Privacy policy
Your diary is not our database.
Last updated: 25 July 2026
The short version: your food diary lives in SQLite on your iPhone and in your own device backup. Kovus does not keep a server copy of it. Online features send only what they need for the task. Meal photos use private temporary storage, are removed after analysis, and are covered by an expiry cleanup process if the normal deletion path fails.
Who is responsible
DishReveal is developed by Josh Waller, trading as Kovus, in Perth, Western Australia. Email josh@kovus.dev with a privacy question or request.
Adults only
DishReveal is for people aged 18 and over, and is not directed at children. Onboarding will not build a plan for an age below 18. Kovus does not knowingly collect information from a child. If you believe a child has provided information through the app, email josh@kovus.dev and it will be deleted.
Information kept on your iPhone
DishReveal stores its private diary in an on-device SQLite database. This includes:
- profile and onboarding answers, nutrition targets and unit preferences;
- meals, meal items, saved meals and local photo references;
- weight, water and exercise logs;
- streak state, reminders and app settings; and
- Coach threads, messages and generated cards.
This information is not synchronised to a Kovus diary database. Under the app's backup setting, it may be included in your own iPhone or iCloud device backup, which Apple controls. Removing the app can remove local data, subject to any backup you control.
Account and server records
You can use manual, barcode and nutrition-label logging without creating a DishReveal account. Sign in with Apple is used when an account is needed for online AI features, subscriptions, referrals or account recovery.
The hosted service uses the following database tables. They are protected by row-level security and are not a second copy of your diary:
scan_jobsfor temporary upload ownership, expiry, delivery status and cleanup;barcode_cachefor product records fetched from Open Food Facts, without a DishReveal user identifier;subscription_entitlementsandrevenuecat_webhook_eventsfor purchase status and reliable webhook processing;feedback_submissionsfor feedback you choose to send;apple_revocation_tokensfor an encrypted Sign in with Apple revocation credential;coach_thread_usage,report_jobs,api_rate_limits,external_api_rate_limits,ai_feature_quota_usageandmeal_fix_usagefor limits, delivery state and abuse prevention;ai_usage_eventsandai_cost_alertsfor model, token, cost and operational accounting; andreferral_codesfor invite and reward redemption.
AI usage records contain operational metadata such as the model, feature, token counts and estimated cost. They do not contain a meal photo, Gemini answer or diary entry. After account deletion, the user link on an AI usage record is removed. A redeemed referral record may remain to preserve a reward, but the deleted referred user's identifier is removed.
Meal photos and analysis
Before upload, the app resizes the longest image edge to no more than 1,024 pixels, re-encodes the image as JPEG and rejects a prepared file if an EXIF metadata segment remains. The JPEG is uploaded through a signed one-time URL to a private Supabase Storage bucket.
The analysis service downloads the photo and sends it to the Gemini API with an optional meal hint. DishReveal may briefly stage the structured result to complete delivery, then clears the result and removes the photo. It does not keep the photo or result as server-side diary history. If the normal path fails, expired upload jobs are processed by the cleanup service. Temporary job metadata can remain until the signed upload token has expired so the same path cannot be reused.
Text meal descriptions and correction requests are also sent to Gemini when you use those features. Nutrition-label OCR runs on your device. The label image and recognised label text are not sent to the DishReveal backend.
Coach and weekly reports
Coach sends your question, up to eight recent messages and a bounded numeric nutrition snapshot to Gemini. The snapshot can include up to 14 days of energy, macro, fibre, meal-count, goal and optional weight values. Weekly reports use up to seven days of numeric totals, goals and optional weights.
Kovus does not keep Coach answers or completed weekly report text on the server. Your Coach conversation and any locally cached report remain on your device.
Gemini processing
Google acts as the AI sub-processor for photo and text meal analysis, corrections, Coach answers and weekly reports. Google handles submitted content and service metadata under the Gemini API terms and related data-processing terms. Kovus's deletion of its own temporary copies does not control any limited provider retention required for security, policy enforcement or law.
Subscriptions
Apple processes purchases. DishReveal uses RevenueCat to validate App Store transactions, maintain the Pro entitlement and restore purchases. RevenueCat can receive an app user identifier, device and operating-system information, Apple receipt information, purchase history and last-seen time. It does not receive your meal diary, photos, Coach messages or Apple Health data from DishReveal.
Read Apple's privacy policy and RevenueCat's privacy policy. Kovus does not receive your payment-card details.
Apple Health
Apple Health access is optional and requires your permission. DishReveal reads steps, active energy and workout counts for display in the app. The current code also requests permission to write dietary energy, protein, carbohydrate, fat and body mass when Health sync is enabled.
Apple Health values are handled on the device. DishReveal does not send Apple Health-derived values to its backend or to Gemini, and does not use them for advertising.
Feedback, notifications and diagnostics
If you send feedback, Kovus receives the category and message with your account identifier so the issue can be handled. Do not include information you do not want to submit.
DishReveal schedules its reminders locally on your device. Version 1 has no third-party analytics SDK and no third-party crash-reporting SDK. Product events are written only to the development console in development builds. Operational errors are written to the device console and are not sent by the app over the network. Apple may provide App Store or TestFlight crash reports under Apple's own service terms.
Retention and deletion
Local information remains until you delete it in DishReveal, delete your account and local data, or remove the app, subject to your own device backup.
Delete Account first removes any outstanding private scan uploads, revokes the stored Apple credential where available, deletes the Supabase Auth user and removes or unlinks linked server records according to the rules described above. DishReveal then wipes the local diary, Coach history, profile, settings, reminders and queued local uploads.
Deleting a DishReveal account does not cancel an Apple subscription. Cancel it separately in Apple ID subscription settings. Apple, RevenueCat, Google and other service providers may retain records required by their own legal and operational obligations.
Security and international processing
Online requests use encrypted HTTPS connections. Private uploads require signed tokens and are restricted to JPEG files of no more than 3 MiB. Server tables deny direct client access unless a specific service path allows it. No system is completely secure, so do not put identifying or highly sensitive information in a meal hint, Coach question or feedback message.
Supabase, Google, Apple and RevenueCat may process information outside Australia under their service terms and privacy arrangements.
Changes and contact
This policy will be updated when the app, providers or retention practices change. The current update date will remain at the top of this page.
Email josh@kovus.dev. You can also read the terms of use and methodology.