Data we collect
- Account: email address (including Hide My Email from Sign in with Apple), display name, and a Firebase user ID. Sign-in methods are email/password, Sign in with Apple, and Sign in with Google.
- Health & fitness (you enter it): gender, birth year, height, weight, goal weight, activity level, diet preference, usual climate, typical fluid intake, caffeine habit, meal times, food logs (including items added from barcode scan or AI Food Scan), water/fluids, and activity burn.
- Barcode lookups: when you scan a product barcode, the numeric code is sent to Open Food Facts to fetch a nutrition estimate. We do not store the live barcode camera preview. We may store the food name, serving, macros, and a product image URL if the lookup returns one.
- AI Food Scan photos: if you capture or pick a meal photo (including a receipt, menu, or a food image on a screen), that image is sent to OpenAI so Bitely can identify the food and estimate nutrition. We do not upload the photo to Firebase Storage or keep it in your diary. We may store the dish name, serving, macros, and emoji you choose to log. A scan is counted only after the photo is confirmed as food.
- Scan usage: daily barcode and AI scan counts on your account so we can enforce plan limits.
- Premium: whether Premium is active and which subscription product you purchased. Apple and Google process payment. We do not receive your card number.
- Device tokens: if you allow notifications, we may store an FCM and/or APNs token so meal reminders and optional updates can reach this device.
- Technical: standard Firebase Authentication, Cloud Firestore, and App Check data needed to sign you in, sync your diary, and reduce abuse, over HTTPS.
- Diagnostics & analytics: crash stack traces, device/OS info, and anonymous product events (screen views, sign-in method, food/drink logged, scan result, Premium purchase/restore). Linked to your Firebase user ID so we can fix bugs. Not used for advertising or cross-app tracking. No email, food names, or photos are sent in these events.
Camera, photos, and scanning
Bitely requests camera access to read a food product barcode (for example EAN/UPC) and, for Premium AI Food Scan, to take a still photo of a meal. The barcode feed is processed on your device. We do not upload barcode preview frames, do not run face or body analysis, and do not use the camera for advertising.
A meal photo you capture is sent to OpenAI for food identification and a nutrition estimate. Bitely does not save that photo in your cloud diary or Firebase Storage.
Photo library access is optional. You can pick an existing photo (a meal, receipt, menu, or screenshot). The selected image is read on the device and sent to OpenAI the same way as a camera capture. Bitely does not copy your whole library.
After a barcode is read, Bitely sends that code to the public Open Food Facts API. Nutrition values returned are community-sourced estimates. You can ignore a result or log a different serving. You can deny camera or photo access and still search or pick foods from the catalog.
How we use it
We use this data only to operate Bitely:
- Authenticate your account (email, Apple, or Google) and keep you signed in
- Estimate calorie, macro, and fluid targets from your profile answers
- Store and display your food, barcode-logged items, AI-logged items, water, and activity diary
- Look up packaged foods when you scan a barcode or search Open Food Facts
- Identify a meal from a photo, receipt, or screenshot you submit via AI Food Scan
- Enforce daily barcode and AI scan limits for your plan
- Unlock Premium features you purchased through the App Store or Google Play
- Send optional meal reminders and updates you enable (local notifications and, on a real device, push via FCM/APNs)
- Diagnose crashes and understand which screens and features are used, via Firebase Crashlytics and Analytics
We do not sell your data. We do not use it for third-party advertising or cross-app tracking. Health and fitness details you enter are used only to run Bitely (targets, diary, reminders, scan limits) — not to profile you for ads. The app does not request App Tracking Transparency / IDFA and does not integrate Apple HealthKit.
How calorie and macro estimates are calculated is explained on our Source of Recommendation page.
Third-party processors
- Google Firebase (Authentication, Cloud Firestore, Cloud Messaging, App Check, Crashlytics, and Analytics) — stores your account and cloud logs, scan usage, optional push tokens, crash reports, and in-app usage events, and helps reduce abuse. Data is transmitted over HTTPS.
- Apple — Sign in with Apple, App Store subscriptions, and APNs when you allow notifications. Sign in with Apple may share your name and email (or a private relay address) with us.
- Google — Sign in with Google and, on Android, Google Play subscriptions. Google may share your name and email when you sign in with Google.
- Open Food Facts — if you search foods or scan a barcode, the search text or barcode number is sent to their public API to fetch nutrition estimates. Camera images are not sent to Open Food Facts. See Open Food Facts terms and Open Food Facts privacy.
- OpenAI — if you use AI Food Scan, the photo you capture or pick is sent to OpenAI’s API to identify food and estimate nutrition. See OpenAI’s privacy policy.
We do not use AppsFlyer, Facebook SDK, or advertising SDKs in the Bitely app.
Notifications
If you allow notifications, Bitely can show meal reminders on this device (scheduled locally) and may receive push messages through Firebase Cloud Messaging / Apple Push Notification service. Tokens are stored with your account so we can reach your device. You can turn notifications off in system Settings at any time. Simulator builds cannot receive Apple push tokens; local reminders still work.
On-device data
Some preferences stay on your device only — for example, food/activity favorites stored locally (not uploaded to Firestore as favorites). Optional meal reminder schedules use on-device notifications. Camera captures may sit briefly in the app’s temporary cache until the system clears them. Uninstalling the app removes local storage; cloud account data remains until you delete the account.
Device permissions
- Camera — barcode scanning and optional meal photos. Optional. Deny it and log foods without scanning.
- Photo library — pick a meal, receipt, or screenshot for AI Food Scan. Optional.
- Notifications — meal reminders and optional updates. Optional.
- Internet — sign-in, sync, Open Food Facts, OpenAI, and store purchases.
Bitely does not request microphone, location, contacts, or tracking (ATT/IDFA) permission.
Sharing, sale, and tracking
We do not sell personal information. We do not share your diary with other users. We do not use your data for third-party advertising. We do not track you across other companies’ apps or websites. Bitely does not show App Tracking Transparency because it does not track in Apple’s sense of that term.
We share data with the processors listed above only as needed to run the service (sign-in, sync, optional push, barcode lookup, AI Food Scan, store subscriptions). Firebase is operated by Google and may process data in the United States or other countries where Google maintains infrastructure. OpenAI may process AI Food Scan images on their servers.
Retention and account deletion
We keep cloud data while your account is active. You can initiate account deletion at any time in the app: Profile → Account → Delete account. No support ticket is required to start that flow (App Store Guideline 5.1.1(v)).
When you confirm deletion in this version of Bitely, we close the account: we mark it disabled, sign you out, cancel local meal reminders, detach this device’s notification token, and block later sign-in with that account in the app. Firebase Authentication and the stored diary remain on our servers in a closed state; they are not shown in the product after deletion.
To request erasure of remaining closed-account records, or if in-app deletion does not complete, email support@bitely.pro from the address on the account. We will process access, correction, and erasure requests as required by applicable law (including GDPR and CCPA where they apply). Uninstalling Bitely removes on-device data only; it does not close the cloud account.
Your rights
Depending on where you live (including GDPR in the EU/EEA and CCPA in California), you may request access, correction, or deletion of personal data. Contact support@bitely.pro.
Security
We rely on Firebase authentication, App Check, and transport encryption (TLS). No method of transmission or storage is 100% secure. Please use a strong password and keep your device updated.
Children
Bitely is for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 created an account, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy. The “Last updated” date at the top will change when we do. Continued use of Bitely after an update means you acknowledge the revised policy.
Contact
Nxt Edge Solution
Email: support@bitely.pro
Web: bitely-calorie.netlify.app