
Last updated: September 5, 2026
Draft for legal review. This policy is pending review by counsel. Items in square brackets must be confirmed before publication.
This Privacy Policy explains how Numen Labs ("Numen Labs", "we", "us") collects, uses, discloses, and safeguards personal information when you use the Bitesy and Bitesy+ mobile applications and website (together, the "Service"). It also describes the privacy rights available to you and how to exercise them.
For the purposes of the EU General Data Protection Regulation ("GDPR") and the UK GDPR, Numen Labs is the data controller of the personal data described in this policy. Our contact details are set out in Section 14.
1. Scope of This Policy
This policy applies to all users of the Service, including users located in the United States, Canada, the European Economic Area ("EEA"), the United Kingdom, and Switzerland. Where a specific law grants you rights beyond those described here, that law controls. Region-specific disclosures appear in Sections 10 (United States), 11 (Canada), and 12 (EEA / UK).
2. Personal Information We Collect
We collect the following categories of personal information:
2.1 Information you provide directly
- Account and identity data. Your name or display name and email address, provided at registration or received from your chosen sign-in provider.
- Health and nutrition data. Age, sex or gender, height, current weight, goal weight, activity level, fitness goal, dietary pattern (for example vegetarian, keto), food allergies, disliked foods, and any medical conditions you choose to disclose in the nutrition assessment. In the EEA and UK, information about health, and in some cases dietary practice revealing religious or philosophical belief, constitutes special category data under Article 9 GDPR. We process it only on the basis of your explicit consent, which you may withdraw at any time (see Section 12).
- Body measurement and progress data. Weight log entries, body-fat percentage, muscle mass, and body measurements you record.
- User-generated content. Meal plans, saved recipes, recipe ratings and reviews, grocery lists, group and potluck entries, group invitations, and messages you send to the in-app Poli assistant.
- Photographs and images. Photographs of meals or food packaging you submit to the meal-scanning or barcode features.
- Support correspondence. The name, email address, subject, and message content you submit through our support form, and any attachments.
- Trainer and client data. If you use the Service as a trainer, the client information you enter, including client names, email addresses, and the health and nutrition data listed above. You are responsible for having a lawful basis to provide us with information about another person.
2.2 Information collected automatically
- Device and technical data. Device type and model, operating system and version, application version, language, time zone, and general (city- or region-level) location inferred from your IP address.
- Usage data. Pages and features viewed, actions taken, session timestamps, and diagnostic or crash information.
- Cookies and similar technologies. On the web application we use cookies and local storage that are strictly necessary to authenticate your session and remember your preferences. [CONFIRM: whether any analytics, advertising, or non-essential cookies or SDKs are in use. If yes, a cookie notice and consent mechanism are required in the EEA and UK, and this section must list each cookie, its purpose, and its duration.]
2.3 Information from third parties
- Sign-in providers. If you sign in with Apple or Google, we receive your name, email address (or Apple's private relay address if you elect to hide your email), and a unique account identifier. We do not receive your password.
- Payment and subscription providers. Stripe and RevenueCat provide us with your subscription status, plan, renewal and expiry dates, transaction identifiers, and the country associated with your billing method.
- Group members. Where another user invites you to a group or potluck, we receive the email address they used to invite you.
2.4 Payment card information
We do not collect, process, or store your full payment card number, card expiry, or security code. Card payments on the web are handled directly by Stripe, Inc.; in-app purchases are handled by Apple or Google. We receive only the limited transaction and subscription-status data described above.
3. How and Why We Use Personal Information
The table below sets out each purpose for which we process personal information and, for users in the EEA and UK, the corresponding lawful basis under Article 6 GDPR (and Article 9 where special category data is involved).
| Purpose | Data used | Lawful basis (EEA / UK) |
|---|---|---|
| Create and administer your account; authenticate you | Account and identity data | Performance of a contract (Art. 6(1)(b)) |
| Calculate macro and calorie targets; generate personalised meal plans, recipes, and grocery lists | Health and nutrition data; preferences | Explicit consent (Art. 9(2)(a)) together with performance of a contract (Art. 6(1)(b)) |
| Track progress over time (weight, measurements, adherence) | Body measurement and progress data | Explicit consent (Art. 9(2)(a)) |
| Process subscriptions, verify purchases, prevent payment fraud | Subscription and transaction data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Respond to support requests | Support correspondence; account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Maintain security, prevent abuse, debug and improve the Service | Device, technical, and usage data | Legitimate interests (Art. 6(1)(f)) |
| Send service and transactional messages (for example receipts, renewal notices, security alerts) | Account and subscription data | Performance of a contract (Art. 6(1)(b)) |
| Send optional marketing or promotional messages | Account and identity data | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Comply with law and enforce our Terms | As necessary | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
[CONFIRM: whether marketing emails are actually sent. The current application sends transactional and service email only. If no marketing is sent, delete the marketing row above and the corresponding disclosures throughout.]
