BiteIt

Legal

Privacy Policy

BiteIt · Last updated 14 September 2026

The short version. Your food diary stays on your phone. We hold an account for you — your email address and whether you have paid — and nothing else. A meal photo you choose to scan is sent for analysis and then discarded.

What stays on your phone

All of the following is written to your device's local storage. It is never uploaded, and we have no copy of it:

We cannot read any of it. Uninstalling the app deletes it. Because the diary is not synced, it does not move to a new phone on its own — only your subscription does.

What we hold on our servers

BiteIt needs an account so that a subscription you paid for survives a new phone. The account record is deliberately small:

WhatWhyKept for
Your email address It is the account. It identifies you when you sign in and is where a sign-in code is sent. Until you delete the account
An account identifier A random ID that links you to your subscription record. Until you delete the account
Your name and profile picture
Google sign-in only
Passed to us by Google. Shown on the Account screen so you can see which account you are signed in as. Until you delete the account
Subscription status Which plan you are on, where it was bought, and when it expires. Until you delete the account

That is the whole of it. No meals, no photos, no weights, no targets.

If you sign in with Google, Google also passes us the name and profile picture on your Google account, and we store them alongside your email. They are used for one thing: showing your name and picture on the Account screen so you can see which account you are signed in as. They are not used for anything else, and they are deleted with your account.

Nothing else comes across. Not your contacts, not your files, not your Google activity, and nothing else in your Google account. If you sign in with an email code instead, no name or picture is collected at all.

What leaves your phone when you scan a meal

Only when you actively scan or describe a meal:

WhatWhere it goesKept for
The meal photo, or the text you typed Our processing server, then Google's Gemini API, which returns the estimate Not stored. It is held in memory for the request and discarded.
Your IP address and a random install identifier Our processing server Counters only, cleared automatically about an hour later

The IP address and install identifier are used for one thing: counting how many analyses have been requested, so the service cannot be run up as a bill by automated abuse. They are not attached to your meals or your diary.

Google processes the image under its own terms. See Google's Gemini API terms.

Crash reports

When the app crashes, a report is sent to Sentry, an error-tracking service, so the bug can be found and fixed. A report contains the error and where in the code it happened, the app version, your Android version and your device model.

It is configured not to send the contents of your diary. Personal data is switched off at the source, and the trail of recent actions that crash reporters normally attach — which is where a meal name or a weight could otherwise appear — is stripped from every report before it is sent.

Payments

BiteIt never sees your card. A subscription bought on Android is processed by Google Play, under Google's own privacy policy, and we are told only that a purchase happened and when it expires.

Purchases are managed for us by RevenueCat, which receives the purchase token from Google Play and your account identifier so the subscription can be attached to the right account.

Who else is involved

ServiceWhat it does for BiteIt
Google GeminiReads the meal photo and returns the estimate
SupabaseHosts the sign-in system and the subscription records
ResendDelivers the sign-in code to your email
SentryReceives crash reports
Google Play & RevenueCatTake the payment and tell us whether it is still valid

Each one receives only what it needs to do that job, and none of them receive your food diary.

Camera and photos

Camera access is used only while a scanning screen is open, to photograph a meal, a barcode or a nutrition label. Photo library access is used only when you pick an existing picture. BiteIt does not browse, scan or upload your photo library, and takes no photo you did not trigger.

Notifications

If you enable reminders, they are scheduled by your phone locally. No notification is sent from a server, and no data leaves the device to produce one.

What we do not do

Children

BiteIt is not directed at children under 13, and calorie targets are calculated with formulas intended for adults. We do not knowingly collect data from children.

Your control

Your diary is yours to erase directly. You can delete any individual meal, weight or water entry from inside the app, and uninstalling BiteIt removes everything — diary, photos, weights and profile — because all of it is stored on the device. Neither needs a request to us, because we never had a copy.

Settings → Reset restarts the setup questions and clears your profile and targets. It does not delete your logged meals or weight history.

For the account we do hold, you can ask us to delete it at any time, along with your email address and your subscription record. The account deletion page explains how, and what happens to a subscription that is still running.

Not medical advice. BiteIt estimates calories and macronutrients for general wellness. Estimates from photographs are approximate and can be wrong. It is not a medical device and does not provide medical advice. Talk to a qualified professional before making significant dietary changes, particularly if you are pregnant, managing a health condition, or have a history of disordered eating.

Changes

If this policy changes materially, the date above will be updated and the new version published here before the change takes effect.

Contact

Questions about this policy: junayedhasan2178@gmail.com

See also the Terms of Use.