This Privacy Policy explains how personal data is collected, used, shared, and protected when you use Thyme, an AI-assisted calorie and nutrition tracking application for Android devices ("Thyme", the "App", the "Service").
Thyme is developed and operated by Ashu Gupta, an individual developer trading under the name SlowCraft, based in Delhi, India ("we", "us", "our"). SlowCraft is a trading name of a sole individual and is not a separately incorporated company. For the purposes of the EU/UK General Data Protection Regulation we are the data controller; under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary; under the California Consumer Privacy Act we are a business.
Contact for all privacy matters: hello@slowcraft.in
This policy applies to personal data we process through the Thyme Android application, the backend services that support it, our email communications, and any SlowCraft website or landing page that links to this policy. It does not apply to third-party services you may reach from within Thyme (for example the Google Play Store or an external website), which are governed by their own privacy notices.
Thyme is available to users worldwide. Where a specific national or state law grants you rights beyond those described here, those rights apply to you and are described in Section 11.
| Category | Examples | Sensitivity |
|---|---|---|
| Account data | Name or display name, email address, password (stored only as a salted cryptographic hash), or identifiers received if you sign in through a third-party provider such as Google Sign-In | Standard personal data |
| Health and body metrics | Height, weight and weight history, age or date of birth, sex assigned at birth, activity level, dietary preferences or restrictions, calorie and macronutrient targets, and goals such as weight loss or maintenance | Sensitive / special category health data |
| Food and nutrition logs | Meals and food items logged, portion sizes, timestamps, calorie and macronutrient values, notes you add | Sensitive / special category health data |
| Food photographs | Photographs you capture with your camera or select from your device gallery so that the AI can identify the food and estimate its nutritional content, together with basic image metadata | Sensitive / special category health data |
| Support and correspondence | Messages, feedback, bug reports and any information you choose to include when contacting us | Standard personal data |
We do not knowingly collect government identification numbers, financial or payment card details (Thyme is free and contains no purchases), precise GPS location, contacts, call or SMS data, or biometric identifiers used for identification purposes. We do not purchase personal data from data brokers.
| Purpose | What this involves |
|---|---|
| Providing the core Service | Creating and maintaining your account, storing your food and body logs, calculating calorie and macronutrient totals, generating targets and progress views |
| AI food recognition and estimation | Analysing the photographs and descriptions you submit in order to identify food items and estimate their nutritional content (see Section 5) |
| Personalisation | Tailoring goals, recommendations, reminders and insights to the profile and preferences you have set |
| Service communications | Sending account emails such as verification, password reset, security notices and material changes to this policy, delivered through Resend |
| Product improvement and analytics | Understanding which features are used and where users encounter problems, in aggregate or pseudonymised form wherever practicable |
| Security, integrity and abuse prevention | Detecting and preventing fraud, abuse, automated scraping, and unauthorised access; maintaining audit and access logs |
| Legal compliance | Responding to lawful requests, exercising or defending legal claims, and meeting record-keeping obligations |
We do not sell your personal data, and we do not share it with third parties for cross-context behavioural advertising. We do not use your health data, food logs or food photographs to serve you advertisements.
Where the EU or UK GDPR applies, we rely on the following legal bases:
| Processing activity | Legal basis (GDPR Art. 6) | Additional basis for health data (Art. 9) |
|---|---|---|
| Creating and running your account | Performance of a contract (Art. 6(1)(b)) | — |
| Storing and analysing body metrics, food logs and food photos | Performance of a contract (Art. 6(1)(b)) | Your explicit consent (Art. 9(2)(a)) |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) or consent where required by local law | — |
| Security, abuse prevention and logging | Legitimate interests (Art. 6(1)(f)) | — |
| Service and transactional emails | Performance of a contract (Art. 6(1)(b)) | — |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | Establishment or defence of legal claims (Art. 9(2)(f)) |
Where you have given consent, you may withdraw it at any time — through the in-app privacy settings or by emailing us. Withdrawal does not affect processing carried out before withdrawal, but some features may stop working if the underlying data is no longer available.
Under India's Digital Personal Data Protection Act, 2023, we process your personal data on the basis of the consent you give at sign-up and in-app, or for legitimate uses permitted by that Act. The notice you receive at the point of collection, read together with this policy, constitutes our notice under Section 5 of that Act.
Thyme's core feature uses artificial intelligence to estimate nutritional information from a photograph or description of a meal.
We keep our supply chain deliberately small. We share personal data only with the following categories of recipients, and only to the extent necessary:
| Provider | Role | Data involved |
|---|---|---|
| Microsoft Azure OpenAI Service | AI analysis of food images and descriptions | Food photographs, food descriptions, minimal meal context |
| Render | Application and database hosting for our backend | All account, profile, log and image data stored by the Service |
| PostHog | Product and usage analytics | Pseudonymous user identifier, device and app data, in-app events |
| Resend | Transactional email delivery | Email address, name, message content |
| Google (Play services) | App distribution, and sign-in where you use it | Account identifier where you choose Google Sign-In; installation and crash data governed by Google's own policies |
Each provider is bound by contract to process personal data only on our documented instructions, to apply appropriate security measures, and not to use it for their own purposes.
