Damson

Your records

Privacy

Last updated 12 August 2026

The short version

Damson keeps what you log on your phone. There is no account to create, nothing asks you to type your name, and nothing you log reaches us. A small amount of work has to happen on a server, and this page says exactly which work, what travels with it, and what is left behind afterwards. The app also counts which of its own screens and actions get used, and the section on that says what the count can and cannot contain. Signing in with Apple is offered and optional, and it is the one place a name can reach us at all.

Who is responsible for your information

Damson is made and published by GPT Genius Lab, LLC, a limited liability company formed in Delaware, United States, at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States. That company is the data controller for everything described on this page, which means it is the one answerable for it. Questions, requests and complaints go to [email protected] and a person answers them. Ask and we will give you a postal address to write to instead.

What lives only on your phone

Your meal records, the answers you give at check-in, your photos, and your conversations with Damson are kept on the device, in storage that only the app can read. Nothing in that list is uploaded to us to be kept. Deleting the app deletes all of it, and we hold no copy to hand over, lose, or sell.

The app keeps at most 42 meal photos. When you take the next one, the oldest is deleted. Forty-two is about two weeks of three plates a day, which is as long as a photo is still doing the job it was taken for. Deleting the picture never touches the meal it belonged to: the plate, its foods and its check-in all stay, and the meal simply reads without a photo from then on.

Optional syncing, through your own iCloud

If you turn syncing on, your records travel through your own iCloud account, under your Apple ID and inside your own iCloud storage, using Apple's CloudKit. They do not pass through our servers and we cannot read them. Apple's terms cover what Apple holds. Turning syncing off leaves everything on the device, and if you would rather nothing at all left the phone, leave it off.

What reaches our servers, and why

Four things reach us, and each one is here because a feature cannot work without it:

  • the one meal photo you submit to be read, which is processed and not stored;
  • a question you choose to ask, with the records you picked to go with it;
  • one random identifier, which counts your daily allowance and does nothing else;
  • counts of what you logged, on a day Damson writes you a note.

None of the four is filed against your name, because we do not have your name. The four sections that follow say what happens to each.

The plate read

When you ask Damson to read a plate, that one image goes to our server and on to the model that reads it. It is deleted as soon as the reading comes back. We keep no copy, we do not file it against you, and we do not let the provider keep it for training. Nothing that identifies you or your device travels with the image.

When a reading finds nothing, we write the model's own reply to our host's log, because that one line is how we tell a photo with no food in it apart from a fault at our end. It is written on failure only, so it can carry no meal of yours, and the log rotates within hours.

If you scan a barcode instead of a plate, the barcode number goes to Open Food Facts to look the product up. Nothing else goes with it.

Asking Damson a question

You choose what to ask, and you choose which of your records go with it. Before anything is sent, the app shows you the whole request on one screen: your question exactly as you typed it, and every record you picked, each one removable. The button reads "Send this, and only this", because that is what it does.

On the way out, contact details and identifier-shaped text are removed from your words: email addresses, links, telephone numbers, long runs of digits such as an account or an identity number, and social handles. We will not pretend that is the same as anonymity. A name written as ordinary prose, as in "my sister cooked this", has no shape any rule can catch, so it cannot be removed for you. That is exactly why the app shows you the request before it goes and asks you to check your own words. The screen is the protection. The removal is the backstop behind it.

The question then goes to OpenAI, which answers it. The request itself tells OpenAI not to keep the text and not to train on it. Your questions and the answers are never stored on our servers. The record of the conversation is the one on your phone, and it leaves with your export and goes with your delete.

Signing in with Apple is optional

Onboarding offers Sign in with Apple, and it is there for one reason: so that a purchase and a daily allowance can follow you to a new phone. Walk past it and the app gives you an anonymous session instead, and every feature still works.

If you do use it, Apple asks whether to share your name and your email address with us, and Apple lets you hide the address so that a relay one reaches us instead of your real one. Whatever you agree to share is held with your sign-in record and is used for nothing else. Deleting your account from inside the app removes it, and asks Apple to revoke the sign-in as well.