4. Automated Processing and AI Features
The Service uses automated systems, including large language models, to generate recipes, estimate nutritional content, produce meal plans, and answer questions you submit to the Poli assistant. To do this, the content of your request — which may include your dietary preferences, allergies, macro targets, and the text or images you submit — is transmitted to our AI processing providers.
These outputs are informational estimates, not medical or dietary advice, and they are not used to make any decision that produces legal effects concerning you or otherwise significantly affects you within the meaning of Article 22 GDPR. We do not engage in profiling for the purpose of automated decision-making. You may request human review of any output by contacting us.
[CONFIRM with counsel and engineering: the identity of each AI subprocessor used through the Base44 platform, the regions in which processing occurs, and whether any provider retains prompt content or uses it for model training. Each must be named in Section 5 and covered by a data processing agreement.]
5. Disclosure of Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We disclose personal information only as described below.
5.1 Service providers and processors
| Recipient | Role | Information disclosed |
|---|---|---|
| Base44 (Wix.com Ltd.) | Application hosting, database, authentication, email delivery, and AI processing platform | All data stored or processed by the Service |
| Stripe, Inc. | Web payment processing and billing management | Email address, customer and subscription identifiers, transaction data. Stripe collects your card details directly as an independent controller. |
| RevenueCat, Inc. | Mobile subscription management and receipt validation | Pseudonymous app user identifier, purchase receipts, subscription status, device and platform data |
| Apple Inc. | Sign in with Apple; App Store in-app purchases and billing | Authentication identifiers; purchase and billing data handled by Apple as an independent controller |
| Google LLC | Google Sign-In; Google Play in-app purchases and billing | Authentication identifiers; purchase and billing data handled by Google as an independent controller |
| U.S. Department of Agriculture — FoodData Central | Reference nutrition database lookups | Food and ingredient search terms only. No account identifiers or health data are transmitted. |
| Spoonacular | Recipe and food data lookups | Recipe and ingredient search terms only. No account identifiers or health data are transmitted. |
| Open Food Facts | Product barcode lookups | Scanned barcode values only |
Each processor is engaged under a written agreement that limits its use of personal information to the provision of services to us. [CONFIRM: that a data processing agreement and, where required, EU/UK Standard Contractual Clauses are executed and on file for each recipient above, and that this list is complete and current.]
5.2 Other users
If you join or create a group or potluck, your display name, email address, the items you contribute or claim, and your meal-completion activity are visible to other members of that group. If you publish a recipe, review, or rating, it is visible as described at the point of publication. Please do not include information in shared content that you do not wish other members to see.
5.3 Trainers
If you are a client of a trainer using the Service, the health, nutrition, and progress information associated with your client record is accessible to that trainer.
5.4 Legal, safety, and corporate transactions
We may disclose personal information where we believe in good faith that it is necessary to comply with applicable law, a lawful request from a public authority, or legal process; to enforce our Terms of Service; or to protect the rights, property, or safety of Numen Labs, our users, or the public. If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy and applicable law. We will notify you before your information becomes subject to a materially different privacy policy.
6. International Transfers
We are based in the United States, and our service providers may process personal information in the United States and other countries whose data-protection laws differ from those of your country of residence.
Where we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on one or more of the following safeguards: (a) an adequacy decision of the European Commission or the UK Government covering the recipient country; (b) the EU Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable; or (c) participation by the recipient in the EU–US, UK–US, or Swiss–US Data Privacy Framework. Where required, we carry out a transfer impact assessment and apply supplementary technical and organisational measures. You may request a copy of the relevant transfer mechanism by contacting us.
For users in Canada: personal information may be stored or processed outside Canada and may therefore be accessible to foreign courts, law enforcement, and national security authorities under the laws of those jurisdictions.
7. Retention
We retain personal information only for as long as necessary for the purposes described in this policy, and thereafter as required to comply with law, resolve disputes, or enforce our agreements.
- Account, health, nutrition, progress, and user-generated content: for the life of your account, and deleted or irreversibly anonymised within [30 / 60 / 90 — CONFIRM] days after you delete your account.
- Support correspondence: [CONFIRM — for example 24 months] from resolution.
- Transaction and subscription records: retained for the period required by applicable tax, accounting, and consumer-protection law [CONFIRM — commonly 7 years].
- Security and diagnostic logs: [CONFIRM — for example 90 days].
We may retain aggregated or de-identified information that can no longer reasonably be associated with you for analytical purposes without time limit.
8. Security
We implement technical and organisational measures appropriate to the risk, including encryption of data in transit, row-level access controls that restrict each record to its owner, restricted administrative access, and secure storage of credentials and API keys. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where required by law, we will notify you and the competent supervisory authority of a personal data breach without undue delay.
9. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us with personal information, please contact us and we will delete it. [CONFIRM with counsel: the age threshold. The Terms of Service require users to be 18 or older; if a lower minimum age is ever adopted, COPPA (US), the applicable GDPR Article 8 age of consent in each EEA member state, and the UK Age Appropriate Design Code will apply.]
10. United States — State Privacy Rights
This section applies to residents of California and of other US states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana. [CONFIRM the current list with counsel, as additional state laws continue to take effect.]
