Privacy policy
Effective October 2, 2026
Demi is a nutrition app. You tell it about your body, your goals, and what you eat; it plans meals and tracks your progress. That data is yours. This page says exactly what Demi collects, where it lives, and how you get it out. No ads, nothing sold, no tracking you across other apps.
What Demi collects
Health and diet data you enter. Your onboarding answers (age, sex, height, weight, activity, goal, an optional body fat estimate, how much you already know about nutrition, and whether you mainly cook or order), meals you log, weigh-ins, what you write to Demi in chat, and the plans Demi builds for you. This is the app; without it there is nothing to plan.
Two safety questions, and three optional ones. Onboarding also asks whether you have a medical condition that affects how you should eat and whether you have ever struggled with an eating disorder or disordered eating, alongside a one-time 18+ confirmation. A yes to either question stops Demi from building or adjusting your plan and points you to a dietitian, your doctor, or the NEDA helpline instead; nobody at Demi reviews these answers, and they are never shared outside your account. Three more questions, all optional and skippable, ask about past dieting or food rules, skipping meals, and drinking your calories. Demi uses them only to change how it talks with you, never to change your plan or targets. All three shape how chat talks with you, and the two about dieting and skipping meals also shape how Demi words the explanations on your plan and your end-of-day reflection.
Apple Health data, only if you connect it. If you turn on Apple Health, Demi reads your steps, active energy, workout minutes, sleep duration, and body weight. Nothing is read until you allow it in the iOS permission sheet, and you can disconnect in Profile, which also deletes the health days Demi stored. The activity readings appear beside your weight trend on Progress. Demi may suggest an activity level from them, and only your tap changes anything. A weight from Health is saved as a check-in exactly like one you typed, and it never overwrites a weight you entered yourself. Because check-ins are how Demi learns your real burn rate, a weight read from Health can change your calorie targets; the activity readings never do on their own. If you allow it, Demi also writes the calories and macros you log back into Apple Health. Nothing read from Health is sent to Anthropic, to analytics, or to anyone else.
An account id and your email. Demi accounts are created with an email address, which is stored so you can sign in with a one-time code. There are no passwords.
Your email, if you join the beta waitlist. The landing page lets you leave an email address, and optionally a first name, to hear when a spot opens, before you have a Demi account at all. Demi uses it to send a confirmation and, later, an invite email, and keeps it only to run that list. Joining does not create an account, and creating an account later does not remove you from the list on its own; email hntrbeeny@gmail.com and Demi takes you off it.
A push token, if you turn on reminders. It lets Apple deliver meal reminders to your phone and is deleted when you disable notifications or delete your account.
A coarse location, when you look up a restaurant. Demi asks for location when you look for takeout, and separately when you use the "where from" field to describe a whole meal you ate out. Either way the fix is rounded to roughly a kilometer before Demi's server or Apple's Maps service ever sees it, and the coordinate itself is used once for that search and never stored. Takeout keeps the result as a single value each use overwrites, so it holds no history. Logging a meal is the one difference: if you name or pick a restaurant there, that name (never the address) is saved as part of the meal, the same as any food name you type in, and stays with that log entry.
Technical telemetry. Request logs (which API route, how long it took, status code) and crash reports (the error and its stack trace). Crash reports are deliberately stripped of your content: no request bodies, no tokens, no user ids.
Which features you use. A short, fixed list of actions: the app was opened, an onboarding question was reached, onboarding stopped to ask for an account, onboarding was resumed with an account, onboarding was finished, onboarding ended at the safety questions with a referral instead of a plan, food was logged, a barcode was scanned, a food's numbers were corrected, a day was closed. Each one records that it happened and nothing about what it was: no food names, no barcodes, no calories or macros, no weights, no notes. The referral entry is the one item on the list that touches health at all, and it carries only that much: the safety step ended there. Which of the two questions it was, and what you answered, stay with your account as described above and are never part of this list. The entries are filed under a random id belonging to this installation, not to your account, so they cannot be traced back to you or to anything you ate, and location lookup is switched off on them. This is how Demi learns which parts of the app work and where the food database lets you down. You can switch it off in Profile under Usage sharing. The switch does not cover the shorter record tied to your account, described next, which also notes each barcode lookup Demi had no match for.
A shorter record tied to your account. Separately, Demi keeps a second log against your account itself: that you finished onboarding, generated a plan, swapped a meal, tapped "why", finished a lesson, opened the app on a given day, or looked up a barcode Demi had no match for. Each entry is a name and a date, nothing about what the plan, meal or product actually was. Demi uses this to understand how new accounts settle in over their first days and how often a barcode comes up empty; it is separate from the anonymous list above, is not affected by the Usage sharing toggle, and is included in your export and deleted with your account like everything else in this section.
