Privacy Policy
Effective July 28, 2026
Summary
fiveplate is a personal health analytics platform built around meal logging and a social feed. We collect the minimum data needed to give you AI macro analysis, a personal diary, and a social feed. We don't sell your data. You can delete your account and all associated data from inside the app at any time.
Information we collect
- Account info: email, username, display name, password hash, and (optionally) avatar, bio, city, and dietary preferences.
- Sign-in providers: if you sign in with Apple or Google we receive a verified email and a provider user ID. We do not receive your password.
- Meal data: photos you upload, AI-generated macros (calories, protein, carbs, fat), meal names, captions, and timestamps.
- Health data you choose to upload: if you use the blood-panel feature, we receive the lab report file (photo or PDF) you upload and the individual markers parsed from it — for example LDL, HbA1c, or haemoglobin — along with the date of the sample and the lab's name. Blood panels are private to your account and are never shown on the feed or to other users.
- Body metrics you enter: height, weight, age, sex, activity level and goals, if you fill them in to get macro targets.
- Hydration: water you log, and your daily water goal.
- Approximate and precise location, only when you tag a place: when you attach a restaurant or place to a meal, we use your device location to find nearby places and we store the coordinates of the place you pick alongside that meal. Location is requested only in that flow, you can decline it, and you can log meals without a place.
- Social activity: likes, comments, saves, follows, competition memberships and scores.
- Safety data: if you report content or block an account, we store the report, the reason you chose, any note you write, and a copy of the reported content so our team can review it. Reports are not shown to the person you reported.
- Device & technical: IP address (for rate-limiting and fraud prevention), device platform (iOS/Android/web), and basic request logs. If you opt into push notifications, we store a device push token.
We do not collect your contacts or your browsing history outside fiveplate. We do not use any of the above for advertising, and we never sell it.
Apple Health and Health Connect
If you connect Apple Health (iOS) or Health Connect (Android), fiveplate reads four things: active energy burned, basal energy burned, step count, and body weight. We use them on your device to show your energy balance — what you ate measured against what you burned.
This data never leaves your device. It is not uploaded to our servers, not sent to our AI provider, and not shared with anyone. It is not used for advertising, and it is never shared with data brokers or sold. Connecting is entirely optional and every screen in the app works without it — you can revoke access at any time in Apple Health or Health Connect, and fiveplate stops reading it immediately.
How we use it
- To run your account and the core product (logging meals, showing your diary, surfacing the feed).
- To send your meal photos to our AI provider (Google Gemini) to estimate macros. Photos are sent over TLS and are not used by Google to train models.
- To send any blood-panel file you upload to the same AI provider (Google Gemini) so it can be read into individual markers, and to show you how those markers trend over time. Lab files are sent over TLS and are not used to train models.
- To send you in-app and (with consent) push notifications about likes, comments, follows, and competitions.
- To review reports, act on violations of our Terms, and keep blocked accounts apart.
- To investigate abuse, prevent spam, and enforce our Terms.
- To produce anonymous, aggregated product metrics.
Sharing
We share data with a small set of processors who operate under contract:
- Cloudflare R2 — meal photo and avatar storage.
- Google Gemini API — image analysis for macros, and parsing of blood-panel files you upload.
- Google Places — restaurant and place search, when you tag a place on a meal.
- Database / cache providers — managed Postgres and Redis for our application data.
- Apple Push / Firebase Cloud Messaging — delivery of push notifications, if enabled.
We do not sell personal data. We do not share data with advertisers. We may disclose data when required by law or to protect our users.
What other users see
Your username, display name, avatar, bio, city, meals you post, any place you tag on a meal, and your competition activity are visible to other fiveplate users.
Private to you: your email, password, push token, macro goals, body metrics, any blood panel you upload and the markers parsed from it, anything read from Apple Health or Health Connect, and any report you file.
Reporting, blocking, and moderation
Every plate, comment and profile in fiveplate can be reported from the ••• menu next to it, and any account can be blocked from the same menu. Blocking is mutual: neither of you will see the other's plates, comments or profile, and any follow between you is removed. You can see and undo your blocks in Settings → Blocked accounts.
We review reports within 24 hours and remove content that breaches our Terms, which prohibit harassment, hate speech, nudity, graphic violence, spam, impersonation, and content promoting self-harm or disordered eating. Repeat violations lose the account. To reach a human about a moderation decision, email support@fiveplate.com.
Retention
We keep your account data until you delete your account. When you tap Delete account in Settings, we permanently remove your user record, meals, photos, blood panels and their markers, body metrics, likes, comments, follows, competition entries, blocks, and notifications. Cached copies on edge CDNs roll off within 30 days. Backups containing your data are overwritten on a rolling 30-day cycle. You can also delete an individual blood panel at any time from the Body tab without deleting your account.
Your rights
- Access & export: email support@fiveplate.com and we'll send you a copy of your data.
- Correction: edit your profile from Settings.
- Deletion: Settings → Manage account → Delete account.
- Withdraw consent: disable push notifications in your device settings at any time.
If you are in the EEA/UK, you have rights under the GDPR including the right to lodge a complaint with your local supervisory authority. If you are in California, you have rights under the CCPA/CPRA. To exercise any of these rights, email support@fiveplate.com.
Children
fiveplate is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect data from children. If you believe a child has created an account, email support@fiveplate.com and we will remove it.
Security
Passwords are hashed with bcrypt. Traffic is encrypted with TLS. Access tokens are short-lived and rotated. No system is perfectly secure — please use a unique password and notify us if you suspect your account has been compromised.
Changes
We'll update the effective date above when this policy changes. Material changes will be announced in-app before they take effect.
Contact
Questions or requests: support@fiveplate.com
See also: Terms of Service · Support