Legal & Data Protection
Crumb Count handles health data, so it sits under some of the strictest privacy law there is. This page explains our regulatory position and the reasoning behind it — which rules apply, why we read them the way we do, and what we are still building.
Last updated 18 August 2026
The short version
- Everything you log here counts as health data in law — the most protected category there is.
- We ask before we collect it, and asking about AI is a separate question you can answer no to and still use the app.
- We have no advertising SDKs and no behavioural profiling, and we do not sell data to anyone. We do measure feature usage, with no personal content in the events and an off switch in Settings.
- Deleting your account erases your data from our servers, including records you could never reach yourself.
- Meal photos are sent to an AI provider for analysis and are never stored by us.
- Crumb Count is a wellness app. It is not a medical device and does not diagnose or treat anything.
Which page answers what
- Privacy Policy — what we do with your data. The formal, binding notice: what is collected, why, who processes it, how long it is kept.
- Terms of Service — the rules for using Crumb Count, and the rights and responsibilities on each side. It also carries our formal statement of what the app is for and what it will never do.
- This page — our legal and regulatory position, and why. Which laws apply to a product like this, how we read them, and where we still have work to do.
- Consumer Health Data Notice — the separate notice Washington and Nevada law require.
Why health data is different
Under the EU and UK GDPR, data about your physical health is a special category (Article 9) — processing it is prohibited by default and only permitted on a narrow set of grounds. For a consumer app like this one, the only realistic ground is your explicit consent.
That covers more than you might expect. Your weight and height are health data. So are your meal logs, your workout history, anything read from Apple Health or Health Connect, and your conversations with the AI coach. In the United States, Washington’s My Health My Data Act goes further still and treats information inferred from other data as health data — which means the calorie estimate an AI model produces from your meal photo is itself protected.
The practical consequence is that we treat the whole dataset as sensitive rather than trying to carve it into protected and unprotected halves.
India: the DPDP Act is our principal framework
Crumb Count is built in India, so India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025 are the framework we organise around. Under it we are a Data Fiduciary and you are a Data Principal, and — this is the part that matters — a fiduciary remains responsible for its processors. If Google or an AI provider mishandles your data, that is our accountability, not a problem we can point downstream at.
Its obligations phase in, with the substantive ones — notice, consent, rights, grievance redressal — binding from 13 May 2027. We are building to them now rather than waiting, because the GDPR requires much the same thing today and building once to the stricter standard is simpler than building twice.
How we read its main requirements
- Notice (s.5) is transactional, not a web page. The Act requires the notice to accompany the consent request itself, so the real DPDP notice is the consent screen in the app, shown before any health data is collected. The Privacy Policy is its published counterpart, not a substitute for it.
- Itemisation (Rule 3).Listing “health information” would not satisfy the Act. That is why the Privacy Policy names height, weight, age, sex, meal logs, workout logs, weight history and chat transcripts individually, each against its purpose.
- Consent (s.6) must be specific and unbundled. Rolling AI consent into general app consent is the standard failure, so we ask separately, pre-tick nothing, and make declining AI survivable — the offline tracker is complete without it.
- Purpose limitation (s.4 and s.5). Each category of data has one stated purpose in the Privacy Policy. Using it for something else requires updating that notice and asking you first.
- Data minimisation. The clearest test is the health integration: five permission types, each with a specific job, and nothing requested that the app does not use. Sleep, glucose, blood pressure and cycle data are all available and deliberately not requested.
- Security (s.8). Encryption in transit and at rest, per-account isolation enforced server-side, secrets held outside the app, and an automated suite that attacks our own rules before each release.
- Erasure (s.8). Deleting your account really deletes, including the server-owned records the app itself cannot touch.
- Breach reporting (s.8). DPDP has no harm threshold — unlike the GDPR, every personal data breach is notifiable. Affected users are told without delay, and the Data Protection Board gets an immediate intimation followed by a detailed report within 72 hours.
- Cross-border transfers (s.16). The Act uses a blacklist model and no restriction has been notified, so our transfers to US infrastructure are permitted from the India side. The binding constraint is the GDPR, not the DPDP Act.
Your grievance contact
Section 8 requires a named, reachable person rather than an anonymous mailbox, and section 13 requires you to raise a grievance with us before approaching the Board. Ours is Shiven Upadhyay, Software Engineer — shiven302@gmail.com, A003, Sarla Mansion, Sector 44, Noida 201301, Uttar Pradesh, India. Acknowledged within 72 hours, resolved well inside the 90-day statutory window.
Two things we are candid about. Section 14 gives you a right to nominate someone to exercise your rights if you die or become incapacitated; that route is by email today, and a proper in-app mechanism is on the list below. And the Act contemplates the notice being available in any Eighth Schedule language — that is engineering work on the consent screen, and it is not done yet.
What Crumb Count is for, and why we say it so precisely
Whether software is a regulated medical device turns on its intended purpose — and regulators assess that objectively, from what a product says about itself in its marketing, its store listing and its own screens. Private intent is irrelevant, and a disclaimer buried at the bottom does not cure a claim made at the top.
