Basil

Privacy Policy

Pastmaps LLC · Last updated September 17, 2026

The short version

Basil is a nutrition coach you talk to. Your journal, your plan, your conversations, and your memories are stored in a database on your phone, and in your phone's backups if you have them turned on. There is no account, and no server of ours stores your food diary — the exception is a bug report you choose to send, described below.

To answer you, Basil sends what the answer needs to an AI provider. It also sends usage analytics, which never include your conversations or health data. This policy says exactly what goes where, and to whom.

Basil is for adults 18 or older. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition.

Where your data is stored

Your journal and meal entries, your plan and the profile behind it, your chat history, the things Basil remembers about you, your weigh-ins and imported health readings, and your profiles and their PINs all live in a local database on the device. We do not receive a copy of that database, and we cannot read it.

That database is part of your phone's normal backups. If iCloud Backup is on for your iPhone, or Google backup for your Android phone, the backup includes Basil's database — including readings imported from Apple Health or Health Connect. Those backups are stored by Apple or Google under their terms and controlled by you; we cannot access them. You can manage what is backed up in your phone's backup settings.

Deleting the app deletes the database on the phone, but not copies already in a backup. Settings has Export and Import if you want to keep a copy of your own.

What Basil sends, and to whom

To generate every reply, Basil sends your messages, your food photos, what you have logged, and the journal entries the model reads while working something out to OpenRouter, which routes the request to an AI model provider — including Google. If you connect Apple Health or Health Connect, every request also includes your latest weight, body-fat percentage, height, lean mass, and an estimated daily energy expenditure. Other connected health data is included when relevant to the answer. If you enable Basil reaching out, recent meals, calorie totals, weigh-ins, synced health metrics, memories, and recent chat are also sent to plan proactive notifications, even when you have not asked for a reply.

Basil can also look things up on the web. Search queries composed by the model are sent through OpenRouter to Exa. Web search is always on.

When you scan a barcode, the barcode number is sent to Open Food Facts to look up the product. The direct connection also exposes network metadata such as your IP address.

When you send a bug report, it goes to a small Cloudflare Worker, which stores nothing and turns it into an issue in our private GitHub repository. By default a report includes the last 10 minutes of your conversation and the app's technical logs; you can change the conversation window or turn either off. A journal snapshot — a week of totals, your body measurements (including readings imported from Apple Health or Health Connect), your plan and profile, and everything Basil remembers — is included only if you turn it on. The full assembled report is available to review before you send it.

Reports are kept as GitHub issues until we delete them. They are read by us and by OpenAI Codex, an automated coding assistant that triages each report and may propose a fix. To have a report deleted, write to us at the address below.

Retention and training by AI providers

OpenRouter and the model providers it routes to handle your requests under their own policies, which you can read at openrouter.ai/privacy. Every request Basil sends asks OpenRouter to route only to providers that do not train on inputs (OpenRouter's data_collection: deny setting). Providers may still retain requests for a time under their own policies; Basil does not currently require zero-retention routing, and will say so here if that changes.

This limit applies with particular force to web search: OpenRouter's retention and training controls do not extend to plugins and tools, so anything sent to Exa is governed by Exa's terms regardless of what is pinned for model routing.

We do not sell your information, and none of it is used for advertising.

Health data (Apple Health and Health Connect)

Basil automatically syncs weight, body fat, height, lean body mass, activity (steps, distance, exercise, and calories burned), sleep, and resting heart rate from your phone’s health app: Apple Health on iPhone, Health Connect on Android. On iPhone, Basil also reads workout sessions automatically to calculate daily exercise totals. When you ask, Basil reads workout details for a date range. It reads nothing else.

This health data is included in what Basil sends to OpenRouter and the AI model selected to generate your replies. It is never used for ads or sold.

Turn this off at any time with Disconnect in Settings. You can also change what Basil may read in the Health app on iPhone or in Health Connect on Android.

Basil only reads from Apple Health — it requests authorization with an empty write set and never saves anything back. Imported readings are stored in Basil's database on the device, which is included in your phone's backups as described above.

Product analytics and reliability

Basil sends product-usage and basic reliability events to Statsig automatically. Analytics is always on in configured production builds and has no in-app switch. Events measure app visits, feature use, health-service connection status, weigh-in and plan-save actions, weekly-review starts, and notification frequency and opens. They do not include your conversations, photos, weight or other health measurements, plan contents, or notification text.

Statsig receives a randomly generated persistent installation identifier, event times, app/build version, operating system, hardware model, locale, and technical failure categories. Direct connections also expose your network IP address to Statsig. The random identifier lets us estimate repeat use and retention; it is separate from the identifier used for support reports and is not your name or a health-profile identifier. This data is pseudonymous, not fully anonymous.

Basic JavaScript crash reporting sends a minimal failure marker on the next app launch. It does not upload crash-log contents, error messages, or stack traces. The Disconnect control above stops health-data sharing with the coach; it does not disable product analytics.

Your choices

Withdraw consent for sharing with the AI at any time with Stop sharing with the AI in Settings. Basil returns to its first screen, clears the conversation history it sends to the AI, and sends nothing further until you accept the disclosure again; your journal, plan, and memories stay on the device.

Withdraw consent for health sharing at any time with Disconnect in Settings, which purges the health data Basil imported and clears the AI request history that may contain those readings. You can narrow or revoke what Basil may read in Apple Health or Health Connect directly.

Export the active profile's data as a file from Settings → Export. Food photos and other profiles are not included; switch profiles and export each one separately. Delete all data in Settings wipes only the active profile's database on the device; switch to each profile to wipe it too. Deletion does not remove copies in your phone's backups, or bug reports you have already sent. To have a report deleted, write to us at the address below.

To ask a question about this policy, or to make a request about your information, write to privacy@pastmaps.com. We respond within 45 days, and you can appeal a refusal by replying to our response.

Children

Basil is not directed to children and is intended only for people 18 or older. We do not knowingly collect information from children.

Changes to this policy

If this policy changes in a way that affects what Basil sends or to whom, we will update this page and the date above, and where the change is material we will say so in the app.