Plateknow asks you to photograph your food and write down how your body felt afterwards. That is among the most intimate data a phone can hold, and this page is the specific, checkable account of where each piece of it goes.
Plateknow is made by AI Joy Apps, the trading name of an independent studio run by its founder, and AI Joy Apps is the data controller for everything described on this page. The app may be listed on the App Store under the founder’s individual developer name; whichever name it appears under, AI Joy Apps is the studio behind it and your point of contact. Privacy and data requests go to hello@plateknow.com.
This page covers both the iOS app and this website. It was last changed on the date above, and it describes the app as it is actually built — not as it is planned. Where the two differ, this page says so rather than describing the plan.
The short version
- There is no account. No sign-up, no password, no email, no Sign in with Apple. There is nothing for us to attach your meals to.
- Your photographs stay on your phone. The full picture is never uploaded. Neither is any note you write, any answer you give, or any body observation you take.
- Your journal syncs through your own iCloud, in Apple’s private database, which we cannot read.
- One thing is sent for an estimate: the cut-out of the food, on a blank background, with no name attached to it.
The four places your data can be
The app is built around this division, and it is enforced in the code rather than in a policy — the types that hold your content have no route to the types that talk to a network. Nothing moves between these except along the arrows described here.
| Where | What is there | Can it leave? |
|---|---|---|
| Your device | Original photographs, body observation photographs, your written notes, your check-in answers, any dimension you named yourself | Only to your own iCloud, and only the meal side of it |
| Your iCloud | Your meal journal — the photographs of the plate, the estimates, the check-ins, the notes — in Apple’s private database | No. It is in your container, encrypted. We have no key and no copy |
| The estimate service | The cut-out of the food, briefly, while the estimate is made | It is not stored after the answer comes back |
| Product analytics | Which screens were opened, and counts | It cannot carry your content — see below |
What is sent when you ask for an estimate
When you photograph a meal, your phone separates the food from everything around it before anything is sent. What travels is that cut-out — the plate on a flat background, at a small size — and two numbers describing how much of the frame it filled.
- The photograph itself is not sent. The table, the room, the people at it and the reflection in the window are removed on your device, before the request is made.
- No identifier is attached. No name, no email, no device id, no iCloud id. The request cannot be traced back to you because it does not carry anything to trace.
- Your notes and answers are not sent. They are never part of an estimate request; the model is asked what the food is, and nothing else.
- Nothing about your day is sent. An earlier version of this app sent how many calories you had left, so the model could phrase itself against your budget. That was removed: your remaining allowance is health information, and a nicer sentence is not worth it.
The request goes to our own service, which adds the credentials for the AI provider and passes the image on. The provider is currently reached through OpenRouter, and the service runs on Cloudflare. Neither receives an identifier from us. Our service does not log the contents of requests, and the image is held only in memory for the length of the call.
You can use the app without ever asking for an estimate. Typing a meal in by hand sends nothing at all, and every other feature — the journal, the check-ins, the recaps — works the same way.
Analytics, and why it cannot leak
The app measures whether the product works: which screens people reach, how often a check-in that was offered gets answered, how often an estimate gets corrected. That is the whole purpose, and the measurement is built so that it is not capable of carrying anything else.
An analytics event in this app is a fixed name from a closed list, and a property can only hold a number, a true/false, or one of a fixed set of labels. There is no way to put text into one. A food name, a note, a calorie figure or a check-in answer has nowhere to go — not because we decided not to send it, but because no part of the code accepts it. An automated test enumerates every event and checks the result against the content of a sample journal.
The only identifier involved is a random code the app generates on first launch and keeps on the device. It is not your Apple ID, not your advertising identifier, and not linked to anything about you.
- Never measured: any food name, any calorie or macro figure, any check-in answer, any note, any dimension you named, or how many body observations you have taken.
- Measured: which screens were opened, whether an offered check-in was answered, whether an estimate was corrected, and whether a paywall was shown.
Who else is involved
This is the complete list. Each one gets only what is described here.
| Service | What it receives | Why |
|---|---|---|
| Apple (iCloud) | Your journal, encrypted in your own private container | Sync between your devices. Governed by Apple’s privacy policy, and inaccessible to us |
| Apple (App Store) | Your purchase, if you subscribe | Payment. We never see your card |
| Cloudflare | The cut-out, transiently. This website’s traffic | Runs the estimate service and hosts the site |
| OpenRouter | The cut-out, transiently, with no identifier | Routes the request to the AI model |
| RevenueCat | Your subscription status, against the random install code | Tells the app whether you have premium |
| Mixpanel, Firebase | Product events only — see above | Whether the product works |
There is no advertising in this app, no ad network is linked, and nothing here is sold or shared for advertising purposes.
