CodewithRomi

DenAI Privacy Policy

Effective date: August 15, 2026 Last updated: August 15, 2026

CodewithRomi LLC ("CodewithRomi," "we," "us," or "our") provides the DenAI mobile application and related services (collectively, "DenAI" or the "Service"). This Privacy Policy explains how information is handled when you use DenAI and the choices available to you.

This Policy describes DenAI version 1.0 as released. If we add a feature that changes how information is handled, we will update this Policy before that feature ships.

1. Privacy at a glance

2. Scope

This Policy applies to DenAI and to CodewithRomi-operated services that link to it. It does not govern Apple, the App Store, or other third-party services. Their own terms and privacy policies apply.

3. Information handled by DenAI

A. Information stored locally on your device

Depending on the features you use, DenAI stores the following in app-local storage on your device:

This information stays on your device until you delete individual entries, use Profile → Privacy and your data → Delete all my data, or delete the app. DenAI has no account, and CodewithRomi operates no cloud storage for your diary.

Device backups. Because DenAI's data is stored in your app's normal storage, it is included in the iPhone backups you make to iCloud or to a computer, and it is restored when you set up a new iPhone from one of those backups. Those backups are made by you and by Apple under Apple's terms; the data goes to Apple, never to CodewithRomi, and we can neither read nor delete it. You can exclude DenAI from iCloud backup in iOS Settings, and you can export your data to a file at any time if you would rather hold your own copy.

Because this information is only on your device, CodewithRomi cannot access it, retrieve it, or delete it for you.

B. Progress photos

Progress photos are copied into a private directory inside DenAI's own app container. They are not written to your camera roll, are not readable by other apps, and are not included in the data export. They are never uploaded. They are removed when you delete the photo, use "Delete all my data," or delete the app.

If you enable the optional photo lock, Face ID or your device passcode is required to view them. Apple performs that authentication; DenAI receives only a success or failure result and never receives biometric data.

C. AI meal scanning — the one feature that transmits data

If you subscribe to Pro and choose to scan a meal, DenAI resizes the photo on your device and sends it to a CodewithRomi-operated endpoint, which forwards it to our AI provider to obtain a food and nutrition estimate. The response is returned to your device for you to review and correct before anything is saved.

Two things are transmitted:

1. The meal image, only for the scan you requested. 2. A device token — a random identifier generated on your device the first time you scan. It is not your name, email, Apple ID, advertising identifier, or device serial number, and it is not linked to your identity. Its only purpose is counting scans so a single installation cannot exhaust the service.

What our endpoint does with the image: it holds the image in memory for the duration of the request and discards it. The image is never written to any database, file store, queue, or log line, and nothing that could reconstruct it — including its size, hash, or any fragment — is recorded.

What our endpoint stores: only the device token together with a count of scans, retained for approximately 36 hours (daily counter) and 40 days (monthly counter), after which it is deleted automatically. It also stores a running total of service cost, which contains no user data.

What our AI provider does. Our current provider is Anthropic PBC (the Claude API). Under Anthropic's commercial terms, Anthropic does not train its models on customer content. Anthropic retains API inputs and outputs for up to 30 days to support its safety and abuse-prevention work, after which they are deleted automatically. Content flagged by Anthropic's automated safety systems as a possible policy violation may be retained longer, up to two years, with classification scores retained longer still. We do not control those periods.

This means we cannot promise your meal photo is destroyed the instant your estimate appears. It is discarded immediately by *our* service, but it may exist in our AI provider's systems for up to 30 days. If that matters to you, do not use meal scanning — every other feature of DenAI works without it, and manual logging is free.

Anthropic's privacy policy: https://www.anthropic.com/legal/privacy

D. Infrastructure and connection information

Our scan endpoint runs on Cloudflare Workers (Cloudflare, Inc.). As with any internet service, Cloudflare processes ordinary connection information such as IP address, timestamp, requested endpoint, and response status in order to route and protect the request. We enable Cloudflare's standard operational logging at a reduced sampling rate for reliability purposes; it captures request metadata only and never request bodies, so meal images do not appear in it. We do not maintain any separate log of our own containing user content.

Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/

E. App updates

DenAI uses Expo Application Services (Expo, Inc.) to deliver over-the-air updates to the app's JavaScript — for example, additions to the food database. On launch, the app asks Expo's update server whether a newer version exists. That request conveys ordinary connection information plus the app's version, platform, and release channel. No diary, profile, photo, or health information is sent with it.

Expo's privacy policy: https://expo.dev/privacy

F. Purchases and subscriptions

If you purchase or restore a DenAI Pro subscription, Apple processes the payment. Apple may provide CodewithRomi or its subscription infrastructure with transaction status, product identifier, purchase and expiration dates, storefront, and an app-scoped transaction identifier. CodewithRomi never receives your payment card number.

Subscription status is managed through RevenueCat, Inc., which receives the app-scoped identifiers described above in order to tell the app whether your subscription is active. It does not receive your diary, photos, or body data.

RevenueCat's privacy policy: https://www.revenuecat.com/privacy

G. Apple Health

Connecting Apple Health is optional and off until you choose it. When you connect, DenAI requests read-only access to exactly three things:

DenAI never requests write access to Apple Health and cannot add, change, or delete anything there. The built app does not carry the HealthKit write permission or the background-delivery entitlement at all.

These values are read on demand while you have the screen open, shown to you, and discarded. They are not saved into DenAI's own storage, and they are never uploaded. We do not use Apple Health information for advertising or marketing, do not sell it, and do not place it in any cloud container.

