Privacy Policy

Last updated: 2026-05-08

The short version: BurnLedger has no servers. We do not collect, store, transmit, or sell any of your data. Everything you log lives only on your device. The only outbound network calls the app makes are: (1) to whichever AI provider you choose — OpenAI, Anthropic (Claude), or Google (Gemini) — using an API key you provide yourself, and (2) to Open Food Facts when you scan a barcode (only the UPC is sent). Apple's on-device AI option runs entirely on your iPhone and never sends data anywhere.

1. Who we are

BurnLedger (the "App") is a single-developer iOS application. The developer is the only party operating it. There is no backend service, account system, or analytics infrastructure associated with the App.

2. What we collect

Nothing. The App does not collect or transmit any personal data, usage data, crash reports, or analytics. There is no server you connect to, no account to create, and no identifier we assign to you.

All data you enter into the App — profile information, food logs, water entries, exercise logs, weight history, custom targets, settings — is stored locally on your device using iOS's encrypted AsyncStorage and Keychain APIs. None of it leaves your device unless you explicitly trigger an AI feature (see Section 3) or use the Export feature (which saves a file you then share or save wherever you choose).

3. Third-party AI providers (OpenAI, Anthropic, Google)

The App offers optional features powered by your choice of AI provider — OpenAI, Anthropic (Claude), or Google (Gemini): photo-based food logging, voice transcription of food descriptions (OpenAI and Gemini only), and daily/weekly recap summaries. These features only work if you provide your own API key for that provider in the AI Configuration section of the App.

If you do not provide an API key for any provider, no data ever leaves your device through any AI feature.

4. Barcode scanning (Open Food Facts)

When you tap Scan on the Food tab and point the camera at a product barcode, the App sends the scanned UPC/EAN number to Open Food Facts, a free open-data nutrition database operated by a non-profit. The response (product name, brand, serving size, macros) is used to pre-fill the food entry on this device.

5. Permissions the App requests

6. iOS Live Activities and Widgets

The App uses iOS Live Activities (lock-screen + Dynamic Island) and home-screen widgets to display your tracked data. These read from a shared on-device App Group container and do not communicate with any server.

7. Children

The App is not directed to children under 13 and does not knowingly collect data from anyone (since it doesn't collect data from anyone, period). If you are a parent or guardian and have concerns, please contact us.

8. Data retention and deletion

Because all data lives on your device, you control retention entirely. The App's Profile screen contains an Erase All Data button that wipes every entry, setting, cached value, and stored API key. Uninstalling the App also deletes all associated data per iOS's standard behavior.

9. Security

Local storage uses iOS's standard data-protection class. Your AI provider API keys are each stored in iOS Keychain. All outbound network requests — to the selected AI provider (OpenAI, Anthropic, or Google) and to Open Food Facts for barcode lookups — use TLS.

10. Apple's collection

When you download or update the App through the App Store or TestFlight, Apple may collect installation and crash-report data per Apple's standard policies. BurnLedger does not have access to that data beyond aggregated, anonymized App Store Connect metrics that Apple provides to all developers.

11. Pricing and in-app purchases

BurnLedger is sold as a one-time purchase through the App Store. There are no subscriptions, recurring fees, in-app purchases, advertisements, or paid upgrade tiers within the App. The price you pay at purchase is the total cost of using the App. The only ongoing cost you might incur is API usage from your chosen AI provider (OpenAI, Anthropic, or Google) — and that's billed by the provider directly to your own account, only if you choose to enable AI features.

12. Changes to this policy

If the App's data behavior ever changes (for example, if a future version adds a backend), we will update this policy and notify users via an in-app prompt before the new behavior takes effect.

13. Contact

Questions or concerns: hend0472@gmail.com