The app allows tracking of:
Key Point: All health data is stored locally on your device using Core Data. We do not have access to it, and we operate no server that stores your health records. It leaves your device only through the optional features described in this policy: iCloud sync (section 3), exports you start yourself (section 6), and the food analysis features (section 5).
When you use AI-powered food analysis features, the following data may be sent to external services for processing:
Key Point: Meal analysis data is only sent when you actively use these features (camera, text search, barcode scanner, or meal ideas). Nothing is sent automatically or in the background. Your symptom history, medications, notes, and HealthKit data are never included.
Limited analytics collected:
Key Point: Analytics data excludes all health information and is anonymized before transmission.
Since data remains on-device, processing includes:
Anonymized data supports:
Device-stored using Apple's Core Data, protected by:
Encrypted in transit and at rest by Apple via CloudKit. We have no server access. Users control activation.
Important: HealthKit-sourced data is excluded from iCloud sync and remains on-device only.
Tract only requests the metrics needed by the cards you have enabled, so most people are asked for a subset of this list:
Only for entries you logged yourself in the app:
Key Point: HealthKit data is accessed only on your device via Apple's approved HealthKit APIs. We do not transmit HealthKit data to our servers.
Control: You can change or revoke permissions via iOS Settings → Privacy & Security → Health → Tract.
Tract offers optional AI-powered features to help you log meals and understand their nutritional and dietary impact. These features require an internet connection and involve sending limited data to external services.
When you photograph a meal, the image is sent to a proxy service we operate on Cloudflare Workers, which forwards it to Google's Gemini API for food identification. The image is used solely to identify foods and estimate nutrition data. Our proxy does not store the image; Google processes the request under the Google Gemini API terms.
When you type food names, the text is sent through the same proxy to estimate nutrition and dietary compliance data (e.g., FODMAP levels, SCD classification). Only the food names you enter are sent, together with the meal context described in section 1. Your name, account information, symptom history, and HealthKit data are not included.
If you ask Tract to suggest meals, it sends a list of food names drawn from the app's built-in food database, marking which ones you have saved as staples, so the suggestions use foods you actually eat. No symptom or medication data is sent.
When you scan a product barcode, the barcode number is sent to Open Food Facts, a public, open-source food product database, to retrieve product name, ingredients, and nutrition information. If Open Food Facts has no entry for the product, the barcode number is sent to UPCItemDB instead. No personal data is sent with either request. The ingredient list that comes back may then be analyzed by the text estimation described above.
To use these features, the app registers anonymously with our service. It sends the app name, bundle identifier, platform, and app version, and receives a randomly generated device identifier and an access token, stored in your device's Keychain. This identifier is not derived from you or from your device's hardware, and it is never linked to your health data. We use it only to apply fair-use limits so the service is not abused. It persists until you uninstall the app or clear its data.
Meal photos are not stored by our proxy. Results of barcode and text lookups are cached on our proxy for up to 30 days, keyed to a hash of the product's ingredient list rather than to you or your device, so that scanning the same product again does not require a new AI request. Requests forwarded to Google are handled under Google's Gemini API terms, linked above.
Key Point: Your symptom logs, medications, notes, and HealthKit data are never transmitted during meal analysis. These features are entirely optional and only activate when you explicitly use them.
Core Policy: We never sell your data, and we never share the health record you build in Tract—your symptoms, medications, appointments, and notes—with anyone. The services listed below receive only what is described against each one, and only at the moment you use the feature that sends it.
Amplitude: Receives anonymized technical data only (app events, feature usage, performance metrics)—never health data.
Cloudflare: Our proxy runs on Cloudflare Workers. Meal photos, food names, and meal-idea requests pass through it. It does not store meal photos.
Google: The proxy forwards those requests to Google's Gemini API, which performs the food identification and nutrition estimation and returns the result. Google processes them under its Gemini API terms.
Open Food Facts: Barcode numbers are sent to the Open Food Facts open-source database to retrieve product information. No personal data is included.
UPCItemDB: Used only as a fallback when Open Food Facts has no entry for a scanned barcode. It receives the barcode number and nothing else.
Occurs only when you explicitly choose to:
The app is not intended for users under 16. We do not knowingly collect information from children under 16.
Access Settings in the app and toggle "Usage Analytics" off. Your preference is saved immediately.
Tract does not include a crash reporting service. Crash and diagnostic information reaches us only if you have opted in with Apple, via iOS Settings → Privacy & Security → Analytics & Improvements, which Apple governs.
Amplitude maintains:
You maintain complete control:
We may update this policy with notifications via posting and updating the "Last Updated" date. Continued use of the app after changes constitutes acceptance of the updated policy.
Email: support@signalishealth.com
For privacy-related questions, data deletion requests, or concerns, please reach out via email.
Tract is for informational and tracking purposes only. It is not intended to diagnose, treat, cure, or prevent any disease. Always consult with qualified healthcare professionals regarding your health condition and treatment.