SoHow is a nutrition, fasting, and wellbeing app designed around a simple privacy principle: your health data stays on your device. We don't run servers that store your data, we don't make you create an account, and we never receive a copy of what you log. This policy explains exactly what that means.
In this policy, "SoHow," "we," "us" refers to Maru Ventures Pte Ltd, the developer of the SoHow iOS app.
1. The short version
- Your meals, photos, profile, weight, fasting, and mood data are stored locally on your iPhone.
- We don't operate servers that store your meals, photos, health data or profile, and we don't create accounts or ask for your name, email, or phone number.
- We never sell or share your data, and we don't use it for advertising or cross-app tracking.
- The only time your content leaves your device is when you trigger it: a barcode lookup, or Enhanced AI (cloud meal analysis), which you can turn off. Both are described below.
- Separately, the app sends anonymous feature-usage counts (for example "a meal was logged") to our analytics provider, so we can see which parts of SoHow people actually use. These carry no meal, photo or health content and nothing that identifies you, and you can switch them off in Profile → Settings → Data & privacy.
2. Information processed on your device
SoHow stores the following only on your device (using Apple's on-device SwiftData framework):
- Profile you enter: sex, age, height, weight, target weight, activity level, and goal.
- Meals you log: photos, identified ingredients, and nutrition values.
- Activity & wellbeing: fasting sessions, weight history, and mood / wellbeing check-ins.
- Apple Health metrics you explicitly authorize SoHow to read or write.
Because this data is processed on-device, we do not have access to it.
3. Where your data lives
All of the above is stored locally on your iPhone. SoHow does not upload, transmit, or back it up to any server we control. If you have iCloud Backup enabled for SoHow, your device backup may include this data — that backup is governed by your agreement with Apple, not by us.
4. When information leaves your device (third-party services)
SoHow uses a small number of third-party services, each for one specific purpose. Everything involving your content happens only when you trigger it; the one exception is the anonymous usage analytics at the end of this list, which runs in the background until you turn it off:
- Apple Intelligence (Foundation Models) & Vision — on device. Meal photos and descriptions are analyzed entirely on your iPhone by default. Nothing is sent anywhere for the standard, on-device analysis.
- Open Food Facts (world.openfoodfacts.org). When you scan a product barcode, we send only the barcode number to look up product data. No personal data is sent.
- Enhanced AI (cloud) via OpenRouter (openrouter.ai). SoHow offers a more accurate, cloud-based meal analysis called Enhanced AI. During your free trial and with SoHow Pro, Enhanced AI is on by default so you get the best results. When it is on, a compressed photo of the meal you are logging is sent to OpenRouter to generate a nutrition estimate for that meal. The image is used only to analyze that meal and is not used to identify you. OpenRouter's handling of the request is subject to its own privacy policy (openrouter.ai/privacy). You can turn Enhanced AI off at any time (Profile → Enhanced AI) to keep all analysis on your device. After the trial, if you don't subscribe, analysis returns to on-device only.
- Enhanced AI also covers typed/dictated descriptions, the menu scanner, the in-app Companion, and Import. The same on/off setting applies when you type or dictate a meal description instead of taking a photo, and to the menu scanner (which sends only the text found on the menu, not the photo). SoHow's in-app Companion, when you ask it something, sends your question and a short summary of figures already computed from your own logged data (such as a nutrient total or a dish you've logged before) — not a raw export of your data. Importing data from another app may send a small text sample of that file to OpenRouter to help identify its columns, but only if on-device analysis isn't available and only with Enhanced AI access.
- Dietary Supplement Label Database (DSLD, api.ods.od.nih.gov) — US National Institutes of Health. Looking up a supplement by barcode or name that isn't in SoHow's bundled database sends only the barcode or the name you typed to this free, public NIH database.
- Apple HealthKit. Reads and writes only the metrics you explicitly authorize, directly through Apple's framework. Apple Health data is never sent to us or to any third party. (Per Apple's rules, HealthKit data is never used for advertising or sold.)
