Privacy policy
GK Health is a food diary, so almost everything in it is about your body. This page says plainly what we hold, what it is used for, who else sees it, how long it stays, and how to take it away.
Who we are
GK Health is made by GK Tools Ltd, a company registered in England and Wales (number 16434833), registered office 483 Green Lanes, London N13 4BS. GK Tools Ltd is the data controller. Questions and requests: support@gk.tools.
What we collect, and why
| Data | Where it comes from | What it is for |
|---|---|---|
| Account: name, email address, or the identifier Apple gives us when you use Sign in with Apple | You, when you create an account | Signing you in, telling you about your subscription, and account emails. Nothing else. |
| Your food diary: meals, items, calories, macros, nutrients, notes, meal times | What you type, say or confirm in the app | The diary itself, your totals, your usual meals, your progress |
| Photos of meals and nutrition labels, with their capture date | Photos you take or choose in the app | Estimating a meal, reading a label, your own photo record |
| Your personal food catalogue and nicknames for foods | Built from what you log and tell the app | Pricing meals you have had before without guessing |
| Weight, body measurements, targets, height, age, sex, activity level | You | Your targets, BMI, maintenance estimate and trend |
| Apple Health data you allow: weight, steps, active energy, heart rate, resting heart rate, sleep, workouts | Apple Health, only with your permission in iOS | Context for the chat ("how was my day?") and the dashboard. Meals you log are written back to Apple Health if you allow that too. |
| Chat messages and the app's replies | You | Answering you, and improving the answers to you (the app learns your usuals and corrections) |
| Feedback you give about the app in the chat | You | Fixing the app |
| Technical records: the device a sign-in came from, when you used the AI, server logs | Your device and our servers | Security, the weekly AI allowance, and fixing faults. Logs do not contain your diary. |
We do not collect your location, contacts, advertising identifiers or anything from other apps. There is no analytics or advertising software in GK Health.
Health data is special-category data
Your diet, weight and Apple Health readings are health data under UK GDPR. We process them because you ask us to, by using the app: the legal basis is your explicit consent (Article 9(2)(a)), which you give when you create your account and can withdraw at any time by deleting it. Account and billing records are processed to perform our contract with you (Article 6(1)(b)); security and fault logs on our legitimate interest in running a reliable service (Article 6(1)(f)).
Who else sees your data
- Google (Gemini API) - when you ask the app to estimate a meal, read a label or answer a question, the text of your message, the relevant photo(s), and the parts of your diary and catalogue needed to answer are sent to Google's Gemini API to produce the reply. We use the paid API, which under Google's Gemini API terms is not used to train Google's models. Nothing is sent until you send a message or a photo.
- Brave Search - only when you explicitly ask the app to look a product up online ("look up ... online"), the product name you typed is sent to Brave's search API. Never your diary.
- Apple - handles all payment. We never see your card. Apple tells us whether a subscription is active, renewed, refunded or cancelled. Sign in with Apple shares with us only what you choose.
- Our hosting provider - the servers gkhealth.app runs on are operated for GK Tools Ltd by its hosting provider. Your photos are stored outside the web root and are only served to your signed-in device.
We do not sell your data, share it with advertisers, or use it to build profiles for anyone else. We will disclose data if the law requires it, and we will tell you if we are allowed to.
Where it is kept
On our own servers, with your photos encrypted in transit and held outside the public web tree, and on your device (the app keeps a local copy of your diary and your photos so it works offline). The AI processing described above happens on Google's servers for the duration of the request.
How long we keep it
- Your diary, photos, catalogue and measurements: for as long as you have an account.
- Deleted account: when you delete your account in the app, it is switched off at once and signed out everywhere. Thirty days later everything - every row and every photo - is removed from our servers for good. Signing in again within those thirty days brings it back, so a slip is not final.
- AI usage records (that a turn happened, not what it said): eight days, for the weekly allowance.
- Subscription notifications from Apple: a year, so we can answer a billing question.
- Photos awaiting your confirmation in the chat: deleted after a day whether or not you log the meal.
Your rights
You can do most of this yourself, in the app, without asking us:
- See and export everything - the app's Settings › Account gives you a complete copy of your data, or email us for one.
- Correct anything - tell the chat, or edit the entry.
- Delete everything - Settings › Account › Delete account, or email us.
- Withdraw consent - deleting your account is withdrawing consent; you can also stop the app reading Apple Health in iOS Settings at any time.
You also have the rights to restrict or object to processing and to data portability. Email support@gk.tools and we will answer within a month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
Children
GK Health is not for anyone under 16, and we do not knowingly hold data about anyone under 16. If you think we do, tell us and we will remove it.
Security
Everything travels over HTTPS. Your session is a per-device token you can revoke by signing out, and the app can lock itself with Face ID or Touch ID. Our staff do not read your diary; the only people who ever see it are you, and - for the seconds it takes to answer - the AI service above.
Changes
If this policy changes in a way that matters, we will say so in the app before the change applies. The date at the top is always the current version.