Privacy
Privacy Policy
Last updated 3 October 2026
1. Introduction
This Privacy Policy explains how AllTaken, Inc. (“AllTaken”, “we”, “us”) collects, uses, discloses and otherwise processes personal information when you use the App, visit alltaken.app, join the beta waitlist or contact us. In this policy, “the App” means our mobile app for tracking supplements, medications and routines, including its widgets and test versions, under whatever name it is listed on the Apple App Store or, once offered, Google Play. Today the App is available for iPhone only. This policy forms part of our Terms of Use; capitalised terms that are not defined here have the meaning given there.
AllTaken is operated by AllTaken, Inc., a Delaware corporation, 2810 North Church Street, Wilmington, DE 19802, United States. How to contact us is set out in section 11.
You must be 18 or older to use AllTaken. When you set up the App it asks for your age range, and anyone who chooses “Under 18” cannot continue to create an account. AllTaken is not directed at children. If we learn that someone under 18 has given us personal information, we will take steps to delete that information and the account.
If you are covered by Washington’s My Health My Data Act, our separate Washington Health Data Privacy Policy also applies to the health information described below.
2. What’s new in this version
This is the first published version of this policy, dated 3 October 2026. When we change it, the changes will be listed here.
3. Personal information we collect
Information you provide directly
- Account and profile information. Email address, password (handled by our authentication provider and never visible to us), display name, time zone, app language, whether onboarding was completed, the goals you choose, any sleep or meditation targets you set, and a record of whether and when you turned AI features on or off.
- Onboarding answers. When you set up the App it asks what you take and roughly how many items, your age range, your height (optional), your main goal, what you find hardest, how confident you are in your routine, how often you forget, and what you want from the App. These answers are kept on your iPhone only; they are not stored in your account on our servers and are not restored to a new device. Two things based on them do leave the iPhone: a goal you choose that matches one of the App’s goals is saved to your account, and, only if you turned usage analytics on, usage events record the category you picked for some answers (for example your age range or main goal), never free text and never your height.
- Supplements, medications and routines. The products you add (product identity, your own dose and unit, schedule, start and end dates, notes), the history of changes to each routine, one-day schedule exceptions, inventory counts and the reminder settings you choose.
- Daily logs. Whether each item was taken, skipped, forgotten or not planned, with the time and an optional reason.
- Wellness entries. Your answers to an occasional one-tap question about how you have been feeling, such as your sleep, energy, digestion or focus, and any daily mood, energy and stress check-ins, with notes, recorded in earlier versions of the App. Together with your routine, this information can indicate a health condition and may be treated as sensitive or health information under some laws.
- Product labels and shelves submitted for scanning. Label photos, the text read from them and barcodes, and, if you scan a whole shelf, a photo of the shelf, handled as described below.
- Questions you submit to AI features. Your questions and the context from your own records used to answer them, handled as described below.
- Shared catalogue submissions. Products you add are private to your account. If you choose to submit a product to the shared catalogue, only the product identification details and label photos you submit are reviewed, never your routine, doses or wellness entries.
- Communications with us. Your email address and whatever you include when you contact support or make a request about your information. If you report an AI answer, the App opens an email to support containing your reason, the answer’s reference and its text; you see it and send it from your own mail app.
- Invitations. Where invitations are offered, if you join through an invitation code or link, we record which code you used and the account that shared it, with the dates you joined and first subscribed, so the invitation can be credited. If you turned usage analytics on, the campaign labels carried by the link that brought you to the App (such as its source and campaign name) are saved to your account once. We do not use advertising identifiers or device fingerprinting.
- Beta waitlist. If you join the waitlist on this website: your email address as you typed it, the time you submitted it, the version of the consent notice you were shown, a record that the signup came from this website, and a status (pending, invited or removed) with the time it last changed, which we update by hand once we have contacted you about testing.
- Payment information. Subscriptions are sold and billed by Apple through the App Store under Apple’s terms, including refunds, and, once the App is offered there, by Google through Google Play under Google’s terms. We do not receive your card details; we keep the store transaction identifiers and subscription status needed to know that your account has an active plan.
