Privacy policy
Munchy · Last updated 2 October 2026
Munchy helps you understand the nutrition label on packaged food. It works without an account, shows no ads and doesn’t track you across apps or websites. This page explains what data Munchy uses and where it goes.
What stays on your phone
- Local copies of scanned products and photos, your shelf and bin, battles, badges, savings and outfits. Online scan information is also processed as explained below.
- What you tell Munchy when you set it up: your goal, favourite workout and, if you give it, your weight. Your weight is only used to work out exercise minutes.
- Share videos are made on your phone and only leave it when you choose to share them.
Cloud reading requires an internet connection and does not require an account. On supported iPhones, local reading remains available without uploading a photo. Android needs an internet connection for new label reading; saved products remain accessible offline.
Deleting a product in Munchy deletes its local photos. It does not delete the shared product database or server scan records. Contact us with the scan identifier for a server-data request.
Your iCloud backup
On iPhone, if you’re signed in to iCloud, Munchy keeps a copy of your game (products, photos, shelf, badges, savings, outfits and your setup answers) in your own private iCloud storage, so it comes back if you reinstall Munchy or move to a new iPhone. This copy is stored by Apple in your iCloud account; Munchy’s makers can’t see it. You can turn it off in Settings › [your name] › iCloud, or delete it in Settings › [your name] › iCloud › Manage Account Storage › Munchy.
Android progress stays on this device. Munchy does not sync or back up Android progress to iCloud or a Munchy account. Uninstalling the app or clearing its storage removes local progress and saved photos; restoring a subscription does not restore your shelf.
What leaves your phone, and why
- Packaging photo analysis. Packaging photos you capture or select for scanning are sent, after you allow photo analysis, to our Firebase service and the Google Gemini API to extract nutrition, ingredients and other product details. Before the first online photo analysis, an inline explanation asks for your permission. On supported iPhones, you can choose on-device nutrition reading instead. Android reads new labels online only. When on-device label reading is used, that processing happens on your phone. Our service stores a small front-of-pack thumbnail when you attach a front photo, so other people scanning the same barcode can see the packaging. Nutrition-table and ingredient photos are processed without retaining the uploaded images. We do not include photos, extracted text or model responses in application logs. Google processes requests under its Gemini API terms.
- Barcode lookups. When you scan a barcode, the barcode number is sent to Open Food Facts and, for US products, USDA FoodData Central to find the product’s nutrition information. The app sends the barcode and a randomly generated scan identifier to Munchy’s Firebase service. Our service checks its cache and contacts these providers using the barcode; provider credentials remain on our server.
- Online scan records and shared products. Our Firebase service stores scan identifiers, barcodes, extracted nutrition and packaging details, source information, processing status and automatic reconciliation decisions. It uses these records to combine asynchronous barcode and photo results. Validated product details may be cached and reused for other people scanning the same barcode. Conflicting observations are retained for review and are not automatically used to replace shared product data. Front-of-pack thumbnails may be stored and displayed as shared product images. Raw nutrition-table and ingredient photos are not stored by Munchy. Only photograph product packaging, avoiding people or personal information.
- App analytics. Munchy uses Google Analytics for Firebase to understand app use and reliability: screens visited, onboarding progress, scan processing outcomes, use of Keep/Bin and Battle, share preparation, and subscription interactions. Google receives a randomly generated app-instance identifier, interaction timestamps and standard device/app information. The Analytics SDK derives approximate geographic information from masked IP addresses and may automatically collect store subscription events, including subscription product identifiers and prices. Munchy does not request precise device location. These operational events are also exported to our Google BigQuery project for reporting. We do not send food photos, barcodes, food product names, extracted label text, nutrition values, scan identifiers, your weight or setup answers in analytics events. Advertising identifiers and advertising personalisation are disabled; we do not set a personal user ID or use analytics for advertising. Contact us with questions or data requests.
- Munchy+ purchases. Subscriptions are handled by Apple on iPhone and Google Play on Android. Munchy uses a subscription service (RevenueCat) to check whether Munchy+ is active; it receives an anonymous app ID and your purchase history for Munchy, not your payment details.
What Munchy never does
- Sell or rent your data.
- Show ads or share data with advertisers.
- Track you across other companies’ apps or websites.
Health information
Munchy gives general nutrition information from food labels. It isn’t medical or dietary advice. Your goal and weight stay on your phone and, on iPhone, in your own iCloud backup.
Children
Munchy isn’t directed at children under 13 and doesn’t knowingly collect their personal information.
Changes
If this policy changes, the date at the top will change and the app will point to the new version.
Contact
Questions or requests: contact@doola.ai
Reporting shared packaging photos
On Android, you can report a shared product photo from its result page. Munchy stores the public image URL, your selected reason and the report time in a private Firebase moderation queue. The report form does not request your name, contact details, a new photo or personal free text. A local block keeps the reported image hidden on your device. Reports help us review and remove inappropriate or incorrect content; a report does not automatically remove an image for everyone.