Privacy Policy

Last updated 26 August 2026 · Applies to the ate Android app and this website

ate is a food collection app. It needs your photos, your account and, if you choose to add it, the place you ate. Nothing else. This page says plainly what happens to each of those.

1. Who is responsible

ate is an independent app built and operated by Noko Labs. For the purposes of the UK GDPR and the EU GDPR, Noko Labs is the data controller. There is no company behind it. The only advertising in ate is one rewarded video you can choose to watch when your daily scans run out, described in section 5.

You can reach the controller at nokolabs.dev@gmail.com.

2. What we collect

DataWhere it comes fromIs it optional?
Account identifier, email address and display nameGoogle Sign-In, or the email address and password you register withNo. It is how your collection stays yours
Photos of dishes, and the cut-out sticker made from themYour camera or photo library, when you save a dishYes. No photo, no entry
Dish name, cuisine, restaurant or place name, date, star rating and your notesEntered or confirmed by youYes, apart from the dish name
Approximate coordinates of a mealYour device location, only if you grant the permission and only at the moment you attach a placeYes. The app works fully without it
Technical records: crash reports, error logs, request timestampsThe app and its servers, automaticallyNo, but they carry no photo or note content
Usage events: which steps of a scan happened (camera opened, photo taken, recognition answered, dish saved), whether a suggestion was accepted or replaced, and which dish it resolved toThe app, automatically, under a random identifierNo, but no photo, note, place or free text is ever in an event
Your device’s advertising ID, along with how you interacted with a rewarded video and whether it played correctlyGoogle’s AdMob SDK, from the point your daily scans run out and the app offers you a videoYes. If you never run out of scans, the ad SDK never starts and never requests an ad

ate does not collect contacts, calendar entries, browsing history, health data or continuous background location. The usage events above are the whole of the app’s analytics: they describe what the app did, not what your food looks like, and they are tied to a random install identifier rather than to your name or email.

3. Why we collect it

We never sell personal data. We do not profile you, and nothing you put into ate is used to target advertising: your photos, dishes, notes, places and ratings are never sent to an ad network.

4. Photos and AI recognition

Read this bit before you photograph anything sensitive. When you save a dish, the photo is sent to Google’s Gemini API so the dish can be named. Under Google’s terms for the free tier, content you submit may be used to improve Google’s products and may be reviewed by human reviewers. Your photo therefore leaves your device and leaves our control at that moment.

Your collection, notes, places, ratings and the stickers themselves stay private to your account and are not shared with Google beyond that single recognition call.

A photo is sent once, at the moment of recognition. It is not sent again when you browse your collection. If you would rather not send a photo at all, you can decline recognition and type the dish name yourself.

When recognition rejects a photo, for example because it sees no food in it, we keep that photo for up to 7 days so we can check whether the rejection was fair, and then it is deleted automatically. It stays in the same private store as your other photos and goes nowhere else.

5. Adverts

ate gives you ten scans a day. When they run out you can watch one rewarded video to get one more scan, or wait until tomorrow. That is the only advert in the app. There are no banners, no interstitials, and nothing appears while you are using it normally.

The video comes from Google AdMob. Two things follow from that, and you should know both:

Your advertising ID is a resettable identifier that belongs to Android, not to us. Android Settings → Privacy → Ads lets you reset it or delete it entirely; deleting it stops personalised advertising across every app on the phone.

6. Who else sees your data

Your collection is private. There is no public profile, no feed and no follower list. Data goes only to the services that make the app run:

ServiceWhat it handlesWhere
SupabaseAccount records, dish metadata, notes, coordinatesManaged Postgres, EU/US regions
Cloudflare R2Your photos and stickers, in a private bucketCloudflare’s object storage
Google (Gemini API)One dish photo per recognition, as described aboveGoogle Cloud
Google (Sign-In)Authenticating you; we receive an identifier and emailGoogle
Google MapsRendering the map. Map tiles are requested for the area you viewGoogle
Google AdMobThe rewarded video, and only once you ask for one: advertising ID, IP address, device information, whether the video playedGoogle
RevenueCatVerifying that a rewarded view really happened, against your ate account identifierRevenueCat, United States
PostHogThe usage events above, under a random identifier, on PostHog’s EU cloudPostHog, hosted in the EU (Frankfurt)
VercelServing this website. No app data passes through itVercel’s edge network

We would also disclose data if legally required to, and we would tell you unless we were forbidden from doing so.

7. How long it is kept

8. Your rights and choices

If you are in the UK, EU, or a jurisdiction with comparable law, you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. Exercising any of these is free and we will respond within one month.

If you are in the UK you may complain to the Information Commissioner’s Office; in the EU, to your national supervisory authority. We would appreciate the chance to fix it first.

California residents: we do not sell personal information, and we do not offer financial incentives in exchange for it. If you watch a rewarded video, the advertising identifier AdMob receives may count as “sharing” for cross-context behavioural advertising under the CPRA. Deleting your advertising ID in Android Settings → Privacy → Ads opts you out of it, as does simply not watching the video. The rights above cover the access and deletion rights you hold.

9. Security

Everything travels over TLS. Photos live in a private object store that is never publicly listable and is reached only through short-lived signed URLs. Database rows are protected by row-level security, so one account’s query cannot return another account’s rows. Server credentials for Gemini and storage exist only on the server and are never shipped inside the app.

No system is perfect. If a breach affects your rights, we will notify you and the relevant authority without undue delay.

10. Children

ate is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.

11. International transfers

Our processors operate globally, so your data may be processed outside your country, including in the United States. Where that happens, transfers rely on the processors’ Standard Contractual Clauses or an adequacy decision.

12. This website

This site sets no cookies, runs no analytics and embeds no third-party trackers. The only figures it displays are aggregate counts: how many people use ate, how many dishes are in the catalogue. Those identify nobody. Vercel keeps standard server request logs, as any web host does.

13. Changes

When this policy changes, the date at the top changes with it. That date is the honest way to check, so it is worth a look after an update. Continuing to use ate after a change means you accept the updated policy.

14. Contact

Questions, requests or complaints: nokolabs.dev@gmail.com. A real person reads it.