Mama Bot Privacy Policy

Effective date: October 8, 2026

This Privacy Policy explains what information the Mama Bot mobile app collects, how we use and share it, and the choices you have. On your phone and inside the app, Mama Bot appears as "MamaBot", which is also the name of its built-in AI helper. This policy covers the whole app, including MamaBot chat, on iPhone, iPad and Android.

Mama Bot is made by Bar-All, Inc ("Bar-All", "we", "us") for the Trim Healthy Mama community. Bar-All is responsible for the app and for your information as described here.

The short version

  • We use your information to run Mama Bot for you: your plan, your logs, your Journal, MamaBot chat and your subscription.
  • No ads, no advertising ID and no marketing trackers. We don't sell your information, and we never use your health information for advertising.
  • Your Journal is invite-only. Friends and a coach you link see only what your sharing settings allow. Logged meals are shared with them by default, and you can change that at any time.
  • Meal photos you choose to analyze and the questions you ask MamaBot are processed by an AI provider through our servers.
  • Progress photos stay on your phone. They're never uploaded to our servers.
  • You can delete your account and data in the app at any time.

Information we collect

We collect information you give us, information created as you use the app, and some technical information from your device.

Account information

  • Email address and password. You sign up with an email address and a password. Your password is stored only in scrambled (hashed) form by our hosting provider's sign-in service, so we can't see it.
  • Sign in with Apple. On iPhone and iPad you can sign in with Apple instead. Apple shares your email address (or a private relay address, if you choose to hide yours) and an identifier for your Apple account. We don't ask Apple for your name.
  • Account ID. Your account gets a random identifier that links your information together.

Your profile and plan

  • Body and plan details: biological sex, birthdate, height, current weight, goal weight, activity level, goal and pace. We use these to build your personalized plan, such as your protein anchors and gentle ranges, and we store the plan we calculate from them.
  • Your weekly Power plan (which days are strength, cardio or rest), if you set one.
  • Display name and profile photo. Both are optional. Friends and your coach can see them.
  • Invite and coach codes. Your account gets a friend invite code, and coaches get a coach code. A code is shared only when someone chooses to share it.
  • Settings, such as whether calories are shown, celebrations, your Journal sharing choices and notification preferences.

What you log

  • Meals: what you ate and when, nutrition details (such as protein, carbs, fat, fiber, sugar alcohols and calories) and the fuel type.
  • Saved meals, recipes and pantry ingredients, including ingredients, servings, instructions and product barcodes.
  • Weigh-ins, workouts, plant check-ins and achievements.
  • Food searches and barcode scans. When you search for a food or scan a barcode, the words you type or the barcode number are sent to the food databases described in "Who we share information with".

Photos

  • Meal photos. If you use AI Food Scan, you take or choose a photo of your meal and can add an optional note about it. The photo and note are sent through our servers for an AI nutrition estimate. The photo is saved with that meal, and a copy is saved with the meal's Journal post.
  • Profile photo, if you add one.
  • Progress photos stay on your phone and are never uploaded to our servers. See "Information that stays on your phone".
  • Hidden photo details. Photo files can carry details saved by your camera, such as where and when the photo was taken. Before any photo you take or pick in the app is saved, uploaded or sent for AI analysis, the app removes its location (GPS) and other identifying details, such as camera details and the time it was taken. It keeps only the photo's orientation, so the photo shows the right way up. This works for JPEG and PNG photos, which is what the app almost always receives. In rare cases a photo can arrive in another format, such as HEIC, AVIF or WebP, that the app can't clean yet. If that photo carries these details, it's used as it is, and the app lets us know through our error reports so we can fix it.
  • The app only gets the photos you take or pick. It doesn't ask for access to your whole photo library.

