The short version

ProteinMate has no Pandaware account system, application-backend database, analytics server, or advertising server. During normal use, ProteinMate does not upload your nutrition history, Apple Health data, settings, templates, Watch state, or diagnostics to Pandaware-operated servers. ProteinMate app data stays in Apple Health, Apple’s private iCloud/CloudKit services associated with your Apple Account, or protected storage on your Apple devices. The exceptions are user-initiated sharing or export and support email; recipients and email providers may retain what you send.

1. Scope and who we are

This Privacy Policy applies to ProteinMate for iPhone and iPad, its Apple Watch companion, and its WidgetKit widgets and complications (together, “ProteinMate” or “the app”). ProteinMate is provided by Pandaware LLC (“Pandaware,” “we,” “us,” or “our”).

This policy describes the current app implementation. Apple’s handling of Health, iCloud, WatchConnectivity, notifications, and device backups is governed by Apple’s own terms and privacy policies, separately from this policy.

The companion static website has no JavaScript, analytics, advertising, tracking pixels, cookies, or forms added by Pandaware. GitHub Pages may process request data under GitHub’s own terms; this policy does not make claims about the host’s operational logs.

2. Apple Health and nutrition information

With the Apple Health permissions you grant, ProteinMate can read dietary energy consumed and dietary protein to show progress and history, write the calories and protein you confirm, read active energy burned to optionally adjust your calorie allowance and show a read-only Health entry, and read resting energy and body mass when you enable automatic goals. ProteinMate does not request unrelated HealthKit categories.

HealthKit is the source of truth for nutrition history, including calories, protein, entries, and intake times. If HealthKit is unavailable or access is not granted, ProteinMate does not create a substitute local nutrition-history database. You can review or change HealthKit access in Apple’s Health app.

ProteinMate uses an opaque, app-generated entry-link identifier and Health sync metadata to recognize entries it created, so it can edit or delete them safely. Entries created by other sources are read-only where the app supports them.

3. Settings, templates, and local app data

ProteinMate processes the settings you choose, including goals, automatic-goal choices, burned-calorie and thermic-effect options, calorie unit, palette, tracking-day boundary, reminders, badges, and other presentation preferences. These settings are used to provide the features you enable. Reminders and badges use iOS’s local notification and application-badge mechanisms; ProteinMate does not use remote notifications for this purpose.

When you name or decorate an intake, ProteinMate may store the template name, selected emoji, optional emoji background color, an opaque entry-link identifier, and a metadata update time. These are presentation metadata and are not a replacement for nutrient values or intake times in Apple Health.

Protected device-local storage contains app preferences, a local copy of presentation metadata, widget and Watch snapshots, and a bounded Watch delivery queue. These local files are requested to be excluded from device backups where the operating system permits. iOS and Apple backup services control final backup behavior.

4. Apple iCloud and CloudKit storage

On signed Apple-device builds, ProteinMate may use Apple’s private CloudKit database for app-generated entry-link ID, optional template name, optional emoji, optional emoji color, and an updated time. This private metadata does not contain nutrient quantities or intake timestamps. It is associated with your Apple Account through Apple’s private iCloud services and is not a public post or Pandaware database.

ProteinMate may mirror this exact bounded set of preferences through Apple’s iCloud Key-Value Store: protein and calorie goals, burned-calorie policy, deficit, thermic effect, calorie unit, palette, day start, and automatic protein and calorie choices. Other preferences and the local app state described above remain on the device. Apple controls the operation and lifecycle of these services under Apple’s policies.

5. Widgets and Apple Watch

iOS widgets and Watch complications read local aggregate snapshots to show progress. The iOS widget snapshot contains aggregates only. When a Watch is paired, WatchConnectivity can deliver current progress and a bounded recent set of app-created entry details to the Watch, and the Watch can queue an intake change for the iPhone to process through the existing HealthKit write path. This transport state is kept in protected local App Group storage; the queue is not authoritative nutrition history.

The Reset action clears app preferences, presentation metadata, mirrored preference keys, widget snapshots, and Watch display snapshots. If a Watch mutation has not yet been acknowledged, Reset may retain that mutation—date, calories, protein, name, emoji, and color—together with delivery IDs until it is safe to acknowledge and remove it. This is a bounded delivery safeguard to prevent duplicate writes, not a separate history store.

6. Sharing, links, and diagnostics

ProteinMate does not publish your data automatically. When you invoke a system Share action, you choose the recipient app or person. A Home progress image can include current calorie and protein progress and goals. An intake share link can include calories, protein grams, an optional template name, emoji, and emoji background color. It does not include the entry UUID or date. The link is Base64-encoded JSON, not encryption, so anyone who receives it may be able to inspect it.

