, target date, activity level, workout frequency, unit preference, meal pattern, coaching tone, dietary preferences, allergies, and foods you avoid.
- Nutrition and activity logs: foods, portions, calories, macronutrients, water, manual workouts and their duration and estimated burn, dates, times, and notes.
- Body-progress information: weight history, body measurements, weekly check-ins, and progress photos with their angle, date, and any associated weight.
- Wellness information: optional hunger, energy, sleep, consistency, and difficulty ratings; optional GLP-1 medication name, dose text, and injection dates; and personal wellness or symptom notes. DenAI does not provide medication dosing instructions and does not interpret symptoms.
- Preferences and settings: appearance (light/dark/system), reminder choices, favorites, recently used foods, custom foods you create, and local feature state.
This information stays on your device until you delete individual entries, use Profile → Privacy and your data → Delete all my data, or delete the app. DenAI has no account, and CodewithRomi operates no cloud storage for your diary.
Device backups. Because DenAI's data is stored in your app's normal storage, it is included in the iPhone backups you make to iCloud or to a computer, and it is restored when you set up a new iPhone from one of those backups. Those backups are made by you and by Apple under Apple's terms; the data goes to Apple, never to CodewithRomi, and we can neither read nor delete it. You can exclude DenAI from iCloud backup in iOS Settings, and you can export your data to a file at any time if you would rather hold your own copy.
Because this information is only on your device, CodewithRomi cannot access it, retrieve it, or delete it for you.
B. Progress photos
Progress photos are copied into a private directory inside DenAI's own app container. They are not written to your camera roll, are not readable by other apps, and are not included in the data export. They are never uploaded. They are removed when you delete the photo, use "Delete all my data," or delete the app.
If you enable the optional photo lock, Face ID or your device passcode is required to view them. Apple performs that authentication; DenAI receives only a success or failure result and never receives biometric data.
C. AI meal scanning — the one feature that transmits data
If you subscribe to Pro and choose to scan a meal, DenAI resizes the photo on your device and sends it to a CodewithRomi-operated endpoint, which forwards it to our AI provider to obtain a food and nutrition estimate. The response is returned to your device for you to review and correct before anything is saved.
Two things are transmitted:
1. The meal image, only for the scan you requested. 2. A device token — a random identifier generated on your device the first time you scan. It is not your name, email, Apple ID, advertising identifier, or device serial number, and it is not linked to your identity. Its only purpose is counting scans so a single installation cannot exhaust the service.
What our endpoint does with the image: it holds the image in memory for the duration of the request and discards it. The image is never written to any database, file store, queue, or log line, and nothing that could reconstruct it — including its size, hash, or any fragment — is recorded.
What our endpoint stores: only the device token together with a count of scans, retained for approximately 36 hours (daily counter) and 40 days (monthly counter), after which it is deleted automatically. It also stores a running total of service cost, which contains no user data.
What our AI provider does. Our current provider is Anthropic PBC (the Claude API). Under Anthropic's commercial terms, Anthropic does not train its models on customer content. Anthropic retains API inputs and outputs for up to 30 days to support its safety and abuse-prevention work, after which they are deleted automatically. Content flagged by Anthropic's automated safety systems as a possible policy violation may be retained longer, up to two years, with classification scores retained longer still. We do not control those periods.
This means we cannot promise your meal photo is destroyed the instant your estimate appears. It is discarded immediately by *our* service, but it may exist in our AI provider's systems for up to 30 days. If that matters to you, do not use meal scanning — every other feature of DenAI works without it, and manual logging is free.
Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
D. Infrastructure and connection information
Our scan endpoint runs on Cloudflare Workers (Cloudflare, Inc.). As with any internet service, Cloudflare processes ordinary connection information such as IP address, timestamp, requested endpoint, and response status in order to route and protect the request. We enable Cloudflare's standard operational logging at a reduced sampling rate for reliability purposes; it captures request metadata only and never request bodies, so meal images do not appear in it. We do not maintain any separate log of our own containing user content.
Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/
E. App updates
DenAI uses Expo Application Services (Expo, Inc.) to deliver over-the-air updates to the app's JavaScript — for example, additions to the food database. On launch, the app asks Expo's update server whether a newer version exists. That request conveys ordinary connection information plus the app's version, platform, and release channel. No diary, profile, photo, or health information is sent with it.