So we state the intended purpose formally, in the Terms of Service: Crumb Count records what you eat and how you move and shows it back to you as estimates against goals you set yourself. That is deliberately the same shape as the example EU guidance gives of software that is not a medical device — a health app tracking nutrition intake to help manage weight.
The Terms also list what the app will never provide: diagnosis, treatment recommendations, medication or dosing guidance, clinical decision support, disease-risk determination, therapeutic diets for diagnosed conditions, and interpretation of test results. Those are permanent product limits, not unbuilt features.
Three regimes reach the same conclusion by different routes. In the EU, guidance excludes nutrition-tracking wellness apps; crossing that line would make it Class IIa and require notified-body assessment. In the US, the FDA’s general wellness policy turns on how a product is claimed, which makes claims language decisive. In India, CDSCO excludes software solely for general wellness or fitness — but that exclusion is function-specific rather than product-specific, so a single diagnostic feature could regulate that feature alone. We keep the wellness core separable for exactly that reason.
The same discipline governs how we describe accuracy. Indian consumer law treats exaggerating a product’s accuracy or capability as a misleading advertisement, puts the burden of proving a performance claim on us, and reaches in-app copy rather than only advertisements. It also holds that a disclaimer cannot rescue an overstated claim. That is why AI output is called an estimate in the claim itself rather than hedged in small print underneath, and why the food catalogue is described as published reference values rather than as exact.
Safeguards for the things a tracker can get wrong
Calorie tracking is not neutral for everyone. Both app stores have rejected apps for encouraging restriction, and the risk is real independent of any regulator, so we treat this as a safety question first.
- Eating disorders. The AI coach is instructed to decline questions about restriction or disordered eating and to refer you to a professional rather than produce a plan, and never to moralise about food or suggest skipping meals. The goal calculator will not set a target below 1,500 kcal for men or 1,200 kcal for women, however aggressive a goal you pick — it stops there rather than following the arithmetic down.
- Pregnancy and breastfeeding.Outside the app’s models entirely — nutritional needs change in ways general-population arithmetic does not represent. The coach declines and refers you to a professional.
- Diabetes. Crumb Count is not a carbohydrate-counting aid for insulin dosing and must never be used as one. Dosing is unambiguously regulated medical-device territory, and it is a line we will not approach.
- Medication. No guidance on starting, stopping, timing or changing anything you are prescribed, and no interaction advice.
These safeguards are imperfect — automated classifiers can be talked around by determined phrasing, and we would rather say so than imply a guarantee. They are a floor, not a substitute for professional care, and the Terms of Service set out when you should not use the app at all.
What we collect, and who else sees it
Held in your account
- Your email address and account identifier
- Height, weight, age, sex, activity level, goal and diet style
- Meals, food items, quantities, calories and macros
- Workouts, routines and sessions
- Weight and activity history
- Your conversations with the AI coach and meal chat
- Technical records of AI usage — which model ran, how many tokens, and when
Read from your device, only if you allow it
Steps, active and total energy, heart rate and exercise sessions, via Apple Health or Health Connect. This is read-only, it feeds your calorie-burn figure, and you can revoke it in your operating system at any time.
The companies that process it
Privacy law requires us to name these rather than describe them generically, so:
- Google Firebase — sign-in, cloud database, and the servers that run our AI requests.
- OpenAI, Anthropic and Google — analysis of meal photos and descriptions, and the AI coach. Which provider handles a given request is set on our side and can change; all three are named here so the disclosure stays accurate either way.
These companies act as our processors: they handle the data to provide the feature, under contract, and not for their own purposes.
AI analysis, stated precisely
When you photograph or describe a meal, that content goes to one of the providers above and comes back as food items with nutrition numbers.
We never store the photo. It is held in memory, sent, and discarded — it is not written to your phone’s database, your account, or any cloud storage. Only the resulting text is kept.
The providers do retain it briefly, and we will not pretend otherwise. Under their API terms they hold request data for a short period for abuse monitoring — currently up to 30 days for OpenAI and 7 days for Anthropic. We use their paid API tiers specifically because those tiers, unlike free consumer tiers, do not train models on your data. We do not opt in to training, and we do not use your data to fine-tune anything.
Our API keys live in Google Secret Manager and never ship inside the app, so your requests always travel through our server rather than exposing a credential on your device.
Your rights
Which rights you have depends on where you live, and the response times differ. We apply whichever is most favourable to you rather than tracking you by jurisdiction.
- Access — a copy of your data and an explanation of how it is used. Settings includes a JSON export you can run yourself, instantly.
- Correction — every field is editable in the app.
- Deletion — Settings → Account → Delete Account.
- Portability — the same JSON export, in a machine-readable format.
- Withdrawing consent — Settings → Privacy has a switch for AI processing that takes effect on your next action, and you can disconnect Apple Health or Health Connect in your OS settings. Turning AI off costs you nothing else: manual logging, the food catalogue, workouts and streaks all keep working.
- Complain — to us first, and then to your data protection regulator if we have not resolved it.
