Damson

Your records

Privacy

Last updated 30 September 2026

The short version

Damson keeps what you log on your phone. There is no account to create and nothing asks you to type your name. What you log stays on the device, and nothing you log is uploaded to us to be kept. Some of it does pass through our server inside a request you make, because a plate cannot be read or a question answered without it, and this page says exactly which requests, what travels with each, and what is left behind afterwards. The app also counts which of its own screens and actions get used, and the section on that says what the count can and cannot contain. Signing in with Apple is offered and optional, and it shares only the email address on the account, never your name. Reading from Apple Health is offered and optional too: it is off until you switch it on, it reads how long you slept and which days a period ran and nothing else, it never writes anything back, and what it reads stays on your phone.

Who is responsible for your information

Damson is made and published by GPT Genius Lab, LLC, a limited liability company formed in Delaware, United States, at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States. That company is the data controller for everything described on this page, which means it is the one answerable for it. Questions, requests and complaints go to [email protected] and a person answers them. Ask and we will give you a postal address to write to instead.

What lives only on your phone

Your meal records, the answers you give at check-in, your photos, your cycle log, the nights read from Apple Health, and your conversations with Damson are kept on the device, in storage that only the app can read. Nothing in that list is uploaded to us to be kept. Deleting the app deletes all of it, and we hold no copy to hand over, lose, or sell.

That is about what is stored, and it is worth being exact about the difference. Some of what you have logged does travel inside a request you make, and the next section lists every one of those requests. It goes so that the request can be answered, it is not filed against you, and it is not kept afterwards. Nothing here is uploaded on its own, on a schedule, or in the background.

The app keeps at most 42 meal photos. When you take the next one, the oldest is deleted. Forty-two is about two weeks of three plates a day, which is as long as a photo is still doing the job it was taken for. Deleting the picture never touches the meal it belonged to: the plate, its foods and its check-in all stay, and the meal simply reads without a photo from then on.

Syncing, through your own iCloud

Syncing is free, and it uses your own iCloud rather than ours. Your records travel under your Apple ID, inside your own iCloud storage, using Apple's CloudKit. They do not pass through our servers and we cannot read them. Apple's terms cover what Apple holds.

It runs from the first day, so your records follow you to your other devices without your having to ask for it. You can switch it off at any time in You, then My data, and it stays off until you switch it on again; from then on everything stays on the phone. Switching it off leaves the copy already in your iCloud where it is, and a separate action on the same screen deletes that copy when you want it gone. Your meal photos are never part of syncing, and neither are the nights read from Apple Health: both stay on the phone.

Apple Health

Damson can read two things from Apple Health and nothing else: how long you slept, and which days a period ran. There is no third thing, and there cannot be one without a new version of the app. It only ever reads. The permission it asks Apple for names nothing at all to write with, nothing in the app is able to write to Apple Health, and using Damson never changes what Apple Health holds.

Nothing is read until you switch it on yourself. The connection is off on a fresh install and off after an update, and it lives in the app under My data, where you switch it on. Apple's own permission sheet then asks you a second time, on top of that. Switching it off stops the reading and removes every night that was read, at the moment you switch it off rather than in a tidy-up afterwards.

What is read is kept on your phone, as your own records: the last ninety nights, and how long each one was. It is there for one thing. A night can sit beside the plates you logged around it, as one of the things Damson looks at when it tells you what it has noticed in your own days. The screen where the connection lives never prints an hours figure: it says which nights are here and stops there.

Period days are handled differently, on purpose. A day Apple Health knows about is never written into your cycle log for you. It is offered to the cycle log with a button, and only your tap makes the record.

None of this reaches our servers. What Damson reads from Apple Health stays on the phone that read it: it is not sent to us, it is not sold, it is not used to advertise anything to you or to anybody else, and it is not used to train a model. It is not part of syncing either, for the reason your meal photos are not: your other phone can read the same nights from Apple Health for itself. Deleting everything from inside the app clears the imported nights along with the rest, and so does deleting the app.

