ZestFit
Privacy Policy
Last updated: August 15, 2026
- Effective date: 15 August 2026
- Developer: Pixelcount Labs
- Website: https://pixelcountlabs.com
- Contact: pixelcountlabs@gmail.com
- App package: com.pixelcountlabs.zestfit
1. Overview
ZestFit is a food-scanning and health-tracking app. It scans product barcodes and food labels, analyses what you eat, keeps a food and health diary, plans meals, and coaches you toward your goals.
We are committed to protecting your privacy.
The short version: Your diary, profile, and health data live on your device by default. ZestFit shows no ads and ships no analytics or tracking SDKs. Some features work by sending specific data to external services — barcode lookups to the Open Food Facts database, and photos, voice notes, or questions you submit for analysis, which go directly from your device to Google (see Section 4). Cloud backup is optional: it requires you to create an account with an email address, and nothing is uploaded to it unless you sign in and back up. You can delete your backup, or your whole account, from inside the app at any time.
2. Data We Collect
2.1 Data You Give Us
- Your name, month and year of birth, and health details (sex, height, weight, activity level, dietary preferences, allergies and any health conditions you choose to record) — entered by you during setup and stored on your device.
- What you log: foods, meals, water, exercise, steps, weight and other vitals, plus any lab-report values you import.
- An email address and password, only if you choose to create an account for cloud backup. If you never create one, we hold no email address for you.
2.2 Data We Do NOT Collect
- Your location — the app neither requests nor holds location permissions
- Advertising identifiers, or any identifier used to track you across apps
- Contacts or calendar data
- Usage analytics, behavioural data, or crash reports (we ship no analytics or crash-reporting SDK; Google Play may still collect aggregate install and crash data automatically, governed by Google's own policies)
- We do not sell or share any of your data with advertisers — the app shows no ads
2.3 Data Stored Locally On Your Device
The following is saved only on your device and stays under your control. It is removed when you delete it in the app (or use "Start over") or uninstall ZestFit:
| Data | Purpose |
|---|---|
| Your profile (age, sex, height, weight, goal, diet, conditions, allergies) | Calculating your calorie/macro targets and personalising analysis |
| Food diary, water, and weight log | Tracking what you eat and your progress |
| Scan history and product details | Reviewing previously scanned products |
| Remembered barcodes | So a product you have already identified is recognised instantly next time, without another lookup |
| Lab-report values and family member profiles | The health reports feature |
| Step counts (from your device's pedometer or Health Connect) | Optionally extending your daily calorie budget |
| Meal plans, recipes, grocery lists, coach conversations | The planning and coaching features |
| Reminder settings and app preferences | Your notification and app settings |
3. How Your Data Is Handled
ZestFit is local-first: your diary, profile, vitals, and reports are stored in a database on your device, and all calorie/macro/score calculations run on-device. Step counts are read from your device's pedometer or, if you allow it, from Android's Health Connect; either way they stay on your device (and in your cloud backup, if you enable one). We never send your step data to any third party, and we never write anything back into Health Connect. Reminders are local notifications scheduled on your device.
Some features need the internet to work, and send only the data listed in Section 4 to provide that feature.
4. Network Use
ZestFit does not show ads. The app connects to the internet only for the features below.
Barcode lookups (Open Food Facts and USDA FoodData Central)
When you scan a product barcode, the app sends the barcode number to the public Open Food Facts database (https://world.openfoodfacts.org) to fetch the product's name, ingredients, and nutrition facts. No personal data is included. As with any web request, the service may observe your IP address; this is governed by Open Food Facts' own privacy policy.
If Open Food Facts has no entry for that barcode, the app then sends the same barcode number to USDA FoodData Central (https://fdc.nal.usda.gov), a free database published by the United States Department of Agriculture, to see whether it is listed there. Again, only the barcode is sent — no personal data — and the service may observe your IP address. This lookup happens only for barcode scans, and only after Open Food Facts has come back empty.
AI analysis
Some features are powered by an AI provider. Today that provider is Google Gemini. When you use these features, the following is sent only to generate the response and is not used by us for any other purpose:
| Feature | What is sent |
|---|---|
| Label / food photo analysis | The photo you capture or pick |
| Lab-report scanning | The report photo or PDF you choose — sent once to read the values; only the extracted numbers are kept, on your device |
| Coach chat, meal plans, recipes, weekly reports | Your question plus relevant context (your goals, profile numbers, and recent diary entries) |
| Voice logging | Your voice recording, transcribed to text |
These requests go directly from your device to the AI provider. The app calls Google's Gemini API itself; there is no server of ours in between. This means:
- We never receive or see your photos, recordings or chats. They travel from your device straight to Google. We operate no server that handles them and therefore keep no copy and no log of them.
- What Google does with them is governed by Google's terms, not by this policy. The Gemini API's free service tier permits Google to retain submitted content and to have it reviewed by people in order to improve their products. If that matters to you, avoid the AI features — every other part of ZestFit works without them.
- An API key is embedded in the app. Because the app contacts Google directly, it must carry a key to do so. A key shipped inside an app can be extracted from it; it grants access to our AI quota only, and gives no access to your diary, your device, or anything you have stored.
- Photos and recordings are sent for processing only — the results come back and are stored on your device.
