What we see, what we don't, and why.
KetoCypher is built so we cannot read your food log, weight, biometrics, or any other entry you make. This policy describes the few things we do see, and the architectural reason we don't see the rest.
Effective: October 1, 2026. This update reflects that KetoCypher is now operated by Optikal LLC, a Colorado limited liability company doing business as Optikal, which took over from the sole proprietorship Optikal Development on October 1, 2026. Nothing else changes: the same people run the app, and how it handles your data is unchanged. The September 29, 2026 update disclosed two changes in app version 1.2.1. Sign-in keys: on Android, the app can create a sign-in key so a new phone recognizes your account, and our server stores that key's public half (section 2); it is not your password and cannot unlock your data. Your own food photos: photos you add to your foods are encrypted on your device like everything else you enter, and are included in your encrypted backups (sections 2 and 3). The September 26, 2026 update added section 4, which discloses the optional Open Food Facts lookups: when you allow it, the app reads scanned barcodes and product photos directly from that public food database, which sees the request and your IP address but never your account or log. It also discloses the content we publish in the app, such as product news: those loads carry nothing about you, and the once-a-day background check for new product news happens only if you turn on update notifications. The September 4, 2026 update disclosed the optional in-app coffee tips: the purchase record we keep when you buy one (processed by Google Play; we never see payment details) and the Supporter status and coffee count stored on your account. It also covers the new body metrics you can track (ketones, glucose ketone index, A1c, cholesterol, blood pressure), which stay encrypted on your device like everything else, and the new two-way Health Connect options: with your per-type permission, the app can now write your own logged data to Health Connect and read nutrition and hydration records that other apps wrote. It follows the July 16, 2026 update, which disclosed the app's opt-out, self-hosted product-usage analytics, and the July 4, 2026 update, which added in-app self-service account and data deletion, clarified password reset versus data recovery, stated our data-retention windows, and disclosed beta feedback, opt-out crash diagnostics, payment processing, and security-incident notification.
1. The short version
- Your food log, weight, biometric readings, ratings, fasting sessions, and any notes are encrypted on your phone before they leave it. The server stores ciphertext only.
- There is no admin key and no operator "recover my data" path, because either would be a backdoor. Resetting your password restores your ability to sign in, but it does not by itself recover your encrypted data: that data is sealed by a key your password only wraps, never creates. After a reset you regain access by entering your 12-word recovery phrase, which re-seals the key under your new password. Without either your old password or that phrase, your data stays encrypted and permanently unreadable.
- The only personal data we retain to identify you is your email address (for the waitlist and your account) and an unguessable password verifier (so you can sign in). Operating a web service also means our servers briefly log technical request data, such as your IP address; see section 2.
- If you allow it, the app looks up scanned barcodes and product photos in Open Food Facts, a public food database. Those requests go straight from your phone and carry only the barcode or photo asked for and your IP address, never your account or your log. See section 4.
- We do not sell data. We do not run ad networks. We do not share data with third parties for marketing.
- If a court compels us, we can hand over ciphertext and account email. We cannot hand over what we cannot read.
2. What the server actually receives
To run an account and (optionally) a cloud backup, the server stores:
- Email address. So you can sign in, and reset your password if you forget it.
- Password verifier. A derived value, not your password. It lets the server confirm you know your password without ever seeing it.
- Sign-in key (Android). When you sign in, the app can create a sign-in key (a passkey) that lets a new phone restored from your Google backup recognize your account. Its private half stays in your Google account's password manager and never reaches us; our server stores only the public half and an identifier for it, linked to your account. It is not your password, you still enter your password on the new phone, and it cannot decrypt anything. Signing out removes it from our server, and it is deleted with your account.
- Account metadata. Account creation timestamp, tier (Free or Premium Backup), and basic billing state if you are on Premium. Premium payments are processed by Google Play Billing; we never see or store your card or payment details.
- Coffee tips (optional). If you choose to buy the devs a coffee in the app, Google Play processes the payment; we never see your card or payment details. To grant and keep your Supporter perks honest, we store a record of each verified coffee purchase linked to your account: the Google Play purchase token, which coffee product it was, how many coffees it counts for, when it happened, and whether Google later voided it (for example after a refund). Your account also carries your cumulative coffee count and Supporter status, which is all the perks are computed from. These records are deleted with your account.
- Encrypted backup blobs (Premium Backup only). Ciphertext, plus the minimum metadata required to upload, list versions, and download (size, version counter, timestamp).
- Standard request logs. Connection metadata such as IP address, user-agent, and the request path and status, retained no more than 7 days for security and abuse handling, and never used for advertising or profiling. These logs never contain your food log, encrypted data, password, or recovery phrase.
- Beta feedback you choose to submit. If you send in-app feedback during the beta, we store the description you write and any screenshot you attach, linked to your account, so we can reproduce and fix the issue. When you delete your account or your server data, the feedback is unlinked from you and its screenshots are deleted; the remaining text is permanently deleted 90 days later.
