HelloBite ("the App", "we", "us") is a recipe collection and cooking assistant that lets you import recipes from text, photos, websites and social media, organise them into cookbooks, plan meals and shop for groceries. This policy explains exactly what data the App handles, why, and the choices you have. It applies to the HelloBite mobile application on Android and iOS.
Information we collect
Information you provide
- Account details. When you sign up with email & password, Google Sign-In or Sign in with Apple, we receive your email address, display name and (for Google) profile photo. Sign in with Apple lets you hide your email; we then receive only Apple's private relay address.
- Your content. Recipes you create or import, cookbooks, meal plans, grocery lists, notes, and comments or recipes you choose to make public.
- Photos and camera. If you import a recipe from a photo, the image you pick or capture is uploaded to our storage and analysed to extract the recipe. The camera and photo library are used only when you start such an import; access is controlled by system permissions you can revoke at any time.
- Links you share. If you import from a website or social-media post (for example an Instagram reel), the App fetches that page's public text and cover image to build the recipe.
- Onboarding preferences. Cooking goals, cuisines and similar preferences you select, used to personalise the App.
Information collected automatically
- Device & app information. Device model, operating-system version, app version, language and timezone.
- Approximate location (country only). On first launch we look up the country of your IP address (see Section 4) solely to offer the right language options. We do not collect precise location and never access GPS.
- Push token. If you allow notifications, a push token is created so we can deliver them.
- Purchase state. Whether you have an active HelloBite Plus subscription and your remaining free import credits. Payment is processed entirely by Google Play or the Apple App Store — we never see or store your card details.
- Device identifier. On Android the device's Android ID (stored hashed); on iOS a random identifier the App generates once and keeps in the device keychain. It exists only to count free imports per device so limits cannot be reset by deleting and re-creating accounts. It is never used for advertising.
- Analytics and diagnostics. Crash reports and product-usage events (screens viewed, "an import completed", credits spent) so we can keep the App reliable and improve it. These are tied to your account ID; no advertising identifier is ever read.
How we use information
- Provide the service: sync your recipes, cookbooks and plans across sessions and devices;
- Run AI features you request: extracting a recipe from a photo, caption or name, and finding or generating a cover image for it;
- Operate the free-credit and Plus subscription system;
- Send push notifications you have opted into (reminders, product updates) — you can turn these off in Settings or system settings at any time;
- Show public recipes you publish to other users, under your profile name;
- Maintain safety and reliability: debugging, abuse prevention, and enforcing per-account usage limits;
- Comply with law and enforce our Terms.
Where the GDPR or similar laws apply, our legal bases are performance of a contract (running your account), your consent (notifications, camera/photos), and legitimate interests (security, preventing abuse, improving the App).
AI processing of your content
HelloBite's import features are powered by third-party AI services acting as our processors:
- Text, captions and photos you import are sent to Google's Gemini API to extract a structured recipe.
- When no suitable real photo of a dish exists, a cover image is generated by fal.ai from a short text description of the dish (your photos are never sent to fal.ai).
- Candidate cover photos from free image libraries are checked by the Gemini API so wrong images are rejected.
Recipe translation is different: it runs entirely on your device using Google ML Kit's offline models. Text being translated for display never leaves your phone.
Service providers we share data with
We share personal data only with the processors below, only for the purposes described, and never for their own advertising:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase | Authentication, database, file storage, app logic, configuration, crash reporting (Crashlytics) and usage analytics | Account details, your content, uploaded images, purchase state, device identifier, crash and usage events |
| Mixpanel | Product analytics (how features are used) | Account ID, email, display name, usage events |
| Google Gemini API | Recipe extraction and image checking | Imported text, captions and photos |
| fal.ai | Generating dish cover images | Short dish descriptions only |
| OneSignal | Push notifications | Push token, account ID, notification preferences |
| RevenueCat | Subscription management | Account ID, purchase receipts from the app store |
| ipwho.is | One-time country lookup for language options | IP address (not stored by us) |
| Wikimedia Commons / Openverse | Finding freely-licensed dish photos | Dish names only — no personal data |
| Google ML Kit | On-device translation | Processed locally; nothing shared |
If you open a recipe's source website inside the App's built-in browser, that website receives your requests directly, under its own privacy policy.
What we do not do
- No third-party advertising and no advertising SDKs;
- No sale or rental of personal information, and no "sharing" for cross-context behavioural advertising as defined by the CCPA/CPRA;
- No precise location collection;
- No access to your contacts, messages or files beyond the photos you explicitly pick.
Storage & security
Your data is stored on Google Firebase infrastructure. Data is encrypted in transit (TLS) and at rest on Google's servers. Access to production data is restricted to the App's operators, our AI features run behind authenticated endpoints with per-account limits, and API credentials are held in a managed secret store, never in the App itself. No system is perfectly secure; if a breach affecting your personal data occurs we will notify you and the relevant authorities as required by law.
Data retention
- Account & content — kept while your account exists; removed when you delete your account (Section 8).
- Recipes you made public — removed from public view when you delete them or your account.
- Purchase records — retained as required for tax, accounting and fraud-prevention obligations.
- Device credit record — the hashed device identifier and its free-import counter are kept after account deletion, so free limits cannot be reset by re-registering. It contains no name, email or content.
- Diagnostics — kept up to 18 months, then deleted or aggregated.
- Anonymous, non-personal data — dish cover images in our shared image library are not linked to any account and may be retained.
Deleting your account & data
You can permanently delete your account inside the App: Settings → Account → Delete account. This removes your account, recipes, cookbooks, meal plans, grocery lists, drafts, preferences and profile from our systems. You may also request deletion by email at support@nextwaveinfotech.com; requests are honoured within 30 days. See the companion Delete your HelloBite account page for step-by-step instructions and exactly what is deleted or retained.
Your privacy rights
Depending on where you live, you have some or all of these rights, and we extend them to all users as a matter of practice: access a copy of your data, correct it, delete it, port it, object to or restrict certain processing, and withdraw consent (for example, turn off notifications) at any time without affecting prior processing.
- EEA / UK (GDPR). You may also lodge a complaint with your local supervisory authority.
- California (CCPA/CPRA). We do not sell or share personal information; you will not be discriminated against for exercising your rights.
- India (DPDP Act 2023). You may exercise the rights above as a Data Principal and have a right to grievance redressal; contact us at the email below and we will respond within statutory timelines.
To exercise any right, use the in-App controls or email support@nextwaveinfotech.com. We may need to verify your identity via your signed-in account.
Children
HelloBite is not directed at children under 13 (or the higher minimum age in your country), and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
International transfers
Our service providers store and process data on servers that may be located outside your country, including the United States. Where required, transfers rely on appropriate safeguards such as the providers' standard contractual clauses and equivalent mechanisms.
Changes & contact
We may update this policy as the App evolves. Material changes will be announced in the App before they take effect, and the effective date above will always reflect the current version. Continued use after a change takes effect means the updated policy applies.
Questions or requests: support@nextwaveinfotech.com