Privacy Policy
FotoBite — AI-powered calorie tracking Effective date: 22 August 2026 This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) 2016/679 and applicable data-protection laws of EEA member states.
1. Data Controller
FotoBite is delivered via a Telegram Mini App and Telegram bot, operated by:
| Field | Value |
|---|---|
| Legal name | Individual Entrepreneur Oleg Lalaev |
| [email protected] | |
| Telegram bot | @fotobite_bot |
We act as Data Controller for all personal data processed through FotoBite. Third-party service providers process data strictly as Data Processors under signed Data Processing Agreements (DPAs).
2. Data We Collect
We apply data minimisation (Art. 5(1)(c) GDPR) and collect only what is necessary to provide the service:
| Category | Specific data | Source |
|---|---|---|
| Telegram identity | Telegram User ID | Telegram API on authorisation |
| Health & biometric data (Special Category — Art. 9) | Sex, age, height (cm), current weight (kg), goal weight (kg), activity level | User input during onboarding |
| Food diary | Meal records: date and time, meal type, food names, portion weights, calories and macronutrients; weight and activity entries; the caption you wrote for a photo. Photos themselves are not part of the stored record. | User input / AI analysis |
| Payment data | Telegram payment charge identifier, payer's Telegram identifier, amount in Telegram Stars, purchased plan, payment date, subscription status, refund date and outcome. Card details are never transmitted to us or processed by us — payment happens entirely inside Telegram. | Telegram Payments API |
| Activity data | Weight log entries, active calories | User input |
| Technical / consent data | Consent timestamp & version, timezone, locale | Automatic |
| Product analytics | Event type (e.g. app opened, meal saved), event source (bot or Mini App), timestamp and a small set of technical event parameters. Nutrition values, weight, food names and Telegram identifiers are never stored in these records. Records are linked to your account and kept for 365 days. | Automatic |
| AI usage metadata | Model name, token counts, latency. A food image is stored in the service's temporary storage for the duration of the analysis and sent to the AI provider without any link to your Telegram identity. The file is deleted when the analysis finishes, whether it succeeded or failed. If processing crashed and the file was orphaned, an automatic sweep removes it no later than 30 hours after upload. We do not keep your photos after the analysis and do not use them to train models. | Automatic |
We do not collect or store your IP address in your profile or consent record. Security mechanisms (rate-limiting, security logging) may use network data transiently, without linking it to your identity and without long-term retention.
⚠️ Health and biometric data are Special Categories of personal data under Art. 9 GDPR. They are processed exclusively on the basis of your explicit consent (Art. 9(2)(a)).
3. Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Providing the FotoBite service | Art. 6(1)(b) — performance of a contract with the user |
| Health & biometric data | Art. 9(2)(a) — explicit consent |
| Telegram reminders (optional, opt-in) | Art. 6(1)(a) — consent (withdrawable at any time in settings) |
| Security monitoring & error logging | Art. 6(1)(f) — legitimate interests (system security and reliability) |
| Compliance with legal obligations | Art. 6(1)(c) — legal obligation |
4. How We Share Your Data
We do not sell personal data. Data is shared only with processors, to the minimum extent necessary:
| Recipient | Location | Data shared | Purpose / Safeguard |
|---|---|---|---|
| Telegram | global | Telegram User ID, bot message content, payment operations | Authentication, bot notifications, payment processing. Governed by Telegram's Privacy Policy. |
| ITGlobal.com | Frankfurt, Germany (EU) | Service data at rest (encrypted) | Backend and database hosting. DPA in place. |
| Cloudflare | EU / US | DNS resolution | Domain resolution. DPA in place. |
| OpenRouter | US | The food image and the prompt — without your Telegram ID or any other user identifier | Dish recognition and nutrition estimation. |
| DeepSeek | China | The dish name you typed (text only, no identifiers) | Fallback nutrition estimation when the primary provider is unavailable. |
| FatSecret | US | Food search query text | Food database search. |
| Open Food Facts | France (EU) | Product barcode | Product composition lookup. |
| USDA FoodData Central | US | Product name (text) | Reference nutrition values. |
| Sentry | EU | Technical error data with no user identifiers or profile data | Error monitoring. |
International transfers. The primary database is hosted in Germany (EU). Individual recognition and reference lookups are processed in the US and in China; those requests carry no Telegram ID, username or other data that identifies you. For transfers outside the EEA we rely on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses).
5. Your Rights Under GDPR
All requests are handled within 30 days (Art. 12 GDPR). To exercise any right, contact us at the address in Section 12.
| Right | Article | How to exercise |
|---|---|---|
| Access | Art. 15 | JSON export in app settings or by email |
| Rectification | Art. 16 | Profile settings in the app |
| Erasure | Art. 17 | "Delete account" in app settings, or a written request. Your profile, health data, food diary, weight and activity records, product analytics and subscription data are erased immediately when you use the in-app function, and no later than 10 working days after a written request. A separate payment record is retained afterwards (see Section 6) — it is required to honour the refund guarantee and contains no health, nutrition or weight data. |
| Restriction | Art. 18 | Written request by email |
| Portability | Art. 20 | JSON export in app settings |
| Object | Art. 21 | Written request by email |
| Withdraw consent | Art. 7(3) | App settings or written request |
| Complaint to DPA | Art. 77 | Contact your local supervisory authority (see edpb.europa.eu) |
6. Data Retention
| Category | Retention period |
|---|---|
| Profile & health data | Until account deletion |
| Food diary, weight and activity entries | Until account deletion |
| Food images | For the duration of the analysis only. Deleted when it finishes; files orphaned by a crash are swept no later than 30 hours after upload |
| Raw AI provider response inside an analysis record | 90 days, then cleared; the analysis record itself is kept until account deletion |
| AI request log (model, tokens, latency) | 180 days |
| Product analytics records | 365 days |
| Consent record (date, version) | 3 years after the processing purposes are met, the consent expires or is withdrawn |
| Separate payment record after account deletion | 3 years from the payment date |
| Sentry error data | 30 days (Sentry's own policy) |
7. Security (Art. 25 & 32 GDPR)
Encryption in transit (TLS 1.2+) and at rest; Telegram-based authentication (no passwords stored); role-based access control and principle of least privilege; real-time infrastructure monitoring (Prometheus / Grafana); security event logging; API documentation disabled in production; no user identifiers or profile data transmitted to our error-monitoring system (send_default_pii=False).
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay (Art. 33 & 34 GDPR).
8. Cookies and Tracking Technologies
We do not use any third-party analytics, advertising, or tracking cookies. The Telegram Mini App uses Telegram's native WebApp initData mechanism and localStorage for the session token only. No third-party trackers are present.
9. Children's Privacy
FotoBite is intended for users aged 18 and over. Data belonging to persons under 18 will be deleted without delay upon discovery.
10. Automated Decision-Making (Art. 22 GDPR)
FotoBite calculates a daily calorie target using the Mifflin–St Jeor formula based on biometric data you provide. This is automated processing but produces no legal or similarly significant effect — all values are advisory and can be overridden by the user. No commercial or advertising profiling takes place.
11. Changes to This Policy
We will notify users of material changes via the Telegram bot at least 7 days before they take effect. Where required by law, fresh consent will be requested.
12. Contact & EU Representative
Data Controller: IE Oleg Lalaev · · Email: [email protected] · Telegram: @fotobite_bot
© 2026 FotoBite. All rights reserved. Effective 22 August 2026.