Information collected automatically
- Usage analytics, only if you turn it on. Usage analytics is off unless you tick it on the consent screen when you set up the App or turn it on later in Profile › Data & Privacy, and you can turn it off at any time. When it is on, product-usage events are recorded to your account, for example that onboarding started, a scan started or failed, a routine was created, a paywall was viewed or a purchase completed. Each event carries an app-session identifier, the app version and a fixed set of categorical properties such as counts, durations, entry points, outcome codes, plan, the categories of your onboarding answers (such as age range and main goal) and app language. Events never contain product or medication names, doses, notes, questions, scanned text, photos or email addresses.
- Technical and security information. Our hosting providers process the technical information needed to deliver and protect the service, such as IP address, request logs and device or browser characteristics. Our own server functions log request status, timing and error codes, not the content of requests. To limit automated abuse of the waitlist form, the signup endpoint keeps a short-lived, hashed count of requests per network address; the address itself is not stored.
- Crash reports. The app contains no crash-reporting or advertising software. If you have chosen to share analytics and crash data with developers in your iPhone settings, Apple provides us with crash reports under Apple’s terms.
- Cookies and tracking. alltaken.app sets no cookies and uses no analytics, advertising or tracking technologies. Apart from the waitlist form, the website has no login and does not connect to the app’s database. Reminders are scheduled on your iPhone; the app does not send push notifications from a server.
Information from third parties
- Sign-in providers. If you use Sign in with Apple or Sign in with Google where they are offered, we receive the identifier and email address that service shares.
- Apple. The App Store transaction identifiers and subscription status described above, and crash reports you have chosen to share.
- Apple Health. Only the categories you authorise, as described in section 4. Apple Health information is used only to provide the features you request; it is never used for advertising or marketing and never shared for those purposes.
We do not buy information about you, and we do not receive it from advertising partners, data brokers or other users.
De-identified or aggregated information
We do not currently create de-identified or aggregated datasets from your information for purposes other than serving your own account. If that changes, this policy will say so and describe the safeguards used.
Apple Health, scanning, AI features and sync
Apple Health is optional and read-only; AllTaken never writes to Health. If you allow it, the app reads daily totals or averages for steps, active energy, resting heart rate, heart rate variability, sleep and workouts. Those daily values are stored on your iPhone and, while you are signed in, in your account on our servers so they can be shown next to your routine. Raw Health samples never leave your iPhone. You can change or revoke access at any time under Settings › Health › Data Access & Devices › AllTaken; revoking stops new imports, and daily values already imported remain in your account until you delete them. If you turn AI features on, summaries of these values can be sent to a third-party AI service as described next.
AI features use a third-party AI service. They are off unless you tick them on the consent screen when you set up the App or turn them on later in Profile › Data & Privacy, and you can turn them off at any time; our server also checks that they are on before it sends anything. With AI features off, scanning still reads label text and barcodes on your iPhone, and nothing is sent to an AI service. With AI features on, the App asks you to confirm before it sends something in each session, and then sends the following to our server, which passes it to a third-party AI service only to produce the answer you asked for:
- Label scans: compressed photos of the front label and the facts panel, the text recognised on your iPhone and any barcode. The details found are shown to you for review, only the details you confirm are saved, and our server does not keep the photos.
- Shelf scans: the photo of your shelf or cabinet, to list the products it shows. Nothing is saved until you confirm each one, and our server does not keep the photo.
- Questions you ask: your question; the recent questions and answers of the same chat (at most the last few exchanges), so the answer can refer to them; and summaries of your own logged data that our server adds from your account: your active supplements and medications with strengths and schedule, ingredient totals and overlaps, adherence and weekly summaries, goal coverage, inventory, safety findings, the intake analysis for a date, and summaries of your connected Apple Health data, namely the average, lowest and highest daily values of sleep, steps, resting heart rate and heart rate variability, and the averages of active energy and workout minutes, over recent days, with averages of any check-ins or meditation sessions you recorded. Raw Health samples are never sent.
