Piply · Last updated: May 26, 2026
Piply is operated by Karahan Labs ("we", "our", or "us"). This policy explains what data we collect, how we use it, where it's stored, and your rights regarding your personal information.
Piply requires an account to use AI features and to keep your subscription attached across devices. You can sign in two ways:
Email and password — we store your email address and a one-way bcrypt hash of your password, never the password itself. We send transactional emails (verification, password reset) from [email protected].
Sign in with Apple — we receive an opaque identifier from Apple plus the email address you choose to share (which may be a private relay address). We never see your Apple ID password.
Account data (stored on our server):
Profile data (stored on your device):
Activity data (stored on your device):
Sent to AI when you analyse content:
Collected automatically:
Anthropic (Claude AI) — Processes food and product images in real time. Images are not retained after processing.
RevenueCat — Manages premium subscriptions and validates Apple App Store / Google Play purchases. We use your RevenueCat user identifier to attach your subscription to your account.
Resend — Sends transactional emails (verification, password reset) on our behalf. Emails are not used for marketing.
Railway — Hosts our backend server and PostgreSQL database in the US region.
PostHog — Anonymised usage analytics (feature use, screen views). No personally identifiable information is sent.
Sentry — Crash reports and error logs to help us fix bugs.
USDA FoodData Central — Public food nutrition database. No personal data is sent to USDA.
On our server — account data is stored in a PostgreSQL database hosted by Railway. Passwords are hashed with bcrypt. All requests use HTTPS. Authentication uses short-lived JWT access tokens and rotating refresh tokens.
On your device — profile, meal history, settings, history lists and your session refresh token are stored locally using AsyncStorage and SecureStore.
We do not sell or share your personal data with advertisers.
Under GDPR, CCPA, and similar regulations, you have the right to:
Use Settings → Delete Account, or contact us at [email protected].
Delete Account — Settings → Data Management → Delete Account
This permanently removes your server account (email, password hash, Apple identifier, subscription history, monthly usage records) and all local data (profile, meal history, settings). The action cannot be undone.
For any server-side data not covered (analytics events, crash reports), email [email protected] with the subject "Data Deletion Request".
Piply is not directed to children under 13. We do not knowingly collect personal information from children under 13.
We may update this policy from time to time. The "Last updated" date above reflects the most recent revision.