تخطَّ إلى المحتوى
Ohlim
←العودة إلى Ohlim

لا تتوفر نسخة معتمدة باللغة المحددة. يتم عرض المستند الإنجليزي المعتمد.

Ohlim

Privacy Policy

Effective date: 2026-09-06·Version: 2.0

This Policy explains how Ohlim handles personal data in its global nutrition-tracking service. Acknowledging this Policy confirms that you have read it; it is not consent to every form of processing. English is the authoritative version, and governs over a translation only to the extent permitted by applicable law.

Contents

  1. Identity and contact
  2. Scope
  3. Data we handle
  4. Sources
  5. Purposes
  6. Legal bases
  7. Health Connect
  8. Photos, OCR and user content
  9. Sharing and service providers
  10. International processing
  11. Retention
  12. Export and deletion
  13. Your rights
  14. Children
  15. Security, changes and contact

1Identity and contact

Ohlim is operated under the Ohlim name. Legal, privacy and security inquiries may be submitted through the public Ohlim contact form. Ohlim does not represent itself here as a registered company, medical institution or medical-device manufacturer.

2Scope

This Policy applies to the Ohlim Android application, the authenticated web application and API, the related account, security and legal services, and the contact form on the public Ohlim website. The public website is not the authenticated application origin and does not receive the application session.

3Data we handle

Depending on the features you use, Ohlim handles account and OAuth identity data; name and email; locale, theme and preferences; profile, birth year and the separate 16+ confirmation; height, weight, goals, allergens and dietary preferences; diary entries, foods, recipes, favourites, corrections and nutrition calculations; activity, steps, sleep, active calories and Health Connect data; photos, screenshots, feedback and moderation submissions; and Premium status and feature usage. A public contact request contains the reply email, selected category, message and locale that you submit.

Technical records may include Ohlim session and login events, IP address and User-Agent recorded for session or security operations, mobile-auth lifecycle data, push token and device metadata, legal acceptance history, rate-limit records, audit/security events, and user-scoped local storage, drafts and service-worker caches. The public contact form also processes Turnstile verification data, HMAC-derived abuse-prevention identifiers and minimal technical delivery and security logs. The form does not store raw IP addresses, messages or complete email addresses in its rate-limit database. Ohlim does not collect a full date of birth for the legal flow.

  • Nutrition and health-related information can be sensitive personal data.
  • Administrative access is limited to functions needed to operate, secure, support or moderate the service.
  • Client caches may retain user-scoped state on a device until sign-out, deletion, expiry or browser/app cleanup.

4Sources

Data comes from you; from the configured OAuth provider used to sign in; from Android Health Connect only after you choose to connect it; from your device and application context; from user-created or moderated catalogue submissions; and, for contact requests, from the form you submit and Cloudflare Turnstile verification. Google sign-in is supported when configured. Apple sign-in is mentioned only conditionally and is available only where credentials are configured and the option is shown.

Food information may also come from Open Food Facts, USDA-derived or other imported catalogues, manufacturers, labels and moderated user contributions. Catalogue data is not used to infer that Ohlim is limited to any country.

5Purposes

Ohlim uses data to create and operate accounts; provide diary, nutrition, recipe, progress and personalization functions; synchronize authorized data; protect sessions and prevent abuse; receive, route and answer contact requests; moderate and improve the catalogue; deliver requested notifications; enforce configured Premium access; record legal acknowledgements; and fulfil export, deletion and legal requests.

Ohlim does not sell personal data or Health Connect data. Health Connect data is not used for advertising, sale, credit or insurance decisions.

6Legal bases

The applicable legal basis depends on the purpose and where you live. It may include performance of the Terms, legitimate interests in service security and abuse prevention, compliance with legal obligations, and your express choice or device permission for Health Connect, camera, notifications or other optional features. A future optional use, such as marketing, must have its own appropriate basis and controls.

Accepting the Terms is contractual; acknowledging this Policy is not blanket consent. Where processing relies on optional consent, you may withdraw it without turning Terms acceptance or Privacy acknowledgement into an optional permission. This Policy does not claim automatic or certified compliance with every privacy regime.

7Health Connect

On supported Android devices, Ohlim requests only read access for steps, weight, active calories and sleep. Access begins only after an explicit connection and is used for dashboard and progress features. Imported records and summaries may be synchronized to and stored by Ohlim's server.

Account Security separates disconnecting Health Connect permissions from deleting imported server data and offers a combined action. Deleting imported data removes Health Connect-sourced records and summaries while preserving manual weight, goals, diary and recipes. Server deletion cannot itself revoke an Android permission on an offline or unavailable device; permissions can also be managed in Android Health Connect settings. Granting permission again may allow a later sync to import data again.

  • Health Connect data is not sold or used for advertising.
  • Ohlim does not request Health Connect write access or unrelated health scopes.
  • Disconnect status and server deletion can partially succeed; the application reports those results separately.

