Privacy Policy

Last updated: September 2026

NibbleWatch was built around one rule: your health data belongs to you, stays on your device, and is never collected, stored, or sold by NibbleWatch. There is no account and no NibbleWatch server holding your log. This page is an honest list of what lives on your device, and the few times the browser talks to someone else.

Where your data lives

Everything you enter — food and water, exercise, sleep, mood, weight, profile details, saved recipes, pantry and refrigerator items, custom foods, Frequent Foods, and unit preference — is stored in your browser’s local storage on that device. Joy Young cannot see it. There is no cloud copy on a NibbleWatch server.

If you clear site data, switch browsers or devices, or reset the device, that copy is gone. There is no account to recover it from. Use Full Backup on My Profile, and the CSV export on Today's Totals, before you clear a browser or give a device away.

When something leaves your device

Your diary is not uploaded. The browser does make a few network requests when a feature needs an outside lookup, or to draw the page:

1. Food search (USDA FoodData Central). When you search for a food, the words you typed are sent to the USDA’s public nutrition database so NibbleWatch can show matches and facts. NibbleWatch uses its own USDA access for ordinary logging; you do not need a key. Only the search text is sent — not your name, log, weight, or profile.

2. Barcode lookup (Open Food Facts). When you look up a barcode in My Pantry, that barcode is sent to Open Food Facts, a public food database. If nothing is found there, the app may also try USDA with the same code. Only the barcode (and a search term, if USDA is used) is sent.

3. Optional AI Recipe Builder. This is off unless you turn it on. If you use it, you paste your own Anthropic or OpenAI key. The ingredients you selected and that key go from your browser straight to that provider. NibbleWatch does not receive or store the key or the conversation. If you never use the builder, this does not apply.

4. Page layout files. Each page loads Bootstrap and icons from a public CDN (jsDelivr) so the site can render. That is not your health data.

NibbleWatch does not send your log to a NibbleWatch server, does not run analytics, and does not check a home server for updates.

What NibbleWatch does not do
Your control
Children

NibbleWatch is not directed at children under 13 and is not designed to collect information from them. There is no NibbleWatch account and no NibbleWatch-held user database. The app is meant for general adult use.

Changes

If a future feature changes how data is handled — including ads or any server-side feature — this page will be updated and the date above will change. Using NibbleWatch after an update means you are using the current policy.

Questions

If something here is unclear, write to support@nibblewatch.com.