Privacy Policy
Last updated: July 2026
1. Introduction
Mr BITE ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us, including:
- Account information: email address, username, password
- Profile information: age, height, weight, activity level, dietary preferences, health goals
- Meal planning data: recipes, meal plans, shopping lists, nutritional targets
- Health tracking data: weight entries, progress photos, water intake, step counts
- User-generated content: custom recipes, photos, notes, reviews
2.2 Automatically Collected Information
When you use the App, we automatically collect certain information, including:
- Device information: device type and operating system. Mr BITE does not collect an advertising identifier (IDFA) or a vendor device identifier (IDFV).
- Usage data: features used, screens viewed, interaction patterns (via Amplitude product analytics). This is anonymised and contains no health data, meal content or message content, and is processed under our legitimate interest in improving the App. Mr BITE does not track you across other companies' apps or websites and shows no App Tracking Transparency prompt. You can opt out of usage analytics at any time.
- Crash and performance data, including error stack traces (via Sentry). Diagnostic breadcrumbs are scrubbed of personal content before upload.
2.3 Health, Wearable, Camera and Voice Data
With your permission, Mr BITE reads a limited set of health and wearable data from services you connect, including Apple HealthKit on iOS and Google Health / Fitbit through Google OAuth. Mr BITE also uses the device camera, microphone and photo library for food logging and progress features. Specifically:
- Apple HealthKit: body weight, steps, active energy, distance, water intake and dietary energy you choose to share. Raw HealthKit records stay on your device in Apple's encrypted store. If you enable a Mr BITE feature that needs a daily summary, we may save normalized values such as today's step count so the App can display your progress.
- Google Health / Fitbit: if you connect your Google account, Mr BITE requests read-only access to Google Health data that may include steps, active energy, distance, sleep and supported health metrics such as resting heart rate. We use this data only to show health signals in the Analytics screen and to support nutrition and progress features visible in the App.
- Google OAuth tokens: access and refresh tokens received from Google are encrypted before storage and are used only by Mr BITE server functions to sync your connected Google Health / Fitbit data. We do not expose these tokens in the App interface.
- Health Connect: on Android, Mr BITE may request Health Connect permissions for local active-calorie and bodyweight data. This supports the Analytics and progress views without requesting native Health Connect access to distance, sleep, heart rate, exercise sessions, cadence or steps in the current Android release.
- Activity recognition: on Android, Mr BITE may request activity recognition to read step activity from the device pedometer for step goals, analytics and Mr BITE context. This is separate from Health Connect and does not diagnose or provide medical treatment.
- Camera and photo library: barcode scans, meal photos, progress photos. Images you save to Mr BITE are stored in our private cloud storage and only you can view them.
- Microphone: voice recordings you make to log meals. Audio is transcribed and then deleted from our servers; transcripts are retained with your meal log.
2.4 Google API Services Data
Mr BITE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Health or Fitbit data for advertising, interest-based advertising, selling data, credit decisions, insurance decisions, employment decisions, or unrelated profiling.
2.5 Third-Party Information
We may receive information from third-party services you connect to the App, such as:
- Authentication providers (Google, Apple) via Clerk
- Google Health / Fitbit via Google OAuth, only after you explicitly connect your account and grant the requested read-only scopes
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the App and its features
- Generate personalized meal plans and recipe recommendations
- Calculate nutritional information and track your health goals
- Display connected wearable and Google Health / Fitbit signals, such as steps, active energy, distance, sleep and supported heart-rate metrics, inside the Analytics screen and related user-facing progress features
- Send you technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze usage patterns and trends
- Detect, prevent, and address technical issues and security threats
- Personalize your experience and provide relevant content
- Comply with legal obligations and enforce our Terms
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers and Sub-Processors
We share limited data with the following sub-processors. Each is bound by contractual terms and may only use your data to deliver the service to Mr BITE.
- Supabase: database, authentication glue, edge functions, and cloud storage for images uploaded to the App (private buckets: recipe images, product images, and transformation/progress photos).
- Clerk: user authentication, session management and OAuth with Google/Apple.
