Today With
Color theme

Today With Privacy Policy

Status: Internal review draft — not approved for publication

This document is not effective. Before publication, Today With must complete the internal release checklist at the end of this file, set an Effective Date, confirm the production data flows and retention rules, and obtain legal review for the initial launch territories.

Effective Date: To be set before the first public release

Last Updated: July 26, 2026

This Privacy Policy explains how Today With handles information when you use the Today With iOS application and the related account, meal-recording, artificial-intelligence, and subscription services (collectively, the “Service”).

In this draft, “Today With,” “we,” “us,” and “our” refer to the public-facing operator identity of the Service. The legal operator and required business details must be confirmed before this Policy is published.

On this page

  1. 1. Scope
  2. 2. Information We Handle
  3. 3. How We Obtain Information
  4. 4. How We Use Information
  5. 5. AI Processing
  6. 6. When We Disclose Information
  7. 7. Data Retention
  8. 8. Account Deletion
  9. 9. Your Choices and Rights
  10. 10. Security
  11. 11. International Processing
  12. 12. Children
  13. 13. Third-party Services and Links
  14. 14. Changes to This Policy
  15. 15. Contact Us

1. Scope

This Policy applies to information handled through the Service, including the iOS app and the backend systems that support it.

The public website at https://todaywith.app currently provides the routes intended to host this Policy and the Terms of Service. Website hosting, logging, analytics, cookies, and other website-specific processing must be separately verified before this Policy is published. This Policy does not describe a feature or provider merely because it is planned or appears in dormant code.

2. Information We Handle

The information we handle depends on the features you use.

2.1 Account and authentication information

Today With requires an account. We may handle:

  • your email address;
  • email verification and delivery records;
  • identifiers and profile information supplied by Apple or Google when you use those sign-in methods;
  • information about the sign-in methods connected to your Today With account;
  • Today With account, session, and app-installation identifiers;
  • sign-in, sign-out, and account-security events; and
  • IP address and request context used to authenticate, secure, and troubleshoot the Service.

The current iOS app supports Sign in with Apple, Google Sign-In, and email verification codes. It does not offer password-based, guest, or anonymous access.

2.2 Meal, photo, and optional location information

When you record a meal, we may handle:

  • meal type, time, recorded or skipped state, and related timestamps;
  • photos you select or capture and the image variants needed to display them;
  • photo metadata such as file type, dimensions, file size, upload state, and storage references;
  • a place name, address, coordinates, and provider place identifier if you choose to attach a location to a meal; and
  • upload, processing, retry, and error information needed to operate the feature.

Location access may be used on your device to support the place picker. A location is saved with a backend meal record only when you select a place and save it with the meal.

2.3 AI-generated and derived information

We may create and store:

  • recognized food composition and food descriptions;
  • estimated energy and macronutrient proportions;
  • meal keywords, impressions, and observations;
  • Day Summaries generated from meal states and meal keywords;
  • analysis status, provider and model information, prompt version, latency, token counts when available, and error information; and
  • internal AI traces containing request summaries and provider responses for operation and troubleshooting.

AI outputs remain associated with your account, meal, or day records. We do not treat them as anonymous merely because they were generated by a model.

2.4 Subscription and purchase information

For Today With Plus, we may handle:

  • App Store product information;
  • internal order identifiers and status;
  • StoreKit and App Store transaction and original-transaction identifiers;
  • subscription lifecycle, renewal, grace-period, expiry, revocation, and refund information;
  • account-linking and subscription-ownership state; and
  • Apple-signed transaction, renewal, and server-notification information.

Apple processes your App Store payment. Today With does not receive or store your payment-card number, Apple Account password, or Apple Pay credential.

2.5 Device, app, and operational information

Authenticated requests may include the app version and build, iPhone or iPad device class, iOS version, display information, network category, app identifier, and an app-installation identifier. We also create request identifiers, job identifiers, timestamps, retry counts, service status, and error details needed to operate, secure, and troubleshoot the Service.

2.6 Information stored on your device

The iOS app stores or caches limited information on your device, including:

  • session and user identifiers and limited recovery state in iOS Keychain;
  • app and account preferences;
  • recently selected meal places associated with your Today With account;
  • downloaded meal-image cache files; and
  • limited pending account-deletion or StoreKit recovery state.

Signing out clears authentication state but may not immediately remove every non-authentication cache. Account deletion performs additional user-scoped cleanup.

2.7 Information we do not currently collect through the app

The current app does not integrate or collect:

  • Contacts, microphone, or HealthKit data;
  • advertising identifiers or cross-app tracking data;
  • push-notification tokens;
  • third-party advertising data; or
  • data through third-party product analytics or crash-reporting SDKs.