- Crash and error diagnostics (opt-out). To find and fix crashes, the app can send diagnostic reports — stack traces, device model, OS and app version — to our own self-hosted error tracker. Reports are scrubbed of personal content and never include your food log or any entry you make. You can turn this off in the app's settings.
- Product usage analytics (opt-out). To understand which features are used and where to improve, the app can send anonymous, content-free usage events (for example, "a backup was created" or "the scanner was opened") to our own self-hosted analytics. These events carry your app version, device model, operating system, and language, plus an approximate location (your country, inferred from your connection; we do not store your IP address). They never include your food log, your health data, your account, or any value you enter. This uses the same opt-out switch as crash diagnostics, in the app's settings.
- Content we publish. The app can load content we publish, such as product news and, in the future, articles and recipes. It does so when you open, refresh, or search one of those sections, and, only if you turn on update notifications, once a day in the background to check for new product news. The daily check carries no account and nothing about you. Content requests never include your food log, your health data, or anything you enter elsewhere in the app. A search you type in a content section is sent to our server to find matches, and like every request it appears only in our standard request logs, kept for up to 7 days.
The server does not see your food log entries, weight, heart rate, sleep, glucose, steps, electrolyte totals, ketone or other lab readings, blood pressure, ratings, fasting sessions, custom foods, photos you add to your foods, recipes, or any other data you enter in the app. Those values are encrypted on your device with your master key before they ever leave it. That master key is unlocked by a key derived from your password (Argon2id) and can also be recovered with your 12-word recovery phrase; we never receive your password, your recovery phrase, or the master key itself.
Beyond the items listed above, the app sends nothing to us. It contains no advertising identifiers and no cross-app tracking, and it uses no third-party analytics service: the only usage analytics and crash diagnostics are anonymous, opt-out, and sent to our own self-hosted servers, never to an outside analytics company. Its outbound network calls to us are authenticated account and backup requests, the content loads described above, and opt-out usage analytics and crash diagnostics, and we send you transactional email. Separately, if you allow it, the app reads product information and photos directly from Open Food Facts, a public food database; see section 4. App updates are delivered by Google Play, not by us.
3. What stays on your device
Everything you enter, everything Health Connect returns to the app, and everything KetoCypher computes from those values, stays on your phone in an encrypted local database (SQLCipher). That includes the body metrics you can log by hand: ketone readings (urine, blood, or breath), your glucose ketone index, A1c, cholesterol panel results, and blood pressure. It also includes photos you add to your own foods, which are encrypted like any other entry and, if you use Premium Backup or export a .kcbak file, travel inside that encrypted backup. Single-signal insights and correlations are computed on-device. We do not see what your sleep is, what your blood glucose was, which foods you logged, or any reading you enter.
4. Open Food Facts lookups (optional)
KetoCypher ships with its own food database on your phone. To identify packaged products it does not already know, the app can read from Open Food Facts, a free, public food database run by a non-profit (openfoodfacts.org). The app only does this after you allow it, which it asks the first time you use a feature that needs it. If you choose "Not now", nothing is sent, and you can still log any food by hand.
Once you allow it, your phone contacts Open Food Facts directly, not through our servers, in two cases:
- Barcode lookups. When you scan the barcode of a product that is not already on your device, the app sends that barcode to look the product up. Products it finds are saved on your device, so scanning one again usually needs no network. A product Open Food Facts does not have, or a lookup that fails, is asked again the next time you scan it.
- Product photos. When the app shows a product's photo, it requests that image from Open Food Facts. Photos are then kept in an encrypted cache on your device, which is cleared when you sign out or delete your account and is never included in your backups.
Open Food Facts receives the barcode or photo being requested, your device's IP address, and a fixed label naming the app and our support address (Open Food Facts asks every app to identify itself this way). It never receives your account, your email, your food log, your health data, or anything you enter. KetoCypher only reads from Open Food Facts: nothing you log, edit, or create is ever sent to it. Open Food Facts handles these requests under its own privacy policy.
5. Google Health Connect
What we read. If you connect Google Health Connect, KetoCypher reads the data types you approve, one permission at a time: weight, sleep, heart rate, blood glucose, and steps. With two further optional permissions, it can also read nutrition and hydration records that your other apps wrote, so it can show you an informational daily summary alongside your own log (records KetoCypher wrote itself are excluded, so nothing is ever counted twice). All reads happen locally, inside Android's sandbox.
What we can write, if you turn it on. Separately from reading, you can allow KetoCypher to write your own logged data out to Health Connect so your other health apps can use it: your logged meals (nutrition), water (hydration), and blood pressure, weight, and blood glucose readings you entered by hand. Each kind is its own permission, off by default, and only ever contains data you logged yourself. You can revoke any of these at any time in Android Settings → Health Connect → KetoCypher, and you can delete what was written from Health Connect itself; deleting an entry in KetoCypher also removes the copy it wrote.
