Privacy Policy
Last updated: August 29, 2026
Thali is built by Amelior Labs. We built this app to help the South Asian diaspora track their nutrition with food data that actually reflects how we eat. This policy explains what data we collect, why, and how you control it. Plain language, no lawyer-speak.
1. Who We Are
Thali is a product of Amelior Labs, based in Canada. You can reach us at support@ameliorlabs.ca.
2. Information We Collect
Account data: Email address when you sign up. Used to identify your account and sync your data across devices.
Health and nutrition data: Thali handles the following information:
- Food logs — what you eat, when, and how much. Used to calculate your daily calorie and macro totals.
- Weight logs — your weight entries over time. Used to show your weight trend and calculate your BMI, and to keep your calorie target in step with what is actually happening.
- Waist measurement — optional, and prompted about once a month rather than every time you weigh in. Used to show your waist-to-height ratio alongside your BMI, which is a better indicator of health risk for South Asian adults than weight alone. Nothing in the app requires it and skipping it changes nothing else. Stored with the weight entry it was taken alongside, and deleted with your account.
- Water logs — your daily water intake tracking.
- Body stats — height, age, sex, and activity level entered during onboarding. Used to calculate your personalised calorie target via the Mifflin-St Jeor formula.
- Fasting periods — your active fasting schedule type and window. Used to adapt the daily logging interface during fasts.
- Apple Health / Health Connect activity — only if you choose to connect it. On Android, Thali reads the calories you burn and nothing else. On iOS it also reads your step count, to show a movement ring. Thali no longer reads recorded workouts on either platform. This is read-only: Thali never writes anything back to Apple Health or Health Connect.
- Photos (AI scanning) — photos you take in-app for food identification. Sent to our secure server and passed to a third-party vision model operated by either OpenAI or Google, depending on your account and usage. Photos are not stored after processing.
- Voice recordings — audio you record in the app, either to log a meal or to describe a recipe. Meal-logging audio is transcribed and discarded immediately. Recipe audio, unlike photos, is stored so you can play it back later. Both are sent to our secure server and processed by Google's Gemini API for transcription. Thali records only in the app — there is no way to upload an existing audio file.
This data is stored securely, never sold, and never used for advertising.
What activity data is used for: one thing only — keeping your daily calorie target accurate. Your activity level is set once when you first use the app, and without this it would never change even if your training did. Your activity is not added to your daily calorie allowance as exercise you can eat back: fitness trackers overestimate calorie burn, often substantially, and eating back an overestimate is the most common way calorie tracking goes wrong.
Connecting is optional and Thali works fully without it. You can stop Thali reading at any time from Profile → Activity & Health, and revoke access entirely in your device's Health settings. Deleting your account deletes this data with it. Health data is never shared with any third party and is never used for advertising.
Usage data: Anonymised analytics (screens visited, features used) to understand how the app is being used. Cannot be linked to you personally.
Device data: Device type, OS version, and app version for bug fixing and performance.
3. AI Photo & Voice Processing — How It Works
Photo scanning
When you use the AI food scan feature, your photo is sent over an encrypted connection to our backend server (Convex), which passes it to a third-party vision model for food identification. Two providers are used: OpenAI (GPT-4o) and Google (Gemini). Which one handles a given scan depends on your account and how much you have scanned, so a photo you take may go to either. The following applies:
- Photos are processed in real time and are not stored on our servers after the scan completes.
- Each provider processes the image under its own API terms. Neither trains its models on API inputs under the terms we use.
- Both API keys are held server-side only — neither is ever embedded in the app or exposed to the client.
- Free users get a daily allowance of AI scans, and can earn additional scans by watching a rewarded ad. Premium users get 50 scans per day. Scan counts are enforced server-side.
Voice recording & transcription
When you record audio in the app, it is sent over an encrypted connection to our backend server (Convex), which passes it to Google's Gemini API for transcription. The following applies:
- Unlike photos, voice recordings are stored — in Convex file storage, attached to the recipe — so you can play them back.
- We use a billing-enabled ("paid tier") Google Cloud project for the Gemini API. Under Google's paid-tier terms, Google does not use the audio or transcripts you submit to train or improve its models.
- Our Google API key is held server-side only — it is never embedded in the app or exposed to the client.
Purpose limitation. We use recordings only to convert speech into text. We do not create voiceprints, we do not use voice to identify or authenticate anyone, and we do not perform speaker recognition. Recordings are not analysed for any purpose other than transcribing what was said and letting you play it back.