- Explanations of a pattern: only the summary being explained: the item and goal, how many days it was and was not taken, the average of the Apple Health value involved (such as sleep or resting heart rate) on each kind of day or your answers to the occasional wellness question, any tags you recorded in that period, and the confidence level.
Before and after the AI service answers a question, the question and the answer are also checked by a safety service that we run on a cloud hosting provider; it records its decision codes, not the text. We do not store your chats as conversations on our servers; your chat history stays on your iPhone. So that a question is not answered and charged twice if your connection drops, our server keeps a copy of the final answer for ten minutes; after that the copy is no longer used and is deleted in the next daily clean-up. Apart from that, it keeps only a fingerprint of the answer, not its text, for abuse monitoring. Requests are made by our server: the AI service does not receive your name, email address or account identity, receives photos only for the scan being processed, and receives your information only so that it can produce the answer. We use two AI processing providers, one as a backup for the other, and describe them by category rather than by name because the provider can change. Our main provider’s business terms state that it does not use our requests to train its models. The backup provider is used only for questions, when the main provider cannot answer, and its terms state that it does not store the content of requests. Each provider handles requests under its own business terms with us, and we send it only what is listed above. We do not use your information to train AI models.
Account storage and sync. The app keeps a full copy of your data on your iPhone in its private storage so it works offline. While you are signed in, everything you record is also synced to your private account on our servers, except your onboarding answers, which stay on your iPhone; each record is protected so that only your account can read it. Sync is part of using a signed-in account; it is not a separate setting. Insights and patterns are computed on your iPhone from your own records.
4. How we use personal information
- To provide the service. To keep your routine, logs and reminders, identify products from labels, show your history, patterns and weekly summaries, maintain your account and keep your records available to you across sessions and devices.
- To process scans and answer AI questions through a third-party AI service, using only your own recorded information as context, and only when you have turned AI features on.
- To manage paid features by honouring your App Store subscription, and to credit invitations where they are offered.
- To communicate with you. To respond to support requests, send administrative notices about changes to this policy or the Terms, and, if you joined the beta waitlist, to contact you about beta testing.
- To respond to privacy-rights requests and to verify them.
- To understand and improve the service and fix problems, only when you have turned usage analytics on.
- To protect the service and its users: monitoring for misuse, preventing fraud and automated abuse of the website and waitlist, and enforcing our Terms.
- To comply with the law, including responding to lawful requests from authorities.
- To run our business: record keeping, audits, accounting, insurance, and the establishment, exercise or defence of legal claims.
- In a business transaction: to evaluate or complete a reorganisation, financing, sale or transfer of the business or its assets, subject to this policy.
AllTaken is a tracking and general-wellness app. It does not diagnose, treat or prevent any condition and does not give medical advice. We do not use your information for advertising, and we do not sell it. Where the law requires a legal basis for each purpose, the basis we rely on is set out in section 13.
5. How we disclose personal information
We disclose personal information only as needed for the purposes above, to these categories of recipients:
- Service providers. Companies that host and operate the app and website on our behalf: cloud hosting, database, authentication, server-function and storage providers for your account; a third-party AI service (two AI processing providers, one a backup for the other) for scans, questions and explanations, only when you have turned AI features on; a cloud hosting provider that runs our safety-check service for questions; and website hosting and security providers that serve alltaken.app, store waitlist signups and protect the signup form from automated abuse. Each receives only what its purpose requires and processes it on our behalf under its terms with us; the AI providers’ terms on training and storage are described in section 3.
- Apple. For App Store distribution and subscriptions, Sign in with Apple, TestFlight, Apple Health on your device and any crash reports you choose to share, under Apple’s terms.
- Google. For Sign in with Google where it is offered, and for distribution and subscriptions through Google Play once the App is offered there, under Google’s terms.
- Other users, only through the shared catalogue. If you submit a product to the shared catalogue, the reviewed product identification details and label photos become visible to other users. Nothing else you record is ever shown to anyone.
- People you choose. If you use the app’s share feature, you decide what is included and where it goes through the iOS share sheet. Nothing is shared automatically.
- Parties to a business transaction. A buyer, merger partner, investor or their professional advisers, before or during a reorganisation, financing, sale or transfer of the business, subject to this policy.
