Feat - Privacy Policy
Effective Date: 22 July 2026 | Last updated: 1 October 2026
This Privacy Policy explains how Feat (“Feat”, “we”, “us”, “our”) collects, uses, shares and protects your information when you use the Feat mobile app and website (together, the “App”). Feat is a nutrition and fitness app that helps you log food, track health and activity metrics, and generate AI-assisted meal plans and food insights.
Feat is operated jointly by Soheil Novinfard and Pouya Jabbarisani, who are the joint data controllers of the personal data described in this Policy. When Feat is incorporated as a company, this Policy will be updated to name that company (and its registered details) as the data controller.
Because Feat processes health-related information, we treat your privacy with particular care. Please read this Policy carefully. If you do not agree with it, please do not use the App.
The short version
- We collect the account, body-measurement, health and food data you give us, plus activity data from Apple Health and basic technical/usage data.
- To recognise food from photos and build meal plans, we send those inputs to AI providers (OpenAI and Anthropic) in the United States.
- We do not sell your personal or health data, and we do not use your Apple Health data for advertising.
- If you choose to share your week with a coach, trainer, dietitian or anyone else, we show that person only the parts you pick, through a private link and a separate code, until you pause or stop sharing.
- If you use Your circle, the people you connect with see your first name, your handle and the food you send them. If you publish a recipe, anyone with its link can read it under your first name and handle.
- Your health data is “special category” data — we rely on your explicit consent to process it, and you can withdraw that consent or delete your account at any time.
- You have rights over your data and can complain to the UK Information Commissioner’s Office (ICO).
1. Who We Are and How to Contact Us
Feat is operated jointly by Soheil Novinfard and Pouya Jabbarisani, acting as joint data controllers. You can reach us about privacy, or to exercise your rights, at:
- Email: [email protected]
- Postal address: Feat, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom
Email is the fastest way to reach us and the best route for privacy requests; we monitor it far more closely than post.
If you are in the UK or EEA and believe we have not handled your data properly, you have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concerns first.
2. Information We Collect
We collect only what we need to run the App. The categories below reflect what the App actually processes.
2.1 Account and identity data
- Username (shown in the App as your handle, see section 2.9), email address, and a securely hashed password.
- First and last name, date of birth, and gender.
- If you sign in with Apple or Google, we receive a unique identifier and basic profile details (email and name) from that provider. Where you sign in with Apple, we retain a minimal Apple account record to allow account recovery.
2.2 Health and fitness data (special category data)
The following are treated as “special category” data under UK/EU data protection law and are processed only with your explicit consent:
- Body measurements you enter: weight, height, and body-fat percentage.
- Goals and derived targets: goal type, target weight/body fat, and calculated calorie and macronutrient targets.
- Health context you choose to provide: ethnicity, health conditions (including any free-text notes), food allergies, and dietary preferences.
- Activity and workout data read from Apple Health (see section 5): steps, distance, active energy, and exercise sessions.
2.3 Food, meal and photo data
- Foods and meals you log, custom foods you create, and foods you favourite.
- Recipes you build: their name, ingredients and amounts, method, and any photo you add (see section 2.9).
- Photos you take to scan food, barcodes or nutrition labels. These are uploaded to our servers for recognition and, to power the food catalogue, may be stored (see sections 4 and 8).
- Food search queries you enter.
2.4 Subscription and purchase data
If you subscribe to Feat Plus, we receive purchase and entitlement information from Apple (for example transaction identifiers, product ID, and subscription status/expiry). We never receive or store your card or bank details — all payments are handled by Apple.
2.5 Device, technical and usage data
- A device identifier (Apple’s “identifier for vendor”, which resets if you reinstall the App), app version and build, operating-system version, and device model.
- IP address and user-agent, and log data generated when you use the App.
- Product-analytics events describing how you use features (see section 6).
2.6 Diagnostic and crash data
To help us support you and debug problems, the App can upload technical breadcrumb logs (the device identifier, app/OS version, device model, and non-content event traces). This is controlled by the “Share usage & diagnostics” setting in Advanced Settings, which is on by default and can be turned off at any time; the same setting also controls product analytics (see section 6). Separately, to keep the App stable, we use crash- and error-reporting (Sentry, EU-hosted) as essential stability monitoring; crash reports include device, app and build information and are linked to your account, but do not include your health data.
2.7 Support data
If you contact us via the support form, we collect your name, email, and message. The form uses Google reCAPTCHA to prevent spam, which processes technical signals such as your IP address and interaction data.
2.8 Sharing with a coach
If you use Share with a coach (see section 7.1), we also keep:
- The name and role you give the person you share with (for example “Maya, my coach”). This is your own description; we do not check who they are.
