Privacy policy
Plain language, no surprises. This page says what Proud collects, who else touches it, and what you can do about it.
Last updated July 26, 2026
The short version
- Proud collects what it needs to run the app: your account, the meals you log, your one buddy, your streaks, and your device basics. Nothing is public. There is no feed.
- Proud never asks for weights, calories, or any number about your body, and does not sell your data or show ads.
- Every meal photo is scanned automatically for safety before your buddy can see it.
- If you talk to Bloom, those conversations are processed by DeepSeek, an AI company based in China. That is a real transfer of personal data abroad, it is optional, and it is explained in full below.
- Deleting your account in the app removes your data immediately. Copies in encrypted backups clear within 30 days. Abuse reports are kept for safety.
| Data | Why Proud has it | Who else touches it |
|---|---|---|
| Account: email, username, display name, optional profile photo | To create your account and let your buddy find you | Google Firebase |
| Sign in: passkey public key (WebAuthn) or a password | To keep your account yours | Google Firebase |
| Content: meal photos, notes, meal type and time, Proud reactions, Unfold journal entries | The product itself | Google Firebase; photos also Google Cloud Vision |
| Bloom conversations and the private profile Bloom keeps | To generate Bloom’s replies | DeepSeek (China); Anthropic as fallback |
| Relationship: your buddy, buddy requests, your six character invite code | Pairing, and showing your buddy your wins | Google Firebase |
| Activity: streaks, rest days, mends, lesson progress, app usage, screens viewed | Streak math, and understanding what to improve | Google Firebase, PostHog |
| Device: push token, language, timezone, app version, crash data | Notifications, localization, fixing crashes | Google Firebase, Expo |
| Purchases: subscription status, transaction identifiers | To know Proud Plus is active | Apple, RevenueCat, Google Analytics |
Who runs Proud
Proud is built and operated by Theo Apteker, its founder and only developer. For everything in this policy, including requests about your data, write to theo@proudforus.com. Theo is the data controller for the personal data described here.
What Proud collects
- Account. Email address, username, display name, and a profile photo if you add one.
- Authentication. If you use a passkey, Proud stores the public half of the credential (WebAuthn). The private half never leaves your device. If you use a password, it is stored hashed by Firebase Authentication; Proud never sees it in plain text.
- Content. Meal photos, the notes you attach, the meal type and time, Proud reactions, and anything you write in the Unfold journal.
- Bloom. Your conversations with Bloom and the private profile Bloom builds to remember context between chats.
- Relationship. Who your buddy is, buddy requests you send or receive, and your invite code.
- Activity. Streaks, declared rest days, mends, lesson progress, which screens you use and when.
- Device. A push notification token, your language and timezone, app version, and crash reports.
- Purchases. Whether Proud Plus is active and transaction identifiers. Payment happens entirely through Apple. Your card details never reach Proud.
- Reports. If you report content or a person, or someone reports you, that report is stored.
Proud does not collect weights, calories, macros, BMI, step counts, or any measurement of your body or your food. That is not a missing feature. It is the point.
What your buddy can see, exactly
Your buddy, and only your buddy, can see:
- Your meal posts that passed the safety scan: the photo, meal type, time, and your note.
- Proud reactions between the two of you.
- Your display name, username, profile photo, current and longest streak, total posts, days active, and your mix of meal types.
Your buddy can never see:
- Your Unfold journal.
- Your conversations with Bloom.
- Your email address.
- Photos held back by moderation.
If you have no buddy yet, your posts are visible to you alone. Nothing in Proud is ever public.
Photo moderation
Every photo you upload is scanned automatically by Google Cloud Vision before your buddy can see it. The scan checks for sexual and explicit imagery. If a photo is flagged, or if the scan cannot complete, the photo stays hidden from your buddy. Proud shares photos only after they pass. This exists because meal photos go to another person, and that person deserves a basic guarantee about what lands in front of them. The scan is automated; no person at Proud reviews your photos in the normal course of things.
Bloom, DeepSeek, and where your words go
Read this part if you use Bloom. When you talk to Bloom, your messages, recent conversation context, and the private profile Bloom keeps are sent to DeepSeek, an AI company based in China, which generates the reply. If DeepSeek is unavailable, the request may instead be handled by Claude, a model run by Anthropic in the United States.
This is a cross border transfer of personal data, including whatever you choose to tell Bloom. It only happens when you use Bloom: opening a conversation, or asking Bloom to reflect on a journal entry. If you never use Bloom, nothing is sent.
Please treat conversations with Bloom accordingly. They are not a confidential clinical disclosure, and Bloom is not a therapist, a medical professional, or a crisis service. Do not share what you would not want processed on servers abroad. If you are in crisis, contact a local crisis line; in the US, call or text 988.
