Privacy Policy — Burnie

Last updated: August 23, 2026

Burnie ("we", "our", or "us") is a calorie-deficit weight-loss application built for Indian users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Burnie.


1. Information We Collect

1.1 Information You Provide

  • Mobile number — used for OTP-based login and account identification.
  • Email address — optional; used for email+password login if you choose to set one.
  • Profile data — display name, sex, birth date, height, weight goals, monthly loss goals. Used exclusively for BMR calculation and weight-loss projections.
  • Food log entries — what you ate, quantities, timestamps. Used to calculate your daily calorie deficit.
  • Weight entries — your weigh-in readings. Used to track progress and generate projections.
  • Academy comments — comments you choose to post are public to other signed-in Burnie members. You can report a comment, block its author, and delete your own comments.
  • 1.2 Health Data (Optional)

    If you opt in, Burnie reads the following from Apple Health on iOS or Health Connect on Android:

  • Active energy burned
  • Resting energy / basal metabolic rate
  • Exercise sessions and their calories
  • Step count
  • Body weight records
  • We never read or access: heart rate, sleep data, blood pressure, location, contacts, or any other health metric. Only the five categories listed above. Health access is read-only, optional, and controlled through Apple Health or Health Connect.

    1.3 Automatically Collected Data

  • Device token — for authentication.
  • Push notification token (FCM) — if you turn on notifications, a Firebase Cloud Messaging registration token for your device is stored so we can deliver them. See Section 1.4.
  • App version and platform — for debugging.
  • Email notification preference — if you explicitly enable email notifications, we use your verified email address to send only the notification categories you selected.
  • We do NOT use advertising identifiers, third-party analytics SDKs, or tracking cookies.

    1.4 AI-assisted Features (Optional)

    When you deliberately use an AI-assisted feature — such as estimating food from text or a photo, parsing a day of meals, or asking the coach — Burnie asks for permission before the first use. The text or image you submit and the minimum context required to answer may be sent securely to the configured provider for that request: Google Gemini, DeepSeek, or Z.ai. Photos are processed for the requested estimate and are not stored by Burnie's server. AI features are optional, their results can be corrected, and this information is not used for advertising. Burnie does not share Apple Health or Health Connect records with an AI provider. Food items you confirm from an AI or barcode estimate are saved to your private food library; they are not published to the community database.

    1.5 Push Notifications (Optional)

    If you enable notifications, Burnie sends push notifications — such as meal-time reminders, "you forgot to log" nudges, and streak or achievement updates — using Firebase Cloud Messaging (FCM), a service provided by Google. To deliver them, your device's FCM registration token is shared with Google solely to route the notification to your device; the message content is created by us, and Google acts only as the delivery channel. These are functional reminders about your own activity — we do not send marketing or promotional notifications. You can choose the type and channel of each notification (push, email, or in-app), or turn them off entirely, from the app's notification settings or your device's system settings. Your push token is deleted when you delete your account.


    2. How We Use Your Information

    PurposeData Used
    Create and authenticate your accountMobile number, device token
    Calculate BMR (resting calorie burn)Sex, birth date, height, weight
    Compute daily calorie deficitFood entries, active calories (from phone or manual)
    Generate weekly/monthly weight-loss projectionsAll profile + food + weight data
    Show streak and on-track statusFood entries, deficit calculations
    Sync phone health data (optional)Resting energy, active energy, workouts, steps and weight from Apple Health or Health Connect
    Respond to an AI-assisted request you start (optional)The food text/photo or coach message you submit and minimum relevant context
    Display an Academy comment you choose to publishComment text, display name and moderation state
    Send the push notifications you've enabled (reminders, streaks, achievements)FCM registration token
    Send email notifications you explicitly enableVerified email address and selected notification category
    Respond to support or grievance requestsContact details you provide

    3. Data Storage & Security

  • All data is stored on servers located in India.
  • Data is encrypted in transit (HTTPS) and at rest.
  • Authentication tokens are managed via Laravel Sanctum with automatic expiry.
  • We do not sell or rent your personal data. Service providers receive only the data required for the feature you choose: Google Firebase Cloud Messaging for enabled push delivery, the configured email delivery provider for enabled email delivery, and the configured AI service provider when you deliberately use an AI-assisted feature after consent.

  • 4. Your Rights Under the DPDP Act, 2023

    As an Indian user, you have the right to:

  • Access — request a copy of all your data (use the Export button in Settings).
  • Correct — update your profile, weight, or food entries at any time.
  • Erase — delete your account and associated data permanently in Settings, or request deletion at /delete-account if you cannot access the app.
  • Grievance — contact our Grievance Officer (see Grievance Officer section).
  • Nominate — designate a nominee to exercise your rights in case of incapacity.

  • 5. Data Retention

  • Active accounts: data retained indefinitely while you use the app.
  • Deleted accounts: the in-app flow deletes account data immediately. Verified external requests are completed within 30 days unless a legal obligation requires limited retention.
  • OTP records: deleted within 15 minutes of verification.
  • Push notification token: kept while notifications are enabled; deleted when you delete your account.
  • Apple Health / Health Connect data: re-read from the phone on each sync. We do not copy raw health records to our server. Burnie stores daily resting- and active-calorie summary values used for your deficit calculation. Step totals remain on the device. A phone weight reading is stored only after you confirm that you want to use it.

  • 6. Children's Privacy

    Burnie is intended only for adults aged 18 or older. We do not knowingly collect personal data from children.


    7. Changes to This Policy

    We will notify you of material changes via the app. Continued use after changes constitutes acceptance.


    Contact: See the Grievance Officer section for contact details.