Countwell · Legal

Privacy policy

Last updated July 18, 2026

Countwell is a food journal made by Eunoia, available as an iPhone app and at countwell.app. This policy covers both, plus this website. It describes what we collect, why, who ever sees it, and how to get rid of it. The data in your journal is yours: we store what you log so we can show it back to you, and nothing in this product is built on selling or advertising against your data.

The short version

  • We collect what you give us to run a food journal — nothing more.
  • We never sell your data, show ads, or track you across other apps and sites.
  • Health data is never used for advertising and never shared for marketing.
  • AI features are off until you consent; Countwell never trains models on your data.
  • You can export everything, and deleting your account deletes everything.

1. What we collect

Information you give us

Account: your email and name, via our sign-in provider (WorkOS). Your plan: the answers you give during setup — age range, height, weight, and goals — used to compute your calorie and nutrient targets. Your journal: the foods you log with their portions and nutrition, weights, goals, saved meals, and preferences like reminders and timezone. Together, your plan and journal are information about your health, and we treat them with that sensitivity throughout this policy.

Information collected automatically

Diagnostics: basic server logs (IP address, user agent, request timing) kept briefly for security and debugging. Website analytics: countwell.app asks before loading two privacy-limited tools: Google Analytics (which counts visits) and PostHog (product analytics hosted in the EU, which counts steps like starting the quiz, finishing onboarding, or opening the upgrade screen so we can see where the website is confusing). Both load only if you agree, and if you decline, or your browser sends Global Privacy Control or Do Not Track, neither is loaded. We send PostHog only these event counts and, once you have an account, your opaque account id. We never send it the contents of your journal: no food entries, weight values, or notes, and it is configured not to record your screen or read the page. Measurement covers the website only; the iPhone app contains no analytics or advertising SDKs.

Information from integrations you turn on

Apple Health: with your permission, weight readings and daily step counts you import (see section 5). Subscription status: we give RevenueCat your stable Countwell account identifier and email so purchased or complimentary Premium access stays attached to the right account across devices. If you subscribe, Apple processes an App Store purchase; RevenueCat and its payment provider Stripe process a web purchase. We do not receive your full card number; RevenueCat tells us whether your subscription is active and where you can manage it.

Voice search

If you tap the microphone in a search field, your device or browser's speech recognition service transcribes the short phrase you speak. Depending on your device and language, that processing may happen on-device or through Apple or your browser provider. Countwell receives only the resulting search text, never stores the audio, and does not add anything to your journal until you choose a result.

What we never collect

Your location, your contacts, advertising identifiers, or anything about what you do in other apps or on other sites.

2. How we use your information

We use the information above to:

  • run the service — store your journal and show it back to you on your devices;
  • compute and adjust your calorie and nutrient targets from your plan answers;
  • answer requests you make, like an AI photo estimate or a coach share link;
  • send the reminders you've asked for;
  • keep the service secure, debug problems, and prevent abuse;
  • meet legal obligations, when we genuinely have to.

That's the whole list. We don't use your data for advertising, we don't build marketing profiles, and Countwell never uses your journal or photos to train models.

3. Who your data is shared with

Processors that run the service

A small set of companies process data on our behalf, under our instructions, and only to run Countwell: Neon (database, hosted in the United States), Vercel (hosting), WorkOS (sign-in), RevenueCat and Stripe (subscriptions and web payments), and—only after website consent—Google Analytics (site measurement). When you search foods or scan a barcode, the search text or barcode number — never your identity or your journal — is sent to FatSecret, our licensed food database, to return matches. When you request an AI meal estimate, the submitted description or photo is sent toGoogle Gemini to produce that estimate.

Sharing you control

Coach links: share links are created only by you, show only what you chose to include, and can be revoked at any time. Anyone with the link can view that data until it expires or you revoke it — treat the link like the data it unlocks. AI connections: you can connect AI apps (Claude, ChatGPT, and others) to your journal. A connection only exists if you approve it, you choose whether it can read or also write, and you can review and disconnect every connection at any time from your account page or the app's AI Connections screen. What a connected app does with data you let it read is governed by its own privacy policy — review it before connecting.

Everyone else

We don't sell personal information, we don't share it for advertising, and no third party gets your health data for marketing — ever. We would disclose data only if the law genuinely compelled us to, or as part of a sale of the business, in which case this policy would continue to protect it and we'd tell you first.

4. AI features, always with your consent

If you use the camera to log a meal, the photo is sent to our servers and then to an AI processing partner to estimate what is on the plate. This never happens silently: the feature is off until you explicitly agree in the app. Countwell processes the photo in memory for your request and does not retain it on our servers. Google states that data sent through its paid Gemini API services is not used to improve its products, although limited prompts and responses may be retained for abuse monitoring under Google's service terms. Countwell never uses your content to train a model. The thumbnail shown with the logged entry is a separate copy that stays on your device until you delete that entry. You can stop using AI features at any time and contact us with a privacy request.

5. Apple Health

On iPhone, with your permission, Countwell reads your weight and step count from Apple Health and writes the meals you log back to Apple Health. Weight readings and daily step counts you import sync to your Countwell account so your progress charts work on the web too. Health data is never used for advertising, never sold, never shared with anyone beyond the processors in section 3, and never sent to our AI provider. You can turn Health access off anytime in iOS Settings.

6. Security

Your data is encrypted in transit everywhere, stored with established cloud providers, and reachable only through your signed-in account. Coach-link tokens are stored hashed, so even our database can't reveal a live link. No service can promise perfect security, but the surface area here is deliberately small: one journal, a handful of processors, no data resale anywhere in the chain.

7. Retention and deletion

We keep your journal for as long as you have an account, so it's there when you come back. Server logs expire on their own within days. You can export everything as CSV or JSON from your account page whenever you like, and you can delete your account — from the app or your account page — which permanently removes your journal, weights, goals, share links, and AI connections. We also request deletion of your WorkOS sign-in identity. If that provider call is temporarily unavailable, we retain only the provider identifier and cleanup status needed to retry; it cannot be used to recreate your Countwell journal. A completed cleanup tombstone is deleted within 30 days.

8. Children

Countwell is for adults age 18 or older and isn't directed at children. We don't knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we'll delete it.

9. Where your data is processed

We operate from the United States and our processors store data there. If you use Countwell from elsewhere, your data is transferred to and processed on U.S. servers, protected by the commitments in this policy and our contracts with each processor.

10. Your rights

Access, correction, export, and deletion are built into the product — you don't need to ask us. Depending on where you live (for example the EU, UK, or California), you may have additional legal rights, like objecting to certain processing, asking what we hold about you, or lodging a complaint with your local data-protection authority. We don't sell personal information or share it for cross-context advertising, so there's nothing to opt out of. For anything you can't do in the product, email countwell@eunoia.so — we'll verify it's you and respond within the timelines your law requires, and exercising your rights never affects the service you get.

11. Not medical advice

Countwell shows estimates — of calories, nutrients, and targets. It is not a medical device and its numbers are not medical advice. Talk to a professional about diagnosis, treatment, or eating-disorder concerns.

12. Changes and contact

If we change this policy in a way that matters, we'll say so in the app before it takes effect, and this page always shows the current version and date. Privacy questions or requests: countwell@eunoia.so.