Privacy and data

Your records stay local by default.

This policy reflects a code review of LessBite Flutter 1.0.0+2057 and the current website.

Last updated: 2026-08-23

Code review baseline: LessBite Flutter 1.0.0+2057; reviewed AndroidManifest, Info.plist, dependencies, step reads, notifications, LAN transfer, exports, local database, and backup implementation.

Summary and operator

Operator: Zhile. LessBite does not require an account. Plans, weight, habits, steps, light activity, achievements, Craving SOS, and pattern records stay on the device by default. The app contains no analytics, advertising, crash-reporting, attribution, or tracking SDKs. Website analytics are separate from app data.

Website analytics

This website loads Google Analytics only after a visitor gives explicit consent, to understand anonymized page visits and website use. Declining means Google Analytics is not loaded. Visitors can clear the lessbite_analytics_consent local-storage item to choose again. Google may process device, browser, approximate-location, and visit-event information under its policies. LessBite never sends in-app records to Google Analytics.

Android permissions

Android declares only Health Connect READ_STEPS for health access. Step sync is initiated through use of the app: after authorization, it runs only when the user opens or returns to relevant screens or taps Sync, never as an independent background health task. LessBite does not write health data. Notification, alarm, and reboot declarations support local reminders and test notifications. INTERNET is used only when the user actively transfers an encrypted .lbk backup over the local network between devices on the same Wi-Fi.

iOS permissions

The current iOS release has no HealthKit or Apple Health integration; steps are manual only. The camera is used only if the user switches to camera during the system file-selection flow. Photo Library Read is used only when the user opens the system photo picker. Photo Library Add is used only when the user saves a trend or share card. Local Network is used only when the user initiates an encrypted backup transfer over the LAN. Notification permission supports the app’s implemented local reminders and test notifications. Each access is triggered by user action; an operating-system usage declaration is not data collection by LessBite.

Network and data use

LessBite has no account service. App records stay on the device by default and are not automatically sent to LessBite or third-party servers. Data moves only after the user selects a system share destination, exports a file, or starts a local-network transfer.

Export and backup

The user can export CSV, Excel, share cards, or encrypted .lbk backups; import through the system file interface; or transfer an encrypted backup on the same Wi-Fi. LessBite does not store the backup password, so a forgotten password cannot be recovered. The user chooses the file location, app, or device that receives exported content.

Retention and deletion

App records remain on the device until the user deletes records or plans in the app, or the operating system removes local app data, such as on uninstall. LessBite has no account or server copy to delete on the user’s behalf. Exported backups, spreadsheets, and images remain wherever the user saved them and must be deleted there by the user.

Children

LessBite provides no accounts and does not knowingly collect children’s personal data on a LessBite server. If a child uses the app, a parent or guardian should supervise use and manage every export or share action.

Contact

Operator: Zhile. For privacy or support questions, contact support@lessbite.com. Never send a backup password or .lbk file to support.

Policy changes

Changes to this policy will be posted on this page and the “Last updated” date will be revised. Review the current version before exporting or transferring data.