Privacy policy

Your health data stays on your device. What you log — food, water, caffeine, sleep, workouts, fasting — lives on your iPhone, iPad and Apple Watch and in your own Apple Health, and syncs only through your own iCloud. slotho has no account, and red8.io runs no server that receives your logs or your health data.

But slotho is a food app, and looking up a food means asking someone who knows about food. Those lookups leave your device, and so does anything you ask slotho PRO’s AI to read. This page says exactly which ones, and what goes with them.

Last updated: 29 September 2026

The slotho app

What stays on your device

Your logs and the health data behind them are stored on your device and written to Apple Health, where your own Health privacy settings govern them. slotho asks for Health access in both directions: read, to show your charts, history and correlations, and write, to log water, nutrition, caffeine, workouts and the rest. You can withdraw either at any time in Settings › Health › Data Access & Devices.

Data moves between your iPhone, iPad and Apple Watch through your own iCloud — slotho’s private iCloud database and iCloud’s settings store. That is Apple’s infrastructure under your Apple Account, not ours; we cannot see inside it, and there is nothing for us to see, because nothing is sent to us.

Looking up a food

When you search for a food or scan a barcode, slotho queries two public food databases and a library built into the app, and merges what comes back:

  • Open Food Facts — a public, non-profit food database.
  • USDA FoodData Central — the United States Department of Agriculture’s food database.
  • A library inside slotho — over 300 common foods stored in the app itself, so looking one of these up makes no request at all.

What travels is the search itself: the words you typed, or the barcode number you scanned. Nothing identifying you goes with it — no name, no account, no health data, no log. Those services will see a request arriving from an internet address, as any website would, and each handles it under its own privacy policy. Barcode scanning happens on your device; only the resulting number is sent.

Foods you have looked up before are cached on your device, so repeat lookups need no request at all.

Adding or correcting a food — this one becomes public

This is the part to read twice. When you create a new food or correct an existing one and it has a barcode, slotho submits it to Open Food Facts, a public database. If you attached a photo, the photo is uploaded too, as that product’s front image.

That contribution is public and permanent: anyone can read it, and it is published under Open Food Facts’ own open licence. It is submitted through a shared slotho contributor account, so it is not attributed to you by name — but the photograph you took is published, so take care that it shows the product and not your kitchen, your hands or anything else you would not put on a public website.

Foods without a barcode, and foods you merely log rather than edit, are never submitted anywhere. Neither is anything about how much of it you ate.

The camera and your photos

The camera is used to read barcodes and to photograph labels. Barcode reading and text recognition run on your device using Apple’s own frameworks; the image is not uploaded for either.

Translating a label uses Apple’s Translation framework, the same one built into iOS. The text goes to Apple under Apple’s privacy policy, not to us and not to a translation company we chose; depending on the languages, iOS may do it entirely offline.

A photo you attach to a food stays on your device, with two exceptions, and each is set out on this page: a barcoded product’s photo contributed to Open Food Facts, above, and a meal photo you ask an AI provider to analyse, below.

Finding a picture for a food

When a food has no image, slotho can look one up on the open web, trying public image search engines — Brave, Bing, DuckDuckGo, Qwant and Yandex — until one answers. What is sent is the food’s name as a search term. No identifier and nothing about you accompanies it, but the request does reach whichever engine answered, and each has its own privacy policy. With an AI provider of your own connected, you can instead ask it to draw an illustration of a food you typed, on one tap: the food’s name goes to that provider, and the drawing is kept on your device.

Workouts and routes

If you record an outdoor workout on Apple Watch, slotho asks for location so it can map your route. The route is written into the workout in Apple Health, on your device, exactly as Apple’s own Workout app does. It is not uploaded, not sent to us, and not shared. Decline location and workouts still record — just without a map.

Writing in plain language

slotho can read a sentence like “two eggs and a coffee” and turn it into a log. By default this uses Apple’s on-device model: the sentence never leaves your iPhone.

You may instead connect an AI provider of your own in Settings by supplying an endpoint and an API key — OpenAI, or any compatible service including one you run yourself. This is off until you configure it. Once you do, the text you are logging is sent to the provider you chose and is handled under their terms; we are not in that exchange and never see it. Your key is stored in the iOS Keychain, and neither the key nor what you send is written to the app’s logs. Clear the key to stop it.

Photographing a meal

slotho can also look at a photograph of a plate and suggest what to log. There is no on-device option — recognising food in a photograph needs a model that runs elsewhere — so this uses either an AI provider you connected yourself, or, with slotho PRO, the service described in the next section. Nothing is sent until you take or choose a photo for it.

