Privacy Policy

Last updated: 16 July 2026

Kidney Lens is an observational food and nutrient log for discussion with your care team — not a diagnosis and not a dose recommendation. It shows potassium, phosphorus, sodium, and protein as honest ranges from government nutrient data, never a verdict on a food and never a personal nutrient limit — your renal dietitian sets your targets.

Health and account data

Kidney Lens is local-first. Your food, fluid, medication, and target logs are stored on your device. Server-side records may include your Sign in with Apple account identifier, refresh tokens, subscription entitlement status, consent history, and a daily photo-scan allowance.

AI providers and consent

Photo scanning is optional. In the current version, Kidney Lens sends your meal photo and any optional note you add to OpenAI to identify foods and estimate a rough portion. Kidney Lens does not send new scan data to DeepSeek in the current version.

We do not retain your meal photo or optional note in the Kidney Lens app database after servicing the scan request. OpenAI states that data sent to its API is not used to train or improve OpenAI models by default unless a customer opts in. Its standard abuse-monitoring logs may include customer content and related metadata and may be retained for up to 30 days, subject to OpenAI's stated legal and safety exceptions.

Earlier Kidney Lens versions may have sent recognized food names to DeepSeek under their prior disclosure. Updating the app or withdrawing scan consent blocks future requests, but cannot retrieve data already received by a third-party processor.

Nutrient values come from public government nutrient data, not either provider.

Meal photo and scan data

Kidney Lens does not retain your meal photo or optional note in its own app database after handling the scan request. The current version does not retain photo-scan corrections in its server database or use them to personalize later v2 scans.

Barcode lookup and device cache

Packaged-food barcode lookup sends only the product GTIN to USDA FoodData Central and accepts only an exact branded-product match. Public product facts may be cached on your device for offline use and in a shared server cache by GTIN. These caches contain no account identifier, meal photo, food log, note, or health data.

Operational scan economics

We keep daily aggregate counts of model attempts, outcomes, token totals, and estimated cost so we can operate the paid scanner sustainably. These aggregates contain no user, device, advertising, request, food, prompt, photo, note, or health-data identifier and cannot be joined back to your account or logs.

Photo-scan allowance

A daily photo-scan allowance is used when secure image analysis begins, including when an image cannot be identified as food. Label, barcode, and manual logging do not use this allowance.

Payments

Subscriptions are processed by Apple StoreKit. The server verifies signed StoreKit transactions and App Store Server Notifications to keep entitlement status current. We do not receive payment card details.

Export and deletion

You can export your app data on-device. You can delete your account and server-held data from the app; deletion revokes refresh tokens and removes Kidney Lens server-held account and scan-service records tied to your account, including consent records, short-lived consent-dispatch leases, entitlement rows, and scan counters. It does not delete data a third-party processor may retain under its own policy.

Contact

Email nora@halehearth.com for privacy requests or support.

Back to Kidney Lens