Privacy Policy
Last updated: July 22, 2026
Thali is built by Amelior Labs. We built this app to help the South Asian diaspora track their nutrition with food data that actually reflects how we eat. This policy explains what data we collect, why, and how you control it. Plain language, no lawyer-speak.
1. Who We Are
Thali is a product of Amelior Labs, based in Canada. You can reach us at support@ameliorlabs.ca.
2. Information We Collect
Account data: Email address when you sign up. Used to identify your account and sync your data across devices.
Health and nutrition data: Thali handles the following information:
- Food logs — what you eat, when, and how much. Used to calculate your daily calorie and macro totals.
- Weight logs — your weight entries over time. Used to show trends and calculate your BMI.
- Water logs — your daily water intake tracking.
- Body stats — height, age, sex, and activity level entered during onboarding. Used to calculate your personalised calorie target via the Mifflin-St Jeor formula.
- Fasting periods — your active fasting schedule type and window. Used to adapt the daily logging interface during fasts.
- Photos (AI scanning) — photos you take in-app for food identification. Sent to our secure server and processed by OpenAI's vision API. Photos are not stored after processing.
This data is stored securely, never sold, and never used for advertising.
Usage data: Anonymised analytics (screens visited, features used) to understand how the app is being used. Cannot be linked to you personally.
Device data: Device type, OS version, and app version for bug fixing and performance.
3. AI Photo Scanning — How It Works
When you use the AI food scan feature, your photo is sent over an encrypted connection to our backend server (Convex), which passes it to OpenAI's GPT-4o vision API for food identification. The following applies:
- Photos are processed in real time and are not stored on our servers after the scan completes.
- OpenAI processes the image under their API terms. They do not train their models on API inputs by default.
- Your OpenAI API key is held server-side only — it is never embedded in the app or exposed to the client.
- Free users get 3 AI scans per day. Premium users get unlimited scans. The scan count is enforced server-side.
4. How We Use Your Information
To run the app: Calculate your daily calorie and macro totals, show weekly progress, calculate SA-specific BMI, and power the food search and AI scanning features.
To personalise your experience: Your calorie target is calculated from your height, weight, age, sex, and activity level. Your fasting mode adapts the daily interface to your schedule.
To improve the app: Anonymised analytics help us understand which features are most useful.
5. Data Storage & Security
Your data is stored on Convex servers (US region). Convex uses industry-standard encryption at rest and in transit. We use Convex's built-in authentication and Row Level Security to ensure your data can only be accessed by you. We never see your password — authentication is handled by Convex Auth.
We never sell your personal data to any third party.
6. Data Retention
We retain your personal data only for as long as necessary to provide the Thali service.
- Active accounts: Your food logs, weight logs, body stats, and fasting periods are retained for as long as your account is active.
- After account deletion: When you delete your account (Settings → Delete Account), your personal data is permanently deleted within 30 days.
- Encrypted backups: Deleted data may persist in encrypted database backups for up to 90 days, after which it is permanently purged.
- Anonymised analytics: Aggregated, anonymised usage data may be retained indefinitely to help us improve the app.
To request deletion of specific data before account deletion, email support@ameliorlabs.ca and we will respond within 14 days.
7. Third-Party Services
We use the following services to operate Thali:
- Convex — database, authentication, and backend functions
- OpenAI — AI food identification via GPT-4o vision (photos processed, not stored)
- RevenueCat — subscription management
- Expo — app infrastructure and push notifications
Each provider has their own privacy policy. We share only the minimum data necessary for each service to function.
8. Your Rights
You can access, correct, or delete your personal data at any time. To delete your account, go to Settings → Delete Account in the app. For other requests, email support@ameliorlabs.ca and we'll respond within 14 days.
If you're in Canada, you have rights under PIPEDA. If you're in the EU/EEA, you have rights under GDPR including data portability and the right to object to processing.
9. Children's Privacy
Thali is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, please contact us immediately.
10. Changes to This Policy
We may update this policy as the app evolves. We'll notify you of significant changes via in-app notice. Continued use after changes means acceptance of the updated policy.
11. Contact
Questions about this policy? Email support@ameliorlabs.ca or write to: Amelior Labs, Canada.