Home › Privacy & Terms
Document
Privacy & terms.
Radish is designed to collect as little data as possible. Here is, plainly, what is processed and by whom.
Privacy Policy: last updated 03/10/2026. Terms of Use: last updated June 2026.
Contents
What this document covers
- P1Your food log, profile, weight
- P2Health connection (optional)
- P3Purchases and subscriptions
- P4AI feature (optional)
- P5Barcode scanning
- P6Usage statistics (optional)
- P6bGoogle Firebase audience measurement (depends on your country)
- P6cnutri-track.fr website audience measurement (depends on your country)
- P7What we don't do
- P8Your rights
- T0Terms of Use (1 to 8)
Privacy Policy
Your food log, profile, weight, and goals
This data is never sent to our servers, except in two cases that you trigger yourself and that are described below: the AI feature (the meal text or photo you choose to have analysed) and barcode scanning (the product code). Outside those two cases, we never receive your diary and never pass it to anyone. If you uninstall the app, everything is deleted. A plain-language summary of the same rules is here: what a calorie tracker with no account keeps on your phone.
Health connection (Apple Health / Google Health Connect) — optional
If you enable the health connection, Radish only reads your daily step count from Apple Health (iOS) or Google Health Connect (Android), in read-only mode. Radish never writes data to Apple Health or Health Connect, and never shares this information with any third party — including us: it is never sent to our servers, like the rest of your diary, and it is used neither by the AI feature nor by barcode scanning. You can revoke this permission at any time in your phone's health settings.
Purchases and subscriptions
Subscription management is handled by our processor RevenueCat, which receives an anonymous identifier and your purchase history (needed to activate your paid features). No email, no name, and no data from your food log is shared with it.
AI feature (optional)
Radish offers two ways to use AI to estimate a complex meal. Neither is enabled by default.
- Hosted Premium AI: the text of your meal — or the photo you choose to have analyzed, and nothing else from your log — is sent to our server function (hosted by Netlify, Inc., United States), which immediately relays it to Anthropic (United States), the provider of the AI model used, after your explicit consent given on a dedicated screen. Our server function does not retain the text or photo: it forwards it and erases it from memory right after the request. This content is deleted by Anthropic within 30 days maximum, except where required by law or to detect misuse of its service. This transfer outside the European Union is governed by the European Commission's Standard Contractual Clauses. To enforce your monthly call quota, a counter — your anonymous subscription identifier linked to the current month, nothing else — is also kept by our host Netlify, Inc. (United States), under the same transfer safeguards described in the "Usage statistics" section below.
- Pro AI (your own API key): your meal text is sent directly from your device to the third-party provider you choose. It never passes through a Radish server. Your API key is stored only on your device.
Barcode scanning
Barcode scanning: the code of the scanned product is sent to the open Open Food Facts database, made available under the Open Database License (ODbL), to retrieve its nutritional information. No other data from your profile is associated with it.
Usage statistics (optional) — added 26/08/2026
Purpose: measuring where people drop off between opening the app and a purchase, so we can fix what is blocking them. Legal basis: your consent (GDPR art. 6.1.a) — a screen asks you explicitly, with two equally-weighted buttons, no pre-ticked box; the default is NO. What is sent, only if you accept: usage counters — which screens are seen, how long the first entry takes, which features are used — never a food, never a weight, never a calorie, never a photo, never your profile. A random technical identifier is created when you consent, to link these counters together over time; this is not anonymous data in the strict sense (it is pseudonymisation), but it is never linked to your identity, to an account (Radish has none), or to an advertising identifier. Processor: these counters are stored with our host Netlify, Inc. (United States — functions hosted in Ohio by default), our processor, and no other third party. This transfer outside the European Union is governed by Netlify's certification under the EU-U.S. Data Privacy Framework, with the European Commission's Standard Contractual Clauses as a fallback mechanism. Retention: a rolling 90 days. Withdrawal: any time in Settings > Data & privacy — the identifier is then destroyed immediately, not put to sleep. Your access and erasure rights: since Radish has no account, show the technical code displayed in Settings > Data & privacy in your request to bonjour@nutri-track.fr, so we can identify and erase what concerns you.