- What you chose to share (your food diary, activity and/or weight), the dates the share covers, and whether it is on, paused or ended.
- A record of each consent you give: the exact words you agreed to, their version, the time, and the version of the App you used.
- A record of each time the shared page shows your data: when it was opened and which week it showed. We do not record who opened it, we set no cookie, and we store nothing about their device. Their IP address is used only briefly, in memory, to limit repeated attempts at the code.
- The share’s private link and a one-way (hashed) form of its six-digit code. We never store the code itself.
2.9 Your circle, contacts and published recipes
- Handle and profile link. Your account has a handle (for example @sam) and a profile link. Anyone who has your handle or your link can see your first name, your handle and your circle code, and can ask to join your circle. Nobody joins until you accept.
- Your circle. We keep who you are connected with (up to 20 people) and the requests you send and receive. For each food you send or are sent we keep its name, brand, picture, meal, portion, calories and nutrients, the day, any note you add (up to 140 characters), and whether the other person added it to their day. The person you send it to gets a notification showing your first name, the food and your note.
- Share links. A link to a single food can be opened by anyone who has it. Its page shows that food and your note with your first name, your handle and your circle code. Each time the page is opened we record that it was opened, the country, the kind of device and the site or app the visitor came from. We set no cookie and keep no IP address or anything else that says who opened it. A link stops working after 30 days.
- Finding people from your contacts. If you tap “Check my contacts” or pick a contact, the App reads names, email addresses and phone numbers on your phone. It sends us only a one-way scrambled (hashed) form of each email address. We compare it with the same form of our members’ email addresses to tell you who is already on Feat, and we do not keep it. Names and phone numbers never leave your phone, and an invitation is sent by you, from your own Messages app.
- Being found. We keep a hashed form of your own email address so that people who already have your address can find you on Feat. This is on by default; you can turn it off in Your circle under “Let people who have my email find me”, and you will then be found only by your handle or profile link.
- Published recipes. A recipe you build is private until you publish it. A published recipe has a public page showing its name, photo, ingredients, method and nutrition, with your first name and handle. We ask search engines not to list these pages, but anyone who has the link can read them and pass it on. You can take a page down at any time, and we may take one down if it breaks our Terms.
3. How We Use Your Information and Our Lawful Bases
Under UK/EU data protection law we must have a “lawful basis” for each use of your data. The table below sets these out.
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and run your account; provide core tracking features | Account, food, body-measurement data | Performance of our contract with you |
| Process your health, ethnicity, allergy and dietary data to personalise targets and meal plans | Special category health data | Explicit consent (which you can withdraw) |
| Recognise food from photos and generate AI meal plans and insights | Photos, food text, health/diet configuration | Contract, plus explicit consent for the health inputs |
| Read activity/workout data from Apple Health | Apple Health data | Explicit consent (granted via Apple’s Health permission) |
| Show the parts of your record you pick to a person you choose (Share with a coach) | Your first name; the food diary, activity and/or weight you pick, for the dates you pick; the name and role you gave them | Explicit consent, given for each share (you can pause or stop it at any time) |
| Connect you with the people you choose and deliver what you send each other (Your circle) | Your first name and handle; your connections and requests; the foods and notes you send | Performance of our contract with you |
| Tell you which of your contacts are already on Feat, and let people who have your email find you | Hashed email addresses | Legitimate interests (you can switch being found off) |
| Show a recipe you publish to anyone who has its link | The recipe and its photo; your first name and handle | Performance of our contract, at your request |
| Take payment and manage Feat Plus entitlements | Apple purchase data | Performance of our contract |
| Send service emails (password reset, one-time codes, support replies) | Email address, message | Contract / legitimate interests |
| Keep the App secure and prevent fraud and abuse | Device, technical, usage data | Legitimate interests |
| Understand feature usage to improve the App (analytics) | Usage/analytics data | Consent, where required (see section 6) |
| Diagnose technical problems | Diagnostic breadcrumb logs | Consent (opt-in) |
| Comply with legal obligations and enforce our Terms | As necessary | Legal obligation / legitimate interests |
We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not use your Apple Health data for advertising or marketing.
4. AI Processing of Your Data
Several Feat features are powered by third-party AI providers located in the United States (currently including OpenAI and Anthropic). We may change these providers from time to time; the current list is kept in our sub-processor list (section 7). To provide these features we send them the following:
- Food recognition: the photo you take of your food, barcode or nutrition label.
- Meal planning: your meal-plan configuration, which can include health conditions, allergies, dietary preferences and your calorie/macro targets. We do not send your name, email, date of birth, or exact body measurements for this purpose.