- Legal, regulatory and safety recipients. Courts, regulators, law-enforcement or other authorities when we are required to by law, or when disclosure is necessary to protect the rights, property or safety of AllTaken, its users or others, to investigate fraud or violations of our Terms, or to establish, exercise or defend legal claims.
We do not sell your information, and we do not disclose it to advertisers, advertising networks, analytics companies, research partners or data brokers. There are no advertising or third-party tracking tools in the app or on this website.
6. Managing your preferences
- AI features and usage analytics are off unless you tick them when you set up the App or turn them on in Profile › Data & Privacy, and you can turn either off there at any time.
- Apple Health, camera, photo library and notifications are managed in iPhone Settings; you can change or revoke each permission at any time.
- Your records. Review and edit any routine, dose, log or note in the app; corrections never rewrite your past logs. Keep products private, or choose to submit one to the shared catalogue.
- Emails. We do not send marketing or promotional emails. The only emails we initiate are administrative notices about your account, replies to your messages, and, if you joined the beta waitlist, messages about beta testing. To leave the waitlist, email [email protected] from the address you signed up with; we then delete your entry.
- Cookies and advertising. There is nothing to manage: the website sets no cookies, and neither the app nor the website shows advertising or tracks you across other sites or apps.
- Deleting your account. See section 10.
7. International transfers
We are based in the United States. Your account and synced records are currently hosted in the European Union (Ireland). Requests to the third-party AI service, and the safety checks on questions, are processed in the United States, and the backup AI provider may process them in other countries where it operates. The website and waitlist are served through a global content delivery network, and our other providers operate in the countries where they are based, so your information may be processed in countries other than the one where you live, whose laws may differ from those of your country and may allow authorities there to access information in certain circumstances. When personal information from the European Economic Area, Switzerland or the United Kingdom is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum and the Swiss amendments where they apply, in our data processing agreements with the providers concerned. You can ask for a copy of the relevant safeguards by emailing [email protected].
8. User content and the shared catalogue
AllTaken has no public profiles, forums, comments or community feeds. The only content that can become visible to other users is a product you deliberately submit to the shared catalogue: its identification details and the label photos you submit, after review. Do not submit a product if you do not want that information to be visible to other users. Your routine, doses, logs, wellness entries and questions are never part of a submission and are never shown to anyone else. The Terms of Use describe the permission you give us for catalogue submissions.
9. How we protect your information
We use technical, organisational and administrative safeguards designed to protect personal information against loss, misuse, unauthorised access, disclosure, alteration and destruction, including:
- encrypted connections between the app, the website and our servers;
- records synced to your account are protected on our servers so that only your account can read them;
- passwords are handled by our authentication provider and are never visible to us;
- the waitlist form is protected by an automated bot check, and request counts are kept as salted hashes rather than network addresses;
- our server functions log outcome codes, not the content of requests, so email addresses and records do not appear in logs.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If you believe your account has been accessed without your permission, contact us at once.
10. How we retain your information
We keep personal information for as long as it is needed for the purposes described in this policy, including to meet legal, accounting or reporting requirements, and then delete or anonymise it. In deciding how long to keep information we consider its amount, nature and sensitivity, the potential harm of unauthorised use or disclosure, the purposes for which we process it, whether those purposes can be achieved another way, and the applicable legal requirements.
- Your account and records (profile, routines, logs, wellness entries, Apple Health daily values, invitation records, usage events and the records of your AI requests): kept for as long as you keep your account, then deleted with it as described below. Turning usage analytics off stops new events; events already recorded stay with your account until you delete it.
- Onboarding answers: kept only on your iPhone, until you delete your account or remove the App.
- Label and shelf photos sent for scanning: analysed to produce the result and not kept on our servers. Photos you choose to submit to the shared catalogue are the exception (section 8).
- AI chats: not kept on our servers as conversations. A copy of each final answer is kept for ten minutes so that a dropped connection does not produce a second answer, and is deleted in the next daily clean-up. For each AI request we keep a record of the feature used, its time, size and cost, the kinds of data looked up, any safety flags and a fingerprint of the answer, never the question or the answer itself; these records stay with your account until you delete it.