Your Journal, friends and coach

  • Journal posts: Thoughts/Wins and prayer requests you write, and posts the app adds for you when you log a meal, a workout or a weigh-in, or unlock an achievement. Each post has a time, and meals logged with AI Food Scan include the photo.
  • Reactions: likes and "praying for you" reactions, and the notifications they create, which include the name of the person who reacted.
  • Connections: friend requests and friendships, your link to a coach if you add one, and people you block, with each person's display name as it was when you blocked them and the date. See "If you block someone".
  • Prayer requests and prayer reactions may reveal your religious beliefs. Sharing them is entirely up to you.

Chats with MamaBot

Your questions and MamaBot's answers are saved to your account so you can come back to a conversation. For each MamaBot request we also keep a short record (the time, whether it worked and its size) to keep the service running and to limit misuse.

Reports

If you report a post, a person or a MamaBot answer, we collect your reason, any note you add and a copy of what you reported. See "Reports and moderation".

Your agreement to our Terms

When you tap "Agree and Continue" on the Community Terms screen, we record which version of our Terms of Use you accepted, when our servers received your agreement, and the time your phone reported for your tap. The app also saves a small note on your phone so it doesn't ask again there. We keep this as a record of your consent. The app asks every account once, and asks again when we publish a new version of the Terms.

Subscriptions

Purchases are made through the Apple App Store or Google Play, and we never see your card or bank details. Our subscription provider, RevenueCat, tells us your subscription status, such as your plan, whether you're in a free trial and when it renews or ends.

Notifications

If you turn on push notifications, we store a push token for your device so we can send you notifications, such as when a friend likes your post or prays for you.

Device and technical information

  • Crash and error reports. When something goes wrong, the app sends a report to our crash-reporting provider, Sentry. A report includes the error, your device model, operating system and app version, the screens you visited and the network requests made just before the problem (these can include food search words), and your account ID, but not your name or email. For some sessions it also includes performance timings.
  • Server logs. Like most online services, our servers record technical details of requests, such as IP address, device and app information, and sign-in events.
  • App updates. The app checks for updates with our update provider, Shorebird. The check includes the app version, your device's platform and a random install identifier.

If you're a coach

We receive your email address from the Trim Healthy Mama coach roster so your account gets coach access. You can add an optional bio and an optional contact email and phone number for your clients.

What we don't collect

Mama Bot doesn't ask for your location, contacts or microphone, or for access to your whole photo library. It doesn't connect to Apple Health, Health Connect or Google Fit, and it doesn't use an advertising ID. We don't ask for your real name, your postal address or, unless you're a coach who chooses to add one, your phone number.

How we use your information

  • To create and secure your account and keep you signed in.
  • To build your personalized plan and show your meals, fuels, Three P's, progress and achievements.
  • To estimate nutrition from meal photos and recipes, look up foods, and answer your questions in MamaBot chat.
  • To run the Journal: showing your posts to the friends and coach you choose, and delivering reactions and notifications.
  • To provide and check your subscription, including free access for approved coaches.
  • To keep the community safe: reviewing reports, keeping your blocks in place, enforcing our Terms of Use and Community Guidelines, keeping a record that you accepted them, and preventing misuse, such as by limiting how many MamaBot requests can be made in an hour.
  • To find and fix bugs and keep the app working well.
  • To send account emails, such as password resets, and to reply when you contact us.
  • To comply with the law and respond to lawful requests.

We don't use your information for advertising, and we don't build marketing profiles about you.

AI features

Two parts of Mama Bot use artificial intelligence:

  • AI Food Scan sends your meal photo and any note you add to an AI model, which returns an estimate of the foods and their nutrition. When you add a recipe from MamaBot chat to My Meals, the recipe's title and ingredients may be sent the same way for a nutrition estimate.
  • MamaBot chat sends your question, along with the last few messages of the conversation for context, to an AI model that writes MamaBot's answer.

