Piala — Privacy Policy

Last updated: 11 October 2026

In short: your profile, food log and weight history stay on your iPhone. Only when you scan a meal — and only after you agree — the photo and your optional hint are sent through our server to Google’s Gemini AI to recognise the food. We do not store your photos. No account, no ads, no tracking.

1. Who we are

Piala is developed by Kurbanbek Kalysov, an individual developer (“we”, “us”). Contact: e-mail dr.kalysov@gmail.com or Telegram @kubaro.

2. Data that stays on your device

Your profile (goal, sex, year of birth, height, weight, activity level, pace), daily targets, food log (dishes, portions, nutrition values, a small thumbnail of scanned meals), weight history and settings are stored only on your iPhone. They are not sent to us or to anyone else.

3. Meal photo recognition (optional, with your consent)

Before your first scan the app asks for your permission. If you agree and take or choose a photo, the app sends over an encrypted connection (HTTPS):

The request goes to our server (a Cloudflare Worker operated by us on Cloudflare’s network), which forwards the photo, hint and language to the Google Gemini API (Google LLC). The AI returns which dishes it sees and estimated portions; calories and macros are then calculated in the app from its built-in database. You review and can edit everything before saving.

Please frame only your food — avoid people, documents or other personal information in the photo. You can always add meals manually without sending anything. If we change the AI provider, we will update this policy and the consent text in the app before the change.

4. Install token and fair-use limits

The app creates a random identifier when it is first used and keeps it in the iOS Keychain. It is sent with each scan only so our server can apply fair-use limits (a few scans per minute and a daily cap). The server keeps a per-day scan counter for that token for up to 48 hours. The token is not linked to your Apple ID, name or any account and is never used for advertising or tracking. iOS may keep Keychain items after the app is deleted.

5. Apple Health

If you turn it on, Piala writes the dietary energy, protein, fat and carbohydrates of meals you save to Apple Health. The app does not read any Health data. Health data is never sent to our server or to third parties, is not used for advertising and is not stored by us in iCloud. Deleting a meal in the app also removes it from Health. You can turn this off in the app’s Settings or in the Health app.

6. Camera and photos

The camera is used only when you tap “Take a photo”. Library photos are chosen with the iOS photo picker; the app receives only the photo you select.

7. Purchases

Subscriptions are sold and processed by Apple; we never receive your payment details. Apple provides us with aggregated sales reports that do not identify you.

8. What we do not do

We have no user accounts, no analytics or advertising SDKs, no tracking across apps or websites, and we do not sell or share your data for marketing.

9. Legal bases (EEA, UK and similar laws)

Photo analysis and writing to Apple Health are based on your consent, which you give in the app and can withdraw at any time by not using the feature or turning it off. The install token is processed on the basis of our legitimate interest in preventing abuse of the service. Running the app and your subscription are based on the contract with you.

10. Retention

11. Your rights and choices

You can stop sending photos at any time and log meals manually, delete all on-device data in Settings, and turn off Apple Health access. Because we do not store photos, hints or accounts, we cannot retrieve or link them to you. You may contact us with any privacy request and, where applicable, complain to your local data-protection authority.

12. Age

Piala is intended for adults aged 18 and over; the onboarding requires an age of 18+.

13. International transfers

Cloudflare and Google operate globally, so scan requests may be processed outside your country, under those providers’ safeguards.

14. Changes

If this policy changes, we will update this page and the date above, and mention material changes in the release notes.

15. Contact

e-mail dr.kalysov@gmail.com or Telegram @kubaro