Adatvédelem
This policy explains what data Foodmetric processes, why it is processed, and the choices available to you.


Language notice: A reviewed legal translation is not yet available for Magyar. The current legal information is therefore provided in clear English. Contact ertekin.developer@gmail.com if you need help understanding it.
Foodmetric is a nutrition-tracking and AI-assisted meal-analysis service provided by Metin Ertekin. The data controller can be contacted at ertekin.developer@gmail.com.
1. What we collect, how we collect it, and why
We receive data (a) directly from you when you create an account, complete your profile, log a meal, or submit a photo or text; (b) automatically from the device while the app operates; or (c) from sign-in and purchase providers.
- Account and profile: email address, username or name, sign-in provider identifier, Foodmetric user identifier, app language, and time zone. If Google Sign-In is used, Google Sign-In may process name, email address, phone number, coarse location, user/device identifiers, and sign-in or usage technical data as disclosed in its bundled Apple privacy manifest. Foodmetric does not ask for a phone number as a profile field and does not collect precise location. We use this data to create and secure your account, sign you in, and synchronize preferences.
- Nutrition and health-related information: age, the sex option you select for calculations, height, weight, goal, activity and target pace, meal name and description, date and meal type, calories and macros, water records, weight history, and nutrition targets. We use these to provide the calculations, meal history, targets, statistics, and AI insights you request.
- Content you provide: a meal or nutrition-label photo, a typed meal description, question or correction, feedback about an AI result, and support messages. We process these only to provide the feature or support you choose.
- Device, usage, and diagnostics: a persistent randomly generated device identifier, app version, operating system and device type, in-app interaction events, standard network information such as IP address, general/country-level coarse location derived by Firebase Analytics from masked IP addresses, other usage and technical data, diagnostics, performance information, and crash logs. We use these for guest allowances, fraud and abuse prevention, troubleshooting, analytics, and performance. When you sign in, an account or device identifier may be associated with these records.
- Notifications: if you allow notifications, a push token, notification preferences, and schedules are processed to deliver reminders.
- Purchases: product, receipt or purchase token, entitlement, and subscription status are received from the store and RevenueCat to validate a purchase, provide Premium access, and restore purchases. We do not receive your full payment-card details.
- Food and barcode queries: a barcode you scan or product query you enter is used to retrieve a product result.
2. Data sent to third-party AI
Foodmetric uses only Google LLC's Google Cloud Vertex AI service (Gemini models) for AI analysis. It does not fall back to the Gemini Developer API. When you initiate an AI feature, only the data needed for the result you request may be sent through a Supabase Edge Function to Vertex AI:
- the meal or nutrition-label image you select;
- a meal description, question, or correction that you type;
- the previous AI result and your feedback when you request a correction;
- to the extent needed for an insight or summary feature you choose, relevant saved meal names, meal types, dates, calories and macros, nutrition targets, and limited meal history;
- the request language and technical fields that tell the model how to perform the analysis.
The Vertex AI request body does not contain your email address, name, Foodmetric or Supabase user identifier, device identifier, push token, purchase information, or Supabase session/JWT token. The session token is used only by Foodmetric's Supabase backend to authenticate you and verify current consent; it is removed from the outbound AI request to Google.
The correction flow may use Google Search grounding to verify real-world food or nutrition information. In that case, search queries derived from the correction, relevant context, and the grounded result are processed by Google. Google states that Google Cloud customer data is not used to train or fine-tune AI models without prior permission or instruction. Under Google's current disclosures, Gemini models may by default keep inputs, outputs, and derived data in project-isolated in-memory caching for up to 24 hours for performance; prompts flagged as suspicious by automated systems may be securely retained for up to 90 days and reviewed by authorized Google employees solely for abuse investigation; and Search-grounding-derived queries and context that are not associated with the customer or an end user may be retained for up to 3 days for debugging. These records are not used for model training. See Google's data-retention disclosure and abuse-monitoring disclosure.
Before the first such transfer, the app explains what may be sent and asks for your explicit permission. If you decline, no data is sent to Vertex AI and manual meal entry remains available. Consent is checked both in the app and on the server, and is tied to your account and the current disclosure version.
3. Supabase transit, cache, and photo storage
Some preferences, guest records, and app copies of photos may remain in the app-specific area of your device. Account-synchronized profile, nutrition and health-related records, meals, goals, notification records, and subscription entitlements are stored using Supabase Inc. infrastructure. A meal photo you choose to save may be stored on your device and in an account-specific folder in Supabase Storage; that saved photo is separate from the temporary AI-input transfer.
An AI request travels over an encrypted connection from the device to a Supabase Edge Function. The server authenticates the account, verifies consent, forwards the required AI payload to Vertex AI, and returns the result to the app. To speed up duplicate image requests, a user-bound Supabase cache retains the photo's one-way SHA-256 digest, the generated analysis result, analysis type, language, and consent version for no more than 30 days. The raw photo is not stored in this cache, and one user's cached result is not served to another user.
