Ore Privacy Policy

Last updated: August 26, 2026

This Privacy Policy describes how 0xdesigner LLC, doing business as Ore ("Ore," "we," "us," or "our"), collects, uses, discloses, and retains personal information through the Ore mobile application, the oreapp.fit website, and Ore support. It is a notice of our data practices and does not create contractual rights or replace the Ore Terms of Use. Ore is operated from the United States and this Policy applies wherever Ore is offered.

Ore is a meal-logging and general-wellness app. We do not sell personal information, use it for targeted advertising, or permit third-party advertising trackers in the app.

For disclosures and rights concerning consumer health data, see the separate Washington Consumer Health Data Privacy Policy and Nevada Consumer Health Data Privacy Policy.

Information we collect

Account information

Ore uses Sign in with Apple. Depending on the choices you make with Apple, we receive an Apple account identifier, your name, and an email address or Apple private-relay address. We use this information to create, authenticate, secure, and support your account and to associate your Ore content with it. Ore does not receive your Apple password.

Meal, nutrition, and plan information

We collect information you submit or create through Ore, including:

Optional Apple Health information

If you choose to connect Apple Health, Ore may read body mass, step count, Active Energy, and workouts from HealthKit. Ore uses available body mass and activity evidence to suggest onboarding answers that you still confirm, show steps in your diary, and calculate a small positive Activity Fuel adjustment on unusually active days. Ore does not write data to HealthKit.

Steps, Active Energy, workouts, and Apple Health source details remain on your device. If an available Health weight seeds the editable weight question, the weight you confirm becomes an ordinary saved program answer. Ore also sends its server the local date, derived Activity Fuel Calories and carbohydrate grams, the calculation version, and calculation/finalization times. The confirmed program answer and derived adjustment are linked to your Ore account so the same program and daily nutrition budget can be shown across your devices. Raw Health samples and the Activity Fuel adjustment are not sent to third-party AI providers. Like a manually entered weight, a weight you confirm may shape saved plan targets; those saved targets may be included in the daily-insight context described below.

You may skip Apple Health and use Ore's manual onboarding answers without losing the core plan or diary. You can change Health access in Apple's Health or Settings app. Because Apple protects read-permission privacy, Ore cannot reliably distinguish a denied Health data type from a type that simply has no available samples.

We use this information to provide the diary, estimates, drafts, saved foods, trends, and planning features you request; personalize those features; maintain your history; prevent abuse; troubleshoot the service; and comply with law.

Microphone and speech information

If you use voice logging, Ore accesses the microphone only while recording. Speech recognition may occur on your device or through Apple's speech-recognition service, depending on the device, operating system, language, availability, and Apple's service behavior. Ore does not deliberately retain raw audio after recognition. The resulting transcript may be processed and retained like other meal text, including in a pending draft and account document history.

You can change microphone and speech-recognition permissions in iOS Settings.

Camera and photo information

If you use photo logging, Ore processes only the photo or photos you take or select for that submission. The app resizes them before transmission. Ore uses the images to identify foods and estimate nutrition. Photos you attach are staged with the pending meal draft and, when you confirm it, stored with the meal entry so Ore can display them in your diary. Ore deletes those stored photos when you delete the meal or your account. Service providers may also temporarily process or retain request data under their applicable API terms, security practices, and legal obligations.

You can change camera and photo-library permissions in iOS Settings.

AI and nutrition processing

Ore uses commercial AI APIs and nutrition-information services for meal analysis and brief daily insights. The initial calorie and macro plan, as well as direct target adjustments, use deterministic software rather than an AI model. Current routing services, configured model families, and service categories are described at oreapp.fit/subprocessors. Providers may change as we change models, routing, infrastructure, or features.

Depending on the feature, Ore may send meal text, a voice transcript, selected photos, and prior draft or logged-meal items when you request a revision. For a daily insight, Ore may send saved calorie and macro targets, the selected goal, dietary restrictions, recent daily macro totals, logging-streak information, and recent insight text. On a day with an Activity Fuel adjustment, Ore omits the changing calorie and carbohydrate targets from daily-insight input. Ore does not send raw Apple Health samples, an Activity Fuel adjustment, sex, age, height, weight, or an optional legacy body-fat estimate to calculate or adjust the initial plan through AI. Ore does not intentionally attach your Ore account name, account email, Apple account identifier, or Apple payment records to AI requests. Content that you choose to type, speak, or photograph may itself contain personal information, and that content will be processed as part of the request.

Ore applies OpenRouter's data_collection: deny routing control to requests made through OpenRouter. OpenRouter describes that setting as excluding inference providers that collect user data. Ore does not use personal information to train a general-purpose AI model of its own. Commercial API terms and provider-side security, abuse-prevention, legal-compliance, or transient technical retention may still apply. A configured model-family name does not necessarily identify the inference provider that receives a dynamically routed request.

Before Ore sends meal or diary information for third-party AI processing, the app asks for permission. If you do not grant permission, you can still create and access an Ore account, complete the deterministic onboarding calculation, and view or adjust your plan targets; AI-powered meal estimates and daily insights remain unavailable until permission is granted. To withdraw permission after granting it, use Settings → Delete Account. Successful account deletion revokes access to Ore and deletes associated account records from Ore's active production database, subject to the limited retention exceptions described under Retention and deletion. Stopping use of Ore prevents new activity but, by itself, does not withdraw permission or delete information already stored in your account.

