KetoCypher is built so we cannot read your food log, weight, biometrics, or any other entry you make. This policy describes the few things we do see, and the architectural reason we don't see the rest.
Effective: July 16, 2026. This update discloses the app's opt-out, self-hosted product-usage analytics (anonymous usage events plus a country-level approximate location). It follows the July 4, 2026 update, which added in-app self-service account and data deletion, clarified password reset versus data recovery, stated our data-retention windows, and disclosed beta feedback, opt-out crash diagnostics, payment processing, and security-incident notification.
To run an account and (optionally) a cloud backup, the server stores:
The server does not see your food log entries, weight, heart rate, sleep, glucose, steps, electrolyte totals, ratings, fasting sessions, custom foods, recipes, or any other data you enter in the app. Those values are encrypted on your device with your master key before they ever leave it. That master key is unlocked by a key derived from your password (Argon2id) and can also be recovered with your 12-word recovery phrase; we never receive your password, your recovery phrase, or the master key itself.
Beyond the items listed above, the app sends nothing to us. It contains no advertising identifiers and no cross-app tracking, and it uses no third-party analytics service: the only usage analytics and crash diagnostics are anonymous, opt-out, and sent to our own self-hosted servers, never to an outside analytics company. Its outbound network calls are authenticated account and backup requests, opt-out usage analytics and crash diagnostics, and the transactional email we send you. App updates are delivered by Google Play, not by us.
Everything you enter, everything Health Connect returns to the app, and everything KetoCypher computes from those values, stays on your phone in an encrypted local database (SQLCipher). Single-signal insights and correlations are computed on-device. We do not see what your sleep is, what your blood glucose was, or which foods you logged.
What we access. If you connect Google Health Connect, KetoCypher reads the data types you approve, one permission at a time: weight, sleep, heart rate, blood glucose, and steps. It reads them locally, inside Android's sandbox, so it can pair them with your food log.
How we use it. These readings are used only to pair with your food log and to compute the correlations and insights KetoCypher shows you, all on your device. We never use Health Connect data for advertising, we never sell or rent it, and we never share it with any third party.
Where it lives, and how it is secured. Readings KetoCypher keeps are written to the same encrypted on-device database (SQLCipher) as the rest of your data, encrypted with your master key. We never receive them in any readable form. The only way any of this data leaves your device is inside an end-to-end-encrypted Premium Backup you choose to create; in that case our servers hold only ciphertext they cannot decrypt, plus a record count in the backup's inventory (a number, never a value).
Retention and deletion. Health Connect readings stay on your device until you delete them in the app or uninstall KetoCypher. Deleting your account or your cloud data removes the encrypted backups from our servers, as described in section 9. You can also revoke any individual data-type permission at any time in Android Settings → Health Connect → KetoCypher, which stops any further reads.
If you submit your email on the landing page waitlist, we store the address and a tag indicating the source (the landing page) in our database. We use it only to notify you when the Android beta opens. To remove yourself, reply to the confirmation email or write to support@ketocypher.com.
On this website we use Cloudflare Web Analytics, which is cookieless and does not track individuals across sites. It records aggregate page-view counts and approximate location at the country level. No personal profile is built.
Inside the Android app we use our own self-hosted analytics (Aptabase) to count anonymous feature usage, for example how often the barcode scanner is opened or a backup is created. These events are content-free and are never linked to your identity, your food log, or your health data. They include your app version, device model, operating system, language, and an approximate location at the country level inferred from your connection. This is opt-out: you can turn it off, together with crash diagnostics, in the app's Settings. We use no third-party analytics service inside the app, and this data is never sold or shared.
KetoCypher is a health and wellness tool intended for adults. It is not directed at anyone under 18, and we do not knowingly collect data from minors. If you believe someone under 18 has signed up, write to support@ketocypher.com and we will remove the account.
Account data and (for Premium Backup users) encrypted backup blobs are stored on infrastructure hosted in the United States. Cloudflare handles the public web edge. KetoCypher is offered only to users in the United States; we do not target or market the app to the EU, UK, or EEA.
You can:
.kcbak file from inside the app. It is still encrypted with your master key.KetoCypher is offered only in the United States and is not directed at the EU, UK, or EEA. Regardless of which law reaches you, the architecture (we cannot read your data) means that for most categories there is no plaintext for us to access, rectify, or port; the in-app export is the only complete copy of your data, and it stays in your hands.
If we add or change a subprocessor in a way that affects this policy, we will update this page.
If we materially change how the app handles your data, we will update the "Effective" date above and call out the change at the top of this page. For material changes, we will also email account holders in advance, since we already have your address. Continued use after a change takes effect means you accept the updated policy.
If we ever discover a security breach affecting your account data, we will notify affected users by email without undue delay, and describe what happened and the steps you should take. Because every entry you make is encrypted with keys we never hold, a breach of our servers exposes ciphertext, your account email, and the limited metadata described above, not your food log, weight, biometrics, or any value you enter in the app.
KetoCypher is built by Optikal Development, a sole proprietorship based in Colorado Springs, Colorado, USA.
General questions: hello@ketocypher.com. Privacy, account, or data requests: support@ketocypher.com.