English Македонски Srpski Shqip Hrvatski

Privacy Policy — Visibite

Last updated: 16 September 2026

This Privacy Policy explains how Visibite ("we", "our", the "app") handles information when you use the Visibite Android application and its backend. We built this policy to be honest and complete. If anything is unclear, contact us at support@visibite.app.

If there is ever a conflict between a translated version and this English version, the English version dated above prevails while re-translation is in progress.

1. Who we are

2. What we collect

2.1 Information you provide directly

2.2 Information collected automatically

2.3 Permissions we request and why

PermissionWhenPurpose
CAMERAWhen you scanCapture meal / label photo
RECORD_AUDIO (optional)Only if you tap mic in chatVoice-to-text input
ACTIVITY_RECOGNITIONOnly if you enable step trackingCount steps
health.READ_STEPS, health.READ_ACTIVE_CALORIES_BURNED (optional)Only if you connect Health ConnectShow steps / active kcal
POST_NOTIFICATIONS (optional)Only if you enable remindersWellness reminders, workout timer
FOREGROUND_SERVICE_HEALTH, RECEIVE_BOOT_COMPLETEDWhen tracking is onKeep step service running, resume after reboot

You can deny or revoke any optional permission in Android Settings; core scanning still works except the feature that needed it.

2.4 Information we do not collect

3. Health data

Weight, height, age, gender, allergens, activity level, exercise, diet and scanned foods can reveal health and are special-category data under GDPR Art. 9. We process them only on your explicit consent (Art. 9(2)(a)), given in the app's Health-data consent screen before first use. Withdrawing consent stops new health processing; prior processing stays lawful. You can withdraw at any time by deleting your account and/or emailing us (section 12). Without that consent you should not use the scanner, chat or planners.

Non-health account data needed to run the service (auth, preferences, entitlements) is processed for performance of the contract (Art. 6(1)(b)). Abuse prevention and stability are legitimate interests (Art. 6(1)(f)). Ads rely on your consent via UMP (Art. 6(1)(a)).

4. How we use your data

We do not sell your health data. We do not use it for third-party marketing. We do not make solely automated decisions with legal or similarly significant effects; AI outputs are estimates you must verify (Terms §2).

5. AI and product-data processing — read this carefully

5.1 Which providers see what

TaskProviderData sent (no name/email)
Food vision (primary)Alibaba Cloud Qwen via DashScope-compatible endpointImage, notes, OCR/barcode, and for plans also age/weight/height/gender/goal + food-level allergens
Barcode cross-check + AI fallbackGoogle Gemini APISame image/notes/barcode subset
Wellness chat (primary, then fallbacks)Groq, then Qwen, then GeminiYour question + diet/exercise context you share
Backup modelsOpenRouter-hosted modelsSame minimal subset when primary fails
Backend computeSupabase Edge Functions (EU)Auth-verified request, never provider keys

We strip name and email before AI calls and send only what the request needs. We operate a key/model ladder with retries across regions; the exact sub-model varies by availability and Pro tier.

5.2 Training, human review and retention at AI providers

We use rate-limited API tiers, including free-quota capacity. Do not assume zero retention:

5.3 Product databases and on-device AI

6. International transfers

7. Who else processes your data

Supabase (EU auth/database/storage/functions), Alibaba Cloud, Google (Gemini, AdMob, Speech, Play), Groq, OpenRouter, RevenueCat / Google Play Billing, OpenFoodFacts, USDA. Each acts as processor/service provider for its purpose under its terms and our instructions. We do not authorise independent reuse of your health data. Authorities receive data only where legally required.

8. Ads and consent

Free-tier users see Google AdMob ads (banner, interstitial, rewarded, app-open). In the EEA/UK/CH we show Google UMP consent before any ad loads; your choice drives personalised vs non-personalised ads. Change it anytime in Dashboard → Settings → About & Legal → Privacy options, plus Android Settings → Privacy → Ads (reset/opt-out of ad personalisation). Personalised ads via AdMob can count as sale/share under US state laws (e.g. CCPA); using Privacy options / OS opt-out is the opt-out. AdMob disclosures: support.google.com/admob/answer/7666366.

9. Crash diagnostics

When the app crashes it automatically tries to send a short technical report immediately (bounded ~4 seconds so the crash dialog is not stalled) and retries on next launch if there was no network. There is no additional opt-in screen because a crashing app cannot reliably show one.