Permissions, and when they are asked
| Permission | When | What for |
|---|---|---|
| Camera | The first time you photograph something, in context | The core of the app |
| Photo library | Only when you choose a photo, and only for the ones you pick | Logging a meal you already photographed. Full library access is never requested |
| Notifications | After you save your first meal — never at launch | The follow-up check-in. Declining is not a dead end: the app works out what is due whenever you open it |
| iCloud | Never asked separately | Uses the account already on your device. Signed out is fine — the app stays local |
Deleting things
There is no account to close, because there was never one to open. Your journal is on your device and in your own iCloud, so deleting it is something you do rather than something you ask us for.
- One meal. Open it and choose Delete. The entry, its photographs and every check-in on it go, on the device and in your iCloud. It cannot be undone.
- The copy on this device. Delete the app.
- The iCloud copy. Settings → your name → iCloud → Manage Account Storage → Plateknow. It is deliberately not removed when you delete the app, so that reinstalling brings your journal back.
- Analytics holds nothing that identifies you, but write to hello@plateknow.com with the subject "Data deletion" and the random install code is purged from the vendors.
A single in-app "delete everything" control is not in this build. It is coming; until then the steps above do the same job and leave nothing behind. We say so rather than describing the control we intend to ship, because a privacy page that describes a button you cannot find is the kind of false statement that is worse than vagueness.
None of this needs our permission or a round trip to us. There is nothing on our side to delete — your journal has never been on a server of ours.
How long anything is kept
| What | How long |
|---|---|
| Your journal | Until you delete it. It is in your possession, not ours |
| The cut-out sent for an estimate | The length of the request — held in memory, not written down, and gone when the answer comes back |
| Product analytics events | Retained by the vendors in aggregate. They carry no content and nothing that identifies you |
| Waitlist rows on this website | Until you ask to be removed, or until the launch email is sent |
| The website’s rate-limit hashes | Two hours, then deleted. They cannot be turned back into an IP address |
| Support correspondence | While it is needed to help you |
Legal bases (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract — to deliver the features you asked for, including the estimate you requested by pressing the shutter.
- Legitimate interests — to keep the service secure and working, and to know which features are used. Balanced, in this product, against a design that carries no identifier: the estimate request has nothing in it to attribute to you, and the analytics cannot hold text.
- Consent — for anything optional, including notifications and the correction feedback you may choose to send. You can withdraw it at any time, in iOS Settings or by simply not sending it.
- Legal obligation — where the law requires us to keep or disclose something.
Your rights and choices
Depending on where you live you may have the right to access, correct, delete, port or restrict the processing of your personal information, and to object to certain processing or withdraw consent. In this app the first four are things you do yourself and do not need to ask for: your data is on your device and in your own iCloud account, in your possession, and the app can remove it.
EEA and UK residents. You may exercise the rights above and lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA). You may request access to or deletion of your personal information, and you are entitled not to receive discriminatory treatment for exercising your rights. We do not sell or share personal information as those terms are defined by California law.
To exercise any right, write to hello@plateknow.com. We may need to verify your identity before responding — although in almost every case the honest answer is that we do not hold the data, you do, and we will show you where it is.
International transfers
We may process and store information in countries other than your own: the estimate service, the analytics vendors and this website’s hosting all operate across borders. Where personal data is transferred internationally we rely on appropriate safeguards, such as Standard Contractual Clauses. What crosses a border at all is limited to what this page describes — and the journal itself, which is the sensitive part, is in your own iCloud and is never transferred by us.
Security
Everything in transit is encrypted. On the device, the journal and its images are written with iOS data protection, so they are unreadable while the phone has not been unlocked since it was switched on. The estimate service is signed and rate-limited, and the AI provider’s credentials exist only on our server and never on your phone.
No method of transmission or storage is completely secure. The strongest thing we can honestly say is structural rather than reassuring: most of what would be worth stealing is not somewhere we could lose it from, because it was never sent to us.
Children
Plateknow is not directed to children under 13, or the minimum age of digital consent in your country if that is higher, and we do not knowingly collect anything from a child. If you believe a child has used the app and something needs removing, write to hello@plateknow.com — although in almost every case the answer is that the data is on that child’s device and in their iCloud, and deleting the app and the iCloud data removes it.