These requests go from the app to our servers, and our servers send them to OpenRouter, a service that routes requests to AI model providers (currently, providers that run the Qwen family of models). The app itself holds no AI keys and never contacts an AI provider directly. We don't include your name, email address or account ID with these requests, but the photo, note or message is sent as you provide it, so please leave out personal details you don't want processed. OpenRouter and the model providers process this content to return a response, and they handle it under their own terms and privacy policies, which may allow them to keep it for a period of time.

Some smaller AI steps, such as matching your question to the right reference passages, run on our own servers and aren't sent to another company.

AI results are estimates and can be wrong. Every AI nutrition estimate stays editable, and MamaBot can make mistakes. See our Terms of Use.

What other people in the app can see

Mama Bot has no public profiles, public feed, user search, comments or direct messages. Other people can see your information only in the ways described below.

Friends

You become friends by sharing your invite and accepting each other. Accepted friends can see:

  • your display name and profile photo;
  • Journal posts you share with friends, including any photo on them, and the reactions on those posts.

By default, meals and prayer requests are shared with friends. Thoughts/Wins, workouts, weigh-ins and achievements are private ("Just You") unless you choose to share them, and each time you log a weigh-in you decide whether to share it. When you react to a post, people who can see that post may see your reaction.

Someone you've sent a friend request to, or who has sent you one, can see your display name. Anyone you give your invite to can see your display name when they enter it, unless you've blocked them.

Your coach

If you link a coach by entering their coach code, your coach can see your display name and profile photo, plus whatever your choices under "What Your Coach Can See" in Journal Settings allow:

  • Meals (on by default): your logged meals, including food names, times and nutrition details such as calories, and your meal Journal posts with any photo.
  • Prayer requests (on by default).
  • Thoughts/Wins, workouts and achievements (off by default).
  • Weight Journey (off by default): when it's on, your coach can see your weigh-in history, including past weigh-ins.

Your coach can't see your body and plan details (such as your birthdate, height or goal weight), your email address, your MamaBot chats, your saved meals and recipes, or your progress photos.

If you're a coach, anyone who enters your coach code, except people you've blocked, can see your name, photo and bio, and your linked clients can see the contact email and phone number you add.

If you block someone

You can block a friend, someone who sent you a friend request, your coach or, if you're a coach, a client. Blocking:

  • ends your friendship, any friend request between you and any coaching link between you, so you stop seeing each other's posts;
  • removes their likes and "praying for you" reactions from your posts, and their notifications from your inbox;
  • stops either of you from sending a friend request, reacting to the other's posts, or linking as coach and client, for as long as the block is in place.

We don't tell them you blocked them. Reactions you left on their posts, and your name in notifications they already received, stay as they are, just as after an unfriend. We keep your list of blocked people, with each person's display name as it was when you blocked them and the date. Only you can see that list in the app, in Journal Settings → Blocked People, and our team may look at blocks when reviewing reports. Unblocking removes the block but restores nothing: your friendship, coaching link and their removed reactions don't come back, and you'd connect again from the start. A block is deleted when you unblock the person or when either of you deletes your account.

Your controls

  • Choose what friends and your coach see in Journal Settings (from the Journal tab). Turning a type off also hides posts of that type you've already shared.
  • Change who can see a single post, or remove it, from that post's menu.
  • Unfriend someone (Journal → Friends) or end a coaching link at any time.
  • Report a post, a person or a MamaBot answer, and block or unblock someone, as described in our Community Guidelines.

Reports and moderation

You can report a Journal post, a person or a MamaBot answer.

  • A post. Anyone who can see a Journal post can report it. A report records who reported it and whose post it is (with both display names), the reason, any note, whether you chose to hide the post just for you, and a copy of the post as it was when reported: its type, text, time and a reference to any photo.
  • A person. You can report a friend, someone who sent you a friend request, your coach, a client if you're a coach, or someone you've blocked. A report records who made it and who it's about (with both display names as they were at the time), how you're connected, the reason, any note, and a reference to (not a copy of) their profile photo at the time.
  • A MamaBot answer. A report keeps a copy of the answer and of the question you asked just before it, your reason, any note, and references to that conversation. Because these are copies, the report is kept even if you later delete the conversation. It includes only that question and answer, not the rest of the conversation, and it names no one but you. Reporting doesn't change or remove the answer in your chat history.