A report contains only: app version/code, debug flag, timestamp; device manufacturer/model/device/product, Android release/SDK, system build DISPLAY, FINGERPRINT, vendor skin properties, installer package name; language/region tags, timezone, screen size/density/font scale/night mode; crashed thread name and stack trace (truncated at ~60,000 chars), plus a 1,500-char stack_head and its SHA-256 stack_hash for grouping. It does not contain name, email, contacts, location, photos, scan content, notes, or profile contents. Reports POST to our EU Supabase crash_reports table with a write-only public key (no read via app keys) and are visible only to the Visibite team. Standard TLS connection metadata (e.g. IP) is processed transiently to receive the request.

10. Health Connect and on-device controls

Health Connect sync is off until you enable it in Wellness/Energy screens. Reads are on-device and limited to steps + active calories; we upload only aggregates you log. Disconnect anytime in Android Settings → Health Connect → App permissions; already-synced aggregates remain until account deletion. Step-service notifications and widgets process counts locally.

11. Retention

DataKept
On-device Room DB, prefs, progress photos, last_crash.txtUntil in-app clear or uninstall
Cloud profile, macros, water, steps, calories burned, workouts, meal plans, templates, contributions, abuse countersUntil account deletion (see §12); edge-function debug logs auto-drop after 7 days
Crash reportsUp to 90 days, then auto-deleted
Purchase receipts/entitlementsUntil account deletion; Google/RevenueCat retain per their own billing/legal retention disclosed at purchase
OFF/USDA cache, Tesseract modelsOn-device cache ~7 days / until replaced
Support emailsUp to 24 months for handling, then deleted or anonymised
Aggregated, de-identified statisticsMay be kept without identifiers

We do not keep health content longer than needed for the purposes above.

12. Deletion and your rights

Delete in app: Dashboard → Settings → Delete my account. This signs you out, deletes your Supabase auth user and all user-linked cloud rows we control — including profile, entitlements, daily macros/water/steps/calories-burned, workouts and templates, AI meal plans and meal-plan templates/entries, barcode contributions and contribution reports, progress sync rows where present, private food-images/<uid>/ files, and rate-limit rows — and is irreversible. On-device data is removed on clear/uninstall. Anonymous crash reports and de-identified abuse aggregates cannot be re-linked; we delete identifiable crash matches best-effort on emailed request. Public product data you contributed that was merged into the shared catalogue may persist in de-identified form; email us for removal review.

Your GDPR/UK GDPR rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21, including to crash processing and to direct marketing/ads), withdrawal of consent (Art. 7) without affecting prior lawfulness. US state rights (CA/CPRA et al.): know/delete/correct, opt-out of sale/share of ad identifiers (use §8 controls), non-discrimination, authorised-agent requests with written permission.

Exercise by email to support@visibite.app from your account email with “GDPR request” or “CCPA request” in the subject. We reply within 30 days (extendable once for complexity) and may ask for verification (e.g. in-app confirmation). If unresolved, complain to your local data protection authority (EEA list via the EDPB) or, for North Macedonia, the Directorate for Personal Data Protection, and/or seek judicial remedy. Withdrawing health consent means scans/chat/plans stop working.

13. Children

Visibite is not directed to children under 13 (or the higher minimum digital-consent age in your country) and is not a kids app. We do not knowingly collect children's data and set UMP tagForUnderAgeOfConsent=false only because we do not target children — we do not age-gate beyond self-declared 13+ in Terms §3. If you believe a child provided data, email us and we will delete it and may terminate the account. Parents/guardians may exercise rights on the child's behalf with proof.

14. Security

15. Medical and accuracy notice

AI nutrition, allergen and diet flags are estimates from images, OCR, public databases and models that can be wrong, especially for life-threatening allergies, diabetes or other conditions. Always read the physical label and consult a qualified professional. See Terms §1–§2. Outputs are informational and do not replace medical, nutritional or dietary advice.

16. Changes

Material changes are published here with a new date and, where appropriate, an in-app notice. Continued use after the effective date is acceptance. For major health/AI/transfer changes we will re-prompt consent where required. Prior versions are available on request.

17. Contact

support@visibite.app
Visibite Developer — Skopje, Republic of North Macedonia

This page is informational and not legal advice. It was drafted against the shipped app and backend; have local counsel review before relying on liability caps or transfer assessments.