Privacy policy
This policy explains how Niko Nishimine, the operator of Buddie: Wellness & Nutrition, collects, uses, shares, and deletes information. Buddie does not sell personal information, show third-party ads, or use health information for advertising.
Information you provide
Buddie stores the profile and wellness information you choose to enter, which may include age range, height, weight and goals; nutrition and meal diary entries; hydration, movement, sleep, energy, fasting, wellbeing and reflection logs; suitability answers; reminder choices; companion and game progress; and private Word Bloom match activity. You may skip optional body information and use weight-neutral wellness features. Buddie also stores app settings, progress, subscription access, and a random profile identifier.
Apple Health
When you connect Apple Health on iPhone, you choose read-only access to steps, sleep, workouts, and heart rate. Buddie reads up to seven days of selected records and shows daily summaries. Sleep, workout, and heart-rate summaries stay in profile-specific storage on this device and are included if you export your data; each refresh replaces the prior seven-day summary. Today's step total and last-read time also save with your profile progress. Raw HealthKit sample identifiers, source names, and workout calorie estimates are not retained. Buddie does not write to HealthKit. HealthKit-derived information is used only for health and fitness features, never sold, used for advertising, or sent to OpenAI, USDA, RevenueCat, or data brokers. Manage access in the Apple Health app, or remove imported summaries from Buddie's Apple Health screen. Deleting your Buddie profile also removes this device's summaries.
Meal tools and AI
Manual food search sends food terms through Buddie's service to USDA FoodData Central. The serving helper may send a USDA food record identifier. Before first use, Buddie asks permission to send meal descriptions, recipe yield, selected photos and accompanying notes to OpenAI. Your choice is remembered for this profile on this device and applies to future meal assistance. You can turn it off under Your settings → Profile → AI meal assistance; food search, package-label entry and manual entry remain available without AI. Before upload, Buddie creates a new JPEG with a generic filename to remove embedded file metadata; anything visible in the image remains visible. Buddie does not save the photo in your profile. It saves only the foods, portions, corrections, confidence information and nutrient estimates you approve.
OpenAI states that API data is not used to train its models by default. Buddie disables response-history storage, but does not claim zero data retention: provider abuse-monitoring logs may retain submitted content, generally for up to 30 days, subject to OpenAI's current controls and legal exceptions. AI requests do not automatically include your Apple Health readings, weight, symptoms, journal, or profile history. Avoid including information unnecessary for the estimate. See OpenAI's API data controls.
Accounts, devices, and purchases
Buddie automatically creates a random app profile and keeps its secret session in an HttpOnly cookie. If you choose Sign in with Apple, the service verifies Apple's response and stores a cryptographic hash of your Apple identifier plus encrypted Apple tokens so you can protect or restore the profile. Buddie does not ask Apple for your name or email. One-time device-link codes can give another device access to the same profile; the service stores only a hash of the code and its short expiry.
Apple processes App Store purchases. RevenueCat receives an anonymous Buddie profile identifier and purchase or entitlement information needed to offer, restore, and verify subscription access. Buddie keeps normalized subscription status and event identifiers separately from wellness entries. It does not send meal entries, HealthKit data, reflections, or Apple identity tokens to RevenueCat.
Storage and service providers
Buddie stores profile data in its Cloudflare-hosted service database. Device storage may hold bounded recovery copies, pending meal changes, imported Health summaries, AI permission, and app preferences so interrupted work can be retried. These local records are not guaranteed backups. Recovery copies and pending meals remain until they sync, you remove them, you delete the profile, or the operating system clears app data. Device preferences remain until you change them, the associated profile is no longer active on that device, or app storage is cleared. Service providers process information for the functions described here: Cloudflare for hosting and storage, Apple for identity, HealthKit and App Store billing, RevenueCat for subscription management, OpenAI for optional meal AI, and USDA for food reference data.
Retention
Profile and meal history remain until you delete them; Buddie does not currently delete active profile data on a fixed inactivity schedule. You can delete individual meals and favorites in the app. Deleted meal contents are removed, while a limited identifier and revision marker may remain until profile deletion to keep an older device copy from restoring the meal. Private Word Bloom matches are eligible for cleanup after 30 days, and expired request-limit records after 24 hours. Limited purchase-verification and fraud-prevention records may remain after profile deletion; these do not include wellness entries. Provider records may follow each provider's own retention obligations.
Your choices
Under Your settings → Profile, Account & subscription lets you manage Apple sign-in and linked-device access. Data & privacy lets you download a full JSON export when the retained diary is reachable, download a recent and pending device copy, or delete the entire Buddie profile. Profile deletion removes the service-side profile, diary, device links, Apple connection, and private matches, and attempts to revoke Sign in with Apple tokens. After the service accepts deletion, Buddie also clears the local recovery copy, pending meals, imported Health summaries, and remembered AI permission for that profile on the device performing the deletion. Buddie cannot remotely erase an offline copy on another device. Deleting Buddie does not cancel an App Store subscription. Manage or cancel it separately in Apple Subscriptions. You may turn off Buddie reminders in Your settings and change Health access in the Apple Health app.
Security and children
Buddie uses scoped sessions, encrypted Apple credentials, and access controls designed to protect information. No system is guaranteed secure. Buddie is a general wellness service and is not directed to children under 13. People under 18 receive weight-neutral features and should use Buddie with a parent, guardian, or qualified professional as appropriate.
Support messages
We use your email address, message, and any attachments to respond to support requests. Our email providers (Cloudflare, Google, and Resend) process this correspondence on our behalf. App records are not automatically included.
Changes and contact
Material changes will be posted here with a new effective date. Email support@nightcat.studio for support and privacy requests. The Support page also provides self-service steps.
Effective September 19, 2026 · Operator: Niko Nishimine
Back to Buddie