Thank you for using Snaqly. This Privacy Policy ("Policy") explains how AppskKuber ("AppskKuber", "we", "our", or "us"), an India-based developer, collects, uses, stores, transfers, shares and protects information about you when you use the Snaqly mobile application available on the Google Play Store (package com.appskuber.snaqly) and our legal subdomain at https://legal.snaqly.com (collectively, the "Service").
Snaqly is an AI-assisted food-logging and nutrition-coaching application. To do its job it necessarily processes information about your body and what you eat — your height, weight, age, dietary preferences, optional health considerations, photographs of your meals, and, if you connect it, movement data from Android Health Connect. Because such information is treated as health data or sensitive personal data under multiple legal regimes worldwide, we apply heightened safeguards and offer enhanced rights to users who entrust this data to us.
This Policy is written to be readable. Where legal terms are necessary we have used them; where plain English serves better, we have used that.
If you do not agree with this Policy, please discontinue use of the Service and, where applicable, delete your account using the procedures in Section 13. Continued use of the Service after the Effective Date stated above constitutes acceptance of this Policy.
1. Definitions
- App
- The Snaqly Android application, package identifier
com.appskuber.snaqly. - Personal Data
- Any information relating to an identified or identifiable natural person, as defined under the DPDP Act, the GDPR, and equivalent laws.
- Health Data
- Personal Data relating to your physical health, including your body measurements, dietary intake, weight history, and movement or fitness records.
- Logged Content
- The entries you create in the App: foods, portions, calories and macronutrients, meal times, water intake, weight readings, workouts, and any notes you add.
- Derived Data
- Values the Service computes from your input, such as BMI, daily calorie and protein targets, weekly weight trend, streaks, detected patterns, and the coaching context document.
- Coach Memory
- Short factual statements the AI coach records about you (for example "usually eats 3 rotis at dinner") so it need not ask again. Capped at thirty (30) facts, each individually viewable and deletable by you.
- Pro
- The paid subscription tier of the Service, sold exclusively through Google Play Billing.
- Service
- The App, its backend Cloud Functions, and this legal website, taken together.
2. Scope & Applicable Law
This Policy applies to all users of the Service, worldwide. Depending on where you live, one or more of the following frameworks gives you rights we honour:
- India — the Digital Personal Data Protection Act, 2023 ("DPDP Act"). AppskKuber acts as a Data Fiduciary; you are a Data Principal.
- European Economic Area — Regulation (EU) 2016/679 ("GDPR"). AppskKuber acts as the data controller.
- United Kingdom — the UK GDPR and the Data Protection Act 2018.
- California, USA — the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- United States, children — the Children’s Online Privacy Protection Act ("COPPA").
- Google Play — the Google Play Developer Programme Policies, including the Health Apps, Health Connect, User Data, AI-Generated Content and Data Safety policies, which we treat as binding on us in addition to the law.
Where the law of your jurisdiction grants you a stronger right than this Policy describes, that stronger right prevails.
3. About AppskKuber and Snaqly
Snaqly is developed and operated by AppskKuber, a sole-proprietor software developer based in Madhya Pradesh, India. Full contact details, including our Grievance Officer, are in Section 24.
What the App does, in outline: you log what you eat — by photographing it, saying it, typing it, scanning a barcode, searching a bundled food list, or repeating something you have logged before. The App estimates calories and macronutrients, keeps a diary, computes targets for you, and an AI coach writes daily briefs, weekly reviews, meal ideas and answers to your questions using that history as context. The App can also read your steps, active energy and weight from Android Health Connect if you connect it.
4. Information We Collect
We collect information from and about you in the following ways: (a) information you provide directly; (b) information we collect automatically when you use the Service; (c) information we receive from Google (sign-in and billing); and (d) information we generate from the data you provide.
4.1 Account Information
- An anonymous Firebase user identifier ("UID"), created the first time you launch the App. It exists so that your diary, targets and server-side automations work before you ever create an account.
- If you sign in with Google: your Google account email address and your display name as reported by Google.
- If you register with email and password: your email address, an optional name, and an authentication credential held and hashed by Firebase Authentication (we never see or store your password).
