Privacy Policy
Last updated: 5 October 2026
This policy covers two things: the Stead app and this website. The app is where your health information lives, so that part comes first. We collect little, we don’t sell anything, and you can take it all back or wipe it at any time.
The Stead app
There is no account
Stead has no signup, no password, and no email wall. On first launch the app generates an anonymous device id, and everything you log is attached to that id. We do not ask for your name, phone number, email address, or payment details, and we have no way to connect your logs to your real identity.
Because the device id is the only key, losing your device or deleting the app means losing access to that history. There is no account recovery.
The device id works like a key: the app sends it with every request, and anyone who had it could read or delete that history. It stays on your phone and with us, and we never show it publicly.
What the app stores
- What you log — meals, weight, workouts, water, and how you feel, with the date and time you attach to them.
- Meal photos — pictures you choose to send, so a meal can be read from a plate.
- What you type or say to log something — so it can be turned into a log. Voice recordings are transcribed and not kept.
- Profile basics — things like your age band, weight, height, diet, allergies, who cooks and your budget, and for workouts your equipment, days, session length and anything that’s hurting. You enter these during onboarding, when a feature first needs them, or in Profile.
- Your plans — the meal plans and training weeks you create, and whether each meal or session happened.
- Memory — two short lists, each line a plain sentence: what you told Stead (things you said that last, like a food you avoid, kept the day you said them) and what Stead noticed (once a week, Stead looks over the food choices you made — what you logged, ordered and picked — and keeps a line when something repeats across at least two weeks). Suggestions, plans and orders use these lines. Each list holds at most ten lines; every line shows where it came from, and you can edit it, pause it, say Not really to remove it for good, or forget everything, in Profile.
- Your weekly review — what Stead learned from that week’s choices and what it will do differently, kept so you can look back at it.
- Pantry — the ingredients you tell it you have.
- Notification token & timezone — if you allow notifications, so they arrive at a sensible local hour.
- Usage records — which days you used the app and which services you ran (for example, a meal suggestion or an order-in pick) and what came back, tied to your device id. We use these to keep Stead working and to see which parts help people. Records of each service run are deleted after 90 days.
- Swiggy data, only if you connect Swiggy — see the next section.
Everything in this list is kept until you delete it or use Delete all my data, except where a shorter period is given.
Earlier versions of the app had a chat. If you used it, those messages are still held for your device and are removed by Delete all my data.
Ordering in with Swiggy (optional)
Powered by![]()
Connecting Swiggy is optional. Nothing below happens unless you choose Connect Swiggy in the app, and the rest of Stead works without it.
How connecting works
You sign in on Swiggy’s own page — Stead never sees your Swiggy password. Swiggy then gives Stead an access token for your account. We store it encrypted, use it only for the things listed below, and it expires after a few days, after which you reconnect.
What we read from Swiggy, and why
- Your saved delivery addresses — so picks are for places that deliver to you. We keep only each address’s Swiggy id, its label (like “Home”) and its area. We do not keep the full address line or the name and phone number on it.
- Your recent Swiggy Food and Instamart orders — what was ordered, from which restaurant or store, when, the total, the order status and which saved address it went to. Names and phone numbers are removed before anything is stored. While you’re connected, we read your recent orders again once a day, so your history builds up even on days you don’t open the app.
- Restaurants, menus, prices, offers, ratings and delivery times — when you ask for something to order, so we can find dishes that are open, in your price range and arrive in time.
- Your Swiggy cart — to check what’s already in it before we add a dish, and to read the real bill for dishes we’re pricing (see below).
- At checkout — the bill, the full delivery address, the coupons available for that restaurant, and the ways Swiggy lets you pay (such as your UPI apps, cash on delivery or Swiggy Money). These are shown to you so you can check them before ordering. We do not store the full address.
- Your order’s status — after you place an order, so you can follow it in the app.
What we do with it
- Learn how you order — with “My addresses and recent orders” on when you connect (in Profile → Swiggy it reads “Use my recent orders to learn what I eat”), we work out things like the places you order from, what you usually spend, when you tend to order in and what you order often, so suggestions and plans fit how you already eat. Your Swiggy Food orders are used for this; your Instamart orders are used to confirm your delivery address, and the food in them counts towards what Stead noticed in your memory.
- Log your delivered orders — with the same setting on, your delivered Swiggy Food orders are added to your food log on their own, at the time you ordered: the dishes, an estimate of calories and protein, and the dish photo when Stead built the order. Stead checks for new deliveries when you open the app. You can change or delete any of these meals in Activity, and an order you delete isn’t logged again. If an order wasn’t just for you, you can say so.
- Suggest dishes — picks that fit your diet, allergies, budget and time.
- Price dishes in your cart — menus don’t show what an order really costs once fees and offers are in, so for Something sweet, Craving something? and late-night picks, Stead adds a shortlisted dish to your Swiggy cart, reads the bill, the delivery fee and the best offer, then removes it and puts your cart back as it was. This happens without asking you each time. Nothing is ordered or paid.
- Add a dish to your Swiggy cart to order it — only when you tap to do so. If your cart already holds something from another restaurant, we ask before replacing it.
- Place the order — only when you tap Place order, after you’ve seen the items, the bill, the delivery address and how you’ll pay. Stead applies the best coupon Swiggy offers for that order by itself, and the bill you see before you tap already shows it. UPI payments are completed in your own UPI app; cash on delivery and Swiggy Money are handled by Swiggy. We keep a record of your latest order (Swiggy’s order id, the restaurant, the items, the total, how you chose to pay and its status) so you can track it.
