Privacy Policy

Last Updated: August 13, 2026

SelfOS ("we", "our", or "the app") is built local-first: your planner and health content lives on your device, and the app works without an account. This policy explains — specifically and completely — what data stays on your device, what leaves it and why, and the choices you have. It applies to the SelfOS mobile application on the Apple App Store and Google Play.

1. Data That Stays on Your Device

Everything you create in SelfOS is stored locally on your device and is never uploaded to us:

The app keeps a small number of automatic local backups on your device so your data survives accidents — they never leave the device and you can delete them at any time (Profile → Restore Backup → Delete All Backups, or Delete All Data). Exports and shareable backups are created only when you request them, and are saved to your device storage (or wherever you choose to share them). We have no access to your backups. There is no account and no cloud copy of this content on our side: if you delete the app without a backup, this data is gone. Note that, like any app, SelfOS's local data may be included in your device's own system backup (iCloud on iOS, Google backup on Android) if you have it enabled — those backups are created, encrypted and managed by Apple or Google under your OS settings, and we have no access to them.

2. Data That Leaves Your Device

A small, defined set of technical data is processed by service providers so the app can function and improve. None of it includes the content you create.

What Service Details
Anonymous usage analytics Google Firebase Analytics Which features are used (for example "a task was created" or "water was logged"), device model, OS version, app version, language and approximate country. Events never include the text or values you enter. We do not collect advertising identifiers, ads personalization is disabled, and raw analytics data is retained for 2 months. You can turn analytics off any time in Profile → Privacy.
Crash reports Firebase Crashlytics Technical crash information (stack trace, device state at the moment of a crash) used only to find and fix bugs. Covered by the same in-app Privacy toggle.
Purchases RevenueCat, Apple App Store, Google Play An anonymous app identifier and your purchase/subscription state, used to unlock Premium and restore purchases. Payments are processed entirely by Apple or Google — we never see your payment details.
Food search Supabase (our search function), fatsecret Platform API, Open Food Facts When you search the food database or scan a barcode, the search text or barcode number is sent to return matching foods. Barcode scanning itself happens on your device: camera frames are processed locally and are never stored or transmitted — only the recognized barcode number is sent to look up the product. Requests are made under an anonymous session; no personal data or health data is attached to them. See fatsecret's privacy policy at fatsecret.com; Open Food Facts is a public database.
Gallery & promo images Unsplash, Cloudinary When you browse the background gallery or view promo banners, the images are loaded from these image services — a standard web request that, like any download, exposes your IP address to the host. No other data is sent.

App permissions and what they are for

SelfOS asks for a permission only when you use the feature that needs it, and uses each one for exactly one purpose:

3. Legal Bases for Processing (GDPR)

Where the EU/UK GDPR applies, we rely on the following legal bases:

ProcessingLegal basis
Anonymous usage analytics and crash reportsLegitimate interest in improving and stabilizing the app (Art. 6(1)(f)) — with an always-available in-app opt-out
Purchase and subscription statePerformance of a contract (Art. 6(1)(b))
Food database searchPerformance of a contract — returning the results you requested (Art. 6(1)(b))

We do not perform profiling and make no automated decisions that produce legal or similarly significant effects (Art. 22).

4. Health Data — Special Category

Your health entries (nutrition, sleep, workouts, weight and body parameters) are special category data under GDPR Art. 9. In SelfOS they are processed exclusively on your device: they are never transmitted to our servers, never included in analytics, and never used for advertising, marketing or data mining of any kind. This is an architectural guarantee, not just a promise — the app has no code path that uploads this data.

5. What We Never Do

6. Data Retention & Deletion

7. Your Rights

Depending on where you live (including under the EU/UK GDPR), you have the right to access, correct, delete, restrict or object to the processing of your personal data, the right to data portability, and the right to lodge a complaint with your supervisory authority. Because SelfOS stores your content on your device, most of these rights are literally in your hands — the export feature gives you your full data, and deletion is one uninstall away. For anything server-side, email us and we will help.

Opting out (right to object). Analytics and crash reporting run on the legitimate-interest basis, and you can object at any time, with prospective effect, using the toggle in Profile → Privacy — no request, no explanation, no dark patterns. Turning the toggle off stops collection immediately.

California residents. We do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information for purposes requiring a limitation right.

8. International Transfers

Our service providers (Google, RevenueCat, Supabase) may process the technical data described above on servers in the United States and the European Union, under safeguards such as Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

9. Security

Your content is protected by your device's own security (passcode, encryption, OS sandboxing) — the strongest protection available, since your content never leaves the device. For the technical data described above, our service providers apply industry-standard safeguards (encryption in transit, access controls). No method of storage or transmission is 100% secure, and we cannot guarantee absolute security — please keep your device protected and your backups safe.

10. Third-Party Links

The app and this site link to third-party resources (for example, fatsecret). This policy covers only SelfOS; third-party sites have their own privacy policies.

11. Children's Privacy

SelfOS is intended for users aged 13 and older. We do not knowingly collect data from children under 13. If you believe a child has provided us data, please contact us.

12. Changes to This Policy

If we change what data is processed (for example, when optional accounts and sync are introduced in the future), we will update this policy before the change ships and note the new date above. Material changes will also be announced in the app.

In Simple Terms

Your data, your device, your privacy.

Questions about privacy?

selfos.contact@gmail.com

Powered by fatsecret Platform API