- Authentication metadata such as sign-in timestamps and sign-in method.
Anonymous use is fully supported. The limitation, which the App states plainly on screen, is that data held under an anonymous UID lives only on that installation — uninstall the App or change phones and it is gone. Signing in upgrades the same identity in place, so nothing is lost.
4.2 Profile & Body Data (Health Data)
- Age and gender — required inputs to the basal-metabolic-rate formula used to compute your calorie target;
- Height and current weight — used for BMI and the same calculation;
- Target weight, goal (lose / maintain / gain) and chosen weekly pace;
- Activity level — one of five bands, used to compute total daily energy expenditure;
- Dietary preference — for example vegetarian, eggetarian, or non-vegetarian, used to filter the food list and the meal suggestions;
- Optional health considerations you may select — for example PCOS, thyroid disorder, diabetes, pregnancy, or acidity. These are optional, are used to set honest expectations about progress speed and to keep coaching advice appropriate, and can be cleared at any time;
- Optional profile photograph, if you choose to add one. It is stored on your device only.
4.3 Logged Content
- Every food or drink entry: name, portion, calories, protein, carbohydrate, fat and fibre, the meal it belongs to, and its timestamp;
- Corrections you make to an estimate, and the portion you settled on (remembered so the same food opens at your amount next time);
- Water intake, including the type of drink;
- Weight readings, their dates, and any note attached;
- Workouts you enter manually: type, duration, estimated energy, and notes;
- Logging streaks and milestones.
4.4 Derived Data
From the above we compute and store, in your own account area, so that each session can present them instantly:
- Daily calorie target and protein target, and the fibre target implied by your chosen pace;
- BMI and its category;
- Daily totals for the last fourteen (14) days;
- Your most frequently logged foods (top twenty) and the median clock time of each of your meals;
- Weight trend expressed in kilograms per week, and progress toward your target;
- Rule-detected patterns — for example weekend intake spikes, low-protein days, late-night eating, breakfast rarely logged, or persistent under-eating;
- Coach Memory — up to thirty short factual statements, each of which you can read and delete in the Coach tab.
These values exist solely to deliver the Service to you. We do not enrich them with information from outside sources, and we do not build advertising or marketing profiles from them.
4.5 Coach Conversations
When you use AI features we store your questions, the AI’s replies, and the automated coach posts written for you (morning brief, evening plan, pattern alerts, weekly review, comeback nudges), together with their timestamps. This is what makes the Coach tab a continuous thread rather than a series of disconnected answers.
4.6 Device and Technical Information
- Device model, manufacturer, operating system and OS version;
- App version, so we can investigate version-specific faults;
- Device language and locale, and time-zone offset;
- Crash reports, including the stack trace and the state of the App at the moment of the crash, with an anonymous installation identifier.
4.7 Usage Information
We record typed product events through Google Analytics for Firebase — for example a meal logged and by which method, a scan started or completed, onboarding steps finished, the paywall being viewed, a purchase started or completed, a screen opened. These tell us which features are actually used and where people get stuck. They are not used for advertising, and no advertising identifier is collected (see Section 10).
4.8 Notification Data
A Firebase Cloud Messaging token, your time-zone offset, your app language, whether notifications are enabled, and four pre-computed UTC hours at which your reminders should fire (morning brief, evening plan, streak saver, weekly review). We store the hours already converted to UTC precisely so that the server never has to guess your local time at send time.
5. Health Data Notice & Explicit Consent
The information described in Sections 4.2, 4.3 and 4.4, together with anything read from Health Connect, is Health Data.
We do not use Health Data for advertising, we do not share it with advertisers or data brokers, and we do not sell it. Google Play’s Health Apps and Health Connect policies forbid this, and so do we.
6. Food Photographs
This section is stated separately because it is the question users ask most.
- A photograph you take or choose is saved on your own device and displayed in your diary from there. The database entry stores only the local file path.
- To estimate what the food is, a copy of the image is transmitted to our backend as the content of a single request and forwarded to Google Vertex AI for analysis. It is used to produce the estimate and is not written to any database or file store of ours.