Google Firebase audience measurement (depends on your country) — added 27/08/2026, corrected 30/08/2026
Purpose: measuring overall app usage (screens seen, features used, crashes) to improve it, via Google Firebase Analytics, provided by Google. What changes depending on where you are: if you are in the European Union (or Switzerland, the United Kingdom, Norway, Iceland, or Liechtenstein), this measurement only starts after your explicit agreement, given on the same screen as the usage statistics described above — until you accept, nothing is sent to Google. Legal basis in that case: your consent (GDPR art. 6.1.a). Everywhere else in the world, this measurement starts automatically as soon as you install the app, with no prior consent screen. Legal basis invoked in that case: our legitimate interest in understanding how the app is used, to improve it (GDPR art. 6.1.f) — a qualification we stand behind but which remains a business judgment, not a guarantee against challenge. In both cases, you can turn this measurement off at any time in Settings > Data & privacy; it stops immediately, though this obviously cannot undo what was already sent before you did so. What is sent, once the measurement is active (per the above): technical usage counters — the events Firebase automatically collects as soon as an app uses this service (app opened, session started, screen displayed, session length, version update; technically named first_open, session_start, screen_view, user_engagement, app_update) — as well as device model, app version, and a technical identifier generated by Google to link these counters together. What is never sent: any advertising identifier (IDFA on iOS, Google advertising ID on Android) — collection of this identifier and advertising personalization ("Google signals") are disabled in our configuration — and any food, weight, calorie, photo, or profile data. Processor: Google Ireland Limited / Google LLC (United States), which receives and processes these counters. This transfer outside the European Union is governed by Google's certification under the EU-U.S. Data Privacy Framework, with the European Commission's Standard Contractual Clauses as a fallback mechanism. Retention: verified on 29/08/2026 in our Firebase configuration (GA4 property #551812482) — 2 months for event data (what happens in the app: screens seen, sessions, etc.) and 14 months for user- and device-level data; this 14-month counter resets on each new user activity for as long as the measurement stays active. Your rights: see "Your rights" below; a request specifically about Google's data can also be sent directly to Google.
Android install source (added 16/09/2026): if you installed the app from the Google Play Store, your device receives the campaign labels that brought you there (source, medium, campaign — not an advertising identifier, not your name, not your email). In the European Union (and the equivalent countries listed above), these three items stay on your device only until you give your consent on the consent screen; they are only sent to Google Analytics after your explicit consent. Legal basis: your consent (GDPR art. 6.1.a). If you decline, these three items are deleted from your phone, not just set aside. Everywhere else in the world, as with the rest of the Firebase measurement described above, this transmission may happen automatically upon installation.
nutri-track.fr website audience measurement (depends on your country) — added 31/08/2026
The following is about the website you're reading right now (nutri-track.fr), not the app described in the sections above. Purpose: measuring website traffic (pages visited, clicks on App Store / Google Play buttons) to know which pages actually drive downloads, via Google Analytics 4, provided by Google. What changes depending on where you are: if you are in the European Union (or Switzerland, the United Kingdom, Norway, Iceland, or Liechtenstein), this measurement only starts after your explicit agreement, given via the banner shown at the bottom of the screen — until you click "Accept," nothing is sent to Google. Legal basis in that case: your consent (GDPR art. 6.1.a). Everywhere else in the world, this measurement starts automatically when the page loads, with no prior banner. Legal basis invoked in that case: our legitimate interest in understanding which pages of the site work (GDPR art. 6.1.f) — a qualification we stand behind but which remains a business judgment, not a guarantee against challenge. In both cases, you can withdraw your consent by clearing this site's browsing data in your browser. What is sent, once the measurement is active: the page visited, and a technical event when you click a download button (App Store or Google Play, and from which page). IP anonymization is enabled, and Google advertising signals and ad personalization are disabled in our configuration. What is never sent: any advertising identifier, and no data about your use of the app (journal, weight, calories, photos) — this website has no access to that anyway. Processor: Google Ireland Limited / Google LLC (United States). This transfer outside the European Union is governed by Google's certification under the EU-U.S. Data Privacy Framework, with the European Commission's Standard Contractual Clauses as a fallback mechanism. Retention: Google Analytics 4's default, 14 months for user- and device-linked data. Your rights: see "Your rights" below; a request specifically about Google's data can also be sent directly to Google. This measurement is separate from the app's Firebase audience measurement (section P6b): two tools, two separate consents, neither ever triggers the other.
