Legal
Privacy Policy
Last updated July 27, 2026
1. Who we are
Cloche is a nutrition and longevity tracking service operated by TrueStandard Labs LLC ("Cloche," "we," "us," or "our"), available at heycloche.com. You can reach us at any time at [email protected].
Cloche lets you photograph a meal and receive an AI-generated breakdown of its nutrition — including micronutrients relevant to long-term health — along with trends over time. This policy explains exactly what we collect, where it goes, and what we will never do with it.
2. Our core promise
We do not use your meal photos or your nutrition data to train AI models.
Your meals are yours. We send them to our AI provider to generate your analysis and for no other purpose. We do not sell your personal information, we do not share it with advertisers, and we do not build training datasets or a food corpus out of what you eat.
3. Information we collect
Information you provide
- Account information from Google. Cloche only supports signing in with Google. When you sign in, we receive your name, email address, profile photo URL, and a Google account identifier. We never see or store your Google password.
- Profile details. Your username, and — if you choose to enter them — your date of birth, gender, body weight, and time zone. We use these to make nutrient targets and daily values accurate for you. They are optional; the app works without them.
- Meal photos and meal details. The photographs you upload, plus the meal name, cuisine, date, and any component details or corrections you enter.
- Recipes and grocery items that you create or save.
Information we generate about your meals
For each meal we store the AI-generated nutrition breakdown, the daily-value percentages derived from it, the assumptions the model made (for example, an estimated portion size), and the units used. This is how your timeline, weekly reports, and trends work.
Information collected automatically
- Sign-in records. How many times you have signed in, the timestamps of your current and previous sign-in, and the IP addresses used. We keep these for account security and abuse prevention.
- Server logs. Standard web-server records such as requested URLs, browser user-agent, and timestamps.
Sensitive information — please read
Your body weight, date of birth, gender, and your dietary history are health-related information. Under the California Consumer Privacy Act this may qualify as sensitive personal information. We collect it only to personalize your nutrient targets and insights. We do not use or disclose it to infer characteristics about you for advertising, and we do not sell or share it. If you would rather not provide it, leave those profile fields blank.
4. How we use your information
- To analyze your meal photos and produce your nutrition breakdown.
- To build your meal timeline, weekly digests, and trend reports.
- To authenticate you and keep your account secure.
- To send you service email — a daily roundup of your nutrition and a weekly digest. These go to registered users as part of the Service. We do not send marketing email, and we never add your address to anyone else's list. You can opt out of all email at any time by emailing [email protected], and we will stop sending immediately.
- To operate, debug, and improve the Service — including looking at aggregate, non-identifying usage patterns to decide what to build next.
- To comply with law and to enforce our Terms of Service.
5. What we do not do
- We do not train AI models on your meal photos or nutrition data.
- We do not sell your personal information, and we never have.
- We do not share your personal information with advertisers or data brokers.
- We do not run third-party advertising or behavioral-tracking pixels on the Service.
- We do not use your health information to build advertising profiles.
6. How AI processes your meals
When you upload a meal, the photograph and any description you provide are sent over an encrypted connection to Google's Gemini API, which returns the nutrition analysis you see in the app. Some nutrition features also send text-only questions to the same API. This processing happens in Google's cloud, not on your device — so your meal photo does leave your phone, and we want to be direct about that.
Google processes this data as our service provider in order to return a result. You can read Google's terms for this API in the Gemini API Additional Terms of Service and their Privacy Policy. To restate our promise: neither we nor our AI provider uses your meals to train models under the paid API terms we operate on.
AI-generated nutrition figures are estimates, not laboratory measurements. See our Terms for what that means for how much you should rely on them.
