Privacy Policy

Last updated: 5 September 2026 · Version 2.0.0

This Privacy Policy explains how Bite’s UAE-based operator (using the service name Bite) collects, uses, stores, and discloses personal information when you use the Bite nutrition-tracking application.

1. Who we are

Bite is a consumer nutrition and wellness information service operated from the United Arab Emirates. The responsible operator is Bite’s UAE-based operator.

Business address: Business address to be published before public release

Privacy contact: biteappnutrition@gmail.com

2. Information we collect

Account information

Profile and nutrition information

Meals and nutrition information

Subscription and entitlement information

Technical and consent information

3. Photos, camera, and photo library

Bite requests camera or photo-library permission only when those features are used. Selecting or capturing a photo does not analyze it until you submit the scan.

When submitted, the image is converted to a supported image representation and sent to Bite’s authenticated Supabase Edge Function, then to OpenAI for food identification and portion estimation. The accompanying meal description is submitted with it.

After a successful validated scan, Bite stores a private copy of the submitted photo in Supabase Storage and stores a user-scoped image hash, context hash, meal fingerprint, pipeline version, canonical analysis, quality, provenance, and storage reference in Supabase. This supports exact-photo consistency and conservative recognition of the same physical meal. The bucket is configured as private and cache records are scoped to the authenticated user.

If you later log the result, the meal record may also contain the device-local photo URI. Other devices generally cannot use that local URI. Failed, aborted, or rejected analyses are not intentionally stored as successful canonical scanner results.

4. Written meal descriptions and AI processing

When you request a written nutrition estimate, Bite sends the description through its Supabase gateway to OpenAI. OpenAI is asked to identify foods, preparation, explicit quantities, cooking fats, sauces, and other calorie-contributing components and to produce provisional nutrition estimates.

Bite then attempts to ground components using verified official commercial sources and USDA FoodData Central where appropriate. Some portions or unresolved components may remain AI-assisted estimates. Estimating alone does not save a meal to your meal history; the app saves it only when you choose Log Meal. Service-provider handling of submitted requests is subject to their applicable service terms and configured retention controls.

5. How we use information

Depending on the activity and applicable law, processing may be based on your consent, steps needed to provide a feature you request, performance of our agreement, compliance with law, or legitimate interests such as service security and fraud prevention. The operator must confirm the final lawful-basis analysis before release.

6. Nutrition data sources

Bite may use USDA FoodData Central to search for structured generic or branded nutrition records. The gateway sends normalized food or product search terms to USDA; it does not intentionally send your account identifier, email, photo, or full profile. USDA does not sponsor, certify, verify, or endorse Bite.

For confidently identified commercial products, Bite may use OpenAI’s web-search capability to locate current official manufacturer or restaurant nutrition pages. The request can include the identified brand/product, size, market, and relevant meal-description text, but not the meal photo or Bite account identifier. Unverified sites are not accepted as official nutrition sources by the scanner’s validation rules.

7. Service providers and disclosure

We may also disclose information when reasonably necessary to comply with law or a valid legal process, protect users or the service, investigate misuse, establish or defend legal claims, or complete a corporate transaction subject to appropriate safeguards. The final operator must contractually and operationally verify provider protections before launch.

8. International and cloud processing

Supabase, OpenAI, USDA, Apple, and related infrastructure may process information on systems outside the UAE. The country and facility used can depend on provider configuration and service operation. Before release, the operator must document applicable cross-border transfer mechanisms, provider locations, and contractual safeguards.

9. Security

Bite uses authenticated Supabase requests, user-ownership checks, database row-level security, a private photo-storage bucket, and server-side API secrets. Network endpoints in the app are configured to use HTTPS. Authentication sessions are persisted using the app’s configured platform storage.

No system can guarantee absolute security. The operator must complete production security, access-control, backup, incident-response, vendor, and data-protection reviews before release.

10. Retention and deletion

Bite does not currently define fixed retention periods in code. Account, profile, meal, weight, entitlement, consent, and scanner-memory data may remain while your account is active and as needed to provide and secure the service. The final operator must adopt and publish a retention schedule before release, including operational logs and provider-held data.

You can request account deletion from Settings. The authenticated deletion function first removes private scanner photos referenced by your cache records and then deletes your Supabase Auth user. User-owned database records configured with cascading user references are then deleted. If photo cleanup or account deletion fails, the function returns an error instead of reporting successful deletion.

Deletion may not immediately remove information that a provider retains independently, lawful records that must be kept, or copies in backups and security logs. The operator must verify those provider and backup practices before release.

11. Your privacy choices and rights

Subject to applicable law and exceptions, you may ask for access to or a copy of personal data, correction, deletion, restriction or cessation of processing, transfer of data where applicable, or information about processing and disclosures. You may also object to certain processing and withdraw consent where consent is the basis. Withdrawal does not affect processing already lawfully performed and may prevent a requested feature from working.

Use in-app editing/deletion controls or contact biteappnutrition@gmail.com. The final operator must publish the applicable complaint route and UAE Data Office or other regulator details after legal review.

12. Children’s privacy

Bite’s current onboarding accepts users aged 14 or older. Users under the age of legal majority should use Bite only with any consent or supervision required by applicable law. Bite is not directed to children under 14. The operator must complete a child-privacy and age-assurance review for every launch market before release.

13. Changes to this policy

We may update this policy when Bite, its providers, or legal requirements change. We will update the date and provide additional notice or request renewed consent where required.

14. Contact us

Privacy: biteappnutrition@gmail.com

Support: biteappnutrition@gmail.com

Address: Business address to be published before public release