- Our cloud file storage is closed. The storage security rules deny every read and every write, for every path, for every user. There is no bucket into which a photograph could be placed.
- Images are captured and uploaded at reduced resolution (720p from the camera, and gallery images capped at 1280 pixels on the long edge), both to make the estimate fast and to send no more data than the task requires.
- Delete a meal from the diary, or uninstall the App, and the photograph goes with it. There is no server copy to delete.
7. How We Use Your Information & Legal Bases
| Purpose | Data used | Legal basis (GDPR / DPDP) |
|---|---|---|
| Provide the diary, targets and progress views — the core Service | Profile, Logged Content, Derived Data | Performance of a contract; consent for the health elements |
| Estimate calories and macronutrients from a photo, a sentence or a barcode | The image or text of that single request, plus your dietary preference | Performance of a contract |
| Generate coaching: briefs, evening plans, pattern alerts, weekly reviews, meal ideas and plans | Derived Data, recent Logged Content, Coach Memory, profile and health considerations | Performance of a contract; explicit consent for health elements |
| Send reminders and coaching notifications | Notification token, time-zone offset, usual meal times, whether you logged today | Consent (you are asked after you have first felt the value, never at cold launch) |
| Restore your data when you sign in on a new device | Account identifier, Profile, Logged Content | Performance of a contract |
| Unlock and verify Pro | Google Play purchase token, subscription state, account identifier | Performance of a contract; legal obligation (tax and accounting records held by Google) |
| Diagnose crashes and improve the App | Device and technical information, usage events | Legitimate interests (keeping the App working), balanced against your privacy |
| Prevent abuse of paid AI capacity and enforce fair-use limits | Request counts per account, App Check attestation | Legitimate interests (security and cost control) |
| Respond to your support messages and rights requests | Your email and the contents of your message | Legal obligation; legitimate interests |
We do not use your information for advertising, profiling for marketing, credit or insurance decisions, or any automated decision-making that produces legal effects concerning you.
8. AI Processing Disclosure
Food recognition, the coach, daily lessons, weekly reviews, meal ideas, recipes and week plans are produced by Google Gemini models running on Google Cloud Vertex AI, within our own Google Cloud project.
8.1 What is sent
- For a photo or text log: the image or the sentence, plus your language and dietary preference.
- For coaching: a compact context document assembled on our server from your own data — your targets, your recent daily totals, today’s foods, your frequent foods and usual meal times, your weight trend, the rule-detected patterns, your streak, and your Coach Memory. Your question is appended.
8.2 What is not done
- Your content is not used to train Google’s models or ours.
- We do not send your email address, your name, or your Google account details to the model.
- We do not send your food photographs to any AI provider other than Google Vertex AI.
8.3 Labelling, reporting and limits
Every AI-written message in the App is labelled AI-generated and carries a Report action that files the message for our review. AI output can be wrong or inappropriate for your circumstances; see the medical disclaimer in Section 21. Server-side fair-use limits apply to AI requests, and safety instructions are applied to every AI call — among other things the coach is instructed never to recommend an unsafe deficit, never to diagnose, and to defer to a professional on clinical questions.
9. Android Health Connect
Connecting Health Connect is optional and is offered only when you tap to connect it — never at first launch.
9.1 What we read
- Steps
- Active energy burned
- Weight
9.2 How it is handled
- Access is read-only. Snaqly never writes to Health Connect.
- Data is read on your device to display your own numbers — today’s steps, the energy figure used in your daily budget, and your latest weight.
- Health Connect data is not used for advertising or marketing, is not sold or shared with third parties, and is not transferred to any service other than the Snaqly account area that already holds your own diary.
- Refusing or revoking permission does not break the App; it simply falls back to what you enter manually.
- You can revoke Snaqly’s access at any time in the Health Connect app, which also shows you an access log.
This use complies with the Health Connect Permissions policy and with the Google Play Health Apps policy. Our use of Health Connect data is limited to the purposes disclosed here.
