Privacy Policy
Last updated: 24 July 2026
1. Who we are
Michi is a conversational AI nutrition companion operated by Quintis Studios Limited (“Quintis”, “we”, “us”). This Privacy Policy explains what personal information we collect through the Michi mobile app and the yourmichi.com website (together, the “Service”), why we collect it, who we share it with, and the rights you have over it.
Because Michi handles food logs, weight entries, dietary restrictions, and health conditions you mention in conversation, much of the information we hold is health information. We handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which apply heightened protections to health information.
Questions or requests about your data: support@yourmichi.com.
2. Our privacy commitments
- We collect only what we need to deliver the product to you.
- We are transparent about what goes where — including exactly which third parties process your data (Section 5).
- Your health data is never sold, never shared with advertisers, and never used for any purpose beyond delivering Michi’s features to you. We do not use your data to train AI models, and our AI providers are contractually prohibited from doing so.
3. What we collect and how long we keep it
| Data | What & why | Retention |
|---|---|---|
| Account data | Email, age, optional name, timezone, and goal type — for authentication and personalisation. | While your account is active. Deleted within 30 days of account deletion. |
| Food logs | Meal descriptions, estimated calories and macros, meal type, input method, timestamps — the core tracking and coaching function. | While your account is active. Deleted within 30 days of account deletion. |
| Weight logs | Weight entries and timestamps — trend tracking and goal monitoring. | While your account is active. Deleted within 30 days of account deletion. |
| Activity data | Daily steps, active energy, and workout sessions you choose to import from Apple Health or Health Connect — powers activity insights and coaching. | While your account is active. Deleted within 30 days of account deletion. |
| Conversation history | Your messages and Michi’s replies, plus session metadata — the context that lets Michi remember your conversation. | Full messages kept for 90 days, then replaced by an AI-generated summary. Summaries kept while your account is active; all deleted within 30 days of account deletion. |
| User memory | Preferences, dietary restrictions, patterns, and goals Michi learns about you — persistent personalisation. | While your account is active. You can view and delete individual memory entries in-app at any time. |
| Photos | Meal, nutrition-label, and menu photos you submit for AI analysis. | EXIF metadata (including GPS) is stripped on upload. The original image is deleted within 24 hours of processing. Only the text results of the analysis are kept, for 30 days. |
| Usage analytics | App events (e.g. log created, photo scanned), session duration, feature usage — product health measurement. No message content or health details. | Raw events deleted after 12 months; only aggregates kept thereafter. |
| Subscription data | Tier, status, billing provider, and period dates — access control for premium features. | Kept for 7 years for financial record-keeping. Personal identifiers are removed after account deletion. |
| Push tokens | Device notification token — for delivering nudges and weekly summaries you opt into. | Deleted when you disable notifications or delete your account. |
4. Photos
Photos are treated as transient processing inputs, not stored assets. When you submit a photo, embedded metadata — including any GPS location your camera added — is stripped before the image is sent to the vision AI. The original file is deleted from our storage within 24 hours of processing regardless of outcome. We keep only the text output of the analysis (identified foods, OCR text, recommendations) for 30 days so you can see your scan history.
5. Who we share data with
We share data only with the service providers below, only to the extent needed to run Michi. Some are located in the United States, so using Michi involves cross-border disclosure of your information — including health information contained in your conversations and photos. We tell you this at onboarding and here.
| Provider | What they receive | Location |
|---|---|---|
| OpenRouter | AI requests — conversation messages and photo-analysis prompts. Routes requests only; does not retain content. | USA |
| OpenAI, Anthropic, Google (via OpenRouter) | Conversation content routed to their language models. Under their API terms, none of them train on this data. | USA |
| Supabase | All stored user data — logs, conversations, weight, memory. Hosted on AWS Sydney (ap-southeast-2); stored data stays in Australia. | Australia |
| Sentry | Error metadata only — user ID, request type, model name, error codes. No health information, message content, or food data by design. | USA |
| PostHog | Behavioural event data only — no health information or message content by design. | USA |
| RevenueCat | Subscription status, purchase receipts, entitlements. | USA |
| Firebase Cloud Messaging (Google) | Device push tokens and notification content, for delivering notifications. | USA |
We do not sell personal information, and we do not share it with data brokers or advertisers.
6. Apple Health & Health Connect
If you enable health sync, Michi reads steps and energy data from, and writes nutrition and weight data to, Apple Health or Health Connect on your device. This happens on-device; only the daily aggregates and workout summaries described in Section 3 are sent to our servers. We never use Health data for advertising or share it with third parties beyond the storage provider listed above, in line with Apple and Google platform policies. You can turn sync off at any time in Settings.
7. Your rights
- Access — you can request a copy of all personal information we hold about you. We respond within 30 days.
- Correction — you can edit any food log, weight entry, or memory item directly in-app, at any time.
- Deletion — you can delete your account from in-app Settings. All personal data is purged within 30 days; subscription records are anonymised and retained for 7 years for financial compliance.
- Export — you can request an export (JSON/CSV) of your food logs, weight logs, and conversation summaries by emailing support@yourmichi.com. Fulfilled within 30 days.
To exercise any of these rights, use the in-app controls or email support@yourmichi.com. If you are unsatisfied with our handling of a complaint, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
8. Age requirement
Michi is for people aged 16 and over. The age gate is enforced at account creation — if you indicate you are under 16, you cannot create an account. We do not knowingly collect personal information from anyone under 16; if we learn we have, we will delete it.
9. Security
All traffic between the app and our servers is encrypted in transit. Data is stored with a managed database provider with row-level security enabled, and access to production systems is restricted. No system is perfectly secure; if a data breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced in-app or by email before they take effect, and the “Last updated” date above will always reflect the current version.
11. Contact
Quintis Studios Limited · support@yourmichi.com