Zenbu is a personal workout, nutrition and body-data app operated by its developer ("we", "us"). This policy explains what Zenbu collects, where it goes, and the choices you have. It applies to the Zenbu iPhone app and its hosted service during the internal beta. Our beta terms of service cover the legal agreement separately.
Signing in is optional: logging works without an account or a wearable. If you sign in with Apple, Apple supplies an account identifier and, on first sign-in, optionally your name and email. We verify your Apple identity token on our backend, store the account identifier, and issue a Zenbu session token. Apple credentials are verified by the backend and are not stored on your device by Zenbu.
Signing in binds your local logs to one account and server, and enables upload of completed workouts, templates, programs, custom exercises, nutrition and food logs, recipes, nutrition plans and weight records. Your location is not collected, and neither is your contacts list, photo library, or advertising identifier.
Workout drafts and rest-timer state, app settings and favorites, and Apple Health imports stay on the device. Apple Health records are cached in a protected folder excluded from device backups and are not sent to our backend, advertising services, or analytics providers, and are not included in Zenbu export files.
Connecting WHOOP is optional. With your consent, Zenbu reads your WHOOP recovery, sleep, physiological cycles, workouts, profile and body measurements — including available recovery scores, heart rate and heart-rate variability, sleep details, strain and activity measurements. We request renewable access so imports can continue while you remain connected. We do not write to your WHOOP account. WHOOP supplies this data under its own privacy policy.
With your permission, Zenbu reads weight, body-fat percentage, lean body mass, steps, sleep, resting heart rate, heart-rate variability (SDNN), active energy and workouts from Apple Health. Zenbu does not write to Apple Health. You choose which categories to share in the iOS permission screen and can change them in the Health app. A successful refresh replaces Zenbu's local snapshot; if the phone is locked or a read fails, the previous cache may remain until a later successful refresh or removal. Disconnecting in Zenbu removes our local copy without deleting your original Health records.
Foods, recipes and nutrition logs can include macronutrients, micronutrients and caffeine amounts along with the time you log them. These records and the nutrition targets you save sync to your Zenbu account. Weekly plan reviews compare logged intake and available weight trends on your iPhone; Apple Health weight readings and calculated review averages stay on the device, and only targets you explicitly approve are saved and synced.
Generic and branded food information comes from public sources: USDA FoodData Central and Open Food Facts. A barcode you scan or type is sent to Open Food Facts to look up that product, and search terms you enter may be sent to those providers. Camera frames are processed on your phone; we do not upload photos of barcodes or labels. Configured generic search sends your food query through Zenbu's server to the USDA. Nutrition data from these sources can be incomplete or wrong — check the package label.
AI food logging is optional and separate from everything else. When you use it, the photo you take — or choose — and any description you type are sent over HTTPS to Zenbu's server, which passes them to a third-party AI service that reads the meal and estimates its nutrition. Zenbu does not store the photo: it is not written to your food log, your local database, your export, or our backups, and it is not retained on the server after the request. The description is passed on for the same purpose and is not stored either.
Before a photo leaves your iPhone it is resized and re-encoded, which removes the metadata a camera attaches — including the location the photo was taken. Only the estimates that come back are saved, as ordinary food log entries, and the whole proposal is shown to you for editing before anything is logged.
Zenbu sends the photo and description to the AI provider selected on our server. Current options are QwenCloud and DeepSeek; the provider can change. Provider retention, use for model training, and processing locations depend on its terms and settings. Zenbu does not promise that providers retain nothing, never use inputs for training, or process inputs only in the United States. See the QwenCloud agreement, QwenCloud privacy policy, and DeepSeek developer terms. AI food logging needs a signed-in account because the request goes through our server, and it needs a network connection — every other way of logging food works without either. If you would rather no photo of a meal ever leaves your iPhone, do not use this input, and the rest of Zenbu is unaffected.
Restaurant nutrition lookup: when your description names a restaurant, Zenbu's server may look up that restaurant's own published nutrition for the menu item using Google's Gemini API with Google Search. Only the restaurant name and the menu item name are sent to Google, for example "Chipotle" and "burrito bowl". Your photo, your description, anything else about your meal, and anything that identifies you — your account, name, email or location — are never sent to Google. The published figures that come back are public restaurant data and are kept on our server for up to 30 days so the same item is not looked up again; they are not linked to you. Google's handling of the request is governed by the Gemini API terms. If no official figures are found, Zenbu estimates the meal from its ingredients instead.
Data is used to display your own history and descriptive progress in Zenbu, and to sync it between your devices. The hosted service stores account records, synced logs, provider records and encrypted WHOOP credentials in a private, encrypted PostgreSQL database on Amazon Web Services in Ohio, United States, served over HTTPS. Your iPhone caches records locally for offline use. Server request handling does not log bearer tokens or health and food payloads, and WHOOP errors shown to users are sanitized.
Amazon Web Services hosts the HTTPS API and database. Automated database backups are retained for one day; separately retained snapshots may last longer. A local development setup used during testing may store test records on the developer's Mac and use a temporary tunnel for consent callbacks and webhooks; local test records are not automatically transferred into the hosted account.
Your Zenbu session token is stored in the iOS Keychain, accessible after first unlock and only on this device. The local database and its folder use iOS file protection. WHOOP OAuth credentials are encrypted on the server with an AES-GCM key bound to your account. Traffic to the hosted service uses HTTPS. No method of storage or transmission is perfectly secure, and the beta makes no guarantee of absolute security.
Native deleted records retain a sync tombstone so deletions replicate correctly; normalized live views exclude them. WHOOP keeps bounded raw payloads while you are connected, and updates replace the current record. Disconnecting removes provider payloads from live Zenbu records and the phone cache, cancels ingestion, and schedules remote revocation; encrypted credentials remain only while revocation is pending and are cleared once it succeeds. If revocation cannot complete, the app reports that state and lets you retry. Your own logged workouts and nutrition stay until you delete them.
Sign-out revokes only the Zenbu session and keeps device logs. Account deletion asks you to confirm with Apple again, revokes Apple authorization, and removes the account's local and server records after WHOOP revocation completes. The fresh Apple authorization code is exchanged on the backend only for deletion, and the resulting Apple tokens are not retained. If authorization or revocation fails, deletion does not proceed and you can retry. Automated database backups are retained for one day, so a deleted record may persist in backup until that retention window passes; we do not promise immediate removal from every backup or snapshot.
You can export your records from Settings, disconnect WHOOP or Apple Health, sign out, or delete your account. Exported files and backups you keep are your responsibility and must be deleted separately. For access, correction, or deletion questions, contact us.
Zenbu's beta is for adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided information, contact us and we will remove it.
We may update this policy as the beta develops. The version and date at the top identify the current policy, and the app will ask you to review a material change before you continue.