Skip to content

Privacy Policy

Last updated 21 August 2026

This Privacy Policy describes how Portion.inc collects, uses, and protects personal data when you use the Portion app. By using the app, you agree to the practices described here.

Data Controller

The data controller for personal data processed through the Portion app is Portion.inc. Direct any questions or requests regarding data processing to mail@myportion.app.

Data we collect

  • Google account data when you sign in with Google: email address, display name, profile photo, and Google account identifier (sub).
  • Food photos you upload for analysis.
  • Optional text notes and voice transcripts you attach to a photo.
  • Analysis results and meal history: plate scores, nutrient levels, meal timestamps.
  • Selected interface language.
  • Technical session data: IP address and user-agent, used for security and abuse prevention.
  • Legacy browser device identifier stored in localStorage (deprecated; kept only to link existing data to your account).
  • AI usage counters: token volume per day and per endpoint, used to enforce fair-use limits.

Why we use your data

  • To analyse food photos and generate balanced-plate recommendations.
  • To maintain your meal history and keep it synced across your devices.
  • To authenticate you and maintain an active session.
  • To prevent abuse and enforce usage limits.
  • To support and improve the service.

Legal bases (GDPR)

  • Performance of a contract (Art. 6(1)(b)) — providing the service you requested: analysis, history, authentication.
  • Legitimate interest (Art. 6(1)(f)) — security, abuse prevention, service integrity, and measuring how the marketing site is used in aggregate: visit counts, referrers, and page-load performance, with no cookie and nothing written to your browser (see Cookies). You can object to this at any time by writing to us.
  • Consent (Art. 6(1)(a)) — session recordings and heatmaps on the marketing site (see Cookies), and any other optional feature where we ask. Withdrawing it is one click in Cookie settings in the site footer.

Third parties and sub-processors

We share data only with the providers necessary to run the service:

  • Google LLC — Sign in with Google authentication.
  • OpenRouter and Google (Gemini models via OpenRouter) — your food photos and notes are transmitted to the AI provider to generate recommendations. Data is processed solely for this purpose.
  • Cloudflare, Inc. — hosts the web app (Cloudflare Pages), this marketing site, stores meal photos (Cloudflare R2 object storage), and provides cookieless site analytics (see Cookies).
  • Railway — hosts the backend API and the PostgreSQL database that holds your meal history and profile.
  • Microsoft Corporation — Microsoft Clarity, on this marketing site only, and only if you accept cookies. Microsoft acts as an independent controller rather than our processor (see Cookies).

What your referrer sees

If you sign up through somebody’s invite link, their invites screen lists you: your first name if we have one, otherwise the email address you signed up with, plus whether you are still on the free window that invite gave you and whether you have subscribed. Nothing else about you — no photos, no meals, no weight, no activity — is ever visible to them.

We show the address because it is often the only thing that tells two invited friends apart. If you would rather not be identifiable there, set a display name in the app, or delete your account (see Your rights) — the invite row goes with it.

How we handle your photos

Photos are resized on your device before upload to reduce data transfer. They are stored in Cloudflare R2 as the primary source of truth, enabling cross-device history, and cached locally in your browser’s IndexedDB for fast offline access.

For analysis, photos are transmitted to the AI provider (see Third parties). If cloud storage is unavailable, the meal is still saved to the database without a photo — the degradation does not block core functionality.

Cookies and local storage

We use one strictly necessary first-party session cookie — __Host-portion_session — to authenticate you in the app. It is HttpOnly, Secure, SameSite=Lax, and expires after approximately 30 days of inactivity.

Functional browser storage (localStorage, sessionStorage, IndexedDB) is used to remember your language preference, onboarding state, and to cache meal photos locally.

If you arrive through someone’s invite link (myportion.app/i/CODE), that page sets one further first-party cookie — portion_ref — on .myportion.app for 30 days. It holds only the invite code you clicked, so the app can still recognise the invitation if you open it later rather than straight away. It is functional, not analytics: it says nothing about you, follows you nowhere, and is not affected by your answer to the cookie banner. It is discarded once the invitation has been applied to your account.

Analytics runs on this marketing site (myportion.app) only — never inside the app itself, and never on your meal data. Two services, with deliberately different deals:

  • Cloudflare Web Analytics — page views, referrers, and page-load performance. It sets no cookie, writes nothing to your browser’s storage, and does not identify you or follow you anywhere, so it needs no consent and is not affected by your answer to the banner.
  • Microsoft Clarity — session recordings and heatmaps: scrolling, clicks, and where a page loses people, which is how we learn what to fix. It runs only if you choose Accept all, and then sets the cookies _clck, _clsk, and CLID to recognise one visit across pages. Text you type is masked before it leaves your browser, including the email field — the only input on the site. Advertising storage is switched off, so Clarity passes no identifiers to Microsoft Advertising.

For Clarity, Microsoft acts as an independent controller, not as our processor. That means Microsoft decides for itself how the data it collects is used, which by its own terms includes improving Microsoft products and services and advertising — see the Microsoft Privacy Statement. We think the tool is worth it; you may not. Choosing Reject all means nothing from Clarity loads at all — not in a reduced form, not without cookies — and the site works exactly the same.

Your answer is stored in one further first-party cookie — portion_consent — for six months, together with the date you gave it and the version of this policy it was given under. You can change it at any time through Cookie settings in the site footer; withdrawing consent deletes Clarity’s cookies and stops the recording. If this policy changes materially we ask again.

How long we keep your data

Your meals, photos, and profile are retained for as long as you use the app. Sessions expire automatically after approximately 30 days of inactivity. Minimal technical logs are kept for a limited period for security purposes only.

Two small records outlive a deleted account, and only these two. If you delete your account we keep your email address, the identifier of the account you signed in with, and the date — for up to 12 months — so that a free trial cannot be claimed a second time by signing up again; it holds nothing about what you did in the app, and after 12 months it is deleted. Separately, if you unsubscribe from our emails or a message to you bounces, your address stays on a do-not-mail list indefinitely: deleting that record on account deletion would let a re-registration start the mail again, which is exactly what it exists to prevent.

To delete your data or account, contact us at mail@myportion.app.

Your rights

Under the GDPR you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Delete your data (“right to be forgotten”).
  • Restrict or object to processing.
  • Receive your data in a portable format (data portability).
  • Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint with your local data-protection supervisory authority.

To exercise any of these rights, write to mail@myportion.app.

International transfers

Your data may be processed on infrastructure located outside the European Economic Area — including services operated by Google, Cloudflare, Railway, and OpenRouter. Where required by law, such transfers rely on appropriate safeguards such as EU Standard Contractual Clauses (SCCs).

Children

Portion is not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us at mail@myportion.app and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date reflects the current version. We will notify you of significant changes within the app.

Contact

Portion.inc — for any questions about this policy or how we handle your data, contact us at mail@myportion.app.

Terms of UsePrivacy Policy

General information, not medical advice.

Portion isn't affiliated with Harvard, and Harvard doesn't endorse products.

Portion uses cookies for analytics. Necessary ones keep the page working — the rest are your choice.