← Back to Home

Privacy Policy

Last updated: February 7, 2026

1. Introduction

BiteCal ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI-powered food calorie counter service at bitecal.com ("the Service").

By using the Service, you consent to the practices described in this policy.

2. Information We Collect

2.1 Account Information

When you sign in with Google, we receive your name, email address, and profile picture from Google. We use this information to create and manage your account.

2.2 Food Photos and Analysis Data

When you use the Service, you upload food photos for AI analysis. We process these photos to provide nutritional estimates. Food photos are sent to OpenAI's API for analysis and are not stored permanently on our servers after processing. Analysis results (calorie and macro estimates) are stored in your account for your meal history.

2.3 Usage Data

We automatically collect certain information when you use the Service, including IP address, browser type, device information, pages visited, and interaction patterns. This data helps us improve the Service.

2.4 Payment Information

Payment processing is handled entirely by Polar (our Merchant of Record). We do not store your credit card numbers or payment details. We only receive subscription status information (plan type, billing period, and customer ID) from Polar.

3. How We Use Your Information

  • To provide and maintain the Service
  • To analyze food photos and deliver nutritional estimates
  • To manage your account and subscription
  • To maintain your meal history and dashboard statistics
  • To enforce usage limits based on your subscription plan
  • To communicate important service updates
  • To detect and prevent fraud or abuse
  • To improve the quality and accuracy of our Service

4. AI Processing

BiteCal uses OpenAI's API to analyze food photos. When you submit a photo:

  • The photo is sent to OpenAI's API for food recognition and nutritional analysis
  • No personally identifiable information is sent with the photo
  • OpenAI does not use API inputs to train their models (per OpenAI's API data usage policy)
  • Photos are processed in real-time and are not stored by OpenAI beyond the processing period

5. Third-Party Services

We use the following third-party services:

ServicePurposeData Shared
SupabaseAuthentication & DatabaseAccount info, meal history, settings
OpenAIFood photo analysisFood photos (anonymized)
PolarPayment processingEmail, subscription status
CloudflareHosting & CDNStandard web traffic data
GoogleOAuth authenticationName, email, profile picture

Each third-party service operates under their own privacy policy. We encourage you to review their policies.

6. Data Storage and Security

Your data is stored securely using Supabase (hosted on AWS) with encryption at rest and in transit. We implement Row Level Security (RLS) policies to ensure you can only access your own data. While we take reasonable measures to protect your information, no method of electronic storage is 100% secure.

7. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Request your data in a portable format
  • Restriction: Request restriction of processing
  • Objection: Object to processing of your data

To exercise any of these rights, contact us at privacy@bitecal.com. We will respond within 30 days.

8. Cookies

We use essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Essential cookies cannot be disabled as they are necessary for the Service to function.

9. Data Retention

We retain your account data and meal history for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.

10. Children's Privacy

The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under 13, we will delete it promptly.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related questions or concerns: