Privacy Policy
Policy version: 1
Last updated: [DOLDURULACAK: publication date, e.g. 1 September 2026]
Applies to: the BiteSage mobile application (iOS and Android) and the pages under [DOLDURULACAK: website address]
1. Who we are
BiteSage ("BiteSage", "we", "us") is a nutrition tracking application operated by:
- Legal entity: [DOLDURULACAK: registered company name]
- Registered address: [DOLDURULACAK: full postal address]
- Trade registry / tax number: [DOLDURULACAK: registry no. and tax office]
- Contact e-mail for privacy questions: [DOLDURULACAK: privacy@yourdomain.com]
- Data controller under the Turkish Personal Data Protection Law (KVKK) and the GDPR: the legal entity named above
- VERBİS registration (KVKK): [DOLDURULACAK: VERBİS registration number, or the statement "we are exempt from VERBİS registration"]
- EU / UK representative, if appointed: [DOLDURULACAK: name and address, or "not appointed"]
- Data Protection Officer / contact person: [DOLDURULACAK: name and e-mail, or "not appointed"]
BiteSage is developed in Türkiye and offered internationally.
2. Summary in plain language
- BiteSage keeps a food diary for you. Almost everything we store is something you typed, photographed, or chose.
- Some of that data — your weight, your body measurements, your allergens, what you eat — is health data. Health data gets special protection, and we treat it that way.
- Meal photos are only uploaded and kept if you switch that on. By default the original photo is deleted from your device right after the analysis finishes.
- To recognise a meal from a photo or a description, we send that photo or text to a third-party AI model provider. That happens because you asked for an analysis; it is part of the service.
- Using your data to train or improve an AI model is a separate, optional permission that is off unless you turn it on.
- We do not sell your data. We do not run ads. We never use your health data for advertising.
- You can export everything and delete everything from inside the app, at any time.
3. What we collect
We only collect what the app actually needs. The list below mirrors the data structures in the product; nothing is collected that is not named here.
3.1 Account data
| Data | Why |
|---|---|
| E-mail address and authentication credentials | To create your account, sign you in, and let you recover access. Authentication is handled by our hosting provider (Supabase); we never store your password in readable form. |
| Internal user identifier | To attach your records to your account. |
| Guest status | BiteSage can be used without an account. In guest mode your data stays on your device until you sign up. |
3.2 Profile and goal data
Display name (optional), goal (for example "lose weight", "build muscle"), year or date of birth, sex, height, current weight, target weight, weekly rate of change, activity level, dietary preferences, allergens, unit system (metric/imperial), app language, country, and time zone.
We also store the calorie and macronutrient plan calculated from that profile (calorie range, protein / carbohydrate / fat / fibre targets, water target), together with the history of changes to that plan and the reason for each change.
3.3 Meal and nutrition records
For each meal: the time you ate, the meal type, how it was logged (photo, text, voice, barcode, manual entry, recipe or favourite), a note if you wrote one, whether you confirmed the entry yourself, and the nutrition values frozen at the moment you saved it.
For each food inside a meal: name and brand, amount and unit, weight in grams, cooking method, hidden ingredients such as added oil, the nutrition values, and the confidence scores of the AI estimate.
3.4 Meal photos
If you log a meal with the camera, the photo is used to produce the analysis. What happens to it afterwards depends on two independent permissions you control in Settings → Privacy and security:
- "Store meal photos" — when this is on, the photo is uploaded to a private storage area that only your account can read, and it stays in your diary until you delete the meal or your account. When this is off, no photo is stored on our servers and only nutrition values are kept.
- "Delete the original after analysis" — on by default. The original file is removed from your device as soon as the analysis has finished.
3.5 AI analysis records
For each analysis we keep: the type of input (photo, text, voice transcript, barcode), whether it succeeded or failed and why, which model provider and model version was used, the foods the model detected, the alternatives and clarification questions it offered, your answers to those questions, the estimated calorie range and nutrient values, the recognition and portion confidence scores, the language and country used for the estimate, how long the analysis took, and — where a photo was stored — a reference to that photo.
