MeThen Privacy Policy
Last updated: August 27, 2026
Our Privacy Commitment
MeThen is a progress-photo check-in app for iOS and Android, built to be private by default. Your photos, check-in records, journal, and optional profile are stored primarily in the app's private container on your phone. There is no account, no cloud sync, no behavioral product analytics, no advertising, and no cross-app tracking. The bounded AI, reporting, configuration, and subscription traffic described below comprises the only off-device transmissions initiated by MeThen. Platform backup behavior is described separately below. LightPath keeps no server-side photo library or full progress history.
AI analysis can send photos on both supported platforms. Deep Compare can also send photos on iOS, where that feature is currently available. Both require an explicit user action, but their consent cadence is different:
- AI analysis (iOS and Android): sends the current check-in's photos — with EXIF and GPS data stripped — plus its journal note (if any) and a compact prior AI-result summary (if available) to our AI provider. The app asks before the first analysis, remembers that grant, and lets you revoke it at any time in Settings. Every upload still requires you to tap Analyze.
- Deep Compare (Pro, currently iOS only): sends both check-ins' photos, the current note, and the earlier result summary so a signed body-fat delta can be computed across the two check-ins. It is approved separately, per comparison. Deep Compare is not included in the current Android release.
MeThen does not transmit photos unless you tap Analyze or, on iOS, run a Deep Compare. Standard Apple-managed backups on iOS are the separate exception described below; Android backup and device transfer are disabled for MeThen. Both AI flows are described in full below.
Follow-up chat is a separate, text-only AI flow. When you tap Send, the saved result summary, recent chat turns, and your question are sent to Google Gemini. Your photos and optional profile are not sent again.
What stays on your device
All of the following is stored in MeThen's private app container on your phone. Uninstalling removes that app-container data. On iOS, standard Apple-managed device or iCloud backups may include local app data and follow Apple's backup-retention controls; separate same-device allowance counters remain in the iOS Keychain after uninstall so reinstalling cannot reset a daily quota. On Android, MeThen disables app backup and device transfer; local data and app-private counters are removed when the app is uninstalled. Specific content is transmitted only for the explicit AI and reporting actions described below; separate non-content service traffic is also described below.
- Check-in photos: the front, side, and back photos you capture with the guided camera, and any photos you import from your camera roll to backdate check-ins
- Check-in history and journal: your timeline, dates, and notes remain stored locally; the current note is included only in an Analyze request you start or, on iOS, a Deep Compare request you separately approve
- Side-by-side comparisons: comparing any two check-ins runs entirely on-device
- AI results and chat: results and chat threads are saved on your device; a compact prior-result summary may accompany Analyze or, on iOS, Deep Compare, and a result summary plus recent text turns is sent when you tap Send in follow-up chat
- Optional profile: height, weight, sex, and age, if you choose to enter them
Your optional profile is not sent by MeThen
MeThen can use an optional profile — height, weight, sex, and age — to anchor its estimate ranges locally. The app never uploads it to LightPath, Google, or RevenueCat and never includes it in AI analysis, Deep Compare, chat, or report requests. Standard iOS device or iCloud backups may include this local preference data under Apple's controls; Android backup and device transfer are disabled for MeThen. If you don't want to enter a profile, the app works without it.
What we do NOT collect
MeThen does not collect, store off-device, or transmit:
- Behavioral usage analytics or advertising telemetry
- Advertising identifiers or cross-app tracking IDs
- Location Services data — GPS and other EXIF metadata are stripped from photos before any upload. Service providers may process a coarse country inferred from ordinary network information for service operation, as described below.
- Contact information automatically through the app — if you email support or submit a privacy request, you voluntarily provide the contact details in that message
- Any account, email address, or login — there is no account
The app contains no behavioral product-analytics SDK, advertising network, or social/login SDK. Firebase service diagnostics and RevenueCat subscription analytics are limited to the operational purposes described below.
