ate← Back to the site

Privacy Policy

Last updated 27 July 2026 · Applies to the ate Android app and this website

ate is a food collection app. It needs your photos, your account and, if you choose to add it, the place you ate. Nothing else. This page says plainly what happens to each of those.

On this page
  1. 1. Who is responsible
  2. 2. What we collect
  3. 3. Why we collect it
  4. 4. Photos and AI recognition
  5. 5. Who else sees your data
  6. 6. How long it is kept
  7. 7. Your rights and choices
  8. 8. Security
  9. 9. Children
  10. 10. International transfers
  11. 11. This website
  12. 12. Changes
  13. 13. Contact

1. Who is responsible

ate is an independent app built and operated by Noko Labs. For the purposes of the UK GDPR and the EU GDPR, Noko Labs is the data controller. There is no company behind it and no advertising business attached to it.

You can reach the controller at nokolabs.dev@gmail.com.

2. What we collect

DataWhere it comes fromIs it optional?
Google account identifier, email address and display nameGoogle Sign-In, when you create an accountNo. It is how your collection stays yours
Photos of dishes, and the cut-out sticker made from themYour camera or photo library, when you save a dishYes. No photo, no entry
Dish name, cuisine, restaurant or place name, date, star rating and your notesEntered or confirmed by youYes, apart from the dish name
Approximate coordinates of a mealYour device location, only if you grant the permission and only at the moment you attach a placeYes. The app works fully without it
Technical records: crash reports, error logs, request timestampsThe app and its servers, automaticallyNo, but they carry no photo or note content

ate does not collect contacts, calendar entries, browsing history, advertising identifiers, health data or continuous background location. There is no third-party analytics SDK and no advertising SDK in the app.

3. Why we collect it

We never sell personal data, and we do not use it for advertising or profiling.

4. Photos and AI recognition

Read this bit before you photograph anything sensitive. When you save a dish, the photo is sent to Google’s Gemini API so the dish can be named. Under Google’s terms for the free tier, content you submit may be used to improve Google’s products and may be reviewed by human reviewers. Your photo therefore leaves your device and leaves our control at that moment.

Your collection, notes, places, ratings and the stickers themselves stay private to your account and are not shared with Google beyond that single recognition call.

A photo is sent once, at the moment of recognition. It is not sent again when you browse your collection. If you would rather not send a photo at all, you can decline recognition and type the dish name yourself.

5. Who else sees your data

Your collection is private. There is no public profile, no feed and no follower list. Data is shared only with the processors that make the app run:

ProcessorWhat it handlesWhere
SupabaseAccount records, dish metadata, notes, coordinatesManaged Postgres, EU/US regions
Cloudflare R2Your photos and stickers, in a private bucketCloudflare’s object storage
Google (Gemini API)One dish photo per recognition, as described aboveGoogle Cloud
Google (Sign-In)Authenticating you; we receive an identifier and emailGoogle
Google MapsRendering the map. Map tiles are requested for the area you viewGoogle
VercelServing this website. No app data passes through itVercel’s edge network

We would also disclose data if legally required to, and we would tell you unless we were forbidden from doing so.

6. How long it is kept

7. Your rights and choices

If you are in the UK, EU, or a jurisdiction with comparable law, you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. Exercising any of these is free and we will respond within one month.

If you are in the UK you may complain to the Information Commissioner’s Office; in the EU, to your national supervisory authority. We would appreciate the chance to fix it first.

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives in exchange for personal information. The rights above cover the access and deletion rights you hold.

8. Security

Everything travels over TLS. Photos live in a private object store that is never publicly listable and is reached only through short-lived signed URLs. Database rows are protected by row-level security, so one account’s query cannot return another account’s rows. Server credentials for Gemini and storage exist only on the server and are never shipped inside the app.

No system is perfect. If a breach affects your rights, we will notify you and the relevant authority without undue delay.

9. Children

ate is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.

10. International transfers

Our processors operate globally, so your data may be processed outside your country, including in the United States. Where that happens, transfers rely on the processors’ Standard Contractual Clauses or an adequacy decision.

11. This website

This site sets no cookies, runs no analytics and embeds no third-party trackers. The only figures it displays are aggregate counts: how many people use ate, how many dishes are in the catalogue. Those identify nobody. Vercel keeps standard server request logs, as any web host does.

12. Changes

If this policy changes materially, the date at the top changes and the app will tell you the next time you open it. Continuing to use ate after a change means you accept the updated policy.

13. Contact

Questions, requests or complaints: nokolabs.dev@gmail.com. A real person reads it.

© 2026 Noko LabsTerms of ServiceDelete your dataSupportnokolabs.dev@gmail.com