Food Health AI Subscription — Privacy Addendum
This addendum covers data handling specific to the Food Health AI Premium subscription. It supplements but does not replace our main Privacy Policy, which remains authoritative for general data practices in the Food Health AI app.
What We Collect for Subscription Management
- Subscription state from Apple: We receive App Store Server Notifications when your subscription status changes. These include trial/subscribed/expired status, renewal dates, original transaction ID, and introductory offer flag.
- Apple appAccountToken: A UUID derived from your device identifier (Apple's identifierForVendor) that lets us bind your Apple subscription to your anonymous in-app identity. This token contains no personal information and cannot be reversed to identify you.
- Anonymous device UUID: Used to look up your subscription state on our server. No real-name identity is collected.
- Server-issued Anthropic API key: When you are an active subscriber or in your free trial, our server issues a short-lived API key that the app uses to call Anthropic's Claude API directly. This key is stored securely in your device's Keychain and never leaves your device once issued.
What We Do NOT Collect for Subscription Management
- Payment information: All billing is handled by Apple. Food Health AI never sees your payment method, card number, billing address, or App Store account email.
- Real-name identifiers: Subscription is tied to an anonymous device UUID, not to your real-name Apple ID.
Bring Your Own Key (BYOK) — Privacy Implications
If you configure your own Anthropic API key, your key is stored exclusively in your device's Keychain. We never receive your API key. When BYOK is active, your photos are sent directly from your device to Anthropic, bypassing our infrastructure entirely — we never see those photos and we do not record AI usage in BYOK mode.
BYOK and the Premium subscription are independent. The choice between subscribing and configuring BYOK is presented during onboarding. After onboarding, users may add, replace, or remove a BYOK key at any time from the app's Settings.
Configuring a BYOK key does not cancel an active Premium subscription. The subscription is a separate Apple billing relationship that continues until canceled via Apple's subscription management. While BYOK is in place, the subscription remains active and renews on schedule, but the server-issued key is unused (the app prefers BYOK at scan time).
Removing a BYOK key while a Premium subscription is active falls back to the server-issued key seamlessly. No additional data is collected as a result of switching.
Apple Server Notifications
Apple sends our server notifications when your subscription status changes (purchased, renewed, expired, refunded, family-sharing revoked). These notifications contain only the subscription metadata required to grant or revoke your access. They do not contain payment information or personal identifiers.
Data Retention for Subscription Records
- Active subscription state is stored on our server for as long as the subscription is active.
- Historical records (transaction IDs, anonymized state changes) are retained up to 7 years for tax and audit purposes per applicable financial regulations.
Your Rights
To request deletion of your subscription record, email support@eidogen-sertanty.com.
Note: subscription cancellation itself is handled in Settings → Apple ID → Subscriptions; deleting our server record does not cancel your Apple subscription.
Third Parties Relevant to Subscription Processing
- Apple Inc. — handles all billing, subscription lifecycle, and App Store Server Notifications. See Apple's privacy policy.
- Anthropic, Inc. — receives your photos when you make a Claude API call (subscription mode uses our server-issued key; BYOK mode uses your key). See Anthropic's privacy policy.
- Google Cloud Platform (GCP) — hosts our subscription verification server. Data minimization: we send Apple-signed JWS payloads to GCP for verification only.
Children's Privacy
Food Health AI is not directed at children under 13. We do not knowingly collect personal information from children. This is consistent with our main Privacy Policy.
Changes to This Addendum
We may update this addendum from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the subscription after changes constitutes acceptance of the revised addendum.
Contact
For privacy questions related to your subscription, contact us at support@eidogen-sertanty.com.