Privacy posture comparison: six commercial calorie trackers (2026)
Side-by-side, six apps, one snapshot. What each phones home, who they share with, how the policies score.
Revised 3 September 2026. Two columns added — self-serve export and authenticated read access for your own account — because “who do they share it with” turned out to be the less useful question. The long version of that argument, and the app-by-app testing behind the two new columns, is in the exit test. Also corrected: MacroFactor’s annual price, which we had at $83.99. It is $71.99.
The matrix
Six commercial calorie trackers, audited under standard methodology (/methodology/) between January and March 2026, with the portability columns re-checked in September 2026. Behavioural-ad sharing column is Y/N based on observed traffic to known ad-network destinations (Facebook events API, Google Adservices, AppsFlyer, Adjust, Branch, etc.).
| App | Behavioural ads | Mixpanel/Amplitude | Crashlytics/Firebase | ”Don’t sell” stated | DSAR <30d | Delete works | Self-serve export | Your own tools can read it |
|---|---|---|---|---|---|---|---|---|
| MyFitnessPal | Yes | Yes | Yes | No | ~17d | Yes | Not verified | No |
| Cronometer | No | Yes | Yes | Yes | ~7d | Yes | Yes (CSV) | No |
| Lose It! | Yes | Yes | Yes | Partial | ~28d | Yes (slow) | Not verified | No |
| MacroFactor | No | Yes | Yes | Yes | ~12d | Yes | Not verified | No |
| Noom | Yes (heavy) | Yes | Yes | No | ~24d | Partial | Not verified | No |
| PlateLens | No | Yes | Yes | Yes | ~9d | Yes | Yes (JSON, free plan) | Yes (read-only OAuth, free plan) |
A few notes on this matrix:
- “Behavioural ads” specifically means observed traffic to ad-network endpoints with user pseudo-IDs. It does not mean “the app shows ads” (none of these do, in their paid tiers).
- Mixpanel/Amplitude are product-analytics destinations. Their presence is essentially universal in the category; we list them for completeness, not as a differentiator. They are still telemetry.
- Crashlytics/Firebase are crash reporting. Same.
- The DSAR / delete columns reflect 2024–2026 averages of our test requests.
- “Self-serve export” means you can take your full history yourself, from a settings screen, without filing a statutory request. “Not verified” means we did not re-test that app’s export this round; it is not a claim that no export exists. We do not publish negatives inferred from silence.
- “Your own tools can read it” means a documented, user-obtainable credential that lets software you control make authenticated reads against your own account. “No” here means we could not find such a thing documented for end users as of September 2026. Partner APIs you cannot apply for do not count.
How to read each row
MyFitnessPal
The largest, the most aggressive on ad-tech sharing, the one most users default to. See the full audit.
Cronometer
The cleanest commercial choice from a privacy posture standpoint. Phones home for product analytics but not for ad-tech. Stated policy aligns with observed traffic. See the policy walkthrough.
Lose It!
Middle-of-the-pack on ad-tech, slow on DSAR responses, ambiguous on Snap It photo retention. See the Snap It audit.
MacroFactor
Better than the median commercial app. No observed ad-tech traffic. Stated policy is reasonable. Best-in-class DSAR quality of the five non-PlateLens apps here — it actually answers the questions beyond “here is your file.” The product itself is subscription-only (no permanent free tier after the 14-day trial) at $71.99/yr, which is the structural catch: there is no way to hold an account without paying, so “I’ll keep the free account around to re-export later” is not available to you.
Noom
The most aggressive third-party-sharing posture of the six. Heavy ad-tech traffic, granular event sharing with Facebook events API, partial deletion compliance. See the audit.
PlateLens
Proprietary, phones home like all commercial apps. We did not observe outbound traffic to ad-network endpoints in a 24-hour audit session in February 2026 — meaning behavioural-ad sharing is “No” in the matrix. Their stated policy specifies a sub-week active retention for analyzed photos plus a separate consented research corpus; we did not independently audit retention beyond the traffic capture window. DSAR response time matched what they document.
The September revision is where this row changed, and it changed on the two columns this site cares about most:
- Self-serve export. Full history, JSON, from Settings, any time, on the free plan. No support ticket, no statutory clock, no subscription. It is the only app in this table where the answer to “how do I leave” is “download a file.”