- Meal images and search: text describing a meal, used to generate illustrative images and to power a semantic cache.
- Recipes you build: the recipe’s name and the ingredient lines and steps you type, when Feat reads an ingredient, drafts a method or reviews the recipe for you.
We keep operational logs of AI requests and responses so we can debug and improve these features; for meal planning these logs can include the health inputs listed above. We are working to minimise and time-limit this retention (see section 10).
Accuracy. AI-generated meal plans, nutrition estimates and insights are approximations and may be inaccurate or incomplete. They are not medical, dietary or clinical advice. Do not rely on them for allergy-critical or medical decisions — always check labels and consult a qualified professional. See our Terms of Service for the full disclaimer.
Your data is not used to train AI models. We use these providers under their API terms, which do not use data submitted through the API to train their models, and we do not permit such use. Your photos and text are sent only to generate your result and for limited operational logging (see section 10).
5. Apple Health (HealthKit)
With your permission, Feat reads data from Apple Health to keep your profile current and calculate your activity-calorie bonus. We read: height, weight, body-fat percentage, steps, walking/running distance, and workouts. Feat only reads from Apple Health — it does not write any data back to it.
You control this permission in the iOS Health app and can revoke it at any time. In line with Apple’s requirements, we never use Apple Health data for advertising or marketing, we do not sell it, and we do not share it with third parties for their own purposes. Data we read is synced to your Feat account and stored as described in this Policy.
If you choose to share your activity or weight with a coach (section 7.1), the steps, workouts and weight Feat has read from Apple Health can appear on the page you share with them, for the dates you pick. This happens only at your request and with your explicit consent, and stops as soon as you pause or stop sharing.
6. Analytics, Crash Reporting and Cookies
We use a product-analytics provider (Amplitude, hosted in the EU) to understand how features are used so we can improve the App. Analytics events may include feature interactions, search terms and some profile attributes (such as your goal, activity level and dietary preference), linked to your account. We use this to improve Feat, not to advertise to you.
We use a crash- and error-reporting provider (Sentry, hosted in the EU) to keep the App stable. Crash reports include device, app and build information and diagnostic breadcrumbs, and are linked to your account so we can investigate issues. We do not send your health data to Sentry.
You can turn analytics off at any time using the “Share usage & diagnostics” toggle in the App’s Advanced Settings — the same control also stops diagnostic-log uploads. Analytics is on by default (you can opt out); crash reporting is treated as essential stability monitoring and is not covered by this toggle. You can also contact us at [email protected].
Our website uses only essential cookies needed for it to function and the reCAPTCHA service on the support form. We do not use advertising cookies.
7. How We Share Your Information
We do not sell your personal or health data. We share it only with the service providers (“processors” and “sub-processors”) that help us run the App, and only as needed, and with people you choose to share with yourself (section 7.1). The list below reflects our current sub-processors; we may update it as our providers change, and will keep this list current.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| OpenAI | Food recognition, meal-image generation, semantic search | Food photos; food/meal text; meal-plan health inputs | USA |
| Anthropic | Food recognition, meal planning | Food photos; meal-plan health inputs | USA |
| Apple | Sign in with Apple, subscriptions, Apple Health, notifications | Account/purchase data; on-device health data | USA / global |
| Sign-in; reCAPTCHA on the support form | Sign-in token; reCAPTCHA technical signals | USA / global | |
| Resend | Transactional email | Email address and message content | USA |
| DigitalOcean | Cloud hosting and file storage | All server-side data; food photos and generated images | UK (London) & EU (Amsterdam) |
| MongoDB | Primary database | All account and health data | EU |
| Redis | Temporary security data (one-time codes, rate limiting) | Hashed email + counters (short-lived) | EU |
| Amplitude | Product analytics | Usage events and profile attributes (incl. goal, diet, workout level), linked to your account | EU |
| Sentry | Crash & error reporting / diagnostics | Crash and error reports, device/app/build info, diagnostic breadcrumbs, and your account ID — no health data | EU (Germany) |
Most of these providers act as our processors and are contractually required to protect your data and use it only to provide services to us. Some — in particular Apple and Google (for sign-in) and, where applicable, the AI providers — may also act as independent controllers for their own purposes under their own privacy policies; we are not responsible for that independent processing, and you should review their policies. We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and property of Feat, our users or others. If our business is ever transferred, your data may transfer with it, subject to this Policy.