10. No Advertising & No Device Advertising Identifiers
Snaqly contains no advertising of any kind, for free users as well as paying ones. Concretely:
- No advertising SDK is present in the App;
- The App does not declare the
com.google.android.gms.permission.AD_IDpermission — it is explicitly removed from the merged manifest; - No Android Advertising ID, IDFA or equivalent identifier is collected, derived or transmitted;
- We run no remarketing, no audience building, and no conversion tracking for advertisers;
- "No ads" is therefore not a paid feature — there is nothing to remove.
The Service is funded entirely by the Pro subscription.
11. Subscriptions & Payments
Pro is sold exclusively through Google Play Billing. Two products exist: a yearly plan (which may carry a free trial) and a monthly plan.
- We never receive or store your payment details. Card, UPI, wallet and billing-address information is handled entirely by Google.
- What we receive and store is a purchase token, the product identifier, the purchase and expiry timestamps, and the resulting entitlement state. The token is verified server-side against the Google Play Developer API before Pro is granted.
- Google keeps its own record of the transaction, including your payment method, under the Google Payments privacy terms. We cannot see or delete that record.
- Refund terms are in the Terms of Service. Refunds are issued by Google, not by us.
12. Third-Party Services & SDKs
Every processor we use is operated by Google. There are no advertising, attribution, social-media or data-broker SDKs in the App.
| Service | Purpose | Data involved |
|---|---|---|
| Firebase Authentication | Accounts, including anonymous identities | UID, email, display name, sign-in metadata |
| Cloud Firestore | Your account area: profile, diary mirror, coach thread, memory, entitlement | Profile, Logged Content, Derived Data, Coach Memory |
| Cloud Functions for Firebase | Food estimation, coaching, planning, purchase verification, scheduled automations | The request contents; your context document |
| Google Cloud Vertex AI (Gemini) | Generating estimates and coaching text | The image or text of a request; the context document |
| Firebase Cloud Messaging | Notifications | Push token, time-zone offset, language |
| Firebase Crashlytics | Crash diagnostics | Stack traces, device and OS details, anonymous installation ID |
| Google Analytics for Firebase | Product usage statistics | Typed product events, device model, locale — no advertising ID |
| Firebase Remote Config | Configuration, such as free-tier limits, without an app update | App instance identifier only |
| Firebase App Check (Play Integrity) | Rejecting requests that do not come from a genuine copy of the App | An attestation token issued by Google Play |
| Google Play Billing / Developer API | Selling and verifying Pro | Purchase token, product ID, subscription state |
| Android Health Connect | Reading steps, active energy and weight, with your permission | See Section 9 |
Google’s handling of this data is governed by the Google Privacy Policy and, for the Cloud and Firebase products, the Google Cloud Data Processing Addendum.
13. Data Retention & Account Deletion
13.1 How long we keep things
| Data | Retention |
|---|---|
| Profile, Logged Content, Derived Data, Coach thread and Coach Memory | For as long as your account exists — the point of a diary is being able to look back at it. Deleted immediately when you delete your account. |
| Food photographs | On your device only, until you delete the entry or uninstall the App. No server copy exists. |
| Entitlement and purchase token | While the subscription is active plus the period needed to verify renewals; deleted with your account. Google retains its own billing record independently. |
| Crash reports | Per Firebase Crashlytics retention (up to 90 days), not linked to your diary content. |
| Analytics events | Per the Google Analytics for Firebase retention window configured for the project (up to 14 months), in aggregated form. |
| Support correspondence | Up to 24 months, so we can see the history of an issue. |
13.2 Deleting your account
You can delete your account and all of its data from inside the App: Profile → Settings → Delete account. There is a two-step confirmation, and then deletion is immediate and permanent. There is no grace period and no recovery.
Deletion removes, from our servers, the documents in every one of your account’s collections — profile, diary mirror, scans, meal logs, weight entries, exercise entries, streaks, badges, progress tracking, insights, notifications, analytics records, feature usage, subscriptions, AI context and memory, coach posts and AI reports — and then deletes the underlying authentication account. The local database and cached preferences on your device are wiped in the same operation.