What reaches our servers, and why

Some things reach us, and each one is here because a feature cannot work without it:

  • the one meal photo you submit to be read, which is processed and not stored;
  • a meal you describe in your own words instead of photographing, and a sentence telling us what a reading got wrong, so it can be corrected;
  • the plate you have just confirmed, so that Damson can write the read that follows it, and, if you ask for ideas, the foods you have told it to leave out and the foods you have saved;
  • a question you choose to ask, with your recent records to go with it: meals, how they sat, symptom marks, your cycle day, current observations and your food boundaries, each one removable before you send;
  • counts of what you logged, on a day Damson writes you a note;
  • one random identifier, which counts your daily allowance and does nothing else;
  • a message you send us from the support screen inside the app;
  • if you have notifications on, the code your phone gives us to deliver one.

Four of those requests can also carry a small amount of what you told us about yourself: how you answered where you are with PCOS, what you are hoping for, the medicines you picked from the list, the day you are on in your cycle, and how regular your cycles are. The dates you recorded in your cycle log are never sent, and what you typed into "Other" never leaves your phone at all.

None of it is filed against your name, because we do not have your name. The sections that follow say what happens to each.

The plate read

When you ask Damson to read a plate, that one image goes to our server and on to the model that reads it. It is deleted as soon as the reading comes back. We keep no copy and we do not file it against you. Every request we send to that company carries an instruction not to keep it, and our agreement with them does not permit your photo to be used to train a model.

Your photo does not carry your name, because we do not have one. It does carry the signed session your app is using, so that we can tell a real user from a stranger and count the reading against your daily allowance. That session travels only as far as our own server. Nothing that identifies you or your device goes on to the company whose model reads the picture.

When a reading finds nothing, we write the model's own reply to our host's log, because that one line is how we tell a photo with no food in it apart from a fault at our end. It is written on failure only, so it can carry no meal of yours, and the log rotates within hours.

If you scan a barcode instead of a plate, the barcode number goes to an open public food database to look the product up. Nothing else goes with it.

If you describe a meal in words instead of photographing it, or tell Damson what a reading got wrong, those words go the same way: to our server, on to the model, and nowhere else. We keep no copy of either. They are your own sentences rather than a form, so read them back before you send them, the same as you would a question.

Asking Damson a question

You choose what to ask. Your recent records go with the question so the answer can be about you rather than about women on average: recent meals, how they sat, your symptom marks, your cycle day, the observations Damson is currently showing you, and your food boundaries. The paperclip beside the question shows every record that will go and lets you remove any of them, or add an older one, before you send. Before your first question the app says this once and asks you to agree.

On the way out, contact details and identifier-shaped text are removed from your words: email addresses, links, telephone numbers, long runs of digits such as an account or an identity number, and social handles. We will not pretend that is the same as anonymity. A name written as ordinary prose, as in "my sister cooked this", has no shape any rule can catch, so it cannot be removed for you. That is exactly why the app shows you the request before it goes and asks you to check your own words. The screen is the protection. The removal is the backstop behind it.

The question then goes to the language model provider, which answers it. The request itself tells the provider not to keep the text, which is true of every request we send it and not only this one, and our agreement with them does not permit training on it. Your questions and the answers are never stored on our servers. The record of the conversation is the one on your phone, and it leaves with your export and goes with your delete.

Signing in with Apple is optional

Onboarding offers Sign in with Apple, and it is there for one reason: so that a purchase and a daily allowance can follow you to a new phone. Walk past it and the app gives you an anonymous session instead, and every feature still works.

If you do use it, the app asks Apple for one thing: your email address. It does not ask for your name, and Apple's sheet will not offer to share one. The address is what tells a real account apart from an anonymous session, and it is what a purchase is matched against when you sign in on a new phone. Apple lets you hide it, so a relay address reaches us instead of your real one, and that works exactly as well. The address is held with your sign-in record and is used for nothing else. Deleting your account from inside the app removes it, and asks Apple to revoke the sign-in as well.

