Recompose Privacy Policy
Last updated: 5 September 2026
Who We Are
Recompose is a product of Recompose Labs, provided by Anton Kiselev (“Recompose”, “we”, “us”, or “our”), an individual developer based in the United Kingdom. Recompose is not currently operated through a separate company — there is no “Recompose Labs” corporation, limited company, or other legal entity distinct from Anton Kiselev.
If you have questions about this policy or how your information is handled, contact us at support@recomposelabs.com.
What Recompose Does
Recompose is a nutrition and body-composition tracking app for people who lift weights. It helps you log meals, track calories and macronutrients, set nutrition goals, follow trends over time, and optionally connect Apple Health and share progress with a coach. Recompose uses cloud-based AI to help estimate nutrition from things you type, photograph, or say, and to answer questions about your own logged data in the Ask feature.
You can use Recompose’s core logging features without creating an account. An account is optional and is used for cloud sync, recovery on a new device, and Coach Sharing.
Recompose is a tracking and estimation tool. It is not a medical device, and it does not provide medical advice, diagnosis, or treatment. See “Health Information / No Medical Advice” in our Terms of Service for more detail.
Information You Provide
Depending on how you use Recompose, you may provide:
- Account information, if you choose to sign in — see “Account and Sign in with Apple” below.
- Profile information — date of birth, biological sex, height, weight, activity level, and your nutrition goal, entered manually or imported from Apple Health.
- Nutrition logs — meal names, timestamps, quantities, and the calories and macronutrients associated with each meal, whether you type them, dictate them, or they are estimated from a photo.
- Photos and camera captures you choose to send for meal analysis or Ask.
- Audio recordings you make to describe a meal or ask a question by voice.
- Ask/chat messages you send to Recompose’s nutrition assistant, including meal-log proposals the assistant generates for you to review.
- Coach-sharing choices — share links you create, coaches you connect with, and the access level you choose.
- Support communications — anything you send us via Send Feedback, Report a Bug, or a direct email to support@recomposelabs.com.
You are never required to log a photo or voice recording to use Recompose — text entry is always available as an alternative.
Health and Nutrition Data
Recompose exists to track health and nutrition information, which under UK GDPR and similar laws is treated as a special, more sensitive category of personal data. This includes your logged meals, calories and macronutrients, body weight, height, date of birth, biological sex, and any data read from Apple Health.
We use this information only to provide Recompose’s own functionality to you — calculating targets, showing your progress, generating trends, enabling AI-assisted logging, syncing supported data when you are signed in, and (if you choose) sharing information with a coach. We do not sell this information, and we do not use it for advertising.
Apple Health
If you choose to connect Apple Health, Recompose asks for permission to:
- Read: date of birth, biological sex, height, body mass (weight), active energy burned, resting (basal) energy burned, exercise time, step count, and workouts. These are used on your device to personalise nutrition targets, show body-weight trends, and help infer a starting activity level. If you sign in, Recompose may also keep a private cloud copy of supported health and activity information — currently weight history, daily activity totals (active energy, resting energy, exercise time, and steps), and workouts — so it can sync across your devices and, if you choose, be included in Coach Sharing.
- Write: the calories, protein, carbohydrates, and fat for meals you log, so that food you log in Recompose can also appear in the Health app if you want it to. You can turn this off in Settings at any time; doing so stops new meals from being written to Health without affecting meals already written.
Connecting Apple Health does not mean that every Health record on your iPhone is uploaded. Recompose only reads the types listed above, and only the supported subset described above is synced to our cloud when you have an account.
Health access is entirely permission-based and controlled by you through iOS. You choose exactly which data types to share when the system permission prompt appears, and you can review or revoke any of them at any time in Settings → Privacy & Security → Health on your device. Recompose never uses Health data for advertising or for any purpose unrelated to the app’s own features.
Photos, Camera and Audio
- Photo library and camera: if you attach an existing photo or take a new one to describe a meal or ask a question, that image is used to estimate nutrition or to help answer your question (see “AI Processing” below). Recompose only accesses the photo(s) you actively select or capture — it does not browse your library in the background. Meal photos are not stored as part of a saved meal record. Photos you send in Ask may be kept locally on your device as part of that conversation.
