Tastelog

Tastelog Privacy Policy

Last updated: 22 August 2026

Tastelog is a private food diary. You photograph meals you want to remember, and the app keeps them for you. This page explains exactly what it stores, where that lives, and who else ever sees it.

It is written to be checked against the app’s behaviour, not to be comprehensive-sounding. If something here turns out not to match what the app does, the app is wrong and we will fix it.


Who we are

Tastelog is made by Bo Zou, an individual developer.

Questions, requests, or anything about your data: support@tastelogapp.com


Accounts are anonymous by default

Tastelog does not ask for your name, email address, phone number, or a password to start. When you first open the app it creates an anonymous account — a random identifier that ties your diary to your device. We cannot tell who you are from it.

You can optionally attach a sign-in method (Apple, Google, or email) to that same account — some friend features ask you to. If you do, we store the email address the sign-in provider gives us; it is used to sign you back in, and for nothing else. Attaching a sign-in is also what makes your diary recoverable on a new device.

If you never attach one, your diary is not recoverable. If you delete the app or lose the device, the anonymous identifier goes with it and there is no way for us to restore your memories or prove they were yours.


What Tastelog stores

Everything below is created by you and stored so the app can show it back to you.

Your meal photos and videos. When you save a memory, the photos and videos you chose are uploaded and stored. They are held in a private bucket and served to your device through short-lived signed links, not public URLs.

What you write. Notes, ratings and verdicts, dish names, occasions, and the names or labels you attach to the people you ate with. If you type a companion’s name, that name is stored. Please only write what you would be comfortable having stored on our behalf.

Where and when. The date and time of a meal, and its coordinates. Location comes from either the photo’s own EXIF data or, if you allow it, your device’s current location at the moment you save. Location is used to work out which restaurant a memory belongs to and to place pins on your map. It is never collected in the background, and never while the app is closed.

Weather at the time. Derived from the coordinates and timestamp above, so a memory can remember that it was raining.

Which restaurant a memory belongs to, once you confirm or correct it.


The wall is the one public thing

Everything above is private by default. The single exception is the wall: if you explicitly choose to pin a photo to a restaurant’s wall, that photo is copied into a public bucket and served from a public URL.

That means it is reachable by anyone who has the link, whether or not they use Tastelog, and it may be cached by third parties. Unpinning removes it from our storage, but we cannot un-cache a copy someone else already took. Treat pinning as publishing.

Nothing is ever pinned automatically. It is always a deliberate, per-photo action.


Permissions the app asks for

Photo library. So you can choose meal photos. Tastelog only receives the photos you actually select.

Camera and microphone. Only while you are actively taking a photo or recording a video inside the app.

Location, while using the app. Only to guess which restaurant you are at when saving a meal. There is no background location tracking.

You can refuse or revoke any of these in iOS Settings. Refusing location means you place memories manually; everything else still works.


Who else sees your data

Tastelog is a solo project built on other people’s infrastructure. These are all of them.

Supabase — hosts the database, file storage, and anonymous authentication. Data is stored in the United States. Supabase holds everything listed above.

Anthropic (Claude) — writes the reflective parts of the app: the taste portrait, dish suggestions, and the extraction of food-related detail from your notes. This means the text of notes you write is sent to Anthropic, along with diary-derived summaries such as which places and dishes you have liked.

OpenAI — generates the text embeddings that make your diary searchable by meaning rather than by exact words, and profiles restaurants. It receives restaurant and dish text, and also a composed description of each memory that includes the note you wrote, verbatim, along with the place, dishes, occasion, companions and weather. What comes back and is stored is the embedding — a list of numbers — not a second copy of what you wrote.

Google — two separate uses. Maps renders the map on your device, so Google receives map interaction data directly from the app. Places supplies nearby restaurant data; those lookups are made by our server, so Google receives coordinates and search terms but never your photos and never a device identifier from us.

Google Gemini and Openverse — used to obtain illustrative photographs of dishes for the suggestions feature. They receive dish names only. No user content of any kind is sent.

Open-Meteo and Photon/Komoot — receive coordinates and a timestamp to return historical weather and a place name. Nothing else.

We do not use analytics or advertising SDKs, we do not track you across other apps or websites, and we do not sell your data or share it for advertising.


Photos and AI

Your meal photos are stored so the app can show them to you. They are not sent to any AI service, and they are not used to train anyone’s models.

The text you write is different, and is covered above: notes go to Anthropic in order to produce the portrait and suggestions, and to OpenAI in order to make your diary searchable by meaning.


How long it is kept

Your memories are kept until you delete them. Deleting a memory removes its photos from storage. Unpinning a wall photo removes the public copy.

If you want everything gone, use Delete account in the app (profile → edit → the ⋯ menu). It erases your account and everything attached to it — memories, photos, wall pins, comments — from our systems. Because accounts can be anonymous, we may have no other way to identify your data on request; the in-app deletion is the reliable path, and you can also write to us and we will delete what you can point us to.


Children

Tastelog is not directed at children under 13, and we do not knowingly collect their data.


Under active development

Tastelog is under active development. Features change, and the data it stores may change with them. Material changes will be reflected here with a new date at the top, and where the change meaningfully affects your privacy we will say so in the app.


Changes

If this policy changes, the date at the top changes. Continuing to use Tastelog after a change means the updated version applies.