LeanPick Privacy Policy

Effective date: August 21, 2026

LeanPick ("LeanPick," "we," "us") is a mobile app published by KellyBot LLC, a Utah limited liability company doing business as Kelly Claude AI, that helps you tell, in plain language, which dishes on a menu fit how you eat. This policy describes, plainly and completely, what data LeanPick collects, why, and how it is handled. It describes only the actual behavior of the shipped app; it is not a generic template.

1. Data we collect

LeanPick has no account, no sign-in, and no user profile stored on a server tied to your identity. The only data the app collects is the following:

WhatWhat it isWhy we collect it
Menu text When you scan a menu (photo, multiple photos, a delivery-app link, or typed text), the app extracts the menu's text on your device and sends that extracted text (never the photo itself) to our server so it can generate your picks and reasons. App functionality: this text is the input our inference service needs to tell you which dishes fit your preferences.
Install identifier (install_id) An identifier generated by the app, seeded from your device's per-vendor identifier (identifierForVendor, "IDFV," supplied by iOS) when available, or a random identifier generated by the app when IDFV is unavailable. It is stored in the device Keychain so it survives a reinstall (this persistence is intentional, so fair-use limits cannot be reset by reinstalling). App functionality only: it lets our server meter how many free scans a given install has used and enforce fair-use limits on paid usage. It is not the Advertising Identifier (IDFA), is not shared with any advertising or data-broker partner, and is never used to track you across other companies' apps or websites.
App usage events Standard product-analytics events (such as app open, onboarding step completed, paywall shown, subscription started) from a fixed, published list. Each event carries only simple values such as a screen name, a count, a duration, or a true/false flag, and an app-generated random installation ID. It never carries your name, your email, your location, your menu photos, or your menu text. These events are recorded to a log on your device and sent to Google Firebase Analytics, which processes them on our behalf. Firebase also generates and sends its own app-instance identifier (a "Firebase installation ID") and standard device and app context, such as device model, operating-system version, app version, language and coarse country, to attribute those events. That identifier is generated by the SDK, is specific to this installation of LeanPick, and is not the Advertising Identifier (IDFA). Analytics and app functionality: understanding which parts of LeanPick people actually use, so we can improve them.
Crash and performance diagnostics If LeanPick crashes, a crash report is sent to Google Firebase Crashlytics. That report contains the app's stack trace at the moment it failed, the device model, the operating-system version, the app version, whether the device was jailbroken, and a Crashlytics-generated installation UUID. It also contains a short breadcrumb trail carrying only the NAMES of the analytics events listed above, never their values. Basic timing information, such as how long a scan took, rides on the analytics events above. App functionality: finding and fixing crashes and slow paths.
Advertising measurement data (TikTok Events SDK) Standard app-event signals (such as app install, session start, tutorial completion, content view, subscribe, and purchase observation) and basic device signals, together with your device's per-vendor identifier (identifierForVendor, "IDFV"). These are sent to TikTok's Events SDK, which we use to measure how our TikTok advertising performs. Advertising measurement: understanding whether a TikTok ad campaign led to an install and a later meaningful action, so we can measure and improve our ad spend. It is not the Advertising Identifier (IDFA), is not used to build a cross-app profile of you, and is sent without any App Tracking Transparency (ATT) prompt because it does not track you across other companies' apps or websites.
Subscription and purchase records When you subscribe, renew, cancel, or receive a refund, a record of that transaction is processed by RevenueCat, which we use to manage subscriptions. RevenueCat receives the StoreKit transaction identifiers and product identifiers Apple issues, the resulting entitlement status and its dates, and basic device and app context (device model, operating-system version, app version, country). It identifies you by its own anonymous app user ID, which it generates itself; we never give it your name, your email, or the analytics installation ID above. It never receives your menu text or your payment credentials. App functionality: managing your subscription and keeping your access accurate.
Subscription / entitlement status Whether your Apple Account currently holds an active LeanPick Plus subscription, as reported by StoreKit. App functionality: unlocking the features your subscription pays for.

We do not collect: your name, email address, phone number, physical address, health records, location, contacts, browsing history, or photos themselves (only extracted menu text leaves your device; the photo you take or select never does).

2. Camera and photo access

If you use the camera-scan feature, LeanPick asks for camera access to photograph a menu. The photo is processed on your device to extract the menu's text; the photo itself never leaves your device. If you use the multi-image or "add from library" road, the system's standard photo picker is used, which does not require LeanPick to request photo-library permission and does not let the app see or enumerate your photo library. If you save a "My Pick" share card, it is written to LeanPick's own storage area on your device (visible in the Files app), not to your system Photos library, so no photo-library-write permission is used or requested.

3. How menu text is processed (our AI feature)

To turn a menu into plain-language picks, the extracted menu text and your stated eating preferences are sent, over an encrypted connection, to a server-side function we operate on Supabase (our backend and database provider), which in turn calls a third-party AI language model (routed through OpenRouter) to generate the assessment. The menu text you submit is processed to generate your result and is not used to build an advertising profile, sold, or shared with data brokers.

