[ michi ]

Privacy Policy

Last updated: 2 September 2026

1. Who we are

Michi is a conversational AI nutrition companion operated by Quintis Studios Limited (“Quintis”, “we”, “us”). This Privacy Policy explains what personal information we collect through the Michi mobile app and the yourmichi.com website (together, the “Service”), why we collect it, who we share it with, and the rights you have over it.

Because Michi handles food logs, weight entries, dietary restrictions, and health conditions you mention in conversation, much of the information we hold is health information. We handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which apply heightened protections to health information.

Questions or requests about your data: support@yourmichi.com.

2. Our privacy commitments

  • We collect only what we need to deliver the product to you.
  • We are transparent about what goes where — including exactly which third parties process your data (Section 5).
  • Your health data is never sold, never shared with advertisers, and never used for any purpose beyond delivering Michi’s features to you. We do not use your data to train AI models, and our AI providers are contractually prohibited from doing so.

3. What we collect and how long we keep it

DataWhat & whyRetention
Account dataEmail, optional display name, goal type, nutrition targets, timezone, unit preference, and language — for authentication, personalisation, and calculating your nutrition targets.While your account is active. Deleted within 30 days of account deletion.
Food logsMeal descriptions, estimated calories and macros, meal type, input method, timestamps — the core tracking and coaching function.While your account is active. Deleted within 30 days of account deletion.
Weight logsWeight entries and timestamps — trend tracking and goal monitoring.While your account is active. Deleted within 30 days of account deletion.
Activity dataDaily steps, active energy, and workout sessions imported from Apple Health or Health Connect, plus workouts you log in chat or on the Training tab. Recurring weekly commitments (including ones you confirm from your calendar), planned training weeks (including per-exercise logged reps, load, distance, and duration), and workout sessions you save as favourites — powers activity insights and the training coach.While your account is active. Deleted within 30 days of account deletion.
CalendarIf you turn on calendar read, Michi looks at events on this device to spot recurring training and find gaps in your week. Event titles, locations, and guests stay on your phone — they are never sent to our servers, our AI providers, or analytics. Only commitments you confirm (a label, weekday, time, and intensity) and title-less busy times (a date and start/end) leave the device. If you turn on calendar write, planned Michi sessions can be shared as a calendar file you choose to import; those titles come from your Michi plan, not from other events.Busy times are kept for yesterday through the next 14 days and deleted nightly outside that window. Turning calendar read off deletes your busy times immediately. Confirmed commitments follow Activity data. All of it is removed within 30 days of account deletion.
Conversation historyYour messages and Michi’s replies, plus session metadata — the context that lets Michi continue a conversation.Full message text is kept for 90 days, then replaced by an AI-generated session summary. Summaries stay while the account is active and are removed within 30 days of deletion.
User memoryPreferences, dietary restrictions, patterns, and goals Michi learns about you — persistent personalisation.While your account is active. You can view and delete individual memory entries in-app at any time.
FavouritesMeals and recipes you save — name, a nutrition snapshot, and for recipes the ingredient list and optional steps — so you can re-log them without another chat turn.While your account is active. You can rename or delete them in-app. Deleted within 30 days of account deletion.
PhotosMeal, nutrition-label, and menu photos you submit for AI analysis.EXIF metadata (including GPS) is stripped before the image is stored. The original image is deleted within 24 hours of processing. The text results of the analysis are kept for 30 days, then deleted.
Voice inputWhen you use the chat microphone on iOS, Apple speech recognition converts audio to text. Michi receives only the resulting transcript (a chat message), never the audio file. Android has no in-app microphone — keyboard dictation is the operating system keyboard, not a Michi recording. Transcripts follow conversation-history retention (90 days → digest).Same as conversation history. We never store or upload the recording.
AI usage recordsModel used, token counts, cost, and latency for each AI request — cost control, fair-use limits, and abuse prevention. No message content or food details.Kept for service and cost analysis. The link to your account is removed when you delete your account.
Usage analyticsApp and server events (e.g. a meal was logged, a photo was scanned), plus anonymous yourmichi.com pageviews, referrers, and outbound clicks. Events record that an action happened, never the values, message content, food details, or calendar titles. The marketing site uses cookieless analytics (no cookies or local storage) and does not record sessions. The auth callback page is excluded.Retained by our analytics provider for up to 12 months; only aggregates kept thereafter.
Subscription dataTier, status, billing provider, and period dates — access control for premium features.Kept for 7 years for financial record-keeping. Personal identifiers are removed after account deletion.
Notification preferencesPer-type toggles (meal reminders, goal nudges, weekly summary, re-engagement) and quiet hours you set in Settings.While your account is active, or until you change them. Deleted with your account.
Push tokensDevice notification token — for delivering nudges and weekly summaries you opt into. We also keep a send log (type, title, and body) to enforce daily caps.Token deleted when you disable notifications or delete your account. Send-log rows are deleted with your account.

The yourmichi.com marketing pages do not set cookies. Anonymous pageviews, referrers, and outbound clicks are sent to PostHog in cookieless mode. The account handoff page at /auth/callback is not measured.