We will update this Policy before materially changing these practices.

3. How We Obtain Information

We obtain information:

  • directly from you when you sign in, select or capture photos, attach a place, edit a meal, contact support, purchase a subscription, or request account deletion;
  • from Apple or Google when you use their authentication, mapping, location, or App Store services;
  • automatically from your device and use of the Service for authentication, operation, security, and troubleshooting; and
  • by generating or deriving information through meal analysis, Day Summary generation, subscription verification, and other service operations.

4. How We Use Information

We use information to:

  • create, authenticate, secure, and maintain your account and session;
  • connect or remove sign-in methods and reauthenticate sensitive actions;
  • upload, store, display, edit, and organize meals, photos, places, and history;
  • provide AI meal analysis, nutrition estimates, meal observations, and Day Summaries;
  • operate the free Nutrition allowance and Today With Plus access;
  • display App Store products, verify purchases, restore or synchronize subscriptions, and resolve subscription ownership;
  • send verification and account-deletion communications;
  • prevent abuse, investigate failures, protect accounts, and enforce service rules;
  • operate queues, caches, storage, logs, and support processes; and
  • comply with applicable legal obligations and resolve disputes.

The current Service does not sell personal information, serve third-party behavioral advertising, or use personal information for cross-app tracking.

5. AI Processing

5.1 What is sent for meal analysis

Today With currently uses Google Gemini through Google Cloud Vertex AI to provide meal analysis and Day Summaries.

For meal analysis, the request may include meal photos, meal type, preferred locale, time zone, optional attached location text, image count, and an internal meal identifier. The internal meal identifier is not your Today With user identifier, but the request should not be considered fully anonymous.

For a Day Summary, the request contains structured text describing meal type, meal state, meal sequence, and AI-generated meal keywords. The Day Summary request does not include meal photos or your Today With user identifier.

The current provider request builders do not add your name, email address, Apple or Google authentication identifiers, subscription or payment information, app-installation identifier, IP address, device information, or account-deletion information to the AI prompt.

5.2 Provider use and retention

Under Google's published Cloud terms for Vertex AI, Google states that it will not use customer data to train or fine-tune AI or machine-learning models without the customer's prior permission or instruction. Today With does not currently submit your content or corrections to Google as model-training feedback.

This does not mean that provider processing has zero retention. Limited prompt logging for abuse monitoring or feature-specific retention may apply, and Google's published Gemini models use project-isolated in-memory caching with a default 24-hour time-to-live unless the project configuration changes it. The production Google Cloud configuration must be verified before any stronger retention claim is made.

See Google's Service Specific Terms and Vertex AI data-retention documentation for more information about Google Cloud's current terms and controls.

5.3 AI limitations and human access

There is no routine professional or human review of an individual meal analysis or Day Summary before it is shown to you. Authorized personnel may access relevant records, AI traces, or service logs when reasonably necessary to operate, secure, investigate, or troubleshoot the Service.

AI outputs are estimates and may be incomplete, inaccurate, inconsistent, delayed, or unavailable. See the Terms of Service for important health, food-safety, and reliance limitations.

6. When We Disclose Information

We disclose information only as needed for the purposes described in this Policy, including to the following categories of service providers:

  • Apple: Sign in with Apple, MapKit, Core Location, the App Store, StoreKit, App Store Server API, and App Store Server Notifications;
  • Google: Google Sign-In and Google Cloud Vertex AI / Gemini;
  • Amazon Web Services: infrastructure used for backend computing, meal-photo storage and delivery, databases, temporary caching, message queues, and email delivery; and
  • authorities or other legally authorized recipients: when disclosure is required by applicable law or reasonably necessary to protect legal rights and safety, investigate misuse, or resolve a dispute.

Each provider may process information under its own terms and privacy practices. We do not list a planned provider as active until it is actually used with production data.

7. Data Retention

We retain information for as long as reasonably necessary to provide the Service, maintain the account or feature you use, secure and troubleshoot the Service, comply with legal and accounting requirements, prevent fraud, resolve disputes, and enforce agreements.

Current retention behavior includes:

  • active account, meal, day, photo, AI-result, and related records are generally kept while the account exists;
  • email verification code values in temporary cache expire after ten minutes, although associated delivery and audit records may be kept longer;
  • uploaded photos that are not attached to a meal after 24 hours may be marked as orphaned, and orphaned photos become eligible for object deletion after seven days;
  • subscription and payment transaction facts are retained after account deletion for operational, accounting, tax, fraud-prevention, dispute, or legal needs; and
  • logs, queues, backups, object versions, anonymized account records, and deletion audit records may remain according to applicable operational or legal retention rules.

Retention is not the same as credential validity. A session, verification code, or recovery token may expire before the related security or audit record is deleted.

