Privacy Policy
This Privacy Policy explains how Bite’s UAE-based operator (using the service name Bite) collects, uses, stores, and discloses personal information when you use the Bite nutrition-tracking application.
1. Who we are
Bite is a consumer nutrition and wellness information service operated from the United Arab Emirates. The responsible operator is Bite’s UAE-based operator.
Business address: Business address to be published before public release
Privacy contact: biteappnutrition@gmail.com
2. Information we collect
Account information
- Email address, first name, account identifier, email-verification status, authentication-provider information, and account creation/update dates.
- If you use email authentication, your password is handled by Supabase Auth. Bite does not receive or store a readable copy of it. Authentication and refresh tokens are stored on your device through the app’s configured session storage.
- If you choose Sign in with Apple, Apple and Supabase process the information needed to authenticate you, which may include an Apple account identifier and an email or relay email selected through Apple.
Profile and nutrition information
- Age, gender, height, current and target weight, activity level, nutrition goal, target pace, dietary preference, allergies, foods to avoid, favourite foods, cooking preferences, preferred units, and usual meal frequency.
- Automatic or custom calorie, protein, carbohydrate, fat, fibre, and sugar targets, together with calculated values such as BMR, TDEE, and suggested calories.
- Weight entries, daily nutrition progress, and achievement information generated from your use of Bite.
Meals and nutrition information
- Meal names and descriptions, meal type, serving information, logged date and time, and calories, protein, carbohydrate, fat, fibre, sugar, and sodium values.
- For AI-assisted analysis: identified foods, preparation, estimated quantities and grams, commercial-product clues, nutrition sources, uncertainty information, model output, and validation/provenance metadata.
- Information typed into food searches or discount-code fields is sent to Bite’s backend to perform the requested lookup. A discount-code check does not by itself create a subscription.
Subscription and entitlement information
- Plan and subscription status, verified billing-period dates, scan allowance and usage, reservation identifiers, and provider subscription identifiers if store billing is later enabled.
Technical and consent information
- Policy/Terms acceptance, document version, acceptance status, and time.
- Service providers may generate normal operational records such as request time, IP address, device/browser or network information, response status, and security logs. Bite’s current app code does not integrate an advertising, behavioural analytics, or third-party crash-reporting SDK.
- Bite may write limited development diagnostics, such as request stage, duration, result category, or payload size. The scanner is designed not to log image contents, passwords, authentication tokens, or API keys.
3. Photos, camera, and photo library
Bite requests camera or photo-library permission only when those features are used. Selecting or capturing a photo does not analyze it until you submit the scan.
When submitted, the image is converted to a supported image representation and sent to Bite’s authenticated Supabase Edge Function, then to OpenAI for food identification and portion estimation. The accompanying meal description is submitted with it.
After a successful validated scan, Bite stores a private copy of the submitted photo in Supabase Storage and stores a user-scoped image hash, context hash, meal fingerprint, pipeline version, canonical analysis, quality, provenance, and storage reference in Supabase. This supports exact-photo consistency and conservative recognition of the same physical meal. The bucket is configured as private and cache records are scoped to the authenticated user.
If you later log the result, the meal record may also contain the device-local photo URI. Other devices generally cannot use that local URI. Failed, aborted, or rejected analyses are not intentionally stored as successful canonical scanner results.
4. Written meal descriptions and AI processing
When you request a written nutrition estimate, Bite sends the description through its Supabase gateway to OpenAI. OpenAI is asked to identify foods, preparation, explicit quantities, cooking fats, sauces, and other calorie-contributing components and to produce provisional nutrition estimates.
Bite then attempts to ground components using verified official commercial sources and USDA FoodData Central where appropriate. Some portions or unresolved components may remain AI-assisted estimates. Estimating alone does not save a meal to your meal history; the app saves it only when you choose Log Meal. Service-provider handling of submitted requests is subject to their applicable service terms and configured retention controls.
5. How we use information
- Provide, secure, and maintain accounts and authentication.
- Personalize nutrition targets and display meals, daily progress, history, weight progress, and achievements.
- Analyze submitted meal photos and descriptions, ground nutrition data, validate estimates, and maintain scanner consistency.