Expo's privacy policy: https://expo.dev/privacy
F. Purchases and subscriptions
If you purchase or restore a DenAI Pro subscription, Apple processes the payment. Apple may provide CodewithRomi or its subscription infrastructure with transaction status, product identifier, purchase and expiration dates, storefront, and an app-scoped transaction identifier. CodewithRomi never receives your payment card number.
Subscription status is managed through RevenueCat, Inc., which receives the app-scoped identifiers described above in order to tell the app whether your subscription is active. It does not receive your diary, photos, or body data.
RevenueCat's privacy policy: https://www.revenuecat.com/privacy
G. Apple Health
Connecting Apple Health is optional and off until you choose it. When you connect, DenAI requests read-only access to exactly three things:
- step count;
- active energy burned; and
- workouts.
DenAI never requests write access to Apple Health and cannot add, change, or delete anything there. The built app does not carry the HealthKit write permission or the background-delivery entitlement at all.
These values are read on demand while you have the screen open, shown to you, and discarded. They are not saved into DenAI's own storage, and they are never uploaded. We do not use Apple Health information for advertising or marketing, do not sell it, and do not place it in any cloud container.
Apple controls this permission. You can change or revoke it at any time in the Health app or in iOS Settings, and Apple deliberately does not tell us which specific items you granted.
H. Barcode scanning
When you scan a barcode, the camera reads the digits printed under it. No photograph is taken, saved, or transmitted. Only the decoded number is sent — to Open Food Facts, to ask which product it is. If you then choose the product, it is stored on your device so it works offline next time.
I. Food recall alerts
DenAI checks the U.S. Food and Drug Administration's public openFDA enforcement data for Class I recalls — the most serious category.
The matching happens entirely on your device. We download the public list of recent recalls and compare it against the packaged products you have scanned, locally. Your food diary, your barcodes, and your identity are never sent to the FDA or to us to perform this check. The FDA's servers see a request for the public recall list and nothing about who asked or what they eat.
A match means a recall mentions a product code similar to something you logged. It does not confirm your specific package is affected — lot numbers and best-by dates usually determine that — so DenAI always links you to the official notice rather than telling you what to do. DenAI is not affiliated with or endorsed by the FDA.
J. Notifications
All DenAI reminders are local notifications scheduled by your own device. DenAI does not request a push token, operates no push server, and has no technical ability to send you a message or to learn whether you opened a reminder. Turning reminders off in DenAI or in iOS Settings stops them entirely.
K. Support communications
If you contact us, we receive what you choose to send: your email address, your message, and any attachments. Please do not send progress photos, GLP-1 notes, or other sensitive health information unless we specifically ask for it.
4. How we use information
We use information only to:
- provide the features you request and maintain your local records;
- calculate and display estimates, trends, and the goals you select;
- return an AI estimate when you intentionally submit a meal photo;
- enforce fair-use limits and protect the scan service from abuse;
- deliver the local reminders you enable;
- process purchases and restore entitlements;
- deliver app updates;
- secure, troubleshoot, and maintain the Service;
- respond to your support requests; and
- comply with law and enforce our Terms of Use.
We do not use health, fitness, body-progress, photo, or food-diary information for behavioral advertising, marketing profiles, or sale to data brokers.
5. How information may be disclosed
Our complete vendor list for DenAI 1.0 is:
| Vendor | Purpose | What it receives |
|---|---|---|
| Apple Inc. | App Store, payments, device services | Purchase and account information under Apple's terms |
| Cloudflare, Inc. | Hosts the scan endpoint | Connection metadata; the meal image transits it in memory |
| Anthropic PBC | AI meal analysis | The meal image and the device token, for one request |
| RevenueCat, Inc. | Subscription status | App-scoped purchase identifiers |
| Expo, Inc. | Over-the-air app updates | Connection metadata, app version, platform, channel |
| Open Food Facts | Packaged-product lookup by name or barcode | The search text or the barcode digits. Never your diary |
| U.S. FDA (openFDA) | Public recall list | A request for the public list. Nothing about you or your food |
Beyond those vendors, we may disclose information only:
- Legal and safety: when reasonably necessary to comply with law or legal process, protect rights or safety, investigate abuse or security issues, or establish and defend legal claims.
