Who we are
Plateknow is made by AI Joy Apps, the trading name of an independent studio run by its founder. AI Joy Apps is the data controller for the processing described on this page. On Google Play the app may be listed under the founder’s individual developer name; whichever name it appears under, AI Joy Apps is the studio behind it and your point of contact.
Privacy questions and data requests: hello@plateknow.com. A person reads and answers it. If you are in the EEA or the UK and need a postal address for a formal request, ask at that address and we will provide one.
This policy covers the Plateknow app for Android (package com.plateknow.app, Android 10 and later). The iPhone app and the plateknow.com website have their own policy, because they work differently — for example, the iPhone app can sync through iCloud, and the Android app has no cloud sync at all.
The short version
- There is no account. No sign-up, no sign-in, no email address, no Google sign-in. The app never asks who you are.
- Your journal is stored only on your phone. Meals, estimates, check-in answers, notes and settings live in the app’s private storage. There is no Plateknow cloud sync.
- Your original photos stay on your phone. For an AI estimate the app sends only a small cut-out of the food on a white background, and sends nothing if it detects a person in the photo.
- Health Connect data stays on your phone. It is never sent to our servers.
- Product analytics and crash reports go to Mixpanel and Google Firebase. They carry fixed event names, counts and labels, never your food, photos, notes, check-in answers or Health Connect data.
- No ads and no advertising ID. We do not sell data.
| Data | On your phone | Leaves your phone? |
|---|---|---|
| Original photos | Yes | No |
| Food cut-out (512 px JPEG on white) and coarse hints | Made on your phone | Only when you ask for an AI estimate: to our gateway on Cloudflare, which forwards the image to an AI model through OpenRouter. Not stored by our gateway |
| Journal: meals, estimates, check-in answers, notes, body profile, settings | Yes | No — except inside your own Android backup to your Google account, if backup is on (photos are excluded) |
| Health Connect data (steps, weight read; nutrition written) | Yes | No, never through Plateknow |
| Random install ID | Yes | To our gateway (kept only as a salted hash), RevenueCat, Mixpanel and Google Firebase |
| Product analytics events (a fixed event name with counts, yes/no values or fixed labels) | Created on your phone as you use the app | To Mixpanel and Google Firebase Analytics, with the random install ID |
| Crash reports | Created if the app crashes | To Google Firebase Crashlytics, with the random install ID |
| Play Integrity token | Created by Google Play on your phone | With each estimate request, to our gateway, which asks Google to verify it |
| Purchases | Status shown in the app | Google Play Billing takes the payment; RevenueCat keeps the subscription record |
| Emails you choose to send us | — | Only when you send them |
What we process, by category
Random install ID
On first launch the app creates a random identifier (a UUID). It is not linked to your name, email address, phone number, Google account or advertising ID, and the app does not read the advertising ID. It is used for three things: as the customer ID in RevenueCat, so that a subscription can be recognised; as the key our gateway uses to count estimates against the daily allowance; and as the identifier on product analytics events and crash reports, so that one install’s events can be read together (see Analytics and crash reports). Reinstalling the app, or using Delete everything, creates a new one.
The food cut-out and estimate hints
When you ask for an estimate, the work starts on your phone. The app finds the food with Google ML Kit subject segmentation, which runs on the device, cuts the food out, places it on a white background and scales it to 512 pixels. If the on-device check detects a person in the photo, nothing is sent.
What is sent is that cut-out JPEG and a few coarse hints that help the estimate: how much of the frame the food covers, how many items were found, the meal slot (such as “lunch”), the app’s language, your device’s region setting and the type of container (such as a bowl). The original photo, your notes, your check-in answers and your Health Connect data are never part of the request.
The request goes to our gateway at plateknow.com/api/v1/food/estimate, a Cloudflare Worker. It forwards the image to an AI vision model through OpenRouter and returns an estimate: a dish name, calories, carbohydrate, protein and fat, sometimes fibre, sugar and sodium, and a confidence level. Our gateway does not store the image, does not log it and does not write it to any database; it is held in memory only while the request is handled. OpenRouter and the model provider process the image to answer the request, and how long they keep request data is governed by their own terms (see Processors).
“I ate this” or “Just curious”. After a photo is analysed, the result screen offers I ate this (selected by default) or Just curious. Just curious shows the nutrition estimate but saves nothing to your journal and schedules no check-in, and the photo and cut-out are discarded when the screen closes. The estimate request is identical either way — the same cut-out goes to our gateway and the same processors — and it counts toward the daily estimate allowance.
Asking for an estimate is optional. Logging a meal by hand sends nothing.
Your journal
Meals, estimates and your corrections, check-in answers, notes, the optional body profile (weight, height, age and activity level, which you type in yourself, used to compute a daily reference figure) and your settings are stored only in the app’s private storage on your phone. We have no copy and cannot see it. You can export it at any time, free, as CSV and JSON.
