Legal
Privacy Policy
Last updated August 15, 2026.
diet.chat is at the waitlist stage. Today this site collects one thing: the details you type into the early access form. This policy describes both that, and how your food log and meal photos will be handled once accounts open — so you can decide now rather than after you've logged six months of your eating.
What we collect today
- Your email address, which is the only required field.
- The optional answers you give — what brought you here, what you're working on or how you'd rather log, what you use today, which AI assistant you use, and anything you write in the free-text box.
- Basic attribution: the page you signed up from, the referring URL, and any campaign parameters in the link you followed.
We do not use advertising trackers, and we do not set cookies to follow you around.
Page analytics
We use Tinylytics to count page views, so we know which pages are worth writing more of. It's a deliberately small, privacy-focused tool, and what it sends is limited to:
- the URL and path of the page you're on;
- the referring URL, if you arrived from another site.
It sets no cookies, assigns you no identifier, and does not follow you
across sites. Adding ?analytics=off to any URL on this site
stops it loading in your browser entirely; ?analytics=on
reverses that.
This matters more here than on a normal marketing site. Which page someone read is ordinarily dull information, and on a site with a page about binge eating it is not. Nothing we collect identifies who read which page.
What we use it for
- Emailing you about early access, and about the product before it opens.
- Understanding which parts of this are worth building first. The free-text answers are read by a person — that is the entire reason the box exists.
- Knowing which landing pages bring people here, so we write more of what helps.
We do not sell your details, and we do not share them with advertisers.
Your food log, once accounts open
When accounts open you'll be able to record meals, photos, notes, hunger and fullness, weight, and whatever context you choose to attach. That data is yours. Specifically:
- It belongs to you, and a full export — including your photos — is available on every plan, including the free one.
- It is not sold, and it is not shared with advertisers or data brokers, in aggregate or otherwise.
- It is not used to train machine learning models, ours or anyone else's.
- You can delete individual entries, or your entire account and everything in it, without asking us.
Photos of meals
Photos are stored as a record of a meal and nothing else. We do not run body or face analysis on them, we do not derive a calorie or macro estimate from them and present it as a fact, and we do not use them to train anything.
Photographs of your food can incidentally contain other things — a kitchen, a room, other people. Bear that in mind when you take them, and note that photos are included in exports and in account deletion, so what you remove is genuinely removed.
Health-adjacent data
A food log is more sensitive than most app data and we treat it that way. Entries about symptoms, weight, appetite, medication timing, a diagnosed condition or an eating disorder are health information about you in ordinary language, even where they may not meet a legal definition of health data in your jurisdiction.
- Access is restricted to what's required to operate the service.
- It is never used for advertising, profiling or scoring of any kind.
- It is not shared with an employer, an insurer, a clinician or anyone else unless you choose to share or export it yourself.
What the AI features send
When you use the chat, the message you write is sent to a third-party model provider to produce a reply, along with the specific context that message needs — for example the entries in the window you asked about. It is not an upload of your whole history with every message.
- Providers are used under terms that do not permit training on your content.
- Answers about your own data are produced by running tools against your record; the counting happens here, not at the provider.
- Photos are sent only when you attach one to a message, or when a feature you've asked for requires it.
- If you never use the chat, nothing you log is sent to a model provider at all.
Connected assistants (MCP)
Connecting an assistant creates a scoped token for that client. It can call the tools you allowed, and each call is recorded in an audit log you can read. What that client's provider does with the conversation is governed by their terms, not ours — which is a good reason to grant write-only access where that's all you need.
Revoking a token stops that client immediately.
Where it lives and who can see it
The site and its database run on servers we control in the EU, with encrypted backups. Access is limited to the operator of this service, and used for support and maintenance only. Sub-processors are limited to the hosting provider, the email provider used for account mail, the analytics tool described above, and the model provider behind the chat features.
How long we keep it
Waitlist entries are kept until launch and for a reasonable period afterwards, then deleted. Once accounts exist, your log is kept for as long as your account does. Deleting your account removes your entries and your photos from live systems promptly and from backups within 30 days.
Your rights
You can ask for a copy of what we hold, correction of anything wrong, or deletion of all of it, and we'll do it without asking why. Unsubscribing from waitlist email is one click and takes effect immediately. If you're in the UK or EU, the GDPR rights of access, rectification, erasure, portability and objection apply, and you may complain to your local supervisory authority.
Changes
If this policy changes materially before launch, everyone on the waitlist gets an email about it rather than a quietly updated date at the top of a page.
Contact
Privacy questions, requests and complaints: privacy@diet.chat.