Apple controls this permission. You can change or revoke it at any time in the Health app or in iOS Settings, and Apple deliberately does not tell us which specific items you granted.

H. Barcode scanning

When you scan a barcode, the camera reads the digits printed under it. No photograph is taken, saved, or transmitted. Only the decoded number is sent — to Open Food Facts, to ask which product it is. If you then choose the product, it is stored on your device so it works offline next time.

I. Food recall alerts

DenAI checks the U.S. Food and Drug Administration's public openFDA enforcement data for Class I recalls — the most serious category.

The matching happens entirely on your device. We download the public list of recent recalls and compare it against the packaged products you have scanned, locally. Your food diary, your barcodes, and your identity are never sent to the FDA or to us to perform this check. The FDA's servers see a request for the public recall list and nothing about who asked or what they eat.

A match means a recall mentions a product code similar to something you logged. It does not confirm your specific package is affected — lot numbers and best-by dates usually determine that — so DenAI always links you to the official notice rather than telling you what to do. DenAI is not affiliated with or endorsed by the FDA.

J. Notifications

All DenAI reminders are local notifications scheduled by your own device. DenAI does not request a push token, operates no push server, and has no technical ability to send you a message or to learn whether you opened a reminder. Turning reminders off in DenAI or in iOS Settings stops them entirely.

K. Support communications

If you contact us, we receive what you choose to send: your email address, your message, and any attachments. Please do not send progress photos, GLP-1 notes, or other sensitive health information unless we specifically ask for it.

4. How we use information

We use information only to:

We do not use health, fitness, body-progress, photo, or food-diary information for behavioral advertising, marketing profiles, or sale to data brokers.

5. How information may be disclosed

Our complete vendor list for DenAI 1.0 is:

VendorPurposeWhat it receives
Apple Inc.App Store, payments, device servicesPurchase and account information under Apple's terms
Cloudflare, Inc.Hosts the scan endpointConnection metadata; the meal image transits it in memory
Anthropic PBCAI meal analysisThe meal image and the device token, for one request
RevenueCat, Inc.Subscription statusApp-scoped purchase identifiers
Expo, Inc.Over-the-air app updatesConnection metadata, app version, platform, channel
Open Food FactsPackaged-product lookup by name or barcodeThe search text or the barcode digits. Never your diary
U.S. FDA (openFDA)Public recall listA request for the public list. Nothing about you or your food

Beyond those vendors, we may disclose information only:

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising.

6. Retention and deletion

InformationWhereHow long
Diary, profile, weights, measurements, wellness notesYour device onlyUntil you delete it or delete the app
Progress photosYour device only, app-private storageUntil you delete them or delete the app
Meal imagesIn memory at our endpointDiscarded when the request completes; never stored
Meal images at our AI providerAnthropicUp to 30 days; longer only if flagged by their safety systems or required by law
Device token and scan countsCloudflare KV~36 hours (daily) and ~40 days (monthly), then deleted automatically
Cloudflare operational logsCloudflarePer Cloudflare's standard retention; metadata only, no request bodies
Purchase recordsApple / RevenueCatAs required for entitlement verification, accounting, and legal obligations
Support emailOur mailboxAs reasonably necessary to respond and to meet legal obligations

Where information exists only on your device, we cannot retrieve or delete it remotely — the in-app controls are the only way to remove it.

7. Your choices and controls

You can:

Deleting DenAI does not cancel an active subscription, and does not delete support correspondence or Apple's transaction records.

8. Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the information we handle. Transmission to our scan endpoint is encrypted in transit. Our API credentials are held as server-side secrets and are never contained in the app.

No method of storage or transmission is completely secure. Because DenAI's records are stored on your device and there is no account recovery, protecting your device with a passcode and current software updates is the single most important safeguard, and loss or reset of your device may permanently remove your data.

If CodewithRomi becomes subject to a legally applicable breach-notification requirement, we will provide notice as required by law.

9. Children and age eligibility

DenAI is intended for adults age 18 and older. It is not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to CodewithRomi, contact support@codewithromi.com. Information stored only on a child's device must be deleted from that device, because CodewithRomi does not possess it.

10. International and regional privacy rights

Depending on where you live, you may have rights concerning personal information CodewithRomi holds, including rights to access, correct, delete, obtain a copy, restrict or object to processing, withdraw consent, or appeal a denied decision, and to complain to your local data-protection authority.

To make a request, email support@codewithromi.com with the subject "Privacy Request." We may need to verify your identity. Because nearly all DenAI information stays on your device, the in-app export and delete controls are usually the only way to act on it — we cannot access it to fulfil a request.

Information handled by our vendors may be processed in the United States. [BEFORE OFFERING DENAI IN THE EEA OR UK: obtain regional legal review and add the controller address, lawful bases, any required representative, and the transfer mechanism.]

11. HIPAA and medical records

DenAI is a consumer wellness tool. It is not intended to be operated by a healthcare provider or health plan on your behalf, is not a HIPAA-covered service, and its contents are not a medical record.

12. Changes to this Policy

We may update this Policy to reflect changes to DenAI, to our vendors, or to legal requirements. We will update the date above and give additional notice where legally required. If a change requires your consent, we will ask for it before it takes effect.

13. Contact us

CodewithRomi LLC, a New Jersey limited liability company Website: https://codewithromi.com Email: support@codewithromi.com

Email is our contact channel for support, legal, and privacy matters, and it is monitored. If you require a postal address for formal legal service, request it at the address above and we will provide one.