If you logged the meal by text or voice, the text you typed or the transcript of what you said is stored as part of the analysis record. We also keep the raw response returned by the model provider so that a wrong estimate can be investigated.
Voice input is transcribed on your device by the operating system's own speech recognition. The audio recording itself is not sent to us and is not stored.
3.6 Your corrections
When you correct an AI estimate — swapping a food, changing a portion, removing an item — we store what was there before and what you changed it to. This is how the app learns to show you better defaults, and how we measure whether the model is getting worse. Each correction record also carries a flag showing whether you consented to that correction being used for model improvement.
3.7 Body measurements and hydration
Weight entries (value, date, source, optional note) and water intake entries (amount, date, source). The source records whether you typed the value yourself or it came from Apple Health / Health Connect.
3.8 Health app integration
If you turn on "Health data integration", BiteSage can read your weight and activity from Apple Health (iOS) or Health Connect (Android) and write your nutrition data back to them. This only happens after you also grant the permission in the operating system's own dialog. Data obtained from Apple Health is never used for advertising or sold, and is not shared with third parties beyond what is described in section 6.
3.9 Consent records
Every permission you grant or withdraw is stored separately with its own timestamp and the version of this policy that was in force. We keep these records so that both you and we can prove what was agreed and when. Consent records are kept even after a permission is withdrawn — that is the point of an audit trail.
3.10 Subscription status
Your subscription tier and status (trial, active, in grace period, billing issue, cancelled, expired), the product you bought, the billing period, which store the purchase came from, trial and expiry dates, and the customer identifier issued by our subscription provider (RevenueCat).
We never receive or store your card number, bank details, or billing address. All payments are processed by Apple or Google.
3.11 Notification and reminder settings
Which reminders you enabled, at what time, on which days, and in which time zone.
3.12 Technical and usage data
- Operational logs. Each AI analysis writes a technical record: which provider and model answered, whether the call succeeded, how long it took, how many tokens it consumed, the cost, and any error code. These logs are used to keep the service running and to control cost. They are linked to your account identifier but contain no meal content.
- Product analytics. Only if you turn on "Personal analytics", and only if analytics are configured for the build you are using. The app is built so that analytics can only ever receive a fixed list of anonymous, numeric or categorical events (for example "a paywall was shown", "an analysis failed") together with an anonymous identifier and a small set of coarse properties: app language, country, unit system, subscription tier, goal category, whether onboarding is complete, and whether notifications are enabled. Meal photos, food names, notes, transcripts, weights and any other health value are structurally prevented from reaching analytics.
- Crash reports. If crash reporting is enabled in the build, a crash sends the technical stack trace, the app version and the device model. Crash reports are used only to fix defects.
- Standard server logs. Our hosting provider records IP addresses and request metadata for security and abuse prevention.
3.13 What we do not collect
We do not collect contacts, precise location, browsing history, advertising identifiers (IDFA / Android Advertising ID), or biometric identifiers. There is no advertising SDK in the app, and no cross-app or cross-site tracking.
4. Health data is special
Your weight, body measurements, allergens, dietary restrictions and food diary are:
- special categories of personal data under Article 9 of the GDPR, and
- özel nitelikli kişisel veri (special category personal data) under Article 6 of the Turkish Personal Data Protection Law No. 6698 (KVKK).
That means we process them only on the basis of your explicit consent, we keep them separated from other data by access controls, and we apply the additional technical and organisational measures required by the KVKK Board's decision on adequate measures for special category data. You can withdraw that consent at any time by deleting the data or the account (section 9).
