Thyme · SlowCraft

Privacy Policy

Effective date: 16 August 2026  |  Last updated: 16 August 2026  |  Applies to: Thyme mobile application for Android and related websites and services

This Privacy Policy explains how personal data is collected, used, shared, and protected when you use Thyme, an AI-assisted calorie and nutrition tracking application for Android devices ("Thyme", the "App", the "Service").

Thyme is developed and operated by Ashu Gupta, an individual developer trading under the name SlowCraft, based in Delhi, India ("we", "us", "our"). SlowCraft is a trading name of a sole individual and is not a separately incorporated company. For the purposes of the EU/UK General Data Protection Regulation we are the data controller; under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary; under the California Consumer Privacy Act we are a business.

Contact for all privacy matters: hello@slowcraft.in

Health data notice. Thyme processes information about your body and diet — including weight, height, age, sex, dietary goals, food logs, and photographs of meals. In many jurisdictions this is treated as a special category or sensitive personal data. We only process it to provide the features you ask for, and, where the law requires a heightened standard, on the basis of your explicit consent, which you may withdraw at any time.
Contents
  1. Scope of this policy
  2. Information we collect
  3. How and why we use your information
  4. Legal bases for processing (GDPR / DPDP Act)
  5. How the AI features work
  6. Service providers and disclosure
  7. International data transfers
  8. Data retention and deletion
  9. Security
  10. Your rights
  11. Region-specific disclosures
  12. Children and young people
  13. Cookies and similar technologies
  14. Google Play permissions and Data safety
  15. Automated decision-making
  16. Changes to this policy
  17. How to contact us and complain

1. Scope of this policy

This policy applies to personal data we process through the Thyme Android application, the backend services that support it, our email communications, and any SlowCraft website or landing page that links to this policy. It does not apply to third-party services you may reach from within Thyme (for example the Google Play Store or an external website), which are governed by their own privacy notices.

Thyme is available to users worldwide. Where a specific national or state law grants you rights beyond those described here, those rights apply to you and are described in Section 11.

2. Information we collect

2.1 Information you provide directly

CategoryExamplesSensitivity
Account dataName or display name, email address, password (stored only as a salted cryptographic hash), or identifiers received if you sign in through a third-party provider such as Google Sign-InStandard personal data
Health and body metricsHeight, weight and weight history, age or date of birth, sex assigned at birth, activity level, dietary preferences or restrictions, calorie and macronutrient targets, and goals such as weight loss or maintenanceSensitive / special category health data
Food and nutrition logsMeals and food items logged, portion sizes, timestamps, calorie and macronutrient values, notes you addSensitive / special category health data
Food photographsPhotographs you capture with your camera or select from your device gallery so that the AI can identify the food and estimate its nutritional content, together with basic image metadataSensitive / special category health data
Support and correspondenceMessages, feedback, bug reports and any information you choose to include when contacting usStandard personal data

2.2 Information collected automatically

2.3 Information we do not collect

We do not knowingly collect government identification numbers, financial or payment card details (Thyme is free and contains no purchases), precise GPS location, contacts, call or SMS data, or biometric identifiers used for identification purposes. We do not purchase personal data from data brokers.

3. How and why we use your information

PurposeWhat this involves
Providing the core ServiceCreating and maintaining your account, storing your food and body logs, calculating calorie and macronutrient totals, generating targets and progress views
AI food recognition and estimationAnalysing the photographs and descriptions you submit in order to identify food items and estimate their nutritional content (see Section 5)
PersonalisationTailoring goals, recommendations, reminders and insights to the profile and preferences you have set
Service communicationsSending account emails such as verification, password reset, security notices and material changes to this policy, delivered through Resend
Product improvement and analyticsUnderstanding which features are used and where users encounter problems, in aggregate or pseudonymised form wherever practicable
Security, integrity and abuse preventionDetecting and preventing fraud, abuse, automated scraping, and unauthorised access; maintaining audit and access logs
Legal complianceResponding to lawful requests, exercising or defending legal claims, and meeting record-keeping obligations

We do not sell your personal data, and we do not share it with third parties for cross-context behavioural advertising. We do not use your health data, food logs or food photographs to serve you advertisements.

