KetoCypher
Why Features FAQ Pricing
Join waitlist
Privacy Policy

What we see, what we don't, and why.

KetoCypher is built so we cannot read your food log, weight, biometrics, or any other entry you make. This policy describes the few things we do see, and the architectural reason we don't see the rest.

Effective: July 16, 2026. This update discloses the app's opt-out, self-hosted product-usage analytics (anonymous usage events plus a country-level approximate location). It follows the July 4, 2026 update, which added in-app self-service account and data deletion, clarified password reset versus data recovery, stated our data-retention windows, and disclosed beta feedback, opt-out crash diagnostics, payment processing, and security-incident notification.

1. The short version

  • Your food log, weight, biometric readings, ratings, fasting sessions, and any notes are encrypted on your phone before they leave it. The server stores ciphertext only.
  • There is no admin key and no operator "recover my data" path, because either would be a backdoor. Resetting your password restores your ability to sign in, but it does not by itself recover your encrypted data: that data is sealed by a key your password only wraps, never creates. After a reset you regain access by entering your 12-word recovery phrase, which re-seals the key under your new password. Without either your old password or that phrase, your data stays encrypted and permanently unreadable.
  • The only personal data we retain to identify you is your email address (for the waitlist and your account) and an unguessable password verifier (so you can sign in). Operating a web service also means our servers briefly log technical request data, such as your IP address; see section 2.
  • We do not sell data. We do not run ad networks. We do not share data with third parties for marketing.
  • If a court compels us, we can hand over ciphertext and account email. We cannot hand over what we cannot read.

2. What the server actually receives

To run an account and (optionally) a cloud backup, the server stores:

  • Email address. So you can sign in, and reset your password if you forget it.
  • Password verifier. A derived value, not your password. It lets the server confirm you know your password without ever seeing it.
  • Account metadata. Account creation timestamp, tier (Free or Premium Backup), and basic billing state if you are on Premium. Premium payments are processed by Google Play Billing; we never see or store your card or payment details.
  • Encrypted backup blobs (Premium Backup only). Ciphertext, plus the minimum metadata required to upload, list versions, and download (size, version counter, timestamp).
  • Standard request logs. Connection metadata such as IP address, user-agent, and the request path and status, retained no more than 7 days for security and abuse handling, and never used for advertising or profiling. These logs never contain your food log, encrypted data, password, or recovery phrase.
  • Beta feedback you choose to submit. If you send in-app feedback during the beta, we store the description you write and any screenshot you attach, linked to your account, so we can reproduce and fix the issue. When you delete your account or your server data, the feedback is unlinked from you and its screenshots are deleted; the remaining text is permanently deleted 90 days later.
  • Crash and error diagnostics (opt-out). To find and fix crashes, the app can send diagnostic reports — stack traces, device model, OS and app version — to our own self-hosted error tracker. Reports are scrubbed of personal content and never include your food log or any entry you make. You can turn this off in the app's settings.
  • Product usage analytics (opt-out). To understand which features are used and where to improve, the app can send anonymous, content-free usage events (for example, "a backup was created" or "the scanner was opened") to our own self-hosted analytics. These events carry your app version, device model, operating system, and language, plus an approximate location (your country, inferred from your connection; we do not store your IP address). They never include your food log, your health data, your account, or any value you enter. This uses the same opt-out switch as crash diagnostics, in the app's settings.

The server does not see your food log entries, weight, heart rate, sleep, glucose, steps, electrolyte totals, ratings, fasting sessions, custom foods, recipes, or any other data you enter in the app. Those values are encrypted on your device with your master key before they ever leave it. That master key is unlocked by a key derived from your password (Argon2id) and can also be recovered with your 12-word recovery phrase; we never receive your password, your recovery phrase, or the master key itself.

Beyond the items listed above, the app sends nothing to us. It contains no advertising identifiers and no cross-app tracking, and it uses no third-party analytics service: the only usage analytics and crash diagnostics are anonymous, opt-out, and sent to our own self-hosted servers, never to an outside analytics company. Its outbound network calls are authenticated account and backup requests, opt-out usage analytics and crash diagnostics, and the transactional email we send you. App updates are delivered by Google Play, not by us.

3. What stays on your device

Everything you enter, everything Health Connect returns to the app, and everything KetoCypher computes from those values, stays on your phone in an encrypted local database (SQLCipher). Single-signal insights and correlations are computed on-device. We do not see what your sleep is, what your blood glucose was, or which foods you logged.

4. Google Health Connect

What we access. If you connect Google Health Connect, KetoCypher reads the data types you approve, one permission at a time: weight, sleep, heart rate, blood glucose, and steps. It reads them locally, inside Android's sandbox, so it can pair them with your food log.

