Privacy Policy — FatLose AI: Calorie & Weight Tracker

Last updated: September 5, 2026

This policy explains what data the FatLose AI Chrome extension ("FatLose", "the extension") handles, where that data lives, who else sees it, and what is not collected. It covers the extension and the FatLose backend at oracleserver1.thebrandwick.com/fatlose, which we operate.

Summary

Your food log, calorie totals and weight entries are stored on your own computer, in the browser's extension storage. You can use FatLose without an account and without anything ever leaving your device.

One optional feature sends data to our server: generating an AI report. It happens only when you press the button. There is no sign-in and no account. Nothing is sold, rented, or used for advertising.

Health data. Weight, calorie and macronutrient entries are health information. We treat them as such: they stay on your device unless you ask for an AI report, and they are never shared with anyone for advertising, profiling or resale.

What FatLose stores on your device

Held in chrome.storage on your computer, never uploaded unless a section below says otherwise:

Uninstalling the extension removes all of it from your computer.

What leaves your device

1. Registering this install

The first time you generate an AI report, the extension sends our server the random device identifier it generated for itself and gets back a session token. No account, email address or name is involved, and we have no way to tell who you are from it. Its only job is to keep your reports separate from anyone else's and to meter usage against the monthly limit.

2. Generating an AI report (optional)

When you press the button to generate a report, and only then, the extension builds a compact summary of the period you chose and sends it to our server. That summary contains the names of foods you logged, their calorie and macronutrient totals, your weight entries, dates, and your calorie and weight goals. Our server bounds and cleans it, then passes it to Amazon Bedrock (AWS, US East region), which runs the model that writes the report.

The finished report is returned to you and saved to your account so it is available on your other computers. The report we save includes the daily calorie and weight figures it was based on, so the charts can be redrawn when you open it again. The rest of the snapshot — including the individual food names — is used to write the report and then discarded; we do not keep a copy of your food log.

We also keep a per-account count of how many reports you have generated and when the last one was, to enforce the usage limit.

Your day-to-day diary is not synced. It is sent only as part of the snapshot for a report you asked for.

3. The address-bar shortcut

Typing log in the address bar followed by a space lets you add an entry without opening the extension. From that point Chrome passes what you type to FatLose so it can suggest foods. That text is matched against the food list on your computer and is never sent to our server. It is the only thing the extension receives from the browser, and it only happens after you type the log keyword.

Where the data sits

DataWhere it is storedWhy
Food log, weights, goals, settings Your computer only To run the tracker
A random per-install device identifier, and the time it was last seen Our PostgreSQL database, on our server To know whose reports are whose
Diary snapshot for a report Sent to our server, then to Amazon Bedrock; discarded once the report is written To produce the report you requested
Generated reports, and the daily calorie and weight figures behind them Your computer and our database So reports survive a reinstall, reach your other computers, and still draw their charts
Report count and timestamp Our database To enforce the monthly limit
Session refresh tokens Our database, stored only as a SHA-256 hash To keep you signed in; the stored value cannot be turned back into a working token

Who else sees your data

Nobody else. We do not use analytics, crash reporting, advertising or tracking services of any kind.

What we never do

Keeping it safe

All traffic between the extension and our server is over HTTPS. Access tokens are short-lived; refresh tokens are single-use and stored only as hashes. The server checks on every request that the signed-in user is the owner of the data being read or written. The AI model key lives only on the server and never reaches your browser. The database is reachable only from the server itself, never from the public internet.

Keeping and deleting your data

Children

FatLose is not directed at children under 13, and we do not knowingly collect data from them.

Not medical advice

FatLose reports are generated by a language model from the numbers you logged. They are informational, not medical advice, diagnosis or treatment. Talk to a qualified professional before making significant changes to how you eat, and especially if you have a medical condition or a history of disordered eating.

Changes to this policy

If this policy changes, the date at the top changes with it, and the current version always lives at this address.

Contact

Questions, or a deletion request: himanshu@thebrandwick.com