Subject to verification and legal exceptions, you have the right to:
- Know and access the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of recipients.
- Delete the personal information we hold about you.
- Correct inaccurate personal information.
- Obtain a portable copy of the personal information you provided to us.
- Opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information, and we do not conduct targeted advertising, so there is no opt-out to exercise.
- Limit the use and disclosure of sensitive personal information. We use the sensitive personal information we collect (health and dietary information) only to provide the Service you requested, and for no other purpose.
- Non-discrimination. We will not deny service, charge a different price, or provide a different level of quality because you exercised a privacy right. We offer no financial incentives in exchange for personal information.
- Appeal. Where your state provides a right of appeal, you may appeal a refusal of your request by replying to our decision; we will respond within the statutory period.
To exercise a right, use the account-deletion and data controls in the app's Settings screen or contact us as described in Section 14. We will verify your request by reference to the email address associated with your account. An authorised agent may submit a request on your behalf with written proof of authorisation. We do not process the personal information of individuals under 16 for sale or sharing.
Notice regarding health information. [CONFIRM with counsel: whether the Washington My Health My Data Act, the Nevada consumer health data law, or similar consumer-health-data statutes apply to the Service. These laws impose separate consent, disclosure, and "consumer health data privacy policy" requirements, and may require a distinct, separately linked notice.]
11. Canada — PIPEDA
If you are in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation, including Quebec's Law 25. You have the right to:
- Be informed of the existence, use, and disclosure of your personal information, and to access it.
- Challenge the accuracy and completeness of your information and have it amended.
- Withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent to the processing of your health and nutrition data means we can no longer provide the personalised features of the Service.
- Request the portability of your information, and to be informed of automated decision-making, where provided by Law 25.
- Complain to our Privacy Officer and, if unsatisfied, to the Office of the Privacy Commissioner of Canada or your provincial commissioner.
We collect, use, and disclose personal information only for the purposes identified in this policy, and we obtain express consent for sensitive information such as health data. [CONFIRM: designate a named Privacy Officer as required by PIPEDA and record the contact details in Section 14.]
12. EEA and United Kingdom — GDPR Rights
If you are in the EEA, the UK, or Switzerland, you have the right to:
- Access your personal data and receive information about how it is processed (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure of your data, the "right to be forgotten" (Art. 17).
- Restriction of processing in certain circumstances (Art. 18).
- Data portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller (Art. 20).
- Object to processing based on our legitimate interests, and to object at any time to processing for direct marketing (Art. 21).
- Not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you (Art. 22). As explained in Section 4, we do not carry out such processing.
- Withdraw consent at any time where processing is based on consent, including your explicit consent to the processing of health and dietary data. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and means we can no longer provide personalised nutrition features.
- Lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, your local data protection authority. We would appreciate the opportunity to address your concerns first.
We respond to requests within one month, extendable by two further months for complex requests, and free of charge unless the request is manifestly unfounded or excessive.
[CONFIRM with counsel: (a) whether a Data Protection Officer must be appointed given the large-scale processing of special category health data under Article 37(1)(c); (b) whether an Article 27 EU representative and a UK representative are required, as Numen Labs is established outside the EEA and UK but offers services to individuals there. If so, their names and addresses must be published in Section 14; (c) whether a Data Protection Impact Assessment under Article 35 is required for the AI-driven processing of health data.]
13. Your Choices
- Access and edit your data. You can view and change your profile, nutrition assessment, dietary profiles, and logged data at any time in the app.
- Delete your account. You can permanently delete your account and associated data from the Settings screen. Deletion is irreversible.
- Email preferences. You may unsubscribe from optional messages using the link in any such message. We will continue to send transactional messages necessary to administer your subscription.
- Device permissions. You can withdraw camera and other device permissions in your operating system settings, which will disable the features that rely on them.
- Do Not Track and Global Privacy Control. [CONFIRM: whether the web application honours the Global Privacy Control signal. California law requires that an opt-out preference signal be honoured where the business sells or shares personal information.]
14. Contact Us
For privacy questions, to exercise a right, or to make a complaint, contact us at support@numenlabs.net.
[COMPLETE BEFORE PUBLICATION: full legal entity name and registration number of Numen Labs; registered postal address; a dedicated privacy contact address; the name and contact details of the Privacy Officer (Canada) and of the Data Protection Officer, EU Article 27 representative, and UK representative, if appointed.]
15. Changes to This Policy
We may update this policy from time to time. We will revise the "Last updated" date above and, where the changes are material, provide notice in the app or by email before the changes take effect. Where required by law, we will obtain your consent. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
16. No Medical Advice
The Service provides general nutrition and wellness information for educational purposes only. It is not medical advice and does not diagnose, treat, cure, or prevent any disease. Nutritional values are estimates. Always consult a qualified healthcare professional before making dietary changes. Numen Labs is not a covered entity or business associate under the US Health Insurance Portability and Accountability Act (HIPAA), and the Service is not a HIPAA-regulated service.
Questions or Concerns?
If you have any questions about this Privacy Policy, please contact us at support@numenlabs.net