A word beyond the legal minimum: this is an app about food and about how your body feels afterwards, and that is not a combination we would put in front of a child even where the law allows it.
Not medical advice, and not a diagnosis
Plateknow shows you what you ate next to how you said you felt. It does not diagnose anything, it does not identify intolerances or allergies, and a pattern it points out is a coincidence in your own records until a professional says otherwise. Calorie and macro figures are estimates from a photograph and carry real error. Do not make decisions about medication, a medical condition, or the treatment of an eating disorder on the basis of anything this app shows you.
This website
Separately from the app: this site loads nothing from anyone else unless you accept the analytics banner, which is described three paragraphs below and is the only exception on this page. No third-party fonts, no advertising, no embedded video, no social widgets, no trackers. Every file comes from this domain, and the build fails if an external request appears in the markup — a check that runs on every deployment. The site never sets an advertising cookie. Before you answer the banner it stores nothing in your browser at all; once you answer, one entry remembers which way you answered so you are not asked again.
If you join the waitlist, the form sends what you typed to a server on this same domain, which stores your email address, your note if you left one, the market and language you were reading in, which page you signed up from, the referring page if your browser sent one, the two-letter country code the network provides, your browser’s user-agent string and the platform we read out of it — iOS, Android or desktop — and the time. The platform is there for one reason: the app ships on iOS first and Android after, and the split in this list is what decides how long "after" is. It is the only field here that changes what gets built. Your IP address is not stored — to stop one person submitting the form a thousand times, the server keeps a salted, truncated hash of your IP and browser string that cannot be turned back into an address, and deletes those rows after two hours.
We use it to tell you when the app reaches your App Store, and to read the notes, because they decide what gets built. That is the complete list. Your address is not sold, not rented, and not added to a newsletter. One company other than Cloudflare does see it, and it is named in the next paragraph. To be removed, write to hello@plateknow.com and it is deleted — no confirmation loop, no "are you sure".
The list is mirrored into a Google Sheet, and Google is the only third party that ever sees a signup. Cloudflare's D1 database is where the list actually lives, and it is written first; a copy of each row — exactly the fields listed above, and never an IP address — is then forwarded from our server to a Google Apps Script we control, which writes it into a private spreadsheet only we can open. Your browser never contacts Google. This page still loads nothing from any other origin, and the build fails if it ever does; the copying happens server to server, after you have already been told the signup worked. Google processes that copy under its own terms as our processor. Ask to be removed and the row is deleted from both.
There is one analytics tool on this site, Google Analytics 4, and it does not run unless you press Accept on the banner. Until you do, nothing is loaded from Google, nothing is stored in your browser, and no request leaves this domain — Google Consent Mode is initialised here with analytics and advertising storage all set to denied, which is not Google’s own default. Decline, or simply ignore the banner, and this site behaves exactly as it did before analytics existed. IP anonymisation is on. Separately from all of this, Cloudflare counts requests at its edge for operational reasons, which happens for any site behind it and involves no script on the page.
If you accept, this is the whole of what GA4 records: which pages you opened and which language you were reading; how far down each page you got — the quarter marks, and which sections came into view; pressing a “join the first limited test” button; following the link out to the App Store; pressing the download link in the small panel in the corner; following a link to another article here; and a signup the server accepted. The reason for measuring reach is worth saying plainly, because it is close to the only thing this site is for: nothing is sold on this page, and the single question we are trying to answer is which of these arguments people actually read before they leave.
The note you leave on the form is never sent to Google. It goes to our own server, as described further up this page. What GA4 receives instead is one label from a fixed list — android, accuracy, price, macros, eating out, when does it launch, and a dozen more — chosen on your own device by matching your note against that list, together with whether the note was short or long. Your words are not in it, and nothing in it is specific to you. The list is not a secret: it is written out in full in this site’s source, in a file called analytics.js. We do it this way because we want to know how many people are asking for Android without Google holding a copy of what any of them wrote.
Changes to this page
The date at the top is the last change. Anything that changes what leaves your device will be described here before the build that does it reaches the App Store, not after.
Contact
Privacy questions, data requests, anything about your own information, and everything else: hello@plateknow.com. It reaches AI Joy Apps, and a person answers it.
If you are in the EEA or the UK and need a postal address for a formal request, ask at hello@plateknow.com and we will provide one.