- Microphone and voice messages: if you record a voice message to describe a meal or ask a question, that recording is sent for transcription so Recompose can understand what you said. Recompose does not use your microphone or camera at any other time. Voice recordings are not stored as part of a saved meal record.
AI Processing
When you use AI features, Recompose sends the request from the app to a Supabase Edge Function, which then sends the relevant content to Microsoft Azure OpenAI to generate a response. Production AI features currently include:
- meal analysis from text;
- meal analysis from photos;
- voice transcription;
- the Ask nutrition coach;
- meal-log proposals generated by the coach for you to review before saving.
Depending on the feature, a request may include:
- text you type or a transcript of what you said;
- a meal photo you selected or captured;
- an audio recording, for transcription;
- relevant nutrition or profile context needed for that request — for example recent meal names and amounts, daily calorie and macro totals, weight trend context, your current targets, and recent Ask conversation messages.
We send what the request needs in order to complete that feature. We do not send your full app database, Health records unrelated to the request, Coach Sharing tokens, or advertising identifiers to Azure OpenAI.
AI estimates can be wrong. Meal names, portion sizes, calories, macronutrients, transcripts, and Ask answers are estimates, not verified facts. You can review and correct suggestions before or after saving a meal.
Recompose does not use your content to train its own AI models. Azure OpenAI and other providers process requests under their own terms, which can change. This policy does not promise that providers will never retain request data, or that they will never use it to improve their services. Check the provider’s current documentation for its practices.
App Integrity and Usage Limits
To reduce abuse of paid AI features, Recompose checks that AI requests come from a genuine copy of the app, and applies usage limits.
- App integrity. Production (Release) builds use Apple App Attest together with Firebase App Check so our servers can verify that an AI request appears to come from an unmodified Recompose app on a genuine Apple device before the request is processed.
- Anonymous use. If you use AI without signing in, usage is associated with a random, app-specific installation identifier stored on your device. It is not an advertising identifier (IDFA), it is not used for advertising, and it is not your Apple ID. Because it is stored in a way that can survive deleting and reinstalling the app, we do not claim that uninstalling Recompose resets it.
- Signed-in use. If you are signed in, AI usage limits are associated with your Recompose account rather than that installation identifier.
- Service-wide limits. We also maintain overall AI usage limits to protect the service.
We do not use your IP address as the application-level identifier for these AI usage limits. Infrastructure providers that deliver the app’s network requests may still process IP addresses and other network metadata as part of ordinary internet communication.
Account and Sign in with Apple
You can use Recompose’s core logging features without creating an account. Signing in with Apple unlocks account-dependent features: syncing supported data across your devices, recovering that data if you get a new device, and Coach Sharing.
When you sign in with Apple, Apple may provide Recompose with:
- a unique, app-specific Apple account identifier;
- your name, only the first time you authorize Recompose with that Apple ID (Apple does not disclose it again on later sign-ins, so Recompose remembers what it was told the first time);
- your email address, or an Apple-generated private relay address, depending on the choice you make during sign-in.
If Apple discloses your name, Recompose may keep the full display name on your device and may also store it in your Supabase Auth account metadata so it can be restored after reinstall. Coach-facing and public share views use a shorter form — typically first name and last initial — rather than your full surname.
We only receive what Apple discloses to us, based on your own choices in the Apple sign-in sheet — we cannot see your real Apple ID password, and if you choose to hide your email, we only ever see the private relay address.
Coach Sharing
Coach Sharing is optional and happens only if you start it. Coaches do not receive access automatically.
If you choose to share:
- You decide whether to share at all, by creating a share link or accepting a coach’s request.
- You choose the access level. Recompose currently supports Daily Summary Only (daily nutrition totals, weight, and activity, without individual meals) and Meal Details (the daily summary plus individual logged meals and their nutrition information). Shared views may also include limited profile context such as a display name, age derived from date of birth, sex, height, current weight, and goal, depending on what you have recorded.