4. Legal bases for processing (GDPR / DPDP Act)

Where the EU or UK GDPR applies, we rely on the following legal bases:

Processing activityLegal basis (GDPR Art. 6)Additional basis for health data (Art. 9)
Creating and running your accountPerformance of a contract (Art. 6(1)(b))
Storing and analysing body metrics, food logs and food photosPerformance of a contract (Art. 6(1)(b))Your explicit consent (Art. 9(2)(a))
Analytics and product improvementLegitimate interests (Art. 6(1)(f)) or consent where required by local law
Security, abuse prevention and loggingLegitimate interests (Art. 6(1)(f))
Service and transactional emailsPerformance of a contract (Art. 6(1)(b))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))Establishment or defence of legal claims (Art. 9(2)(f))

Where you have given consent, you may withdraw it at any time — through the in-app privacy settings or by emailing us. Withdrawal does not affect processing carried out before withdrawal, but some features may stop working if the underlying data is no longer available.

Under India's Digital Personal Data Protection Act, 2023, we process your personal data on the basis of the consent you give at sign-up and in-app, or for legitimate uses permitted by that Act. The notice you receive at the point of collection, read together with this policy, constitutes our notice under Section 5 of that Act.

5. How the AI features work

Thyme's core feature uses artificial intelligence to estimate nutritional information from a photograph or description of a meal.

Accuracy. AI-generated nutritional estimates are approximations and may be materially inaccurate. Thyme is a wellness tool, not a medical device, and its output is not medical, nutritional or dietary advice. See the Terms & Conditions for the full disclaimer.

6. Service providers and disclosure

We keep our supply chain deliberately small. We share personal data only with the following categories of recipients, and only to the extent necessary:

ProviderRoleData involved
Microsoft Azure OpenAI ServiceAI analysis of food images and descriptionsFood photographs, food descriptions, minimal meal context
RenderApplication and database hosting for our backendAll account, profile, log and image data stored by the Service
PostHogProduct and usage analyticsPseudonymous user identifier, device and app data, in-app events
ResendTransactional email deliveryEmail address, name, message content
Google (Play services)App distribution, and sign-in where you use itAccount identifier where you choose Google Sign-In; installation and crash data governed by Google's own policies

Each provider is bound by contract to process personal data only on our documented instructions, to apply appropriate security measures, and not to use it for their own purposes.

We may also disclose personal data: (a) where required by law, court order or a valid request from a public authority; (b) where necessary to establish, exercise or defend legal claims; (c) to protect the rights, safety or property of users, the public or ourselves; or (d) to a successor in the event that the Thyme service or its assets are transferred, in which case we will notify you and this policy will continue to apply until replaced.

7. International data transfers

We operate from India and our providers operate globally, so your personal data may be processed in India, the European Economic Area, the United Kingdom, the United States and other countries where our providers maintain infrastructure. Data protection laws in those countries may differ from those in your own.

Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards under Article 46 GDPR — principally the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where applicable), supplemented by technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by emailing hello@slowcraft.in.

8. Data retention and deletion

9. Security

We apply technical and organisational measures appropriate to the sensitivity of health data, including: encryption of data in transit using TLS; encryption at rest for stored data and images; hashed and salted password storage; role-based, least-privilege access controls, with access limited to the developer and strictly necessary automated systems; segregated production credentials and secret management; and regular dependency and platform patching.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your device and account credentials secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where the law requires, affected users without undue delay — within 72 hours of becoming aware where the GDPR applies, and within the timelines prescribed by the DPDP Act and its rules in India.

