HealthSync · Legal

AI Guidelines

Preamble
These AI Guidelines describe how artificial intelligence is integrated into HealthSync (part of itsmarian's projects, available at https://healthsync.itsmarian.dev), what it may and may not be used for, what risks it brings, and what your responsibilities are as a user.
They complement and are part of the Terms of Use and the Privacy Policy. Please read all three before enabling AI features.
Last updated: 18 June 2026

Table of Contents

#1
Preamble
#2
Overview of AI in HealthSync
#3
Provider, model and your API key
#4
What AI may be used for
#5
What AI must not be used for
#6
Known risks and limitations
#7
Data sent to the AI provider
#8
Your responsibilities
#9
Your controls and opt-out
#10
Children and minors
#11
Costs, quotas and rate limits
#12
Incidents and abuse reporting
#13
Changes and updates
Overview of AI in HealthSync
HealthSync uses AI in two clearly separated places. Knowing which is which helps you understand what leaves your device and what does not:
  • AI Detection (external, opt-in): Inside CalSync, you may optionally use AI to estimate nutrition values from a food photo, a camera capture or a text description (e.g. "two slices of whole-wheat bread with butter"). This sends the input you provided to Google's Gemini API and parses the returned JSON into a draft food entry that you can review, edit and save.
  • AI Tips widget (local, rule-based): The "AI Tips" card on the dashboard generates short, motivational hints (e.g. "You are 200 ml away from your hydration goal"). Despite the name, this widget is fully rule-based and runs entirely on your device. It does not contact any AI provider and does not send your data anywhere.
Throughout these guidelines, the term "AI" refers to the AI Detection feature unless explicitly stated otherwise.
Provider, model and your API key
AI Detection is powered by Google's Gemini API (currently gemini-2.0-flash or a comparable successor model). HealthSync integrates the API directly from your browser; we do not operate a proxy that stores or relays your AI requests on our servers.
To use AI Detection you must:
a)Open Settings → AI Detection inside HealthSync.
b)Accept the in-app AI terms and confirm that you have read these AI Guidelines.
c)Have given third-party / functionality cookie consent in the cookie banner (required because AI uses an external service).
d)Provide your own Google Gemini API key. You can obtain a key from https://ai.google.dev/.
The API key you enter is stored locally in your browser's localStorage under the key calsync_ai_api_key and is sent only directly to Google when you trigger an AI request. We never receive, log or sync your key.
By enabling AI Detection you also agree to Google's Gemini API Terms and to the applicable Google privacy notices. Google may use and process the content you submit under those terms.
What AI may be used for
AI Detection is provided as a convenience to speed up logging. You may use it to:
  • Estimate calories and macronutrients of a meal from a photo, camera capture or short text description.
  • Pre-fill the manual food entry form with a draft you can review and adjust before saving.
  • Quickly recognise foods you don't want to look up manually.
All AI suggestions are treated as drafts. They are never saved automatically. You always confirm - and may freely modify - the values before they become a HealthSync entry.
What AI must not be used for
AI Detection is a personal estimation aid. It is not suitable for any of the following, and you agree not to use it for:
  • Medical decisions, diagnosis, treatment, dosing, or anything resembling clinical nutrition counselling.
  • Decisions affecting infants, children, pregnant or breastfeeding people, athletes during competition, or anyone with a medical condition that requires precise nutritional control (e.g. diabetes, kidney disease, allergies, eating disorders).
  • Allergen or intolerance checks. AI cannot reliably identify hidden ingredients, traces, or cross-contamination.
  • Calorie or macro tracking where accuracy actually matters (e.g. competitive bodybuilding cuts, regulated diets). Use the barcode scanner, a verified database, or manual entry instead.
  • Analysing images that contain other people, faces or any identifying personal data unrelated to food. Crop or recompose the photo first.
  • Generating, classifying or moderating content beyond the scope of food and nutrition estimation.
  • Any unlawful, harmful, abusive, deceptive or rights-infringing purpose, or any use that would violate Google's Gemini API Terms or applicable law.
Known risks and limitations
Generative AI is, by design, probabilistic. You should treat every AI output with healthy scepticism. Among the known limitations:
  • Hallucination: The model can invent details that look plausible but are simply wrong (e.g. a non-existent brand, a misattributed dish, a fabricated nutrient value).
  • Portion-size errors: Estimating weights and volumes from a single image is unreliable. The same plate can produce very different calorie totals depending on lighting, angle and visible reference objects.
  • Ingredient blind spots: The model cannot see oils, sauces, sugar, butter or other ingredients hidden inside or under food. Real calories are frequently higher than the AI estimate.
  • Cultural and regional bias: The model is more accurate for foods that are well-represented in its training data. Regional dishes, home-made meals and atypical preparations are more error-prone.
  • Inconsistency: Sending the same input twice may produce noticeably different values. Do not rely on a single AI estimate as if it were a measurement.