5. Why we process your data, and on what legal basis
| What we do | Data used | Legal basis (GDPR) | Legal basis (KVKK) |
|---|---|---|---|
| Create and run your account, keep your diary in sync across your devices | Account, profile, meals, measurements | Performance of a contract (Art. 6(1)(b)) | Necessary for the performance of a contract (Art. 5/2-c) |
| Calculate your calorie and macronutrient targets, produce charts and insights | Profile, goal plan, meals, weight, hydration — health data | Explicit consent (Art. 9(2)(a)) | Explicit consent (Art. 6/2) |
| Analyse a photo, text or voice description of a meal | Photo or text, language, country, dietary context | Explicit consent (Art. 9(2)(a)) for the health content; performance of a contract for the analysis itself | Explicit consent (Art. 6/2) |
| Store meal photos in your diary | Photos — health data | Explicit consent (Art. 9(2)(a)) | Explicit consent (Art. 6/2) |
| Use anonymised photos and corrections to improve food recognition | Photos, corrections | Explicit, separate consent | Explicit, separate consent (Art. 6/2) |
| Manage subscriptions, entitlements and restore purchases | Subscription status, store identifiers | Performance of a contract (Art. 6(1)(b)) | Necessary for the performance of a contract (Art. 5/2-c) |
| Send reminders you asked for | Notification settings | Consent (Art. 6(1)(a)) | Explicit consent (Art. 6/2) / open consent (Art. 5/1) |
| Send product news and offers | E-mail address | Consent (Art. 6(1)(a)) | Open consent (Art. 5/1) and, in Türkiye, an İYS-registered commercial electronic message approval |
| Keep the service secure, prevent abuse, control AI cost, fix crashes | Technical logs, crash reports | Legitimate interests (Art. 6(1)(f)) | Legitimate interests of the controller (Art. 5/2-f) |
| Product analytics | Anonymous event data | Consent (Art. 6(1)(a)) | Open consent (Art. 5/1) |
| Prove what you consented to, and comply with legal obligations | Consent records, billing records | Legal obligation (Art. 6(1)(c)) and legitimate interests | Legal obligation (Art. 5/2-ç) |
Where we rely on legitimate interests, we have weighed our interest against your rights, and we limit that processing to technical data that carries no meal content.
6. AI processing — what leaves the app
To turn a photo or a description into nutrition values, BiteSage sends the input to a third-party AI model provider. This is what happens, step by step:
- Your app sends the request to our own server function. Your app never talks to the model provider directly and never holds a provider API key.
- Our server function sends the model provider only what is needed for the estimate: the meal photo (as a short-lived signed link or as encoded image data), or the text / voice transcript, plus the language, country, unit system and any dietary context you configured (for example your allergens, so the model can warn you).
- We do not send your name, e-mail address, account identifier, weight, or your diary history to the model provider.
- The provider returns the detected foods and estimated nutrition values. We store that answer against your account and show it to you for confirmation.
Which provider. The provider is configurable and may be one of [DOLDURULACAK: name the providers actually configured in production, e.g. OpenAI, Google Gemini, Anthropic]. The currently used provider and model version are recorded with every analysis and can be seen in your data export. If the primary provider fails, the request is retried with the next configured provider.
How long the provider keeps it. Retention at the provider is governed by that provider's own terms. We use their API tiers under which inputs are not used to train their models and are retained only briefly for abuse monitoring — typically up to 30 days — unless a shorter zero-retention arrangement applies. [DOLDURULACAK: confirm the exact retention window and training terms with the provider(s) you sign with, and link their policy here.]
Model training is separate and optional. The permission "Help improve the model" in Settings → Privacy and security is off by default. It is the only basis on which we would use your photos and corrections to improve food recognition, and it is never bundled with any other permission. If you turn it on, contributions are stripped of identifiers before use. If you turn it off, we stop using new data for that purpose; material already incorporated into a trained model cannot be extracted from it, which is why the switch starts off.
The estimate is an estimate. AI recognition of food and portion size is approximate. BiteSage always shows a calorie range and separate confidence scores instead of a single false-precision number, and asks you to confirm. Please review every estimate before saving it.
