Grif — Third-party notices and data-source licences

Version 1.1 — effective 17 September 2026. Changes from 1.0: PostHog added to the services, with what it receives, including the IP address in transit; website checkout processors removed.

Grif is built on public nutrition data, open-source software, and a few services. This page gives the attributions their licences require and points to the full licence texts. It is linked from the app (Food tab → "How we count" → Sources) and from grif.fit/third-party-notices.

1. Nutrition reference data

The calories and macronutrients Grif shows are computed by our own code from the following reference databases. Energy is computed with our own coefficients (4 / 9 / 4 kcal per gram of available carbohydrate / fat / protein), so a figure in the app may differ slightly from the source's own energy column.

SourceWhat we useLicenceAttribution / link
USDA FoodData Central (U.S. Department of Agriculture, Agricultural Research Service) — SR Legacy and FNDDS 2021–2023Raw and cooked foods; dishes "as eaten" with their ingredient linesPublic domain (CC0 1.0)U.S. Department of Agriculture, Agricultural Research Service. FoodData Central, https://fdc.nal.usda.gov/
CIQUAL — Table de composition nutritionnelle des aliments (ANSES, France)European foods and dishesLicence Ouverte / Open Licence 2.0 (Etalab) — attribution requiredSource: ANSES-CIQUAL French food composition table, https://ciqual.anses.fr/ , under the Etalab Open Licence https://www.etalab.gouv.fr/licence-ouverte-open-licence/
CoFID — Composition of Foods Integrated Dataset (Public Health England / UK)British foods and dishesOpen Government Licence v3.0 — attribution requiredContains public sector information licensed under the Open Government Licence v3.0, https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/ ; dataset: McCance and Widdowson's Composition of Foods Integrated Dataset, https://www.gov.uk/government/publications/composition-of-foods-integrated-dataset-cofid
Open Food Facts (packaged products looked up by barcode, and a mirror of the same database behind text search — the mirror is disabled until an operator turns it on)Product name, brand, serving size, per-100 g nutrients of the product you scanned or searched forOpen Database License (ODbL) v1.0 — attribution and share-alike© Open Food Facts contributors, https://world.openfoodfacts.org/ , licensed under the ODbL, https://opendatacommons.org/licenses/odbl/1-0/ . Rows sourced from Open Food Facts — whether from one barcode lookup or the mirror — are kept separable in our database (source = 'off', with the raw response, the mirror in its own off schema) and are available on request under ODbL §4.6; product images are not used
Our own recipes (composed)Dishes with no source entry (borscht, pilaf, syrniki…)Ours—
Nutrition labels you photograph (upcoming)The figures printed on the pack, read by the vision modelThe manufacturer's data, entered at your requestShown in the app as "from the label"

We do not use FatSecret, Edamam or Nutritionix (their terms forbid storing their data) and do not use Russian tables whose licensing is unclear.

2. Vision providers

Meal and label photographs are recognised by Google Gemini (primary) and OpenAI (fallback) under their API terms and our data-processing agreements. Their names and the retention period they may apply are shown on the in-app consent card before the first scan. See the Privacy Policy §6.

3. Services

ServiceRolePolicy
Apple App Store, StoreKit, Apple Push Notification serviceBilling on iOS; push deliveryhttps://www.apple.com/legal/privacy/
Google Play, Play Billing, Firebase Cloud Messaging, Play Install ReferrerBilling on Android; push delivery; install sourcehttps://policies.google.com/privacy
PostHog Cloud EUProduct analytics (SDK in the app; events without body data). PostHog receives your IP address in transit, like any server; our app replaces it with 0.0.0.0 in stored events, and no location is stored with events or profiles. PostHog's feature-flag service may use the request IP to evaluate flags for that request; we do not use feature flagshttps://posthog.com/privacy (data processed in Frankfurt, Germany)
ApphudSubscription infrastructure (SDK in the app, webhooks to our server)https://apphud.com/privacy (data processed in the United States)
Keycloak (self-hosted)Sign-in serviceRuns on our server; no third party involved
DigitalOceanHosting (Frankfurt)https://www.digitalocean.com/legal/privacy-policy
CloudflareDNS; forwarding of mail to support@grif.fit; planned config-file CDNhttps://www.cloudflare.com/privacypolicy/

4. Brand marks

The "Where did you hear about us?" step shows the marks of TikTok, App Store, Google, Instagram, Facebook, X and YouTube so that you can recognise the service you name. Each mark is the property of its owner, is used only for identification, and implies no partnership, sponsorship or endorsement. Vector paths come from the Simple Icons project (CC0 1.0) and, for Google, from Google's own published asset.

5. Open-source software

The app and the server are built with open-source libraries, among them Kotlin and Compose Multiplatform, Ktor, SQLDelight, Koin, Coil, kotlinx, AndroidX and Health Connect (Apache-2.0), ZXing (Apache-2.0, barcode reading on Android, upcoming), Tink (Apache-2.0), the Play Billing Library, the Apphud SDKs (MIT), the PostHog SDKs (MIT), Go and its golang.org/x modules (BSD-3-Clause), and the Go libraries listed in the server module file. The full list of components and their licence texts is available on request at support@grif.fit.

6. Illustrations

The pace-step animals (turtle, hare, cheetah) and all in-app glyphs are the operator's own drawings; no third-party icon set ships in the build.


Terms · Privacy · Health data · Subscriptions · Third-party notices · Delete account · Home