We may also disclose personal data: (a) where required by law, court order or a valid request from a public authority; (b) where necessary to establish, exercise or defend legal claims; (c) to protect the rights, safety or property of users, the public or ourselves; or (d) to a successor in the event that the Thyme service or its assets are transferred, in which case we will notify you and this policy will continue to apply until replaced.
We operate from India and our providers operate globally, so your personal data may be processed in India, the European Economic Area, the United Kingdom, the United States and other countries where our providers maintain infrastructure. Data protection laws in those countries may differ from those in your own.
Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards under Article 46 GDPR — principally the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where applicable), supplemented by technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by emailing hello@slowcraft.in.
We apply technical and organisational measures appropriate to the sensitivity of health data, including: encryption of data in transit using TLS; encryption at rest for stored data and images; hashed and salted password storage; role-based, least-privilege access controls, with access limited to the developer and strictly necessary automated systems; segregated production credentials and secret management; and regular dependency and platform patching.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your device and account credentials secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where the law requires, affected users without undue delay — within 72 hours of becoming aware where the GDPR applies, and within the timelines prescribed by the DPDP Act and its rules in India.
Subject to your local law, you have the right to:
To exercise any right, email hello@slowcraft.in from the address registered to your account, or use the in-app privacy controls. We respond within 30 days, and will tell you if we need a permitted extension. We may ask for information to verify your identity before acting, purely to protect your account. Exercising your rights is free unless a request is manifestly unfounded or excessive.
As a Data Principal you have the right to access a summary of your personal data and our processing, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of your death or incapacity. You are also expected to provide authentic information and not to file false or frivolous grievances. Consent may be withdrawn at any time with the same ease as it was given. Our grievance contact is given in Section 17; if your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.
The rights in Section 10 correspond to Articles 15–22 GDPR. We have not appointed a Data Protection Officer, as we are not required to do so. If you are in the EEA or UK, you may lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
In the preceding 12 months we have collected the categories of personal information described in Section 2, for the business purposes described in Section 3, from the sources described in Section 2, and disclosed them to the service providers listed in Section 6. Health and precise-inference data of the kind Thyme handles is treated as sensitive personal information; we use it only to provide the Service you requested and for permitted purposes such as security — not to infer characteristics about you for advertising.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, including of consumers under 16. You have the rights to know, delete, correct, and to limit the use of sensitive personal information; and we will not discriminate against you for exercising them. You may use an authorised agent, with proof of authorisation. Submit requests to hello@slowcraft.in. Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws may exercise equivalent rights, including appealing a refusal by replying to our decision email.
Thyme is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected data from a person under 16, we will delete the account and its data promptly. Where local law sets a higher age of digital consent or requires verifiable parental consent for minors — including under India's DPDP Act, which requires verifiable parental consent for children under 18 — you must not use Thyme unless that consent has been obtained. A parent or guardian who believes a child has provided us with personal data should contact hello@slowcraft.in.
The Thyme Android app does not use browser cookies for advertising. It uses local device storage and a secure authentication token to keep you signed in, plus a pseudonymous analytics identifier.
Our website and landing pages may use:
| Type | Purpose | Consent |
|---|---|---|
| Strictly necessary | Session management, security, load balancing, and remembering your cookie preferences | Not required |
| Analytics (PostHog) | Understanding page visits, referral sources and feature interest in aggregate | Requested where required by law |
We do not use advertising or cross-site tracking cookies. You can block or delete cookies through your browser settings; strictly necessary cookies cannot be disabled without affecting site function. We honour Global Privacy Control (GPC) signals where legally required.
Thyme requests only the permissions needed for the features you use:
You can withdraw any permission at any time in your Android settings; features that depend on it will stop working. Our declarations in the Google Play Data safety section are consistent with this policy. Thyme complies with Google Play's User Data, Health Apps and Photo & Video Permissions policies, and we do not transfer your data to third parties for purposes incompatible with those policies.
Thyme uses automated processing to estimate nutritional values and to generate suggested calorie and macronutrient targets. These outputs are informational suggestions only. They do not produce legal effects or similarly significant effects on you within the meaning of Article 22 GDPR, and you remain free to disregard or manually override them.
We may update this policy to reflect changes in the Service, our providers, or the law. The "Last updated" date at the top will always reflect the current version. If a change is material — for example a new purpose for processing health data or a new category of recipient — we will notify you in the app or by email before it takes effect and, where the law requires it, ask for your renewed consent. Continued use of Thyme after a change takes effect means you accept the updated policy.
Data Controller / Data Fiduciary: Ashu Gupta, trading as SlowCraft
Location: Delhi, India
Privacy and grievance contact: hello@slowcraft.in
Response time: acknowledgement within 7 days; substantive response within 30 days
If you are not satisfied with our response, you may complain to your local data protection authority — the Data Protection Board of India, your EEA supervisory authority, the UK Information Commissioner's Office, or your US state Attorney General, as applicable to you.