- Log, edit, and delete meals at your direction.
- Administer free and Bite+ scan allowances, prevent duplicate charging, enforce rate limits, and protect against misuse.
- Record legal choices, respond to support/privacy requests, diagnose failures, and comply with applicable legal obligations.
Depending on the activity and applicable law, processing may be based on your consent, steps needed to provide a feature you request, performance of our agreement, compliance with law, or legitimate interests such as service security and fraud prevention. The operator must confirm the final lawful-basis analysis before release.
6. Nutrition data sources
Bite may use USDA FoodData Central to search for structured generic or branded nutrition records. The gateway sends normalized food or product search terms to USDA; it does not intentionally send your account identifier, email, photo, or full profile. USDA does not sponsor, certify, verify, or endorse Bite.
For confidently identified commercial products, Bite may use OpenAI’s web-search capability to locate current official manufacturer or restaurant nutrition pages. The request can include the identified brand/product, size, market, and relevant meal-description text, but not the meal photo or Bite account identifier. Unverified sites are not accepted as official nutrition sources by the scanner’s validation rules.
7. Service providers and disclosure
- Supabase: authentication, session infrastructure, database, private file storage, Edge Functions, and access controls.
- OpenAI: AI-assisted photo and written-meal interpretation and, for eligible commercial products, official-source web search.
- USDA FoodData Central: structured food and nutrition searches.
- Apple: Apple authentication when selected and, once implemented, App Store subscription processing.
- Expo and device operating-system services: app runtime and permission handling. Current code requests notification permission but does not register or store an Expo push token.
We may also disclose information when reasonably necessary to comply with law or a valid legal process, protect users or the service, investigate misuse, establish or defend legal claims, or complete a corporate transaction subject to appropriate safeguards. The final operator must contractually and operationally verify provider protections before launch.
8. International and cloud processing
Supabase, OpenAI, USDA, Apple, and related infrastructure may process information on systems outside the UAE. The country and facility used can depend on provider configuration and service operation. Before release, the operator must document applicable cross-border transfer mechanisms, provider locations, and contractual safeguards.
9. Security
Bite uses authenticated Supabase requests, user-ownership checks, database row-level security, a private photo-storage bucket, and server-side API secrets. Network endpoints in the app are configured to use HTTPS. Authentication sessions are persisted using the app’s configured platform storage.
No system can guarantee absolute security. The operator must complete production security, access-control, backup, incident-response, vendor, and data-protection reviews before release.
10. Retention and deletion
Bite does not currently define fixed retention periods in code. Account, profile, meal, weight, entitlement, consent, and scanner-memory data may remain while your account is active and as needed to provide and secure the service. The final operator must adopt and publish a retention schedule before release, including operational logs and provider-held data.
You can request account deletion from Settings. The authenticated deletion function first removes private scanner photos referenced by your cache records and then deletes your Supabase Auth user. User-owned database records configured with cascading user references are then deleted. If photo cleanup or account deletion fails, the function returns an error instead of reporting successful deletion.
Deletion may not immediately remove information that a provider retains independently, lawful records that must be kept, or copies in backups and security logs. The operator must verify those provider and backup practices before release.
11. Your privacy choices and rights
Subject to applicable law and exceptions, you may ask for access to or a copy of personal data, correction, deletion, restriction or cessation of processing, transfer of data where applicable, or information about processing and disclosures. You may also object to certain processing and withdraw consent where consent is the basis. Withdrawal does not affect processing already lawfully performed and may prevent a requested feature from working.
Use in-app editing/deletion controls or contact biteappnutrition@gmail.com. The final operator must publish the applicable complaint route and UAE Data Office or other regulator details after legal review.
12. Children’s privacy
Bite’s current onboarding accepts users aged 14 or older. Users under the age of legal majority should use Bite only with any consent or supervision required by applicable law. Bite is not directed to children under 14. The operator must complete a child-privacy and age-assurance review for every launch market before release.
13. Changes to this policy
We may update this policy when Bite, its providers, or legal requirements change. We will update the date and provide additional notice or request renewed consent where required.
14. Contact us
Privacy: biteappnutrition@gmail.com
Support: biteappnutrition@gmail.com
Address: Business address to be published before public release