FotoBiteFotoBite

Privacy Policy

FotoBite — AI-powered calorie tracking Effective date: 22 August 2026 This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) 2016/679 and applicable data-protection laws of EEA member states.


1. Data Controller

FotoBite is delivered via a Telegram Mini App and Telegram bot, operated by:

FieldValue
Legal nameIndividual Entrepreneur Oleg Lalaev
Email[email protected]
Telegram bot@fotobite_bot

We act as Data Controller for all personal data processed through FotoBite. Third-party service providers process data strictly as Data Processors under signed Data Processing Agreements (DPAs).


2. Data We Collect

We apply data minimisation (Art. 5(1)(c) GDPR) and collect only what is necessary to provide the service:

CategorySpecific dataSource
Telegram identityTelegram User IDTelegram API on authorisation
Health & biometric data (Special Category — Art. 9)Sex, age, height (cm), current weight (kg), goal weight (kg), activity levelUser input during onboarding
Food diaryMeal records: date and time, meal type, food names, portion weights, calories and macronutrients; weight and activity entries; the caption you wrote for a photo. Photos themselves are not part of the stored record.User input / AI analysis
Payment dataTelegram payment charge identifier, payer's Telegram identifier, amount in Telegram Stars, purchased plan, payment date, subscription status, refund date and outcome. Card details are never transmitted to us or processed by us — payment happens entirely inside Telegram.Telegram Payments API
Activity dataWeight log entries, active caloriesUser input
Technical / consent dataConsent timestamp & version, timezone, localeAutomatic
Product analyticsEvent type (e.g. app opened, meal saved), event source (bot or Mini App), timestamp and a small set of technical event parameters. Nutrition values, weight, food names and Telegram identifiers are never stored in these records. Records are linked to your account and kept for 365 days.Automatic
AI usage metadataModel name, token counts, latency. A food image is stored in the service's temporary storage for the duration of the analysis and sent to the AI provider without any link to your Telegram identity. The file is deleted when the analysis finishes, whether it succeeded or failed. If processing crashed and the file was orphaned, an automatic sweep removes it no later than 30 hours after upload. We do not keep your photos after the analysis and do not use them to train models.Automatic
We do not collect or store your IP address in your profile or consent record. Security mechanisms (rate-limiting, security logging) may use network data transiently, without linking it to your identity and without long-term retention.
⚠️ Health and biometric data are Special Categories of personal data under Art. 9 GDPR. They are processed exclusively on the basis of your explicit consent (Art. 9(2)(a)).

3. Legal Bases for Processing

PurposeLegal basis
Providing the FotoBite serviceArt. 6(1)(b) — performance of a contract with the user
Health & biometric dataArt. 9(2)(a) — explicit consent
Telegram reminders (optional, opt-in)Art. 6(1)(a) — consent (withdrawable at any time in settings)
Security monitoring & error loggingArt. 6(1)(f) — legitimate interests (system security and reliability)
Compliance with legal obligationsArt. 6(1)(c) — legal obligation

4. How We Share Your Data

We do not sell personal data. Data is shared only with processors, to the minimum extent necessary:

RecipientLocationData sharedPurpose / Safeguard
TelegramglobalTelegram User ID, bot message content, payment operationsAuthentication, bot notifications, payment processing. Governed by Telegram's Privacy Policy.
ITGlobal.comFrankfurt, Germany (EU)Service data at rest (encrypted)Backend and database hosting. DPA in place.
CloudflareEU / USDNS resolutionDomain resolution. DPA in place.
OpenRouterUSThe food image and the prompt — without your Telegram ID or any other user identifierDish recognition and nutrition estimation.
DeepSeekChinaThe dish name you typed (text only, no identifiers)Fallback nutrition estimation when the primary provider is unavailable.
FatSecretUSFood search query textFood database search.
Open Food FactsFrance (EU)Product barcodeProduct composition lookup.
USDA FoodData CentralUSProduct name (text)Reference nutrition values.
SentryEUTechnical error data with no user identifiers or profile dataError monitoring.

International transfers. The primary database is hosted in Germany (EU). Individual recognition and reference lookups are processed in the US and in China; those requests carry no Telegram ID, username or other data that identifies you. For transfers outside the EEA we rely on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses).


5. Your Rights Under GDPR

All requests are handled within 30 days (Art. 12 GDPR). To exercise any right, contact us at the address in Section 12.

RightArticleHow to exercise
AccessArt. 15JSON export in app settings or by email
RectificationArt. 16Profile settings in the app
ErasureArt. 17"Delete account" in app settings, or a written request. Your profile, health data, food diary, weight and activity records, product analytics and subscription data are erased immediately when you use the in-app function, and no later than 10 working days after a written request. A separate payment record is retained afterwards (see Section 6) — it is required to honour the refund guarantee and contains no health, nutrition or weight data.
RestrictionArt. 18Written request by email
PortabilityArt. 20JSON export in app settings
ObjectArt. 21Written request by email
Withdraw consentArt. 7(3)App settings or written request
Complaint to DPAArt. 77Contact your local supervisory authority (see edpb.europa.eu)

6. Data Retention

CategoryRetention period
Profile & health dataUntil account deletion
Food diary, weight and activity entriesUntil account deletion
Food imagesFor the duration of the analysis only. Deleted when it finishes; files orphaned by a crash are swept no later than 30 hours after upload
Raw AI provider response inside an analysis record90 days, then cleared; the analysis record itself is kept until account deletion
AI request log (model, tokens, latency)180 days
Product analytics records365 days
Consent record (date, version)3 years after the processing purposes are met, the consent expires or is withdrawn
Separate payment record after account deletion3 years from the payment date
Sentry error data30 days (Sentry's own policy)

7. Security (Art. 25 & 32 GDPR)

Encryption in transit (TLS 1.2+) and at rest; Telegram-based authentication (no passwords stored); role-based access control and principle of least privilege; real-time infrastructure monitoring (Prometheus / Grafana); security event logging; API documentation disabled in production; no user identifiers or profile data transmitted to our error-monitoring system (send_default_pii=False).

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay (Art. 33 & 34 GDPR).


8. Cookies and Tracking Technologies

We do not use any third-party analytics, advertising, or tracking cookies. The Telegram Mini App uses Telegram's native WebApp initData mechanism and localStorage for the session token only. No third-party trackers are present.


9. Children's Privacy

FotoBite is intended for users aged 18 and over. Data belonging to persons under 18 will be deleted without delay upon discovery.


10. Automated Decision-Making (Art. 22 GDPR)

FotoBite calculates a daily calorie target using the Mifflin–St Jeor formula based on biometric data you provide. This is automated processing but produces no legal or similarly significant effect — all values are advisory and can be overridden by the user. No commercial or advertising profiling takes place.


11. Changes to This Policy

We will notify users of material changes via the Telegram bot at least 7 days before they take effect. Where required by law, fresh consent will be requested.


12. Contact & EU Representative

Data Controller: IE Oleg Lalaev · · Email: [email protected] · Telegram: @fotobite_bot

© 2026 FotoBite. All rights reserved. Effective 22 August 2026.