API keys and requests are handled on Proud’s servers, not in the app, and your conversations are not used by Proud to train AI models.
The companies Proud relies on
Proud is one person, so infrastructure comes from specialists. Each one is named here, with what it does and where it operates.
| Processor | What it does for Proud | Where |
|---|---|---|
| Google Firebase | Sign in, database, file storage, server functions, app analytics, crash reporting | US and global |
| Google Cloud Vision | Automated safety scan of every uploaded meal photo. Photos are transmitted for moderation before your buddy sees them | US and global |
| DeepSeek | Generates Bloom’s replies. Conversations and context you send to Bloom are processed by DeepSeek | China |
| Anthropic | Fallback model for Bloom when DeepSeek is unavailable | US |
| RevenueCat | Keeps your subscription state in sync | US |
| PostHog | Product analytics, only with your consent | US cloud |
| Expo and Apple Push Notification service | Deliver push notifications to your device | US |
| Google Analytics (Measurement Protocol) | Server side subscription events, so Proud can tell whether Plus works as a product | US and global |
| Apple | App distribution and all payment processing. Proud never receives card details | Per your storefront |
Why Proud processes your data, legally speaking
- To provide the service you signed up for (contract): your account, content, buddy relationship, streaks, subscriptions, and notifications you asked for.
- Legitimate interests: photo moderation, abuse prevention and the retention of reports, crash diagnostics, and keeping the service secure. These protect you and your buddy as much as they protect Proud.
- Consent: usage analytics (the toggle described below), and Bloom, which only processes what you choose to send it. You can withdraw either at any time.
- Legal obligations: transaction records connected to payments, held by Apple and RevenueCat.
Analytics and your consent
Proud has a consent toggle for analytics. In the app, go to Settings, then Manage your data, then the Privacy section, and turn Share usage data on or off. It reads: helps us understand which parts of Proud are useful and fix what is not, and never includes your posts, journal entries, or messages.
Turning it off stops product analytics events. Crash reports stay on either way, so problems can be diagnosed. Analytics never includes the content of your meals, journal, or Bloom conversations.
International transfers
Proud’s infrastructure runs mostly in the United States, so if you live elsewhere, your data is transferred to the US. Bloom conversations are additionally processed in China by DeepSeek, as described above. Where transfers leave your region, Proud relies on its processors’ data processing agreements and standard contractual protections, keeps what is sent to each processor to the minimum needed for its job, and keeps Bloom strictly optional.
How long data is kept
- While your account exists: your data is kept so the app works.
- When you delete your account: deletion runs immediately. Your profile, posts and photos, journal, Bloom conversations, buddy links, requests, notifications, and subscription record are removed, and your username is released. See Delete your account for the exact path.
- Backups: encrypted backups can hold copies for up to 30 more days before they clear.
- Reports: reports filed by you or about you are kept after deletion. This stops someone from erasing an abuse record by deleting and re registering.
- Transactions: Apple and RevenueCat retain transaction records as financial regulations require.
Security
- Data is encrypted in transit (TLS) and at rest.
- Database rules enforce that only you, and where relevant your buddy, can read your data. There is no public read path.
- Passkey sign in means there is no password to steal. If you use a password instead, it is stored hashed.
- API keys for moderation and Bloom live in server side secret storage, not in the app on your phone.
A plain word about sensitive data
What you log in Proud can reveal things about your relationship with food, and sometimes about your health. Proud is built on that assumption: content is visible to one chosen person at most, nothing is public, nothing is sold, there are no ads, and no third party gets your content except the ones named above doing the specific jobs described. Proud does not ask for diagnoses and does not want them.
Children
Proud is not directed at children under 13, and you must be at least 13 to create an account. If the law where you live sets a higher age for consenting to data processing, that higher age applies. If you believe a child under the minimum age is using Proud, write to theo@proudforus.com and the account will be deleted.
Your rights
If you are in the European Economic Area, the UK, or anywhere with similar law, you have the right to:
- Access the personal data Proud holds about you.
- Correct it if it is wrong.
- Delete it (the app has a built in path for this).
- Receive a portable copy.
- Object to or restrict certain processing.
- Withdraw consent at any time, for analytics with the in app toggle, and for Bloom by not using it.
- Complain to your local supervisory authority.
To exercise any of these, email theo@proudforus.com from the address on your account. You will get a reply within 30 days.
Changes to this policy
When this policy changes, the date at the top changes with it, and the changelog below says what moved. For significant changes you will be told in the app before they take effect.
- July 26, 2026. Complete rewrite. Every processor is now named, including DeepSeek and the Anthropic fallback behind Bloom. Added buddy visibility, moderation, transfers, retention, and GDPR rights sections. Replaces the previous policy, which named no third parties.
Contact
Questions, requests, or something this page should say and does not: theo@proudforus.com.