Free-text notes run through an automated safety screen; notes it flags are discarded rather than stored. If Demi keeps a note from a chat, it is one short sentence you told it, about your life, your food, what you know about nutrition, or how you like to be coached. A note never holds a number, a weight, or anything medical, and you can see and delete every one in Profile under What Demi remembers.
Where it lives and who processes it
Your data is stored with Supabase (Postgres, encrypted at rest) in the United States (us-east-1). Ordinary account reads use row-level security that limits each query to your own account. One export read is different: label checks live in a table with no user-readable policy, so after Demi verifies your sign-in, the server reads only rows matching your account id. The app itself runs on Vercel.
Anthropic's API does every job in Demi that needs a language model. Here is each job and what it sends. Chat sends your message, up to 24 earlier messages from the same conversation, and a summary of your account: your goal, activity level, meals per day, training days and time, how much you know about nutrition, your dietary preferences, allergies and dislikes, budget, cooking skill, whether you mainly cook or order, what you said gets in your way, your answers to the three optional questions above, today's targets, the meals you logged today and today's plan, your latest weigh-in and how your weight has been changing, your logging streak, meals you liked or turned down, the names of your saved meals, recipes and pantry items, the takeout places you picked, your time zone and any area you typed yourself, and the notes Demi remembers about you. A chat message the safety screen flags is not sent, and your answers to the two safety questions never are. After a reply, if coach memory is on, a second request sends that exchange and whether you said yes about past dieting or skipping meals, so Demi can decide whether to keep a note. The first message of each conversation is sent once more to give it a title.
Anthropic also writes the explanations on your plan, from the meals Demi chose with their times, calories and macros, your targets and the reason behind them, your goal, activity level, meals per day, protein and calorie-spread preferences, what you said gets in your way, and the notes Demi remembers about you. It writes the end-of-day reflection, from that day's targets, what was planned, the meals you logged with their calories and protein, the energy rating and note you gave, and those same notes. If you said yes about past dieting or skipping meals, both of these requests also carry an instruction to word things more carefully, which tells Anthropic that you said yes. It turns meal descriptions and label photos into nutrition estimates, and when you describe a meal from a named restaurant or chain it may run up to three web searches to check that place's published menu or nutrition before answering. And it reads recipes: text or a video caption you paste or share, the transcript of a cooking video you share, and a saved recipe you ask Demi to adapt, along with your instruction. Anthropic does not train on this API data, and photos are processed for the estimate and not stored by Demi.
A few narrow jobs use other processors. The USDA FoodData Central database answers food searches, with Open Food Facts consulted when USDA has few or no matches, including scanned barcodes (both receive only the search text or the barcode digits, never anything tied to your account), Apple's Maps service answers restaurant lookups when you use the "where from" field, Resend delivers sign-in code emails and the beta waitlist's confirmation and invite emails, Apple delivers push notifications, Sentry receives the stripped crash reports described above, and PostHog receives the feature-usage list described above.
One more, and only if you share a cooking video to Demi: turning its narration into text uses Apple's speech recognition. That usually runs on your iPhone, but Apple's service may receive the audio when your device cannot do it alone, which is Apple's own behavior and is covered by their privacy policy. The video file never leaves your phone, and Demi deletes it as soon as it has been read. The text it becomes goes to Anthropic to be read as a recipe, as described above.
That is the whole list. Nothing is sold, shared for advertising, or used to track you across apps or websites.
Your controls
Export your account data. Profile → Export your data downloads a JSON copy of your profile, logs, plans, weigh-ins, Apple Health days, recipes, saved meals, pantry, preferences, feedback, and account activity. It excludes raw device push tokens and Demi's internal push-delivery, rate-limit, and operator account-classification records.
Delete everything. In the app, go to Profile → Delete account, type the confirmation, and your account and every row of data tied to it are permanently deleted on the spot. Prefer email? Write to hntrbeeny@gmail.com from your account email (or include your account id from the export) and the same deletion happens within 72 hours. If you only joined the beta waitlist and never made an account, the same email removes that too.
What Demi will not do
Demi gives general wellness guidance, not medical advice, and it is built to keep you safe rather than hooked: it will not coach below safe calorie floors, and its safety rules run on the server where no setting can switch them off. Demi is not directed at children.
Changes and contact
If this policy changes, the effective date above changes with it, and material changes are called out in the app. Questions, requests, or anything unclear: hntrbeeny@gmail.com.