- A share link is a capability link. Anyone who has a valid link can open the coach-facing shared view at the access level you chose, until you revoke the link. Treat a share link like a password.
- You can revoke access. Revoking a coach’s access or deleting a share link in Settings stops further access through Recompose. We cannot make someone “unsee” information they already viewed, or guarantee they have not saved or screenshotted a copy. Please only share with people you trust.
A coach is a third party you have chosen, not Recompose.
Analytics, Crash Reporting and App Check
Recompose uses Google Firebase for three separate purposes:
- Firebase Analytics — product analytics, such as which screens and features are used, where people drop off during onboarding, and whether key settings are changed.
- Firebase Crashlytics — diagnostics for crashes and a small number of caught technical errors (for example a failed save or a failed sign-in attempt).
- Firebase App Check — abuse prevention and verification that AI requests appear to come from a genuine Recompose app, as described in “App Integrity and Usage Limits”.
Firebase is not Recompose’s account system or primary application database. Those roles belong to optional Sign in with Apple and Supabase.
Recompose’s own analytics and crash events include a random diagnostic session ID — a fresh value generated when the app process starts, not derived from your Apple ID, email, or the installation identifier used for AI limits. It resets when the app is relaunched and exists to correlate one session’s usage events, crashes, and a bug report you submit during that session.
The analytics and crash events Recompose records are limited to app usage and technical diagnostics. They are designed not to include meal descriptions or other free-text nutrition content, calorie or macro values, weight, height, date of birth, biological sex, HealthKit values, photos, audio, Ask/chat message text, your Apple account identifier, your name or email, a coach’s name, or coach share-link tokens. Firebase products may still collect standard technical or installation data needed to operate Analytics, Crashlytics, and App Check.
No third-party advertising. Recompose does not use third-party advertising, does not use an
advertising identifier (IDFA) for AI usage limits or advertising, does not link AdSupport, and
does not show an App Tracking Transparency prompt. This is not a claim that Recompose performs no
analytics.
If you email us via Report a Bug, the report includes a small technical attachment — app version, build number, iOS version, device model, and the same diagnostic session ID — so we can correlate your report with Analytics/Crashlytics activity from the same session. That attachment is designed to avoid unnecessary sensitive content; it does not include your meal history or a dump of app logs. Send Feedback does not attach this diagnostic information. Either way, the email itself comes from your own device’s Mail app and will show whatever email address you send it from.
Cloud Storage
Recompose is local-first. Core nutrition logs, your profile, Ask history, and preferences live on your device using on-device storage (including SwiftData) whether or not you ever sign in. Data that remains only on your device is not uploaded until you sign in, except for AI requests and related integrity/usage checks described above, which go to the cloud when you use those features.
If you sign in with Apple, Recompose uses Supabase for authentication and as the cloud backend for account-dependent features. When you are signed in, Supabase may store:
- your authentication account, including email (or private relay) and name metadata;
- your nutrition profile and nutrition targets;
- meal history (names, amounts, timestamps, and nutrition values — not meal photos);
- unit-system preference;
- supported Apple Health / activity copies described in “Apple Health”;
- Coach Sharing relationships, share links, and access levels;
- operational AI usage counters used to apply the limits described above.
Ask conversation history, meal photos, and voice recordings are not stored as part of your synced nutrition database.
Service Providers
We use a small number of service providers to operate Recompose, each for a specific purpose:
| Provider | Purpose |
|---|---|
| Apple (Sign in with Apple, Apple Health / HealthKit, App Attest) | Authentication, Health integration, and production app-integrity attestation |
| Supabase | Authentication, cloud sync/storage of supported app data, Coach Sharing, Edge Functions (including AI routing and account deletion), and related backend operations |
| Microsoft Azure / Azure OpenAI | Cloud AI processing for meal analysis, transcription, Ask, and related coach proposals |
| Google Firebase (Analytics, Crashlytics, and App Check) | Product analytics, crash/error diagnostics, and app-integrity / abuse-prevention checks |
These providers process data under their own applicable terms and, where required, a data processing agreement with us. We only send each provider the data it needs to perform its specific role. Ordinary network and hosting infrastructure used to deliver those services may also process technical metadata such as IP addresses.
