Privacy Policy
Last updated October 3, 2026
The short version
ARGoals keeps what it needs to show you your own history across your devices, and no more. There is no advertising, no third-party analytics, and nothing is sold or shared. You can delete everything from inside the app.
Who we are
ARGoals is made by AR Web & Development LLC (“we”, “us”), a New Jersey limited liability company. For anything in this policy, including a deletion request, write to [email protected].
What we store
- Your account.Email address and a password, stored only as a hash. If you use Sign in with Apple we receive your name and an email address, which may be one of Apple’s private relay addresses.
- What you log. Meals, foods and their nutrition, recipes, saved meals, water, fasting sessions, weight and measurements, and the times you recorded them.
- Photos you take — food photos for AI analysis and any progress photos you add.
- Profile details you enter — age, height, weight and the goals you set for yourself.
- AI usage counters — how many AI calls your account has made this month and what they cost us, so one runaway client cannot exhaust the budget for everyone. The content of the messages is not stored on our servers.
- Feedback you send us from inside the app, and our replies to it.
What stays on your device
Your full log is kept locally so the app works offline, and your AI coach conversation history lives on the device rather than on our servers. Authentication credentials are stored using protections provided by the device operating system.
What we never collect
No advertising identifiers. No location tracking. No third-party analytics, attribution or tracking SDKs. No behavioural profiling. We do not sell or share personal information.
Who else is involved
- OpenAI — food photo analysis. The photo is sent for an estimate and is not retained by them.
- Google (Gemini) — the AI nutrition coach, reached through our own proxy so that your device never holds a provider key.
- Apple— push notifications, delivered through Apple’s Push Notification service. That relay is not end-to-end encrypted, so we keep notification text to the minimum needed to be useful.
- USDA FoodData Central and Open Food Facts — nutrition and barcode lookups. No personal information is sent to either.
Your account data is stored on servers we operate ourselves in the United States, and is not passed to any other company for storage.
Deleting your account
More → Settings → Delete Account, inside the app. It asks for your password and there is no grace period.
Deleting removes your login, profile, food logs and their entries, saved meals, recipes, water and fasting records, progress photos, AI usage counters, and any feedback you sent us.
One thing outlives the account, deliberately.Barcodes you scanned and submitted to the shared food database stay, with your name removed from them. They are facts about a product rather than about you, and other people’s lookups depend on them. The same applies to custom foods you created that others are using.
Backups, honestly
Our servers are backed up in encrypted form every night so that a failed disk does not destroy your history. A deleted account can therefore still exist inside those backups for up to 30 days, after which every backup that contained it has been destroyed.
We do not use backups to bring deleted accounts back. If we ever have to restore from one, deleting the accounts that were deleted before it is part of that restore. Nobody looks inside a backup in the ordinary course of business.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal information, and to object to how it is used — including under the CCPA if you are in California and the GDPR if you are in the EU or UK. Deletion is available to everyone from inside the app without asking us. For anything else, write to [email protected] and we will respond within 30 days.
Children
ARGoals is intended for users 17 and older and is not directed at children. We do not knowingly collect their information.
Security
All traffic between the app and our servers uses HTTPS. Passwords are hashed and never stored in a form anyone can read, including us. Provider API keys live only on our servers and never reach your device, so a lost or stolen phone cannot spend against them. We apply industry-standard protections against unauthorised access and review them as the app changes.
No system is perfectly secure. ARGoals is built to hold as little as the features allow, so that there is less to lose.
Changes
If we change this policy we will update the date above, and for anything that materially affects what we collect or how long we keep it, we will say so in the app.