Privacy Policy
1. General Information
This privacy policy describes how we collect, use, and protect your personal data when using the Food Diary application.
2. Data We Collect
Account data:
- Name, language, theme, and profile settings if provided
Nutrition and health tracking data:
- Meal records, products, recipes, calories, macro and micronutrients
- Weight, waist, fasting, hydration, cycle, exercise, goals, and related check-in data
- Food photos if you upload them
AI feature data:
- Text descriptions of meals
- Voice recordings converted to text
- Food images
Technical, security, and analytics data:
- IP address and masked IP shown to administrators
- User-Agent, browser, operating system, and device type
- Login timestamp and authentication provider
- Error, performance, and security logs
- Campaign attribution data such as UTM parameters, landing page, referrer host, anonymous visitor ID, session ID, signup and premium conversion events
3. How We Use Data
We use data for:
- Providing application functionality
- Analyzing and improving the service
- AI features such as food recognition
- Security and abuse prevention
- Reviewing successful login history and aggregated device/browser usage in the admin area
- Understanding which campaigns, referral sources, and landing pages lead to signups or premium conversions
4. AI and Third-Party Services
Our application uses third-party AI services such as OpenAI. When you use AI features, your text, voice, or image data may be transmitted to these services and processed according to their privacy policies and terms.
According to OpenAI documentation, data sent via the API is not used for model training by default, unless a customer explicitly opts in or provider terms change.
5. Legal Basis for Processing
We process your data on the following grounds:
- Performance of contract for providing the service - Art. 6(1)(b) GDPR
- Your consent for AI features where required - Art. 6(1)(a) GDPR
- Legitimate interests for security, service analytics, and campaign attribution - Art. 6(1)(f) GDPR
6. Data Transfers Outside the EU
Your data may be transferred to countries outside the European Economic Area, for example the United States. Such transfers are carried out using Standard Contractual Clauses or other safeguards provided by GDPR.
7. Data Retention
- Account data - as long as the account exists
- Nutrition and tracking data - until deleted by the user or account deletion
- Technical logs - limited time, normally up to 30 days
- Login activity records - normally up to 180 days unless longer retention is required for security investigation or legal reasons
- Raw campaign attribution events - normally up to 365 days; aggregated campaign analytics may be retained longer without directly identifying personal data
We do not store raw data sent to AI longer than necessary for processing unless a feature explicitly requires retention.
8. Your Rights
You have the right to request access, correction, deletion, restriction of processing, data portability, and withdrawal of consent where processing is based on consent.
9. Security
We take reasonable technical and organizational measures to protect your data.
10. Policy Changes
We may update this policy. In case of significant changes, we will notify you.