The identifier behind your daily allowance

Your copy of the app holds a random identifier whose only job is counting. It lets us hold a fair daily limit on plate readings and questions, so that one phone cannot use up what everyone else has paid for. We store it as a one-way hash, next to the number of readings taken that day. It is not tied to a name or an email address, it is never sent to the model providers, it is not joined to your records, and it is not used to build a picture of you. Counting which parts of the app get used is a separate thing with a separate identifier, set out below, and the two are never put side by side.

The note Damson writes you

Damson can write you one short noticing a day about what you have already logged. To do that, our server sends counts and food names to OpenAI: how many lunches carried lentils, how often you said the meal settled afterwards, how many days you answered. Your food and meal names are your own words, so they pass the same removal a question passes. Photos never go with them, and neither do free-text notes, any identifier, or any figure the app has not already shown you.

What we keep afterwards is only the sentence you were shown, the records it points at, the day, and whether the day had anything worth saying. We never keep the counts it was written from, the instructions the model was given, or anything the model sent back before it was checked.

Counting which parts of the app get used

The app counts what gets used, so that we can tell which parts of it are worth keeping and which are in the way. A company called Mixpanel does that counting for us, and this is the whole of what it is sent:

  • that a plate was photographed, chosen from the library, scanned as a barcode, searched for, or typed in by hand;
  • that a reading came back or failed, and which kind of failure it was, such as a timeout or no food found;
  • that a reading was corrected, and how many items were changed or removed;
  • that a meal was saved, and how many foods were on it;
  • that the reflection after a meal was reached;
  • that a check-in happened, and whether it was inside the window the app asked for, late, or filled in afterwards;
  • that check-in reminders were switched on or off, and that one was opened;
  • that a suggestion was asked for, shown, added, saved or turned down, and whether it came from your own saved foods or from our list;
  • that a pattern or a noticing was opened, its sources read, and roughly how many meals it was standing on, as a band such as 3-4 or 10+;
  • that a question was asked of the assistant, roughly how many records went with it as a band, and whether it was answered;
  • that the companion focus was turned on or off;
  • that the paywall was seen, where from, and whether a purchase or a restore followed;
  • that the first run was started, finished or skipped, and that an export or a delete-everything was performed.

That is a list of things you did, and it is not a list of anything you wrote or ate. Mixpanel never receives a food name, a meal name, a photo, the words of a check-in, a note you typed, anything at all about your cycle, a question you asked, or an answer you were given. It cannot: the app is only able to send it a short name and a handful of labels chosen from fixed lists, and there is no way to attach your own words to one. Nothing it receives describes a particular plate.

What travels alongside is your phone model, its operating system version, the app version, and an identifier that belongs to your copy of this app and to no other app on the phone. It is not the advertising identifier, and the counting does not read that one. We also tell Mixpanel not to turn the connection into a location, so no town, region or country is recorded against you. If you have signed in with Apple, the counting is keyed to the same random identifier our own database uses for you, so that a new phone is not counted as a new person. Your name and your email address are never given to it.

This counting is on from the first launch and there is no switch for it in the app. We would rather say plainly what it is than offer a switch over something this thin. If you would rather we did not count your use of the app, the rights section below applies to it like everything else on this page.

The companies that help us run this

We keep the list short on purpose, and this is all of it.

  • Apple runs the App Store, takes the payment, and holds your iCloud if you turn syncing on. We never see your card details.
  • RevenueCat tells the app whether a purchase is valid and current. It sees the purchase, not your records.
  • Supabase hosts the database our server uses. It holds the counting described above, your time zone and app version, whether a subscription is active, and any message you have sent us from inside the app. It holds nothing you have logged.
  • OpenAI answers the questions you send and drafts the day's note. It receives the scrubbed text with no identifier attached, and the request tells it not to keep that text and not to train on it.
  • Mixpanel counts which parts of the app get used, and receives only the list of actions set out in the section above, with your phone model, its operating system version, the app version and an identifier for your copy of the app. It never receives a food name, a meal name, a photo, a check-in answer, anything about your cycle, a question you asked, your name or your email address. Its project holding this runs in the United States.
  • Meta helps us measure the adverts we run for Damson on Meta's own platforms. Its kit in the app reports standard app events, that the app was installed, that it was opened, and that a purchase happened, so we can tell whether an advert led to an install. It never receives a meal, a food name, a photo, a check-in answer, anything about your cycle, a question you asked, your name or your email address. There are no adverts inside Damson.
  • Netlify hosts this website, and holds your email address if you join the waitlist.
  • Plausible counts visits to this website. It sets no cookies, which is why there is no cookie banner here, and it holds no personal data.