Diagnostics, usage, and technical information

We collect information needed to secure, operate, and improve Ore, including IP address and request timing for rate limiting; request and account identifiers in server logs; app and OS version; feature or model path; model and token usage; processing time; and success, failure, or repair status.

Apple's MetricKit may provide crash, hang, CPU, or disk-write diagnostics. Ore forwards the diagnostic payload supplied by Apple to our server and does not intentionally add meal text or photos to it. MetricKit payloads may contain technical device, operating-system, application, and stack-trace information.

Structured model-usage records do not include the meal text, transcript, or photo itself. We use technical information for authentication, security, rate limiting, debugging, reliability, capacity planning, cost management, and first-party product analytics—not advertising.

Purchases and subscriptions

Apple processes App Store purchases and payment details. Ore receives verified subscription and transaction information needed to determine access, such as the product and original transaction identifiers, subscription status, expiration or renewal information, environment, and an account-linking token. Ore does not receive your full card number or billing address.

Support communications

If you contact support, we collect your sender address, message, attachments, and any information you choose to include. Support correspondence is processed through Google Workspace and used to respond, investigate issues, maintain appropriate business records, protect the service, and comply with law. Do not send information that is unnecessary for us to address your request.

How we disclose information

We may disclose personal information as reasonably necessary for the purposes described above:

These providers may process information in the United States or other locations. We do not sell personal information or disclose it for targeted advertising.

Retention and deletion

We generally retain account, meal, nutrition, plan, draft, derived Activity Fuel, telemetry, and diagnostic information while your account remains active and as reasonably needed to provide, secure, and support Ore. Apple Health steps, Active Energy, workouts, and source details are queried on-device and are not retained in Ore's hosted database. A Health-seeded weight is retained only after the consumer confirms it as a program answer.

You may request account deletion inside Ore under Settings → Delete Account. Ore authenticates deletion requests, and the in-app process also attempts required Apple credential revocation. When in-app deletion succeeds, Ore deletes the account and associated records from its active production database, including account-linked document history, telemetry, and diagnostics. If the in-app process cannot complete, email support@oreapp.fit with the subject Privacy Request; a failed Apple credential-revocation attempt does not waive a deletion right available under applicable law.

Some information may remain temporarily in restricted backups, security logs, or service-provider systems until overwritten or deleted under applicable retention schedules. We may retain limited information when reasonably necessary to comply with law, resolve disputes, enforce agreements, prevent fraud or abuse, or establish or defend legal claims. Where applicable law requires broader or faster deletion, including deletion instructions to processors or deletion from backups, we follow those requirements. Apple retains its own purchase history independently.

Support correspondence is retained only as reasonably necessary to respond, investigate issues, maintain appropriate business records, prevent abuse, and comply with law.

Deleting the Ore app or your Ore account does not cancel an App Store subscription. Subscriptions must be managed separately through Apple.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including encrypted network connections. No safeguard, system, transmission, or storage method can guarantee absolute security.

Children's privacy

Ore is not directed to children under 13, or the higher minimum age that applies in your country, and we do not knowingly collect personal information from a child under that age. If you believe a child has provided information to Ore, contact us so we can review and address the request.

Your choices and privacy rights

You can:

We may need to authenticate a request. Applicable law may permit or require us to retain certain information or decline a request in limited circumstances. We will not unlawfully discriminate against you for exercising a privacy right.

United States state notices

Washington consumers and people whose consumer health data is collected in Washington should review the separate Washington Consumer Health Data Privacy Policy. Nevada consumers should review the separate Nevada Consumer Health Data Privacy Policy. These notices provide additional disclosures, request methods, and appeal rights.

Connecticut consumers may, subject to applicable law, ask to confirm processing; access, correct, delete, or obtain a portable copy of personal information; and opt out of covered sales, targeted advertising, or profiling. Ore does not sell personal information or use it for targeted advertising. Submit a request by emailing support@oreapp.fit with the subject Privacy Request. To appeal a refusal to act, use the subject Connecticut Privacy Appeal. Ore will respond to an appeal within 60 days and, if an appeal is denied, provide a method to contact the Connecticut Attorney General.

Users outside the United States

Ore is operated from the United States, and the information described in this Policy is processed and stored in the United States and in the other locations where our service providers operate. Data-protection laws in the United States may differ from those of your country. By creating an Ore account, you understand that your information, including meal, dietary, and body information, will be transferred to and processed in the United States as described in this Policy. Ore separately asks for in-app permission before sending covered meal or diary information to third-party AI providers.

Where laws such as the EU or UK General Data Protection Regulation or Canada's federal and provincial privacy laws apply, Ore relies on the following legal bases:

You may withdraw AI-processing consent at any time through Settings → Delete Account as described under AI and nutrition processing; this deletes the account and ends access to the service. You may decline AI-processing consent without losing access to your account, but AI-powered meal estimates and daily insights remain unavailable. Subject to applicable law, you may also request access to, correction of, deletion of, or a portable copy of your personal information, request restriction of or object to certain processing, and decline to consent without discrimination. Submit requests by emailing support@oreapp.fit with the subject Privacy Request. You also have the right to lodge a complaint with your local data-protection or privacy authority.

Changes to this Policy

We may update this Policy as our service, providers, or legal obligations change. We will update the date above and provide additional notice when required by law.

Contact

The entity responsible for this Policy is 0xdesigner LLC, doing business as Ore. For privacy questions or requests, email support@oreapp.fit.