7. Who we share data with
We do not sell personal data, and we do not share it with data brokers or advertising networks. We share only with the service providers we need to run the app:
| Recipient | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Hosting, database, authentication, file storage, server functions | All account, profile, diary, photo and consent data | [DOLDURULACAK: the region your Supabase project runs in, e.g. eu-central-1 (Frankfurt)] |
| RevenueCat | Subscription status and entitlement management | Anonymous customer identifier, purchase and subscription status, store receipts | United States |
| AI model provider(s) | Meal recognition from photo, text or barcode | Meal photo or description, language, country, dietary context | [DOLDURULACAK: provider processing region] |
| Apple / Google | Payment processing, app distribution, push notifications, on-device speech recognition | Purchase and subscription data held by the store; we receive only the status | Global |
| [DOLDURULACAK: analytics provider, if enabled — e.g. PostHog] | Product analytics, only with your consent | Anonymous events and coarse properties (section 3.12) | [DOLDURULACAK] |
| [DOLDURULACAK: crash reporting provider, if enabled — e.g. Sentry] | Crash diagnostics | Stack trace, app version, device model | [DOLDURULACAK] |
| [DOLDURULACAK: e-mail provider, if you send marketing e-mail] | Product news and offers, only with your consent | E-mail address | [DOLDURULACAK] |
We may also disclose data where we are legally required to (a valid court order or a lawful request from a competent authority), or to establish, exercise or defend legal claims.
8. International transfers
BiteSage is operated from Türkiye and uses service providers located outside Türkiye and, depending on the region, outside the European Economic Area.
- Under the GDPR, transfers outside the EEA are made on the basis of an adequacy decision where one exists, and otherwise on the basis of the European Commission's Standard Contractual Clauses together with the supplementary measures we consider necessary.
- Under the KVKK, cross-border transfers are made on one of the bases set out in Article 9 — an adequacy decision where one exists, a standard contract notified to the Turkish Data Protection Authority within the statutory period, binding corporate rules, or your explicit consent to the transfer for the specific data concerned.
[DOLDURULACAK: state which of these mechanisms you actually rely on for each provider once your contracts are in place, and confirm any standard-contract notification to the Kurum.]
You can ask us for a copy of the safeguards in place by writing to [DOLDURULACAK: privacy@yourdomain.com].
9. Your rights and how to use them
Under the GDPR and the KVKK you have the right to learn whether we process your data, to access it, to have it corrected, to have it erased, to receive it in a portable format, to object to or restrict certain processing, to withdraw a consent you gave, and to not be subject to a decision based solely on automated processing that produces legal effects on you.
Most of these you can exercise yourself, immediately, in the app:
| Right | Where in the app |
|---|---|
| See and correct your data | Profile tab, and Settings → Profile. Every meal can be edited from the Diary tab. |
| Withdraw or grant a consent | Settings → Privacy and security → Manage permissions. Every permission has its own switch. Turning one on never turns another on. |
| Get a portable copy (data portability) | Settings → Privacy and security → Your data → Export my data. This produces a single machine-readable JSON file containing your profile, goal plan, meals, weight and hydration entries, recipes, consent records, streaks, subscription status and notification preferences. |
| Delete everything (erasure) | Settings → Privacy and security → Your data → Delete my account. You will be asked to type a confirmation word. This erases your profile, meals, photos, measurements, consent records and the account itself. It cannot be undone. |
| Turn off analytics | Settings → Privacy and security → Personal analytics. |
| Turn off health app access | Settings → Privacy and security → Health data integration, and in the operating system's own health privacy settings. |
| Stop reminders | Settings → Notifications. |
Deleting your account from the web. If you cannot access the app, you can request deletion at [DOLDURULACAK: https://yourdomain.com/legal/delete-account.html] or by writing to [DOLDURULACAK: privacy@yourdomain.com] from the e-mail address on the account. We will verify that the request comes from you and complete the deletion within 30 days.
A subscription is not cancelled by deleting your account. Subscriptions are billed by Apple or Google and must be cancelled in your App Store or Google Play account. Cancel first, then delete.
Written requests. You can also contact us at [DOLDURULACAK: privacy@yourdomain.com] or at the postal address in section 1. We respond within 30 days (KVKK Article 13) and within one month (GDPR Article 12), free of charge unless the request is manifestly unfounded or excessive. In Türkiye, applications may also be made in the form set out in the Communiqué on Application Procedures to the Data Controller.
Complaints. If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr) or, in the EEA/UK, to your local supervisory authority.