The waitlist

Joining the waitlist gives us your email address and the page you signed up from, and nothing else. Netlify holds it. We use it once, to say the app is out, and then we delete it. To come off the list sooner, reply to any email from us or write to [email protected], and it is gone.

How long anything is kept

  • On your phone: until you delete the record, or the app. Photos go sooner, once 42 newer ones exist.
  • The count behind your daily allowance: today's and yesterday's. Anything older is deleted the next time a count is read.
  • The day's note: the sentence you were shown is kept for a week, so that a phone a day behind still reads what it showed you. The number of notes written on a day is kept for two days.
  • The fact that a plate reading happened: a row with a time on it and no meal in it, kept while the app is installed and removed when you delete your account.
  • The count of which parts of the app were used: held by Mixpanel for as long as our project there keeps it, and never joined to anything you logged.
  • Your waitlist email address: until the launch email has been sent.
  • When you delete your account from inside the app, we remove your sign-in, your profile, anything you sent us through support, and the notes you were shown. One thing outlives it on purpose: today's allowance count, held against the one-way identifier, so that deleting and starting again is not a way to get a second day of free readings. It goes within two days like every other count.

Your rights over your information

UK and EU data protection law gives you rights, and they apply to anything we hold:

  • to ask what we hold about you, and to have a copy of it;
  • to have it corrected if it is wrong;
  • to have it erased;
  • to receive it in a portable form and take it elsewhere;
  • to object to what we do with it, and to ask us to restrict it;
  • to complain to a supervisory authority. In the UK that is the Information Commissioner's Office, and you can go to it without asking us first.

An honest note about the first four of those. For everything that lives on your phone, you already hold the data and we do not have it, so there is nothing for us to send you and nothing for us to erase. The app's own export hands you your records as a file, and the delete-everything action in the app clears them. Those two functions are the mechanism, not a substitute for it: a letter to us cannot reach data that never reached us. For the small amount we do hold, write to us and we will answer within a month.

We rely on two legal bases and no others. Performing our contract with you, for the work you asked for: reading a plate, answering a question, checking that a purchase is current. Legitimate interest, for three kinds of counting: the one that keeps the daily limits fair and the service affordable, and the one that tells us which parts of the app are used, which is how a small team decides what to build next, and the one that tells us whether an advert for Damson led to an install. All three are the least identifying way we could find to do the job, and none of them touches what you logged. There are no adverts inside Damson, we do not profile you, and we sell nothing to anybody.

Where your information is processed

Our server, the database behind it, this website, the model provider and the company that counts app use run in the United States and the European Union. The counting runs in the United States. Where information leaves the UK or the EU it travels under the standard contractual clauses in our agreements with those companies, which is the transfer mechanism UK and EU law provides.

What we never do

  • Sell or share your records. They are not ours to sell.
  • Show you advertisements, or let anyone target you through Damson.
  • Make you create an account in order to use Damson.
  • Keep your photos, your conversations, or your questions on our servers.
  • Use what you write to train a model, ours or anyone else's.

Children

Damson is written for adults and is not directed at anyone under 16. We do not knowingly collect anything from a child. If you believe a child has been using the app and something of theirs has reached us, write to us and we will remove it.

Changes to this page

When the app changes in a way that affects this page, we change the page and the date at the top on the same day. If a change matters to you, because it widens what reaches us or adds a company that receives it, we will say so in the app before it takes effect rather than quietly editing this page. Earlier versions are yours on request.