- Apple App Store / StoreKit. Subscriptions and the free trial are handled by Apple. We don't receive your payment details; Apple shares only anonymized/aggregate purchase information with developers.
- PostHog (EU-hosted) — anonymous product analytics. So we can tell which features are worth building on, the app sends counts of anonymous events — things like "onboarding finished", "a meal was logged", "a fast completed" — together with coarse buckets (for example a streak band such as "3–6 days", never the exact number). It never includes your meals, photos, food names, weight, mood, or any Apple Health data, and it carries no name, email, device ID or advertising identifier. Each install gets a random ID that is not linked to you and is regenerated if you delete your data, and profiles are explicitly disabled, so the events cannot be assembled into a picture of a person. Data is processed on EU servers. You can turn this off at any time: Profile → Settings → Data & privacy → Share anonymous usage statistics. Turning it off stops all sending immediately, and that choice survives "Delete all my data" — we will not quietly switch it back on.
5. What we do NOT do
- We don't create accounts or collect your name, email address, or phone number.
- We don't sell or share your personal information.
- We don't use your data for advertising, and we don't track you across other apps or websites.
- We don't build profiles of you. We do use anonymous product analytics (§4) — but with person-profiles switched off, no identifiers, and no meal or health content, so there is nothing to profile. We include no third-party advertising trackers and no ad SDKs of any kind.
6. Health data is sensitive
Much of what SoHow handles (nutrition, body metrics, mood, Apple Health) is sensitive / special-category data. That's precisely why SoHow is built to keep it on your device and out of our hands. We process it only to provide the app's features to you.
7. Data retention
Your data remains on your device until you remove it. You can edit or delete any entry in the app, and deleting the app removes all locally-stored SoHow data. Because we don't store your meals, photos, health data or profile on our servers, there's nothing of yours for us to retain or delete on our side.
The one exception is the anonymous usage events in §4. Those are held by our analytics provider on EU servers so we can see how features perform over time. They contain nothing that identifies you and cannot be traced back to a person — which also means we cannot single out "your" events to delete on request. If you'd rather not contribute them at all, switch them off: Profile → Settings → Data & privacy → Share anonymous usage statistics.
8. Security
Your data benefits from your iPhone's built-in security (device encryption, app sandboxing, and Face ID/Touch ID/passcode protection at the OS level). Enhanced AI requests are sent over encrypted connections (HTTPS).
9. Your rights & choices
You are in control:
- Access & portability: export your full dataset as CSV (Profile → Your data → Export).
- Rectification: edit any entry in the app.
- Erasure: delete entries individually, or uninstall to remove everything.
- Opt out of cloud processing: turn Enhanced AI off in Profile.
- Opt out of anonymous analytics: Profile → Settings → Data & privacy → Share anonymous usage statistics.
- Manage Apple Health sharing: Settings → Health → Data Access & Devices → SoHow.
See Your Privacy Choices for a step-by-step guide.
EEA / UK (GDPR): our legal basis for processing is performing the service you request (and your consent for optional Enhanced AI). Because we don't hold your data, most rights (access, deletion, portability) are exercised directly in the app. You also have the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): we do not sell or share personal information and have not in the prior 12 months. California residents have rights to know, delete, and correct — see Your Privacy Choices.
10. Children
SoHow is not intended for users under 16, and we do not knowingly collect data from children.
11. International users
SoHow runs on your device wherever you are. If you enable Enhanced AI, that meal image is processed by OpenRouter, which may operate servers outside your country; enabling Enhanced AI is your choice.
12. Changes to this policy
We may update this policy as the app evolves. We'll change the "Last updated" date above and, for material changes, surface a notice in the app.
13. Contact
Questions or privacy requests: privacy@sohow.app (or support@sohow.app).
Maru Ventures Pte Ltd, Singapore.