- Google's handling of what you send is governed by its own privacy policy (https://policies.google.com/privacy) and the Gemini API terms.
We intend to move this traffic behind a gateway we operate, so that no key ships inside the app and prompts are never retained. That gateway is not live yet. This section describes what the app does today, and we will update this policy when that changes.
Optional cloud backup
Cloud backup requires you to create an account with an email address and password. Until you do, nothing leaves your device for backup purposes.
If you sign in, a snapshot of your app data — profile (including your name), diary, vitals, steps, settings, saved recipes, coach messages and imported report findings — is stored in Google Firebase (Firestore) under your account's user ID. Because it is tied to your account, it is not anonymous.
Once signed in, the app backs up once a day automatically. You can turn that off with the "Auto backup" switch, and automatic backup never runs for users under 18.
You can delete the cloud backup, or delete your entire account, from the Profile screen at any time. Deleting your account removes both the account and everything stored against it.
Where it is stored: Google Firebase servers, which are located in the United States. If you are in the UK, EEA or another region with data-transfer rules, using cloud backup means your data is transferred there. Google's processing is governed by the Google Privacy Policy (https://policies.google.com/privacy).
5. Permissions
ZestFit requests only the permissions it needs:
| Permission | Why it is needed |
|---|---|
CAMERA | Scanning product barcodes and capturing food-label / lab-report photos |
| Photos / media access (system picker) | Analysing a label or report photo you already have |
ACTIVITY_RECOGNITION | Counting your steps while the app is open (only if you enable step tracking) |
health.READ_STEPS (Health Connect) | Reading your daily step count from Android's Health Connect, so steps you take with the app closed still count. Read-only — ZestFit never writes to Health Connect. Only if you grant it; the feature works without it, counting fewer steps. |
| Microphone | Logging food by voice (only when you use voice input) |
| Notifications | Meal, water, and weigh-in reminders you turn on |
INTERNET | Barcode lookups, AI analysis, and optional cloud backup (Section 4) |
ZestFit does not request location or contacts permissions.
Where data is processed:
- Barcode lookups go to Open Food Facts (servers in France) and, on a miss, to USDA FoodData Central (United States). Only the barcode is sent.
- AI requests go from your device straight to Google, which processes them on its own infrastructure, largely in the United States. No server of ours is involved.
- Cloud backup is stored in Google Firebase, in the United States.
Health information is special-category data, and we rely on your explicit consent — given when you choose to use an AI feature or enable cloud backup — as the legal basis for processing and transferring it. If you are in the UK or EEA, using these features means your data is transferred outside that region. You can withdraw that consent by not using those features and by deleting your account.
6. Data Retention
- Your diary, profile, and health data: Stored on your device until you delete them in the app (including the "Start over" reset) or uninstall the app.
- AI requests: We run no server in this path, so we store nothing. Whether Google retains what you send — and for how long — is governed by Google's terms; on the free service tier it may retain the content and have it reviewed by people to improve its products.
- Cloud backup (if enabled): Kept until you delete it, overwrite it with a newer backup, or delete your account. Deleting your account removes it immediately and permanently.
- Uninstalling ZestFit removes the app's locally stored data.
7. Children's Privacy
ZestFit is for people aged 13 and over. During setup the app asks for your month and year of birth:
- Under 13 — the app does not let you continue, and nothing is stored.
- Under 18 — the app never offers a weight-loss or calorie-deficit plan, and automatic cloud backup stays switched off.
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through the app, please contact us and we will delete it.
If you are under 18, please talk to a parent or guardian before using an app that tracks your health.
8. Security
Your data lives primarily on your device, so its security depends on your device's security. We recommend:
- Keeping your device OS and the app up to date
- Using a screen lock on your device
- Enabling cloud backup only on devices you trust
Backups are transmitted to Firebase over encrypted (HTTPS) connections.
9. Your Privacy Rights (GDPR, CCPA/CPRA, and others)
We do not sell or share your personal information, and do not build advertising profiles about you. For California residents: we have not sold or shared personal information in the preceding 12 months, and we do not do so now. The categories we collect, why, and how long we keep them are set out in Sections 2, 4 and 6.
Your data is on your device, where you can view, edit and delete it directly:
- "Start over" (Profile screen) erases everything stored on this device. It does not touch a cloud backup.
- "Delete cloud backup" removes the copy held in the cloud, leaving the account and your device data intact.
- "Delete my account" permanently removes your account and everything stored against it.
To exercise access or portability rights over anything held in the cloud, or if you have any question about your data, contact us using the details below.
Data sent to third parties to power a feature (Open Food Facts, USDA FoodData Central, the AI provider, Firebase for optional backup) is governed by those providers' policies, linked in Section 4. Regardless of where you live, if you have questions about your privacy or wish to make a request, you can contact us using the details in Section 12.
10. Third-Party Links
The app may contain links to external websites (e.g. the Play Store, our website). We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective date at the top of this page. Continued use of the app after any change constitutes acceptance of the updated policy. For significant changes, we will provide a more prominent notice.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
Pixelcount Labs
- Email: pixelcountlabs@gmail.com
- Website: https://pixelcountlabs.com
This privacy policy was last updated on 15 August 2026.