- Request-limit counters tied to your account: deleted one day after their time window starts.
- Account deletion records: when you ask us to delete your account, we keep a record of the request (your account’s random identifier, its dates and whether it was completed or cancelled) for 90 days after it is completed or cancelled, so that we can answer questions about it. If the account had an App Store subscription, we keep a one-way fingerprint of the purchase’s transaction identifier, with nothing that links it to you or your account, so that the same subscription can be used with a new account.
- AI usage totals: daily totals of AI requests and cost for each feature, used to enforce spending limits. They contain no account information and are not personal information.
- Support emails: kept for 2 years after your question is resolved, then deleted.
- Privacy requests: a record of each request and how we answered it (its date, type and outcome) is kept for 24 months, as California law requires; the rest of the correspondence follows the support rule above.
- Beta waitlist signups: kept until the beta ends or you ask to leave the waitlist, and deleted within 30 days after that.
- Server backups: data you delete can remain in our database host’s daily backups for up to 7 days, until they are overwritten. Backups are used only to restore the service after a failure.
- Hosting and security logs: kept by our providers for up to 7 days, unless we need them longer to investigate a specific security incident.
In the App, Profile › Delete my account and data schedules the deletion of your account. When you confirm, the App signs you out straight away, removes everything stored on that iPhone and cancels its reminders. Our server deletes your account and all the data held in it, including usage events, AI request records and any catalogue submissions, once 72 hours have passed. If you sign in again before then, on any device, the deletion is cancelled and your account and data are kept; after the 72 hours, signing in can no longer cancel it. If the request cannot reach our server, nothing is deleted and you stay signed in so you can try again. If changes on your iPhone have not yet reached your account, the App tells you first, so you can wait for them to sync or continue without them. Deleting your account does not cancel an App Store subscription; manage that in your Apple account.
11. Contact us
For questions, complaints or requests about this policy or our privacy practices, including requests under Washington’s My Health My Data Act, email [email protected]. For help using the App, email [email protected].
You can also write to us at: AllTaken, Inc., Attn: Privacy/Legal, 2810 North Church Street, Wilmington, DE 19802, United States.
If you are in the European Economic Area, Switzerland or the United Kingdom, you can also contact our representative there, DataRep, as described in section 13.
12. Your privacy rights
Depending on where you live, the law may give you rights over your personal information. Subject to the conditions and exceptions in the law that applies to you, these may include:
- Access and portability. To confirm whether we process your information, to learn the categories of recipients, and to receive a copy in a portable, commonly used format where technically feasible.
- Deletion. To have your information deleted; you can do this yourself in the app at any time (section 10).
- Correction. To have inaccurate information corrected; most records can be edited directly in the app.
- Limiting or objecting to processing. To withdraw consent, object to or restrict certain processing, or opt out of sales, sharing for advertising, targeted advertising and profiling. We do none of the latter; AI features, usage analytics and Apple Health access are each consent-based and can be turned off at any time.
- Non-discrimination. We will not treat you differently for exercising your rights.
- Appeal. If we decline a request, you can ask us to review the decision by emailing [email protected] with “APPEAL” in the subject line and a reference to the decision. Where the law provides for it, you may also complain to a supervisory authority.
How to exercise your rights
Email [email protected] and tell us which right you are exercising. We may need information sufficient to verify your identity before acting, and we will respond within the time required by applicable law. Where the law allows, an authorised agent may submit a request on your behalf; we will verify the agent’s identity and authorisation. We do not charge for reasonable requests. Many of these requests you can also handle yourself in the App: Profile › Data & Privacy › Download my data gives you a copy of your account, most records can be edited directly, and Profile › Delete my account and data deletes it.
13. Additional information for certain jurisdictions
AllTaken launches first in the United States, followed by Canada and the European Union. The subsections below apply where the relevant law covers you.
