Privacy Policy

Last updated: 25 August 2026

Sapida is an iOS app for logging food and digestive symptoms and spotting the connections between them. It was built to keep your data on your phone. This policy explains, in plain English, what data the app handles, what (little) leaves your device, and why.

The short version

Who we are

Sapida is developed by Iain McAndrew, a sole independent developer based in the United Kingdom, who is the data controller for any personal data processed in connection with the app.

Contact: hello@sapida.app

This policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What the app stores — on your device

Everything you enter in Sapida is stored locally on your iPhone using Apple's SwiftData database:

We cannot see any of this. There is no Sapida server, and the app does not sync your data to iCloud or any other cloud service.

Apple Health (HealthKit)

Sapida's use of Apple Health has two separate halves, each with its own permission: reading context about your day, and (optionally) writing your logged nutrition back. Neither is required to use the app, and all HealthKit processing happens on your device.

What Sapida reads

With your permission, Sapida reads a deliberately narrow set of types — exactly the ones it actually uses, and nothing more:

This is shown alongside your food and symptom logs so you can tell a bad night from a bad meal. Earlier versions of the app also asked for general heart rate, water intake and mindfulness minutes; those were removed, because nothing in the app read them.

A daily summary of these values is imported into the app's own on-device database when you open the app (and when you pull to refresh or tap Sync Health Data), so charts work without querying Health each time. Because it is stored in the app, it is included in exports you create and is deleted by Clear All Data.

What Sapida writes (off by default)

If you turn on Write Nutrition to Health in Settings, Sapida writes the nutrition from the food you log — calories, protein, carbohydrates, fat and fibre — into Apple Health, so it appears alongside data from your other apps.

Both directions

What leaves your device, and why

Sapida talks to a small number of external services, and only sends the minimum needed for each job. Your symptom history, health data and identity are never included in these requests. Note that any request over the internet necessarily reveals your device's IP address and standard connection metadata to the service that receives it.

Before any of that happens, food searches and barcode scans are answered from a food database bundled inside the app itself — around 20,000 common branded products plus a set of generic whole foods — and from an on-device cache of your recent lookups. Many lookups are satisfied entirely on-device and never generate a network request at all; the services below are used when the bundled data doesn't have a match.

Open Food Facts

Why: product and nutrition lookup when you search for a food or scan a barcode.

What it receives: the search text you typed, or the barcode number you scanned. Searches (not barcode scans) also include the country your device is set to — for example "United Kingdom" — so that products actually sold near you appear first. This comes from your device's region setting in iOS, not from location tracking: Sapida never asks for, or has access to, your location. Open Food Facts is a non-profit open food database (openfoodfacts.org).

USDA FoodData Central

Why: nutrition lookup for generic foods (e.g. "banana").

What it receives: the food name being looked up. FoodData Central is run by the US Department of Agriculture.

Apple

Why: voice input, AI meal parsing and subscription purchases.

Voice input: if you dictate a meal, the audio is transcribed using Apple's speech recognition, which may process audio on Apple's servers depending on your device and language settings.

AI meal parsing and label reading: plain-English food descriptions, and the text of nutrition labels you photograph, are interpreted by Apple Intelligence on your device. There is no cloud fallback — that text is not sent to us or to any AI provider, and photographs of labels are processed on-device and not stored by us.

Purchases: Sapida+ subscriptions are handled entirely by Apple through the App Store. We never see your payment details; the app only learns whether you have an active subscription.

Bug reports

If you choose to send a bug report from the app, Sapida first asks whether to include diagnostic logs, then opens a pre-filled email in your own mail app addressed to our support inbox (or the iOS share sheet, if you don't have Apple Mail set up, so you can send it from Gmail, Outlook or anything else).

The report includes basic diagnostics: app version and build, bundle ID, device model, iOS version, locale, date and time, and whether you have an active subscription (yes/no). If you choose Email with logs, a text file of the app's own technical log entries from roughly the last two hours is attached — app events only, not your food, symptom or health data. You can review, edit or remove anything before sending, and nothing is sent automatically.

No ads, no tracking, no selling of data

Sapida contains no advertising, no analytics SDKs and no third-party trackers. We do not sell, rent or share your personal data with anyone. We have no data to sell — it lives on your phone.

How long your data is kept

Because your data is stored on your device, you are in control of it:

Children

Sapida is not directed at children and is not intended for use by anyone under 13. We do not knowingly collect personal data from children — and since the app collects no personal data on our servers, there is nothing for us to collect.

Your rights under UK GDPR

You have the usual rights over your personal data: access, rectification, erasure, restriction, portability and objection. In practice, because your data is stored only on your device and we cannot access it, you exercise most of these rights directly in the app — view and edit entries, export them, or delete them.

For anything we do hold (essentially, emails you've sent us), contact hello@sapida.app and we'll respond within one month.

If you're unhappy with how we've handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Legal bases

Where UK GDPR applies to the little processing that touches us or our service providers: food lookups and purchases are processed because they're necessary to provide the service you've asked for (performance of a contract), and support correspondence is handled under our legitimate interest in helping users and improving the app.

Changes to this policy

If the app's data practices change — for example, if iCloud sync is ever added — this policy will be updated and the "last updated" date changed before the change ships.

Contact

Questions about this policy or your data: hello@sapida.app