Privacy Notice
1. Data processed
- Telegram user ID, username where available and language code;
- selected timezone;
- a submitted photo while AI analysis is running;
- recognized foods, portions, calories, macronutrients, diary and goals;
- technical status and limited security/error logs;
- Telegram Stars subscription and payment events, transaction identifiers and entitlement history.
Do not include documents, faces, addresses or unrelated personal data in food photos.
2. Purposes
Data is used to operate the bot, estimate nutrition, maintain and correct the diary, manage quotas and subscriptions, provide support, maintain security, prevent duplicate charges and abuse, and improve aggregate service quality.
3. Photos and AI providers
A photo is downloaded from Telegram, normalized in volatile memory and sent through OpenRouter to a selected upstream AI provider, including Google or OpenAI depending on the locked processing profile. This may be a cross-border transfer.
The application does not persist original or normalized photo bytes. They are released after the operation. Requests require ZDR, data_collection=deny and store=false. Derived meal data and limited technical result metadata may be stored in the diary and service logs.
The service displays this transfer notice before the first photo. Sending a photo after the notice requests AI analysis. You may decline by not sending a photo and stopping use of the feature.
4. Recipients
- Telegram for messages, files and payments;
- OpenRouter and the selected upstream AI provider for photo analysis;
- hosting, database and backup providers for service operation;
- public authorities only where disclosure is mandatory.
The operator does not sell personal data or authorize photo-based advertising profiling on its behalf.
5. Location and retention
The initial MVP is planned to be hosted in Germany/EU; the specific provider may change. Database backups are retained for up to 30 days. Drafts and temporary state expire under technical TTLs. Diary and settings remain until account deletion or while needed to provide the service. Payment, anti-fraud and audit records may remain longer in pseudonymized form for disputes, abuse prevention and mandatory accounting.
6. Deletion and re-entry
/delete_me removes the nutrition profile, diary, goals, scans, drafts, sessions and all re-fetchable photo handles. A plaintext Telegram ID is not retained in the deleted nutrition profile. A non-reversible keyed fingerprint may remain to prevent a repeated trial and connect mandatory payment/audit records without restoring nutrition history. A later /start creates an empty profile.
7. Requests and rights
You may request access, correction or deletion through @foodbot_support, or delete the account with /delete_me. Some records may remain where deletion is prohibited or the record is needed for a payment dispute, security or mandatory accounting.
8. Security
The service uses access controls, transport encryption, separated secrets, minimal logs, backups and a prohibition on persistent raw photos. No system can provide absolute security.
9. Changes
A new version will be published for material processing changes and renewed acceptance will be requested where needed to use a feature or make a purchase.