The identifier behind your daily allowance

Your copy of the app holds a random identifier whose only job is counting. It lets us hold a fair daily limit on plate readings and questions, so that one phone cannot use up what everyone else has paid for. We store it as a one-way hash, next to the number of readings taken that day. It is not tied to a name or an email address, it is never sent to the model providers, it is not joined to your records, and it is not used to build a picture of you. Counting which parts of the app get used is a separate thing with a separate identifier, set out below, and the two are never put side by side.

The note Damson writes you

Damson can write you one short noticing a day about what you have already logged. To do that, our server sends counts and food names to the language model provider: how many lunches carried lentils, how often you said the meal settled afterwards, how many days you answered. Your food and meal names are your own words, so they pass the same removal a question passes. Photos never go with them, and neither do free-text notes, any identifier, or any figure the app has not already shown you.

What we keep afterwards is only the sentence you were shown, the records it points at, the day, and whether the day had anything worth saying. We never keep the counts it was written from, the instructions the model was given, or anything the model sent back before it was checked.

Counting which parts of the app get used

The app counts what gets used, so that we can tell which parts of it are worth keeping and which are in the way. Two services receive that count: a product analytics service, and an install attribution service that also uses it to tell us whether an install came from one of our adverts or links. This is the whole of what they are sent:

Separately, the configuration service described in the companies list keeps its own automatic count: that the app was opened, how long it was open, and that a purchase happened. It receives nothing from the list below and nothing you have logged.

  • that the app was opened, and whether it was the first time since it was installed;
  • that a plate was photographed, chosen from the library, scanned as a barcode, searched for, or typed in by hand;
  • that a reading came back or failed, and which kind of failure it was, such as a timeout or no food found;
  • that a reading was corrected, and how many items were changed or removed;
  • that a meal was saved, and how many foods were on it;
  • that the reflection after a meal was reached;
  • that a check-in happened, and whether it was inside the window the app asked for, late, or filled in afterwards;
  • that check-in reminders were switched on or off, and that one was opened;
  • that a suggestion was asked for, shown, added, saved or turned down, and whether it came from your own saved foods or from our list;
  • that a pattern or a noticing was opened, its sources read, and roughly how many meals it was standing on, as a band such as 3-4 or 10+;
  • that a question was asked of the assistant, roughly how many records went with it as a band, and whether it was answered;
  • that the companion focus was turned on or off;
  • that the paywall was seen, where from, and whether a purchase or a restore followed;
  • which screen of the first-run setup was reached, and that the agreement at its start was accepted, but never what was answered on it;
  • that the first run was started, finished or skipped, and that an export or a delete-everything was performed.

That is a list of things you did, and it is not a list of anything you wrote or ate. It never receives a food name, a meal name, a photo, the words of a check-in, a note you typed, anything at all about your cycle, a question you asked, or an answer you were given. It cannot: the app is only able to send it a short name and a handful of labels chosen from fixed lists, and there is no way to attach your own words to one. Nothing it receives describes a particular plate.

What travels alongside is your phone model, its operating system version, the app version, and an identifier that belongs to your copy of this app and to no other app on the phone. It is not the advertising identifier, and neither service reads that one: the app never asks for permission to track you, and it tells the attribution service not to read it. Both services see the internet address the app connects from, as any server it talks to does. The product analytics service uses it to work out the town, region and country you are in, and records those alongside the actions it counts, so we can see where Damson is used. It never asks your phone where you are, and the app has no permission to. The attribution service also receives Apple's own anonymous reports of which advert, if any, led to an install. If you have signed in with Apple, the counting in both is keyed to the same random identifier our own database uses for you, so that a new phone is not counted as a new person. Your name and your email address are never given to either.

This counting is on from the first launch and there is no switch for it in the app. We would rather say plainly what it is than offer a switch over something this thin. If you would rather we did not count your use of the app, the rights section below applies to it like everything else on this page.