We never tell the person you report, or whose post you report, who reported them, and they can't see the report. Reporting someone doesn't block them, and blocking someone doesn't report them. Our team reviews reports to enforce our Community Guidelines and may remove content or accounts. Reports about MamaBot answers help us correct MamaBot's mistakes. We keep reports, including their copies, so they can be reviewed, as described in "How long we keep information".

Who we share information with

We share information only as this policy describes. We use these service providers to run Mama Bot, and they process information on our behalf to provide their services to us:

  • Supabase hosts our database, sign-in, file storage and server functions, and sends account emails. Our servers are in the United States.
  • OpenRouter and the AI model providers it routes to handle AI Food Scan, recipe estimates and MamaBot chat, as described in "AI features".
  • Google Firebase Cloud Messaging and the Apple Push Notification service deliver push notifications. We use Firebase only for notifications, with Firebase Analytics turned off. Notification text, which includes the name of the friend who reacted, passes through these services.
  • RevenueCat manages subscriptions. It receives your account ID and your purchase history from Apple or Google, but not your name or email.
  • Apple and Google process payments and manage subscriptions under their own terms through the App Store and Google Play. Apple also provides Sign in with Apple.
  • Sentry receives crash and error reports.
  • Shorebird delivers app updates.

The app also looks up foods in two public food databases:

  • Open Food Facts. When you search packaged foods or scan a barcode, your phone sends your search words or the barcode number directly to Open Food Facts, a nonprofit open food database. Like any website, it also sees your device's IP address. We don't send it your name, email or account ID.
  • USDA FoodData Central. Generic food searches go through our servers to the U.S. Department of Agriculture's food database. Only the search words are sent, with nothing that identifies you.

We may also share information:

  • With people you choose, as described in "What other people in the app can see", and when you use your phone's share sheet to send something, like your invite or a recipe, outside the app.
  • For legal and safety reasons, when we believe in good faith that the law or legal process requires it, or that it's needed to protect the safety, rights or property of our users, the public or Bar-All. For example, we report content that exploits children to the authorities.
  • In a business transfer, such as a merger, acquisition or sale of assets. This policy will continue to apply to your information unless you're told otherwise.

No selling, no ads, no tracking

We don't sell your personal information, and we don't share it for targeted advertising. We never use your health information, such as your weight, body details, meals or photos, for advertising or marketing. Mama Bot has no ads and no advertising ID. It includes no advertising or marketing tools, and no analytics tools beyond the crash reporting described above. It doesn't track you across other companies' apps or websites.

Information that stays on your phone

  • Progress photos, and the optional weight saved with them, are stored only on your phone. They're never uploaded to our servers, and no one else can see them in the app.
  • A working copy of your data. To work quickly and offline, the app keeps a copy of your own information on your phone. Signing out clears this copy, but progress photos stay on the phone so you don't lose them.
  • Device backups. If backups are turned on for your phone, your phone's own backup service (iCloud on iPhone and iPad, or Google's backup on Android) may include the app's data on your phone, including progress photos. Apple or Google handles those backups under your account and settings, and we can't see them.

How long we keep information

  • Account, profile, logs, Journal posts and chats: until you delete them or delete your account.
  • Meal photos: the photo saved with a meal is deleted automatically after 7 days. The copy saved with the meal's Journal post is kept until you delete your account. That copy is currently kept even if you remove the post or delete the meal, although it's no longer shown to anyone. You can email us to have those photos deleted sooner.
  • Profile photo: until you replace it or delete your account.
  • Reports: a report and its copy of what was reported are kept so our team can review it and keep the community safe, even if the post, name or conversation is later changed or removed. A report about a post or a person is deleted when the account of the person who made it, or of the person it's about, is deleted. A report about a MamaBot answer is deleted when the account of the person who made it is deleted.
  • Blocks: until you unblock the person, or either of you deletes your account.
  • Your agreement to our Terms: kept as a record of your consent, including records for earlier versions you accepted, until you delete your account.
  • Push tokens: until you sign out, turn off notifications or delete your account.
  • Crash reports: up to 90 days.
  • Server logs and backups: a limited time, under our providers' retention settings.
  • Subscription records: RevenueCat keeps a record of your purchases under your random account ID after you delete your account, for purchase and accounting records. Apple and Google keep their own billing records.
  • Coach roster: a coach's email stays on the roster until it's removed. Email us to ask.
  • Food searches: USDA search results are stored on our servers to speed up later searches, with nothing that identifies who searched.

How we protect your information

Information sent between the app, our servers and our service providers is encrypted in transit (HTTPS). Our database enforces access rules so each person can reach only their own information and what others have chosen to share with them. Photos are kept in private storage and shown only through time-limited links. Secret keys, including our AI keys, live only on our servers, never in the app. No system is perfectly secure, so please use a strong password that you don't use anywhere else, and keep your phone's passcode turned on.

Deleting your data and your account

You can delete individual meals, weigh-ins, Journal posts and MamaBot conversations in the app at any time. To delete everything, open the Profile tab, tap "Delete Account" in the Account section, and confirm with "Delete Forever". This permanently deletes your account and the information stored with it on our servers, including photos, your blocks, the reports you've made and the record of your agreement to our Terms, and erases your progress photos from that phone. If you can't use the app, email us from your account's email address. See Delete your account for details, including the few records that may be kept.

Deleting your account doesn't cancel a subscription. Cancel it first in the App Store or Google Play.

Your choices and rights

  • See and update your information. You can view and edit most of your information in the app. To ask for a copy of your information, or for help with anything you can't change yourself, email us.
  • Sharing. Change what friends and your coach see at any time in Journal Settings.
  • Notifications. Turn push notifications on or off with the Push Notifications setting in Profile, or in your phone's settings.
  • Optional features. AI Food Scan, MamaBot chat, friends and coaching are all optional. Without friends or a coach, your Journal is seen only by you.

Depending on where you live, including certain U.S. states, the European Economic Area, the United Kingdom and Switzerland, you may have the right to access, correct, delete or get a copy of your personal information, to object to or limit certain uses of it, and to withdraw your consent. To use any of these rights, email us. We may need to confirm the request comes from you. We won't treat you differently for using your rights, and if we turn down a request, you can ask us to reconsider. You can also contact your local data protection authority.

If you're in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our agreement with you (running the app you signed up for); your consent, including for the health information you choose to enter and for optional features, which you can withdraw at any time by deleting that information, turning the feature off or deleting your account; our legitimate interests in keeping Mama Bot safe, secure and working, such as crash reports and moderation; and meeting our legal obligations.

Children and teens

Mama Bot is designed for adults and isn't directed to children. You must be at least 13 years old to use it. If you're under 18, or under the age of majority where you live, you may use Mama Bot only with a parent's or guardian's permission. We don't knowingly collect personal information from children under 13. If we learn that a child under 13 has created an account, we'll delete it. If you believe a child under 13 is using Mama Bot, please email us.

Where your information is processed

Our servers are in the United States. Our service providers, including AI model providers, may process information in the United States and other countries. If you use Mama Bot from outside the United States, your information will be transferred to and processed in the United States and those countries, whose data protection laws may differ from the laws where you live.

Changes to this policy

We may update this policy as Mama Bot changes. We'll post the new version on this page and update the effective date. If the changes are significant, we'll also let you know in the app or by email.

Contact us

Questions or requests about your privacy? Email Bar-All, Inc at:


Mama Bot is made by Bar-All, Inc for the Trim Healthy Mama community. See also our Terms of Use and account deletion instructions.