Tavo — Privacy Policy

Last updated: 22 September 2026

Tavo is a food and weight diary. It is built so that your diary stays on your own phone. This policy explains, in plain language, what is stored, what is sent, and to whom.

Tavo is operated by Athena Consulting & Overseas, a proprietorship of Akshay P.R. Tripathi.
Contact: support@tavofitness.in

Health information

Tavo is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a healthcare professional for medical advice, diagnosis, or treatment.

Your diary never leaves your device

Everything you log — meals, weights, your name, height, age, targets, and every number Tavo calculates from them — is stored only in your device's local storage. There is no account, no sign-in, and no Tavo server that holds your diary. We cannot see it. If you uninstall the app or clear its data, that diary is gone, and we have no copy to restore it from.

Android's own cloud backup is switched off in the app, so Android does not copy your diary to Google Drive behind your back. The only copies that exist are the encrypted backup files Tavo writes: the ones you make yourself, and — if you turn them on — the automatic backups described below.

Backups you make yourself

The Backup feature writes an encrypted .tavo file to a location you choose. It is encrypted on your device with AES-GCM-256 using a key derived from your passphrase (PBKDF2-SHA256, 600,000 iterations). The passphrase is never stored — not in the file, not on the phone, not by us. If you lose it, the file cannot be recovered by anyone, including us.

Automatic backups

Automatic backup is optional, and it is off unless you turn it on in the Android app's Settings. When you turn it on, you pick a destination folder through Android's own system picker, and the first backup is written straight away. That can be a folder on your device, or a folder that an app such as Google Drive or OneDrive keeps synced for you — if you pick a cloud-synced folder, the syncing is done by that app, under your own account and that provider's terms. Tavo itself connects to no cloud service, holds no account, and is granted access to that one folder only.

Each automatic backup is the same encrypted .tavo file, encrypted on your device before it is written. So that backups can run quietly without asking for your passphrase each time, the key derived from your passphrase is stored on your device for automatic backups. The passphrase itself is still never stored — not on the phone, not in the file, not by us. We still receive nothing and can decrypt nothing: an automatic backup never touches a Tavo server, and a copy synced to your own cloud folder is encrypted with a key only you can recreate.

Photos and the AI features

Tavo can read a nutrition label or estimate a plate from a photo. This is the one feature that sends data off your device, and it only runs when you tap it.

The photo, and any text you typed with it, is sent to Tavo's server, which passes it to Anthropic, our AI provider, for processing. Anthropic is located outside India, so this is a cross-border transfer, and their handling is governed by their own terms. Your device identifier is not passed on to Anthropic; it stops at Tavo's server.

Tavo's server records one short line per request — the time, the feature used, and whether the request was allowed — so that the free daily allowance can be enforced. That line does not contain your device identifier. A separate daily counter is kept against a random device identifier for the same purpose. That count is not linked to your diary, your name, or anything you have logged. Clearing the app's data generates a new identifier. Server logs are retained per our host's standard policy (Netlify).

Neither the request line nor the counter records your diary, your name, or anything you have logged. The photo is never stored on our side, and it is never stored in your diary as sent — only a small thumbnail is kept, on your device, alongside the entry.

If you supply your own Anthropic API key in Settings, requests go from your phone straight to Anthropic. They do not pass through Tavo's server, no device identifier is sent, and we log nothing at all.

The device identifier

On first use, Tavo generates a random identifier and keeps it on your device. It is not derived from your phone, your SIM, your Google account, or anything about you, and it is not an advertising ID. It is sent only with AI requests, only on the free tier, and only to count them. Clearing the app's data generates a new one.

Permissions

The Android app requests exactly two permissions: Internet, for the AI features, and Camera, which is optional and is used only to open your phone's camera when you choose to photograph a label or a plate. Tavo does not open a camera stream, does not record video, and does not access your photo library beyond the single file you pick.

Third-party services

Tavo contains no advertising, no advertising SDK, no social login, and no third-party tracker beyond those named here.

Children

Tavo is not directed at children under 13 and we do not knowingly collect information from them.

Your rights and deleting your data

Because your diary is only on your device, you delete it yourself: clear the app's data, or uninstall it. To request deletion of anything on our side — limited to the request lines and counters described above — write to support@tavofitness.in and we will act within 30 days.

Step-by-step instructions, and the full list of what is deleted and what is kept, are on a separate page: how to delete your data.

Under India's Digital Personal Data Protection Act, 2023, you may ask us what we hold about you, ask for it to be corrected or erased, and raise a grievance with us at support@tavofitness.in.

Changes

If this policy changes materially, the updated version will be posted here with a new date, and the change will be noted in the app.