Privacy Policy
Effective date: 15 August 2026
Iron Fork (the app) is developed by Mohamed Nassar, an individual developer based in Germany.
The short version
- Your data lives on your device. There are no accounts and no cloud database.
- Meal photos and descriptions leave your device only when you ask for AI analysis, and only to produce your result. A barcode scan sends only its barcode to Open Food Facts.
- We do not sell data, show ads, or track you across apps. The app collects anonymous, content-free usage statistics, which you can switch off in Settings.
- Delete the app and your data is gone, except backups you exported yourself.
What the app stores on your device
- Meals you log: names, nutrition values, ingredient breakdowns, portion notes, text descriptions, and any photos you attach.
- Weight entries and your goal weight.
- Settings: daily calorie and macro targets, unit and theme preferences, and the optional profile used to calculate targets on your device, including age, gender, height, and activity level.
All of this is stored locally on your device. Backups are JSON files you create and control yourself; they include your meals, weights, and settings, but not photos.
What leaves your device, and when
No meal, photo, nutrition, weight, or other health content is sent anywhere automatically. When you actively request an AI feature, the app sends the minimum needed for that request to our server, which forwards it to OpenAI and returns the result:
- Meal analysis: your meal photo(s) and/or description. The server also reads a country-level signal from your network connection, per request only, to help interpret ambiguous dishes and preparation defaults; it never uses location permission, derives nothing more precise, or stores the signal.
- Recent-meal nutrient update: when you confirm the one-time action in Settings, ingredient names, quantities, and calories from up to 50 recent meals are checked against USDA FoodData Central. Stored photos are sent only to re-check verified label or barcode rows. Existing meal totals are not replaced, and the server does not retain this content.
- Optimize: the analyzed meal being optimized.
- Coach suggestions: today's intake and targets, recent meals, your weight and goal context, and any nutrient you select for a meal idea. The server also infers your country, at country level only, from your network connection to suggest locally available, in-season foods. No location permission is used, nothing more precise than country is derived, and it is read per request and never stored.
Requests are not tied to an account or identity because the app has no user accounts.
If you choose to share nutrition with Apple Health, Iron Fork writes your logged meal's calorie, protein, carbohydrate, fat, and fiber totals directly from your device to your personal Health data. Iron Fork does not read from Apple Health, send meal content to Apple's servers, or write unavailable nutrients as zero. Deleting or editing a meal also removes or replaces the corresponding nutrition samples.
If you choose to sync weight with Apple Health, Iron Fork reads your body-mass samples and writes your logged weigh-ins directly between your device and your personal Health data. Weight samples stay on your device and are never sent to Iron Fork's servers or analytics. You can turn this off at any time in Settings.
When you scan a packaged-food barcode, the app sends that barcode to Open Food Facts to retrieve the product label. It does not send a photo, meal description, account identifier, or other user identifier. Retrieved product labels are cached on your device for repeat scans.
Anonymous usage analytics and diagnostics
The app sends anonymous usage events and a small sample of operational request traces to PostHog, hosted in the EU, unless you turn this off in Settings → “Share anonymous usage statistics”. Events describe which features are used; traces contain only timing, status buckets, app/platform version, and fixed flow/provider labels so failures can be diagnosed.
The app also sends crash diagnostics, device metadata, and Firebase installation identifiers to Google Firebase Crashlytics so we can diagnose failures. Firebase Analytics is enabled only for Crashlytics's automatic breadcrumbs and crash-free metrics; Iron Fork sends no custom Firebase Analytics events. Crash reports and breadcrumbs never include meal text, photos, ingredients, nutrition or body values, AI payloads, credentials, or other user content.
- Events and traces never contain meal names, descriptions, photos, ingredients, nutrition values, body weight, barcodes, prompts, responses, credentials, or anything you type. Trace spans also exclude IP or network-address attributes and stable identifiers.
- Trace identifiers are random for one request journey and are not reused as a user identifier.
- There are no accounts: events carry a random anonymous identifier that is not linked to your identity, and analytics is never used for advertising or cross-app tracking.
- Turning the toggle off stops analytics and trace export immediately.
Third parties we rely on
- OpenAI processes AI requests. API inputs and outputs are not used to train OpenAI models by default; its abuse-monitoring logs may retain content briefly. See OpenAI’s API data controls.
- Cloudflare runs the server that relays AI requests. The server processes requests in memory and does not store your meal content. Cloudflare’s network provides the country-level signal used for Coach suggestions and meal analysis; our server reads it per request and does not store it. Cloudflare may process limited request metadata for routing, security, and rate limiting under its Privacy Policy.
- PostHog receives the anonymous, content-free usage events and sampled operational traces described above, unless you have turned analytics off.
- Google Firebase Crashlytics and Analytics receive the limited diagnostics and automatic crash breadcrumbs described above. Firebase Analytics is not used as a product-analytics pipeline.
- Open Food Facts receives a scanned product barcode to return its public product-label data. Read requests use an app-identifying User-Agent, not a user identifier.
- USDA FoodData Central receives ingredient search terms for deterministic nutrition matching during meal analysis and a user-requested recent-meal nutrient update. It receives no account identifier or meal photo.
- Apple Health receives the optional logged meal totals and weigh-ins, and supplies optional body-mass samples for weight sync. This is a direct on-device exchange with your personal Health data, not a transfer to Iron Fork's servers.
What we do not do
- No accounts, advertising, analytics that identify you, or sale of personal data.
- No location permission, contacts access, or cross-app tracking.
Retention and deletion
- On-device data stays until you delete individual entries, clear data, or uninstall the app.
- Our server keeps none of your meal content after a request completes.
- Anonymous usage events and sampled operational traces, if enabled, are held by PostHog in the EU; they contain no meal or body content and traces use no stable user identifier.
- Crash diagnostics and automatic breadcrumbs are retained by Google Firebase under its applicable retention settings; they contain no user meal or body content.
- Backup files you exported are under your control; delete them like any file.
Your rights under the GDPR
Because your data is stored on your device, you exercise most rights—access, correction, deletion, and portability—directly in the app. For anything else, contact info@ironfork.app. You also have the right to lodge a complaint with a data-protection supervisory authority.
Health disclaimer
Nutrition values and recommendations are AI-generated estimates for general guidance. They are not medical, dietary, or training advice. Do not rely on them for medical decisions, and consult a professional for conditions such as pregnancy, eating-disorder history, or medically supervised diets.
Changes
We will update this policy when the app’s data practices change and revise the effective date above. Material changes will be noted in the app’s release notes.
This policy applies to the Iron Fork mobile app. Need help? Visit Support.