Privacy Policy
CarbMate sees your dinner. That's a lot of trust, so here's exactly what happens to it β without the legal fog.
Last updated: 20 July 2026
The short version
The whole policy in six lines. The detail is underneath.
We don't sell your data
Not to advertisers, not to anyone. No ad SDKs, no trackers, no third-party analytics.
There's no sign-up
No email, no password, no name. We genuinely donβt know who you are.
Your meal photos are yours
Stored against an anonymous account only you hold the key to. Delete them whenever you like.
Photos go to OpenAI to be read
Thatβs the one place your photo travels outside our servers β and itβs how the app works at all.
Our stats can't reach your photos
Usage data uses a random install ID that is built to be unlinkable to your account.
No IP addresses, no health questions
We resolve a country code and throw the rest away. We never ask about your health.
Who we are
CarbMate is made by Pink Wolf Ltd, a company registered in England and Wales (company no. 17327279), whose registered office is at 29b Fairlight Road, London, SW17 0JE, United Kingdom.
For the purposes of UK data protection law, Pink Wolf Ltd is the data controller for the personal data described here β meaning we decide what is collected and why, and we're accountable for it.
Questions about anything on this page? contact@carbmate.app
This policy covers both our website and the CarbMate iPhone app. The two are quite different, so they get their own sections.
When you visit our website
carbmate.app is a plain marketing site. There's no login, no comment box, no
shop, and nothing to fill in.
We don't put any analytics on it. No Google Analytics, no Meta pixel, no heatmaps, no session recording. The fonts are served from our own site rather than Google's, so loading a page doesn't quietly tell anyone else you were here. We set no cookies of our own, which is why you won't see a cookie banner.
What happens anyway, because every website works this way
The site is hosted on Cloudflare Pages. To deliver a page to you and keep the site up, Cloudflare's servers briefly process your IP address, your browser type and the page you asked for, and may set a strictly necessary security cookie to tell real visitors from bots. We don't get a report from this, we can't identify you from it, and we don't combine it with anything else. It's housekeeping, not tracking β but it's real, so we'd rather say it than pretend the number is zero.
If you email us, we'll obviously have your email address and whatever you wrote. We keep support conversations for up to two years, then delete them.
When you use the CarbMate app
There's no account, and we don't know who you are
CarbMate has no sign-up. You never give us an email address, a password, a name or a phone number, and we never ask you to sign in with Apple or Google.
Instead, the first time you open the app it generates a random secret key on your device and stores it in your iPhone's Keychain. That key is the only thing that identifies your data to us. On our side it maps to an anonymous account β a random ID and nothing else. There's no name attached to it, because we never had one.
Keep your recovery code safe
The app shows you that key once as a recovery code. If you lose both your Keychain copy and your written-down code, we genuinely cannot get your history back. There's no "forgot password" link, because there's no password and no account to look you up by. That's the trade for not having to sign up.
Because that key is effectively the key to your diary, we treat it as a secret: it travels over an encrypted connection only, it's stored on our servers as a one-way hash rather than the key itself, and it never appears in our logs.
Your meal photos and notes
When an estimate succeeds, we save the photo, any note you added, and the estimated carb range to your history so you can look back at it. These are stored on our own servers in the United States, and they're only ever accessible with your key.
Photos and notes stay in your history until you delete them. Delete a meal and its photo is gone from our servers. Delete your account and everything goes at once β photos, notes, history. We don't put a timer on your data; you decide how long it lives.
Encrypted backups of our database may still contain deleted items for up to 30 days before they rotate out. That's a normal consequence of having backups at all, and after 30 days it's gone from those too.
We never look through your photos for advertising purposes, we don't sell them, we don't use them to train any AI model, and no third party gets a copy of your history.
Estimating your carbs
This is the part worth reading closely, because it's the one place your photo leaves our control.
To work out what's on your plate, CarbMate sends your photo and any note you typed to OpenAI, whose vision model does the actual recognition. The request goes through our own server rather than straight from your phone, which means OpenAI never sees your device, your IP address or your account.
OpenAI processes the photo, returns a result, and may keep a copy for up to 30 days for abuse monitoring before deleting it. Under the API terms we use, your photos are never used to train OpenAI's models.
If you'd rather a particular meal never left your phone, the answer is simply not to photograph it β the estimate can't happen locally, so there's no setting that avoids this. We'd rather be straight about that than bury it.
Usage analytics
We keep basic, anonymous usage stats β which screens get opened, whether an estimate succeeded, how long it took, and what it cost us to run.
These are tied to a random ID that belongs to your app install, not to you. It resets if you reinstall, and it's never connected to your photos, notes or history. This isn't a policy we've adopted; it's built into how our database is arranged, so an analytics record simply has no route back to anyone's meal diary.
We don't collect or store IP addresses in analytics. We do resolve your country from the connection at the moment your request arrives β just the two-letter country code, never a city, never coordinates β so we know roughly where the app is being used, and the IP itself is discarded immediately and never written down.
We never share any of this with advertisers or analytics companies, and there's no third-party analytics SDK in the app.
We delete these records after 14 months. Anonymous totals β like how many estimates ran on a given day β we keep, since they can't point back to anyone.
Subscriptions and payments
CarbMate is free for your first 10 estimates. After that, CarbMate Pro unlocks unlimited estimates.
We never see your payment details. All purchases go through Apple's App Store, which handles your card, your billing address and your receipt. We can't see any of it. Apple's handling of that is governed by Apple's privacy policy.
