Privacy Policy — Omni

Effective Date: September 28, 2026 | Last updated: September 28, 2026

Executive Summary

Omni is a 100% advertisement-free and third-party analytics-free health and nutrition tracking application. We do not contain Google AdMob, Firebase Analytics, or any behavioral tracking SDK. The vast majority of your data never leaves your device; the only exception is your profile, which is synchronised through your own private iCloud account so it follows you to a new device (see Section 2.7). Where external processing is required (AI features, weather, subscriptions, barcode lookups), we use the minimum data necessary and rely only on the small set of providers named in this policy: Apple, Google, RevenueCat and Open Food Facts.

1. Data Controller

The data controller responsible for your personal data is:

Enes Beyaz
Email: support@beyazlabs.com

If you are located in the European Economic Area (EEA) and have questions about how your personal data is processed, please contact the Service Provider at the address above.

2. What Data We Collect and Why

2.1 Data You Provide Directly

The following information is stored locally on your device via Apple SwiftData and, for your profile only, in your own private iCloud account (see Section 2.7). It is never uploaded to the Service Provider's servers:

2.2 Apple HealthKit

With your explicit permission, the Application reads the following HealthKit data types:

With your permission, the Application also writes to HealthKit: the meals, drinks, water and nutrients you log, and — if you use cycle tracking — the period days, symptoms, ovulation test results and pregnancy or breastfeeding status you enter in the Application, so they stay consistent with your other health apps.

Cycle data stays on your device. Your period dates, symptoms and cycle history are never sent to the AI or to anyone else. If you turn on Share phase with AI in cycle settings (off by default), only the name of your current phase (for example, "luteal") is included in AI requests so that suggestions can adapt to it.

HealthKit data is governed by strict rules:

2.3 Camera and Image Data

The Application uses your device camera and, if you choose, your photo library for:

Images are transmitted to the Google Gemini API solely for real-time analysis. Your photographs are never stored on the Service Provider's servers. They are discarded immediately after analysis is complete.

Barcodes: When you scan a barcode, only the barcode number is sent to the Open Food Facts public database to look up the product's nutrition label. No image, account identifier or personal data is sent with it. Open Food Facts data is available under the Open Database License: world.openfoodfacts.org/terms-of-use

Text you type: When you describe a meal in words, answer a question the Application asks you, or list ingredients for a recipe, that text is sent to the Google Gemini API for real-time analysis under the same rules as images.

2.4 Location Data (Apple WeatherKit)

The Application accesses your device's approximate location to:

Regionally appropriate recipe suggestions are based on your device's time zone and region setting, not on your location. Your location is never sent to the AI.

Location data is processed momentarily via Apple's WeatherKit framework. Coordinates are never logged, stored historically, or shared with third parties for advertising. You may restrict location access at any time in your device settings.

2.5 Subscription Data (RevenueCat)

Premium subscription validation is managed through RevenueCat. RevenueCat receives a pseudonymous account identifier (the anonymous identifier from Sign in with Apple — never your name or email) and your App Store transaction and subscription status, in order to verify your entitlement across your devices. The Service Provider does not have access to your payment card or billing details.

RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

2.6 Technical Data

Lock Screen and Dynamic Island (Live Activity): If enabled, your daily water progress can be displayed on your Lock Screen and in the Dynamic Island. This information is rendered on your device only and is never transmitted anywhere. Because a Lock Screen is visible without unlocking your device, anyone with physical access to your phone could see this figure; you can turn the feature off at any time in app settings, or dismiss the activity directly from the Lock Screen.

2.7 iCloud Sync (Profile Only)

To spare you from re-entering everything when you get a new device or reinstall the Application, your profile is synchronised through Apple's iCloud Key-Value Store. The following items are covered:

The following are deliberately not synchronised, because they are specific to a single device or day: your meal and supplement intake logs, streaks, notification timing state and your profile photo. Your water and nutrition history already travels with you through Apple Health.

Health information is never stored in iCloud. Your height, weight, weight targets, food allergies, medical conditions and pregnancy or breastfeeding status stay on your device (and in Apple Health, where you have chosen to save them). On a new device, the Application asks for them again during setup, so the AI safety rules that protect you apply from the first recipe.

This data is stored in your own iCloud account under Apple's encryption. The Service Provider has no access to it, it is not sent to our servers, and it is never used for advertising or analytics. You can turn it off at any time in iOS Settings → [your name] → iCloud, and deleting your account inside the Application also erases the iCloud copy.

3. Artificial Intelligence and Google Gemini API

The Application uses the Google Gemini API to power:

Data transmitted to Gemini:

Transmitted data falls into two distinct categories, which are governed by different rules:

(a) Safety data — always included when you request an AI feature.
Your food allergies, diagnosed medical conditions, and special conditions (pregnancy or breastfeeding) are included in every food-related AI request — recipe generation, meal photo analysis, and meal suggestions — regardless of whether you have enabled AI health personalization. This is a deliberate safety decision: an AI that does not know your allergy could suggest a dish that harms you. Withholding this data would make the feature unsafe rather than more private. If you do not wish this data to be transmitted, do not enter it in your profile, or avoid using the AI recipe and scanning features.

(b) Personalization data — only with your explicit AI health consent.
Derived wellness signals (heart-rate variability trend, sleep duration, activity level), aggregated behavioural patterns learned on-device (for example, typical logging times), and weekly aggregate nutrition totals are transmitted only when you have enabled AI health personalization. These improve suggestion quality; they are not required for safety.

