English
Македонски
Shqip
Privacy Policy — Visibite
Last updated: 13 July 2026
This Privacy Policy explains how Visibite ("we", "our", the "app") handles
information when you use the Visibite Android application. We built this
policy to be honest and short. If anything is unclear, contact us at
support@visibite.app.
1. What we collect
1.1 Information you provide directly
- Email address (if you choose to sign in with email or Google).
- Profile details you enter: name, age, height, weight, activity level,
dietary preferences, allergens, custom watch terms, macro goals.
- Food scan inputs: photos of meals or packaging that you capture with the
camera, optional notes you add before a scan.
- Barcode contributions: product names, brands, ingredients, nutrition
panels, and barcode numbers you voluntarily submit to improve our
database.
- Progress tracking data: weight logs, progress photos, and daily
calorie summaries you record in the Track Your Progress hub.
1.2 Information collected automatically
- Device step-counter readings, stored locally on your device.
- App usage events needed for rate limiting and abuse protection (for
example, how many scans you have submitted today).
- Advertising identifiers: handled by Google AdMob and the Google User
Messaging Platform under your consent selection. See section 4.
1.3 Information we do not collect
- We do not collect your phone contacts, call logs, SMS, photos outside
the camera capture you take inside the app, precise location, or
browsing history.
2. How your data is stored
- On your device. Profile data, daily macros, step
counts, and scan history live in an AES-256 encrypted database on your
phone. The encryption key is generated on your device and managed by
the Android Keystore.
- On our servers (Supabase, EU region). If you are
signed in, your profile and subscription state sync to a Supabase
Postgres database protected by Row-Level Security so only your account
can read or write its own rows.
- Sent to AI providers for processing. To analyse food and
answer wellness questions we send data to third-party AI providers:
- Food scans and nutrition analysis: the captured image and
any optional notes are sent to Alibaba Cloud's Qwen models
(primary) and, for barcode cross-checks, to Google's Gemini API.
- Wellness chat: your question and the diet/exercise context
you choose to share are sent to Groq (primary), then Alibaba
Cloud's Qwen, then Google's Gemini as fallbacks.
- Health profiling: when you ask for meal or training plans
we send your age, weight, height, gender, and goal, plus food-level
allergens, to the providers above for that single request.
We pass only what is needed for each request and do not include your
name or email with these calls. Image-based scans are not retained by
the providers beyond request processing.
3. Why we use your data
- To run the scanner, detect allergens, and estimate nutrition.
- To sync your profile and macro history across devices if you are
signed in.
- To prevent abuse and enforce fair-use rate limits.
- To show ads to free-tier users and to grant bonus scans after you
watch a rewarded ad.
4. Lawful basis and your health data
Visibite processes information that can reveal health (a special category of
personal data under Article 9 GDPR): your weight, height, age, allergens,
activity level, exercise, and the food you scan. We process this health data
only on the basis of your explicit consent (Article 9(2)(a)
GDPR), which you give in the app before first use and can withdraw at any time
(see section 8, Your rights). Account, profile, and subscription data needed to
provide the service are processed on the basis of performance of a
contract (Article 6(1)(b) GDPR). Advertising is processed on the
basis of your consent collected through the Google User Messaging Platform
(see section 6).
5. International data transfers
We store your profile and subscription data in the European Union (Supabase EU
region). To analyse food and answer wellness questions, some data is sent to
processors established outside the EEA:
- United States: Google LLC (Gemini API) and Groq, Inc.
process food images, notes, and wellness-chat context.
- Mainland China: Alibaba Cloud (Qwen models) processes
food images and notes for scan analysis and wellness chat.
Where we transfer personal data outside the EEA, we rely on appropriate
safeguards such as the European Commission's Standard Contractual
Clauses and any supplementary measures. Food images sent for analysis
are not retained by these providers beyond the time needed to process each
request. You can request more detail about the safeguards we use by emailing
support@visibite.app.
6. Ads and consent
Visibite uses Google AdMob to show ads to free-tier users. In the European
Economic Area, the United Kingdom, and Switzerland, we show a consent
dialog powered by the Google User Messaging Platform before any ads load.
Your selection controls whether AdMob shows personalized or
non-personalized ads.
You can change your choice at any time from the main Dashboard → Settings →
About & Legal → Privacy options. AdMob's own disclosures are at
support.google.com/admob/answer/7666366.
7. Third-party services we rely on
| Service | Purpose | Data sent |
| Supabase (EU) | Auth, profile sync, edge functions | Email, profile fields, scan metadata |
| Groq | Wellness chat (primary) | Chat question, diet/exercise context you share |
| Alibaba Cloud (Qwen) | Food scan analysis (primary), wellness chat | Food image, notes, profile fields for plans |
| Google Gemini API | Barcode cross-check, wellness chat fallback | Food image, notes |
| Google AdMob | Ads for free-tier users | Advertising ID (subject to consent) |
| RevenueCat | Subscription management | Purchase receipts, anonymous user ID |
8. Your rights
You can:
- Delete your account at any time from the main Dashboard →
Settings → Delete my account. Deletion is immediate and removes your
login, your cloud-synced profile data, daily macros, water and step
records, workout sessions, AI-generated meal plans, meal-plan
templates and entries, workout templates, progress photos, weight
logs, and any barcode contributions you submitted. This action cannot
be undone.
- Withdraw ad-tracking consent from the main Dashboard → Settings → About &
Legal → Privacy options.
- Contact us at
support@visibite.app
with any access, correction, or erasure request under the GDPR, UK
GDPR, or CCPA.
- Request portability of your data, restriction of processing, or object to
processing, by emailing
support@visibite.app.
9. Children
Visibite is not directed to children under 13 (or the minimum age in your
country). We do not knowingly collect data from children. If you believe a
child has given us data, contact us and we will delete it.
10. Data retention
- Scan history on your device: kept on your device until you clear it
from within the app or uninstall.
- Cloud-synced profile: kept until you delete your account.
- Edge-function logs: retained by Supabase for up to 7 days for
operational debugging, then automatically dropped.
11. Security
- All network traffic uses HTTPS/TLS.
- Local database is encrypted with SQLCipher and a device-generated
AES-256 key stored in the Android Keystore.
- Backend enforces Row-Level Security so no user can read another
user's records.
- API keys for AI providers are never embedded in the app; they live in
server-side secrets.
12. Changes to this policy
If we change anything material, we will update this page and the "last
updated" date above. Continued use of the app after that update means
you accept the revised policy.
13. Contact
support@visibite.app
Visibite Developer
Operated from Republic of North Macedonia