English Македонски Srpski Shqip Hrvatski
Last updated: 16 September 2026
This Privacy Policy explains how Visibite ("we", "our", the "app") handles information when you use the Visibite Android application and its backend. We built this policy to be honest and complete. If anything is unclear, contact us at support@visibite.app.
If there is ever a conflict between a translated version and this English version, the English version dated above prevails while re-translation is in progress.
com.allergyapp.decoder), our Supabase backend in the EU, and the website pages at visibite.app/legal/.filesDir/progress_photos/); cloud sync of progress is opt-in only.StepsRecord and ActiveCaloriesBurnedRecord. We do not read other Health Connect types.SpeechRecognizer converts speech to text. The audio is handled by the device / Google speech service under Google's terms; we receive only the transcript you confirm.request_logs), model/key error counters with truncated key hashes (qwen_model_bans, no user content).| Permission | When | Purpose |
|---|---|---|
CAMERA | When you scan | Capture meal / label photo |
RECORD_AUDIO (optional) | Only if you tap mic in chat | Voice-to-text input |
ACTIVITY_RECOGNITION | Only if you enable step tracking | Count steps |
health.READ_STEPS, health.READ_ACTIVE_CALORIES_BURNED (optional) | Only if you connect Health Connect | Show steps / active kcal |
POST_NOTIFICATIONS (optional) | Only if you enable reminders | Wellness reminders, workout timer |
FOREGROUND_SERVICE_HEALTH, RECEIVE_BOOT_COMPLETED | When tracking is on | Keep step service running, resume after reboot |
You can deny or revoke any optional permission in Android Settings; core scanning still works except the feature that needed it.
Weight, height, age, gender, allergens, activity level, exercise, diet and scanned foods can reveal health and are special-category data under GDPR Art. 9. We process them only on your explicit consent (Art. 9(2)(a)), given in the app's Health-data consent screen before first use. Withdrawing consent stops new health processing; prior processing stays lawful. You can withdraw at any time by deleting your account and/or emailing us (section 12). Without that consent you should not use the scanner, chat or planners.
Non-health account data needed to run the service (auth, preferences, entitlements) is processed for performance of the contract (Art. 6(1)(b)). Abuse prevention and stability are legitimate interests (Art. 6(1)(f)). Ads rely on your consent via UMP (Art. 6(1)(a)).
We do not sell your health data. We do not use it for third-party marketing. We do not make solely automated decisions with legal or similarly significant effects; AI outputs are estimates you must verify (Terms §2).
| Task | Provider | Data sent (no name/email) |
|---|---|---|
| Food vision (primary) | Alibaba Cloud Qwen via DashScope-compatible endpoint | Image, notes, OCR/barcode, and for plans also age/weight/height/gender/goal + food-level allergens |
| Barcode cross-check + AI fallback | Google Gemini API | Same image/notes/barcode subset |
| Wellness chat (primary, then fallbacks) | Groq, then Qwen, then Gemini | Your question + diet/exercise context you share |
| Backup models | OpenRouter-hosted models | Same minimal subset when primary fails |
| Backend compute | Supabase Edge Functions (EU) | Auth-verified request, never provider keys |
We strip name and email before AI calls and send only what the request needs. We operate a key/model ladder with retries across regions; the exact sub-model varies by availability and Pro tier.
We use rate-limited API tiers, including free-quota capacity. Do not assume zero retention:
world.openfoodfacts.org (fallbacks de./fr./it./es./mk. mirrors) with the barcode and a Visibite/1.0 user-agent. Responses are public product data under the Open Data Commons Open Database License (ODbL); we cache results on-device for ~7 days. Their terms and attribution apply.api.nal.usda.gov/fdc/v1/foods/search with the food text only.tessdata_fast models, SHA-256 verified) and ML Kit; no image upload is needed for that step.Supabase (EU auth/database/storage/functions), Alibaba Cloud, Google (Gemini, AdMob, Speech, Play), Groq, OpenRouter, RevenueCat / Google Play Billing, OpenFoodFacts, USDA. Each acts as processor/service provider for its purpose under its terms and our instructions. We do not authorise independent reuse of your health data. Authorities receive data only where legally required.
Free-tier users see Google AdMob ads (banner, interstitial, rewarded, app-open). In the EEA/UK/CH we show Google UMP consent before any ad loads; your choice drives personalised vs non-personalised ads. Change it anytime in Dashboard → Settings → About & Legal → Privacy options, plus Android Settings → Privacy → Ads (reset/opt-out of ad personalisation). Personalised ads via AdMob can count as sale/share under US state laws (e.g. CCPA); using Privacy options / OS opt-out is the opt-out. AdMob disclosures: support.google.com/admob/answer/7666366.
