Basalt Privacy Policy
Basalt is an honest health ledger: food, training, sleep, and vitals, recorded as they happened. This policy follows the same rule the app does — it says what actually happens, in plain language, and nothing it doesn't.
The short version
- Your data is yours: you can export all of it in one tap, and delete all of it in one flow.
- There are no ads, no analytics trackers, and no sale or sharing of your data for anyone's marketing.
- The only things that ever leave your device are listed below, each with its reason.
What Basalt stores
When you use Basalt, the following is stored in your account:
- Account — your email address and a password hash (managed by Supabase Auth).
- Profile & targets — the onboarding answers you gave: age, sex, height, weight, goals, training location and equipment, dietary flags and allergies, health conditions and medications you chose to note, and the nutrition targets computed from them (with the formula's reasoning stored alongside).
- Food ledger — meals, portions and nutrients you log, barcodes you scan, recipes you save or import, meal plans, and your grocery list.
- Training ledger — workout sessions, exercises, sets (weight, reps, RIR/RPE, comments), and guided-timer sets.
- Walks — distance, duration, pace, elevation, and the simplified GPS route you recorded.
- Body & recovery — weight entries, steps, sleep sessions and stages, water, and mindfulness sessions.
Photos you choose to attach to food entries are stored in a private, per-account storage area, shown only to you via short-lived signed links, and deleted with the entry or your account. Nothing is ever posted or shared.
Where it is stored
Your data is stored in a database hosted by Supabase, protected by row-level security: every row is keyed to your account, and no other user can read it. Data is encrypted in transit (TLS). Basalt's staff is one person; there is no data team browsing your ledger.
Health Connect
If you connect Android Health Connect, Basalt reads the record types you approve (steps, sleep, workouts, vitals and related types — each one is listed in the system permission screen) and stores those readings in your account so they appear in your ledger with their source named. Basalt never writes to Health Connect, and Health Connect data is never used for advertising or shared with third parties. You can disconnect at any time in Health Connect settings; already-synced rows remain in your ledger until you delete them or your account.
What leaves your device, and why
- Supabase — everything in "What Basalt stores", to sync your ledger. That is its job.
- Anthropic (AI quick-add only) — when you use AI quick-add, the food
description you type is sent to Anthropic's Claude API to produce a nutrition estimate.
Only that text is sent — never your name, email, ledger, or any other data. Estimates come back
marked as estimates (
~) and nothing is saved until you confirm it. Under Anthropic's commercial API terms, API inputs and outputs are not used to train their models. If you never use AI quick-add, nothing is ever sent to Anthropic. - Open Food Facts — when you scan a barcode, the barcode digits are sent to the Open Food Facts database to look up the product.
- Recipe import — when you paste a recipe URL, Basalt fetches that page to read its recipe data.
- Map tiles — when a walk map is shown, map tiles for the route's area are fetched from the tile provider (OpenStreetMap-based). Tile requests necessarily reveal the approximate area being viewed to the provider, as with any map app. Your GPS route itself is never sent to the tile provider.
That is the complete list. There are no analytics SDKs, no advertising SDKs, and no crash trackers phoning home.
Live beacon (optional)
If you start a live beacon while recording a walk, Basalt shares your latest position with whoever you send the link to — and only for as long as the beacon runs. You start it explicitly, you stop it explicitly, and it expires on its own after at most 2 hours. The link shows only the most recent position — no name, no history, no route — and the app shows a clear indicator the whole time it is active. If you never start a beacon, your location is never shared with anyone.
What Basalt will never do
- Sell your data, or share it with anyone for marketing.
- Use your health data for advertising.
- Show you fabricated numbers — and by the same rule, this policy will not fabricate claims.
Export
Settings → Your data exports everything — every table row belonging to your account — as JSON, CSV, or a per-table CSV archive, in one tap. No request forms, no waiting.
Deletion
Settings → Delete account & all data removes every row in every table belonging to your account, then the sign-in record itself. It runs server-side and is verified — not a soft-delete, not a 30-day queue. See the account deletion page for the full flow and a contact path if you can no longer sign in.
Children
Basalt is not directed at children and is intended for users 16 and over.
Changes
If this policy changes, the change and its date will be stated here plainly. No silent edits.
Contact
Questions: [contact email — to be confirmed before publication]
Draft for review · written from what the app actually does · nothing in this policy is aspirational