10. Your rights

Subject to your local law, you have the right to:

To exercise any right, email hello@slowcraft.in from the address registered to your account, or use the in-app privacy controls. We respond within 30 days, and will tell you if we need a permitted extension. We may ask for information to verify your identity before acting, purely to protect your account. Exercising your rights is free unless a request is manifestly unfounded or excessive.

11. Region-specific disclosures

11.1 India — Digital Personal Data Protection Act, 2023

As a Data Principal you have the right to access a summary of your personal data and our processing, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of your death or incapacity. You are also expected to provide authentic information and not to file false or frivolous grievances. Consent may be withdrawn at any time with the same ease as it was given. Our grievance contact is given in Section 17; if your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.

11.2 European Economic Area and United Kingdom — GDPR

The rights in Section 10 correspond to Articles 15–22 GDPR. We have not appointed a Data Protection Officer, as we are not required to do so. If you are in the EEA or UK, you may lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

11.3 California — CCPA/CPRA, and other US state laws

In the preceding 12 months we have collected the categories of personal information described in Section 2, for the business purposes described in Section 3, from the sources described in Section 2, and disclosed them to the service providers listed in Section 6. Health and precise-inference data of the kind Thyme handles is treated as sensitive personal information; we use it only to provide the Service you requested and for permitted purposes such as security — not to infer characteristics about you for advertising.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, including of consumers under 16. You have the rights to know, delete, correct, and to limit the use of sensitive personal information; and we will not discriminate against you for exercising them. You may use an authorised agent, with proof of authorisation. Submit requests to hello@slowcraft.in. Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws may exercise equivalent rights, including appealing a refusal by replying to our decision email.

12. Children and young people

Thyme is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected data from a person under 16, we will delete the account and its data promptly. Where local law sets a higher age of digital consent or requires verifiable parental consent for minors — including under India's DPDP Act, which requires verifiable parental consent for children under 18 — you must not use Thyme unless that consent has been obtained. A parent or guardian who believes a child has provided us with personal data should contact hello@slowcraft.in.

13. Cookies and similar technologies

The Thyme Android app does not use browser cookies for advertising. It uses local device storage and a secure authentication token to keep you signed in, plus a pseudonymous analytics identifier.

Our website and landing pages may use:

TypePurposeConsent
Strictly necessarySession management, security, load balancing, and remembering your cookie preferencesNot required
Analytics (PostHog)Understanding page visits, referral sources and feature interest in aggregateRequested where required by law

We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser settings; strictly necessary cookies cannot be disabled without affecting site function. We honour Global Privacy Control (GPC) signals where legally required.

14. Google Play permissions and Data safety

Thyme requests only the permissions needed for the features you use:

You can withdraw any permission at any time in your Android settings; features that depend on it will stop working. Our declarations in the Google Play Data safety section are consistent with this policy. Thyme complies with Google Play's User Data, Health Apps and Photo & Video Permissions policies, and we do not transfer your data to third parties for purposes incompatible with those policies.

15. Automated decision-making

Thyme uses automated processing to estimate nutritional values and to generate suggested calorie and macronutrient targets. These outputs are informational suggestions only. They do not produce legal effects or similarly significant effects on you within the meaning of Article 22 GDPR, and you remain free to disregard or manually override them.

16. Changes to this policy

We may update this policy to reflect changes in the Service, our providers, or the law. The "Last updated" date at the top will always reflect the current version. If a change is material — for example a new purpose for processing health data or a new category of recipient — we will notify you in the app or by email before it takes effect and, where the law requires it, ask for your renewed consent. Continued use of Thyme after a change takes effect means you accept the updated policy.

17. How to contact us and complain

Data Controller / Data Fiduciary: Ashu Gupta, trading as SlowCraft
Location: Delhi, India
Privacy and grievance contact: hello@slowcraft.in
Response time: acknowledgement within 7 days; substantive response within 30 days

If you are not satisfied with our response, you may complain to your local data protection authority — the Data Protection Board of India, your EEA supervisory authority, the UK Information Commissioner's Office, or your US state Attorney General, as applicable to you.