Before this Policy is published, Today With must finalize and document the retention periods or deletion criteria identified in the internal release checklist below.

8. Account Deletion

You can request permanent account deletion in the app through Settings → Delete Account. The app requires reauthentication before the request is submitted.

After the server accepts the request:

  • ordinary account access is blocked and active Today With sessions are revoked;
  • the deletion process is intended to complete no later than seven days after acceptance;
  • meal and day records, attached locations, meal-photo objects identified by the deletion process, photo metadata, AI results and traces, Nutrition trial records, and related app content are removed through the deletion workflow;
  • authentication and login records are deleted or de-identified as applicable; and
  • Today With does not offer a way to cancel the request or restore the deleted account or deleted app content.

Some records are retained after deletion, including de-identified account and login records, the deletion-request audit record, and Apple subscription, transaction, renewal, refund, and notification facts after direct Today With account ownership is released. Infrastructure logs, backups, or non-current object versions may also remain until their applicable deletion or retention cycle ends. Retained information must be limited to documented operational, security, accounting, tax, fraud-prevention, dispute, or legal purposes.

Deleting your Today With account does not cancel an App Store subscription, stop Apple billing, or request a refund. Manage or cancel the subscription through Apple before deleting your account if you do not want it to renew. Apple provides subscription-management instructions and a separate refund-request process.

After the former identity is released, you may register again. A later registration creates a new Today With user identifier and does not restore the former account, meal data, photos, AI analyses, or summaries.

9. Your Choices and Rights

Depending on where you live, you may have rights concerning access, correction, deletion, restriction, objection, portability, consent, or complaints. These rights may be subject to legal conditions and exceptions.

The current Service lets you:

  • view account connection and subscription status in Settings;
  • change your verified email and connect or disconnect Apple or Google while retaining at least one sign-in method;
  • view and edit meals, photos, optional locations, and available AI-generated results;
  • remove individual attached photos or a location by editing a meal;
  • manage App Store subscriptions and restore purchases through Apple-supported flows; and
  • delete your Today With account through the in-app flow described above.

The current Service does not provide a self-service export of all account information. To ask about access, correction, a copy of information, portability, privacy rights, or another request not available in the app, contact support@todaywith.app. We may need to verify your identity before acting on a request. Do not send a password, verification code, session token, provider credential, payment-card number, or private key.

Apple and Google separately control information held in your Apple or Google account. You can also revoke Camera, Photos, or Location permission through iOS Settings; doing so does not automatically delete information already uploaded or saved with a meal.

10. Security

We use technical and organizational measures intended to protect information, including HTTPS for the production app API, iOS Keychain storage for Today With session data, access controls tied to authenticated accounts, and time-limited URLs for meal-photo transfer.

No system is completely secure. We do not promise end-to-end encryption, zero-knowledge storage, deletion from every backup at the same moment, or a security certification that has not been independently verified.

11. International Processing

Today With may be used from a country different from the countries where Today With, its service providers, infrastructure, or personnel process information. Information may therefore be transferred to, stored in, or processed in countries whose data-protection rules differ from those in your country.

The providers involved may include cloud infrastructure, authentication, AI, payment, mapping, email, and operational providers described in this Policy. Where applicable law requires a particular transfer mechanism or safeguard, Today With will use the mechanism or safeguard applicable to the relevant transfer. The final production provider entities, processing locations, backup locations, and transfer mechanisms must be confirmed before this Policy is published.

12. Children

Today With is a general-wellness service and is not directed to children under 16. You must be at least 16 to create or use a Today With account and must meet any higher minimum age required in your jurisdiction. If you have not reached the age of legal majority where you live, you must have permission from a parent or legal guardian where local law requires it.

The current Service does not ask for your date of birth or independently verify every user's age. If a parent or legal guardian believes that a person under the applicable minimum age provided personal information through Today With, contact support@todaywith.app. A sufficiently verified underage account will be handled through the account-deletion and retention process, subject to applicable retention exceptions.

13. Third-party Services and Links

The Service relies on or links to services controlled by Apple, Google, Amazon Web Services, and other providers described above. Their handling of information is governed by their own terms and privacy notices. A link to a third-party service does not mean that Today With controls that service.

14. Changes to This Policy

We may update this Policy when the Service, data practices, providers, or legal requirements change. Before a revised version becomes effective, we will update the Effective Date or Last Updated date and provide any notice required by applicable law. Material changes may require additional notice or choices.

15. Contact Us

For general support, privacy requests, account or deletion questions, AI-related concerns, or Today With subscription-ownership issues, contact:

  • Email: support@todaywith.app
  • Website: https://todaywith.app

Apple controls App Store billing, cancellation, purchase history, and refund decisions.