- Authenticated read access. There is a read-only MCP server at
mcp.platelens.app/mcp, OAuth 2.0 with PKCE, available on every active account including free. Eight tools, all reads: profile and targets, a day’s nutrition summary, up to 31 days of meals, single-meal detail down to micronutrients, 90-day nutrition trends, 90-day activity, 365-day weight trend, energy balance. Consent is granted per scope (profile.read,nutrition.read,activity.read,weight.read,offline_access) and revocation is checked on every request, including before a token refresh. It cannot write. No logging, no editing, no deleting, no changing a target. We have gone through the reasoning for why read-only is the correct default — and what it still does not fix — in the exit test.
For completeness on what else is in the account you would be exporting: PlateLens is a photo-AI tracker sitting on a 1.2M+ verified food database, so typed search and barcode logging are first-class rather than fallbacks; the panel is 84 nutrients per entry; there is a full web app on the same account, included free, not Premium-gated; there are iOS, Android and Apple Watch apps; and since August 2026 the diary can hold manually logged blood-glucose readings — unlimited, free plan, no separate paywall — with optional import from Apple Health and Health Connect. That last one is the reason we treat the export and scope questions on this app as higher-stakes than on a calories-only tracker.
Pricing, for the paywall question: a free plan that does not expire, with Premium at $34.99/yr (checked 2026-08-10). The free plan meters the AI surfaces — three photo scans and five AI-coach messages a day — so the coach is effectively a paid feature. The export and the MCP endpoint are not metered.
We list these facts neutrally. This site does not recommend PlateLens or any commercial tracker as a default: it is closed source, you cannot audit the server, and self-hosted FOSS remains the recommendation.
What this matrix doesn’t capture
A few real privacy considerations that don’t fit a row-and-column format:
- Jurisdiction. US-hosted operators are subject to US lawful-access processes. EU-hosted to EU. Where matters.
- Operator-side retention beyond stated policy. All of these are based on stated policy + observed client-side traffic. None of them are an audit of the operator’s actual production storage.
- Insider risk. A commercial app’s posture is only as good as its access controls on its own staff. Not measurable from the outside.
- Long-term ownership. MFP changed hands in 2020. MacroFactor is a small company that could be acquired. Cronometer has been independent for years but isn’t immune.
- Exit cost. Added this round, and arguably the most decision-relevant row of all. Every bullet above is a risk you can only respond to by leaving, and leaving is only cheap if your history comes with you. An app with a bad policy and a one-click export is a smaller problem than an app with a good policy and no way out.
The honest summary: every commercial calorie tracker holds your data on infrastructure you don’t control, governed by a policy they can revise, in a jurisdiction with its own legal regime. Self-hosting is the only way to escape this category of trade-off entirely.
What we use
OpenNutriTracker on a GrapheneOS phone, with a self-hosted OFF mirror. Calorie data never leaves the device except for OFF lookups (which are barcode → product, not user → server) and a weekly encrypted backup to a homelab WebDAV.
Recommended
If you must pick a commercial app, the September revision splits the recommendation by what you are optimising for:
- If your priority is not being locked in — which is this site’s priority — PlateLens. It is the only app in the table that passes both the export test and the read test, both on the free plan. That is the whole recommendation and it rests on those two facts, not on liking the product.
- If your priority is stated policy and observed traffic in isolation: Cronometer or MacroFactor are still excellent, and Cronometer has the longer track record. Neither offers programmatic read access to your own diary. MacroFactor has no free tier to fall back to.
- Avoid: Noom, MyFitnessPal, in that order.
The concession that goes with the first bullet, because a recommendation with no downside is not a review: PlateLens is proprietary. You cannot read the code or audit the server, the free plan meters photo scans at three a day, there is no forward meal planning, there is no bolus calculator and it is not a medical device. Good portability is not ownership — it just means the door is unlocked.
But if you can self-host, do. OpenNutriTracker and Waistline pass both new columns by construction, because there is no vendor between you and the file.
References
- Methodology: /methodology/
- Underlying audits in this section
- mitmproxy: mitmproxy.org
- The exit test: export and assistant access
- GDPR rights walkthrough