4. Photos

Embedded metadata — including any GPS location your camera added — is stripped from every photo before it is stored. The image is re-encoded on our server, which discards all EXIF data. The re-encoded copy is stored only long enough to generate your analysis, in a private bucket that only your account can reach. Photos are never used for advertising, never used to train AI models, and never shared beyond the providers listed in Section 5.

The original image is deleted within 24 hours of processing. The text results of the analysis (identified foods, OCR text, recommendations) are kept for 30 days, then deleted. Anything still present when you delete your account is removed with it.

5. Who we share data with

We share data only with the service providers below, only to the extent needed to run Michi. Some are located in the United States and Finland, so using Michi involves cross-border disclosure of your information — including health information contained in your conversations and photos. We tell you this at onboarding and here.

ProviderWhat they receiveLocation
HetznerHosting for the Michi API. Every request to the Service passes through this infrastructure, including conversation content and photos while they are being processed.Finland (EU)
OpenRouterAI requests — conversation messages and photo-analysis prompts. Routes requests only; does not retain content.USA
OpenAI, Anthropic, Google (via OpenRouter)Conversation content routed to their language models. Under their API terms, none of them train on this data.USA
SupabaseAll stored user data — logs, conversations, weight, memory, favourites, photos, training plans, title-less calendar busy times, notification preferences. Hosted on AWS Sydney (ap-southeast-2); stored data stays in Australia.Australia
SentryError and diagnostic reports — your user ID and email address, plus request type, model name, and error codes. Message content, food data, health details, and calendar titles are excluded by design.USA
PostHogBehavioural event data from the app, API, and yourmichi.com — the fact that an action happened, never the values, message content, food details, or calendar titles. Marketing-site events are cookieless.USA
RevenueCatSubscription status, purchase receipts, entitlements.USA
Firebase Cloud Messaging (Google)Device push tokens and notification content, for delivering notifications.USA
Apple SpeechWhen you use the iOS chat microphone, Apple may process the audio to produce a transcript. Michi does not upload recordings to Hetzner, OpenRouter, or any Michi server — we receive only the text, as a chat message. Android has no in-app microphone.On device / Apple

We do not sell personal information, and we do not share it with data brokers or advertisers.

6. Apple Health & Health Connect

If you enable health sync, Michi reads steps, active energy, and workouts from, and writes nutrition, weight, and workouts you log in chat to, Apple Health or Health Connect on your device. This happens on-device; only the daily aggregates and workout summaries described in Section 3 are sent to our servers. Chat-logged workouts are also stored on our servers so Insights and coaching work even when health sync is off. We never use Health data for advertising or share it with third parties beyond the storage provider listed above, in line with Apple and Google platform policies. You can turn sync off at any time in Settings.

7. Calendar

Calendar access is optional and off by default. Two independent switches live in Settings:

  • Read my calendar — Michi reads events only on this device, only from calendars you pick (none are selected until you choose), and only in a limited window. Matching for recurring training happens on the phone. We never send event titles, attendees, locations, notes, or organiser details to our servers, to our AI providers, or to analytics. What we store is listed in Section 3: commitments you explicitly confirm, and busy times with no title.
  • Add workouts to my calendar — planned sessions can be shared as a calendar file (.ics). That file is created on your device from your Michi plan. This does not require calendar permission and does not read your other events.

You can turn either switch off at any time. Turning read off deletes busy times from our servers immediately. Confirmed commitments stay until you remove them in Training or delete your account. We do not use calendar-derived data for advertising. Section 5 is unchanged — nothing new leaves the device, so no new sub-processor is added.

8. Your rights

  • Access — you can request a copy of all personal information we hold about you. We respond within 30 days.
  • Correction — you can edit any food log or weight entry in-app or in chat, at any time. You can view and delete individual memory entries in Settings. You can rename or delete saved meals and recipes from the Favourites tab or in chat.
  • Deletion — you can delete your account from in-app Settings (Delete account). Personal data is purged when you confirm (and in any case within 30 days); subscription records are anonymised and retained for 7 years for financial compliance.
  • Export — you can request an export (JSON/CSV) of your food logs, weight logs, conversation history, training data, and title-less calendar busy times by emailing support@yourmichi.com. Fulfilled within 30 days.

To exercise any of these rights, use the in-app controls or email support@yourmichi.com. If you are unsatisfied with our handling of a complaint, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).

9. Age requirement

Michi is for people aged 16 and over. By creating an account you confirm that you are 16 or older. We do not knowingly collect personal information from anyone under 16 — if we become aware that we have, we will delete it and close the account. If you believe a child under 16 has created an account, contact us at support@yourmichi.com.

10. Security

All traffic between the app and our servers is encrypted in transit. Data is stored with a managed database provider with row-level security enabled, and access to production systems is restricted. No system is perfectly secure; if a data breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced in-app or by email before they take effect, and the “Last updated” date above will always reflect the current version.

12. Contact

Quintis Studios Limited · support@yourmichi.com