Who we are
Grava ("we", "us") is a calorie-tracking app for iPhone, iPad, and Mac. This policy explains what information the app handles, why, and the choices you have. It applies to the Grava app and this website.
Information we collect
- Account information. You sign in with Sign in with Apple. We receive a unique account identifier and, if you choose to share them, your name and email address (Apple lets you hide your real email). We never see your Apple ID password.
- Profile details. To compute your calorie targets, the app asks for your biological sex, birth year, height, weight, and activity level.
- Your food log. Each entry you confirm stores the food's name, the time it was logged, the calorie estimate (including its range), protein, carbohydrate, and fat estimates, how it was logged (camera, library, text, or manual), and whether you edited the estimate.
- App settings. Your preferences, such as your goal mode (cut, maintain, bulk) and when your calorie day ends.
What we don't collect
- Photos are never stored. Pictures you take or select are used only to produce the estimate in front of you, then discarded. They are not saved to your account or our servers.
- No analytics or advertising. The app contains no analytics SDKs, no advertising SDKs, and no trackers.
- No location, contacts, or health-record access. Grava doesn't request them.
How food photos and descriptions are analyzed
When you ask Grava to estimate a food, the photo and/or text you provide is processed in one of two ways:
- Cloud analysis (default when online). The image and text are sent over an encrypted connection to Google's Gemini model via Firebase AI Logic, which returns the estimate. Grava does not store the photo or the request; Google processes it as a service provider under its Firebase privacy terms.
- On-device analysis (offline fallback). On devices with Apple Intelligence, the analysis runs entirely on your device using Apple's on-device models. In this mode, nothing you photograph leaves your device.
Where your data lives
Your profile, settings, and food log are stored in Google Cloud Firestore (part of Firebase), in a record tied to your account. Access rules ensure your data is readable and writable only by you when signed in. Data is encrypted in transit.
How we use your information
Only to run the app: computing your targets, producing estimates, showing your history, and syncing across your devices. We do not sell your data, share it for advertising, or use it for marketing. Our only service providers are Apple (Sign in with Apple, on-device analysis) and Google Firebase (authentication, database, and cloud AI analysis).
Data retention and deletion
- Individual entries can be deleted in the app at any time, from any day in your history.
- Your account and all data can be deleted by contacting us at the address below. We'll remove your profile, settings, and entire food log.
Security
All traffic between the app and our servers is encrypted (TLS). Authentication is handled by Apple and Firebase; database rules restrict your data to your signed-in account. No system is perfectly secure, but we keep the amount of data we hold to the minimum the app needs.
Children
Grava is not directed at children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Everything Grava stores about you is visible in the app itself (your profile in Settings, your log in History); for a copy of your data or deletion, contact us and we'll handle it.
Changes to this policy
If we change this policy, we'll update this page and its effective date. Material changes will be called out in the app.
Contact
Questions or requests: email support — or see the Support page.