Privacy
Last updated 9 October 2026
Trofelo tracks what you eat, the supplements you take and how you feel, so what you put in it is health data. This page says in plain words what Trofelo stores, how it's protected and what leaves the server.
- The app's database holds no names or e-mail addresses.
- Your notes and all backups are encrypted.
- No ads, no trackers, nothing sold. No cookies on this website.
- Export your data whenever you like, or ask us to delete it.
This website
trofelo.com sets no cookies, runs no analytics and loads nothing from other websites. It keeps no log of your visits.
Your account
You sign in through Trofelo's own sign-in service, which runs on Trofelo's server. It holds what you sign in with: your e-mail address and name, and a password or passkey, or the link to your Google account if you choose Continue with Google.
The app's database, where your diary lives, holds none of that. There, your account is only a code made from your sign-in with a secret key. That key is kept apart from the database and its backups, so a copy of the database alone can't be traced back to you.
What the app stores
What you put in: the supplements you take and their doses, the food and meals you log, your weight, how you rate your days and what was going on (sick, poor sleep, alcohol), your notes, and what your targets are worked out from: sex, year of birth, height, activity, goal and the region you choose. Only you see these.
Your notes are encrypted with a key of your own. The rest is protected by not being linked to you, rather than encrypted.
What's shared with other people using Trofelo
Products are shared, so nobody has to scan the same thing twice. When you add a product, its name, brand, barcodes, nutrition label and label photo become known to everyone using Trofelo. Label photos are stored without the place and time they were taken. Whether and how much you take or eat of a product stays yours.
Research summaries about nutrients are shared too. They're about nutrients, not about anyone.
What leaves the server
- Barcode lookups. A barcode Trofelo doesn't know yet is looked up at Open Food Facts and UPCitemdb. Only the barcode's digits are sent.
- Labels online. To find a product's label on the web, its name and barcode are searched on DuckDuckGo, and the pages found are fetched.
- Reading labels. Label photos, and the label text from product pages, are read by an AI model through OpenRouter. Only the label goes there, never your account or your diary.
- Research. Trofelo asks PubMed for studies about the nutrients in people's products and has an AI model summarise their abstracts. These requests are about nutrients, never about you.
- Sharing with Open Food Facts. After you save a product that Open Food Facts doesn't have, the app offers to add it there. Only if you tap Share are its name, brand, nutrition values and photos sent, under Open Food Facts' open licences.
- Google. Only if you choose Continue with Google when you sign in.
Where it's kept
On a server Trofelo rents from OVHcloud, reached only over HTTPS. A backup is made every day, encrypted before it's stored, and kept for two weeks. The key that opens the backups isn't on the server.
No ads, nothing sold
Trofelo shows no ads, has no trackers or analytics in the app, and doesn't sell or hand over your data to anyone.
Your data, your call
- Export: in the app, You › Settings › Export gives you your data as CSV files.
- Delete: write to hello@trofelo.com from the address you signed up with, and your account and everything in it will be deleted.
Changes and questions
If anything here changes, this page changes with it, with a new date at the top. Questions are welcome at hello@trofelo.com.