4. How We Use Your Information
To run the app: Calculate your daily calorie and macro totals, show weekly progress, calculate SA-specific BMI and waist-to-height ratio, and power the food search, AI scanning, and voice recording features.
To personalise your experience: Your calorie target is calculated from your height, weight, age, sex, and activity level. Your fasting mode adapts the daily interface to your schedule.
Voice recordings: used to transcribe what was said, attach that text to the relevant recipe, and let you play the recording back. We do not use voice recordings to build a profile of you, and we do not use them for anything beyond that recipe.
To improve the app: Anonymised analytics help us understand which features are most useful.
5. Data Storage & Security
Your data is stored on Convex servers (US region). Convex uses industry-standard encryption at rest and in transit. We use Convex's built-in authentication and Row Level Security to ensure your data can only be accessed by you. We never see your password — authentication is handled by Convex Auth.
Voice recordings are held as files in Convex's file storage, under the same access controls as the rest of your account — only you can access your recordings.
We never sell your personal data to any third party.
6. Data Retention
We retain your personal data only for as long as necessary to provide the Thali service.
- Active accounts: Your food logs, weight logs, body stats, and fasting periods are retained for as long as your account is active.
- Voice recordings: Retained for as long as the recipe they're attached to exists. Deleting a recipe deletes its voice recording from storage, not just the recipe entry. Deleting your account deletes all of your recordings.
- After account deletion: When you delete your account (Settings → Delete Account), your personal data is permanently deleted within 30 days.
- Encrypted backups: Deleted data may persist in encrypted database backups for up to 90 days, after which it is permanently purged.
- Anonymised analytics: Aggregated, anonymised usage data may be retained indefinitely to help us improve the app.
To request deletion of specific data before account deletion, email support@ameliorlabs.ca and we will respond within 14 days.
If you were nearby while someone recorded and your voice was captured incidentally, you can ask us to delete that recording — email support@ameliorlabs.ca and we will respond within 14 days.
7. Third-Party Services
We use the following services to operate Thali:
- Convex — database, authentication, and backend functions
- OpenAI — AI food identification via GPT-4o vision (photos processed, not stored)
- Google — Gemini API, paid tier. Used for both voice transcription (recordings are stored — see Data Retention above) and, for many scans, food identification from photos (photos not stored).
- Google — AdMob, which serves the ads described in section 8 below
- RevenueCat — subscription management
- Expo — app infrastructure and push notifications
Each provider has their own privacy policy. We share only the minimum data necessary for each service to function.
8. Advertising
Thali shows ads from Google AdMob. Today this means rewarded ads only — an ad you choose to watch in exchange for an extra food scan. You are never required to watch one, and nothing in the app is withheld behind an ad you cannot skip. Premium subscribers see no ads at all.
We do not use your advertising identifier. On Android, Thali does not request the AD_ID permission, so the identifier is returned to the ad SDK as zeroes. On iOS, Thali never asks for App Tracking Transparency permission, so the IDFA is never available to it. The practical result on both platforms is that ads shown in Thali are not personalised and cannot be used to track you across other apps or websites.
AdMob does still receive technical information needed to serve and count an ad — such as device type, coarse location inferred from your IP address, and whether an ad was shown and completed. Google processes that data under its own privacy policy. Ad content is restricted to a G rating, because ad slots in a calorie app sit next to body-weight content and a gambling or weight-loss-scam creative there would be a genuinely bad experience.
What is never used for advertising: the food you log, your weight, waist, BMI or waist-to-height figures, your Apple Health or Health Connect activity, your photos, and your voice recordings. None of it is shared with AdMob or any advertiser, and none of it influences which ads you see.
9. Your Rights
You can access, correct, or delete your personal data at any time. To delete your account, go to Settings → Delete Account in the app. For other requests, email support@ameliorlabs.ca and we'll respond within 14 days.
If you're in Canada, you have rights under PIPEDA. If you're in the EU/EEA, you have rights under GDPR including data portability and the right to object to processing.
10. Children's Privacy
Thali is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, please contact us immediately.
A voice recording made in a kitchen or dining room may incidentally include a child's voice in the background. If that describes a recording on your account, contact us and we'll delete it.
11. Changes to This Policy
We may update this policy as the app evolves. We'll notify you of significant changes via in-app notice. Continued use after changes means acceptance of the updated policy.
12. Contact
Questions about this policy? Email support@ameliorlabs.ca or write to: Amelior Labs, Canada.