Skip to content

Privacy Policy

Micheal Waltz edited this page Jul 20, 2026 · 7 revisions

Onigiri Privacy Policy

The canonical copy lives at https://ecliptik.github.io/onigiri/privacy/ β€” this page mirrors it.

Last updated: July 20, 2026

Onigiri is a calorie, nutrition, and water tracker for iPhone, iPad, and Apple Watch. It is built so that your data stays yours.

The short version

  • Your logs live in Apple Health on your device. We never see them.
  • Onigiri has no accounts, no analytics, no ads, and no servers.
  • By default, no data is sent to third parties β€” everything remains on your device. Online food lookups (the search text or barcode sent to public food databases) and the AI features are both off until you turn them on β€” offered once during onboarding, changeable anytime in Settings.

Health data

With your permission, Onigiri reads and writes Apple Health (HealthKit) data: dietary energy, nutrients, sodium, water, body weight, and energy burned. This data is stored by Apple Health on your device and synced between your devices by Apple, under Apple's protections. Onigiri never transmits Health data anywhere, never shares it with third parties, and never uses it for advertising or research. Deleting the app leaves your Health data intact in Apple Health; you can also revoke Onigiri's access at any time in the Health app (Profile β†’ Apps β†’ Onigiri).

Food database lookups

Online lookups are off by default β€” with them off, food search uses only your saved library and the scanner reads nutrition labels on-device. When you turn them on (onboarding or Settings β†’ Online Database), searching or scanning a barcode sends only the search text or barcode to one of two public services, per your Settings:

  • Open Food Facts β€” barcode scans and text search. Data licensed under the Open Database License (ODbL).
  • USDA FoodData Central β€” optional text search, used only if you supply your own free api.data.gov key. Your key is stored in the device Keychain and sent only to USDA.

These requests include no Health data, no identity, and no identifiers beyond your device's network address, which every internet request carries. Each service's own privacy policy governs what it does with queries it receives.

AI features (optional)

Onigiri's AI features β€” food estimates, meal-name suggestions, nutrition-label reading, and Identify Food β€” are off by default. Nothing AI-related runs until you turn the switch on in Settings β†’ AI. When you do, they run on-device through Apple Intelligence on devices that support it β€” on that setting, no data is sent to third parties and everything remains on your iPhone.

Two of these features are hybrids with an on-device first stage that runs no matter which provider you pick: nutrition labels are read by Apple's on-device text recognition first, and the AI only fills in values the local reader missed; food photos are screened by Apple's on-device image classifier before anything is identified. Barcode scans never use AI at all. With the default Apple Intelligence engine, every stage stays on the phone.

In Settings you can instead bring your own AI provider. When you do, those features send only the text you typed, the label transcript being read, or the photo being identified to the provider you configured, under your own API key:

  • Anthropic β€” your Anthropic API key, sent only to Anthropic.
  • OpenAI β€” your OpenAI API key, sent only to OpenAI.
  • A local server you run (Ollama, LM Studio, or any OpenAI-compatible endpoint) β€” requests go only to the address you configure, typically on your own network, and to nowhere else.

API keys are stored in the device Keychain, are never included in backups or library exports, and are sent only to their own provider. These requests carry no Health data and no identity. Each provider's own privacy policy governs what it does with the content it receives. AI providers are off unless you configure one β€” deleting the provider's key or switching back to Apple Intelligence stops all AI traffic immediately.

What Onigiri stores on your device

Your food and meal library, goals, and preferences are stored locally (and shared with the app's own widgets and watch app). Library backups are saved to the app's Documents folder under your control, visible in the Files app. Nothing is uploaded.

Data collection

Onigiri collects no data. There are no analytics or crash-reporting SDKs, no advertising identifiers, and no tracking.

Not medical advice

Calorie budgets, deficit targets, and weight projections are informational estimates computed from your own numbers. They are not medical advice. Consult a qualified professional before making significant changes to your diet or exercise.

Contact

Questions or concerns: open an issue on the project repository.

Changes

Material changes to this policy will be noted in the app's release notes and on this page.