eat well, beautifully
Privacy Policy
Last updated August 27, 2026
Mykonos is built by Henry Vantieghem ("we"). This page describes exactly what data the Mykonos iOS app handles and why. The short version: your journal belongs to you, we don't run ads, we don't sell or share your data, and we don't track you.
What we collect
- Account: your email address, an internal account identifier, and a password (stored as a salted hash by our authentication provider). Used to sign you in, prevent abuse, recover access, and sync your journal.
- Journal and user content: the foods, water, workouts, weight and body measurements, targets, plans, reminders, achievements, searches, feedback, and chat messages you choose to log. Stored on our backend (Convex) linked to your account so the journal can sync and survive a new device.
- Optional name: whatever you tell Myko to call you.
Photos and AI processing
- When you send a message or a meal photo, it is transmitted to our AI provider (Azure OpenAI) to produce the reply, the nutrition estimates, and the dish artwork.
- Meal photos can sync. A downscaled copy is kept on your device and, when account sync is active, in private object storage linked to your account. Access uses short-lived authenticated links. Removing an attachment or deleting your account removes the stored copy from active systems.
- Azure OpenAI processes API data under Microsoft’s enterprise service terms. We do not use journal content or images for advertising or to train our own model.
Apple Health
Health access is optional and controlled in Mykonos Settings and Apple Health. Mykonos reads only the body measurements and workouts you enable, including workout active energy. It can write nutrition, water, weight, and workouts that you deliberately log. We do not request steps, resting energy, nutrition-read access, or water-read access. Health information imported into your Mykonos journal is linked to your account and can sync through Convex; HealthKit itself remains controlled by Apple and your device. Health and fitness data is never used for advertising, sold, or shared with data brokers.
Location
- Nearby search: when you ask for nearby food, Mykonos requests one foreground location and uses it transiently with Apple MapKit. Your precise search origin and derived distances are not attached to chat, stored, or synced. Public place facts such as a venue name, address, phone number, website, and map coordinate may be saved with the answer so history and directions still work.
- Optional place-aware coaching: if you explicitly enable it, Mykonos can recognize meaningful visits using Apple’s low-power visit/significant-change services. It stores only a named, coarse location rounded to roughly a city block, not a continuous route. Coarse visits are linked to your account for sync and personalization, follow your visible retention setting, and can be exported or deleted in Settings.
Speech, notifications, and widgets
- Composer dictation is offered only when Apple’s on-device speech recognition is available. Audio is not retained or sent to our servers; the resulting text becomes journal content only if you send it.
- Reminders default off. Enabling a reminder is the only time Mykonos asks for notification permission. Reminder schedules and quiet hours are stored for app functionality; notification text is generated on device.
- Widgets receive only a minimal App Group snapshot. When access expires, personal values are redacted. Widget controls write one local action file for the authenticated app to acknowledge; no account credential is placed in the widget extension.
Subscriptions & payments
Mykonos Plus is billed by Apple through your App Store account — we never receive or store your card or payment details. We use Adapty to present products and verify subscriptions. Adapty receives an app-install/device identifier, device and OS information, the Mykonos account identifier used to reconcile access, paywall and purchase interactions, and purchase, renewal, expiration, refund, or restore events. It does not receive your journal, Health data, location history, chat text, or photos. Our backend stores the subscription state and valid expiration needed to enforce access. Subscription terms are in our terms of use.
Referral fraud prevention
When you ask to redeem a referral discount, the app sends Apple's signed AppTransaction proof to our backend. Apple's official verification library validates that proof for Mykonos. We do not store the signed proof or Apple's raw app-transaction identifier. We store only a keyed, non-reversible digest, whether it came from Production or Sandbox, and verification/redemption timestamps linked to your Mykonos account. Sandbox and TestFlight proofs never consume live offer codes. This processing prevents one Apple Account from claiming limited one-time referral codes through multiple Mykonos accounts.
What we don't do
- No advertising, no ad networks, and no cross-app tracking — we never ask for tracking permission and never share your data with data brokers.
- No selling or renting of your personal data — ever.
- No contacts, advertising profiles, continuous location routes, or data the app does not visibly use.
Where data lives
The SwiftData journal stays in the app’s private container on your device (and may be included in device backups). Synced journal records and coarse visits are stored on Convex; synced image attachments use private object storage; AI requests are processed by Azure OpenAI; subscriptions are managed through Apple and Adapty; nearby place results come from Apple MapKit. These providers handle only the data needed for the functions described above. We do not use tracking domains or advertising SDKs.
Deleting your data
In the app: open the journal → Settings → Account → Delete account. This removes your account, synced journal, attachments, agent schedules, coarse location history, achievements, and subscription-linking record from active systems, clears local account data and widget handoffs, and cancels pending reminders. To prevent delete-and-recreate referral abuse, we retain only the keyed, non-reversible Apple app-transaction digest, its Production/Sandbox environment, hash version, and deletion time; it is no longer linked to your deleted Mykonos account. Apple purchase history and HealthKit records remain under Apple’s controls. Any residual copies in routine encrypted backups age out on our normal backup cycle. Details: account deletion. Prefer not to use the app? Email us from your account address and we'll erase your data within 30 days.
Your rights
You can request a copy, correction, or deletion of your data at any time at vantieghemhenry@gmail.com. EU/EEA users: the legal basis for processing is performance of contract (running your journal); you may lodge complaints with your local supervisory authority.
Children
Mykonos is not directed at children — under 13 in the US, or the minimum digital-consent age in your country — and we do not knowingly collect their data.
Changes
If this policy changes materially we'll note it here with a new date.