Tiro · Legal
Privacy Policy
Last updated July 28, 2026
Your health data is yours. This policy explains, in plain language, exactly what Tiro collects, what stays on your device, and how to get your data out or delete it entirely.
1. Introduction and scope
This policy explains how Tiro (“we”, “us”, “our”) collects, uses, and protects your information when you use the Tiro mobile app and this website. Tiro is operated by Lightzone Solutions LTD, a company registered in England & Wales. Tiro is a GLP-1 tracking companion — it is not a medical device and does not provide medical advice. By using Tiro you agree to this policy.
2. The data we collect, and why
Tiro is anonymous-first: you can use every core feature without creating an account. We collect only what the app needs to work for you. The data types below are the same ones declared on Tiro's App Store privacy label:
- Health & Fitness data you enter — doses (medication, mg, date, time, injection site, how it felt), the inputs behind your estimated medication-level curve, your titration schedule, symptoms, weight, water, food and nutrition logs and macros, and the numeric body measurements derived from a body scan. By default this is stored only on your device. It is transmitted to and stored in your private account (on our backend) only if you turn on sign-in / sync.
- Contact info (optional) — if you choose to sign in with Apple, Google, or email, we receive an email address, and (with Sign in with Apple, on first consent) a display name. Anonymous users provide neither. We use this only for your account, backup, and cross-device restore — never for marketing.
- An anonymous user ID — created on first launch so the food-recognition service can be rate-limited fairly and so your data can sync if you opt in. It is not an advertising identifier and is never shared for advertising or with data brokers.
- Food photos, voice notes, and typed meal entries — when you log a meal by photo or by voice, that image or recording is sent securely to our food-recognition service purely to produce the calorie/macro estimate, and is not stored afterwards (see “Food photo & voice recognition” below).
What we do NOT collect: no advertising identifier (IDFA), no location, no contacts, no browsing or search history, no third-party analytics, and no crash or performance SDK. Tiro contains no ads and no cross-app or cross-site tracking, and we never sell or rent your data.
Your body-scan photos are never collected — see the next section.
3. Apple Health
Tiro can connect to Apple Health (HealthKit) so your data stays consistent across the apps and devices you already use. This connection is optional, is off until you turn it on, and can be turned off at any time — either inside Tiro (Profile → Apple Health) or in the iOS Settings → Health → Data Access & Devices → Tiro screen, where you control each data type individually.
Data Tiro writes to Apple Health (only the entries you log in Tiro): your weight, body fat percentage and BMI from body scans, the calories and macronutrients (protein, carbohydrates, fat, fiber) of meals you log, and your water intake.
Data Tiro reads from Apple Health (only if you allow it): your step count and active energy for your daily dashboard, and — so your history stays complete — weight and dietary-energy entries recorded by your other apps or devices.
How your Health data is handled:
- Health data is processed on your device. Tiro does not transmit your Apple Health data to our servers, and it is never stored in iCloud by Tiro.
- We never use Apple Health data for advertising or marketing, and we never sell it or share it with data brokers or other third parties.
- Apple Health data is used solely to provide the app's health- and fitness-tracking features to you.
- When you delete your account or your data in Tiro, Tiro also removes the samples it wrote to Apple Health (on a best-effort basis). Entries that other apps or devices wrote to Apple Health are not affected — you can manage those in the Apple Health app.
Your use of Apple Health is also governed by Apple's own privacy policy.
4. Body-scan photos never leave your device
If you use the camera body scan, the photos and the analysis that estimates your measurements run entirely on your device. The images are processed on your phone and then discarded — they are never uploaded to our servers and are never shared with any third party. Only the numeric measurements you choose to save are kept, and they leave your device only if you have enabled sync. This is why body-scan photos are not listed as “data collected” on our App Store privacy label.
