Privacy Policy — how the app handles your information, in plain terms.
This policy explains how Matresense ("the app," "we," "us") handles your information. Matresense is developed by Molly Greenwood.
If you have questions about this policy or your data, contact: [email protected]
Depending on how you use the app, this can include:
If you tap the microphone icon when searching for a food to log, your speech is handed to your device's own built-in speech-to-text feature (typically provided by Google, via Android's standard speech recognition service) — not to any code or server of ours. Only the resulting written text comes back to the app, to use as your search text; the app never records, stores, or has access to the audio itself, and doesn't request microphone permission for its own use.
Depending on your device and its settings, that built-in speech-to-text feature may process your voice on-device or send it to Google's servers to be transcribed — the same as it would for any other app's search box or Android's own voice typing. That processing is governed by Google's Privacy Policy and your own device's speech/voice settings, not by this app.
Alongside the health data above, the app stores your own preferences locally: which coaching topics you've hidden, which nutrients you've chosen not to display, your streak progress and earned badges, which tabs you've pinned, and whether you've seen each one-time welcome screen. These never leave your device.
The app asks, once, whether to keep everything local to your device or to create an account. Local-only is the default and the only thing that actually does anything beyond create an identity right now — see below.
If you choose to create an account, you provide an email address and password, handled by Google's Firebase Authentication service — we don't see or store your password ourselves; Firebase does, using its own security practices. Creating an account does not currently back up or sync any of your logged data (food, symptoms, weight, profile, etc.) — it only creates an identity you could sign into on another device in future, once that syncing capability is built as a separate piece of work. Until then, an account behaves the same as local-only for every purpose except your email address and password, which Firebase holds. You can switch between local-only and account mode, or sign out, at any time in Settings.
Accurate for the current version. If any of this changes, the policy is updated first — see Changes to this policy.
All the information listed above is stored locally on your device, in the app's own private database. There is no company server this data is sent to or stored on. If you've created an account, your email and password are held by Firebase for sign-in purposes only — your logged health data itself still isn't synced or backed up anywhere, in either storage mode, until that capability is built.
The app sends specific, limited data to the following third-party services in order to provide specific features. No profile, health, or symptom data is sent to any of them beyond what's described here.
generativelanguage.googleapis.com): if you
photograph a nutrition label or a food item to log it, that photo is sent
to Google's Gemini API for analysis (identifying the food and its
nutrition values). Google's own privacy policy governs how they handle
that request — see
Google's Privacy Policy and their
Gemini API terms.Besides Firebase Authentication for anyone who opts into an account, none of these integrations involve creating an account with the third party, and none of them receive your name, profile, or logged health/ symptom data — only the specific photo, search text, barcode, or location needed for that one feature to work.
Google, the USDA, Open Food Facts and OpenWeather may handle these requests on servers outside the UK. Each of them is responsible for that processing under its own privacy policy and its own safeguards, linked above. The only things that travel are the ones listed above — a photo, a search term, a barcode, or an approximate location. Your profile, your logged entries and your health records are not among them, and never leave your device.
The in-app "Send feedback" option opens your device's own email app with a pre-filled message addressed to our feedback inbox, including your typed feedback plus the app version, Android version, and device model. This is sent from your email account via your email app — we don't have access to it until you actually send it, and it isn't routed through any server we run. Whatever your own email provider's retention/privacy practices are will apply to that message.
The "report something that doesn't look right" option on a food entry works the same way, and additionally includes details of the entry you are reporting — the food name, where its nutrition data came from, and the figures shown — so the problem can be investigated. You can see and edit the whole message before sending it, and nothing is sent if you close your email app without sending.
Because almost all your data lives only on your device, the most direct way to exercise control over it is within the app itself: you can view, edit, or delete any logged entry, and uninstalling the app removes the local database outright — permanently and with no copy kept anywhere, as described under "How your data is stored" above.
There's currently no in-app tool to export a machine-readable copy of your data (your right to data portability under UK GDPR) — since the data already lives only on your own device and we hold no copy of it ourselves, the practical way to see or take a copy of anything is to view it directly in the app. If that matters to you, let us know at the address below.
For data you've sent to a third party (e.g. a photo sent to Google's Gemini API), that provider is separately responsible for that copy of the data under their own privacy policy, and you'd need to contact them directly for requests relating to it.
Under UK GDPR you have the right to be informed about how your data is used, to access it, to have inaccurate data corrected, to have it erased, to restrict or object to its processing, and to data portability. Because the app holds your data only on your own device and we keep no copy, you exercise most of these directly in the app rather than by asking us: you can view, edit and delete any entry, and remove all of it by uninstalling.
If you are unhappy with how your data has been handled, please contact us first at [email protected]. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
Matresense is intended for adults aged 18 and over who are tracking their own pregnancy, postpartum or preconception health. It is not directed at children, we do not knowingly collect data from them, and the app is listed for an adult audience on Google Play.
This is a statement of who the app is designed for, not an age check. The app holds your data on your own device and has no accounts, so we have no way of knowing any user's age and do not attempt to determine it.
If this policy changes, the "Last updated" date at the top will be revised, and the current version will always be available at this address.
If a change materially affects how your data is handled, that will be flagged inside the app as well, rather than only here. That includes a new third-party service, a new category of information leaving your device, and the introduction of advertising, analytics or crash reporting if any of those are added in a future version. Anything involving your health data specifically would need your explicit consent, not just a policy update — see the note on special category data above.
Email: [email protected]
This is a monitored address on the app's own domain, and is the same address the in-app "Send feedback" option writes to.