Privacy Policy
Pensum · last updated 3 July 2026
Pensum is a nutrition tracker. It works locally on your device and does not require an account. This policy explains what data Pensum handles and what leaves your phone.
Controller: Alessandro Parini, Einzelfirma, Grienmattweg 1, 4410 Liestal, Switzerland (UID CHE-181.827.819). Contact: [email protected].
1. Data stored on your device
Your diary, foods, recipes, weight log, and targets are stored in a local database on your device only. Pensum has no user account and does not upload this data to any server. Uninstalling the app removes it.
2. Health Connect (Android)
If you grant permission, Pensum reads total energy expenditure, steps, weight, and body fat from Android Health Connect to show your energy balance and refine your estimates. This data is read on your device and is not transmitted off your device by Pensum.
Pensum can also, only when you switch the matching toggle on, write data back to Health Connect: logged meals (their calories and macros) and weigh-ins you enter in the app. This lets other apps you authorize in Health Connect (for example Fitbit) read what you eat and weigh. Pensum only ever writes its own records and never modifies data written by other apps. Turning a toggle off stops future writes; records already written stay until you remove them. Both reading and writing stay on your device and are not transmitted off it by Pensum. You can revoke any of these permissions in Health Connect at any time.
3. Photos, labels, and recipes you send for analysis
Pensum has optional AI features: analysing a meal photo, reading a nutrition label, or importing a recipe. When you use one, the photo or text you provide and any context you add (e.g. known ingredients, portions) are sent over HTTPS to our own processing endpoint at proxy.pensumapp.com, which forwards it to a vision model and returns an editable result you can correct. The content is used solely to perform that analysis and is not stored by us. You can use the entire rest of the app without ever using these features.
4. Food databases and Open Food Facts
Food information comes from open data sources: Open Food Facts, Bundeslebensmittelschlüssel (BLS), the Swiss Food Composition Database, and USDA FoodData Central. The generic-food catalogue is bundled with the app, so most searches never leave your device. When you scan a barcode, or when a text search finds no match in the bundled catalogue, Pensum queries Open Food Facts over HTTPS, sending only the barcode or the search term you typed, never personal data or your diary.
If you use the nutrition-label scanner and confirm the values, Pensum can also contribute that product back to Open Food Facts (its name, the values you confirmed, and the label photos) so the next person who scans it finds it. This goes through proxy.pensumapp.com and, like Open Food Facts itself, is public.
5. Product analytics
Pensum contains no third-party analytics SDKs, no advertising, and no ad trackers, and we never sell or share your data. The analytics below are first-party (they run through our own server, not a data broker) and pseudonymous (tied to a random per-install identifier, never to you, your name, or an account).
Launch ping. When the app starts it sends a random per-install identifier, the app version, the platform, the build type (a normal release build vs. our own development builds), and the install source (for example the Play Store vs. a direct APK download), so we can count how many installs are actually in use and keep our own test devices out of those numbers.
Behavioral events. To understand which features work and where the app is confusing, Pensum records that an action happened and, where relevant, how: for example that a meal was logged and by which method (search, barcode, photo, and so on), that a search ran and roughly how many results it returned, that a photo scan was corrected before you accepted it, that a setting was toggled, which onboarding step you reached, session start and end, and, once, the acquisition channel your install came from. These record that an action happened, not what it contained.
What these events never contain: your diary or the foods you eat, your weight or body data, your photos or their metadata, the text of searches that returned results, precise location, contacts, or advertising identifiers.
One deliberate exception: failed searches. When a food search returns no results, we record the search text (truncated, and stored without the per-install identifier) so we can find and fill gaps in our food database. This is food-name text, never a diary entry.
6. Delete your data
On your device: Pensum has no account, so your diary, foods, recipes, weight log, and targets exist only in a local database on your phone. Uninstalling the Pensum app deletes all of it, and we hold no copy on our servers.
On our server: the only data we hold is the pseudonymous per-install identifier and the analytics described in section 5 (app version, platform, build type, install source, request route, timestamps, token counts, and the behavioral events listed there: never diary content, foods, weight, or photos). Failed-search text is stored without your install identifier, so it cannot be tied to you to delete, but it is capped and carries no personal data. To have your install's data deleted, email [email protected] from any address, stating your request and, if known, roughly when you installed Pensum, and reference "Pensum" as the app. We will delete the matching install identifier and its associated usage records within 30 days and confirm by reply. Aggregated statistics that no longer reference your install identifier (e.g. total active-install counts) are not personal data and are kept.
7. Your rights (GDPR and Swiss FADP)
Because Pensum is local-first with no account, your personal data lives on your device and is under your control; deleting the app erases it. For the photo-analysis described in section 3, or any question about your data, contact [email protected]. Users in the EU/EEA and Switzerland have rights of access, rectification, and erasure under the GDPR and the Swiss FADP.
8. Children
Pensum is not directed at children under 16.
9. Changes to this policy
We may update this policy; the date at the top reflects the latest version.
Questions: [email protected]