If you cannot open the App — a lost phone, for instance — email us and we will do it for you. Full instructions, and the list of what is kept and why, are on the Delete Your Account page.
15. International Data Transfers
AppskKuber is based in India. The Firestore database for the Service is located in the United States (multi-region nam5), Cloud Functions execute in Google Cloud regions, and Vertex AI processes requests on Google Cloud infrastructure. Your data will therefore be processed outside your country of residence, including in the United States.
For transfers out of the EEA and the UK we rely on the European Commission’s Standard Contractual Clauses as incorporated into the Google Cloud Data Processing Addendum, together with the technical measures described in Section 18. For transfers out of India we rely on the DPDP Act’s permission to transfer to countries not restricted by the Central Government. You may request a copy of the transfer safeguards from our Grievance Officer.
16. Push Notifications & Communications
Notifications are opt-in. The App asks only after you have logged something, so you can judge the value first, and explains what each kind of notification is for.
- Reminders at your own usual meal times, and an evening nudge if the day is still empty. These are scheduled on your device;
- Coaching messages — a morning brief, an evening plan, pattern alerts, a weekly review, and a gentle note if you have been away for three or seven days. These are sent from our server at the local hours stored for you;
- We do not send advertising or third-party marketing, and we do not send promotional email.
Turn them off in the App’s Settings or in Android’s notification settings at any time. Doing so does not affect anything else.
17. Analytics & Telemetry
We use Google Analytics for Firebase and Firebase Crashlytics. Both are configured without any advertising identifier and without Google Signals. The events we record are product events (see Section 4.7), not the contents of your diary: we log that a meal was logged and by which method, not what you ate.
Crash reports contain technical state, not Logged Content. We filter known low-value non-fatal errors (network timeouts, image-decode failures, audio timeouts) so that genuine faults are visible.
18. Data Security
- Encryption in transit for every network call (TLS), and encryption at rest as provided by Google Cloud;
- Per-user isolation enforced server-side. Firestore security rules permit reads and writes only under the signed-in user’s own document tree. One user cannot reach another’s data even with a modified App;
- Cloud file storage entirely closed — all reads and writes denied;
- Firebase App Check with Play Integrity, so backend calls from tampered or emulated clients are rejected;
- Server-side verification of purchases, so Pro cannot be granted by a modified client;
- Obfuscated release builds with symbol files kept privately for crash de-obfuscation;
- Data minimisation — reduced-resolution images, no advertising identifiers, no contact-list or precise-location access, and no third-party SDKs beyond Google’s.
No system is perfectly secure. If you believe you have found a vulnerability, please write to support@snaqly.com with the subject "Security" before disclosing it publicly; we will acknowledge within 72 hours. If a breach ever affects your Personal Data we will notify you and the competent authorities as the applicable law requires.
19. Your Rights & Choices
19.1 Rights you have everywhere, in the App itself
- Access and portability — your diary is visible in the App at all times; email us for a machine-readable export;
- Correction — edit any profile field, and any portion or entry in the diary;
- Granular erasure — delete a single meal, a single weigh-in, or a single remembered fact in the Coach tab, without deleting anything else;
- Full erasure — Profile → Settings → Delete account;
- Withdraw consent — revoke Health Connect access, turn off notifications, or clear the optional health-considerations field.
19.2 Rights under the GDPR / UK GDPR (EEA and UK users)
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)) at any time without affecting the lawfulness of processing before withdrawal. You also have the right not to be subject to a decision based solely on automated processing that produces legal effects — we take no such decisions.
19.3 Rights under the DPDP Act (Indian users)
You have the right to access a summary of your Personal Data and our processing, the right to correction, completion, updating and erasure, the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right of grievance redressal through our Grievance Officer (Section 24) before approaching the Data Protection Board of India.
19.4 Rights under the CCPA / CPRA (California residents)
You have the right to know what Personal Data we collect, use and disclose; the right to delete it; the right to correct it; the right to opt out of sale or sharing (we do neither); the right to limit the use of sensitive personal information (we use it only to provide the Service you requested, which the statute already permits); and the right not to be discriminated against for exercising any of these rights. We do not offer financial incentives for your data. You may use an authorised agent, with proof of authorisation.
