Herrkos Privacy Policy

Last updated: September 27, 2026

Herrkos is designed to keep your food diary private and local to your iPhone. The app does not require an account and the developer does not operate a server that receives your diary, voice transcripts, or food photos.

Data stored on your device

Food logs, original voice transcripts, favorites, goals, weight entries, settings, personal portion corrections, reviewed personal Nutrition Facts foods, and cached food matches are stored in the app's private container. An optional personal USDA API key is stored in the iOS Keychain.

Microphone, speech recognition, camera, and photos

The app requests microphone and speech-recognition access for voice logging and camera or photo-library access when you choose photo or barcode features. Voice transcription, scale OCR, and Nutrition Facts OCR run on your device. Nutrition Facts photos are used to create an editable draft and are not retained by the app. Voice interpretation uses Apple Intelligence on your device by default. On devices without Apple Intelligence, you can use an AI service with your own API key (below), or send watch logs to a device that has it. The developer does not receive recordings, transcripts, or photos.

Optional AI services you choose

Settings lets you separately choose OpenAI processing for voice or food photos. It is off by default, requires an explicit confirmation, and never activates as an automatic fallback. When enabled for voice, the current transcript and the names of your saved food shortcuts are sent directly from your device to OpenAI. When enabled for photos, the current resized photo and locally recognized scale text are sent directly from your device to OpenAI. Audio and diary history are not sent.

Your OpenAI API key is supplied by you, stored in the iOS Keychain, excluded from Herrkos backups, and sent only in an authorization header to OpenAI's official API endpoint. Herrkos sends store: false, which disables optional Responses API application-state storage but does not guarantee zero retention. OpenAI states that API inputs and outputs may be retained for up to 30 days for safety and abuse monitoring by default; qualifying API accounts may have approved stricter controls. OpenAI may also process network metadata under the terms, billing, and privacy policy associated with your OpenAI account. Removing the key turns off OpenAI processing for both features.

Optional network requests

Optional food searches may contact USDA FoodData Central or Open Food Facts directly from your device. If you add a personal USDA key, it is sent to USDA in an authentication header and is excluded from app backups. Those independent services may process network metadata such as your IP address under their own policies.

iOS may also download and manage the Apple on-device speech-recognition asset for your language the first time voice transcription is prepared. Apple shares that system asset between apps and manages its retention.

Instead of OpenAI you may choose Anthropic (Claude), another AI service that uses the OpenAI format (for example OpenRouter, Groq, Moonshot, Z.ai, DeepSeek, Google Gemini, Mistral, or Together AI), or a server you run yourself, such as Ollama on your own computer reached over your home network or Tailscale. The same content rules apply: only the current transcript and your shortcut names (or, for photos, the current photo and scale text) are sent, directly from your iPhone to the address you entered, using your key. Herrkos shows that address before anything is sent. Each provider's own terms and retention policy apply.

Apple Health, reminders, and Siri

If you turn on “Save to Apple Health”, Herrkos writes each entry's food name, calories, protein, carbs, and fat to Apple Health on your iPhone and keeps edits and deletions from the last 14 days in sync. If you turn on “Read weight from Apple Health”, Herrkos reads your body-weight samples (the last year at first, then new ones) and copies them into your weight entries. It reads no other Health data. Health data is managed by Apple under your Health settings and is never sent to the developer.

Meal reminders are local notifications scheduled on your iPhone. They never include what you ate or your numbers. Siri and Shortcuts actions, the Lock Screen and Home Screen widget, Control Center controls, and the watch face complication only open the app; widgets never show diary data. If you dictate food to Siri, that text is handled like typed input.

iCloud Sync and Apple Watch

iCloud Sync is off unless you turn it on in Settings. When on, your diary, foods, shortcuts, goals, weight entries, and notes are stored in your private iCloud database through Apple's CloudKit so they match on your iPhone and iPad. API keys and settings kept in the Keychain are not synced. The developer cannot access your private iCloud database; Apple's iCloud terms apply. On Apple Watch you can choose which device understands a watch log: your iPhone transcribes the recording on-device, and only the resulting words travel through your iCloud to that device. Recordings are deleted after transcription. Your iPhone also sends the watch today's calorie and macro totals and goals for the rings; food names are not sent.

Exports and deletion

Backups are created only when you choose Export and include diary data, original transcripts, and structured personal-food records, but no Nutrition Facts images. You can protect an export with a password, which encrypts it on your device; the password is never stored and cannot be recovered. Protect unencrypted exports as you would any health-related record. Optional weekly automatic backups are always password-protected and are written only to a folder you choose; Herrkos removes only its own older automatic backup files there. The automatic-backup password is kept in this iPhone's Keychain. Settings provides a control to delete all app data, including API keys. With iCloud Sync on, this also deletes the synced diary from your iCloud and your other devices. Deleting the app removes its app-container data, subject to normal iOS backup and restoration behavior. iOS can keep Keychain items after an app is deleted, so Herrkos removes any API keys left behind the first time it is opened after a reinstall.

Analytics, advertising, and tracking

Herrkos contains no developer analytics, advertising, or cross-app tracking. The only AI services Herrkos contacts are the ones you choose and set up with your own key, described above. The developer does not sell personal data.

Children, security, and changes

Herrkos is a general personal food diary and is not directed to children under 13. Reasonable platform security controls are used, but no storage system can be guaranteed completely secure. Material policy changes will be published at the same public URL with an updated date.

Contact

Questions about this policy or your data? Email support@herrkos.com. Help and answers to common questions are on the Herrkos support page.