Privacy Policy
FotoBite — AI-powered calorie tracking Effective date: 10 July 2026 This Privacy Policy complies with the EU General Data Protection Regulation (GDPR) 2016/679 and applicable data-protection laws of EEA member states.
1. Data Controller
FotoBite is delivered via a Telegram Mini App and Telegram bot, operated by:
| Field | Value |
|---|---|
| Legal name | Individual Entrepreneur Oleg Lalaev |
| [email protected] | |
| Telegram bot | @fotobite_bot |
We act as Data Controller for all personal data processed through FotoBite. Third-party service providers process data strictly as Data Processors under signed Data Processing Agreements (DPAs).
2. Data We Collect
We apply data minimisation (Art. 5(1)(c) GDPR) and collect only what is necessary to provide the service:
| Category | Specific data | Source |
|---|---|---|
| Telegram identity | Telegram User ID, first name, username | Telegram API on authorisation |
| Health & biometric data (Special Category — Art. 9) | Sex, age, height (cm), current weight (kg), goal weight (kg), activity level | |
| Food diary | Meal records (date, type, macros/kcal, food items), food photos | User input / AI analysis |
| Activity data | Weight log entries, active calories | User input |
| Technical / consent data | Consent timestamp & version, timezone, locale | Automatic |
| Product analytics | Event type (e.g. app opened, meal saved), event source (bot or Mini App), timestamp and a small set of technical event parameters. Nutrition values, weight, food names and Telegram identifiers are never stored in these records. Records are linked to your account and kept for 365 days. | Automatic |
| AI usage metadata | Model name, token counts, latency. Food images are sent to the AI provider without any link to your Telegram identity, processed at analysis time and deleted immediately. We do not store your photos. | Automatic |
We do not collect or store your IP address in your profile or consent record. Security mechanisms (rate-limiting, security logging) may use network data transiently, without linking it to your identity and without long-term retention.
⚠️ Health and biometric data are Special Categories of personal data under Art. 9 GDPR. They are processed exclusively on the basis of your explicit consent (Art. 9(2)(a)).
3. Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Providing the FotoBite service | Art. 6(1)(b) — performance of a contract with the user |
| Health & biometric data | Art. 9(2)(a) — explicit consent |
| Telegram reminders (optional, opt-in) | Art. 6(1)(a) — consent (withdrawable at any time in settings) |
| Security monitoring & error logging | Art. 6(1)(f) — legitimate interests (system security and reliability) |
| Compliance with legal obligations | Art. 6(1)(c) — legal obligation |
4. How We Share Your Data
We do not sell personal data. Data is shared only with processors, to the minimum extent necessary:
| Recipient | Data shared | Purpose / Safeguard |
|---|---|---|
| Telegram | Telegram User ID | Bot notifications. Governed by Telegram's Privacy Policy. |
| ITGlobal.com (Frankfurt, Germany) | Service data at rest (encrypted) | Backend hosting. DPA in place. |
| Cloudflare | Encrypted database backups (R2); DNS resolution | Backup storage and domain resolution. DPA in place. |
International transfers. The primary database is hosted in Germany (EU); encrypted backups are stored in Cloudflare's infrastructure. For any transfers outside the EEA, we rely on appropriate safeguards under Art. 46 GDPR (Standard Contractual Clauses).
5. Your Rights Under GDPR
All requests are handled within 30 days (Art. 12 GDPR). To exercise any right, contact us at the address in Section 12.
| Right | Article | How to exercise |
|---|---|---|
| Access | Art. 15 | JSON export in app settings or by email |
| Rectification | Art. 16 | Profile settings in the app |
| Erasure | Art. 17 | "Delete account" in app settings (immediate) |
| Restriction | Art. 18 | Written request by email |
| Portability | Art. 20 | JSON export in app settings |
| Object | Art. 21 | Written request by email |
| Withdraw consent | Art. 7(3) | App settings or written request |
| Complaint to DPA | Art. 77 | Contact your local supervisory authority (see edpb.europa.eu) |
6. Data Retention
| Category | Retention period |
|---|---|
| Profile & biometric data | Until account deletion; backups purged within 30 days |
| Food diary entries | Until account deletion |
| Food images | Not stored — processed at analysis time and deleted immediately |
| Technical / API logs | 90 days |
| Consent records (date, version) | 3 years |
| Sentry error data | 30 days (Sentry's own policy) |
7. Security (Art. 25 & 32 GDPR)
Encryption in transit (TLS 1.2+) and at rest; Telegram-based authentication (no passwords stored); role-based access control and principle of least privilege; real-time infrastructure monitoring (Prometheus / Grafana); security event logging; API documentation disabled in production; no PII transmitted to Sentry (send_default_pii=False); backups stored encrypted.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay (Art. 33 & 34 GDPR).
8. Cookies and Tracking Technologies
We do not use any third-party analytics, advertising, or tracking cookies. The Telegram Mini App uses Telegram's native WebApp initData mechanism and localStorage for the session token only. No third-party trackers are present.
9. Children's Privacy
FotoBite is intended for users aged 16 and over. For users aged 16–17, processing is carried out with the awareness of a parent or guardian where required by applicable law. Data belonging to persons under 16 will be deleted without delay upon discovery.
10. Automated Decision-Making (Art. 22 GDPR)
FotoBite calculates a daily calorie target using the Mifflin–St Jeor formula based on biometric data you provide. This is automated processing but produces no legal or similarly significant effect — all values are advisory and can be overridden by the user. No commercial or advertising profiling takes place.
11. Changes to This Policy
We will notify users of material changes via the Telegram bot at least 7 days before they take effect. Where required by law, fresh consent will be requested.
12. Contact & EU Representative
Data Controller: IE Oleg Lalaev · · Email: [email protected] · Telegram: @fotobite_bot
© 2026 FotoBite. All rights reserved. Effective 10 July 2026.