7.1 People you choose to share with
With Share with a coach you can let a person you choose (for example a coach, personal trainer, nutritionist, dietitian or doctor) see a read-only page of your week. They need both a private link and a separate six-digit code from you. They see your first name, the name and role you gave them, and only the parts you picked (food diary, activity and/or weight) for the dates you picked, including the daily targets that go with them. They never see your email address or anything you did not pick, and they cannot change anything. You can see in the App when your page was last opened and how many times.
That person is not our processor: what they do with what they see is up to them, so share only with people you trust and keep the link and code private. You can pause or stop a share, change what it shows, or make a new code or link at any time in the App, and the page stops showing your data straight away. Deleting your account deletes all your shares.
With Your circle you send food to people you have connected with, and a share link or a published recipe can be opened by anyone who has the link (section 2.9). None of these people is our processor: what they do with what they see is up to them. You can remove someone from your circle at any time, which stops anything new passing between you; what you have already sent them stays with them. They never see your email address.
8. Where Your Data Is Stored and International Transfers
Our servers and primary storage are located in the United Kingdom (London) and the European Union (Amsterdam). Your food-scan photos and generated meal images are stored in the EU.
We deliberately keep our analytics (Amplitude) and crash reporting (Sentry) in the EU. Some other providers — in particular the AI providers (OpenAI, Anthropic), email (Resend), and the sign-in services (Apple, Google) — process data in the United States. When we transfer personal data outside the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses, together with additional protection measures where needed.
While these safeguards are designed to protect your data, no international transfer can be guaranteed entirely free of risk, and by using the App you acknowledge that your data may be processed in the countries described above. You can ask us for more detail about these safeguards using the contact details in section 1.
9. Data Security and Your Responsibilities
We use technical and organisational measures to protect your data, including encryption in transit, hashed passwords, access controls, and reputable cloud infrastructure. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. To the fullest extent permitted by law, you use the App and provide data at your own risk, and our responsibility for any security incident is subject to the limitations of liability in our Terms of Service. Nothing here limits our non-excludable obligations under data protection law.
You are responsible for keeping your login details confidential, for the accuracy of the information you give us, and for the content you choose to share (including anything you add to shared custom foods). Please do not share sensitive information you do not want us to process.
10. Data Retention
We keep your data only as long as we need it:
- Account and health data: for as long as your account is active, and then deleted or anonymised after you delete your account (see section 11), subject to the points below.
- AI operational logs: kept for debugging and abuse-prevention. We are implementing a defined retention limit and minimising the health data these logs contain.
- Diagnostic logs: short-lived and used only for troubleshooting.
- Coach shares: kept while a share runs, and deleted 400 days after it ends or you stop it; the record of each time its page was opened is deleted 400 days after that opening. We keep them this long so you can see when your page was opened and as the record of the consent you gave. Deleting your account deletes them straight away.
- Your circle and recipes: your connections, requests and the foods you sent or were sent are kept while your account exists, and deleted for both of you when either account is deleted. Share links stop working after 30 days, and the record of each time one was opened is deleted after 400 days. Deleting your account takes down every recipe page you published and removes your name and handle from it; the recipe and its photo are kept without any link to you. A food that someone has already added to their own diary stays in their diary.
- Apple sign-in recovery record: a minimal record is retained after deletion to prevent account-recovery issues; you can ask us to erase it.
- Legal/financial records: kept where we are legally required to retain them.
11. Your Rights and How to Exercise Them
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data (“right to erasure”);
- Withdraw consent at any time, including for the processing of your health data (this won’t affect processing already carried out);
- Object to or restrict certain processing;
- Data portability — receive your data in a portable format.
Deleting your account. You can delete your account and associated data directly in the App (Settings → Account), or by emailing [email protected]. We will respond to rights requests within one month. You will not be discriminated against for exercising your rights, and you can also complain to the ICO (section 1).
12. Children
Feat is not intended for children or minors. You must be at least 18 years old to use the App. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it. We chose 18 (rather than the lower digital-consent ages some laws allow) because Feat processes health data — a higher bar keeps children’s-data obligations out of scope.
13. Third-Party Links and Services
The App may link to or integrate with third-party services (for example fitness trackers or sign-in providers). We are not responsible for their privacy practices; please review their policies before using them.
14. Changes to This Policy
We may update this Policy from time to time and reserve the right to do so at our discretion. If we make material changes, we will notify you in the App or by email and update the “Last updated” date. For significant changes to how we use your health data, we will seek fresh consent where required. Your continued use of the App after an update takes effect means you accept the updated Policy, to the extent permitted by law.
15. Contact Us
Questions or concerns about this Policy or your data? Contact us at [email protected], or write to us at Feat, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.
By using Feat, you acknowledge that you have read and understood this Privacy Policy.