Privacy Policy
How PushMe collects, processes, and protects your dietary, weight, and fitness information.
Key Takeaway & Guarantee
Your photos are read and discarded — never stored. When you snap a meal, the image is passed via an encrypted connection to our secure AI processing function solely to identify dishes, and then deleted immediately. PushMe does not store your food photos, sell your nutritional data, or track your physical GPS location.
1. Overview and Scope
PushMe ("the App", "we", "us", or "our"), accessible via the website usepushme.com and distributed through the Google Play Store, is an AI-powered calorie tracking and adaptive weekly nutrition coaching application.
We take personal privacy and the sensitivity of personal health data seriously. This Privacy Policy details the types of information we process, how that information is safeguarded, our compliance with applicable data protection regulations including the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA), and your statutory rights to access, rectify, and delete your data.
2. Data We Collect and Why
To provide accurate calorie estimations and weekly adaptive coaching, PushMe processes the following categories of data:
- Onboarding Profile Metrics: Age, biological sex, height, current weight, target weight, general daily activity level, city/region (to localize dish preparation defaults), and home-cooking style (light, normal, or oily). This data establishes your baseline metabolic rate.
- Meal Logs: Text descriptions of foods consumed, place of consumption (e.g., home, street shop, restaurant, hotel buffet), portion answers (e.g., smaller / same / bigger), predicted caloric range, and final saved caloric value.
- Morning Weigh-in Records: Periodic body weight entries used exclusively to smooth weekly weight trends and calculate adaptive calorie target adjustments.
- Anonymous Authentication Identifier: PushMe uses anonymous account generation on initial launch so you can use the application immediately without providing a public email or phone number.
3. Handling of Food Photos — Ephemeral Processing
When you use PushMe's optional camera feature to log a meal:
- The photograph is compressed locally on your device (resized to approximately 800px) to minimize bandwidth.
- The image is transmitted over TLS/HTTPS encryption to our secure cloud Edge Function proxy.
- The AI model processes the image solely to detect visible food items and infer meal portions.
- Immediate Disposal: Once the dish-identification response is received, the photograph is completely purged from server memory. PushMe never writes your meal photos to disk, never archives them, and never trains any model on them. The paid Gemini tier we use excludes your data from Google's product improvement and model training; see section 4.
4. Data Processors and Service Providers
We work with trusted third-party infrastructure providers to host and operate the service under strict confidentiality and data protection agreements:
- Supabase Inc. (Database & Auth Processor): Secure cloud PostgreSQL database hosting your encrypted user profile, meal log numbers, and weigh-in records. Data is protected by Postgres Row Level Security (RLS), ensuring each user can strictly query only their own records.
- Google (Gemini API — meal recognition): Your meal description, and your photo if you send one, are passed to Google's Gemini API purely to identify which dishes are present. PushMe never stores either. We use the paid Gemini API tier, on which Google does not use submitted data to improve its products or train its models — we pay for inference precisely so your meals stay out of anyone's training set. We do not train any model of our own on your data either. If you would still rather no photo of yours left your device, text logging is unlimited, free, and needs no photo.
- Google Play In-App Billing: Handles transaction processing for PushMe Pro subscriptions. We never collect or store credit card numbers or financial credentials.
5. Compliance with Sri Lanka PDPA (2022) & International Laws
Under the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA), biometric and physical health metrics are recognized as special category personal data requiring heightened standards of care. PushMe ensures:
- Explicit Consent: You give explicit consent to process your dietary and weight metrics upon initial application launch.
- Data Minimization: We only collect the minimal parameters required to run the metabolic coaching arithmetic.
- No Telemetry Selling: We do not monetize, rent, or sell your health metrics to data brokers, insurers, or advertising platforms.
6. Android Device Permissions
PushMe requests the following specific runtime permissions on Android devices:
CAMERA(Optional): Required only if you choose to photograph meals for automatic identification. You can fully use PushMe with unlimited text logging without granting camera access.POST_NOTIFICATIONS(Android 13+): Used solely to send your scheduled meal check-ins, morning weigh-in reminders, and weekly coach updates. You can disable notifications anytime in Android Settings.SCHEDULE_EXACT_ALARM: Used to deliver timely reminders with exact precision at the times you configure.
7. Data Retention and Account Deletion
You have full sovereignty over your personal data at all times.
- In-App One-Tap Deletion: You can permanently erase your entire history directly within the app by navigating to Settings → Account → Delete Account & Data. This action immediately purges your profile, meal logs and weigh-ins from your device, and any records held in our database. Note that during the closed beta, cloud sync is not enabled — your logs live on your phone, so uninstalling the app also removes them.
- Web Deletion Route: If you uninstalled the application before deleting your account, visit our public Account Deletion Request Page or email [email protected] to request complete data erasure.
8. Children's Privacy
PushMe is intended for individuals aged 16 and older who train or seek personal nutritional awareness. We do not knowingly collect personal information from children under the age of 16.
9. Contact Information
If you have questions regarding this Privacy Policy, your rights under Sri Lanka PDPA, or wish to exercise your data rights, please contact our Data Protection Officer at:
Email: [email protected]
Website: usepushme.com