BiteSet
Privacy policy
Last updated 25 August 2026
This policy explains what BiteSet collects, why, and what you can do about it. It covers the BiteSet mobile app and the BiteSet API.
WHO WE ARE
BiteSet provides nutritionist-built meal plans. For data protection purposes BiteSet is the data controller for the information described below. Contact us through Support in the app for any privacy request.
WHAT WE COLLECT
Account information. Your name, email address and password. Passwords are stored only as a bcrypt hash and are never readable by us.
Body and goal information. Age, gender, height, current weight, target weight, goal and activity level. We collect this because it is the only way to calculate your calorie and macro targets. Without age in particular, a target cannot be produced.
Weight check-ins. Any weight you log over time, so the app can show a trend.
Food preferences. Your diet style, any food allergies you tell us about, foods you would rather avoid, and the longest you want to spend cooking. We use these to keep meals you cannot or do not want to eat off your plan. Allergy information is health data, and we ask for it only so the plan can avoid those foods. You do not have to give it, and you can clear it at any time under Food preferences in the app — though a plan cannot avoid an allergen we do not know about.
Meal ratings. Whether you liked or disliked a dish, used to order the swap suggestions we show you and to avoid repeating dishes you disliked.
Plan activity. Which meals you mark as eaten, which meals you swap, which recipes you favourite, and which grocery items you tick off. This is what drives your adherence figures and achievements.
Photos you choose to upload. Progress photos in your private gallery, and photos attached to community posts. Progress photos are visible only to you through your account. Community photos are visible to other subscribers.
Community content. Posts, captions, comments, likes, bookmarks, reports and blocks.
Support messages. The subject and body of anything you send us through Support, along with your name and email so we can reply.
Subscription information. Which plan you hold, when it starts and expires, and an Apple transaction identifier when you subscribe through the App Store. We never see or store your card details; Apple handles payment.
Device information for notifications. If you enable push notifications we store a push token for your device so we can send them. You can turn this off at any time in Settings.
Technical information. Standard server logs, including IP address and request times, kept for security and debugging. If crash reporting is enabled, we receive crash diagnostics that may include your account identifier so we can trace a fault back to a report.
WHAT WE DO NOT DO
We do not sell your personal information. We do not use your data to serve you advertising. We do not share your body metrics, weight history or progress photos with other users or with advertisers.
WHY WE ARE ALLOWED TO USE IT
We process your account, body and plan information to perform the contract you enter when you subscribe. We process community content on the basis of our legitimate interest in running a safe community. We send push notifications only with your consent, which you can withdraw in Settings. Allergy information is health data, and we process it on the basis of your explicit consent, given when you choose to enter it. You can withdraw that consent by clearing the field, and we will stop using it immediately. We keep security logs on the basis of our legitimate interest in protecting the service.
WHO WE SHARE IT WITH
We use a small number of processors to run the service: cloud hosting and database providers, an object storage provider for uploaded images, an email delivery provider for transactional email such as password resets, and a push notification provider if you enable notifications. Apple processes your payment and tells us only whether your subscription is active. Each of these acts on our instructions and may not use your data for their own purposes.
HOW LONG WE KEEP IT
We keep your account and plan data while your account exists. Server logs are kept for a short operational period. When you request deletion we remove your account and its associated plan data, photos, posts and support history, except where we are required to retain a record for legal or accounting reasons.
YOUR RIGHTS
You can see and change your name, contact details, body metrics and goals in the app at any time under Edit profile. You can delete individual progress photos and community posts yourself. You can request deletion of your whole account from Settings, and we will confirm by email. Depending on where you live, you may also have the right to a copy of your data, to correct it, to object to certain processing, or to complain to your local data protection authority. Contact us through Support to exercise any of these.
CHILDREN
BiteSet is not intended for anyone under 16 and we do not knowingly collect information from children. If you believe a child has created an account, contact us and we will remove it.
SECURITY
Access tokens are stored in the device keychain rather than in general app storage. Traffic between the app and our API is encrypted in transit. Access to production data is limited to the people who need it to operate the service. No system is perfectly secure, and we will tell affected users promptly if a breach puts their data at risk.
INTERNATIONAL TRANSFERS
Our providers may process data outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses.
CHANGES
If we change this policy in a way that materially affects you, we will tell you in the app before the change takes effect.