PANCAKE

Pancake

Privacy Policy

Last updated July 17, 2026

The short version

Pancake stores what you log on your device by default, and there is no Pancake account or server holding your training, food, photos, or Health history. Data leaves the device only for a backup you choose to save in your own iCloud Drive, App Store purchase processing, install/ad measurement signals with your permission, or an optional body scan you explicitly approve. Each is spelled out below.

What is stored on your device

Your profile (name and the body stats you enter), your training program and workout history, your bodyweight entries, your food log and saved foods, your progress photos, and any body-scan results are all saved locally on your iPhone using Apple's on-device storage. They stay on your device and in your device backups. Deleting the app removes them.

Backups

Pancake can save a backup of your data (your profile, training and workout history, bodyweight, food log, progress photos, and body-scan results) to your own iCloud Drive so you can restore it later. This happens automatically only if you turn on automatic backup in Settings; otherwise it runs only when you tap Back up now. These files live in your iCloud Drive in a folder named Pancake and sync across your devices. They are never sent to us. Because they sit in your iCloud Drive, anyone who can open your Files app or reach your iCloud account can read them, so keep your devices and Apple Account secured. “Delete all my data” also removes them.

Subscriptions

Pancake Pro is billed by Apple through your App Store account; we never see your payment details. To keep your subscription working, purchase receipts and transaction history are processed by RevenueCat, our subscription manager, tied to a random identifier rather than your name or email (we don't have those). You can manage or cancel anytime in the app's Settings, or in your App Store subscriptions.

Install and ad measurement

Pancake grows through TikTok videos and, later, ads. To see which of them actually bring people here, the app uses AppsFlyer, a measurement service. With your permission (the iOS tracking prompt), it collects device identifiers (like the advertising identifier), the rough location implied by your IP address, and a few anonymous app events (for example install, onboarding and paywall views, and trial start). These signals are shared with our ad partners (TikTok and Meta) only to measure and improve that marketing. If you decline the prompt, you get the exact same app, and measurement falls back to Apple's anonymous, aggregated system. You can change your answer anytime in iOS Settings under Privacy & Security → Tracking.

Apple Health

If you connect Apple Health, Pancake reads your bodyweight and heart rate to show your progress and tune your nutrition targets, and writes your finished workouts and bodyweight back to Health. This only happens with your permission and is handled by Apple's Health framework. Health data is never sent to us, never shared with ad partners, and never used for advertising. You can turn this off at any time in the Health app.

Camera and photos

The camera is used only when you choose to take a progress photo. Progress photos are stored on your device; they leave it only if you explicitly agree to run a body scan on one, or include them in a backup saved to your own iCloud Drive. If you add a photo from your library, it is read only when you pick it.

Body scan

Body scans are optional. When you explicitly agree to run one, Pancake sends the photo you chose, plus the sex, age, height, and weight in your profile and a random app-installation identifier, over an encrypted connection to Pancake's scan service. The service passes them to OpenRouter and Amazon Web Services, which runs Anthropic Claude through a zero-data-retention route. They process the data only to return body-fat and muscle-balance estimates. Pancake does not store the photo or profile fields on its server. Its rate limiter stores the random identifier and scan-attempt count for up to 48 hours. The AI route is configured not to retain the photo or prompt or use them for model training. The numbers returned are saved on your device. You can revoke future scan sharing in Settings without deleting results already on your phone. The results are rough estimates from one photo, not measurements or medical advice.

Food search

When you search for a food, the text you type is sent over a secure connection to Open Food Facts, an open nutrition database, to return matching results. The query is not tied to your identity, and we do not log it. Recipe images are loaded from TheMealDB.

What we do not do

No accounts. Pancake does not receive your training history, food log, progress-photo library, or HealthKit records. An optional backup goes to your own iCloud Drive, and an optional body scan sends only the photo and profile fields described above. Nothing of yours is sold or used to train AI models; ad measurement sharing is limited to the permission-based signals described above.

Deleting your data

You can erase everything Pancake has stored at any time from Settings, using “Delete all my data”. This also revokes body-scan permission and removes the random scan identifier from your phone. The scan service's short-lived rate-limit record expires within 48 hours. Data you wrote to Apple Health is removed in the Health app, since Health is the system of record for that. AppsFlyer measurement data expires on its servers and can be deleted on request via the contact below.

Children

Pancake is a general fitness app and is not directed at children under 13.

Not medical advice

Calorie targets, macro splits, and training suggestions are general fitness estimates, not medical or dietary advice. If you have a health condition, talk to a doctor or dietitian before changing your diet or training.

Contact

Questions about privacy? Email hey@heypancake.com.