4. Payment and subscriptions

LeanPick offers an optional auto-renewing subscription, "LeanPick Plus," billed by Apple through your Apple Account. Apple processes all payment details; LeanPick and its developer never see your card number, billing address, or other payment credentials. We only receive confirmation of your subscription's entitlement status (active/inactive) from Apple's StoreKit framework. See our Terms of Use for full subscription terms.

5. Who we share data with

We do not sell your data, and we do not share it with data brokers. We share data only with the service providers that operate LeanPick on our behalf, including the advertising-measurement processor listed below, each acting as a processor for the purpose described:

LeanPick uses Apple's own on-device SKAdNetwork and AdAttributionKit frameworks so that, if you installed LeanPick from a paid advertising campaign, the ad network that ran it can learn, in aggregate, that its campaign led to installs and coarse, delayed conversion milestones (such as reaching your first result or starting a subscription). This runs entirely on your device under Apple's design: it reports only a coarse, delayed, install-level signal, never anything tied to you as an individual, and it requires no ad SDK in the app and no App Tracking Transparency (ATT) prompt.

LeanPick also uses the TikTok Events SDK described above to measure TikTok advertising performance. Like SKAdNetwork and AdAttributionKit, it does not use Apple's App Tracking Transparency (ATT) framework and does not read or use the Advertising Identifier (IDFA); it identifies your device only by IDFV, the per-vendor identifier iOS supplies, not by anything tied to your name or account. LeanPick does not track you across other companies' apps or websites, and none of these measurement mechanisms can be used to do that either.

6. Data retention and deletion

LeanPick has no user account, so there is no account to delete. Menu text you submit for assessment is processed to generate your result and is not retained by our server beyond what is needed for that processing, fraud prevention, and abuse monitoring. Your install identifier is stored in your device's Keychain and, by design, persists even if you delete and reinstall the app: this is intentional, so that fair-use limits on paid usage cannot be reset simply by reinstalling. It is not tied to your name or any account and is used only for metering. It is a device-local anonymous identifier, stored only in this device's Keychain and never synced to iCloud or shared across your devices. Because it is anonymous and used only for fair-use metering, it persists on this device and is cleared when you erase the device. Your saved preferences and results, and the local copy of your analytics events, are held only on your device and are removed when you delete the app.

Data held by our processors is retained as follows. None of it is tied to your name or to any account, because LeanPick has no accounts:

ProcessorWhat it holdsHow long
Google Firebase AnalyticsProduct-analytics events and the SDK's installation identifierEvent-level records expire on Google's shortest available user-data retention setting, 2 months; aggregate, non-identifying reporting totals may persist longer
Google Firebase CrashlyticsCrash reports and their breadcrumb trailsGoogle deletes crash reports 90 days after they are received
RevenueCatSubscription transaction and entitlement recordsKept for the life of the anonymous subscriber record, so entitlements and refunds stay accurate, and deleted on our request
Supabase (our edge function)Menu text in transit, and fair-use metering counts keyed to the install identifierMenu text is not stored after your result is generated; metering counts are kept only as long as needed to enforce the fair-use window
OpenRouter and the AI model providerThe menu text sent for assessmentUnder their own retention terms for the routes we use; the text is never used to train a model on our instruction and we do not send it any identifier of you
ApplePayment and subscription recordsUnder Apple's own policy; we never receive or store payment details
TikTok (Events SDK)App-event data, device signals, and the IDFV used to measure ad performanceUnder TikTok's own retention terms for advertising measurement data; not tied to your name or any account

If you want the analytics, crash, or subscription records associated with your installation deleted, email support@kellyclaudeai.com and we will request their deletion from the processors above. Because those records carry only anonymous installation identifiers, deleting and reinstalling the app also stops any further Firebase or RevenueCat records being associated with the old identifier.

7. Your choices

8. Children

LeanPick is rated 4+ and is not directed at children. We do not knowingly collect data from children in a manner different from any other user, and the app collects no information that identifies any user, child or adult, by name.

9. Region

LeanPick is offered in the United States storefront only in this version, and this policy is written for that scope. If LeanPick expands to additional regions, this policy will be updated before that expansion ships.

10. Changes to this policy

If LeanPick's data practices change, for example, adding a user account or a new data-processing partner, we will update this policy before that change ships in the app.

11. Contact and governing jurisdiction

LeanPick is published by KellyBot LLC, a limited liability company organized in the State of Utah, United States, doing business as Kelly Claude AI. KellyBot LLC is the party responsible for the data described here. LeanPick is offered on the United States App Store storefront only, and this policy is written under, and governed by, the laws of the State of Utah and the United States, without regard to conflict-of-laws rules. Questions, requests, and deletion requests can be sent to support@kellyclaudeai.com, and we answer them ourselves; there is no third-party support desk that receives your message.

Terms of Use