Privacy Policy

Pensum · last updated 14 September 2026

Pensum is a nutrition tracker. It works locally on your device and does not require an account. This policy explains what data Pensum handles and what leaves your phone.

Controller: Alessandro Parini, Einzelfirma, Grienmattweg 1, 4410 Liestal, Switzerland (UID CHE-181.827.819). Contact: [email protected].

1. Data stored on your device

Your diary, foods, recipes, weight log, and targets are stored in a local database on your device. Pensum has no user account. Uninstalling the app removes it.

There is one exception, and you choose it: if you subscribe to Pensum Plus, the app keeps a cloud backup of that database so you can get your diary back after losing or changing your phone. Section 7 describes exactly what is uploaded, when, where it is stored, and how to delete it. Optional AI requests and import failure reports can also send data you choose to provide, as described in sections 3 and 6.

2. Health Connect (Android)

If you grant permission, Pensum reads total energy expenditure, weight, and body fat from Android Health Connect to show your energy balance and refine your estimates. These readings are processed on your device. Weight and body-fat values saved in your Pensum database are included if you enable cloud backup (section 7). Relevant saved values may also be sent when you choose to use Ask Pensum or submit an import failure report (sections 3 and 6).

Pensum can also, only when you switch the matching toggle on, write data back to Health Connect: logged meals (their calories and macros) and weigh-ins you enter in the app. This lets other apps you authorize in Health Connect (for example Fitbit) read what you eat and weigh. Pensum only ever writes its own records and never modifies data written by other apps. Turning a toggle off stops future writes; records already written stay until you remove them. Reading from and writing to Health Connect happens on your device; the optional uploads described above are separate. You can revoke any of these permissions in Health Connect at any time.

3. Photos, labels, and recipes you send for analysis

Pensum has optional AI features: analysing a meal photo, reading a nutrition label, or importing a recipe. When you use one, the photo or text you provide and any context you add (e.g. known ingredients, portions) are sent over HTTPS to our own processing endpoint at proxy.pensumapp.com, which forwards it to a vision model and returns an editable result you can correct. The content is used solely to perform that analysis and is not stored by us. You can use the entire rest of the app without ever using these features.

The optional Ask Pensum chat works the same way. When you opt in and ask a question, your message, any photos you attach, the conversation so far, and the parts of your data needed to answer it (for example average intake over recent weeks, weigh-in points, your target history, or the entries you logged on a specific day you asked about) are sent over HTTPS to proxy.pensumapp.com, which forwards them to an AI model and streams the answer back. Only what a question actually needs leaves your device, a few named days at most, never your whole food log. We do not store the conversation or the summaries; we record technical metering data only (an anonymous install identifier, token counts, timing). Your conversations are kept only on your device, where you can reopen, rename or delete them at any time. They are excluded from automatic cloud backups, but the conversation context is sent for each AI request as described above. A backup file you export yourself contains them, like the rest of your data. It can also suggest changes to your goals, targets and recipes; a suggestion is shown to you as a card and nothing changes until you tap Apply. Ask Pensum stays off until you opt in, and its answers are not medical advice.

4. Food databases and Open Food Facts

Food information comes from open data sources: Open Food Facts, Bundeslebensmittelschlüssel (BLS), the Swiss Food Composition Database, and USDA FoodData Central. The generic-food catalogue is bundled with the app, so most searches never leave your device. When you scan a barcode, or when a text search finds no match in the bundled catalogue, Pensum queries Open Food Facts over HTTPS, sending only the barcode or the search term you typed, never personal data or your diary.

If you use the nutrition-label scanner and confirm the values, Pensum can also contribute that product back to Open Food Facts (its name, the values you confirmed, and the label photos) so the next person who scans it finds it. This goes through proxy.pensumapp.com and, like Open Food Facts itself, is public.

5. Product analytics

Pensum contains no third-party analytics SDKs, no advertising, and no ad trackers, and we never sell or share your data. The analytics below are first-party (they run through our own server, not a data broker) and pseudonymous (tied to a random per-install identifier, never to you, your name, or an account).

Launch ping. When the app starts it sends a random per-install identifier, the app version, the platform, the build type (a normal release build vs. our own development builds), and the install source (for example the Play Store vs. a direct APK download), so we can count how many installs are actually in use and keep our own test devices out of those numbers.

Behavioral events. To understand which features work and where the app is confusing, Pensum records that an action happened and, where relevant, how: for example that a meal was logged and by which method (search, barcode, photo, and so on), that a search ran and roughly how many results it returned, that a photo scan was corrected before you accepted it, that a setting was toggled, which onboarding step you reached, session start and end, and, once, the acquisition channel your install came from. These record that an action happened, not what it contained.

