Last Updated: October 26, 2025
Effective Regions: United States, South Korea, Japan, Singapore, and Australia
Not offered in: EEA (EU), United Kingdom, China, Russia, and other restricted regions
We collect and process data only to:
| Category | Data Items | Storage | Encryption / Access |
|---|---|---|---|
| Account Information | Email (Google/Apple OAuth) | AWS Cloud | Encrypted at rest |
| Food Logs | Text or photos of foods consumed | Local + AWS Cloud | Encrypted (AWS KMS) |
| Preferences / Allergens | Foods marked as liked/disliked or allergens | Local + AWS Cloud | Encrypted |
| Experience Logs | Reaction types (encrypted) + numeric severity | Local + AWS Cloud | Partial encryption |
| Device / Usage Info | Model, OS version, app version, logs | AWS Cloud | Standard protection |
All transmissions use HTTPS/TLS, and data stored in the cloud are encrypted using AWS-managed encryption keys.
Authorized administrators can access limited fields (email, logs, encrypted reactions, numeric data) only for maintenance, under strict access control.
User data are stored both on the device and in secure AWS cloud servers to support synchronization and recovery.
External access requires proper credentials and encryption-key authorization.