Android backup. If Android backup is turned on, Android may include the journal’s data files in your device backup to your Google account. Photos are excluded from that backup. On phones with a screen lock, the backup is end-to-end encrypted with your lock-screen PIN, pattern or password. We cannot read it. You control it in your phone’s backup settings.
Health Connect
Optional, and off until you connect it. Plateknow writes the nutrition of meals you save, reads today’s steps and reads your latest weight. That data stays on your phone. Details are in the Health Connect section below and on the Health Connect page.
Play Integrity
Each estimate request carries a Play Integrity token, created by Google Play on your phone and bound to a hash of that request. Our gateway sends the token to Google to confirm that the request came from the genuine Plateknow app installed from Google Play, on a genuine Android device. We use the result — whether the app was recognised, and the device-integrity labels — only to prevent abuse of the estimate service, and cache it against the hashed install ID for up to 6 hours. To create the token, Google Play processes information about the app and the device under Google’s own terms.
Purchases
Premium is bought through Google Play Billing. Google takes the payment; we never see your card or your Google account details. RevenueCat receives the purchase record (such as the product, purchase token, dates and subscription status) linked to the random install ID, and tells the app whether Premium is active.
Notifications
Check-in questions are scheduled on your phone with Android’s WorkManager. No push server sends them, and they never name the food.
Messages you send us
If you email us — including a “Report this estimate” message, which the app prepares as a draft in your email app for you to review — we receive what you send and your email address. We use it only to answer you and to fix problems, and keep it only as long as that takes.
Google ML Kit on the device
The food cut-out is made on the phone by Google ML Kit, delivered through Google Play services. ML Kit processes the image on the device and does not send the image to Google. Like other Google Play services components, it may send Google limited performance and usage information — such as device model, app and feature version, performance metrics and error codes, with a device identifier used for that purpose — under Google’s terms.
Analytics and crash reports
The app measures whether the product works — which onboarding screens people reach, whether the camera is opened and a photo taken, whether the timeline is opened, when a paywall is shown and whether a purchase starts, completes, fails or is restored, when a recap period has too little in it yet, and when a check-in closes unanswered. For this it uses Mixpanel and Google Firebase Analytics, the same services as the Plateknow iPhone app, and Google Firebase Crashlytics for crash reports.
An analytics event is a fixed name from a closed list, and a property can only hold a number from 0 to 999, a yes/no value, or one of a fixed set of labels. There is no way to put text into one. A food name, a photo, a note, a check-in answer, a nutrition figure or Health Connect data has nowhere to go — not because we decided not to send it, but because no part of the code accepts it. The labels include which onboarding screen was shown, which built-in focus you picked in onboarding (such as “digestion” or “energy”), where a paywall was opened, and whether a plan was monthly or annual. Every event also says whether it came from a Google Play build or a development build.
Events carry the random install ID and whether Premium is active. Google Firebase also records the standard information its SDK collects automatically: an app-instance identifier, app version, Android version, device model, language, an approximate country or region derived from the network connection, and when the app was first opened and used. Mixpanel attaches similar device and app information (such as device model, Android and app version, and screen size). Crash reports contain the technical state of the app at the moment of the crash — the stack trace, app version, device model, Android version and memory and storage state — with the install ID. The advertising ID is not collected: the permission to read it is removed from the app and advertising-ID collection is turned off.
Analytics and crash reports are part of how the app is maintained, and there is no setting in the app to turn them off, which is also true of the iPhone app. Delete everything resets them for your install (see Deleting your data), and you can ask us to delete what was already sent.
What we do not collect
We do not access your location, microphone, contacts, photo library or advertising ID (the analytics services derive only an approximate country or region from the network connection, as described above). To import a photo the app uses Android’s system Photo Picker, which gives the app only the one photo you choose.
Processors
These companies process data on our behalf, only for the purposes below. None of them receives your journal, your original photos, your check-in answers or your Health Connect data.