  • Out-of-scope content: If the input is unclear, not food, or ambiguous, the model may still answer with confidence. Always discard outputs that don't match what you actually ate.
  • Provider-side changes: Google may update, deprecate or restrict the Gemini API at any time, which may degrade or temporarily disable AI Detection without prior notice.
  • Network and privacy risks: AI Detection requires an internet connection. Any data you submit leaves your device and is processed by a third-party provider in accordance with their terms.
Data sent to the AI provider
When you actively trigger an AI request, HealthSync sends, directly from your browser to generativelanguage.googleapis.com, the following:
  • The food image, camera capture or text description you provided as the input.
  • A short fixed prompt that instructs the model to return nutrition values in a structured JSON format.
  • Your Gemini API key, used to authenticate the request.
  • Standard request metadata that any HTTPS call carries (your IP address, user agent, TLS information).
HealthSync does not send your account e-mail, your full food log, your goals, your workouts, your name or any other unrelated personal data to the AI provider. The request contains only what is necessary to estimate the nutrition of the specific item you submitted.
The processing of that request - including retention, training use, region, and sub-processors - is governed by Google's applicable terms and privacy notices: https://ai.google.dev/gemini-api/terms and https://policies.google.com/privacy.
For the European Union, transfers to the United States are covered by the EU-US Data Privacy Framework (DPF) and, additionally, by Standard Contractual Clauses where applicable. See the Privacy Policy for further details on international transfers.
Your responsibilities
Because AI Detection sends data to a third-party provider using your API key, you are responsible for the way you use it. By enabling the feature you agree to:
  • Use AI Detection only for personal nutrition estimation, in accordance with these Guidelines, the Terms of Use and applicable law.
  • Treat every AI output as an estimate and verify any values that matter to you against trusted sources (manufacturer label, official nutrition database, dietitian).
  • Avoid submitting images or text that contain personal data of third parties, sensitive content, intellectual-property-protected material you do not have rights to, or anything that violates Google's Gemini API Terms.
  • Keep your Gemini API key confidential, monitor your own usage and billing, and rotate or revoke the key if it leaks.
  • Comply with all laws applicable to you (in particular data protection, IP, and any sector-specific rules if you happen to use HealthSync in a professional context).
HealthSync, itsmarian and Marian D. assume no liability for AI output, for decisions you take based on that output, or for usage costs incurred on your own Gemini API key, subject to the limits set out in the Terms of Use, section #11 (Liability).
Your controls and opt-out
You stay in control of AI at all times. You can:
  • Use HealthSync entirely without AI - the feature is disabled by default.
  • Toggle AI Detection off at any time in Settings → AI Detection. Once disabled, HealthSync stops contacting any AI endpoint.
  • Remove your API key from the Settings panel; it is also erased when you clear the app's site data.
  • Withdraw third-party cookie consent through "Change Cookie Preferences" in the footer; AI features will then be unavailable until consent is granted again.
  • Discard, edit or modify any value AI proposes before it is saved as an entry.
Withdrawing consent or disabling the feature does not affect the lawfulness of any AI processing that took place before withdrawal.
Children and minors
HealthSync is not directed at children under the age of 16, and AI Detection is in particular not suitable for minors. Do not enable AI features for or on behalf of a person under 16 without verifiable parental consent and a clear understanding of the risks set out in these Guidelines.
Costs, quotas and rate limits
AI requests are billed by Google, not by HealthSync. Free tiers and paid quotas depend on your Google account configuration and may change at any time. HealthSync does not impose its own surcharge for AI usage.
HealthSync may apply reasonable client-side rate limits or input-size constraints in order to protect you against accidental over-usage of your API key. These are technical safeguards and not a substitute for monitoring your own Google billing dashboard.
Incidents and abuse reporting
If you encounter what you believe is harmful, unsafe or illegal output from AI Detection inside HealthSync, or if you suspect that the feature is being misused, please report it to support@itsmarian.dev with as much detail as you can reasonably share (without exposing other people's personal data). I will investigate and take appropriate action, including disabling specific AI behaviour if necessary.
Abuse of the Gemini API itself should additionally be reported to Google through the channels listed in their terms.
Changes and updates
These AI Guidelines may evolve as the AI feature, applicable law (e.g. the EU AI Act) or the underlying provider changes. I will revise the Guidelines whenever a change is necessary and update the "Last updated" date at the top of this page. Where a change materially affects your rights or the way your data is processed, I will request your consent again in-app before AI Detection can be used.
GitHubKo-fi

AI Guidelines • Contact • Cookies • Privacy Policy • Terms of Use

Change Cookie Preferences

© 2026 itsmarian | All rights reserved!

Back to top