Before the first photo goes anywhere, slotho names where it is going and asks. Your answer is recorded per destination, so a different provider asks again rather than inheriting it, and you can withdraw it in Settings › Intelligence. The photo is shrunk and re-encoded first, which removes its location, capture time and camera details. With a provider of your own, it goes to the provider you chose, under their terms, and we never see it.

slotho PRO’s AI

With slotho PRO you do not need a provider of your own. PRO can read a meal photo, read a food you typed, draft a meal or workout plan, write a meditation and give it a voice, and voice the notes in your own workout plans. Each of these runs only when you ask for it, and Settings › Intelligence decides which engine runs each feature — Apple’s on-device model, your own provider or PRO — so you can keep any of them off PRO entirely.

What is sent is only what the feature needs: the photo (stripped as above); the words you typed for a food; for plans and meditations, the options you picked from the app’s own lists, never free text, plus your eating pattern if you set one (it can say something about what you believe, so it is only sent for a meal plan); and, for voiced workout notes, the text of those notes. Nothing from Apple Health, your logs or your identity goes with any of it. slotho asks before the first photo, before the first text request and before the first voiced note, and each consent can be withdrawn in Settings › Intelligence.

The request goes to a small service red8.io runs on Google Cloud. It checks that the request comes from the genuine slotho app (Apple’s App Attest, through Firebase App Check) and from a current PRO subscription (the signed App Store transaction your iPhone already holds), then passes the request to Google’s Gemini models on Vertex AI, or to Google Cloud Text-to-Speech for a voice, and returns the answer. Google processes it as our service provider and does not use it to train its models.

What we keep is a count: how much of each monthly allowance has been used, stored against the anonymous original transaction number the App Store gives your subscription — not your name, email or Apple Account — so the allowance survives a reinstall and is shared by your devices without a sign-in. The photos, words and notes themselves are not stored; our logs record the size of each request and its answer, never the content. A meditation written for you, and the voice clips for it and your notes, are stored on your devices only.

Voices for meditations and workouts

With PRO, the guided meditations and the Apple Watch’s Coach Voice can be read in slotho’s own voice. Those recordings are the same for everyone, so they are downloaded from our Google Cloud Storage bucket rather than made for you; the download carries the same App Attest check as above and nothing about you. The Apple Watch receives them from your iPhone. Without them, the voice built into iOS reads the same words on your device.

Where you ate

A meal can carry a place. You can type one, or tap Find places near me to list venues around you; only that button asks for your location. To find the venues, slotho asks Apple Maps with a coordinate — the photo’s own, or your location once you tap — under Apple’s privacy policy, never with the meal. The place’s name and Maps category go into Apple Health with the meal, where other apps you allow to read your nutrition can see them; the coordinates stay in slotho’s own storage on your iPhone. The whole row can be turned off in Settings › Food & Drink.

Purchases

slotho PRO is sold through Apple. Payment details are handled by Apple under Apple’s privacy policy and never reach us; we receive only anonymous sales reports. When you use PRO’s AI, the app sends the signed App Store transaction for your subscription so our service can confirm it is current; that record names the product and dates, not you.

No analytics, no advertising, no account

The app contains no analytics, no advertising and no crash-reporting service. There is no sign-in and no profile of you anywhere, because there is no account to hold one. Nothing follows you across other apps or websites, which is why iOS never shows you a tracking prompt.

This website (slotho.io)

slotho.io is a static page that embeds nothing from a third party. It is served through Cloudflare, which handles the request and keeps the standard security logs any host keeps. It uses Google Analytics to count visits and see which links people use — but only if you agree to it first.

On your first visit you are asked. The default is no: until you accept, no analytics runs and nothing is sent to Google. Declining costs you nothing. Your answer is remembered in a cookie named zaraz-consent, set either way because either answer has to be remembered; if you accept, Google Analytics sets a first-party cookie too, so repeat visits from one browser count as one person rather than several.

If you accept, what is recorded is: the pages you opened and for how long, where you arrived from, which links you clicked, and your approximate location (country and city) worked out from your IP address along with your browser and device. Your IP is used for that and then discarded. Nothing identifies you personally, and Google’s advertising and remarketing features are switched off, so it is not used to follow you elsewhere. The records are kept for two months — the shortest Google allows — then deleted.

The tags run on Cloudflare’s network rather than in your browser, so no Google script is loaded onto the page. None of this touches the app: your health logs are not involved, and the website has no way to reach them.

The same consent-gated measurement runs on badmintho.com and luizmaiaj.com.

Health and medical

slotho is a wellness and information tool, not a medical device. Its nutrition, fasting and workout features do not provide medical advice and must not be used to diagnose or treat anything.

Children

slotho is not directed at children under 13, and we do not knowingly collect data from them.

Your rights

We hold no account, no profile and no copy of your data, so in almost every case there is nothing for us to retrieve, correct or delete — your data is on your device and in your iCloud, and deleting the app removes slotho’s copy. We do keep the monthly PRO AI counts described above, which are keyed by an anonymous transaction number and cannot be tied back to you. The other exception is a food you contributed to Open Food Facts: that lives in their public database, and corrections or removals go to them. Write to us and we will help you do it.

Contact

Questions about this policy: privacy@red8.io.