What these events never contain: your diary or the foods you eat, your weight or body data, your photos or their metadata, the text of searches that returned results, precise location, contacts, or advertising identifiers.

One deliberate exception: failed searches. When a food search returns no results, we record the search text (truncated, and stored without the per-install identifier) so we can find and fill gaps in our food database. This is food-name text, never a diary entry.

6. Import failure reports (optional)

When an import from another tracker (Cronometer, Lifesum, MacroFactor, MyFitnessPal, OpenNutriTracker) fails, or its preview looks wrong, you can choose to send us a report so we can fix the importer. This never happens automatically: the app tells you exactly what the report contains and sends it only after you confirm.

A report contains the export file(s) you picked, in full, including the food diary and weight history they contain, together with the error details and your app version. It is sent over HTTPS to our own server, used solely to reproduce and fix the import problem (never for analytics or any other purpose), and deleted automatically within 90 days. To have a report deleted sooner, email [email protected].

7. Cloud backup (Pensum Plus)

What. A copy of the Pensum database on your phone: your diary entries, the foods and recipes you created, your weight log, your targets and your settings. That is health data, and we treat it as such. Two things are deliberately left out. Ask Pensum conversations and notes are stripped from the copy before it is uploaded and stay on your device only. Unused bundled food entries are removed too, because your app already has them; entries referenced by your diary or other saved data are retained. A backup file you export yourself from Settings > App > Backup & restore still contains everything, and stays wherever you put it.

When. Once a calendar day, the first time you send the app to the background that day, while the subscription and the "Automatic cloud backup" switch are both on. A backup can also run when Plus first activates. The app sends the backup and its fingerprint; if it matches the newest stored copy, the server keeps that copy without adding a duplicate version. Turning the switch off stops uploads and leaves what is already stored alone.

Where. Object storage we rent in the EU (Amsterdam), reached through our own server at proxy.pensumapp.com. It is not shared with anyone, and it is used for nothing but giving your data back to you.

How long. We keep the last three versions per device and delete older ones as new ones arrive. If your subscription ends, the backups are kept for 12 months and then deleted, so a lapsed subscription is never a lost diary. You can delete all of them at any time from Settings > App > Backup & restore, which removes them from the server immediately, or by emailing [email protected].

Encryption. Each backup travels over HTTPS and is encrypted at rest with a key we hold. To be plain about what that does and does not mean: this is not zero-knowledge encryption. We could technically read a backup; we do not, and nothing in our systems does. If that distinction matters to you, use the manual file export instead and keep the file yourself.

Your subscription. Pensum Plus is sold through Google Play, and Play handles the payment: we never see your card or your billing address. We use RevenueCat as a service provider to check whether a subscription is active; it processes the purchase token Play issues, keyed to the same random per-install identifier used elsewhere in this policy, and not to your name or an account. To have that purchase record deleted, email [email protected].

8. Delete your data

On your device: Pensum has no account, so your diary, foods, recipes, weight log, and targets live in a local database on your phone. Uninstalling the Pensum app deletes all of it. Unless you subscribe to Pensum Plus and leave cloud backup on, we hold no copy of it on our servers.

On our server: the only data we hold is the pseudonymous per-install identifier and the analytics described in section 5 (app version, platform, build type, install source, request route, timestamps, token counts, and the behavioral events listed there: never diary content, foods, weight, or photos), plus any import failure report you explicitly chose to send us (section 6), which is deleted automatically within 90 days or sooner on request, plus your cloud backups if you subscribe to Pensum Plus (section 7), which you can delete in the app at any time. Failed-search text is stored without your install identifier, so it cannot be tied to you to delete, but it is capped and carries no personal data. To have your install's data deleted, email [email protected] from any address, stating your request and, if known, roughly when you installed Pensum, and reference "Pensum" as the app. We will delete the matching install identifier and its associated usage records within 30 days and confirm by reply. Aggregated statistics that no longer reference your install identifier (e.g. total active-install counts) are not personal data and are kept.

9. Your rights (GDPR and Swiss FADP)

Because Pensum is local-first with no account, your personal data lives on your device and is under your control; deleting the app erases it. For the photo-analysis described in section 3, or any question about your data, contact [email protected]. Users in the EU/EEA and Switzerland have rights of access, rectification, and erasure under the GDPR and the Swiss FADP.

10. Children

Pensum is not directed at children under 16.

11. Changes to this policy

We may update this policy; the date at the top reflects the latest version.


Questions: [email protected]