Privacy Policy
Bitewise · Effective 31 August 2026
Bitewise has no accounts. It never asks for your name, your email address or your phone number, and it has no way to work out who you are. What follows is everything it does handle.
The short version
- No sign-up, no login, no account. Your phone gets a random identifier and that is all we know about it.
- Your dietary profile — which is health-adjacent information — is stored on the phone and sent with each scan, and is stored alongside that scan.
- Photos you take are uploaded so a model can read the label, kept for up to seven days, then deleted.
- Nothing is sold, shared with advertisers, or used to track you across other apps or websites.
- Settings → Delete my data erases everything held for your phone, in one step.
The anonymous device id
The first time you open Bitewise, the app generates a random identifier — a UUID — and keeps it in the device keychain. It is not Apple’s advertising identifier, not the vendor identifier, and not derived from anything about you or your hardware. It is sent with every request so the server can return your history rather than someone else’s, count your scans against the included allowance, and rate-limit abuse. Deleting the app removes it; the next install is a new, unrelated identifier.
Your dietary profile
The profile is the diets and allergies you pick, which of them you mark as severe, and any free text you add under “also avoid”. It lives on your phone.
It travels with every scan, and it is stored with that scan. This is not incidental: a verdict is meaningless without knowing what it was judged against, so the profile is sent to the server with each photo and written onto the scan record alongside the result. Two people photographing the same packet get different answers, and the record has to say why.
Allergy and dietary information is health-adjacent data, and we treat it as such: it is attached only to the anonymous device identifier, it is never linked to a name, an email address or an account, and it is used for nothing but producing and storing the verdict you asked for. Two of the options — halal and kosher — may reflect a religious observance, and they are handled with the same care as the rest of the profile.
Photos and text you send
When you photograph a label, the app first downsizes the picture to at most 1024 pixels on its longest side and re-encodes it as a JPEG on your phone. That re-encode also discards the EXIF metadata the camera wrote, including GPS coordinates — which matters, because a label photo is usually taken in a shop.
The reduced image is then uploaded so a vision model can read it, and is kept for up to seven days so your history screen can still show it. After that it is deleted. The scan record — the ingredients that were read, the verdict, the profile it was judged against, the language, timings — stays until you delete it.
If you type or paste an ingredient list instead of photographing one, or ask a follow-up question about a scan, that text is sent and stored in the same way.
Barcodes
Scanning a barcode sends the number to Open Food Facts, a free public food database, to look the product up and skip the photograph entirely. Open Food Facts receives the barcode and, as with any web request, your network address. It does not receive your device identifier or your dietary profile.
Who processes this data
Bitewise runs on a small number of services, each doing one job:
| Who | What reaches them | Why |
|---|---|---|
| The model provider — OpenRouter, and EachLabs where it is configured | The photo or the ingredient text, your dietary profile, and your chosen language | Reading the label and producing the verdict |
| MongoDB Atlas, hosted in the European Union | The scan record: profile, result, language, the anonymous device id, timings | Your history, the result cache, and the scan allowance |
| The image host | The downsized photo, for up to seven days | The model fetches it by URL, and your history shows it |
| Open Food Facts | A barcode number, when you scan one | Looking a product up instead of photographing it |
| RevenueCat — only once subscriptions are switched on | The anonymous device id and the store transaction | Knowing whether a subscription is active |
There is no advertising network, no analytics vendor and no attribution service in this list, and no advertising identifier is read. Nothing is sold or shared with data brokers.
Because these services operate internationally, data may be processed outside your own country. The scan database is hosted in the European Union.
What Bitewise does not collect
- No contact details. There is no account, so there is nothing to ask for.
- No location. The app never requests location permission, and photo GPS data is stripped on your phone before upload.
- No contacts, calendar, microphone or health-app data. None of those permissions are declared.
- No usage analytics. No analytics SDK is included in the app; nothing about which screens you visit leaves your phone.
- No crash-reporting SDK. Crash reports Apple or Google collect on their own are outside the app and governed by their policies.
- No tracking. Nothing is joined with data from other apps or websites, so the app never shows a tracking permission prompt.
Deleting your data
Open Settings → Delete my data. That single action:
- deletes every scan record stored for your device;
- deletes every stored photo that no other scan still points at;
- clears your profile, your local history and your shopping trips from the phone.
There is no account to close, so nothing survives it. If you would rather ask us to do it, or want confirmation that it was done, write to support@mirai.app — but note that without your device identifier we have no way to find your rows, so please send the request from the app’s feedback link, which includes it.
If you are in a jurisdiction that grants rights of access, correction, portability or objection — the GDPR and the UK GDPR among them — those rights apply here too, and the same address is the way to exercise them. Where the GDPR applies, the lawful basis for processing your profile and photos is your consent, given when you start a scan, and it can be withdrawn at any time by deleting your data and uninstalling the app.
Subscriptions
Once in-app purchases are switched on, a subscription auto-renews unless it is cancelled at least 24 hours before the end of the period, in your device’s own subscription settings — on iOS: Settings → your name → Subscriptions. The Terms of Use cover this in full. Until then no purchase flow exists and RevenueCat receives nothing.
Children
Bitewise is not directed at children and does not knowingly collect anything from them. There is no account, no profile beyond dietary preferences, and no social feature of any kind.
Security
Everything travels over HTTPS. The photo is reduced and stripped of metadata before it leaves your phone. The database is reachable only by the API. No credential of yours exists, because there is no account to hold one.
Changes
If this policy changes in a way that affects what is collected or who receives it, the effective date at the top changes and the new version is published here before the change reaches the app.
Contact
A reminder that belongs here too. Bitewise is informational. It is not medical advice, it cannot diagnose anything, and it can be wrong. If a mistake would be dangerous for you, check with the manufacturer.