Iron Fork

Privacy Policy

Effective date: 15 August 2026

Iron Fork (the app) is developed by Mohamed Nassar, an individual developer based in Germany.

The short version

What the app stores on your device

All of this is stored locally on your device. Backups are JSON files you create and control yourself; they include your meals, weights, and settings, but not photos.

What leaves your device, and when

No meal, photo, nutrition, weight, or other health content is sent anywhere automatically. When you actively request an AI feature, the app sends the minimum needed for that request to our server, which forwards it to OpenAI and returns the result:

Requests are not tied to an account or identity because the app has no user accounts.

If you choose to share nutrition with Apple Health, Iron Fork writes your logged meal's calorie, protein, carbohydrate, fat, and fiber totals directly from your device to your personal Health data. Iron Fork does not read from Apple Health, send meal content to Apple's servers, or write unavailable nutrients as zero. Deleting or editing a meal also removes or replaces the corresponding nutrition samples.

If you choose to sync weight with Apple Health, Iron Fork reads your body-mass samples and writes your logged weigh-ins directly between your device and your personal Health data. Weight samples stay on your device and are never sent to Iron Fork's servers or analytics. You can turn this off at any time in Settings.

When you scan a packaged-food barcode, the app sends that barcode to Open Food Facts to retrieve the product label. It does not send a photo, meal description, account identifier, or other user identifier. Retrieved product labels are cached on your device for repeat scans.

Anonymous usage analytics and diagnostics

The app sends anonymous usage events and a small sample of operational request traces to PostHog, hosted in the EU, unless you turn this off in Settings → “Share anonymous usage statistics”. Events describe which features are used; traces contain only timing, status buckets, app/platform version, and fixed flow/provider labels so failures can be diagnosed.

The app also sends crash diagnostics, device metadata, and Firebase installation identifiers to Google Firebase Crashlytics so we can diagnose failures. Firebase Analytics is enabled only for Crashlytics's automatic breadcrumbs and crash-free metrics; Iron Fork sends no custom Firebase Analytics events. Crash reports and breadcrumbs never include meal text, photos, ingredients, nutrition or body values, AI payloads, credentials, or other user content.

Third parties we rely on

What we do not do

Retention and deletion

Your rights under the GDPR

Because your data is stored on your device, you exercise most rights—access, correction, deletion, and portability—directly in the app. For anything else, contact info@ironfork.app. You also have the right to lodge a complaint with a data-protection supervisory authority.

Health disclaimer

Nutrition values and recommendations are AI-generated estimates for general guidance. They are not medical, dietary, or training advice. Do not rely on them for medical decisions, and consult a professional for conditions such as pregnancy, eating-disorder history, or medically supervised diets.

Changes

We will update this policy when the app’s data practices change and revise the effective date above. Material changes will be noted in the app’s release notes.

This policy applies to the Iron Fork mobile app. Need help? Visit Support.