Version 1.1 — effective 17 September 2026. Changes from 1.0: PostHog added to the services, with what it receives, including the IP address in transit; website checkout processors removed.
Grif is built on public nutrition data, open-source software, and a few services. This page gives the attributions their licences require and points to the full licence texts. It is linked from the app (Food tab → "How we count" → Sources) and from grif.fit/third-party-notices.
The calories and macronutrients Grif shows are computed by our own code from the following reference databases. Energy is computed with our own coefficients (4 / 9 / 4 kcal per gram of available carbohydrate / fat / protein), so a figure in the app may differ slightly from the source's own energy column.
| Source | What we use | Licence | Attribution / link |
|---|---|---|---|
| USDA FoodData Central (U.S. Department of Agriculture, Agricultural Research Service) — SR Legacy and FNDDS 2021–2023 | Raw and cooked foods; dishes "as eaten" with their ingredient lines | Public domain (CC0 1.0) | U.S. Department of Agriculture, Agricultural Research Service. FoodData Central, https://fdc.nal.usda.gov/ |
| CIQUAL — Table de composition nutritionnelle des aliments (ANSES, France) | European foods and dishes | Licence Ouverte / Open Licence 2.0 (Etalab) — attribution required | Source: ANSES-CIQUAL French food composition table, https://ciqual.anses.fr/ , under the Etalab Open Licence https://www.etalab.gouv.fr/licence-ouverte-open-licence/ |
| CoFID — Composition of Foods Integrated Dataset (Public Health England / UK) | British foods and dishes | Open Government Licence v3.0 — attribution required | Contains public sector information licensed under the Open Government Licence v3.0, https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/ ; dataset: McCance and Widdowson's Composition of Foods Integrated Dataset, https://www.gov.uk/government/publications/composition-of-foods-integrated-dataset-cofid |
| Open Food Facts (packaged products looked up by barcode, and a mirror of the same database behind text search — the mirror is disabled until an operator turns it on) | Product name, brand, serving size, per-100 g nutrients of the product you scanned or searched for | Open Database License (ODbL) v1.0 — attribution and share-alike | © Open Food Facts contributors, https://world.openfoodfacts.org/ , licensed under the ODbL, https://opendatacommons.org/licenses/odbl/1-0/ . Rows sourced from Open Food Facts — whether from one barcode lookup or the mirror — are kept separable in our database (source = 'off', with the raw response, the mirror in its own off schema) and are available on request under ODbL §4.6; product images are not used |
Our own recipes (composed) | Dishes with no source entry (borscht, pilaf, syrniki…) | Ours | — |
| Nutrition labels you photograph (upcoming) | The figures printed on the pack, read by the vision model | The manufacturer's data, entered at your request | Shown in the app as "from the label" |
We do not use FatSecret, Edamam or Nutritionix (their terms forbid storing their data) and do not use Russian tables whose licensing is unclear.
Meal and label photographs are recognised by Google Gemini (primary) and OpenAI (fallback) under their API terms and our data-processing agreements. Their names and the retention period they may apply are shown on the in-app consent card before the first scan. See the Privacy Policy §6.
| Service | Role | Policy |
|---|---|---|
| Apple App Store, StoreKit, Apple Push Notification service | Billing on iOS; push delivery | https://www.apple.com/legal/privacy/ |
| Google Play, Play Billing, Firebase Cloud Messaging, Play Install Referrer | Billing on Android; push delivery; install source | https://policies.google.com/privacy |
| PostHog Cloud EU | Product analytics (SDK in the app; events without body data). PostHog receives your IP address in transit, like any server; our app replaces it with 0.0.0.0 in stored events, and no location is stored with events or profiles. PostHog's feature-flag service may use the request IP to evaluate flags for that request; we do not use feature flags | https://posthog.com/privacy (data processed in Frankfurt, Germany) |
| Apphud | Subscription infrastructure (SDK in the app, webhooks to our server) | https://apphud.com/privacy (data processed in the United States) |
| Keycloak (self-hosted) | Sign-in service | Runs on our server; no third party involved |
| DigitalOcean | Hosting (Frankfurt) | https://www.digitalocean.com/legal/privacy-policy |
| Cloudflare | DNS; forwarding of mail to support@grif.fit; planned config-file CDN | https://www.cloudflare.com/privacypolicy/ |
The "Where did you hear about us?" step shows the marks of TikTok, App Store, Google, Instagram, Facebook, X and YouTube so that you can recognise the service you name. Each mark is the property of its owner, is used only for identification, and implies no partnership, sponsorship or endorsement. Vector paths come from the Simple Icons project (CC0 1.0) and, for Google, from Google's own published asset.
The app and the server are built with open-source libraries, among them Kotlin and Compose Multiplatform, Ktor, SQLDelight, Koin, Coil, kotlinx, AndroidX and Health Connect (Apache-2.0), ZXing (Apache-2.0, barcode reading on Android, upcoming), Tink (Apache-2.0), the Play Billing Library, the Apphud SDKs (MIT), the PostHog SDKs (MIT), Go and its golang.org/x modules (BSD-3-Clause), and the Go libraries listed in the server module file. The full list of components and their licence texts is available on request at support@grif.fit.
The pace-step animals (turtle, hare, cheetah) and all in-app glyphs are the operator's own drawings; no third-party icon set ships in the build.
Terms · Privacy · Health data · Subscriptions · Third-party notices · Delete account · Home