Translation. This is an English translation of the Armenian original. If the two differ, the Armenian text prevails.
Responsible party
Responsible party: Karen Nikoghosyan.
Contact: hamovai.app@gmail.com, or through the app’s “Profile → Contact us” section.
What data we collect
- Account data. Your email address and password (stored only in hashed form), or your Google account identifier, name and photo if you sign in with Google.
- Profile answers. Goal, target weight, pace, age, sex, height, weight, activity level, allergies, foods to avoid, diet, familiarity with Armenian cuisine, mealtimes, cooking frequency. Your daily targets are calculated from these.
- Scans. Barcodes, recognised products and dishes, their nutritional values, the time of the scan and technical details of the result.
- Diary and weight. Logged meals, daily totals and weight entries.
- Water, weekly plan and recipes. The water you log, the weekly plan the app makes for you and, when you ask for recipes, the ingredients you name and the limits you set (the meal, the cooking time).
- Eating window and reminders. The hours and days of your eating window, when a window started and ended, and which reminders are on and at what times.
- Church-fast mode. Only if you turn it on — it is off by default: which fasts you keep, what you leave out during them (meat, dairy, eggs, fish) and any fasting dates you set yourself. It is used only to choose and mark products and dishes for you.
- Photos. See the next section.
- Corrections. The corrections you send about product data.
- Ideas. In the “Profile → Suggest an idea” section, your answers (the app section, the text you write, how often you use the app, the app version and platform and, if you attach one, an image) are assembled into a PDF file on your phone and sent to us through your email app when you tap “Send”. The app does not keep them on our servers; the email is stored in the HamovAI mailbox, and to have it deleted, write to us.
- Subscription. Your subscription status (free, trial, Pro), which we receive from RevenueCat; payment details do not reach us.
- Technical data. App crash reports and anonymous usage events (below).
- Your phone’s notification address. So that we can tell you when a scan is ready, the app registers your phone with Google’s Firebase Cloud Messaging and stores the address (“token”) it is given next to your account. It identifies the app on your phone, not you. It is removed when you sign out or delete your account.
Photos
- Label photos are stored on our servers by default: they are photos of commercial packaging and help us refine the product database.
- Dish photos are stored on the server only with your consent (the “Profile → Photo storage” switch, off by default). When it is off, the photo is sent for recognition and is not stored.
- The profile photo is stored in a private storage area, accessible only to you.
- Progress photos (“Progress → Photos”) are stored in a private storage area, accessible only to you; each one is added by your separate choice, is shown to no one, is not sent to any artificial intelligence service, and is deleted together with your account.
- An image attached to an idea (a screenshot or photo, optional) is only included in the PDF of that email; it is not stored on the server, is not sent to any artificial intelligence service, and only the HamovAI team sees it.
- From all photos, EXIF data is removed before upload (location, device model, time).
- Small previews stored on the phone do not leave the phone.
- Dish photos stored on the server may be viewed by people in order to improve the recognition of Armenian dishes. They are not used to train artificial intelligence models without an update of this policy and your new consent.
Steps (Health Connect)
- Only with your permission. The “Connect Health Connect” button in “Home → Steps” opens the Health Connect permission dialog. Without it the app does not read steps.
- What we read. Only the number of steps for the day, from Health Connect (recorded by, for example, Samsung Health, Google Fit or a watch). We do not read heart rate, sleep, workouts or any other Health Connect data, and we write nothing there.
- They stay on your phone. The steps, the distance and calories burned calculated from them, the steps goal and the “Add the extra steps to the day’s goal” switch are calculated and stored only on the phone; they are not sent to our server, to any artificial intelligence service or to any third party.
- The Steps widget in the background. If you allow “Refresh in background” in “Steps → Widget”, the app will read the day’s steps also while closed, about every 15 minutes, only while the Steps widget is on your home screen, and when you tap the widget’s refresh button. What it reads also stays on the phone. Without that permission the widget refreshes when you open the app.
- Withdrawing. “Profile → Steps → Disconnect”, or the Health Connect settings, at any time.
How we use the data
- To show and store your scan results.
- To calculate your daily targets and show your progress.
- To complete the shared database of products and dishes; that database contains product data, not your personal data.
- To find and fix errors in the app.
Third-party services
The app works through the following services. Each of them is given only what it needs for its task.
- Supabase (European Union, Frankfurt) — database, accounts and file storage. Your data is stored here.
- Google Gemini (Google) — recognition of label and dish photos. The photo is sent for recognition.
- Mistral AI (France) — fallback recognition when the main one is unavailable.
- OpenAI and Google Cloud Vision — fallback services for the same purpose.
- Sentry (European Union) — crash reports. Personal data is removed from the report before it is sent. The IP address is not stored.
- PostHog (European Union) — anonymous usage statistics (for example, “scan finished”). The IP address and location are not stored.
- RevenueCat — subscription management. Payment is made through Google Play or the App Store; we do not receive your payment details.
- Resend — delivery of service emails (for example, the password reset code). It receives only your email address and the content of the email.
- Firebase Cloud Messaging (Google) — delivery of the “your scan is ready” notification on Android. It receives your phone’s notification address and the text of the notification: the name of the scanned product or dish and its calories. No photo is sent to it.
Photos sent to artificial intelligence services contain no identifying data; your name or email is not passed to them.
How long we keep it
- Account, profile, scan, diary and weight data: as long as the account exists.
- Crash reports and usage events: up to 90 days.
- When an account is deleted, all data and photos are deleted immediately (see below).
Your rights
- View and change. All profile answers can be changed in the app.
- Get your data. “Profile → PDF summary” creates a summary of your meals, calories and weight on your phone; you send or save it yourself, and we do not receive it. Progress photos are not included in the summary.
- Delete. “Profile → Delete account” deletes your account, all data and photos. This action cannot be undone.
- Withdraw consent. You can turn off the storage of dish photos at any time.
- Questions. “Profile → Contact us”.
If you are in the European Union, the GDPR applies to you, and you also have the right to data portability and the right to lodge a complaint.
Children
The app is not intended for children under 13. The calorie deficit goal and the eating window are available only from age 18.
Changes
When this policy changes, you will see the updated version in the app, with a new date.
Updated: 8 October 2026