5. Food photo & voice recognition
To recognize a meal, a food photo, voice recording, or typed description is sent over an encrypted (TLS) connection to our recognition service, hosted on Supabase, which passes it to our AI provider Google (Gemini) for inference. The image or audio is used only to generate the estimate and is not stored after processing — we keep only an anonymized counter to prevent abuse. These items are processed transiently and are not linked to your identity.
6. Your permission before anything is sent to the AI
Tiro asks you inside the app, before the first meal you scan, and will not send anything to the AI provider until you agree. The request tells you exactly what is sent, and who receives it:
- What is sent — only the single item you submit for that scan: the meal photo you take, the voice clip you record, or the description you type. Nothing else is attached to it: not your name, email, weight, body scans, doses or symptoms.
- Who receives it — our own server, which forwards it to Google (Gemini, on Google Cloud Vertex AI) to identify the food and estimate its nutrition. The estimate is returned to your phone.
- What they may do with it — Google states that data sent to Vertex AI is not used to train its foundation models. Google processes it under the Google Cloud data processing terms, which require confidentiality and security protections equivalent to those described in this policy, and it is not shared with anyone else.
You can decline, and every other part of Tiro keeps working — you can still log meals by entering them yourself. If you agree and later change your mind, turn it off under Profile → AI food scanning; nothing further will be sent.
7. Third parties and sub-processors
We use a small, fixed set of infrastructure providers to run the app. They process data only on our instructions and only to provide the service:
- Supabase — our backend: authentication, database, private storage, and the edge functions that power sync and food recognition.
- Google (Gemini) — the AI model that recognizes food from photos, voice, and text. It receives the meal input only to return an estimate, only after you have agreed in the app, and Google states it is not used to train its foundation models.
- Open Food Facts — the volunteer-run public food database. When you scan a barcode, only that barcode is looked up. No personal data is sent, and it is not an AI service.
- Apple — the App Store, which distributes the app and handles Sign in with Apple.
We do not use any advertising network, data broker, or third-party analytics or crash-reporting service.
8. Legal bases for processing (GDPR)
Where GDPR applies, we process your data on the basis of your consent (which you can withdraw at any time by turning off sync, signing out, or deleting your account), to perform our contract with you (providing the app), and our legitimate interest in keeping the app secure and functional. Health data is processed only with your explicit consent.
9. Data retention
Data you keep on your device stays until you delete it in the app or remove the app. If you enable sync, we keep your synced data for as long as your account is active. Food photos, voice recordings, and typed meal entries are processed transiently and are not retained after the estimate is produced. When you delete your account, your personal data is deleted from our systems within 30 days, except where we are legally required to retain limited records.
10. Your rights and how to exercise them
You can access, export, correct, or delete your data at any time. Most of this is available directly in the app under Settings: use Export my data to download everything as a JSON file, and Delete account & all data to erase everything on your device and on our servers. You can also delete your account from the account deletion page or by emailing us.
To revoke consent, turn off sync or sign out (which stops data leaving your device), turn off AI food scanning under Profile → AI food scanning (which stops anything being sent to our AI provider), or delete your account (which erases it).
GDPR (EEA/UK): you have the right to access, rectification, erasure, portability, restriction, and objection, and to lodge a complaint with your local data protection authority. CCPA/CPRA (California): you have the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information — and we do not sell or share your personal information. We will not discriminate against you for exercising any of these rights.
11. Children's privacy
Tiro is rated 13+ and is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has used the app, contact us and we will delete the data.
12. International data transfers
If data is transferred outside your region, we use appropriate safeguards (such as the standard contractual clauses) to protect it in line with applicable law.
13. Security
We use encryption in transit (TLS), access controls, and reputable infrastructure providers to protect your data. No system is perfectly secure, but we work to protect your information and will notify you of a breach where required by law.
14. Changes to this policy
We may update this policy as the app evolves. Material changes will be highlighted in the app or on this page, and the “last updated” date above will change.
15. Contact us
Questions about privacy, or want to exercise a data right? Email support@tiroglp1.app and we'll help. Tiro is operated by Lightzone Solutions LTD (England & Wales).