Not every regime grants every right, and we would rather be accurate than generous on paper. India’s DPDP Act gives a shorter list than the GDPR: access, correction, erasure, grievance redressal and nomination, but no general right to object, no restriction right and no portability right. The Privacy Policy sets out each regime separately for that reason. In practice we apply the most favourable version to everyone.
Statutory deadlines: one month under the GDPR, 45 days under Washington’s My Health My Data Act, and 90 days under India’s DPDP Act. Write to shiven302@gmail.com.
What deletion actually does
Account deletion is often a soft switch that hides your profile. Here it is not.
When you delete your account, a server-side process erases your entire record: meals, saved days, favourites, app state, workout history, coach conversations, and the AI usage and quota counters. That last part matters — those counters are written by our servers and are deliberately not deletable by the app, so only a server-side deletion can remove them. Your sign-in account is deleted, and the app wipes its local database and secure storage on the device.
It runs when the account is deleted rather than when the app asks nicely, so it does not depend on your phone staying online to finish. Deletion is permanent and cannot be undone — export first if you want a copy.
Children
Crumb Count is an 18+ product, stated identically in the Terms of Service, the Privacy Policy and in onboarding, which asks you to confirm your age before collecting anything. Calorie tracking is generally inappropriate for children without professional supervision, and we do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we delete it.
India’s DPDP Act treats anyone under 18 as a child and bans behavioural monitoring and targeted advertising to them outright. We do neither to anyone: we run no advertising and build no behavioural profiles. Our usage measurement counts how often features are opened, and is never used to target or profile an individual. If you believe a child has created an account, contact xerosbynevish@gmail.com and we will delete it.
Not a medical device
Crumb Count is a general wellness and fitness tracking application. It is not a medical device and does not diagnose, treat, cure, mitigate, or prevent any disease or medical condition. Nutritional and calorie values, including those estimated from photographs using artificial intelligence, are estimates only and may be inaccurate. Content from the in-app AI assistant is generated automatically, is for general informational purposes, and is not a substitute for professional medical, nutritional, or dietary advice.
Always seek the advice of a qualified physician, registered dietitian, or other healthcare professional with any questions regarding a medical condition, before beginning any diet or exercise programme, and before making changes to medication or treatment. Never disregard or delay seeking professional medical advice because of something you have read in this app.
Do not use Crumb Count if you are under 18, pregnant, or have a diagnosed eating disorder, diabetes, kidney disease, or another condition requiring medically supervised nutrition, without first consulting your healthcare provider. If you are experiencing a medical emergency, contact your local emergency services immediately.
AI transparency
The coach and meal chat are powered by large language models. You are talking to software, not a person, and it can be confidently wrong — about nutrition as much as anything else. Treat its output as a starting point, not a verdict.
Under the EU AI Act, a nutrition assistant of this kind is a limited-risk system: the obligation is to tell you plainly that you are interacting with an AI, which is what this section does.
Where your data is held
Our servers and database run in the United States on Google Cloud, and our AI providers are US companies. If you are in the EU, UK or India, your data is transferred internationally to reach them.
India’s DPDP Act permits these transfers. For EU and UK users, transfers rely on the safeguards in our providers’ data processing agreements, which is the standard mechanism for a service of this kind.
Security
- Data is scoped to your account, and server-side rules prevent one account from reading another’s.
- All traffic is encrypted in transit.
- API credentials are held in a dedicated secret store and never shipped inside the app.
- Records our servers own — such as AI usage counters — cannot be altered by the app at all.
- We maintain an automated suite that attacks our own security rules and server endpoints, so a change that would expose one account’s data to another fails before it ships.
No system is perfect. If you find a security problem, please report it to xerosbynevish@gmail.com rather than disclosing it publicly, and we will work with you on it.
What we are still building
Crumb Count is pre-launch, and we would rather tell you what is not finished than imply everything is. In progress:
- A web-based deletion route, so you can delete an account without needing to install the app.
- An expanded export covering workouts and coach conversations, not just meals and settings.
- A date-of-birth field in place of the 18+ checkbox, which is better evidence of age than a confirmation tick.
- An in-app nomination mechanism for the DPDP right to appoint someone to act for you; today that request goes by email.
- The consent notice in Eighth Schedule languages, so the screen that carries the notice can be read in a language you choose.
- A representative in the EU and the UK, as a company based outside both is required to appoint, published here once named.
- Shorter, published retention clocks, with the tightest one on AI conversations.
We will update this page as each lands rather than describing them as done in advance.
Contact
Privacy, data protection, rights requests and grievances: Shiven Upadhyay, Software Engineer — shiven302@gmail.com
A003, Sarla Mansion, Sector 44, Noida 201301, Uttar Pradesh, India
Everything else: xerosbynevish@gmail.com
Crumb Count is provided by Xeros (by Nevish), a sole proprietorship established in India.
This page explains how we approach data protection law. It is not legal advice, and it does not replace the Privacy Policy, which is the binding notice, or the Terms of Service, which govern your use of the app.