Legal

Privacy Policy

Last updated: Version 1.0

This policy explains what personal data My Diet Bot collects, why we collect it, who processes it for us, how long we keep it, and the choices you have. It covers the My Diet Bot iPhone app and this website, mydietbot.com.

1. Who we are

My Diet Bot is provided by Furkan Kesen, an individual developer based in Hamburg, Germany (“we”, “us”, “our”). Under the EU and UK General Data Protection Regulation (GDPR), Turkey's Personal Data Protection Law No. 6698 (KVKK) and similar laws, Furkan Kesen is the controller of the personal data described in this policy.

2. What we collect

We only collect what we need to run My Diet Bot. Most of it comes directly from you. Some comes from Apple or Google if you use them to sign in.

Account

  • Your email address and name. If you sign in with Apple or Google, we receive these from them (with Apple, the email may be a private relay address).
  • A unique account identifier from Apple or Google, if you use them to sign in.
  • If you sign up with email, a securely hashed version of your password. We never store or see your password itself.

Profile and health information (only what you share)

  • Current and target weight (and weight updates you share over time), height and age.
  • Sex, used only in the calorie formula.
  • Activity level, goals and preferred pace.
  • Dietary style, allergies and foods you avoid.
  • Units and similar preferences.

Your journal and conversations

  • Meals you log: items, portions, times, calorie and macro estimates, and your corrections.
  • Meal photos you take or choose.
  • Voice notes (audio recordings) and their transcripts.
  • Your chat messages with your coach, and the coach's replies.
  • Coach memories: things your coach keeps in mind, such as a food preference or an allergy. You can correct or forget any of them.
  • Coach preferences: the name you give your coach, its tone, and check-in preferences.

App activity

A history of actions in the app, such as a message sent, a meal logged or corrected, a memory saved or forgotten, or your profile updated. We use it to run and sync features and to fix problems. It's kept while your account exists and deleted with it.

Timezone and language

Your device's timezone and language or region setting, so days, dates and replies match where you are. We don't collect your precise location.

Safety signals

If a message suggests something like pregnancy, disordered eating or self-harm, the app may record a flag so your coach can respond safely, for example by holding back calorie-deficit suggestions or pointing you to support. These flags are used only for that purpose.

Technical data

  • Server logs: IP address, time of request, request identifiers, app version and error details.
  • Crash and error diagnostics collected with Sentry: device model, operating system, app version and technical error details. We don't attach your name, email address or account identity to these reports.
  • A random installation identifier used by Expo to deliver app updates. It isn't linked to your account.

What we don't collect

No advertising identifiers, no precise location, no contacts, no payment card details, no data from Apple Health, and no tracking of what you do in other apps or on other websites.

3. How we use your data, and our legal bases

Purposes of processing and legal bases under the GDPR
Purpose Data used Legal basis
Create and run your account, sync your journal across devices, and show your dashboard and insights Account, journal, profile, app activity, timezone and language Performing our contract with you (Art. 6(1)(b)); for health information, your explicit consent (Art. 9(2)(a))
AI features: coach replies, meal estimates, voice-note transcription, read-aloud, remembering context and safety checks Messages, photos, voice notes, profile and health information, memories Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Calorie and macro targets, only if you ask for them Weight, height, age, sex, activity level and goals Your explicit consent (Art. 9(2)(a))
Responding safely to messages about pregnancy, disordered eating or self-harm Safety signals Your explicit consent (Art. 9(2)(a))
Account emails, such as email verification, password reset and important service notices Email address Performing our contract with you (Art. 6(1)(b))
Security, abuse prevention, usage limits, debugging and crash diagnostics Technical data Our legitimate interests in keeping My Diet Bot secure and working (Art. 6(1)(f))
Complying with the law and handling legal claims Only what's needed Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Withdrawing consent. You can withdraw your consent to AI processing at any time in the app's Settings. We then stop sending your data to OpenAI, and AI features switch off. Withdrawing doesn't affect processing that already happened. If you don't want us to keep your health information at all, you can delete it, or delete your account.

