Privacy Policy

Last updated: 13 May 2026

Olara is built and operated by Zak Edmundson, referred to in this policy as "we", "us", or "Olara". This policy explains what data Olara collects when you use the app, where it lives, and the choices you have over it. The short version: most of your data stays on your phone, the small slice that touches our servers is the bare minimum for billing and the Snap feature, we don't sell anything, and you can take it all with you or delete it at any time.

What we collect

On your phone, Olara holds the gut scores you log each day, the meals and symptoms you log, the trigger profile you build through reintroduction or that Olara infers from your logs, notes you save against recipes, items you add to your shopping basket, your notification preferences, and a small set of app preferences.

If you provided your email address during onboarding (it's optional, you can skip it), we store that on your phone too and pass it to our newsletter service so we can send you occasional updates. You can ask us to remove you at any time.

When you take a Snap or open the paywall, the app talks to our server, and that server briefly holds a device-specific identifier so we can apply the trial Snap limit and check your subscription status. That identifier is generated by your phone (Apple's IDFV on iOS, Android's per-app ID on Android) and isn't linked to your real-world identity.

Snap (photo analysis)

When you use the Snap feature to photograph a meal, menu, or food label, the photo goes to Olara's server (hosted by Vercel in the EU) which forwards it to Anthropic's Claude API for analysis. Anthropic returns a structured result (estimated ingredients and rough quantities) which our server passes back to your phone and stores in your meal log on your device.

Neither Olara nor Vercel retains a copy of the photo. Anthropic's handling of API inputs is governed by their commercial terms: photos aren't used to train their models.

Subscriptions and billing

When you subscribe to Olara (£9.99/month after the 7-day free trial), payment is handled by Apple's App Store or Google Play. We never see your card details. Those stay with Apple or Google.

We use RevenueCat to mirror your subscription state (is it active, when does it renew, has it been cancelled). RevenueCat receives an anonymous purchase token from Apple or Google plus your device-specific identifier. They do not receive your name, email, or any identifying data.

If you tick the cooling-off waiver checkbox before subscribing, you've asked us to start your subscription immediately. UK Consumer Contracts Regulations give you a 14-day right to cancel any digital service; ticking the waiver means you've consented to start the service straight away and the 14-day right no longer applies. You can still cancel auto-renewal at any time from your App Store or Play Store settings.

Where your data lives

Most of your Olara data is stored locally on your phone, in a SQLite database managed by iOS or Android. It does not leave your device unless you explicitly:

  • Use Export my data: the file goes wherever you choose to share it.
  • Use Report a bug: anything you paste into the email goes to zak@zakedmundson.com.
  • Use Snap: the photo only, as described above.

On our server, we hold a small set of records per device:

  • Your trial-start timestamp and a rolling 7-day list of Snap timestamps (for the trial Snap limit).
  • A cached mirror of your subscription state.
  • A pending-deletion record if you've asked us to delete your account on a 30-day grace.

That's it. Olara has no analytics, no tracking pixels, no advertising IDs, no third-party SDKs that share data outside the app.

Who else processes your data

We use a small number of services to run Olara. Each is bound by their own privacy terms and contractual data-protection obligations to us:

  • Anthropic (US/EU): Snap photo analysis. Photos aren't retained, aren't used for training.
  • Vercel (EU): hosts the Olara server (proxy + rate-limit + entitlement records).
  • RevenueCat (US/EU): subscription state.
  • Apple, Google: App Store / Play Store billing. They process your card data; we don't see it.
  • Beehiiv (US): sends Olara's newsletter to you, if you've opted in.
  • Sentry (EU): receives crash reports if the app or our server hits an unhandled error. Reports contain technical details only (which screen, which code path, device model, app version, OS version). They don't include your name, email, logged meals, symptoms, gut scores, photos, or any other Olara data.

We don't share your data with anyone else.

Your rights under UK GDPR

You have the right to:

  • Access your data: Profile → Data & privacy → Export my data. The export includes both what's on your device and what we hold on our server.
  • Erase your data: Profile → Delete my account. You can choose Delete now (we wipe local and server data immediately and ask RevenueCat to delete your subscription record) or Delete in 30 days (recoverable until then if you change your mind). Account deletion doesn't cancel any active Apple or Google subscription; you need to cancel that in your App Store or Play Store settings.
  • Correct inaccurate data: edit any log directly inside the app.
  • Take it elsewhere: Export my data gives you a JSON file you can move anywhere.
  • Withdraw consent: if you opted into the newsletter, unsubscribe from any newsletter email or contact us.
  • Complain to a regulator: the UK Information Commissioner's Office at ico.org.uk if you think we're handling your data wrongly.

Children

Olara isn't for under-18s. If you're under 18, please don't use this app. We don't knowingly collect data from children. The age confirmation step before subscribing is the moment you tell us you're old enough; tapping "I'm not" closes the paywall and disables it permanently.

Changes to this policy

We'll update this policy if anything material changes about how Olara handles data. The "Last updated" date above will change when we do. For substantial changes (new sub-processors, new data we collect), we'll surface a notice inside the app before the change takes effect.

Contact

Questions about this policy or your data: zak@zakedmundson.com. We aim to respond within a week.