| Processor | What it receives | Why | Its terms |
|---|---|---|---|
| Cloudflare | Estimate requests (cut-out, hints, install ID, integrity token) and the network connection, including your IP address, which our gateway does not store | Runs our gateway at plateknow.com | cloudflare.com/privacypolicy |
| OpenRouter | The cut-out and the estimate request, sent by our gateway rather than your phone, so it does not receive your IP address | Routes the request to an AI vision model | openrouter.ai/privacy |
| AI model provider, reached through OpenRouter | The cut-out and the estimate request | Produces the estimate | Retention is governed by the provider’s terms as applied through OpenRouter |
| RevenueCat | The purchase record and subscription status, linked to the random install ID | Keeps track of whether Premium is active | revenuecat.com/privacy |
| Google Play Billing | Your purchase, through your Google account | Takes payment for Premium | policies.google.com/privacy |
| Google Play Integrity API | The integrity token sent with each estimate request | Confirms a genuine app and device, to prevent abuse | policies.google.com/privacy |
| Mixpanel | Product analytics events (fixed names, counts, yes/no values and fixed labels), the random install ID, whether Premium is active, and device and app information the SDK attaches | Tells us whether the product works: where onboarding is left, and how the camera and paywall are used | mixpanel.com/legal/privacy-policy |
| Google Firebase Analytics | The same product analytics events and install ID, plus the standard app-instance, device and approximate-location information its SDK collects | The same purpose; it also sits next to the crash reports | firebase.google.com/support/privacy |
| Google Firebase Crashlytics | Crash reports: stack trace, app version, device model, Android version and memory state, with the install ID | Finding and fixing crashes | firebase.google.com/support/privacy |
| Google ML Kit (on the device) | No images. Limited performance and usage information, as described above | Cuts the food out on your phone | policies.google.com/privacy |
These providers operate in the United States and other countries, so data may be processed outside the country where you live. Where the law requires it, we rely on the safeguards those providers offer, such as Standard Contractual Clauses in their data-processing terms. What crosses a border is limited to what this page describes.
There is no advertising in Plateknow. We do not sell personal data, do not share it for advertising, and do not track you across other apps or websites.
Health Connect
Health Connect is optional and stays off until you connect it. When connected, Plateknow uses three permissions, each tied to one thing you can see in the app:
| Permission | Access | What it is used for |
|---|---|---|
| Nutrition | Write | After you save a meal, Plateknow writes that meal’s estimated energy, carbohydrate, protein and fat — and fibre, sugar and sodium when the estimate includes them — to Health Connect. Correcting the meal updates the same record; deleting the meal removes it. |
| Steps | Read | Today’s step total, shown on the Today screen. |
| Weight | Read | Your most recent weight from the last 30 days, read only when you tap Use the latest weight from Health Connect in Me → Your body, to fill in the body profile that computes your daily reference figure. |
Plateknow reads only today’s step total and your most recent weight. It does not request the permission to read past Health Connect data (history) or the permission to read Health Connect data in the background.
- Health Connect data stays on your phone: Plateknow never sends it to our gateway or to any processor.
- It is never sold, never used for advertising, and never used for credit or lending decisions.
- It is never shared with third parties and never used to train AI models.
You can stop at any time by turning off Connected in Me → Health Connect, or revoke Plateknow’s permissions in Health Connect’s own settings. Records Plateknow has already written stay in Health Connect until you delete them there.
Plateknow’s use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements.
Permissions
| Permission | When it is asked | What for |
|---|---|---|
| Camera | When you open the camera | Photographing a meal. You can import a photo or log by hand instead. |
| Notifications | After you save your first meal, never at launch | Check-in questions (“How did that sit?”) 2 and 6 hours after a meal by default, only between 10:00 and 22:00, at most 3 a day. They never name the food. |
| Internet | Granted at install | Sending the cut-out for an estimate and checking your subscription. |
| Health Connect: write nutrition, read steps, read weight | Only when you choose to connect Health Connect | See Health Connect. |
| Google Play billing | Granted at install | Buying Premium through Google Play. |
That is the complete list. Plateknow does not request or access location, microphone, contacts, or photo and media storage (imported photos come through the system Photo Picker), and uses no exact alarms and no foreground service.
How long data is kept
| What | Where | How long |
|---|---|---|
| Original photos, journal and settings | Your phone | Until you delete them, use Delete everything, or uninstall the app |
| Items you delete one scope at a time | “Recently deleted”, on your phone | 30 days, then removed |
| Food cut-out | Our gateway | Not stored — held in memory only while the request is handled |
| Food cut-out | OpenRouter and the model provider | As set by their own terms |
| Salted hash of the install ID, with request counters and a cached subscription tier | Our gateway | Expires on its own within 48 hours |
| Replay-protection cache | Our gateway | 10 minutes |
| Play Integrity verdict | Our gateway | Up to 6 hours |
| Raw IP address | Our gateway | Not stored |
| Purchase record linked to the install ID | RevenueCat | While needed for the subscription and our records, or until you ask us to delete it. Google Play keeps its own order history |
| Product analytics events linked to the install ID | Google Firebase Analytics | Event-level data for 2 months and user-level data for 14 months (the 14 months restart with new activity), then deleted by Google. Reports built from aggregated counts can be kept longer. Deleted for your install ID on request |
| Product analytics events linked to the install ID | Mixpanel | Kept by Mixpanel under our account settings and its terms. The events carry no content and nothing that names you. Deleted for your install ID on request |
| Crash reports linked to the install ID | Google Firebase Crashlytics | Up to 90 days, then deleted by Google |
| Emails you send us | Our inbox | As long as needed to help you |
Security
- All network traffic is encrypted in transit with TLS (HTTPS).
