Privacy Policy
Last updated August 15, 2026
TwentyGrams is built to be precise and trustworthy, and that includes how we handle your data. This page says plainly what we collect, why, and what we never do with it.
The waitlist (this website)
If you join the waitlist, your email address is stored with Kit (ConvertKit), our email provider. You'll get one confirmation email (double opt-in) and, later, one email when TwentyGrams launches. If you checked "I'm curious about how food affects my blood sugar," we tag your signup so we understand demand for that use case — nothing more.
We never sell or share your email with advertisers, and we never use it for ad targeting. You can unsubscribe from any email we send, at any time, with one click.
This website's analytics
We use Google Analytics (GA4) to see aggregate, anonymised traffic — how many people visit, which pages they read. We don't build individual visitor profiles from it, and we don't use it to retarget you with ads elsewhere.
GA4 doesn't run until you say yes: on your first visit to this website (not the app) you'll see a cookie banner with an Accept and a Reject option, and no analytics script loads until you choose Accept. You can change that choice anytime from the "Cookie preferences" link in the footer.
The TwentyGrams app
The app itself is anonymous-first: it works fully with no account, and your food log lives in a local database on your own phone. We collect only aggregate, anonymised usage events (things like "a log was completed," never the food itself) to understand whether the app is working for people — never your individual entries, never sold, never used for ad targeting.
If you delete the app without ever creating an optional account, your data is gone with it — we tell you that plainly in Settings, not as a hidden gotcha.
Cloud sync (only if you create an account)
Creating an account is optional and is what turns on cloud sync — it's how TwentyGrams Premium gets your data onto the web dashboard and keeps a second device in step. If you never create one, none of this section applies to you: nothing about your logging leaves your phone. Accounts are handled by Clerk, our sign-in provider; we never see or store your password ourselves.
Once you do create an account, here's exactly what syncs to our server: your food log entries, your app settings and goals (like your daily carb target), and banked carb allowance. If you log or connect them, we also sync health metrics — step count, water intake, weight, active energy, resting heart rate, and sleep — plus your saved recipes (name, ingredients, instructions, photo, notes) and your shopping list state (pantry staples, checked items, and anything you've added or dismissed manually). Nothing syncs that you haven't logged yourself or connected via Health/Health Connect.
Two more names worth knowing: your synced data is stored on Turso, our database host, and RevenueCat, our subscription/billing provider, receives your account's Clerk ID so it can check whether you have Premium — it doesn't get your food log or any of the health data above.
Deleting your account (Settings → Delete account, or by deleting your Clerk account directly) erases everything synced above from our server — every table it's stored in, not just the parts you'd notice missing. We don't run a separate countdown or "grace period": we keep synced data only for as long as your account exists, and deletion is real deletion, not a soft flag. Connections to our server and to Clerk are encrypted (HTTPS/TLS) the whole way.
Want a copy of everything we have stored about you? Email us at the address below and we'll send it to you.
Public reviews
If you write a review — of a recipe or of the app itself — it's genuinely public: anyone can see it, along with your display name and, if you've set one, your profile photo and a short bio. By default those come from your account; you can change or remove them anytime in Settings.
Deleting your account takes your reviews down from public view immediately — the same thing happens if you use the "withdraw my review" option yourself — and permanently deletes your profile (email, display name, photo, bio). We keep an internal, non-public record of what was posted rather than purging the review text outright. That's a deliberate policy choice, not a loophole: it protects the integrity of the review system — so a review can't quietly disappear and reappear, and so we have a record if a review's authenticity is ever disputed — the same principle behind the FTC's rules against businesses manipulating their own review record. It isn't sold, shared, or shown publicly again. If you want us to reconsider retention in your specific case, email[email protected]. Any likes you'd given other people's reviews are removed completely when your account is.
Why we're allowed to process this
Joining the waitlist relies on your consent — you opt in, and the confirmation email makes sure it was really you. This website's GA4 analytics also relies on your consent — the cookie banner described above — before it ever runs. The app's own aggregate usage analytics relies on our legitimate interest in understanding whether TwentyGrams works for people; it's aggregate and anonymised, so it was never about you individually. Creating an account and using cloud sync relies on the contract you're asking us to perform — syncing your data is the service. The optional parts on top of that — connecting Health/Health Connect, writing a public review — additionally rely on your consent to switch them on in the first place.
Your privacy rights
Wherever you are, you have the right to: know what we hold about you (access), fix it if it's wrong (rectification), have it deleted (erasure), get a copy in a portable format (portability), ask us to pause processing it (restriction), and object to processing based on our legitimate interest, like analytics. Email[email protected]to exercise any of these — that's the one mechanism for all of them, there's no separate portal to hunt for.
California residents (CCPA/CPRA)
Do Not Sell or Share My Personal Information: there's nothing to opt out of, because we don't do it — see "What we never do" below. That's not a setting we could turn off; it's a standing choice about how we operate.
California residents also have the right to know what we collect, request its deletion, correct it if it's wrong, and not be discriminated against for exercising any of these rights. Some of what syncs — weight, steps, sleep, heart rate — counts as "sensitive personal information" under CPRA; we don't limit our use of it beyond everything else this page already says, because we never sell it, share it, or use it for advertising in the first place. Same request, same address:[email protected].
How long we keep it
Synced account data — everything listed under Cloud sync, plus your profile — is kept only as long as your account exists; deleting your account is real, immediate deletion, not a soft flag (see above). Public reviews follow the rule described above: taken down from view on deletion, kept internally rather than purged. Waitlist emails stay with Kit until you unsubscribe or ask us to delete the record — we don't run a separate countdown on top of that. Analytics events, on this site and in the app, are aggregate and anonymised from the moment they're collected, and sit inside the bounded retention window the analytics platform itself enforces automatically.
Where your data lives
TwentyGrams has users everywhere, and the providers we use to run it are US-based: Turso (our sync database) runs on AWS infrastructure in the US; Clerk (accounts) runs on Google Cloud in the US; RevenueCat (billing), Kit (waitlist email), and Google Analytics all process data in the US too. None of them offer EU-only data residency — instead, each covers the transfer under GDPR-recognised mechanisms (Standard Contractual Clauses and/or the EU-US Data Privacy Framework) named in their own Data Processing Agreements. That's lawful transfer, not in-region storage — worth knowing the difference if it matters to you.
Children's privacy
TwentyGrams is built for adults managing their own diet and isn't directed at children. We don't knowingly collect data from anyone under 13 (or under 16, where GDPR sets that higher bar). If you believe a child has an account, email us and we'll delete it.
What we never do
- — Sell your email or usage data to anyone
- — Use your data for ad targeting or retargeting
- — Share individual food logs with anyone, for any reason
- — Add tracking beyond aggregate, anonymised analytics
- — Sell or share your synced health data (steps, water, weight, sleep, heart rate, and the rest) with anyone, for any reason
- — Turn on cloud sync without you explicitly creating an account first
Questions
Reach us at [email protected].