Privacy policy

Plain language, no surprises. This page says what Proud collects, who else touches it, and what you can do about it.

Last updated July 26, 2026

The short version

Summary of data Proud collects, why, and where it goes
DataWhy Proud has itWho else touches it
Account: email, username, display name, optional profile photoTo create your account and let your buddy find youGoogle Firebase
Sign in: passkey public key (WebAuthn) or a passwordTo keep your account yoursGoogle Firebase
Content: meal photos, notes, meal type and time, Proud reactions, Unfold journal entriesThe product itselfGoogle Firebase; photos also Google Cloud Vision
Bloom conversations and the private profile Bloom keepsTo generate Bloom’s repliesDeepSeek (China); Anthropic as fallback
Relationship: your buddy, buddy requests, your six character invite codePairing, and showing your buddy your winsGoogle Firebase
Activity: streaks, rest days, mends, lesson progress, app usage, screens viewedStreak math, and understanding what to improveGoogle Firebase, PostHog
Device: push token, language, timezone, app version, crash dataNotifications, localization, fixing crashesGoogle Firebase, Expo
Purchases: subscription status, transaction identifiersTo know Proud Plus is activeApple, RevenueCat, Google Analytics

Who runs Proud

Proud is built and operated by Theo Apteker, its founder and only developer. For everything in this policy, including requests about your data, write to theo@proudforus.com. Theo is the data controller for the personal data described here.

What Proud collects

Proud does not collect weights, calories, macros, BMI, step counts, or any measurement of your body or your food. That is not a missing feature. It is the point.

What your buddy can see, exactly

Your buddy, and only your buddy, can see:

Your buddy can never see:

If you have no buddy yet, your posts are visible to you alone. Nothing in Proud is ever public.

Photo moderation

Every photo you upload is scanned automatically by Google Cloud Vision before your buddy can see it. The scan checks for sexual and explicit imagery. If a photo is flagged, or if the scan cannot complete, the photo stays hidden from your buddy. Proud shares photos only after they pass. This exists because meal photos go to another person, and that person deserves a basic guarantee about what lands in front of them. The scan is automated; no person at Proud reviews your photos in the normal course of things.

Bloom, DeepSeek, and where your words go

Read this part if you use Bloom. When you talk to Bloom, your messages, recent conversation context, and the private profile Bloom keeps are sent to DeepSeek, an AI company based in China, which generates the reply. If DeepSeek is unavailable, the request may instead be handled by Claude, a model run by Anthropic in the United States.

This is a cross border transfer of personal data, including whatever you choose to tell Bloom. It only happens when you use Bloom: opening a conversation, or asking Bloom to reflect on a journal entry. If you never use Bloom, nothing is sent.

Please treat conversations with Bloom accordingly. They are not a confidential clinical disclosure, and Bloom is not a therapist, a medical professional, or a crisis service. Do not share what you would not want processed on servers abroad. If you are in crisis, contact a local crisis line; in the US, call or text 988.

API keys and requests are handled on Proud’s servers, not in the app, and your conversations are not used by Proud to train AI models.

The companies Proud relies on

Proud is one person, so infrastructure comes from specialists. Each one is named here, with what it does and where it operates.

Third party processors, their purpose, and location
ProcessorWhat it does for ProudWhere
Google FirebaseSign in, database, file storage, server functions, app analytics, crash reportingUS and global
Google Cloud VisionAutomated safety scan of every uploaded meal photo. Photos are transmitted for moderation before your buddy sees themUS and global
DeepSeekGenerates Bloom’s replies. Conversations and context you send to Bloom are processed by DeepSeekChina
AnthropicFallback model for Bloom when DeepSeek is unavailableUS
RevenueCatKeeps your subscription state in syncUS
PostHogProduct analytics, only with your consentUS cloud
Expo and Apple Push Notification serviceDeliver push notifications to your deviceUS
Google Analytics (Measurement Protocol)Server side subscription events, so Proud can tell whether Plus works as a productUS and global
AppleApp distribution and all payment processing. Proud never receives card detailsPer your storefront

Why Proud processes your data, legally speaking

Analytics and your consent

Proud has a consent toggle for analytics. In the app, go to Settings, then Manage your data, then the Privacy section, and turn Share usage data on or off. It reads: helps us understand which parts of Proud are useful and fix what is not, and never includes your posts, journal entries, or messages.

Turning it off stops product analytics events. Crash reports stay on either way, so problems can be diagnosed. Analytics never includes the content of your meals, journal, or Bloom conversations.

International transfers

Proud’s infrastructure runs mostly in the United States, so if you live elsewhere, your data is transferred to the US. Bloom conversations are additionally processed in China by DeepSeek, as described above. Where transfers leave your region, Proud relies on its processors’ data processing agreements and standard contractual protections, keeps what is sent to each processor to the minimum needed for its job, and keeps Bloom strictly optional.

How long data is kept

Security

A plain word about sensitive data

What you log in Proud can reveal things about your relationship with food, and sometimes about your health. Proud is built on that assumption: content is visible to one chosen person at most, nothing is public, nothing is sold, there are no ads, and no third party gets your content except the ones named above doing the specific jobs described. Proud does not ask for diagnoses and does not want them.

Children

Proud is not directed at children under 13, and you must be at least 13 to create an account. If the law where you live sets a higher age for consenting to data processing, that higher age applies. If you believe a child under the minimum age is using Proud, write to theo@proudforus.com and the account will be deleted.

Your rights

If you are in the European Economic Area, the UK, or anywhere with similar law, you have the right to:

To exercise any of these, email theo@proudforus.com from the address on your account. You will get a reply within 30 days.

Changes to this policy

When this policy changes, the date at the top changes with it, and the changelog below says what moved. For significant changes you will be told in the app before they take effect.

Contact

Questions, requests, or something this page should say and does not: theo@proudforus.com.