Privacy Policy

Last updated: August 31, 2026

This policy explains what EATit collects, why, who processes it, and how to delete it. Short version: we collect what the features need, we never sell your data, and the only data we share for advertising is app-install and subscription activity, together with your account id — never your photos, never your chat messages, never your diet profile, and never your email address. If you allow tracking when iOS asks, that sharing also includes your device's advertising identifier.

What we collect

Menu photos you scan (processed to extract the menu; the photo itself is used transiently for text recognition), dish photos you choose to upload (User Content), your email address and name from sign-in (Contact Info), approximate location when you use Nearby (Coarse Location — never precise), purchase history for your subscription (Purchases), an account id (User ID — also used for advertising measurement, see below), your diet and allergen preferences (used only to filter menus, never for hard safety claims), the messages you type in diet chat (Other User Content), device identifiers (Device ID — an app-specific id used for crash reports and analytics, plus your advertising identifier only if you allow tracking when iOS asks), and crash and usage diagnostics.

Who processes it

EATit's backend and storage run on Supabase (our data processor; data at rest). Everything else is named below, with what it receives.

Reading a menu: Google Cloud Vision and Google Gemini Vision receive the menu image when your device's own reading falls short. Microsoft Azure OpenAI receives the recognised menu text to structure it, with Google Gemini as the automatic failover if it is unavailable.

Diet chat: Microsoft Azure OpenAI receives your message, the earlier turns of the conversation, the menu being discussed and your saved diet profile — including any allergens you have declared — with Google Gemini as the automatic failover.

Photo moderation: Google Cloud Vision screens a dish photo you upload, then the same text-model chain checks that it shows the dish.

Dish photos: Pexels and Wikimedia receive dish-name search strings (no personal data); when no real photo exists, Google Gemini or Microsoft Azure OpenAI generates one from the dish name. Microsoft Azure OpenAI also receives dish names for search embeddings.

Everything else: Google Places receives a restaurant name and coordinates — never photos; Apple, RevenueCat and Superwall receive purchase state; Sentry and Datadog receive crash, performance and usage diagnostics, scrubbed of personal identifiers.

Diagnostics only: Azure AI Content Understanding and OpenRouter (Qwen 2.5 VL) are alternative menu readers we compare ours against. They are limited to test environments and to accounts we allowlist for diagnostics; an ordinary scan never reaches them.

Advertising: Meta is the one company here that receives your data for advertising. It receives this in two ways. From the app: installs and activations, and your trial starts and purchases — the product, its price and currency, and an id used so the same purchase is not counted twice. If you allow tracking when iOS asks, the app also sends your device's advertising identifier (IDFA); if you decline, it does not, and every part of the app works exactly the same either way. From our servers: the same trial starts and purchases, sent again so they are not lost, together with your account id in scrambled (hashed) form so Meta can tell that the two reports are the same purchase. Your answer to the tracking question is sent with them, so Meta knows to limit what it does with a purchase from someone who declined. We send your account id rather than your email address on purpose: Meta never receives your email. It never receives your photos, your chat messages, your diet profile or your allergens either. No other company here receives your data for advertising, and we never sell your data.

AI training

Your photos are not used to train AI models unless you explicitly opt in. The opt-in is off by default.

Deletion and retention

Delete your account from Account → Delete Account. Deletion immediately deactivates the account, revokes subscription entitlements, and permanently erases your personal data, uploads, and sign-in record within 7 days. Shared menu content you scanned stays available to the community but is unlinked from you.

Questions

For privacy questions or data requests, use the support contact listed on EATit's App Store page.