When the app crashes it automatically tries to send a short technical report immediately (bounded ~4 seconds so the crash dialog is not stalled) and retries on next launch if there was no network. There is no additional opt-in screen because a crashing app cannot reliably show one.
A report contains only: app version/code, debug flag, timestamp; device manufacturer/model/device/product, Android release/SDK, system build DISPLAY, FINGERPRINT, vendor skin properties, installer package name; language/region tags, timezone, screen size/density/font scale/night mode; crashed thread name and stack trace (truncated at ~60,000 chars), plus a 1,500-char stack_head and its SHA-256 stack_hash for grouping. It does not contain name, email, contacts, location, photos, scan content, notes, or profile contents. Reports POST to our EU Supabase crash_reports table with a write-only public key (no read via app keys) and are visible only to the Visibite team. Standard TLS connection metadata (e.g. IP) is processed transiently to receive the request.
last_crash.txt, or simply uninstall.Health Connect sync is off until you enable it in Wellness/Energy screens. Reads are on-device and limited to steps + active calories; we upload only aggregates you log. Disconnect anytime in Android Settings → Health Connect → App permissions; already-synced aggregates remain until account deletion. Step-service notifications and widgets process counts locally.
| Data | Kept |
|---|---|
On-device Room DB, prefs, progress photos, last_crash.txt | Until in-app clear or uninstall |
| Cloud profile, macros, water, steps, calories burned, workouts, meal plans, templates, contributions, abuse counters | Until account deletion (see §12); edge-function debug logs auto-drop after 7 days |
| Crash reports | Up to 90 days, then auto-deleted |
| Purchase receipts/entitlements | Until account deletion; Google/RevenueCat retain per their own billing/legal retention disclosed at purchase |
| OFF/USDA cache, Tesseract models | On-device cache ~7 days / until replaced |
| Support emails | Up to 24 months for handling, then deleted or anonymised |
| Aggregated, de-identified statistics | May be kept without identifiers |
We do not keep health content longer than needed for the purposes above.
Delete in app: Dashboard → Settings → Delete my account. This signs you out, deletes your Supabase auth user and all user-linked cloud rows we control — including profile, entitlements, daily macros/water/steps/calories-burned, workouts and templates, AI meal plans and meal-plan templates/entries, barcode contributions and contribution reports, progress sync rows where present, private food-images/<uid>/ files, and rate-limit rows — and is irreversible. On-device data is removed on clear/uninstall. Anonymous crash reports and de-identified abuse aggregates cannot be re-linked; we delete identifiable crash matches best-effort on emailed request. Public product data you contributed that was merged into the shared catalogue may persist in de-identified form; email us for removal review.
Your GDPR/UK GDPR rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21, including to crash processing and to direct marketing/ads), withdrawal of consent (Art. 7) without affecting prior lawfulness. US state rights (CA/CPRA et al.): know/delete/correct, opt-out of sale/share of ad identifiers (use §8 controls), non-discrimination, authorised-agent requests with written permission.
Exercise by email to support@visibite.app from your account email with “GDPR request” or “CCPA request” in the subject. We reply within 30 days (extendable once for complexity) and may ask for verification (e.g. in-app confirmation). If unresolved, complain to your local data protection authority (EEA list via the EDPB) or, for North Macedonia, the Directorate for Personal Data Protection, and/or seek judicial remedy. Withdrawing health consent means scans/chat/plans stop working.
Visibite is not directed to children under 13 (or the higher minimum digital-consent age in your country) and is not a kids app. We do not knowingly collect children's data and set UMP tagForUnderAgeOfConsent=false only because we do not target children — we do not age-gate beyond self-declared 13+ in Terms §3. If you believe a child provided data, email us and we will delete it and may terminate the account. Parents/guardians may exercise rights on the child's behalf with proof.
usesCleartextTraffic=false + network security config); SQLCipher AES-256 local DB with Keystore-managed key; Supabase Row-Level Security so users read/write only own rows; provider keys in server secrets, never in the app; Play Integrity attestation for sensitive calls where configured; least-privilege storage rules (food-images/<uid>/ private). No method is 100% secure — report suspected incidents immediately so we can rotate keys and notify where required.AI nutrition, allergen and diet flags are estimates from images, OCR, public databases and models that can be wrong, especially for life-threatening allergies, diabetes or other conditions. Always read the physical label and consult a qualified professional. See Terms §1–§2. Outputs are informational and do not replace medical, nutritional or dietary advice.
Material changes are published here with a new date and, where appropriate, an in-app notice. Continued use after the effective date is acceptance. For major health/AI/transfer changes we will re-prompt consent where required. Prior versions are available on request.
support@visibite.app
Visibite Developer — Skopje, Republic of North Macedonia
This page is informational and not legal advice. It was drafted against the shipped app and backend; have local counsel review before relying on liability caps or transfer assessments.