10. How long we keep data
| Data | Retention |
|---|---|
| Profile, goal plan, meals, meal photos, weight and hydration entries | For as long as your account exists. Deleted immediately when you delete the account or the individual record. |
| Meal photo originals on your device | Deleted right after analysis when "Delete the original after analysis" is on (the default). |
| AI analysis records, including raw provider responses and text/voice transcripts | For as long as your account exists, so that estimates you saved remain explainable. Deleted with the account. |
| Corrections marked for model improvement | Until you withdraw the consent. Anonymised contributions that no longer identify you may be retained. |
| Consent records | Kept as an audit trail for [DOLDURULACAK: retention period, we suggest 10 years, aligned with the Turkish Code of Obligations limitation period] after the account is closed, then deleted. |
| Data export files | Automatically expire 7 days after they are generated. |
| Subscription and billing records | For the period required by tax and commercial law — in Türkiye, 10 years. |
| Operational AI usage logs and server logs | [DOLDURULACAK: e.g. 12 months], then deleted or aggregated. |
| Crash reports | [DOLDURULACAK: e.g. 90 days]. |
| Anonymous analytics events | [DOLDURULACAK: e.g. 24 months]. Not linked to your identity. |
Deletion means deletion: when your account is removed, the diary rows, the stored photos and the authentication record are all destroyed. Backups are overwritten on our hosting provider's normal backup rotation, at most [DOLDURULACAK: e.g. 30 days] later.
11. How we protect your data
- All traffic between the app and our servers is encrypted in transit (TLS). Data at rest is encrypted by our hosting provider.
- Every table containing your data is protected by row-level security, so a request authenticated as you can only ever read rows belonging to you.
- Meal photos live in a private bucket keyed to your account identifier; there are no public links.
- API keys for AI providers exist only on the server. They are never shipped in the app, and the app cannot read them.
- Access to production data by our staff is limited to named administrators, and every administrative write is recorded in an audit log.
- Analytics and logging are designed so that health values and free text cannot be attached to an event.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority within 72 hours (GDPR Article 33) and the Turkish Data Protection Authority within 72 hours, and we will inform you without undue delay, as required by KVKK Article 12 and the Board's decision of 24 January 2019.
12. Children
BiteSage is not directed at children. You must be at least 13 years old to use it — and at least 16 if you are in an EEA country whose national law sets that higher age for consent to information society services. [DOLDURULACAK: confirm the minimum age you will enforce and state it consistently in the Terms of Service and in your App Store / Google Play age rating.]
We do not knowingly collect data from children below that age. If you believe a child has given us data, write to [DOLDURULACAK: privacy@yourdomain.com] and we will delete the account.
Nutrition tracking can be harmful for people with a history of disordered eating. BiteSage deliberately avoids judgemental language and does not label foods as "good" or "bad", but it is still a calorie tracker. Please read the medical disclaimer in the Terms of Service.
13. Advertising
BiteSage does not show advertising, does not contain an advertising SDK, and does not sell or share personal data for cross-context behavioural advertising. Your health data is never used for advertising or marketing profiling, and it is never shared with an advertising network — this is also an explicit requirement of Apple's HealthKit and Google's Health Connect policies, which we follow.
"Product news and offers" is a separate, optional e-mail permission that uses only your e-mail address.
14. Automated decisions
The AI estimate of what is on your plate is automated, and your calorie and macronutrient targets are calculated from your profile using standard energy-expenditure formulas. Neither produces a legal effect or a similarly significant effect on you: both are suggestions you can review, edit and override, and the app always shows a range with confidence scores instead of a single figure. You can enter every meal manually if you prefer not to use the AI at all.
15. Changes to this policy
If we change how we handle your data, we will update this page and raise the policy version. For material changes we will notify you in the app before the change takes effect, and where the change concerns processing based on your consent we will ask for that consent again. Consent records store the policy version you agreed to, so you can always see which version applies to you.
16. Contact
[DOLDURULACAK: registered company name]
[DOLDURULACAK: full postal address]
Privacy: [DOLDURULACAK: privacy@yourdomain.com]
Support: [DOLDURULACAK: support@yourdomain.com]