To know whether your subscription is real and current, we use RevenueCat, which checks the purchase with Apple and tells our server the answer. RevenueCat receives a public support ID for your account and the purchase details from Apple. It never receives your photos, your notes, your carb history, your key, or any health information β only "this anonymous ID has a valid subscription".
We keep purchase and subscription records longer than everything else, because UK tax and accounting rules require us to hold transaction records for six years.
Crash reports and diagnostics
If you've turned on "Share With App Developers" in your iPhone's Analytics settings, Apple may send us crash logs and performance data about CarbMate. Apple aggregates this and it doesn't identify you. You can turn it off any time in Settings β Privacy & Security β Analytics & Improvements. We don't run any separate crash-reporting SDK of our own.
What CarbMate deliberately doesn't do
- No health data. We never ask whether you're diabetic, what your blood sugar is, what your goals are or what you weigh. CarbMate doesn't read from or write to Apple Health, and it holds no health profile about you.
- No judgements. We don't score your meals or label them good or bad β and we don't build a profile of your eating from your history.
- No tracking across apps or websites, no advertising identifier, no ad networks, no data brokers.
- No selling or renting your data, ever, to anyone.
Where your data lives
Our servers are in the United States (Newark, New Jersey), and OpenAI processes photos in the United States too. So if you're in the UK or the EU, your data is transferred outside your country.
We chose the US because that's where OpenAI's models are β putting our server next to them is what keeps estimates fast. It's a deliberate decision, not an accident of hosting.
These transfers are covered by the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, which are the legal mechanisms that require our providers to protect your data to UK/EU standards wherever it sits.
How long we keep things
| What | How long |
|---|---|
| Meal photos, notes and history | Until you delete them, or until you delete your account |
| Your anonymous account | Until you delete it |
| Deleted items sitting in encrypted backups | Up to 30 days |
| Copies held by OpenAI for abuse monitoring | Up to 30 days |
| Usage analytics | 14 months |
| Anonymous totals (e.g. estimates per day) | Kept β they can't identify anyone |
| Purchase and subscription records | 6 years (UK tax and accounting law) |
| Support emails | Up to 2 years |
If you stop using CarbMate entirely, your history simply stays as you left it until you come back or delete it. We'd rather you found your data waiting than discovered we'd quietly binned two years of it.
Why we're allowed to do this
UK GDPR requires us to name a lawful basis for each thing we do with your data:
| What we do | Lawful basis |
|---|---|
| Run estimates, store your history, keep your account working | Contract β it's the service you asked us for (Art. 6(1)(b)) |
| Anonymous usage analytics, and keeping the service secure and affordable to run | Legitimate interests β understanding whether the app works and stopping abuse, balanced against your privacy by keeping analytics unlinkable to your content (Art. 6(1)(f)) |
| Keeping purchase records | Legal obligation β UK tax and accounting law (Art. 6(1)(c)) |
| Answering your emails | Legitimate interests β replying to someone who contacted us (Art. 6(1)(f)) |
You can object to anything we do on the basis of legitimate interests β see your rights below.
Your rights
Under UK and EU data protection law you have the right to:
- Get a copy of the personal data we hold about you.
- Correct anything that's wrong.
- Delete your data β in the app, right now, without asking us. Delete a single meal, clear your whole history, or delete your account entirely from the Account screen.
- Take your data elsewhere in a portable format.
- Restrict or object to how we use it, including anything based on legitimate interests.
- Withdraw consent where we relied on it, without affecting what came before.
A genuine limitation you should know about
Because we deliberately don't know who you are, we usually can't answer an access or deletion request by email β we've no way of matching an email address to an anonymous account, and a stranger's request to delete "an account" is something we'd be wrong to act on. This is why deletion is built into the app and available to you directly. If you need help and the in-app controls aren't enough, email us and we'll do what we can β please don't send us your recovery code.
We'll respond within one month.
If you're unhappy with how we've handled your data, please tell us first β we'd like the chance to fix it. You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 Β·
ico.org.uk/make-a-complaint
If you're in the EU, you can complain to your own national data protection authority instead.
Security
Everything travels over encrypted connections (HTTPS). Your secret key is stored on our servers only as a one-way hash, never in a form we could read or hand over. Your photos and history can't be reached without that key, and our analytics database has no route to them at all. Backups are encrypted and stored away from the main server. Our dashboards are locked down and not publicly reachable.
No system is perfectly secure, and we won't claim otherwise. What we can say is that we've kept the amount of data worth stealing deliberately small β there are no email addresses, no passwords and no payment details in our database to lose.
Age
CarbMate is for people aged 13 and over. If you live in a country where the minimum age to consent to data processing is higher β 16 in Germany, Ireland and the Netherlands, for example β you need to be that age, or have a parent or guardian agree on your behalf.
We don't knowingly collect anything from children under 13. If you believe a child has used CarbMate and saved data, email contact@carbmate.app and we'll delete it.
A note on health
CarbMate gives estimates, always as a range, and it can be wrong. It's not a medical device and it doesn't give medical advice. If you're managing diabetes or another condition, please don't use CarbMate as your only source of truth for dosing or treatment decisions β talk to your healthcare team.
We mention this here because it shapes our privacy choices too: we deliberately don't collect health information, so there's nothing sensitive about your condition sitting in our database to leak.
Changes to this policy
If we change how we handle your data, we'll update this page and change the date at the top. For anything significant, we'll tell you in the app before it takes effect rather than hoping you re-read this page.
Contact
Questions, requests, or something here that doesn't look right?
Pink Wolf Ltd
29b Fairlight Road, London, SW17 0JE, United Kingdom
Registered in England and Wales, company no. 17327279