Last updated 28 August 2026
Rylia is an AI calorie scanner: you photograph a meal, or describe it, and the app estimates its calories and macronutrients. This policy explains exactly what we collect, where it goes, and how to get rid of it. It describes what the app does today, not what it might do one day.
Rylia is operated by Om Prakash Kumar, an individual developer based in Jamshedpur, Jharkhand, India. For anything in this policy, write to support@rylia.app.
During setup the app asks for your sex, age, height, weight, activity level and goal, and optionally a target weight and dietary preferences. This is used solely to calculate your daily calorie and macronutrient targets. Some of it is health-related information, and we treat it accordingly.
When you scan a meal, the photo is resized on your device and sent over an encrypted connection to our server, which forwards it to Google's Gemini API for analysis. When you type a description instead, the text takes the same path.
The photo is not kept. Our server does not write it to any database or file store. For 24 hours we cache the analysis result against a one-way cryptographic hash of the image, so that scanning the same plate twice does not produce two different answers. The hash cannot be turned back into your photo. The photo file itself stays in your phone's own storage, under your control, and is deleted when you delete the meal or the app.
Meals you save — names, calories, macronutrients, portion sizes, timestamps — are stored on your device. If you sign in with Google, they are also backed up to Google Firebase so you can recover them on a new phone.
You can use Rylia without an account; the app creates an anonymous identifier so your data can be saved. If you sign in with Google to enable backup, we receive your Google account identifier and email address from Google.
If you subscribe, the purchase is handled by Google Play. We never see your card or UPI details. We receive only whether your subscription is active.
We may collect crash reports and anonymised usage events to find bugs and understand which features are used. These never include your photos or your meal contents.
We do not sell your data or share it for advertising. We use these service providers, each handling only what its job requires:
| Provider | What it receives | Why |
|---|---|---|
| Google (Gemini API) | Your meal photo or description | To identify the food and estimate nutrition |
| Google Firebase | Account identifier, profile, meal log | Sign-in and cloud backup |
| Cloudflare | Requests in transit; cached results | Runs our server and protects it from abuse |
| Google Play | Purchase and subscription status | Billing |
| RevenueCat | Subscription status, account identifier | Manages subscription entitlements |
| Sentry, PostHog | Crash reports, anonymised usage events | Diagnostics |
We may also disclose information where the law requires it.
These providers operate globally, so your data may be processed outside India, including in the United States and the European Union. All transfers happen over encrypted connections.
| Data | Kept for |
|---|---|
| Meal photos | Not retained by us. Cached analysis results expire after 24 hours |
| Profile and meal log | Until you delete them or delete your account |
| Account record | Until you delete your account |
| Diagnostics | Up to 90 days |
Under India's Digital Personal Data Protection Act 2023, and under the GDPR if you are in the European Economic Area or the UK, you have the right to access your data, correct it, delete it, withdraw consent, and complain to a regulator.
You can exercise most of these in the app itself: Settings → Delete account removes your account, your cloud backup and your local data. It cannot be undone. For anything else, email support@rylia.app and we will respond within 30 days.
Rylia is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, write to us and we will delete it.
Traffic is encrypted in transit. Access to your cloud data is restricted to your own account by server-side rules, and our AI endpoint requires an authenticated request. No system is perfectly secure, and we do not claim otherwise.
If this policy changes materially we will update the date above and notify you in the app. Please check back occasionally.
Om Prakash Kumar, Jamshedpur, Jharkhand 831012, India
support@rylia.app