1. Scope
What this policy covers
This policy applies to the AI BiteBuddy mobile app (iOS and Android), related
support channels, and the technical services used to operate the app. It is
intended to describe the categories of information that may be processed when
users authenticate, analyze meals, track nutrition, browse history, or contact
support.
2. Data we may collect
Categories of information
Account and authentication data
- Anonymous Firebase user identifier when a guest session is created.
- Email address and profile information if the user chooses Google Sign-In.
- Basic session identifiers used to keep the app signed in and functioning.
Device, usage, and preference data
- Device and app instance identifiers used for analytics, messaging, or ads.
- Diagnostic and usage events related to navigation, stability, and feature usage.
- Preferences such as selected language, units (metric/imperial), and notification choices.
- Push notification token, when notifications are enabled by the user.
Meal analysis and nutrition tracking data
- Meal photos you upload or capture. These are sent to OpenAI for AI analysis.
- Meal descriptions and manual edits (ingredients, portions, cooking methods).
- Analyzed nutritional data (calories, protein, carbs, fat, confidence scores).
- Saved meals and personal history stored locally on your device.
- Personal profile information (age, weight, height, activity level, fitness goals).
3. How we use data
Purpose of processing
The information collected is used exclusively to:
- Authenticate and authorize your access to the app and your personal data.
- Analyze meals using OpenAI's vision models to estimate nutritional content.
- Calculate personalized targets based on your profile (BMR, daily burn, calorie goals).
- Display advertisements via AdMob (Google Ads) to support the free app.
- Monitor app stability and performance through Firebase analytics.
- Respond to support requests when you contact us.
4. Third-party services
External services that may access your data
The app uses the following third-party services that may collect or process your information:
Google Services
- Firebase Authentication & Realtime Database: User authentication and session management.
- Firebase Analytics: App usage, crashes, and feature adoption.
- Firebase App Check: Security verification of API requests.
- Google Play Services: System libraries and device identifiers.
- AdMob (Google Ads): Display and serve advertisements in the app.
AI & Backend
- OpenAI API: Meal photo analysis and nutritional estimation.
- Render Backend: Secure server-side API for meal analysis and metabolic calculations.
For details on how these services handle data, consult their privacy policies:
5. How your data is stored
Data storage and local privacy
On your device: Your meal history, personal profile, and preferences are stored locally on your device using encrypted local storage (Hive). These data never leave your phone unless you explicitly upload or sync them.
On our servers: Meal photos uploaded for AI analysis are sent to our backend (Render) and temporarily processed by OpenAI. After analysis, photos are not retained unless you explicitly save them to your device.
Session data: Your authentication token and usage analytics are stored in Firebase and Google services according to their retention policies (typically 90 days for analytics, indefinitely for auth).
6. Data retention and deletion
How long we keep your information
- Meal photos: Only retained on your device. Photos sent to OpenAI are deleted after processing (not stored by us).
- Meal history and profiles: Stored locally on your device indefinitely until you delete the app or clear data.
- Analytics and usage data: Retained by Firebase for 90 days, then automatically deleted.
- Authentication records: Retained indefinitely by Firebase to maintain your account.
- Ad data: Retained by AdMob according to Google's data retention policies.
To delete your account and data: Send an email to alebler@gmail.com with the subject "Data Deletion Request." We will remove your Firebase authentication and any server-side records within 30 days. To remove data from your device, uninstall the app and clear its cache through your device settings.
7. Security
How we protect your data
- Encrypted transmission: All communication between your device and our servers uses HTTPS/TLS encryption.
- Firebase security: User authentication and session data are protected by Google Firebase's enterprise-grade security.
- Local encryption: Meal history on your device is encrypted using Hive's built-in encryption.
- App Check: Firebase App Check verifies that requests come from legitimate app instances, preventing API abuse.
- No photo storage: Meal photos are never stored on our servers—only temporarily processed for analysis.
8. Your rights and choices
What you can control
- Notifications: Enable or disable push notifications in app settings. You can withdraw consent at any time.
- Location: BiteBuddy does not request or use your location.
- Analytics: You cannot opt out of analytics used to improve app stability, but you can delete your account.
- Personalization: You can update or delete your profile at any time within the app.
- Account deletion: You can request account and data deletion by contacting alebler@gmail.com.
9. Children's privacy
Data from minors
BiteBuddy is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete such information and terminate the child's account.
For users ages 13–18, parental consent is recommended before downloading the app, especially regarding meal photo analysis and analytics tracking.
10. Changes to this policy
Policy updates
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by updating the "Last updated" date at the top of this page. Your continued use of the app after such modifications constitutes your acceptance of the updated policy.
11. Contact us
Privacy questions and support
If you have any questions, concerns, or requests regarding this privacy policy or our privacy practices, please contact us:
Email: alebler@gmail.com
Subject: AI BiteBuddy Privacy Inquiry
We will respond to your request within 30 days.