RESERVE

Privacy Policy

Your data lives on your phone.

What we collect

Reserve runs entirely on your device. The app does not have a server, an account system, or analytics. We do not collect your name, email, body weight, food logs, activity history, or anything else.

If you connect Apple Health, Reserve reads your weight and active-energy samples directly from HealthKit on this device. We do not transmit them anywhere. They do become part of your log, though — and your log is mirrored to your own private iCloud when iCloud is on, exactly as described under “What we store”. So an Apple Health reading can leave this phone, and when it does, your iCloud is the only place it goes.

What we store

Reserve stores your profile, weight history, food log, and activity log in the operating system's standard local storage (UserDefaults) on this device only.

If iCloud Key-Value Storage is enabled and you are signed in to iCloud on the device, Reserve mirrors your weight log and activity log to your private iCloud container so you can move between iPhone and iPad. This data is encrypted by Apple in transit and at rest, and only your Apple ID can access it. We cannot.

What we share

We do not sell, license, or trade your data. There is no advertising network, no analytics, no “trusted partners” list, and no server of ours for anything to be sent to.

Two outside services do receive something, and both are named here rather than buried: Sentry, which receives crash reports, and Open Food Facts, which receives a barcode number or the words you type when you search its online food database. Each is described in its own section below. Nothing else about you goes anywhere.

Food search & barcodes

Reserve carries its own food database inside the app — about 38,000 foods and 30,000 barcodes — and it is checked first, offline, every time. Most lookups never touch the network at all.

When a scanned barcode is not in that database, or when you open the online search and type into it, that barcode number or that search text is sent to Open Food Facts, an open food database, to look the product up. That is the whole of what is sent: a barcode, or the words you typed. Not your weight, not your log, not your name, not an identifier for you or your device. Reserve has no account there and cannot be linked back to you.

You can avoid it entirely: decline the online search, and enter the food by hand instead.

Talking to Reserve

On iPhones with Apple Intelligence, you can write or dictate a sentence like “two eggs and a coffee” and Reserve turns it into log entries. The sentence is read by Apple's on-device language model, which runs on your iPhone. We never see it, Apple's servers never see it, and it is never written to storage or added to your log. Reserve holds it only while that screen is open.

The model's only job is splitting your sentence into foods and amounts. It never produces a calorie or a macro — every number comes from the food database inside the app. On every other iPhone, the quick parser Reserve has always used does the same job, unchanged.

Reserve has no speech recognition of its own. When you dictate, you are using the iPhone keyboard's microphone key, and whether that audio is processed on your device or by Apple is an Apple setting (iOS Settings → General → Keyboard → Enable Dictation).

Diagnostics

Reserve uses Sentry to receive anonymous crash reports so we can fix bugs. A crash report contains technical details about the failure (device model, OS version, and the code path that crashed). It does not include your name, your health data, your food logs, or anything that identifies you.

HealthKit

HealthKit access is opt-in. You can grant or revoke specific permissions at any time in iOS Settings → Privacy & Security → Health → Reserve.

When you log food or exercise in Reserve, we mirror those entries back to Apple Health (if you've granted write permission) so the rest of your health ecosystem stays consistent. This write-back is local to your device โ€” Apple Health is your data, not ours. Health data is never used for advertising and is never sold.

Notifications

Local notifications (fasting milestones, daily check-ins, goal-reached) are scheduled on your device using Apple's standard notification system. They are not push notifications from a server โ€” Reserve has no server. You can disable them in Profile → Preferences → Notifications, or in iOS Settings → Notifications → Reserve.

Resetting your data

Profile → Preferences → Reset All Data wipes the locally-stored snapshot, the activity log, the nutrition log, and the iCloud mirror (if enabled). Your profile details (name, birth date, weight, goal) are preserved unless you also reset them manually.

Deleting the Reserve app from your device removes everything else, including the profile.

Contact

For privacy questions or data requests, email briankq@icloud.com.

Last updated: August 2026