Track & Table
Privacy Policy
Last updated August 2, 2026
The short version
Track & Table (“we”, “us”) is a diet companion for people who eat out in NYC. To run the product we collect account info, the health and food data you give us, your chats with the companion, and product analytics — including session replays. We don’t sell your personal information. This policy is written for a US audience (we’re focused on New York City for now).
Using the app means you agree to this policy and our Terms of Service.
What we collect
Account. Email, name, profile photo if you add one, and sign-in details (e.g. Google OAuth or one-time email codes).
Health & diet profile. Things you enter in onboarding or later — goal, height, weight, birth year, sex, activity level, dietary preferences, allergies, and related preferences we need to build your calorie budget.
Usage of the product. Food and workout logs, plans, restaurant searches and recommendations, companion chat messages (including photos you send), memories the companion saves, notification settings, and similar app data.
Location (optional, contextual). When you choose to share it (for nearby restaurants/gyms), we process approximate or precise location as needed for that feature. We don’t require location at signup.
Device & technical data. Browser/app type, rough device info, IP address (as handled by our hosts and analytics), pages viewed, and diagnostic events.
Analytics & session replay. We use PostHog for product analytics. That includes event tracking (what you click/do in the product) and session replays — recordings of interactions with the app UI so we can fix bugs and improve the experience. Replays may capture on-screen content you interact with in the product. We also use error monitoring tools that may receive crash/diagnostic data.
Communications. Emails we send you (sign-in codes, product notes) and messages you send us for support.
How we use it
- Provide the companion, calorie budget, recommendations, and logging features
- Personalize the experience (your goals, allergies, preferences, history)
- Run AI models that power chat and recommendations — which means sending relevant prompts and context to model providers
- Send transactional email and optional push notifications you enable
- Understand product usage, debug issues, and improve the app (including via PostHog analytics and session replays)
- Keep the service secure, prevent abuse, and enforce our terms
- Comply with law when we’re required to
Who we share with
We use service providers that process data on our behalf so the product works. Typical categories:
- Hosting & database (application hosting, Postgres)
- AI / model providers (to run the companion and related features)
- Analytics — PostHog (product analytics and session replays)
- Error monitoring (crash and performance diagnostics)
- Email delivery (sign-in codes and product email)
- Object storage (photos and uploads you send)
- Auth / identity (e.g. Google sign-in if you choose it)
We don’t sell your personal information. We may disclose data if required by law, to protect rights and safety, or as part of a merger/acquisition with appropriate notice where required.
Cookies & similar tech
We use cookies and local storage for sign-in sessions, preferences, and analytics (including PostHog). That’s how we keep you logged in and understand how the product is used. Session replay is part of that analytics stack.
Retention
We keep your data while your account is active and as long as needed to provide the service. If you delete your account, we remove associated personal data we control from production systems, with limited residual copies that may linger briefly in backups or logs before they rotate. Analytics vendors may retain events according to their own retention settings.
Your choices
- Access / update. Edit profile and preferences in the app.
- Delete. Delete your account in Account settings — that wipes the data we hold for you (see Retention).
- Notifications. You can decline or turn off push; email sign-in codes are required to log in with OTP.
- Location. Only share when a feature asks and you choose to.
- Questions / requests. Email legal@tracktable.app.
We’re a US product focused on NYC for now. If that expands, we’ll update this policy.
Security
We use reasonable technical and organizational measures to protect your data. No system is perfectly secure; use a strong unique approach to account access and tell us if you suspect unauthorized use.
Children
The service is for adults (18+). We don’t knowingly collect personal information from children. If you think a minor created an account, contact us and we’ll delete it.
Changes
We may update this policy. We’ll change the “Last updated” date above. Continued use after an update means you accept the revised policy. For meaningful changes we may also surface a note in the product.
Contact
Privacy questions: legal@tracktable.app.