How we use it. Health Connect data is used only to pair with your food log and to compute the correlations and insights KetoCypher shows you, all on your device. We never use Health Connect data for advertising, we never sell or rent it, and we never share it with any third party. Writing happens only between apps on your phone; nothing about it goes to our servers.
Where it lives, and how it is secured. Readings KetoCypher keeps are written to the same encrypted on-device database (SQLCipher) as the rest of your data, encrypted with your master key. We never receive them in any readable form. The only way any of this data leaves your device is inside an end-to-end-encrypted Premium Backup you choose to create; in that case our servers hold only ciphertext they cannot decrypt, plus a record count in the backup's inventory (a number, never a value).
Retention and deletion. Health Connect readings stay on your device until you delete them in the app or uninstall KetoCypher. Deleting your account or your cloud data removes the encrypted backups from our servers, as described in section 10. You can also revoke any individual data-type permission at any time in Android Settings → Health Connect → KetoCypher, which stops any further reads.
6. Waitlist
If you submit your email on the landing page waitlist, we store the address and a tag indicating the source (the landing page) in our database. We use it only to notify you when the Android beta opens. To remove yourself, reply to the confirmation email or write to support@ketocypher.com.
7. Analytics
On this website we use Cloudflare Web Analytics, which is cookieless and does not track individuals across sites. It records aggregate page-view counts and approximate location at the country level. No personal profile is built.
Inside the Android app we use our own self-hosted analytics (Aptabase) to count anonymous feature usage, for example how often the barcode scanner is opened or a backup is created. These events are content-free and are never linked to your identity, your food log, or your health data. They include your app version, device model, operating system, language, and an approximate location at the country level inferred from your connection. This is opt-out: you can turn it off, together with crash diagnostics, in the app's Settings. We use no third-party analytics service inside the app, and this data is never sold or shared.
8. Minors
KetoCypher is a health and wellness tool intended for adults. It is not directed at anyone under 18, and we do not knowingly collect data from minors. If you believe someone under 18 has signed up, write to support@ketocypher.com and we will remove the account.
9. Data location
Account data and (for Premium Backup users) encrypted backup blobs are stored on infrastructure hosted in the United States. Cloudflare handles the public web edge. KetoCypher is offered only to users in the United States; we do not target or market the app to the EU, UK, or EEA.
10. Your rights
You can:
- Export your data. Free and Premium users can export a portable
.kcbakfile from inside the app. It is still encrypted with your master key. - Delete your account or data. In the app, go to Settings → Account → "Delete account or data." You can either delete your cloud data (your encrypted backup blobs) and keep your account, or permanently delete your entire account and all server-side data. Both actions require confirmation and re-entering your password, take effect immediately, and cannot be undone. Deletion of the live account data is immediate; any residual copies in our database provider's short-term, point-in-time-recovery backups roll off automatically within 7 days. Neither touches the data stored on your own device, which stays encrypted and readable only with your recovery phrase or a valid account. You can also email support@ketocypher.com from the address on the account. Because we cannot read your encrypted blobs, once they and the account record are removed no further readable "data" exists for us to delete. See ketocypher.com/delete-account for the full process.
- Correct or update contact details by writing to support@ketocypher.com.
KetoCypher is offered only in the United States and is not directed at the EU, UK, or EEA. Regardless of which law reaches you, the architecture (we cannot read your data) means that for most categories there is no plaintext for us to access, rectify, or port; the in-app export is the only complete copy of your data, and it stays in your hands.
11. Subprocessors
- Cloudflare (CDN, DNS, web analytics).
- Supabase (database and auth for account email + verifier + waitlist).
- Amazon SES (transactional email: account, password reset, beta invite).
- Google Play Billing (payment processing for Premium Backup and optional coffee tips; Google processes your payment so we never receive your card or payment details).
Open Food Facts is not a subprocessor: it does not process anything on our behalf. It is a public database your phone reads from directly, only if you allow it (section 4).
If we add or change a subprocessor in a way that affects this policy, we will update this page.
12. Changes
If we materially change how the app handles your data, we will update the "Effective" date above and call out the change at the top of this page. For material changes, we will also email account holders in advance, since we already have your address. Continued use after a change takes effect means you accept the updated policy.
13. Security incidents
If we ever discover a security breach affecting your account data, we will notify affected users by email without undue delay, and describe what happened and the steps you should take. Because every entry you make is encrypted with keys we never hold, a breach of our servers exposes ciphertext, your account email, and the limited metadata described above, not your food log, weight, biometrics, or any value you enter in the app.
14. Who we are & contact
KetoCypher is built and operated by Optikal LLC, a Colorado limited liability company doing business as Optikal, based in Colorado, USA.
General questions: hello@ketocypher.com. Privacy, account, or data requests: support@ketocypher.com.