Opening an intake link only pre-fills ProteinMate’s editor; the recipient must confirm before anything is written to their Apple Health. A recipient’s app, messaging service, email provider, or cloud storage may retain what you send. If you use Handoff, its activity payload contains only the selected destination and a schema version, not nutrition values, goals, dates, identifiers, templates, or drafts.

If you request support or send an email to contact@pandaware.us, Pandaware receives the address, message, and attachments or other information you choose to include. Email providers may process and retain that exchange under their own policies. A user-initiated diagnostic export, where offered by a development or support build, may contain local settings, identifiers, build and runtime details, and Watch state; the current report intentionally omits HealthKit-derived values. Review it before choosing a share destination.

7. How information is used and disclosed

The app uses information on your devices and through the Apple services you enable to provide, maintain, and secure the features you request. Pandaware uses support messages to respond to you and handles them as described above. Pandaware does not sell your information, serve ads, use nutrition data for cross-app tracking or data-broker profiling, or share normal app data with another person unless you direct a share or ask for support.

ProteinMate contains no third-party advertising, analytics, or tracking SDKs, and Pandaware does not operate an analytics server. Apple frameworks and services—including HealthKit, CloudKit/iCloud, WatchConnectivity, WidgetKit, App Intents, UserNotifications, TestFlight, and App Store Connect—may process information as needed for their operating-system and distribution functions under Apple’s policies.

Apple analytics and diagnostics

When you enable Apple’s “Share With App Developers” analytics choice, or participate in TestFlight where Apple applies separate diagnostic sharing rules, Apple may provide Pandaware with aggregated or otherwise non-personally-identifying usage and diagnostic reports relevant to ProteinMate. Depending on availability and Apple’s privacy thresholds, these reports can include App Store discovery and downloads, sessions, retention, app and widget usage, Shortcuts action runs, crashes, and technical performance. Apple also provides operational telemetry for the private CloudKit container, such as request counts, errors, latency, bandwidth, and storage use.

ProteinMate does not deliberately add nutrition values, Apple Health samples, goals, template content, entry identifiers, or intake times to analytics events. Pandaware uses Apple-provided reports only to improve ProteinMate, diagnose crashes and performance, and understand adoption of Apple-provided features. We do not use them to identify a person or device, combine them with Health data, sell them, or provide them to an external analytics service.

TestFlight beta builds follow Apple’s separate beta rules. Apple automatically shares TestFlight crash logs with Pandaware regardless of the tester’s device analytics setting. For an email-invited tester, Apple may associate session, crash, device, and submitted-feedback information with the TestFlight invitation. Feedback a tester chooses to submit may include comments, screenshots, and device or runtime details. ProteinMate does not add nutrition values or Apple Health records to that feedback.

8. Your choices

9. Retention and deletion

Nutrition entries written to Apple Health remain there until you or Apple Health removes them. ProteinMate’s Reset action does not delete Apple Health entries. When you edit or delete an app-created entry, the app attempts to update or remove the corresponding Apple Health samples after Apple confirms the operation.

Reset removes app-owned local preferences, presentation metadata, mirrored bounded preference keys, and rendered widget and Watch display snapshots. It may retain an unacknowledged Watch mutation and its delivery IDs as described in section 5. Support email is retained only for as long as reasonably needed to respond, maintain support history, resolve disputes, and meet legal obligations.

Apple controls the lifecycle of data in HealthKit, CloudKit, iCloud Key-Value Store, and device backups. If a device or older installation leaves data you believe should be removed, email contact@pandaware.us with enough detail for us to investigate. Do not include more health information than necessary.

Apple controls retention of analytics and diagnostic information within App Store Connect, TestFlight, Xcode, and CloudKit Console. Pandaware does not maintain a separate analytics database. If we download an Apple report to investigate a specific problem, we retain it only as long as reasonably needed to complete that investigation and maintain necessary support or security records.

10. Privacy requests

Depending on where you live, you may have rights to ask for access to, correction of, or deletion of personal information Pandaware handles, or to object to certain uses. Email contact@pandaware.us with your request. We may need to verify your identity. HealthKit and iCloud data controlled by Apple must be managed through Apple’s settings and services; Pandaware cannot directly delete your Apple Health records.

11. Security

ProteinMate relies on Apple’s protected HealthKit and iCloud mechanisms, protected local file locations, atomic local updates, and system share controls. No storage or transmission method is guaranteed to be completely secure. Keep your devices, Apple Account, and operating systems protected, and review recipients before sharing.

12. Children’s privacy

ProteinMate is not directed to children under 13, and we do not knowingly ask children to create an account or provide information directly to us. If you believe a child has contacted us or sent personal information, please contact us so we can review the request.

13. Changes to this policy

We may update this policy when ProteinMate’s features, data flows, or legal obligations change. The “Last updated” date at the top will change with a new version. If a change is material, we will provide additional notice where appropriate.

14. Contact us

Questions, requests, or concerns about this policy can be sent to contact@pandaware.us. Return to the ProteinMate home page.