Last updated: September 5, 2026
This policy explains what data the FatLose AI Chrome extension
("FatLose", "the extension") handles, where that data lives, who else sees it,
and what is not collected. It covers the extension and the
FatLose backend at oracleserver1.thebrandwick.com/fatlose, which
we operate.
Your food log, calorie totals and weight entries are stored on your own computer, in the browser's extension storage. You can use FatLose without an account and without anything ever leaving your device.
One optional feature sends data to our server: generating an AI report. It happens only when you press the button. There is no sign-in and no account. Nothing is sold, rented, or used for advertising.
Health data. Weight, calorie and macronutrient entries are health information. We treat them as such: they stay on your device unless you ask for an AI report, and they are never shared with anyone for advertising, profiling or resale.
Held in chrome.storage on your computer, never uploaded unless
a section below says otherwise:
Uninstalling the extension removes all of it from your computer.
The first time you generate an AI report, the extension sends our server the random device identifier it generated for itself and gets back a session token. No account, email address or name is involved, and we have no way to tell who you are from it. Its only job is to keep your reports separate from anyone else's and to meter usage against the monthly limit.
When you press the button to generate a report, and only then, the extension builds a compact summary of the period you chose and sends it to our server. That summary contains the names of foods you logged, their calorie and macronutrient totals, your weight entries, dates, and your calorie and weight goals. Our server bounds and cleans it, then passes it to Amazon Bedrock (AWS, US East region), which runs the model that writes the report.
The finished report is returned to you and saved to your account so it is available on your other computers. The report we save includes the daily calorie and weight figures it was based on, so the charts can be redrawn when you open it again. The rest of the snapshot — including the individual food names — is used to write the report and then discarded; we do not keep a copy of your food log.
We also keep a per-account count of how many reports you have generated and when the last one was, to enforce the usage limit.
Your day-to-day diary is not synced. It is sent only as part of the snapshot for a report you asked for.
Typing log in the address bar followed by a space lets you add
an entry without opening the extension. From that point Chrome passes what you
type to FatLose so it can suggest foods. That text is matched against the food
list on your computer and is never sent to our server. It is
the only thing the extension receives from the browser, and it only happens
after you type the log keyword.
| Data | Where it is stored | Why |
|---|---|---|
| Food log, weights, goals, settings | Your computer only | To run the tracker |
| A random per-install device identifier, and the time it was last seen | Our PostgreSQL database, on our server | To know whose reports are whose |
| Diary snapshot for a report | Sent to our server, then to Amazon Bedrock; discarded once the report is written | To produce the report you requested |
| Generated reports, and the daily calorie and weight figures behind them | Your computer and our database | So reports survive a reinstall, reach your other computers, and still draw their charts |
| Report count and timestamp | Our database | To enforce the monthly limit |
| Session refresh tokens | Our database, stored only as a SHA-256 hash | To keep you signed in; the stored value cannot be turned back into a working token |
Nobody else. We do not use analytics, crash reporting, advertising or tracking services of any kind.
All traffic between the extension and our server is over HTTPS. Access tokens are short-lived; refresh tokens are single-use and stored only as hashes. The server checks on every request that the signed-in user is the owner of the data being read or written. The AI model key lives only on the server and never reaches your browser. The database is reachable only from the server itself, never from the public internet.
FatLose is not directed at children under 13, and we do not knowingly collect data from them.
FatLose reports are generated by a language model from the numbers you logged. They are informational, not medical advice, diagnosis or treatment. Talk to a qualified professional before making significant changes to how you eat, and especially if you have a medical condition or a history of disordered eating.
If this policy changes, the date at the top changes with it, and the current version always lives at this address.
Questions, or a deletion request: himanshu@thebrandwick.com