Privacy Policy
Last updated: [date]
WellBite (“we”, “us”) is a nutrition tracking app operated by [legal name / sole proprietor Ilsur Gabdulkhakov]. This policy explains what we collect, why, and your choices. Short version: your data stays on your device first, meal photos are analyzed and immediately discarded, we don’t sell your data, and there are no ads.
Information we collect
You provide:
- Goal-quiz answers: sex, age, height, weight, activity level, and your goal (bulk, cut, maintain, weight loss, GLP-1 support). Used solely to compute your protein and calorie targets.
- Food logs: meals, dishes, recipes, pantry items, custom foods, portion weights, and body-weight entries.
- Meal, fridge, and nutrition-label photos you choose to take.
Created automatically:
- An anonymous account identifier (Firebase UID). WellBite works without a signup — no name or email is required or collected at registration.
- Usage analytics (PostHog): screens viewed and feature events (e.g. “meal logged”), tied to the anonymous ID.
- Crash and error reports (Sentry): device model, OS version, and technical state at the time of a crash.
- AI request metadata: a daily counter and request log used for abuse prevention and cost control.
Meal photos & AI
Photos are sent to our servers only to be analyzed by an AI model that recognizes foods and estimates nutrition. We do not store your photos on our servers — they are processed and discarded; only the structured result (food names, grams, macros) is kept. A compressed copy of the photo may be stored locally on your device as part of your scan history; it stays there and is deleted with the app. AI nutrition estimates can be inaccurate — they are editable and provided for information only.
How we use information
- Compute your targets and power tracking, suggestions, and the Gap Closer feature (which runs on your device).
- Back up your logged data to our server (keyed to your anonymous ID) so it can be restored if you reinstall.
- Maintain, debug, and improve the app (aggregated analytics, crash reports).
- Prevent abuse of the AI features.
We do not sell personal information, share it for advertising, or show ads.
Subscriptions
Payments are processed by Apple App Store or Google Play — we never see your payment details. We use Adapty to manage subscription state; it receives your anonymous ID and purchase state (trial, active, expired).
Third-party services
| Service | Purpose | What it receives |
|---|---|---|
| Firebase (Google) | Anonymous authentication, app integrity (App Check) | Anonymous UID, device attestation |
| AI provider ([Anthropic/Google]) | Photo → nutrition analysis | The photo (transient), no identifiers beyond request context |
| Adapty | Subscription management | Anonymous UID, purchase state |
| PostHog | Product analytics | Anonymous UID, feature events |
| Sentry | Crash reporting | Device/OS info, error traces |
| Apple / Google | Payments, receipts | Handled under their own policies |
Health data
Your quiz answers, food logs, and weight entries are health-related information. We use them only to provide the app’s features, never for advertising, and never share them except with the processors listed above as needed to run the service. WellBite does not currently read from or write to Apple Health / HealthKit; if that changes, we will ask your permission first and update this policy.
Retention & deletion
Your data lives primarily on your device. The server backup is retained while your anonymous account is active. Settings → Delete account erases your server backup, usage records, and the anonymous account itself; deleting the app removes all local data, including scan history. You can also email us (below) to request deletion.
Your rights
Depending on where you live (e.g. GDPR, CCPA/CPRA), you may have rights to access, correct, export, delete, or restrict processing of your personal information. Because WellBite is anonymous-first, most data is directly visible and editable in the app; for anything else, contact us and we will respond within [30] days. We do not discriminate for exercising your rights. California residents: we do not “sell” or “share” personal information as defined by the CCPA.
Children
WellBite is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has used WellBite, contact us and we will delete the data.
Security
Data in transit is encrypted (TLS; our domain enforces HTTPS). Server access is restricted; requests are authenticated with short-lived tokens issued only to genuine store builds (Firebase App Check).
International transfers
Our servers are located in [the United States]. If you use WellBite from elsewhere, your information is processed in [the US] under this policy.
Changes
We’ll post updates here and update the effective date; material changes will be announced in the app.