What we never do
- Place an order or start a payment without your tap on Place order.
- Leave a dish in your cart that we added only to read its price.
- See or store your card or bank details, your UPI PIN or your Swiggy Money balance.
- Sell your Swiggy data or share it with advertisers or restaurants.
How long we keep it, and how to stop
- Stored order records are deleted automatically after 90 days.
- Turning off “Use my recent orders to learn what I eat” (Profile → Swiggy) stops new orders being read or logged, and deletes the order records we stored and everything we learned from them.
- Disconnecting Swiggy (Profile → Swiggy → Disconnect) signs Stead out of your Swiggy account and deletes the access token, your saved-address details, the order records, the record of orders placed through Stead and everything learned from them. We keep only a short list of which order ids were already logged or deleted, so that if you reconnect, a meal you deleted doesn’t come back.
- Meals logged from your orders stay in your log, like anything else you logged, until you delete them. Each one keeps the order’s details: the restaurant, the items, what you paid, when, and Swiggy’s order id.
- Delete all my data removes all of the above too.
Your Swiggy account, orders, payments and deliveries are Swiggy’s and are covered by Swiggy’s own privacy policy and terms. Disconnecting from Stead doesn’t change anything in your Swiggy account.
Health and lab information
If you share lab values or mention a health condition, Stead treats it as a constraint on food suggestions only — for example, steering toward lower-glycaemic or lower-sodium meals. It does not interpret your numbers, does not name conditions back at you, and never discusses medication. For anything medical it will point you to a registered doctor. This is enforced in the product, not just promised here.
Who processes it
Some features use AI models to understand what you enter and to put together suggestions and plans. Specifically:
- OpenAI — the text you enter, meal photos you send and voice recordings are sent to OpenAI to be understood. To build suggestions and plans, OpenAI also receives the profile details they need (like your diet, allergies, budget and workout setup) and your recent logs. Once a week it receives a summary of the food choices you made that week, so it can word what Stead noticed. If you connect Swiggy, it also receives dish and restaurant names, menus, prices, delivery times, when you tend to order and a summary of your ordering habits. It never receives your address, phone number, name or Swiggy order ids. OpenAI acts as our processor and, under its API terms, does not use this content to train its models. Its servers may be outside India.
- Swiggy — if you connect it, we exchange data with Swiggy through its official developer access, as described in the Swiggy section above.
- Google Cloud (Firebase, Cloud Run, Cloud Storage) — hosts the service and stores your logs and meal photos. Data sits in the Mumbai (
asia-south1) region. - MongoDB Atlas — the database holding your logs, profile, memory, and conversation.
- Firebase Cloud Messaging — delivers notifications, if you turn them on.
These are service providers acting on our instructions. We do not sell your information, do not share it with advertisers, and there are no advertising or analytics SDKs inside the app.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, you can:
- See what we hold — Export my data in Profile → Settings downloads a zip containing everything held for your device as a single JSON file. If you connected Swiggy, it includes what we learned from your orders and your saved-address labels. The stored order records themselves aren’t in the one-tap export; email us if you want a copy. The services we share data with, and what each receives, are listed under Who processes it above.
- Correct it — change or delete any log in Activity, and your profile and memory in Profile.
- Delete it — Delete all my data in Profile → Settings wipes the server record for your device, meal photos and Swiggy data included, disconnects Swiggy, and resets the app. Immediate and irreversible.
- Withdraw your consent — turn off a Swiggy setting or disconnect Swiggy, pause or forget memory, turn off notifications, or delete all your data. Withdrawing is as easy as agreeing was, and doesn’t affect what was done before.
- Nominate someone to use these rights for you if you die or can’t act yourself — email us and we’ll set it up.
- Raise a grievance — email our grievance contact, Arnab Goswami, at arnab.goswami@heystead.com. We reply within 30 days.
- Complain to the Data Protection Board of India — if you’re not satisfied with our reply.
Because there is no account, we can only find your data by your device id. For a request by email, we may ask you to send it from the app or to share that id.
Children
Stead is for people aged 18 and over. We do not knowingly collect information from anyone under 18. If you think someone under 18 is using Stead, email us and we’ll delete their data.
This website
What we collect here
- iPhone waitlist — if you ask to hear when Stead comes to iPhone, we store the email address you enter and, optionally, your answer to “what do you use for your health today?”
- Website analytics — we use Google Analytics to understand how people find and use this page (pages viewed, approximate location, device/browser, and the referring link or campaign). This is aggregate usage data, not tied to your name.
We do not ask for your name, phone number, payment details, or any health information on this website.
How we use it
- To email you when Stead is on iPhone, and occasionally to ask people on the list what they’re looking for. Email us to be taken off the list.
- To understand which messages and channels bring interested people, so we build the right thing.
We do not sell your information, and we don’t send marketing spam.
Cookies & analytics
Google Analytics sets cookies to measure visits. You can block cookies in your browser or use a tracker-blocking extension; the site works either way.
Where it’s stored
Waitlist entries are stored with Google Firebase on Google
Cloud infrastructure in the Mumbai (asia-south1) region, and
analytics is processed by Google Analytics.
Your choices
You can ask us to show you what we hold, correct it or delete it, at any time — in the app for your health data, or by email for anything else. Everything under Your rights applies to this website too.
Changes
If this policy changes, we’ll update the date at the top of this page.
Contact
Questions, a deletion request or a grievance? Email arnab.goswami@heystead.com.