- OpenAI: food photo recognition and voice transcription. Meal photos and audio are sent without your identity attached and are not used by OpenAI to train their models.
- DeepSeek: powers Mr BITE chat, recipe and meal-plan generation, recipe edits, macro estimation, and shopping-list consolidation. Your messages, the recipe and ingredient text you provide, and relevant context (such as targets, meals, and, if you connect a health source, your steps, energy, sleep, and resting heart rate) are sent without your identity attached. Under our provider settings, this data is not used to train DeepSeek's models.
- Mistral: reads the text out of nutrition documents you choose to upload (for example a PDF meal plan), sent without your identity attached. Under our provider settings, it is not used to train Mistral's models.
- Spoonacular and Open Food Facts: recipe and food-product reference data. Barcode numbers are sent to these services; your identity is not.
- Sentry: crash reporting and error monitoring. We send only your anonymised user id, app version, and error context; we do not send your email address or meal content.
- Amplitude: first-party product analytics only. Anonymised usage events run under our legitimate interest in improving the App. Your identity is anonymised before anything is sent, no health data, meal content or message content is included, and you can opt out at any time. We do not record your screen or your sessions.
Each provider is bound by contractual terms requiring the same or equal protection for your data as this policy. The app asks your permission in-app before any data is sent to an AI provider.
4.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities.
4.3 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction.
4.4 With Your Consent
We may share your information with your explicit consent or at your direction.
4.5 Google Health / Fitbit Data
We do not sell, rent, or transfer Google Health / Fitbit data to third parties for advertising or unrelated purposes. We may process this data through Supabase, our database and edge-function provider, only to provide and improve the user-facing wearable features you requested. We may disclose information only if required by law, for security and abuse prevention, or with your explicit consent.
4.6 Community Recipe Catalog
When you import a recipe from a public social media link (such as an Instagram Reel, TikTok, or YouTube video), Mr BITE creates a private copy in your account and, if the import is a genuine recipe with coherent ingredients, may also add it to a shared community recipe catalog. Catalog recipes are searchable by other Mr BITE users and may be suggested by our meal-planning features. A catalog entry includes only the recipe content: title, ingredients, instructions, nutrition, a cover image, and attribution back to the original creator (their name and a link to the source reel or video so users can watch it). It never includes your account, profile, health data, or any information that identifies you as the importer. We only publish recipes sourced from publicly available links, and we act on valid removal requests from creators or rights holders. If you do not want a recipe shared, you can avoid importing it from a public link, or contact us to have a catalog entry removed.
4.7 Community Product Library
When you scan a product barcode that is not in our data sources, Mr BITE lets you add the product by entering its name, brand, serving size, and the nutrition printed on the label. Contributions are held for review and, once approved, are added to a shared community product library so that other Mr BITE users who scan or search for the same product get the information too. A library entry contains only the product details you enter, never your account, profile, health data, or any information that identifies you as the contributor. Entries are reviewed before they become visible to others, and you can request removal of an entry at any time.
5. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Regular security assessments and updates
- Limited access to personal information on a need-to-know basis
- Encryption of Google OAuth tokens before storage, with token access limited to server-side sync functions
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal purposes.
When you disconnect Google Health / Fitbit in the App, we delete the stored Google OAuth tokens and remove the synced Google Health daily snapshots associated with that connection. You may also delete your account or contact privacy@nutriflex.app to request deletion of your personal data.
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information, including:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data to another service
- Objection: Object to processing of your personal information
- Restriction: Request restriction of processing
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, please contact us at privacy@nutriflex.app. We will respond to your request within 30 days.
8. Children's Privacy
The App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using the App, you consent to the transfer of your information to these countries.
10. Cookies and Tracking Technologies
The App may use cookies, local storage, and similar tracking technologies to enhance your experience, analyze usage, and assist with security. You can control these technologies through your device settings, though this may affect App functionality.
11. Third-Party Links and Services
The App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.
12. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information (we do not sell personal information).
13. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the rights listed in Section 7. Our legal basis for processing your information includes consent, contract performance, legal obligations, and legitimate interests.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
15. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: privacy@nutriflex.app
Support: support@nutriflex.app