NutriTrace
Self-hosted personal nutrition and calorie tracker
Alternative to: myfitnesspal, cronometer, lose it, waistline

v1.4.0-dev01
2026-09-22First dev pre-release of the 1.4.0 minor. The headline is offline mode: your diary and your own foods are kept in the browser, what you log offline goes up on its own, and the installed app opens in a dead zone. Also in: body composition through MCP and the REST API, update checks that are off until you ask for them, and fonts served by your own instance instead of Google.
Added
- Body composition through MCP and the REST API (#234). A new
get_body_compositionread tool returns your saved scale readings over a date range, keeping each source separate rather than merging them. Also at/api/v1/body-compositionwhen the Public API is on. Contributed by @kgenerozov. MCP tools. - Offline mode (#211). Your diary and your own foods are kept in the browser, so the app opens in a dead zone, the day still adds up, and what you log goes up on its own when the connection returns, merged the same way the Android app’s changes are. The menu button shows an amber cloud while anything is waiting. Works the same on iPhone, since it doesn’t rely on Background Sync. What works offline.
- What else works in offline mode (#211). Your own foods, meals and recipes, manual activity, settings and goals, the fasting timer, your profile and picture, and the wellness figures you have already seen. Anything you make offline can be used straight away and keeps its identity when the queue goes up.
- Offline mode says what it cannot reach (#211). Searches, lookups, photos, the wellness providers, Trace and anything admin need a connection, and each says so where you would otherwise see an empty screen or a wrong answer. If your server refuses what is waiting, it says why and keeps trying.
Changed
- Update checks are off until you turn them on, and your server does the asking. Every browser and phone used to ask GitHub directly every 4 hours. Setup now asks, skipping the question leaves checks off, and a fresh install contacts nothing on its own. Existing installs keep checking as before.
UPDATE_CHECK=offkeeps them off for good. Reported on r/selfhosted.
Fixed
- “A New Version Is Available” on the web now says what it means, and Reload works. The browser banner used the Android wording and its Reload button could do nothing at all, and a tab left open never noticed a new version. Same fix in all four Trace apps.
- The Copy sheet’s buttons no longer sit under Android’s navigation bar (#233). That one sheet overwrote the spacing that keeps content clear of the bar. Thanks @nomad64 for the report.
- The Trace button no longer covers what’s on top of it (#233). It floated above every sheet and dialog, so wherever you had dragged it, it could sit over a title or a button. Thanks @nomad64 for the report.
- Something deleted while online stays deleted when the connection goes. An older copy of the list could be carried over from before you signed in, so what you removed came back the moment you were offline. Reported in testing.
- A photo kept offline is scaled to something a request comfortably carries, so your server never turns it away after you have been told it was saved.
- Adding a photo with no connection no longer fails on an installed app. The part of the app that keeps a photo was fetched from your server at the exact moment there was nothing to fetch from. It travels with the app now.
- The copy this browser keeps now has a ceiling, and if storage runs out, what you have changed is kept and the copy makes way for it, rather than the app refusing to log anything offline.
- Work queued while a sync was running no longer waits for you to do something else before it goes up, and a change made before the page had built its connection now carries the token your server asks for.
- A picture kept offline holds its transparency, and an unusual camera format is converted rather than lost. A drawing could come back with a black background, and an iPhone’s HEIC would have been refused on arrival without saying so.
- What a row created offline became is now remembered on disk, not just while the page stays open, so a sync that stopped halfway can’t leave work queued against an id your server never had.
- A profile saved before the app had finished checking your server no longer goes to the wrong place. Your name and picture could be written to local settings instead of your account.
- Fonts are served by your own instance. The app loaded Inter and the icon font from Google on every page load, so Google saw the address of everyone who opened it, whatever your settings said. They are split by script, so a page still downloads only the alphabets it needs. Reported on r/selfhosted.
Security
- No security fixes this cycle.
npm auditreports 0 vulnerabilities for the app and the server, and there are no open Dependabot alerts. The privacy changes above (fonts, update checks) came out of a review on r/selfhosted.
Testers: offline mode is the headline, so that’s what needs real use: log in a dead zone, kill the connection mid-edit, reload the installed app with no signal, and add a photo offline. If something you did offline never arrives, or arrives twice, say what you did and roughly when.