- Business transaction: as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate confidentiality protections.
- With your direction or consent.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising.
6. Retention and deletion
| Information | Where | How long |
|---|---|---|
| Diary, profile, weights, measurements, wellness notes | Your device only | Until you delete it or delete the app |
| Progress photos | Your device only, app-private storage | Until you delete them or delete the app |
| Meal images | In memory at our endpoint | Discarded when the request completes; never stored |
| Meal images at our AI provider | Anthropic | Up to 30 days; longer only if flagged by their safety systems or required by law |
| Device token and scan counts | Cloudflare KV | ~36 hours (daily) and ~40 days (monthly), then deleted automatically |
| Cloudflare operational logs | Cloudflare | Per Cloudflare's standard retention; metadata only, no request bodies |
| Purchase records | Apple / RevenueCat | As required for entitlement verification, accounting, and legal obligations |
| Support email | Our mailbox | As reasonably necessary to respond and to meet legal obligations |
Where information exists only on your device, we cannot retrieve or delete it remotely — the in-app controls are the only way to remove it.
7. Your choices and controls
You can:
- skip any optional field or feature;
- edit or delete any entry inside DenAI;
- export your data as a JSON file (Profile → Privacy and your data → Export my data). The export contains your diary, profile, and metrics; it does not contain progress photo images. Once you share it, it is outside our control;
- restore from a previously exported file (Profile → Privacy and your data → Restore from a file). This replaces everything currently on the device;
- delete everything on the device (Profile → Privacy and your data → Delete all my data), which also removes progress photos and cancels scheduled reminders;
- turn reminders off in DenAI or in iOS Settings;
- revoke camera or photo access in iOS Settings;
- manage or cancel your subscription in your Apple account settings; and
- email support@codewithromi.com about information CodewithRomi actually holds.
Deleting DenAI does not cancel an active subscription, and does not delete support correspondence or Apple's transaction records.
8. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the information we handle. Transmission to our scan endpoint is encrypted in transit. Our API credentials are held as server-side secrets and are never contained in the app.
No method of storage or transmission is completely secure. Because DenAI's records are stored on your device and there is no account recovery, protecting your device with a passcode and current software updates is the single most important safeguard, and loss or reset of your device may permanently remove your data.
If CodewithRomi becomes subject to a legally applicable breach-notification requirement, we will provide notice as required by law.
9. Children and age eligibility
DenAI is intended for adults age 18 and older. It is not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to CodewithRomi, contact support@codewithromi.com. Information stored only on a child's device must be deleted from that device, because CodewithRomi does not possess it.
10. International and regional privacy rights
Depending on where you live, you may have rights concerning personal information CodewithRomi holds, including rights to access, correct, delete, obtain a copy, restrict or object to processing, withdraw consent, or appeal a denied decision, and to complain to your local data-protection authority.
To make a request, email support@codewithromi.com with the subject "Privacy Request." We may need to verify your identity. Because nearly all DenAI information stays on your device, the in-app export and delete controls are usually the only way to act on it — we cannot access it to fulfil a request.
Information handled by our vendors may be processed in the United States. [BEFORE OFFERING DENAI IN THE EEA OR UK: obtain regional legal review and add the controller address, lawful bases, any required representative, and the transfer mechanism.]
11. HIPAA and medical records
DenAI is a consumer wellness tool. It is not intended to be operated by a healthcare provider or health plan on your behalf, is not a HIPAA-covered service, and its contents are not a medical record.
12. Changes to this Policy
We may update this Policy to reflect changes to DenAI, to our vendors, or to legal requirements. We will update the date above and give additional notice where legally required. If a change requires your consent, we will ask for it before it takes effect.
13. Contact us
CodewithRomi LLC, a New Jersey limited liability company Website: https://codewithromi.com Email: support@codewithromi.com
Email is our contact channel for support, legal, and privacy matters, and it is monitored. If you require a postal address for formal legal service, request it at the address above and we will provide one.