How we use it. These readings are used only to pair with your food log and to compute the correlations and insights KetoCypher shows you, all on your device. We never use Health Connect data for advertising, we never sell or rent it, and we never share it with any third party.

Where it lives, and how it is secured. Readings KetoCypher keeps are written to the same encrypted on-device database (SQLCipher) as the rest of your data, encrypted with your master key. We never receive them in any readable form. The only way any of this data leaves your device is inside an end-to-end-encrypted Premium Backup you choose to create; in that case our servers hold only ciphertext they cannot decrypt, plus a record count in the backup's inventory (a number, never a value).

Retention and deletion. Health Connect readings stay on your device until you delete them in the app or uninstall KetoCypher. Deleting your account or your cloud data removes the encrypted backups from our servers, as described in section 9. You can also revoke any individual data-type permission at any time in Android Settings → Health Connect → KetoCypher, which stops any further reads.

5. Waitlist

If you submit your email on the landing page waitlist, we store the address and a tag indicating the source (the landing page) in our database. We use it only to notify you when the Android beta opens. To remove yourself, reply to the confirmation email or write to support@ketocypher.com.

6. Analytics

On this website we use Cloudflare Web Analytics, which is cookieless and does not track individuals across sites. It records aggregate page-view counts and approximate location at the country level. No personal profile is built.

Inside the Android app we use our own self-hosted analytics (Aptabase) to count anonymous feature usage, for example how often the barcode scanner is opened or a backup is created. These events are content-free and are never linked to your identity, your food log, or your health data. They include your app version, device model, operating system, language, and an approximate location at the country level inferred from your connection. This is opt-out: you can turn it off, together with crash diagnostics, in the app's Settings. We use no third-party analytics service inside the app, and this data is never sold or shared.

7. Minors

KetoCypher is a health and wellness tool intended for adults. It is not directed at anyone under 18, and we do not knowingly collect data from minors. If you believe someone under 18 has signed up, write to support@ketocypher.com and we will remove the account.

8. Data location

Account data and (for Premium Backup users) encrypted backup blobs are stored on infrastructure hosted in the United States. Cloudflare handles the public web edge. KetoCypher is offered only to users in the United States; we do not target or market the app to the EU, UK, or EEA.

9. Your rights

You can:

  • Export your data. Free and Premium users can export a portable .kcbak file from inside the app. It is still encrypted with your master key.
  • Delete your account or data. In the app, go to Settings → Account → "Delete account or data." You can either delete your cloud data (your encrypted backup blobs) and keep your account, or permanently delete your entire account and all server-side data. Both actions require confirmation and re-entering your password, take effect immediately, and cannot be undone. Deletion of the live account data is immediate; any residual copies in our database provider's short-term, point-in-time-recovery backups roll off automatically within 7 days. Neither touches the data stored on your own device, which stays encrypted and readable only with your recovery phrase or a valid account. You can also email support@ketocypher.com from the address on the account. Because we cannot read your encrypted blobs, once they and the account record are removed no further readable "data" exists for us to delete. See ketocypher.com/delete-account for the full process.
  • Correct or update contact details by writing to support@ketocypher.com.

KetoCypher is offered only in the United States and is not directed at the EU, UK, or EEA. Regardless of which law reaches you, the architecture (we cannot read your data) means that for most categories there is no plaintext for us to access, rectify, or port; the in-app export is the only complete copy of your data, and it stays in your hands.

10. Subprocessors

  • Cloudflare (CDN, DNS, web analytics).
  • Supabase (database and auth for account email + verifier + waitlist).
  • Amazon SES (transactional email: account, password reset, beta invite).
  • Google Play Billing (payment processing for Premium Backup; Google processes your payment so we never receive your card or payment details).

If we add or change a subprocessor in a way that affects this policy, we will update this page.

11. Changes

If we materially change how the app handles your data, we will update the "Effective" date above and call out the change at the top of this page. For material changes, we will also email account holders in advance, since we already have your address. Continued use after a change takes effect means you accept the updated policy.

12. Security incidents

If we ever discover a security breach affecting your account data, we will notify affected users by email without undue delay, and describe what happened and the steps you should take. Because every entry you make is encrypted with keys we never hold, a breach of our servers exposes ciphertext, your account email, and the limited metadata described above, not your food log, weight, biometrics, or any value you enter in the app.

13. Who we are & contact

KetoCypher is built by Optikal Development, a sole proprietorship based in Colorado Springs, Colorado, USA.

General questions: hello@ketocypher.com. Privacy, account, or data requests: support@ketocypher.com.

Product KetoCypher · V1 · Android
Contact hello@ketocypher.com support@ketocypher.com
Legal User Manual Privacy Policy Terms of Use Promo Code Terms
Follow Facebook
Decode your diet · Encrypt your data © 2026 KetoCypher