Cookie-free click counter — added 18/09/2026. nutri-track.fr uses an anonymous click counter (page visited, store chosen, day) to measure traffic, with no cookie, no identifier and no stored IP address. This measurement does not require your consent (CNIL recommendation on exempted audience-measurement tools). What is counted: a click on a download button (App Store, Google Play or the "Download" page), with the page it came from and the day — never the time. What is never recorded: your IP address, your browser, the page you came from, and no identifier of any kind; nothing is stored on your device. These totals are processed on our servers (Netlify), shared with no one, and erased after 13 months.
What we don't do
No advertising identifier (IDFA/Google advertising ID) or cross-app tracker actively collected: neither our own usage statistics nor the Firebase and Google Analytics audience measurements above collect them. Your data is never shared with third-party ad networks or sold to data brokers. No advertising, no advertising identifier and no ad personalization.
Your rights — corrected 02/09/2026
Under the GDPR, you have the right to access, correct, and erase your data. Your locally stored data (see the exceptions described above: AI, barcode scanning and audience measurement) is never sent to our servers (except AI or barcode scanning, if you use them), so uninstalling the app is enough to erase it. For the optional usage statistics described above, see the dedicated section. For any question or to exercise your rights, write to us at bonjour@nutri-track.fr. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL (www.cnil.fr) — if you believe your data isn't processed in accordance with the GDPR.
Terms of Use
The eight articles
Last updated: June 2026.
-
1
Acceptance
By using Radish, you accept these terms. If you disagree, do not use the app.
-
2
Service provided "as is"
Radish is usable free of charge; some advanced features (including Premium AI) are offered via an optional subscription. The service is provided "as is", with no warranty of being error-free or continuously available.
-
3
Not medical advice
Radish is for informational and educational purposes. Calculations (calories, macros) and nutrition data are estimates and may be inaccurate. The app does not replace advice from a doctor, dietitian, or health professional. Consult a professional before any major dietary change, or in case of illness, pregnancy, or medical treatment.
-
4
Data accuracy
Food and recipe values come from open databases and user input; we do not guarantee their accuracy. Verify important information against the product packaging.
-
5
AI feature & costs
If you use the AI coach with your own key, usage costs are your responsibility and governed by your agreement with the AI provider.
-
6
Liability
To the extent permitted by law, we disclaim liability for direct or indirect damages arising from use of the app, including data loss (remember to export backups regularly).
-
7
Intellectual property
The Radish name, logo, design, and code are protected. Third-party nutrition data remains the property of its respective sources.
Part of the nutrition values comes from the ANSES Ciqual table. Source: ANSES, Ciqual 2025 table, updated 19/11/2025 (DOI 10.57745/RDMHWY), reused under the Licence Ouverte / Open Licence Etalab 2.0. ANSES does not endorse Radish and is in no way associated with this app. Other values come from USDA FoodData Central (public domain, CC0).
-
8
Contact
Questions or reports: bonjour@nutri-track.fr.
Where the numbers come from: Data sources.About Radish