SpotBite

Privacy Policy

Last updated: September 12, 2026 · Effective: April 30, 2026

SpotBite ("we", "us", "our") provides a mobile application that scans food photos and estimates how meals may affect your skin. This Privacy Policy explains what data we handle and how. If you do not agree, do not use the app.

The short version: Your food photos and scan history stay on your device. The food image you scan is sent transiently to our server, forwarded to an AI provider for analysis, and not stored. We do not collect your name, email, or location. We do not sell your data. We do not advertise.

1. Who we are

SpotBite is operated by an independent developer based in the Republic of Korea. For privacy questions, contact [email protected].

2. Data we handle

2.1 Stored on your device only

The following are stored locally on your device using Apple/Google's standard app storage. We never receive copies.

Uninstalling the app deletes all of the above permanently.

2.2 Sent to our server transiently (not stored)

When you scan a meal, the food image is sent over HTTPS to our server (a Cloudflare Worker proxy at acne-snap-proxy.dmdghto.workers.dev), which immediately forwards it to our AI provider (Perplexity AI, which routes the request to a Google Gemini vision model) for nutrition recognition. The result is returned to your device. We do not write the image, the response, or your IP address to any database. The proxy may briefly log request metadata for abuse prevention but discards it within hours.

2.3 Subscription data (RevenueCat)

If you subscribe to SpotBite Pro, our payment infrastructure provider RevenueCat receives:

RevenueCat does not receive your name, email, or payment card details. The actual payment is processed by Apple App Store or Google Play and governed by their privacy policies.

2.4 Crash and error reports (Sentry, optional)

If a crash or unhandled error occurs, a report may be sent to Sentry for diagnostic purposes. Reports include:

Reports do not include your photos, food data, or any content you entered. Sentry retains reports per their stated retention policy (typically 30–90 days).

2.5 What we never collect

3. How we use data

PurposeData usedLegal basis (GDPR)
Recognize food and estimate nutritionFood image (transient)Contract performance
Calculate your Skin Score and patternsLocal scan data on your deviceContract performance
Manage your subscriptionAnonymous subscription state via RevenueCatContract performance
Diagnose crashes and improve stabilityAnonymized error reportsLegitimate interest
Understand which features are used and where people drop offAnonymous in-app and website usage eventsLegitimate interest
Send you the local reminders you opt intoNotification settings on your deviceConsent

4. Sharing

We share data only with the following service providers, strictly as needed to operate the app:

We do not sell or rent any data, and we do not track you across other apps or websites. The analytics we do use (PostHog in the app and on this website, and the Meta SDK for counting ad installs) are limited to anonymous usage counts.

4.1 This website

Our website (spotbite.app, including the food pages) counts page views and store-link clicks through PostHog so we can see which pages people find useful. It sets no cookies, stores nothing in your browser, and uses a fresh random identifier for every page view, so visits cannot be linked to each other or to you.

5. Data retention

6. Your rights

You can:

If you are in the EU/EEA, UK, or California, you have additional rights under GDPR/UK GDPR/CCPA, including access, rectification, portability, and the right to lodge a complaint with your local data protection authority. Because we collect almost no personal data, most of these rights are exercised by deleting the app. For any other request, contact us.

7. Children's privacy

SpotBite is rated 12+ on the App Store and Google Play. We do not knowingly collect personal data from children under 13 (or the equivalent age in your jurisdiction). If you believe a child has used the app, contact us and we will delete any associated subscription record.

8. International transfers

The service providers listed in Section 4 may process data in countries outside your own (primarily the United States). They contractually commit to providing protections equivalent to those required by GDPR via Standard Contractual Clauses or equivalent mechanisms.

9. Security

All network requests use HTTPS (TLS 1.2+). On-device data is stored in app-private storage that requires device unlock to access. We do not operate user accounts or passwords, which eliminates an entire class of credential-related risks.

10. Changes to this policy

We may update this policy as the app evolves. The "Last updated" date at the top will reflect the most recent revision. Material changes will be highlighted in-app on next launch.

11. Contact

Questions, requests, or complaints: [email protected]