Privacy Policy
Last updated
This policy explains what the cran app and this website do with your data. It describes what cran does today. We update this page when that changes.
The short version
- cran never asks for your name, email, phone number or a password. Your account is tied to your App Store purchase of cran, not to who you are.
- Your journal stays on your phone: plate names, foods, calories, macros, notes, plans, targets and your profile answers. So does your Apple Health data.
- Photos of your plates are uploaded so cran can estimate what’s on them. A resized copy is sent to an AI model to read it.
- We don’t sell your data, share it for advertising or use it to train AI models.
- You can delete your account in the app at any time.
Who is responsible
cran is made by Mohamed Hatem, an individual based in Egypt, who is responsible for your data (the “data controller”).
- Privacy questions and requests: info@getcran.app
- The responsible person: mhatem@getcran.app
“We” and “us” in this policy mean cran.
Who cran is for
cran is for adults aged 18 or older. cran suggests calorie targets, including calorie deficits, which aren’t suitable for minors. We don’t knowingly collect data from anyone under 18. If you believe a minor uses cran, write to info@getcran.app and we’ll delete the account.
What stays on your phone
These never leave your phone and are never sent to us or anyone else:
- Your journal: plate names, ingredients, calories and macros, notes, collections, plans, targets, settings and insights.
- Your profile answers from setup: name, goal, weight, height, age, sex, pregnancy or breastfeeding, sleep and energy.
- Apple Health data. With your permission, cran reads sleep, steps, water and weight from Apple Health, and writes the calories and macros of logged plates, water, weight and sleep to it. None of it is sent to us or to any third party. Health data is used only to show it in your journal, and never for advertising. You can disconnect Health, or change its permissions per type, in the app or in the iPhone’s Settings.
What the app sends to us
The app talks to our server at api.getcran.app.
Your account
When you first open cran, the app proves to our server that it’s a genuine copy of cran (using Apple’s App Attest) and sends Apple’s signed record of your App Store purchase of cran. From these we create your account. We store:
- the App Store purchase identifier (Apple’s “appTransactionId”): Apple’s identifier for your App Store account’s purchase of cran. It’s the same on all your devices, which is how cran recognizes you without a sign-in;
- whether cran was installed from the App Store or TestFlight, and when the account was created;
- for each phone, technical identifiers that let the app sign in securely. Never your name or contact details.
Photos
Each photo you take or pick for a plate is uploaded to our storage (Cloudflare R2) so the estimate can read it.
- Photos of plates you don’t log are deleted automatically after a few days.
- Photos of plates you log are kept until you delete your account, so the app can show them with older plates.
- For each photo we keep its storage key, size, a fingerprint (SHA-256), a random plate identifier and the time. Not what’s on the plate, and no names or numbers.
Logged plates
For each logged plate the server keeps a random plate identifier, the time it was logged and the photo details above. It does not get the plate’s name, foods, numbers or notes.
Estimates, searches and recipes
- Estimates: the app tells the server which photos to read. The server returns the foods and nutrition estimates, which are then kept on your phone.
- Search: what you type into food search or Inspire search is sent to our server to search our food catalog. We don’t store it, but it can appear in our request logs (see “Logs”).
- Recipe lookups: the name of a dish that cran’s own estimate produced, to find a recipe for it.
- Taste hints (off by default; a switch in Settings): food tags drawn from your journal, used to tailor suggestions. Never plate names.
On every request
The app version and the phone’s time zone.
Who else receives data
We use a small number of service providers to run cran. Each receives only what it needs, and none may use it for its own advertising. Their own policies govern how long they keep it; follow the links for details.
| Provider | What it receives | Why |
|---|---|---|
| Apple | App Attest, App Store and StoreKit records; Apple Health and iCloud stay with Apple | Distributing the app, proving it’s genuine, purchases, Health |
| Cloudflare | Everything the app sends to our server, including photos | Hosting our server, storage (R2), this website, and AI models (Workers AI) |
| OpenRouter, and the AI providers it routes to, which may not store or train on it | A copy of each photo, resized to 768 pixels | Reading the photo with an AI vision model |
| Brave Search | Dish names (text only) produced by our estimate | Finding recipes for dishes our catalog lacks |
How the AI providers are used:
- Photo estimates. Every request to OpenRouter carries its “no data collection” setting, which routes it only to AI providers that don’t store or train on it.
- Fallback. If OpenRouter is unavailable, Cloudflare Workers AI reads the resized photo instead.
- Food names. The names of foods (text, never photos) go to Cloudflare Workers AI to match them to our food catalog and search it.
We don’t sell your data, share it for advertising or use it to train AI models.
Logs
Our server keeps request logs (Cloudflare Workers Logs) for a few days: the path requested, the result, the time, the app version and the country, plus, on estimate requests, your account identifier and timings. Never the contents of photos.
Calls to Cloudflare Workers AI (the fallback photo model and food-name matching) pass through Cloudflare AI Gateway. We’ve configured Cloudflare AI Gateway not to log these requests.
The website
getcran.app sets no cookies, runs no analytics and loads nothing from other companies. We keep no request logs for the website. Cloudflare, which hosts it, processes each request (including your IP address) to deliver and protect the site, under its privacy policy.
How long we keep data
| Data | Kept |
|---|---|
| Photos of plates you don’t log | A few days |
| Photos of logged plates, and plate records | Until you delete your account |
| Request logs | A few days |
| Your account | Until you delete it; then removed immediately |
Deleting your account
You can delete your account in the app, on the Account screen. When you do, immediately:
- your photos are deleted from our storage;
- every record of your account on our server is permanently deleted, including the link to your App Store purchase;
- you’re signed out on every device.
Deleting the app alone doesn’t delete your account. Deleting your account doesn’t touch your journal on your phone or your Apple Health data; delete the app, or the data in Health, to remove those.
Your rights
Depending on the law where you live, you can ask us to:
- tell you what data we hold about you and give you a copy;
- correct it;
- delete it;
- stop or limit a use of it, or object to it.
Write to info@getcran.app. To find your account, include the code shown after “Signed in” on cran’s Account screen.
Depending on where you live, these rights come from laws such as the UK GDPR, Australia’s Privacy Act, Canada’s PIPEDA and US state privacy laws. If you’re unhappy with our answer, you can complain to your local data protection authority.
Legal bases (UK). We use your data to provide the service you asked for (the contract with you), and for our legitimate interests in keeping cran secure and working, such as logs and App Attest.
Where data is processed
Our providers run servers in many countries, including the United States. Your data may be processed outside your country, with the protections their policies and contracts provide.
Security
Data travels over encrypted connections. Each phone proves it’s running a genuine copy of cran.
Changes
If we change this policy, we update this page and its date.