AI coach and meal scan
Activate authenticated streaming chat and private structured image analysis.
The Coach and Scan experiences work in mock mode. The included production path sends requests through authenticated Supabase Edge Functions so the AI provider key never enters the mobile bundle.
Prompt
Read agent-skills/wire-ai-chat.md, agent-skills/wire-file-uploads.md, and
PRODUCTION-SETUP.md. Activate the included Coach streaming and meal-scan backend
with my OpenAI-compatible provider. Keep the provider key in Supabase secrets,
use authenticated quotas and private uploads, validate structured results, and
keep user review before saving an AI estimate.What the server path protects
- verifies the user JWT and trusted premium entitlement,
- enforces per-feature daily limits,
- bounds message history, size, schema, and timeout,
- creates only a short-lived signed image URL,
- validates structured meal output before returning it,
- removes temporary objects in immediate and scheduled cleanup paths.
The app should always call nutrition output estimated and let the user edit the meal name and macros before saving. Do not present it as diagnosis or guaranteed health advice.
Provider decisions you still own
Choose a model that supports your text/image and structured-output needs. Review its retention, training, subprocessors, region, and health-adjacent terms. Name the actual provider and retention behavior in Privacy.
Verify failure paths
Test English/Spanish, slow and chunked streaming, stop, background/resume, offline, expired auth, free/premium quota, provider timeout, malformed stream or JSON, prompt-injection content, and provider failure. Confirm another user cannot access the image and that prompts, image URLs, provider keys, and auth tokens do not enter analytics, Sentry, or logs.