8Photos, OCR and user content

Camera or gallery access occurs only after a user action. Nutrition-label images sent to the nutrition-vision endpoint are processed by Ohlim's server-side Tesseract OCR implementation; the current code does not send them to an external AI/OCR provider. Product, recipe, correction-evidence and feedback images may be uploaded to server storage and reviewed where moderation or support requires it.

Private evidence is not made public automatically. If you submit content for the shared catalogue and it is approved, the resulting catalogue content may become available to other users. You must have the right to upload the content.

9Sharing and service providers

Ohlim discloses data only as needed for the relevant function: to hosting and infrastructure providers; the configured local mail system used to hand off contact messages; Cloudflare Turnstile for bot verification; configured Google OAuth services; Apple OAuth only if enabled; Firebase Cloud Messaging when push delivery is configured; Android Health Connect; Open Food Facts for permitted network catalogue lookup; and authorities or other recipients when legally required. Providers receive only information needed for their function and remain subject to their own terms and privacy practices.

The current application does not integrate a third-party advertising network or third-party analytics SDK. Local product-usage events and internal operational metrics are not a promise that this will never change; a future material change requires updated disclosures and, where required, consent.

10International processing

Ohlim is available globally. Data may be processed in the country where infrastructure is hosted and in locations where relevant service providers operate. Ohlim does not state a server region or transfer mechanism that has not been confirmed. Safeguards required by applicable law will be used where they apply.

11Retention

Active account data is generally retained while the account exists and the data is needed to provide the service. Session, security, audit and contact records are retained while reasonably needed for support, security, abuse prevention, legal obligations or dispute handling. Contact rate-limit events expire automatically, but no unsupported fixed retention period is promised for a message handed to the mail system. Mobile authentication handoffs expire after five minutes and expired or consumed handoffs are eligible for cleanup; client drafts normally expire after 24 hours, while abandoned nutrition evidence is eligible for cleanup after 24 hours.

Deletion operations retain only a minimal anonymized receipt. Approved shared catalogue contributions may remain without account attribution. Backups are not erased individually at the same moment as active data; copies expire through the ordinary backup lifecycle. Data may be retained longer where law, security, fraud prevention or dispute resolution requires it. Ohlim does not promise an unsupported fixed retention period.

12Export and deletion

From Account Security, a signed-in user can download a ZIP copy of account data and user content. Its manifest describes included datasets and files with integrity hashes. Authentication secrets, full push tokens, other people's data, private moderator information and internal anti-abuse records are excluded. Exporting does not delete data.

Account deletion is a separate verified process available in the application; instructions are also available on the Account deletion page. It removes the active account and private data rather than merely freezing them. Approved shared catalogue content may remain only after account attribution and private evidence are removed. Backup copies expire through the normal lifecycle.

13Your rights

Depending on applicable law, you may have rights to access, correct, export or delete data, and to object to or restrict certain processing, withdraw optional consent, and complain to a competent authority. Rights and exceptions differ by location. Use in-app controls or the public privacy contact form.

Withdrawing an optional permission does not withdraw the Terms. Privacy acknowledgement records that the Policy was presented; it is not an optional consent to all processing.

14Children

Ohlim is intended for people aged 16 or older and is not knowingly directed to children under 16. The legal flow requires a separate 16+ confirmation and the profile uses birth year rather than full date of birth. If a user or guardian believes an underage account exists, use the public privacy contact form so it can be reviewed and deleted. Ohlim does not claim to operate a parental-consent system.

15Security, changes and contact

Ohlim uses reasonable technical and organizational safeguards described in the Security Policy, but no system is absolutely secure. Material changes to Terms or Privacy are handled through the versioned legal contract and require a new in-app action. Non-material corrections may be published without blocking access or promising an individual notice in every case.

Version 2.0 is effective 2026-09-06. Ohlim is operated under the Ohlim name. Legal, privacy and security inquiries may be submitted through the public Ohlim contact form.

Related resources

  • Terms of Service
  • Security Policy
  • Account deletion
  • Privacy and data contact

English is the authoritative version. A translated version yields only to English to the extent permitted by applicable law.

Ohlim Beta

التسجيل في إصدار Android التجريبي

عند الانضمام إلى قائمة Android التجريبية، يجمع Ohlim عنوان البريد الذي تقدمه واللغة المحددة ومصدر التسجيل وسجلات أمان محدودة. نستخدم هذه المعلومات فقط لإدارة المشاركة وإرسال الوصول وتعليمات التثبيت وتحديثات الحالة أو الإطلاق المرتبطة مباشرة بالإصدار التجريبي.

يُحتفظ بالتسجيل أثناء إعداد الاختبار المغلق أو تشغيله، وبالقدر المعقول اللازم للأمان أو الالتزامات القانونية أو معالجة طلبك. لا يؤدي الانضمام إلى اشتراكك في نشرة تسويقية عامة.

Ohlim

سجل تغذية متعدد اللغات للسعرات والعناصر والوصفات والتقدم.

الخصوصيةالشروطالأمانحذف الحساب
الدعم