Last Updated: October 26, 2025

Effective Regions: United States, South Korea, Japan, Singapore, and Australia

Not offered in: EEA (EU), United Kingdom, China, Russia, and other restricted regions


1. Purpose of Collection and Use

We collect and process data only to:


2. Information We Collect and Store

Category Data Items Storage Encryption / Access
Account Information Email (Google/Apple OAuth) AWS Cloud Encrypted at rest
Food Logs Text or photos of foods consumed Local + AWS Cloud Encrypted (AWS KMS)
Preferences / Allergens Foods marked as liked/disliked or allergens Local + AWS Cloud Encrypted
Experience Logs Reaction types (encrypted) + numeric severity Local + AWS Cloud Partial encryption
Device / Usage Info Model, OS version, app version, logs AWS Cloud Standard protection

All transmissions use HTTPS/TLS, and data stored in the cloud are encrypted using AWS-managed encryption keys.

Authorized administrators can access limited fields (email, logs, encrypted reactions, numeric data) only for maintenance, under strict access control.


3. Local and Cloud Storage

User data are stored both on the device and in secure AWS cloud servers to support synchronization and recovery.

External access requires proper credentials and encryption-key authorization.