The companies that help us run this

We keep the list short on purpose, and this is all of it. One rule runs through the companies that count things: they receive what you did, never what you logged. No food name, no meal, no photo, no check-in answer, nothing about your cycle, no name and no email address is sent to any of them. The language model provider is the exception, and it is the exception on purpose: it cannot read a plate or answer a question without the plate or the question. What goes to it, and what never does, is set out above.

  • The app store sells the app, takes the payment, and holds your records in your own iCloud while syncing is on. We never see your card details.
  • A purchase service tells the app whether a subscription is valid and current. It sees the purchase, not your records.
  • A database host runs the database our server uses. It holds the counting described above, your time zone and app version, whether a subscription is active, and any message you have sent us from inside the app. It holds nothing you have logged.
  • A language model provider answers the questions you ask and drafts the day's note. Your question is what it works from, so the words of the question go to it, and everything around them does not: the request goes from our server rather than from your phone, with contact details and identifiers stripped out of the text and no account, device or name attached to it. There is nothing in it that says the question is yours. The request also tells the provider not to keep the text and not to train on it.
  • A product analytics service counts which parts of the app get used. It receives only the list of actions set out in the section above, with your phone model, its operating system version, the app version, an identifier for your copy of the app, and the town, region and country it works out from the internet address the app connects from.
  • An install attribution service tells us whether an install of Damson came from one of our adverts or links. It receives that the app was installed and opened, the same list of actions as the product analytics service, your phone model, its operating system version, the app version, the internet address the app connects from, an identifier for your copy of the app, and Apple's anonymous advert reports. It does not receive the advertising identifier, and nothing you have logged.
  • An app configuration service sends the app the settings that decide which version of a screen you see, and its kit reports back that the app was opened, how long it was open and that a purchase happened, along with the app version and an identifier for your copy of this app, with no advertising identifier and nothing you have logged.
  • An advertising network lets us measure the adverts we run for Damson on its own platforms. Its kit in the app reports standard app events, that the app was installed, that it was opened, and that a purchase happened, so we can tell whether an advert led to an install. There are no adverts inside Damson.
  • A crash reporting service is told when the app hits a fault, so that we can fix it. It receives the kind of error, where in the app it happened, your phone model, its operating system version and the app version. Your email address, your foods, your meals, your photos, your notes and your name are removed from the report before it is sent, and the report is not tied to a lasting identity for you.
  • An error monitoring service does the same job for our server. It receives the fault and where it happened. The contents of the request that failed, and anything identifying the person who made it, are stripped out before the report leaves our server.
  • A website host serves this website. It holds your email address if you join the waitlist, and it holds your address and your message if you write to us through the form on the support page. Neither reaches our own server, because this website does not have one.
  • Two website analytics services count visits to this website and a short list of things you can do on it: joining the waitlist, opening the App Store link, opening one of the studies we cite, and reaching the end of an article. Neither stores anything on your device, which is why there is no cookie banner here, and neither receives your email address or anything you type. One of them uses the internet address your visit came from to work out which country you are in without storing it.

The waitlist

Joining the waitlist gives us your email address and the page you signed up from, and nothing else. The website host holds it. We use it once, to say the app is out, and then we delete it. To come off the list sooner, reply to any email from us or write to [email protected], and it is gone.

Writing to us

The form on the support page sends your email address and your message to the website host, where we read it and reply. It is kept while the question is open and deleted once it is answered and there is no reason to keep it. It is never added to the waitlist or to any other list, and what you write is not used for anything except answering you.

Writing to us from inside the app

The support screen inside Damson sends your message and the subject you gave it to our own server, where we read it and reply. Your reply arrives as a notification, which is why the app asks for the code your phone uses to receive one, and the first line of our reply travels inside that notification. What you write is used for nothing except answering you, it is never added to any list, and it goes when your account goes.