19.5 How to exercise a right
The fastest route for erasure is the in-App control. For anything else, email support@snaqly.com with the subject "Privacy Rights Request" from the address on your account. We respond within 30 days (extendable once, with notice, where the law permits). We may ask you to verify control of the account email; we do not ask for identity documents. There is no charge unless a request is manifestly unfounded or excessive.
20. Children’s Privacy
Snaqly is not directed to children. You must be at least 13 years old, or the higher minimum age set by the law of your country (16 in parts of the EEA), to use the Service. We do not knowingly collect Personal Data from children below that age, and we do not use age-gating to serve advertising because we serve none.
Calorie restriction is a genuinely sensitive subject for young people. If you are a parent or guardian and believe a child has created an account, email support@snaqly.com with the subject "Child Account" and we will delete the account and its data promptly and without charge.
21. Medical Disclaimer
Snaqly is not a medical device and does not provide medical advice. Calorie and macronutrient figures are estimates; estimation from a photograph in particular can carry a substantial margin of error, which is why the App lets you correct every portion. Targets, plans, lessons and coach replies are general information, not a diagnosis, treatment, cure or prescription.
Consult a qualified health professional before changing your diet — particularly if you are pregnant or breastfeeding, under 18, have or have had an eating disorder, or manage a condition such as diabetes, thyroid disease, PCOS or kidney disease. Never delay professional advice because of something the App said. In an emergency, contact your local emergency service.
The App applies safety floors to the targets it computes and is instructed never to propose an unsafe deficit, but these are safeguards, not clinical supervision.
22. Do Not Track Signals
The App is not a browser and performs no cross-site tracking, so there is no Do Not Track signal for it to honour. This legal website sets no cookies, runs no analytics, and loads no third-party scripts or fonts.
23. Changes to This Policy
We may update this Policy to reflect changes in the Service or the law. When we do, we revise the "Last Updated" date and the version number in the header. If a change is material — a new category of data, a new purpose, or a new recipient — we will notify you in the App before it takes effect and, where the change relies on consent, ask for your consent afresh. Continued use after the stated effective date constitutes acceptance. Superseded versions are available on request.
24. Contact & Grievance Officer
Data Controller / Data Fiduciary
AppskKuber
Rupesh Patel
5/50/1 Chanakyapuri Colony, Padra
Rewa – 486001, Madhya Pradesh, India
Email: support@snaqly.com
Legal centre: https://legal.snaqly.com
Developer: https://appskuber.com
Grievance Officer (DPDP Act, India)
Name: Rupesh Patel
Designation: Grievance Officer, AppskKuber
Address: 5/50/1 Chanakyapuri Colony, Padra, Rewa – 486001, Madhya Pradesh, India
Email: support@snaqly.com
Subject line: "Privacy Grievance"
Response time: within thirty (30) days of receipt
If you are not satisfied with our Grievance Officer’s response, you may complain to the Data Protection Board of India once it is constituted and operational under the DPDP Act.
Privacy Rights Requests
For a request under any applicable law (DPDP, GDPR, UK GDPR, CCPA/CPRA, COPPA or other), email:
support@snaqly.com
Subject line: "Privacy Rights Request"
Account Deletion
In the App: Profile → Settings → Delete account — immediate and permanent.
If you cannot open the App: email support@snaqly.com with subject "Snaqly account deletion request".
Full details: https://legal.snaqly.com/delete-account
Remember to cancel an active Google Play subscription in Play first — deleting the account does not cancel it.
Supervisory Authority — EEA & UK
EEA and UK users have the right to lodge a complaint with their local supervisory authority. A list of EU authorities is at edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may complain to the Information Commissioner’s Office at ico.org.uk.
California Privacy Rights
California residents may submit verifiable rights requests by emailing support@snaqly.com with the subject "California Privacy Request", and may designate an authorised agent to act on their behalf.
This Privacy Policy is the entire statement between you and AppskKuber regarding the privacy of your Personal Data in the Snaqly Service, and supersedes any prior privacy notice issued for it.