Privacy Policy
ate is a food collection app. It needs your photos, your account and, if you choose to add it, the place you ate. Nothing else. This page says plainly what happens to each of those.
1. Who is responsible
ate is an independent app built and operated by Noko Labs. For the purposes of the UK GDPR and the EU GDPR, Noko Labs is the data controller. There is no company behind it. The only advertising in ate is one rewarded video you can choose to watch when your daily scans run out, described in section 5.
You can reach the controller at nokolabs.dev@gmail.com.
2. What we collect
| Data | Where it comes from | Is it optional? |
|---|---|---|
| Account identifier, email address and display name | Google Sign-In, or the email address and password you register with | No. It is how your collection stays yours |
| Photos of dishes, and the cut-out sticker made from them | Your camera or photo library, when you save a dish | Yes. No photo, no entry |
| Dish name, cuisine, restaurant or place name, date, star rating and your notes | Entered or confirmed by you | Yes, apart from the dish name |
| Approximate coordinates of a meal | Your device location, only if you grant the permission and only at the moment you attach a place | Yes. The app works fully without it |
| Technical records: crash reports, error logs, request timestamps | The app and its servers, automatically | No, but they carry no photo or note content |
| Usage events: which steps of a scan happened (camera opened, photo taken, recognition answered, dish saved), whether a suggestion was accepted or replaced, and which dish it resolved to | The app, automatically, under a random identifier | No, but no photo, note, place or free text is ever in an event |
| Your device’s advertising ID, along with how you interacted with a rewarded video and whether it played correctly | Google’s AdMob SDK, from the point your daily scans run out and the app offers you a video | Yes. If you never run out of scans, the ad SDK never starts and never requests an ad |
ate does not collect contacts, calendar entries, browsing history, health data or continuous background location. The usage events above are the whole of the app’s analytics: they describe what the app did, not what your food looks like, and they are tied to a random install identifier rather than to your name or email.
3. Why we collect it
- To run your account, so your collection follows you to a new phone. Lawful basis: performance of a contract with you.
- To identify the dish in a photo: the core feature you asked for. Lawful basis: performance of a contract.
- To store and show your collection, map and journeys: the product itself. Lawful basis: performance of a contract.
- To keep the service working and secure: diagnosing crashes, preventing abuse. Lawful basis: legitimate interests.
- To improve dish recognition: we record when a suggestion was wrong, in aggregate, without your photo attached. Lawful basis: legitimate interests.
- To see where the app loses people: the usage events above tell us, in aggregate, how far scans get and where they fail. Lawful basis: legitimate interests.
- To show and pay for the rewarded video, and to check that a reward was really earned before crediting a scan. Lawful basis: your consent, given by choosing to watch it.
We never sell personal data. We do not profile you, and nothing you put into ate is used to target advertising: your photos, dishes, notes, places and ratings are never sent to an ad network.
4. Photos and AI recognition
Read this bit before you photograph anything sensitive. When you save a dish, the photo is sent to Google’s Gemini API so the dish can be named. Under Google’s terms for the free tier, content you submit may be used to improve Google’s products and may be reviewed by human reviewers. Your photo therefore leaves your device and leaves our control at that moment.
Your collection, notes, places, ratings and the stickers themselves stay private to your account and are not shared with Google beyond that single recognition call.
A photo is sent once, at the moment of recognition. It is not sent again when you browse your collection. If you would rather not send a photo at all, you can decline recognition and type the dish name yourself.
When recognition rejects a photo, for example because it sees no food in it, we keep that photo for up to 7 days so we can check whether the rejection was fair, and then it is deleted automatically. It stays in the same private store as your other photos and goes nowhere else.
5. Adverts
ate gives you ten scans a day. When they run out you can watch one rewarded video to get one more scan, or wait until tomorrow. That is the only advert in the app. There are no banners, no interstitials, and nothing appears while you are using it normally.
The video comes from Google AdMob. Two things follow from that, and you should know both:
- AdMob receives your device’s advertising ID, its IP address and general device information, and records whether the video loaded, played and finished. Google uses this to select the advert, to measure it, and to detect fraudulent traffic. Google acts as an independent controller for this, not as our processor.