How long anything is kept

  • On your phone: until you delete the record, or the app. Photos go sooner, once 42 newer ones exist.
  • Nights read from Apple Health: the last ninety, and none at all once you switch the reading off.
  • The count behind your daily allowance: today's and yesterday's. Anything older is deleted the next time a count is read.
  • The day's note: the sentence you were shown is kept for a week, so that a phone a day behind still reads what it showed you. The number of notes written on a day is kept for two days.
  • The fact that a plate reading happened: a row with a time on it and no meal in it, kept while the app is installed and removed when you delete your account.
  • The count of which parts of the app were used: held by the product analytics and install attribution services for as long as our projects there keep it, and never joined to anything you logged.
  • Your waitlist email address: until the launch email has been sent.
  • A message you send us from inside the app: kept while the question is open and for as long as we may need it to answer a follow-up, then deleted with your account.
  • The record of a purchase: kept while you have an account, so that a subscription can be restored on a new phone and a billing question can be answered.
  • The code that delivers your notifications: kept while notifications are on, and removed with your account.
  • Your sign-in: kept while the account exists. The identifier Apple gives us is stored as a one-way hash rather than as itself.
  • When you delete your account from inside the app, we remove your sign-in, your profile, anything you sent us through support, and the notes you were shown. Two things outlive it on purpose. Today's allowance count, held against the one-way identifier, so that deleting and starting again is not a way to get a second day of free readings, and it goes within two days like every other count. And, if we have given you Premium for free, the note that says so, which holds an account identifier and sometimes an email address, so that the gift survives you reinstalling. Write to us and we will remove that one too.

Your rights over your information

UK and EU data protection law gives you rights, and they apply to anything we hold:

  • to ask what we hold about you, and to have a copy of it;
  • to have it corrected if it is wrong;
  • to have it erased;
  • to receive it in a portable form and take it elsewhere;
  • to object to what we do with it, and to ask us to restrict it;
  • to complain to a supervisory authority. In the UK that is the Information Commissioner's Office, and you can go to it without asking us first.

An honest note about the first four of those. For everything that lives on your phone, you already hold the data and we do not have it, so there is nothing for us to send you and nothing for us to erase. The app's own export hands you your records as a file, and the delete-everything action in the app clears them. Those two functions are the mechanism, not a substitute for it: a letter to us cannot reach data that never reached us. For the small amount we do hold, write to us and we will answer within a month.

We rely on three legal bases and no others.

Your consent, for the health information you enter. Before Damson asks you anything about your health, it asks you to agree to it handling what you enter, and it will not go on until you do. That consent is what allows the small amount of health context described above to travel with a request you make. You can withdraw it at any time by deleting everything from inside the app, which clears the agreement along with the records, or by writing to us. Withdrawing does not undo what was already done with it. Reading from Apple Health rests on the same basis, and it is asked for separately and twice: you switch the connection on, and Apple's own sheet asks you again on top of that. Switching it off withdraws it, and takes the nights that were read with it.

Performing our contract with you, for the work you asked for: reading a plate, answering a question, checking that a purchase is current.

Legitimate interest, for three kinds of counting: the one that keeps the daily limits fair and the service affordable, the one that tells us which parts of the app are used, which is how a small team decides what to build next, and the one that tells us whether an advert for Damson led to an install. All three are the least identifying way we could find to do the job, and none of them touches what you logged. There are no adverts inside Damson, we do not profile you, and we sell nothing to anybody.

What we never do

  • Sell or share your records. They are not ours to sell.
  • Show you advertisements, or let anyone target you through Damson.
  • Make you create an account in order to use Damson.
  • Keep your photos, your conversations, or your questions on our servers.
  • Let anyone train a model on what you write. Our agreements with the companies that process it do not permit it.
  • Write anything into Apple Health, or use what we read from it to advertise to you or to train a model. Damson only reads from it, and only once you have switched the reading on.

Children

We do not knowingly collect anything from a child. If you believe a child has been using the app and something of theirs has reached us, write to us and we will remove it.

Changes to this page

When the app changes in a way that affects this page, we change the page and the date at the top on the same day. If a change matters to you, because it widens what reaches us or adds a company that receives it, we will say so in the app before it takes effect rather than quietly editing this page. Earlier versions are yours on request.