Privacy Policy
← Back to FuelkitLast updated: July 11, 2026
This policy explains what information Fuelkit ("we," "us") collects, how we use it, and the choices you have. Fuelkit is a personal nutrition- and weight-tracking app. By using it, you agree to this policy and to our Terms of Service.
The short version: your data belongs to you, is kept private to your own account, is never sold, and you can export or permanently delete all of it at any time from inside the app.
Information we collect
We only collect what's needed to run the app for you:
- Google account info — when you sign in with Google, we receive your email address, name, and profile picture. We request only basic profile scopes; we do not access your Gmail, Drive, contacts, or other Google data.
- Information you enter — your food and nutrition log, meals and recipes, weigh-ins, active-calorie entries, daily targets, and profile details you provide (such as age, height, and sex used to estimate your energy needs).
- Photos you upload — nutrition-label photos you choose to submit.
- API keys — personal access keys you generate for connecting external tools; these are stored in hashed form.
- Basic technical data — a login session cookie and standard server logs (such as request timing) needed to keep you signed in and to operate and secure the service.
We do not collect payment information, we do not run advertising, and we do not use third-party tracking or analytics for advertising.
How we use your information
- To provide the app: store your logs, compute your macros, targets, and energy balance, and show your history.
- To authenticate you and keep your account secure.
- To look up nutrition facts you request (see "How your information is stored and shared" below).
- To operate, maintain, debug, and improve the service.
How your information is stored and shared
Your data is isolated to your own account. We do not sell, rent, or share your personal information with third parties for their own purposes. We use a small number of service providers only to run the app on our behalf:
- Cloudflare — hosting, database (D1), key-value and object storage (R2) for your data and uploaded photos.
- Google — sign-in / authentication.
- USDA FoodData Central — when you search for a food, your search term is sent to look up nutrition facts. We don't send them your identity.
We may also disclose information if required by law, or to protect the rights, safety, or security of our users or the service.
Who processes your data
FuelKit uses a small number of service providers. Each receives only what its job requires:
| Service | What they receive | Why |
|---|---|---|
| Cloudflare (hosting) | All app data — database, food photos, sessions — encrypted in transit and at rest | Infrastructure (Pages, D1, R2, including Workers AI label parsing) |
| Google Sign-In | Your Google email, name, and profile photo, at sign-in only | Authentication — nothing else is read from your Google account |
| Resend | Recipient email address + message content for transactional mail (household invites, bug-report replies) | Email delivery from [email protected] |
| USDA FoodData Central | Your food search text only | Nutrition lookup |
| Open Food Facts | Barcode numbers only | Barcode lookup |
| Kroger | Product search terms and your chosen store | Grocery price lookup |
| Your AI assistant (optional) | Whatever you ask it to read or write through your personal connection | Only if you connect Claude or ChatGPT yourself |
AI processing
FuelKit never sends your data to external AI providers. Nutrition-label photos you queue may be parsed by a vision model running on our hosting infrastructure (Cloudflare Workers AI) to pre-fill a suggestion that you confirm, edit, or dismiss — they never leave Cloudflare. If you connect your own assistant (Claude or ChatGPT), it can also read your queued photos under your control. Photos are deleted from storage once a food is created from them.
Children
FuelKit is not directed to children under 13. We do not knowingly collect personal information from children under 13. Accounts require users to be at least 13 years old. If we learn we have collected personal information from a child under 13, we will delete it promptly. Contact [email protected] if you believe a child under 13 has an account.
Your choices and rights
You are in control of your data, primarily through the app itself:
- Access / export — you can export all of your data from the app at any time (Foods → backup/export).
- Delete — you can permanently delete your account and all associated data from the app. This removes your records from our database.
- Revoke Google access — you can disconnect Fuelkit from your Google account at any time in your Google Account settings.
California residents (CCPA/CPRA): we do not sell or "share" (for cross-context behavioral advertising) your personal information. You have the right to know what we collect, to access and export it, and to request its deletion — all of which you can do directly in the app, or by contacting us. We will not discriminate against you for exercising these rights.
Cookies
We use a single essential cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
Data retention
We keep your data for as long as your account exists. When you delete your account, your data is removed from our database. Deleting your account removes your data from live systems immediately; residual infrastructure backups expire within 7 days.
Security
We take reasonable measures to protect your information — data is scoped to your own account, session and API-key secrets are stored hashed, and connections are encrypted in transit (HTTPS). No online service can be guaranteed perfectly secure, but we work to keep your data safe.
Children
Fuelkit is not directed to children and is not intended for anyone under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "Last updated" date above. Significant changes may be surfaced in the app.
Contact
Questions or privacy requests: [email protected]. For access, export, or deletion, the fastest route is the export and delete features inside the app.