- RevenueCat verifies the reward. AdMob confirms the view to RevenueCat’s servers rather than to your phone, and RevenueCat tells our backend which account earned the scan. This is what stops a modified app from awarding itself unlimited scans. RevenueCat receives your ate account identifier and nothing else.
Your advertising ID is a resettable identifier that belongs to Android, not to us. Android Settings → Privacy → Ads lets you reset it or delete it entirely; deleting it stops personalised advertising across every app on the phone.
6. Who else sees your data
Your collection is private. There is no public profile, no feed and no follower list. Data goes only to the services that make the app run:
| Service | What it handles | Where |
|---|---|---|
| Supabase | Account records, dish metadata, notes, coordinates | Managed Postgres, EU/US regions |
| Cloudflare R2 | Your photos and stickers, in a private bucket | Cloudflare’s object storage |
| Google (Gemini API) | One dish photo per recognition, as described above | Google Cloud |
| Google (Sign-In) | Authenticating you; we receive an identifier and email | |
| Google Maps | Rendering the map. Map tiles are requested for the area you view | |
| Google AdMob | The rewarded video, and only once you ask for one: advertising ID, IP address, device information, whether the video played | |
| RevenueCat | Verifying that a rewarded view really happened, against your ate account identifier | RevenueCat, United States |
| PostHog | The usage events above, under a random identifier, on PostHog’s EU cloud | PostHog, hosted in the EU (Frankfurt) |
| Vercel | Serving this website. No app data passes through it | Vercel’s edge network |
We would also disclose data if legally required to, and we would tell you unless we were forbidden from doing so.
7. How long it is kept
- Your memories and photos: until you delete them, or until you delete your account.
- Your account record: until you delete your account.
- Deleted items: removed from the live database immediately and purged from backups within 30 days.
- Technical logs: up to 90 days, then discarded.
- Photos rejected by recognition: up to 7 days, for checking that the rejection was fair, then deleted automatically.
- Usage events: kept in aggregate under their random identifier; deleting your account does not delete them because they were never linked to it.
- Anonymous recognition-accuracy records: kept indefinitely, because they contain no personal data and no photo.
8. Your rights and choices
If you are in the UK, EU, or a jurisdiction with comparable law, you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. Exercising any of these is free and we will respond within one month.
- Access, correct or delete individual entries: do it in the app, on any dish or memory.
- Delete everything: see Delete your data.
- Withdraw location permission: Android Settings → Apps → ate → Permissions. Meals already saved keep their pin until you edit them.
- Reset or delete your advertising ID: Android Settings → Privacy → Ads. This is a phone-wide control and it applies to every app, not only ate.
- Export a copy: email nokolabs.dev@gmail.com and we will send you a machine-readable export.
If you are in the UK you may complain to the Information Commissioner’s Office; in the EU, to your national supervisory authority. We would appreciate the chance to fix it first.
California residents: we do not sell personal information, and we do not offer financial incentives in exchange for it. If you watch a rewarded video, the advertising identifier AdMob receives may count as “sharing” for cross-context behavioural advertising under the CPRA. Deleting your advertising ID in Android Settings → Privacy → Ads opts you out of it, as does simply not watching the video. The rights above cover the access and deletion rights you hold.
9. Security
Everything travels over TLS. Photos live in a private object store that is never publicly listable and is reached only through short-lived signed URLs. Database rows are protected by row-level security, so one account’s query cannot return another account’s rows. Server credentials for Gemini and storage exist only on the server and are never shipped inside the app.
No system is perfect. If a breach affects your rights, we will notify you and the relevant authority without undue delay.
10. Children
ate is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
11. International transfers
Our processors operate globally, so your data may be processed outside your country, including in the United States. Where that happens, transfers rely on the processors’ Standard Contractual Clauses or an adequacy decision.
12. This website
This site sets no cookies, runs no analytics and embeds no third-party trackers. The only figures it displays are aggregate counts: how many people use ate, how many dishes are in the catalogue. Those identify nobody. Vercel keeps standard server request logs, as any web host does.
13. Changes
When this policy changes, the date at the top changes with it. That date is the honest way to check, so it is worth a look after an update. Continuing to use ate after a change means you accept the updated policy.
14. Contact
Questions, requests or complaints: nokolabs.dev@gmail.com. A real person reads it.