Privacy Policy — Luko
This Privacy Policy explains how we collect, use, share, and protect information when you use the Luko iOS app and related services (the “Service”).
Previous version: August 17, 2026
1. Who we are
Luko is a consumer wellness app focused on food logging and personal nutrition targets. You can complete onboarding, set a calorie/macro plan, log meals (photo, text, or voice description), see an AI note after a log, generate recipe ideas, unlock Adventure companions as you log, and manage your profile in Settings.
Luko is not a medical device and does not provide medical advice, diagnosis, or treatment.
This version does not include workout/fitness tracking, a daily context/condition journal, AI chat or voice coaching, or paid subscriptions. If we add those later, we will update this Policy.
2. Information we collect
A. Account & identity
When you create or sign in (via Clerk and supported sign-in methods), we may collect name, email address, authentication identifiers/tokens, and account settings (e.g., timezone). After onboarding, we ask you to create an account so your plan and logs can be saved.
B. Profile & wellness information you provide
During onboarding and in settings, you may provide age/birthday, sex, height, weight, goals (lose/maintain/gain), activity level, pace, dietary preferences, allergies, and disliked foods. This may be treated as health-related personal data under some laws. We use it to personalize calorie/macro targets.
C. Food-logging content
Meal photos (camera or photo library), typed or spoken meal descriptions, structured meal logs, estimated calories/macros, meal history, and optional AI follow-up text/audio about a logged meal (“honest summary”).
D. Recipe ideas
If you use Plan my meals / recipe ideas, we send your request (and any extra note you type) to our servers so we can return suggested meals.
E. Adventure progress
Companion unlock progress, map progress, and related Adventure state are stored on your device in this version so you can keep Stars / Companions as you log meals. If we sync Adventure later, we will update this Policy.
F. Device & technical data
Device type, OS/app version, diagnostics needed to operate and secure the Service, push notification tokens (if enabled), and local preferences on device.
G. Analytics (PostHog)
We send product-usage events to PostHog (for example: app opens, onboarding steps, meal-log funnel, which settings were changed — not their values). We also store categorical onboarding answers as PostHog person properties: main goal, secondary goals, goal pace, activity level, sex, and self-reported install source.
We do not send to analytics: your name, age, height, weight, target weight, message/chat content, meal photos, or voice transcripts. Session replay (screen recording) is disabled.
PostHog may receive a technical identifier and, by default, IP address used to infer an approximate region (not precise GPS).
H. Advertising measurement (AppsFlyer)
AppsFlyer measures which ads or campaigns led to your install and a small set of campaign events (registration completed, onboarding completed, and a meal logged). Meal-log events sent to AppsFlyer do not include meal photos, descriptions, or nutrition values. That is “tracking” under Apple’s rules: it can link data from Luko with data from other companies’ apps or sites for ad measurement.
On iOS we show Apple’s App Tracking Transparency prompt. If you allow it, AppsFlyer may use the advertising identifier (IDFA). If you decline, the app works the same; attribution falls back to Apple’s SKAdNetwork (delayed, aggregate, no user-level IDFA). We may still set an AppsFlyer customer user ID after you sign in (your account ID) for attribution matching.
We do not show third-party ads in the app in this version.
I. Permissions (iOS)
| Permission | Purpose |
|---|---|
| Camera | Scan meals |
| Photo Library | Choose meal photos |
| Microphone | Voice meal descriptions (optional). Speech is on-device when the device supports it; otherwise it may use Apple’s speech service |
| Speech Recognition | Turn speech into a meal description you can edit before sending |
| Notifications | Optional habit reminders |
| Motion | Optional: make Meal tokens tumble when you tilt or shake your phone. Motion stays on device |
| Tracking | Optional: measure which ads brought you to Luko (AppsFlyer). Declining does not change how the app works |
You can change permissions in iOS Settings.
J. Children
We do not knowingly collect personal information from children under 13 (or the minimum age required in your country). Contact us to request deletion if needed.
3. How we use information
We use information to:
- provide the Service (account, plan targets, meal logging, recipe ideas, Adventure progress, history, settings);
- analyze meals with AI to estimate nutrition and, after a log, generate a short spoken/text note;
- authenticate and secure accounts;
- send optional push reminders you opt into;
- understand product usage and improve reliability (PostHog);
- measure advertising campaigns (AppsFlyer);
- comply with law and enforce our Terms.
We do not sell your personal information. This version does not process payments or subscription data.
4. AI processing
When you log food by photo, text, or voice, relevant content may be sent to our servers and/or subprocessors so we can return nutrition estimates. After you confirm a log, we may generate a short AI note (text and, on iOS, spoken audio). Recipe-idea requests are also processed by AI.
Outputs are estimates and may be inaccurate. Do not rely on them for medical decisions.
5. How we share information
We may share information with:
- Service providers under contracts that limit use to serving us: hosting, Clerk (authentication), AI providers (meal analysis, honest summary, recipe ideas), PostHog (product analytics), AppsFlyer (install and campaign measurement), support;
- Apple for Sign in, speech recognition (if used), App Store operations, and SKAdNetwork attribution;
- legal/safety recipients when required by law or to protect rights, or in a merger/acquisition (with notice where required).
We do not share meal photos or health profile data for third-party advertising. AppsFlyer receives account identifiers and campaign events (including that a meal was logged) for ad measurement, not meal photos, meal descriptions, or body metrics.
6. Retention
We keep information while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. Delete your account in-app (Settings → Accounts → Delete My Account) or by emailing us; we will delete or anonymize personal data except where law requires retention. Analytics and attribution vendors retain data under their own retention settings.
On-device Adventure progress is removed when you delete the app or account data on the device.
7. Security
We use reasonable administrative, technical, and organizational measures (including encrypted transit and access controls). No method of transmission or storage is 100% secure.
8. Your choices & rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent.
- Account deletion: Settings → Accounts → Delete My Account, or email us from your account email.
- Tracking: decline Apple’s tracking prompt, or later iOS Settings → Privacy & Security → Tracking.
- Notifications, camera, photos, microphone, motion: iOS Settings.
- Sign out: Settings → Accounts.
9. International transfers
We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards.
10. Changes
We may update this Policy when features or data practices change. We will post a new last-updated date. Continued use after changes means you accept the updated Policy where permitted by law.
11. Contact
hu@zentarilabsinc.com
Zentari Labs Inc.
650 California St, Fl 7
San Francisco, CA 94108