The consent record contains the Foodmetric user identifier, disclosure and policy version, provider, locale, platform, app version and build number, and the grant or withdrawal time. The consent table does not contain a photo, prompt text, or AI response.
4. Service providers and the data disclosed to each
- Supabase Inc.: authentication; account, profile, meal, and other synchronized records; meal photos in an account-specific folder; notification and consent records; secure transit of the AI payload through Edge Functions; and the user-bound 30-day result cache.
- Google LLC: Google Cloud Vertex AI (Gemini models) processes only the AI content listed above, and Google Search grounding may process correction-derived queries and context. If Google Sign-In is used, Google Sign-In may process name, email address, phone number, coarse location, user/device identifiers, and sign-in or usage technical data. Separately, Firebase Analytics processes app-event, general-location, and app-instance/device information, Firebase Crashlytics processes crash and diagnostic data, Firebase Cloud Messaging processes a push token and delivery data, and our Google-hosted support inbox processes your sender address and message content when you email support.
- RevenueCat, Inc.: a Foodmetric or RevenueCat app user identifier, store, product, receipt or purchase token, transaction, and subscription/entitlement status, to validate purchases, provide Premium access, and restore purchases.
- Apple Inc. and Google LLC / Google Play: if you use that provider to sign in, the sign-in provider identifier and email/name you choose to share; plus store account, product, receipt, purchase, and subscription status for sign-in, store billing, validation, restoration, cancellation, and refunds. Foodmetric does not receive your full card details.
- Nutritionix: a scanned barcode may be sent through a Supabase Edge Function to retrieve nutrition and product information.
- Open Food Facts and UPCitemDB: a scanned barcode or product query, plus standard IP/request information for a direct network request, may be processed to retrieve a product result.
We do not sell or rent personal data or use it for third-party advertising. We may disclose information when required by law, to protect rights, or to respond to a security incident.
5. Permissions and AI consent
- Camera and photos: used only when you ask to capture or select a meal or nutrition-label image. This system permission is not consent to send a photo to Google.
- AI data sharing: requested through a separate disclosure before the first transfer. You can withdraw it at Profile > Settings > AI data sharing. Withdrawal blocks future AI requests in both the app and backend; manual logging continues to work.
- Notifications: used only after permission to deliver reminders and relevant app notifications.
Withdrawing AI consent cannot undo a transfer that has already finished, but it stops new transfers and immediately deletes Foodmetric's existing user-bound AI cache. Account deletion also removes the consent and cache records from active systems with the account.
6. Retention and deletion
We retain account-linked records while your account is active, or only as long as needed for security, dispute resolution, or a legal obligation. A raw AI-input photo is not retained in the AI cache; the user-bound result cache is retained for no more than 30 days. Google Cloud, Firebase, RevenueCat, and store records are subject to their applicable contract, security, and legal retention periods. Diagnostics, fraud-prevention records, and backups may remain for a limited period.
You can delete your account in the app at Profile > Settings > Delete Account or at https://foodmetricai.com/account-deletion/hu-HU. Account deletion removes the account, profile, nutrition records, AI consent and cache, and meal photos in the account-specific Supabase Storage folder from active Foodmetric systems. Local copies are removed when app data is cleared or the app is uninstalled. Deleting a Foodmetric account does not automatically cancel a store subscription; cancel any active subscription separately in your Apple App Store or Google Play account.
7. Your choices and rights
You can review, correct, or delete app records; withdraw AI data-sharing consent; disable notifications; and delete your account. Depending on your location, you may also have rights to access, correct, erase, restrict, object to, or port personal data. Email ertekin.developer@gmail.com to make a request; we may need to verify your identity.
8. Equal protection, security, and international processing
We require every third party that processes personal data on our behalf to provide the same or equivalent privacy and security protection through contracts, data-processing addenda, processing instructions, confidentiality, and security obligations. These include the Supabase Data Processing Addendum, Google Cloud Data Processing Addendum, and RevenueCat Data Processing Addendum. Store and product-data sources receive only the minimum necessary data under their service and privacy terms; we do not disclose personal data to a party that does not provide the same or equivalent protection.
We use reasonable technical and organizational safeguards such as encryption in transit, user-scoped database-row controls, server-side consent verification, and provider security features. No system is risk-free. Providers may process data outside your country; when required, standard contractual clauses or other safeguards recognized by applicable law apply.
9. Children's privacy
Foodmetric is a general-wellness service and is not a medical service for children. A person who cannot legally consent to data processing where they live should use the app only with a parent or legal guardian. Contact us if you believe a child provided data without the required permission.
10. Changes and contact
We may update this policy when the app, processing purposes, data categories, or providers change. If the AI-transfer disclosure changes materially, we will request consent again for the new disclosure version. For privacy questions, email ertekin.developer@gmail.com.
Last updated: July 20, 2026