7. Who we share information with
We do not sell your data. We share it only with the service providers who make the app function, and only to the extent each one needs. We name the providers that actually see your meals or identity, and describe the routine infrastructure by category:
| Who | Why | What they receive |
|---|---|---|
| Google (Gemini API) | Generates your meal nutrition analysis | Meal photos and meal descriptions you submit |
| Google (Sign-In) | Authenticates you — the only sign-in method we offer | Your name, email address, profile photo, and account ID |
| Cloud object storage provider | Stores your meal images | Your meal images and their file identifiers |
| Email delivery provider | Sends transactional and digest email | Your email address, name, and the contents of that email |
| Cloud hosting provider | Runs our servers and database | Hosts all of the above; no independent use of your data |
Every provider above is bound to use your information only to deliver their service to us. We may also disclose information if we are legally required to, to protect our rights or someone's safety, or to a successor if the Service is ever transferred — in which case this policy continues to apply to information collected before the transfer.
8. Meals you choose to share publicly
Cloche can generate a shareable link or image for an individual meal. If you use that feature, the meal photo and its nutrition breakdown become viewable by anyone who has the link, without signing in. That is the point of the feature, but it is worth stating plainly: sharing a meal takes it outside your private account. Deleting the meal removes the shared page.
9. Cookies
We use a small number of essential cookies only — the ones that keep you signed in, remember your session, and protect forms against cross-site request forgery. Without them the app cannot work.
We do not run any third-party analytics or advertising cookies. There is no Google Analytics, no Meta Pixel, and no behavioral tracking on Cloche. Because we set no non-essential cookies, there is no cookie consent banner to click through.
10. How long we keep your data
- While your account is active, we keep your meals and profile so your history and trends stay intact.
- Individual meals can be deleted by you at any time from within the app. Deleting a meal removes its record, its nutrition data, and its stored image.
- On account deletion, we delete your account, profile, meals, recipes, and stored images within 30 days of your request.
- Encrypted backups are rotated on a rolling basis, so deleted data may persist in a backup for a short period before being overwritten.
- We may retain minimal records where the law requires it, or to resolve a dispute.
11. Deleting your account
Cloche does not yet have a self-serve "delete my account" button. To delete your account, email [email protected] from the address you signed up with and we will delete it, and everything in it, within 30 days. We will confirm by email when it is done. There is no charge and we will not ask you to justify the request.
12. Your privacy rights
If you are in the EEA, UK, or Switzerland (GDPR)
You have the right to:
- access the personal data we hold about you;
- correct it if it is inaccurate;
- have it erased;
- receive a portable copy of it;
- restrict or object to how we process it; and
- lodge a complaint with your local data protection authority.
Our legal bases for processing are: performance of a contract (delivering the Service you signed up for), legitimate interests (security, abuse prevention, and improving the Service), consent for the optional health details you choose to enter and for digest emails, and legal obligation where applicable. You can withdraw consent at any time.
If you are in California (CCPA/CPRA)
You have the right to:
- know what personal information we collect, use, and disclose;
- delete the personal information we hold about you;
- correct inaccurate personal information;
- opt out of the "sale" or "sharing" of personal information and of the use of sensitive personal information beyond what is necessary to provide the Service — we do not sell or share your personal information, and we use sensitive personal information only to deliver the Service, so there is nothing here for you to opt out of; and
- not be discriminated against for exercising any of these rights. We do not offer financial incentives in exchange for your data.
How to exercise any of these rights
Email [email protected] from your account email address. We respond within 30 days, and we will tell you if we need longer. You may use an authorized agent; we may need to verify their authority.
13. Security
We protect your information with encryption in transit (HTTPS), access controls on our servers and database, hashed credentials, and signed URLs for image access so your meal photos are not publicly enumerable. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach ever affects your personal data, we will notify you and the relevant authorities as required by law.
14. International data transfers
We operate from the United States, and our servers and service providers are located in the United States. If you use Cloche from outside the US, your information is transferred to and processed in the US, where privacy laws may differ from your own. Where required, we rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism.
15. Children
Cloche is intended for adults. You must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, email [email protected] and we will delete it.
16. Changes to this policy
If we change this policy we will update the "Last updated" date above. For changes that materially affect your rights — a new category of data, a new AI provider, or any change to the no-training promise — we will notify you by email or in the app before the change takes effect.
17. Contact us
For any privacy question, request, or complaint: [email protected].
TrueStandard Labs LLC
Operator of Cloche — heycloche.com
See also our Terms of Service.