Data Retention
- Local device data (meal logs, profile, Ask history, preferences) stays on your device until you delete it or remove it through the app or ordinary device/app lifecycle. Deleting your cloud account does not automatically erase this local nutrition data.
- Installation identifier used for anonymous AI limits may remain on the device after you delete the app, as explained in “App Integrity and Usage Limits”.
- Apple Health data follows Apple’s own Health app retention and permissions — Recompose does not control how long Health itself keeps data, only what it reads and writes.
- Cloud account data in Supabase is kept while your account exists. Deleting your account removes the authentication user and associated cloud data as described in “Account and Data Deletion”.
- AI request content is sent to generate a response. We do not keep meal photos or audio as part of your synced nutrition records. Azure OpenAI and other providers may retain operational data according to their own policies.
- Analytics, crash, App Check, and usage-limit records are retained according to those providers’ and our backend’s operational practices, and as needed to run and protect the service.
- Support emails are retained in our mailbox for as long as reasonably needed to resolve your request, and are not used for advertising.
We do not promise fixed retention periods we cannot guarantee for provider-controlled systems.
Data Security
We use providers (Apple, Supabase, Microsoft Azure, Google) that encrypt data in transit and, where applicable, at rest, and we limit what each provider receives to what it needs for its role. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Your Choices and Rights
If you are in the UK, you have rights under UK GDPR, including the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- request deletion of your data;
- object to or restrict certain processing;
- request a copy of your data in a portable format;
- withdraw consent, where we rely on it, at any time.
If you are in the European Economic Area, equivalent rights apply under EU GDPR. To exercise any of these rights, contact support@recomposelabs.com. If you are not satisfied with our response, UK users can complain to the Information Commissioner’s Office (ico.org.uk); EEA users can complain to their local data protection authority.
Many of these choices are also available directly in the app: you can edit or delete meals and profile information, disconnect Apple Health, revoke coach access, and delete generated share links, all from within Recompose.
Account and Data Deletion
- Signing out removes your Apple account connection from the app on that device. It does not delete your local nutrition data on that device, and it does not delete your cloud account or synced data — sign out is about ending a session, not erasing information.
- Deleting your Recompose account (Delete Account in Settings, when you are signed in) deletes your Supabase authentication user and associated cloud data, including synced profile, meal history, nutrition targets, supported health/activity copies, and Coach Sharing records. This cloud deletion is irreversible. Local nutrition data, profile, and Ask history on the device are intentionally left in place so you can keep using Recompose without an account. Local sign-in state is cleared. If you cannot access the app, contact support@recomposelabs.com.
- Uninstalling the app removes data stored only in the app’s local database. It does not delete your cloud account. It also may not remove the installation identifier used for anonymous AI limits.
- Revoking coach access stops a coach’s future access through Recompose; see “Coach Sharing” for what this can and cannot undo.
- Apple Health data you’ve written from Recompose remains in the Health app under Apple’s own controls unless you delete it there.
International Data Transfers
Recompose and its service providers may process data in different countries and regions, including the United Kingdom, the European Economic Area, and the United States. International processing and transfers are handled subject to applicable data-protection law and the safeguards provided by the relevant service providers.
Children
Recompose is not intended for children under 13, and users under 13 may not use the service. We do not knowingly collect personal data from children under 13. If we learn that we have collected personal data from a child under 13, we will take reasonable steps to delete it.
Users aged 13 to 17 may use Recompose subject to applicable law and, where required, with the permission of a parent or legal guardian. Recompose does not currently provide special child accounts or a technical parental-consent verification mechanism.
Changes to This Policy
We may update this policy as Recompose’s features or our service providers change. We will update the “Last updated” date above, and where a change is material, we will provide reasonably prominent notice in the app.
Contact Us
Questions, requests, or concerns about this policy or your data: support@recomposelabs.com.