Privacy policy
Last updated 27 August 2026
Cut is an iPhone app for logging food and weight. This page describes what happens with your data, in plain English. It is short because not much happens.
The short version: your log stays on your devices and, when iCloud is available, in your private iCloud database. The app has no accounts, no developer-readable copy of your database, no analytics SDK, no ads and no third-party tracking of any kind. This website is a separate thing and does measure visits - see This website at the end.
Data leaves your private log only when you use an online feature, such as an AI estimate, coach answer or barcode lookup. Each situation is described below.
What Cut stores, and where
Every meal, weigh-in, activity record, fridge snapshot and coach conversation is stored in a local database on your iPhone, using Apple's SwiftData. When your phone is signed in to iCloud, that database also syncs to your private CloudKit database under your Apple Account. It is not an account or database run by us, and the developer cannot read it. Without iCloud, Cut keeps the log on that phone only.
The one piece of infrastructure we do run is the relay described further down, which forwards requests to Anthropic so the API key need not be stored inside the app. It keeps usage counts, never content.
Deleting the app deletes its local database from that phone. If iCloud sync was active, the private iCloud copy remains and returns when you reinstall under the same Apple Account. Choosing Erase everything inside Cut removes the app's records from both the phone and its synced iCloud copy. Apple Health keeps data already written to Health.
Apple Health
With your permission, Cut reads your weight, step count, active energy, workouts and time asleep from Apple Health. It also reads the height, date of birth and biological sex already in your Health profile, so it does not have to ask you for them again. It writes back the calories and protein you log plus any weigh-ins you enter by hand, so the Health app stays the source of truth.
Health data is used for one thing: showing you your own numbers, and computing your weight trend and calorie target on the device. It is never used for advertising and never sold or shared with anyone.
One nuance worth stating plainly: if you ask the coach a question or request meal suggestions, the summary sent to Anthropic (described below) includes numbers derived from this data, such as your weight trend and daily activity. If you never use those features, no Health-derived data leaves the phone.
Meal and fridge photos
When you photograph a meal or your fridge, that photo is sent over an encrypted connection to Anthropic's Claude API, which estimates the nutrition or suggests meals. The photo is used to produce that response, and the relay does not keep it. A photographed meal keeps a smaller copy attached to the meal, so you can check months later what a number was read from; deleting the meal deletes that copy with it. The attached copy is stored in Cut's local database and, when sync is active, its private iCloud copy. It is not uploaded to any database we can read. Photos are stored at about 150 KB each, so a year of photographing four meals a day is roughly 215 MB. Anthropic processes API requests under its own privacy policy, and does not use API data to train its models by default.
The relay in between
Requests to Anthropic do not go straight from your phone. They pass through a small relay we run on Cloudflare Workers, which exists so the API key is not stored inside the app where anyone could extract it.
The relay never stores the contents of a request or a response. It does not keep your photos, your meals, your messages to the coach or its replies — those pass through and are gone. What it records, per request, is the usage metadata needed to keep the service running and its costs bounded: a timestamp, which app token made the call, whether it succeeded, how long it took, and the number of tokens used. That record contains nothing about you or your food.
The coach
When you ask the coach a question, Cut builds a compact summary of your own logged data on the device: daily calorie and protein totals, your weight trend, activity, your most-logged meals and the item list from your latest fridge photo. That summary is sent, via the relay described above, to Anthropic's API so the answer can be grounded in your actual history rather than generic advice.
Your full database is never sent to the coach. Coach conversations are kept in the same local and private iCloud database as your meals so you can read them again. What gets sent when you ask a question is the freshly built summary above plus the messages of the conversation you are currently in, never your archive of past conversations.
Barcodes
Scanning a barcode sends the barcode number to Open Food Facts, a public, non-profit food database, to fetch the product's label data. Nothing else is sent with it beyond the ordinary metadata of any internet request.
What Cut does not do
- No Cut account, and no personal profile in a database run or readable by us.
- No analytics or advertising SDKs inside the app, and no third-party trackers of any kind in it. Crash reporting exists only in beta builds - see below - and sends nothing to any third party. The marketing website is covered separately below.
- No ads.
- No selling, renting or sharing of your data with anyone, ever.
This website
Everything above is about the app. This site - the pages you are reading now - uses Google Analytics to count visits, so I can tell whether writing these pages is worth the time. It records the usual things a web analytics tool records: the page you viewed, roughly where in the world you are, and what kind of device and browser you used. It is not connected to the app, cannot see anything in your food log, and there is nothing here to sign in to.
If you would rather not be counted, any content blocker or your browser's "do not track" setting will stop it, and the site works exactly the same without it.
Crash reporting (beta builds only)
TestFlight and development builds of Cut report crashes to a crash-reporting service we host ourselves (a self-hosted Sentry instance) so crashes can be fixed quickly during testing. A crash report contains technical diagnostics only: device model, OS version, app version, and the state of the code when it crashed. It never contains your meals, weights, photos, health data, or anything you typed. App Store builds of Cut do not include active crash reporting and send nothing.
Changes
If any of the above changes, this page will be updated before the change ships, and the date at the top will move.
Contact
Questions about any of this: [email protected].