Privacy Policy for Prova

Last updated: October 10, 2026

Your data. Your device. Your control.

Prova is built around a simple principle: you own your data.

Your food database, recipes, nutrition logs, weight, steps, and water entries, targets, summaries, custom metrics, and settings are stored locally on your device.

Prova does not require an account, does not contain advertisements, does not sell personal information, and does not operate a cloud database that collects your complete nutrition history.

Prova does not request access to your location, contacts, calls, messages, or calendar. Camera and photo-library access are optional (barcode scan or meal photos for AI Estimate). Microphone access is optional (on-device Dictate on AI Estimate). Speech-to-text runs on your device. Prova does not upload audio. Estimate photos are not stored by Prova.

On Android, Prova may optionally connect to Health Connect when you opt in, so activity and weight can sync with other health apps on your device. Health Connect data stays on your device unless you choose a feature that sends derived facts to Google for AI (described below).

Optional AI features may send limited information to Google (meal text and/or one or more compressed meal photos for estimates, or a compact set of derived facts for optional For You wording). Free or subscription AI uses Google Firebase AI Logic with Firebase App Check under the developer’s Firebase project. Bring-your-own-key (BYOK) AI talks to Google’s Gemini API with your key. Neither path uploads your complete diary to a developer-operated nutrition server. An optional Connect other apps feature can upload a Personal snapshot to an address you choose. That copy is not sent to the developer unless you point Prova at an address the developer controls.

Prova also includes optional fictional demo data so you can explore the app before entering your own information. Demo data is stored locally.

Core privacy principles

1. About Prova

Prova is a personal nutrition-tracking application developed and published by Rostom Baccar (RB Studio). Package name: com.rbstudio.prova.

This Privacy Policy explains how Prova processes, stores, protects, and transmits information.

Prova does not require registration, sign-in, or a developer-operated online account for core use.

2. Information processed by Prova

Prova allows you to create and manage information including:

Prova may compute derived values locally, such as protein-to-calorie ratio, daily scores, adaptive targets, and summary metrics. These calculations use information on your device and are not uploaded to a developer-operated nutrition database.

This information is processed only to provide the features you choose to use.

3. Local storage and data ownership

Your food database, recipes, nutrition logs, weight, steps, and water data, targets, summaries, trends, custom metrics, and settings are stored locally on your device (SQLite and related app storage).

An optional Gemini API key is stored in the device’s secure credential storage (expo-secure-store), not in CSV/ZIP exports.

The developer does not operate a user-account system or cloud nutrition database that receives and stores your complete nutrition history.

You retain control over your locally stored information. You may:

Prova does not claim ownership of nutrition information, meal descriptions, food-database entries, or exported files created by you.

4. Local search, filters, and organization

Searching your foods and log history, filtering, sorting, recipe management, and related organization features run on your device. They do not send your search terms, filters, sort choices, or nutrition history to a developer-operated server.

5. No advertising or behavioral tracking

Prova does not contain advertising.

Your nutrition activity is not used by the developer to:

Prova does not intentionally include advertising networks, developer-operated behavioral analytics, or social-tracking SDKs.

6. Phone permissions

Prova is designed to work with minimal permissions. Optional permissions are requested only when you use the related feature.

Location No precise or approximate location access
Camera Optional barcode scan or AI meal photos. Estimate photos are not stored by Prova
Microphone Optional on-device dictation for AI Estimate only. Audio is not uploaded
Contacts No address book access
Calls / messages No call history, phone, SMS, or messaging access
Photos and media Optional only to pick a barcode image or AI meal photos. No unrestricted library access
Calendar No calendar access
Notifications Optional local meal or custom reminders. No developer push server

Prova uses Android’s system document picker for CSV import and the native share sheet for export. Those flows do not grant unrestricted access to all files on your device.

7. Health Connect (Android, optional)

On supported Android devices, you may opt in to Health Connect so Prova can work with health data already on your phone.

When enabled, Prova may:

Health Connect sync is on-device between Prova and Health Connect. Prova does not upload Health Connect records to a developer-operated server. If you later use optional AI For You polish, only compact derived facts (for example recent totals or step counts already summarized in Prova) may be sent to Google, not your raw Health Connect history dump.

You can disconnect Health Connect or turn related options off in Settings. Revoking permissions in the system Health Connect controls also stops access.

8. Optional AI nutrition estimates

Prova can estimate calories, protein, and optionally fat, fiber, and carbs from a meal description and/or one or more meal photos you choose (currently up to four photos per estimate).

How you can access AI estimates

  1. Free Firebase path (when enabled in your build): a limited number of estimates per local calendar day (currently 5), sent through Google Firebase AI Logic. Firebase App Check (for example Play Integrity on production Android) helps protect the project from abuse. This uses the developer’s Firebase project as a transport to Google’s models. It is not a Prova cloud diary.
  2. Bring your own Gemini API key (BYOK): requests go from your device to Google’s Gemini API with your key. Your key stays in secure device storage and is not included in exports.
  3. Optional Google Play subscription (when offered): may unlock unlimited Firebase AI estimates. Purchase status is handled by Google Play Billing. Prova may cache subscription status locally. Google processes payment under Google’s terms.

AI runs only when you deliberately request an estimate. You may type or dictate a description (dictation is on-device; audio is not uploaded) and optionally attach one or more camera or gallery photos. Photos are compressed for the request, are not saved into your nutrition log by Prova, and are not kept on a developer server. When several photos are attached, Prova may estimate them as one combined meal or prompt you to confirm how they should be treated.