United States: California
If you are a California resident, the categories of personal information we may collect, described in section 3, correspond to: identifiers (such as email address, account and device identifiers and IP address); commercial information (store subscription status and transaction identifiers); internet or network activity (usage events, only if you turn analytics on, and technical logs); audio, electronic or visual information (label and shelf photos you scan); inferences (insights and summaries computed on your iPhone from your own records); and sensitive personal information, including health information (your supplements, medications, wellness entries and Apple Health values). Sources, purposes and recipients are described in sections 3 to 5, and how long we keep each category is described in section 10. In the past 12 months we have disclosed identifiers, commercial information, internet or network activity, audio, electronic or visual information and sensitive personal information to service providers for business purposes (hosting your account, processing scans and questions you send to AI features, and serving the website), and to Apple for App Store purchases and sign-in. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We use sensitive personal information only to provide the features you request, so there is no further use to limit. You may have the rights to know, delete, correct, limit the use of sensitive information and be free from discrimination, and to request information about disclosures for direct marketing (we make none). To exercise them, email [email protected].
United States: Washington and Nevada
Washington’s My Health My Data Act and Nevada’s consumer health data law require specific disclosures about consumer health data. They are provided in our separate Washington Health Data Privacy Policy, which also covers Nevada.
Other US states
If you live in another state with a consumer privacy law, such as Colorado, Connecticut, Oregon, Texas or Virginia, you have the rights in section 12 to the extent that law provides them, including the right to appeal a decision. Several of these laws treat health information as sensitive data that may be processed only with your consent, which we ask for before you use the App’s health features. If we decline your appeal, you may contact your state’s attorney general.
European Economic Area, Switzerland and United Kingdom
Where these laws apply, the controller of your personal information is AllTaken, Inc., identified in section 1, which you can contact as set out in section 11. We have not appointed a data protection officer; privacy questions go to [email protected].
Our representative. We have appointed DataRep as our data protection representative in the European Union, the United Kingdom and Switzerland, so that you can contact it in your own country. You can reach it by email at [email protected], through its web form at datarep.com/data-request, or by post at a DataRep address in your country (email us for the address).
In addition to the rights in section 12, you may have the right to object to processing based on legitimate interests, to request restriction, to receive your information in a machine-readable format where processing is based on consent or contract, and to withdraw consent at any time without affecting earlier processing. AllTaken makes no decisions about you based solely on automated processing that produce legal or similarly significant effects. Retention follows section 10; transfers outside these territories follow section 7.
You also have the right to complain to a data protection authority: in the EU, the authority where you live, work or where the alleged infringement occurred (list of EU authorities); in Switzerland, the Federal Data Protection and Information Commissioner; in the United Kingdom, the Information Commissioner’s Office. We would appreciate the chance to resolve your concern first.
The table below sets out the lawful basis we rely on for each processing activity.
| Activity | Lawful basis |
|---|---|
| Providing the app, your account and sync | Performance of a contract; explicit consent for health information |
| Apple Health import | Explicit consent, given through the Health permission |
| Scanning and AI features | Explicit consent, given by turning AI features on |
| Usage analytics | Consent, given by turning analytics on |
| Support and administrative communications | Performance of a contract; legitimate interests |
| Beta waitlist | Consent, given when joining |
| Security, abuse prevention and enforcing the Terms | Legitimate interests |
| Legal compliance and responding to authorities | Legal obligation |
| Business records and business transactions | Legitimate interests |
Canada
Where Canadian privacy law applies, we collect, use and disclose personal information with your consent, express or implied, unless the law permits otherwise. You are not obliged to provide personal information, but some features cannot work without it. You may request access to, and correction of, the personal information we hold about you, and you may complain to the relevant privacy commissioner if a concern is not resolved. Quebec residents may additionally request their information in a structured, commonly used technological format, or ask that it be transferred to another organisation, and may ask us to stop disseminating information or de-index a link where the law provides for it. Requests go to [email protected].
Changes to this policy
We may update this policy as the service or its practices change, for example when we add a feature or launch on another platform. The policy will always show the date it was last updated and list the changes in section 2. If a change is material, we will tell you in the App or by email before it takes effect, and where the law requires your consent, for example before using health information for a new purpose, we will ask for it.