AI analysis — opt-in, remembered consent, explicit Analyze tap
MeThen offers opt-in AI trend insights and body-fat range estimates. Before the first analysis, the app explains the upload and asks for consent. That grant is remembered and can be revoked at any time in Settings under Allow AI photo analysis. Nothing is uploaded in the background: every photo upload still requires you to tap Analyze. When you do:
- What is sent: the photos of the check-in you chose to analyze, its journal note (if any), and a compact prior AI-result summary (if available). EXIF and GPS data are stripped from photos before upload. Your optional profile and other photos are not sent.
- Who processes it: Google, via Google Vertex AI (Gemini), solely to generate your analysis.
- Not used for training: your photos are not used to train AI models.
- Limited provider retention: LightPath does not create a server-side archive of your photos or result. Google may temporarily retain request data for abuse monitoring, service protection, or caching under its policies and project settings. The generated result is saved in MeThen on your device.
Every result is presented as a broad range with a confidence level, caveats, and a non-medical disclaimer — these are visual estimates, not measurements or medical information.
Follow-up chat — text only, sent on demand
After a result exists, you may ask follow-up questions. When you tap Send, MeThen sends the saved result summary, a bounded set of recent text turns, and your new question to Google Vertex AI (Gemini). It does not resend check-in photos or your optional profile. Threads remain local on your phone, and each AI response can be reported separately if you choose.
Chat includes 10 successful replies per day on the free tier. Pro removes the successful-reply cap, subject to service availability and a reasonable-use ceiling of 120 actual provider attempts per day, including fallback attempts; the free tier has a separate 30-attempt ceiling. Daily usage counts are stored locally. On iOS, allowance counters also remain in the iOS Keychain so uninstalling and reinstalling does not reset the same-day allowance. On Android, the counters are app-private and are removed with the app because Android backup is disabled.
Deep Compare on iOS — a separate consent, every time
Deep Compare is currently an iOS-only Pro feature and is not included in the current Android release. On iOS, it computes a signed body-fat delta between two check-ins. To do that, it uploads both check-ins' photos, the current check-in's journal note (if any), and a compact summary of the earlier AI result (if available). The prior photos are downscaled before upload. Because this sends more than a regular analysis, Deep Compare shows its own consent screen for every single comparison — it is never covered by a previous approval, and it is separate from the regular Analyze consent.
- EXIF data is stripped from all photos before upload.
- The same processing terms apply as for a regular analysis: Google Vertex AI (Gemini) generates the comparison, requests are not used for training, and Google may temporarily retain request data for abuse monitoring, service protection, or caching.
- Your optional profile is not sent.
Subscriptions (RevenueCat)
MeThen Pro is an auto-renewable subscription purchased through the Apple App Store on iOS or Google Play on Android. Payment is handled entirely by the applicable store — we never see your payment-card details. To validate purchases and unlock Pro features across reinstalls, MeThen uses RevenueCat, a subscription-management service. RevenueCat processes the applicable store receipt or purchase token, product and entitlement state, and a random anonymous app-user identifier — not your name, email, photos, or any content from the app (there is no account, so we have no identity to attach). RevenueCat uses this data for receipt validation, entitlements and restores, fraud prevention, and its Customer History, Charts, and Experiments analytics. It may also process limited device/app/service metadata and infer a coarse country from ordinary network information. None of this is used for advertising or cross-app tracking.
Model configuration (Firebase Remote Config)
When MeThen launches, it checks Firebase Remote Config for which Gemini model version to use. This keeps already-installed copies working if Google retires a model before an app update can be released. Firebase may receive technical metadata needed to provide and monitor this service, including a Firebase installation identifier, app and SDK versions, device language and time zone, operating-system version, fetch time, bundle identifier, and a country inferred from ordinary network information. The request contains no photo, journal, profile, result, or chat content. This service call can occur before AI consent, and LightPath does not use it for advertising or behavioral profiling.