A typical estimate request may include:

Prova does not intentionally include your complete food database, complete nutrition history, or full targets profile in a meal-estimate request.

Prova may try another compatible Gemini model if the first model is unavailable or cannot return a usable result. Google may still apply its own daily or per-minute limits.

Local free-quota counters live on your device. Clearing app data or reinstalling can reset those local counters. Google’s own limits and App Check protections still apply on the Firebase path.

If you save an AI estimate to your food database, the resulting entry is stored locally and may be tagged as an AI estimate.

Do not put names, medical records, or other sensitive personal information in meal descriptions or photos. AI estimates can be wrong. Verify important nutrition values yourself.

9. Optional For You AI polish

Insights can show a short supportive note. By default, wording can be produced locally from your on-device data.

If you choose optional AI polish, Prova may send a compact fact pack (for example day totals, protein, streak-style signals, weight-trend deltas, or summarized steps) to Google through the same Firebase or BYOK paths described above. Prova does not send your full diary export in that request. A separate local limit applies (currently one polish per rolling 24 hours unless your access mode differs).

10. Gemini API-key storage

When you use BYOK, the Gemini API key is provided and controlled by you. Prova stores it in secure credential storage. Older installs may migrate a legacy SQLite copy into secure storage and then remove the legacy copy.

After you open Google AI Studio to create a key, Prova may briefly peek at the clipboard (only when you trigger that flow) to detect a plausible key you copied. You remain in control of whether to save it.

Your key is not included in CSV or ZIP backups. You are responsible for protecting the key and complying with Google’s terms.

11. Open Food Facts (optional)

When you use Online food search or barcode lookup, Prova contacts Open Food Facts with the search text you type or the barcode digits you scan. A User-Agent identifying Prova may include a support contact address for API etiquette. Prova does not send your diary, targets, photos, or API key to Open Food Facts. Product fields you choose to save are stored locally.

12. CSV imports, exports, and backups

Imports and exports are processed locally. Prova can generate food-database and nutrition-log CSV files, plus full ZIP backups that may also include weight and steps depending on version. Water entries stay on-device and may not be included in every export format. Exports do not include a derived daily-summary CSV (daily totals come from your logs) and do not include your Gemini API key.

When you export or share, you choose the destination via the system share sheet. The developer does not automatically receive those files.

Optional connections to other apps

Connect other apps is off until you turn it on in Settings. You paste an address you control, usually a Cloudflare Worker you deploy yourself. Prova then uploads a Personal snapshot: food names, meals, targets, weight, steps, and water. Demo data is not included. The upload happens when Prova is open and online. It is not a live connection to the phone.

The remote copy is readable only with a token stored on your device. Stop sharing deletes that copy when the address is reachable, and removes the token from the phone. If Prova does not update the copy for 90 days, it expires. Whoever controls the address can read the snapshot. If that address is your own Cloudflare account, the developer does not receive the diary.

13. Widgets and local reminders

Home-screen widgets show a local snapshot of your diary or targets. They do not require network access for that display.

Reminders use on-device notifications (and may use exact-alarm capability where permitted). There is no developer push-notification server for these reminders.

14. Information not collected by the developer

The developer does not operate a backend that collects:

Limited content you submit for optional AI, Open Food Facts lookups you trigger, App Check attestation traffic, and (when offered) Play Billing purchase state involve third parties as described in this policy. Those are not a substitute for a Prova cloud diary.

15. Device capabilities used by Prova

Internet access does not mean Prova uploads your complete nutrition history to the developer.

16. External webpages and services

Prova may open external pages such as Google AI Studio, the Health Connect listing, Buy Me a Coffee (optional tips), and this Privacy Policy. After you leave Prova, those sites follow their own policies.

17. Data security

Prova limits exposure by keeping the diary local. Keys use secure storage. AI and Open Food Facts requests use HTTPS. No method is perfectly secure. Device compromise, OS backups, rooted devices, and apps you share exports with can affect security.

18. Data retention and deletion

Local data remains until you edit or delete it, import over it, clear app data, remove your API key, delete exports, or uninstall Prova.

Information sent to Google (Gemini / Firebase AI) or Open Food Facts may be retained under those parties’ policies. The developer cannot retrieve or delete data held only by those third parties on your behalf.

Because Prova does not host your complete diary on a developer server, the developer normally has no server-side nutrition history to access or delete. A copy you upload to an address you control is deleted from that address when you stop sharing, or it expires after 90 days without an update.

19. Children’s privacy

Prova is not directed toward children under 13 or below the applicable digital age of consent. Optional Google AI and Play features are also subject to Google’s eligibility rules.

20. Health disclaimer

Prova is a personal food and nutrition logging tool. It is not a medical device and does not diagnose, treat, cure, or prevent disease.

Calculations, scores, targets, trends, Health Connect-derived activity displays, and AI estimates are general information only, not medical or dietary advice. Verify important values. Consult a qualified professional before significant health decisions.

21. Third-party services

Each third party processes data under its own privacy policy and terms.

22. Changes to this Privacy Policy

This Privacy Policy may be updated when features, integrations, permissions, or data practices change. The “Last updated” date at the top will be revised when a new version is published.

23. Contact

Prova is developed and published by Rostom Baccar (RB Studio).

For questions about this Privacy Policy, contact:

rostombaccar.et@gmail.com