What we never do. We don't sell or rent your personal data, use it for advertising, share it with data brokers, or track you across other companies' apps and websites. We don't make decisions about you that have legal or similarly significant effects based solely on automated processing. Calorie targets are suggestions you can accept, change or ignore.

4. AI processing with OpenAI

My Diet Bot uses the OpenAI API to power your coach. Once you've given consent, we send OpenAI only what each feature needs:

  • Coach replies: your message, the recent conversation, your profile (body details such as weight and height, goals, dietary style, allergies, coach name and tone, units, language, and check-in preferences such as meal times and quiet hours), relevant memories, and today's meals.
  • Meal estimates: the meal photo and any text you add, or your description.
  • Voice notes: the audio recording, so it can be transcribed.
  • Read-aloud: the text of your coach's reply, to generate an AI voice.
  • Safety checks: message text and photos may be checked by OpenAI's moderation model.

We never send your email address or password. So that OpenAI can detect abuse without knowing who you are, requests may include a pseudonymous, hashed account identifier.

OpenAI processes this data as our service provider (processor) under its data processing terms. OpenAI does not use data sent through its API to train its models. We send requests with OpenAI's response storage turned off. OpenAI may keep API inputs and outputs in abuse-monitoring logs for up to 30 days, after which they are deleted unless the law requires otherwise. OpenAI processes data in the United States. Read more about how My Diet Bot uses AI.

5. Who we share it with

We share personal data only with service providers that help us run My Diet Bot. They act on our instructions under contracts that limit their use of your data to providing their services to us.

Service providers (processors)
Provider What they do for us Location
OpenAI AI coach replies, meal estimates, transcription, read-aloud voice and safety checks United States
Convex Database and file storage for your account, journal, photos and voice notes EU (Ireland)
Railway Hosting for our API server and this website, including server logs EU (Netherlands)
Resend Sending account emails, such as verification and password reset EU
Sentry Crash and error diagnostics, without your identity EU (Germany)
Expo (EAS Update) Delivering app updates, using a random installation identifier United States
Cloudflare Email routing: passes emails you send to support@mydietbot.com or privacy@mydietbot.com on to our mailbox United States
Google (Gmail) Our mailbox, where we read, answer and keep the support and privacy emails you send us United States

Apple and Google. If you choose Sign in with Apple or Sign in with Google, that provider handles your sign-in as an independent controller under its own privacy policy. Apple also distributes the app through the App Store under its own terms.

Other disclosures. We may disclose personal data if the law or a valid legal process requires it, or to protect the rights, safety and security of our users or others. If My Diet Bot is ever transferred to a new owner, your data would move with it only under this policy, and we'd tell you before that happens.

6. International transfers

Some providers, such as OpenAI, Expo, Cloudflare and Google (and Apple and Google for sign-in), are based in the United States, and some providers may access data from other countries to support their services. When personal data is transferred out of the European Economic Area, the UK, Switzerland or Turkey, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) in our providers' data processing agreements, or another lawful transfer mechanism. You can ask us for details at privacy@mydietbot.com.

7. How long we keep it

  • Your account and journal: for as long as your account exists. You can edit your profile, delete meals and forget memories at any time.
  • Chat history: the app keeps your most recent 200 chat messages (fewer if they are very long); older messages are deleted automatically. Your logged meals stay in your journal.
  • When you delete your account: your account, profile, chat history, meals, photos, voice notes, memories and app activity are permanently deleted from our live systems immediately, and removed from our rolling backups within 30 days.
  • Server logs: up to 30 days.
  • Crash reports: up to 90 days.
  • OpenAI: up to 30 days in abuse-monitoring logs, as described above.
  • Account emails: our email provider keeps delivery records for a limited period under its retention settings.
  • Legal requirements: if the law requires us to keep something longer, for example to handle a legal claim, we keep only what's required and only for as long as required.

We may keep a minimal technical record that an account was deleted, without its content, name or email address, so that the deletion can't be accidentally reversed.

8. Your rights and choices

Depending on where you live, you have the right to:

  • access your personal data and get a copy of it;
  • receive your data in a portable, machine-readable format (export);
  • correct inaccurate data;
  • delete your data;
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • withdraw your consent at any time, without affecting earlier processing;
  • complain to a data protection authority, for example in the country where you live or work.