Optional AI content reports
If you choose Report this result or Report response, MeThen first shows exactly what will be sent: the selected reason, your optional comment, a bounded copy of the AI output you are reporting (which may include a derived body-fat range or change estimate), result identifiers, limited model and request details, timestamps, app version, platform, and a random per-install identifier used only for abuse rate-limiting. Reports never include photos, your optional profile, or the rest of a chat thread. They are sent to a LightPath-operated reporting service hosted by Google and may be reviewed by LightPath to investigate unsafe or incorrect AI output. Reports are scheduled to expire 180 days after receipt; short-lived quota records are scheduled to expire after two days. Google processes TTL deletion asynchronously, so deletion may occur after the scheduled timestamp. Both production expiration policies were verified active on August 10, 2026. You may request earlier deletion through our privacy requests page, although we may be unable to locate an anonymous report without enough matching details. If the service is unavailable, the app offers to copy the report so you can decide whether to email it instead.
Firebase App Check
To prevent abuse of the AI features, MeThen uses Firebase App Check to verify that AI requests come from a genuine, unmodified copy of the app before they are accepted. The attestation exchange involves Apple's and Google's attestation infrastructure and contains no photos and no chat content — it only vouches for the integrity of the app itself.
Third-party processors
- Google — Gemini via Firebase AI Logic for the AI content you explicitly send; Firebase App Check for app/device integrity; Firebase Installations and Remote Config for model-version delivery and limited service diagnostics; and Google Cloud for optional content reports
- RevenueCat — anonymous subscription and entitlement management, purchase restoration, fraud prevention, and purchase-history analytics
- Apple — App Store payment, receipt, subscription, and App Attest services on iOS under Apple's privacy policy
- Google Play — payment, purchase-token, subscription, and Play Integrity services on Android under Google's privacy policy
We do not sell this data, use it for advertising, or use it to track you across apps or websites.
Permissions MeThen requests
- Camera (optional): to capture your guided front/side/back check-ins. On both platforms, photos upload only for an AI action you choose.
- Selected photos (optional): to import existing photos when you backdate check-ins. On iOS, selected-photos library access is sufficient. On Android, MeThen uses the system Photo Picker and does not request broad photo-library access.
- Device authentication / Privacy Lock (optional): if you enable Privacy Lock, MeThen asks iOS or Android to verify you with the screen lock or biometric method configured on your phone. Authentication is performed by the operating system; MeThen receives only the success or failure result and never receives your fingerprint, face template, passcode, or other device credential.
That is the entire list. MeThen does not request location, microphone, or contacts.
Support and privacy requests
If you voluntarily email support or use the privacy-request page, your email app sends the name, email address, message, and any details you choose to include to LightPath. We use that information only to answer, investigate, or fulfill your request, and retain it only as long as reasonably needed for that purpose and related legal obligations. You can ask us to delete it through the same privacy-request page.
Children's privacy
MeThen is not directed at children under 13 and we do not knowingly collect personal information from them. The app has no account and stores photos, history, journal, and the optional profile in its app container. Standard Apple-managed backups may include that local data on iOS; Android backup and device transfer are disabled. MeThen-controlled off-device transmission is limited to the explicit AI and reporting actions and the anonymous service traffic described in this policy.
International users
AI analysis, iOS Deep Compare, follow-up chat, optional content reports, support/privacy-request email, Firebase service traffic, and RevenueCat subscription traffic may transit infrastructure outside your country. They are processed for the specific functions and service operations described above, not to build an advertising profile. MeThen does not transmit other content; Apple-managed backup copies remain governed by Apple's controls on iOS, while Android backup and device transfer are disabled.
Changes to this policy
We may update this privacy policy from time to time. Changes will be reflected on this page with an updated revision date at the top. Because MeThen has no account or mailing list, we generally cannot notify app users directly — please check this page if you want to confirm the current version.
Contact
If you have questions about this privacy policy or about MeThen's privacy practices, please contact us at:
- Email: [email protected]
- Support: MeThen support page
- Data requests: privacy requests page
Privacy by design
MeThen is on-device by default — no account, no cloud sync, no behavioral analytics, no ads, no tracking. A normal analysis requires a remembered, revocable grant plus an explicit Analyze tap; the iOS-only Deep Compare feature asks separately every time. Follow-up chat and optional reports send only the bounded content you choose, when you choose. Your progress is yours.