- Estimate requests are signed with an HMAC, carry a Play Integrity attestation, and are checked against a replay cache.
- The AI provider’s credentials exist only on our server, never in the app.
- The install ID is kept on the server only as a salted hash, and raw IP addresses are not stored.
- The journal sits in app-private storage, protected by Android’s app sandbox and your device’s storage encryption.
No system is perfectly secure. The strongest thing we can honestly say is structural: most of what would be worth stealing is not on our servers, because it never reaches them.
Children
Plateknow is intended for people aged 13 and over and is not directed to children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has used the app, uninstalling it removes everything on the phone, and you can write to hello@plateknow.com about any purchase record.
Your rights
Most rights in this app are things you do yourself: your journal is on your phone, you can export it for free and you can delete it. For what is held off the phone — the hashed counters, which expire on their own, RevenueCat’s purchase record, and the analytics events and crash reports linked to the install ID — write to hello@plateknow.com and include the install ID shown in Me → Data management. The install ID is how we find the record, so we do not need any other proof of identity.
EEA and UK (GDPR and UK GDPR)
You may ask to access, correct, delete, restrict or port your personal data, object to processing, and withdraw consent at any time. We rely on: contract, to provide the estimate you ask for and the subscription you buy; legitimate interests, to prevent abuse, count the free allowance, keep the service secure, know which features are used and fix crashes — balanced against a design in which analytics events cannot hold text and carry no name, email or advertising ID; consent, for optional permissions such as Health Connect, notifications and the camera, which you can withdraw in Android settings; and legal obligation, for purchase records we must keep. You can complain to your local data protection authority.
California (CCPA/CPRA)
In the last 12 months we have collected: identifiers (the random install ID), commercial information (purchase records), internet or other electronic network activity (in-app product analytics events), device information and crash reports (including the device information the analytics services collect) and images (the food cut-out, not retained by our gateway), for the purposes on this page. You may request to know, delete or correct personal information. We do not sell or share personal information as California law defines those terms, and we will not treat you differently for exercising your rights.
Taiwan (Personal Data Protection Act)
Purposes: providing the estimate service, managing subscriptions, preventing abuse, and product analytics and fixing crashes. Data: as described on this page. Period: as in the retention table. Regions: Taiwan and the countries where our processors operate, including the United States. Recipients: the processors listed above. Under Article 3 you may ask to review, obtain a copy of, supplement or correct your data, ask us to stop collecting, processing or using it, and ask us to delete it. You can choose not to provide data: without AI estimates or Health Connect, the rest of the app still works. Product analytics and crash reports cannot be turned off in the app; Delete everything resets them for your install, and you can ask us to delete what was sent.
South Korea (Personal Information Protection Act)
Overseas transfer, to perform our contract with you: items — the food cut-out and hints, the hashed install ID and integrity token, the purchase record, and product analytics events and crash reports with the install ID and device information; countries — the United States and other countries where the processors operate; when and how — over an encrypted connection, at the moment you request an estimate or make a purchase, and while you use the app for analytics and crash reports; recipients — Cloudflare, OpenRouter and the model provider, RevenueCat, Mixpanel and Google (including Firebase); purpose and retention — as in the tables above. You can refuse the estimate and purchase transfers by not using AI estimates or purchases; manual logging still works. Analytics and crash reports cannot be refused in the app, but you can ask us to delete them. You may request access, correction, deletion or suspension of processing. Privacy officer: AI Joy Apps, hello@plateknow.com.
Deleting your data
- Everything on the phone: Me → Data management → Delete everything erases every file and setting immediately and forgets the install ID. It also resets the analytics services for this install: Google Firebase clears the install ID and its analytics data on the phone, unsent crash reports are discarded, and Mixpanel stops receiving events from this install. It cannot be undone. Export first if you want a copy.
- Part of the journal: scoped deletes move items to “Recently deleted” on your phone for 30 days, then they are removed.
- Uninstalling removes everything the app stores on the phone. It does not cancel a subscription — cancel in Google Play.
- Server side: the hashed counters expire on their own within 48 hours (integrity verdicts within 6 hours). To have the RevenueCat purchase record, or the analytics events and crash reports already sent, deleted, email hello@plateknow.com with your install ID; we complete it within 30 days.
There is no account, so there is no account to delete. Step-by-step instructions are on the data deletion page.
Not medical advice
Plateknow is a food diary, not a medical device. It does not diagnose, treat, cure or prevent anything, and estimates carry real error. See the health disclaimer.
Changes to this policy
The date at the top is the last change. Any change to what leaves your phone will be described here before the app version that makes it is published on Google Play, and material changes will also be shown in the app.
Contact
Privacy questions, data requests and anything else: hello@plateknow.com. It reaches AI Joy Apps, and a person answers it.