You can do much of this yourself in the app: edit your profile in Settings, correct or forget memories, edit or delete meals, withdraw AI consent in Settings, and delete your account (Settings, then Delete account). For anything else, email privacy@mydietbot.com from the email address on your account. Requests are free. We'll respond within one month, or tell you if a complex request needs up to two more months. We may need to confirm it's really you before we act.

Turkey (KVKK)

If you're in Turkey, Article 11 of Law No. 6698 gives you the right to learn whether your personal data is processed and request information about it; to learn the purpose of processing and whether it's used accordingly; to know the third parties in Turkey or abroad it's transferred to; to request its correction or deletion and have third parties notified; to object to a result against you that arises solely from automated analysis; and to claim compensation for damage caused by unlawful processing. Apply to us at privacy@mydietbot.com. You can also complain to the Personal Data Protection Authority (KVKK).

California

If you're a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect, use and disclose; to delete and correct it; and not to be discriminated against for exercising your rights. We don't sell your personal information or share it for cross-context behavioral advertising, and we use sensitive personal information, such as health information, only to provide the service you asked for. The categories we collect, their sources, our purposes and the service providers we disclose them to are described above. To exercise your rights, email privacy@mydietbot.com. An authorized agent may also make a request on your behalf.

9. Consumer health data privacy

Some US state laws, such as Washington's My Health My Data Act and Nevada's consumer health data law, give you specific rights over consumer health data. This section is our consumer health data privacy policy.

  • What we collect: body measurements (weight and height), age and sex used for calorie calculations, meals and nutrition intake, dietary habits, food allergies and avoidances, activity level, weight goals, and safety signals about pregnancy, disordered eating or self-harm that may be inferred from your messages.
  • Sources: you (what you type, say, photograph or enter in the app), and inferences the app's AI makes from that content.
  • Why: to provide the features you ask for, such as logging, estimates, targets, coaching and safe responses. We don't use it for advertising.
  • Who we share it with: only the service providers listed in section 5, to provide the service. We don't sell consumer health data.
  • Consent: we collect and share consumer health data only with your consent, which you can withdraw in Settings.
  • Your rights: to confirm whether we collect, share or sell your consumer health data; to access it, including a list of the third parties it has been shared with; to withdraw consent; and to have it deleted. Email privacy@mydietbot.com.
  • Appeals: if we decline your request, reply to our decision with the word “Appeal” and we'll review it and explain the outcome in writing. If you're still unhappy, you can contact your state Attorney General.

10. Children

My Diet Bot is for adults aged 18 and over. It isn't directed at children, and we don't knowingly collect personal data from anyone under 18. If you believe someone under 18 is using My Diet Bot, contact privacy@mydietbot.com and we'll delete the account.

11. Security

We protect your data with encryption in transit (HTTPS) and encryption at rest by our hosting providers, access limited to what's necessary, a server-only secret between our API and our database, short-lived signed links for photos and voice notes, and hashed passwords. No system is perfectly secure. If a breach affects your personal data, we'll notify you and the relevant authorities as the law requires.

12. This website

mydietbot.com doesn't use cookies, analytics or third-party trackers, and it loads its fonts and images from our own server. Our host, Railway, processes your IP address, browser details and the pages you request in server logs to deliver the site and keep it secure. These logs are kept for up to 30 days.

If you email us, your message passes through our email routing provider (Cloudflare) to our mailbox (Google (Gmail)), as listed in section 5. We use your message and email address to reply, and keep the conversation for as long as we need to handle your request.

13. Changes to this policy

We'll update this policy when our practices change, and update the date and version at the top. If a change is significant, for example a new AI provider or a new use of your health information, we'll tell you in the app or by email before it takes effect, and ask for your consent again where required.

14. Contact

Furkan Kesen, Hamburg, Germany
Privacy: privacy@mydietbot.com
Support: support@mydietbot.com

If you're not satisfied with our response, you can complain to your local data protection authority.