Privacy Policy

Downlio Planner for iOS · Last updated 18 August 2026

The short version. Downlio Planner keeps what you write in it on your phone. There is no account, no sign-in, and no copy of your planner on our servers.

Three things do leave your device, and only when you choose to use the feature that sends them: a photo or description of a meal when you ask for a calorie estimate, a barcode when you scan one, and your subscription status, which is handled by Apple. Nothing else is transmitted, and nothing is sold, shared or used for advertising.

Who this policy is from

Downlio Planner is an iOS app published by Emmanuel Guerrero. This policy covers the app only. It does not cover any other product that shares part of the name — in particular, it is unrelated to any Shopify application called Downlio, which is a different product from a different company.

What stays on your phone

Almost everything. The following is written to your device's own storage and is never transmitted to us:

This data lives in the app's private storage on your device, inside the app's sandbox. It is included in your iPhone's encrypted backups if you have those switched on, which is between you and Apple — we have no access to it. If you delete the app, this data is deleted with it, so export a copy first if you want to keep it.

What leaves your phone, and when

WhatWhenWhere it goes
A photo of a meal, plus any note you type with it Only when you tap to estimate a meal from a photo Our estimate service, which passes it to an AI provider that returns the calorie and macro estimate
A short text description of a food (up to 120 characters) Only when you ask for an estimate by description instead of a photo The same route as above
A product barcode number Only when you scan a barcode Open Food Facts, a public non-profit food database
A random app-generated identifier Alongside the two estimate requests above Our estimate service, to count requests against the monthly allowance
Your subscription status On launch, and when you subscribe or restore Handled entirely by Apple — see below

About the meal photos

A photo is sent only for the single request you asked for. We do not attach your name, your email, your Apple Account or your location to it, because the app does not hold any of those — there is no account for it to be attached to.

The photo is passed to a third-party AI provider in order to produce the estimate, and is sent for that purpose only. We do not add it to a library, use it to build a profile of you, or associate it with anything else you have entered in the app.

About the random identifier

The identifier is a random value the app generates on your device the first time you use the estimate feature. It is not Apple's advertising identifier, not your device's serial number, and not linked to your name, email or Apple Account. Its only purpose is to count how many estimates have been used so the monthly allowance can be enforced. It cannot be used to identify you, and deleting and reinstalling the app produces a new one.

About barcodes

Scanning a barcode sends the barcode number to Open Food Facts and nothing else — no identifier, no photo, no personal information. Open Food Facts is an independent organisation with its own privacy policy.

About your subscription

Subscriptions are purchased and managed through Apple's App Store. Payment is handled entirely by Apple. We never see, receive or store your card details, your billing address or your Apple Account credentials. The app asks Apple's StoreKit whether an active subscription exists on the device and receives a yes or no. We do not operate our own account system and cannot link a subscription to a person.

What we do not do

Permissions the app asks for

Every one of these can be refused or withdrawn in iOS Settings. Refusing the camera or photo permission disables the photo estimate feature; the rest of the app is unaffected.

How long anything is kept

Data on your device is kept until you delete it or delete the app. We do not hold a copy, so there is nothing for us to retain and nothing for us to delete on your behalf.

For the estimate service, requests are processed and returned; the request count associated with the random identifier is retained for the current billing period so the allowance can be enforced.

Your rights

Because there is no account and we hold no copy of your planner, most rights are exercised directly in the app rather than by asking us:

If you are in the UK, EEA, California or another region with statutory data rights and you want to make a request about the estimate service, contact us at the address below. Because the identifier is random and unlinked to you, we may be unable to locate records tied to a particular person, and we will say so rather than guess.

Children

Downlio Planner is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has used the estimate feature and you want it addressed, contact us.

Security

Requests to the estimate service and to Open Food Facts are sent over HTTPS. Data on your device is protected by iOS's own file protection and by your device passcode or biometric lock. No system is perfect, and an app that keeps your records on your own phone shifts most of that responsibility to keeping your phone locked and up to date.

Changes to this policy

If the app starts doing something materially different with data, this page will be updated and the date at the top will change. Continuing to use the app after a change means the updated policy applies.

Contact

Questions about this policy, or about anything the app does with data: guerrero.emmanuel23@gmail.com