In addition, the following context may be transmitted when relevant to your request: age range, weight range, health goal type, dietary preference, local weather context (temperature and humidity) used to calculate dynamic hydration goals, your country or region (derived from your device's time zone and region setting) so that suggestions fit your cuisine, the text you type, food or supplement images, and — only if you turned on Share phase with AI — the name of your current cycle phase. This list is illustrative and not exhaustive; in all cases the data is de-identified and never accompanied by your name, email address, or account identifier.

Critical safeguards:

This processing is governed by Google's Privacy Policy and the Google Gemini API Terms of Service:
https://ai.google.dev/gemini-api/terms

GDPR — Automated Decision-Making and Profiling (Article 22):
The Application uses automated processing of your data to generate personalized recommendations (recipes, hydration goals, coaching tips). This constitutes profiling under GDPR. These recommendations are informational and do not produce legal effects or significantly affect you in a similarly serious manner. You have the right to object to this profiling at any time by disabling the AI Master Toggle.

EU AI Act Compliance:
The AI features in this Application are classified as low-risk under the EU AI Act. All AI outputs are clearly presented as informational suggestions and do not replace professional medical or nutritional advice.

4. Advertising

The Application does not contain any advertising. There are no third-party advertising SDKs (including Google AdMob), no behavioral tracking pixels, and no advertising identifiers collected. Neither free nor premium users are shown advertisements.

5. Third-Party Analytics

The Application does not use any third-party behavioral analytics SDKs (including Firebase Analytics, Flurry, Mixpanel, or similar services). In-app data visualizations (charts, trends) are computed locally on your device using Apple's native frameworks.

6. Data Storage and Architecture

Data Type Where Stored
Profile, logs, recipes, streaks Your device (Apple SwiftData); profile also in your own iCloud
HealthKit metrics Apple Health app (Service Provider has no server copy)
Cycle tracking data Your device and Apple Health (never sent to the AI; see Section 2.2)
Barcode lookups Momentary — only the barcode number is sent to Open Food Facts
Weather data Momentary — not stored
Camera images (your photographs) Momentary — discarded after Gemini analysis
Subscription status RevenueCat (pseudonymous account identifier and transaction status)
Payment details Apple App Store (Service Provider never accesses these)

The Service Provider does not operate any servers that store personal user data.

7. Lawful Basis for Processing (GDPR — EEA Users)

Processing Activity Lawful Basis
Health, nutrition, and dietary data Explicit consent — Article 6(1)(a) and Article 9(2)(a)
Allergy and medical condition data sent to the AI as a safety constraint Explicit consent — Article 6(1)(a) and Article 9(2)(a), given when you enter this data after being informed that it is used to filter AI-generated food suggestions
Camera image analysis via Gemini Explicit consent — Article 6(1)(a)
Location data for WeatherKit Explicit consent — Article 6(1)(a)
Core app functionality Performance of a contract — Article 6(1)(b)
Subscription and payment records Legal obligation — Article 6(1)(c)

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal does not prevent you from continuing to use the Application's core features.

8. International Data Transfers

Google LLC (Gemini API, Firebase App Check and Remote Config) and RevenueCat process data on servers located in the United States. Barcode numbers are looked up in the Open Food Facts database, operated by a non-profit association based in France. Where such transfers occur from the EEA, the Service Provider relies on:

You may request a copy of applicable transfer safeguards by contacting: support@beyazlabs.com

9. Data Retention

Data Type Retention Period
Profile and health data Duration of app use + 12 months, unless you delete the app or request erasure
Notification history 90 days (local, on-device)
Camera images Zero — discarded immediately after analysis
HealthKit data Accessed in real time; no copy retained by Service Provider
Subscription and payment records 7 years (tax and accounting legal obligation)
Anonymized and aggregated data Indefinitely (contains no personal data)

Uninstalling the Application immediately and permanently deletes all locally stored data from your device.

10. Your Rights Under GDPR (EEA Users)

If you are located in the EEA, you have the following rights:

To exercise any of these rights, contact: support@beyazlabs.com

The Service Provider will respond within 30 days. This period may be extended by two further months where necessary. You also have the right to lodge a complaint with your national data protection supervisory authority. A directory of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

11. Your Rights — General (All Users)

Regardless of your location, you may at any time:

Contact: support@beyazlabs.com

12. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

The Service Provider does not sell or share personal information with third parties for cross-context behavioral advertising.

To exercise your CCPA/CPRA rights, contact: support@beyazlabs.com

13. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, you will also be notified directly without undue delay, as required by GDPR Article 34.

14. Children's Privacy

The Application is not directed to children under the age of 16. The Service Provider does not knowingly collect personal information from children under 16. If the Service Provider becomes aware that a child under 16 has provided personal information, that information will be deleted promptly. If you are a parent or legal guardian and believe your child has provided personal information to the Application, please contact: support@beyazlabs.com

15. Security

The Service Provider implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. All data transmitted to external services (Gemini API, Firebase, RevenueCat, WeatherKit, Open Food Facts) is encrypted in transit using industry-standard TLS. Locally stored data is protected by Apple's iOS Data Protection framework.

16. Changes to This Privacy Policy

The Service Provider may update this Privacy Policy from time to time. For material changes, you will be notified via an in-app notification and the updated policy will be posted with a new effective date. Where required by applicable law (including GDPR), your consent will be sought before material changes take effect. Previous versions are available upon request at: support@beyazlabs.com

17. Contact

Enes Beyaz
Email: support@beyazlabs.com

For complaints that cannot be resolved directly, EEA users may contact their national data protection supervisory authority:
https://edpb.europa.eu/about-edpb/about-edpb/members_en