Privacy Policy
Last updated:
Hapka AI is a calorie tracker for iPhone and Android that works from photos of your food. That means you trust us with personal data, including health data. This policy explains what we collect, why, where it goes and how to delete it.
1. Who is responsible for your data
The data controller is the developer of Hapka AI, established in Bulgaria. You can reach us about anything in this policy at the email address at the end of this page.
2. What we collect
We collect only what the app needs to work. By category:
- Account: name, email address and the sign-in identifier from Apple or Google. If you use Apple's Hide My Email, we only receive the relay address.
- Profile and goals: sex, birth date, height, weight, activity level, goal, pace, unit system and language. Your daily targets are computed from these.
- What you log: meals, ingredients and weights, meal photos, scanned barcodes, free-text descriptions, weigh-ins, water, exercise, progress photos, saved foods and meals, and your avatar.
- Corrections and feedback: when you fix an ingredient or rate a scan, we keep the correction to improve recognition.
- Health data (only if you connect Apple Health or Health Connect): steps, active energy and workouts. See section 5.
- Technical data: push notification token, app and OS version, language, timestamps, and your IP address in server logs.
We do not collect location data. We do not ask for your contacts, microphone or photo library, beyond the single photo you choose for a specific meal.
3. How we use it
- To provide the service: recognising food, computing calories, macros and daily targets, and showing your history and progress.
- To improve accuracy: your corrections train our matching of ingredients to the food database. We do not train AI models on your photos.
- For notifications you have turned on, such as a reminder to log a meal.
- For security: limiting abuse, rate limiting and investigating incidents.
- For support: to answer you when you write to us.
We do not use your data for advertising, marketing profiles or sale to third parties.
4. Photos and AI processing
When you scan a meal, the photo is uploaded directly to our storage. Before it is stored it is downscaled and all metadata (EXIF), including GPS coordinates, is removed.
The processed photo and/or your text description is sent to OpenAI's API to identify the dish and its ingredients with approximate weights. The model returns names and weights only; every calorie is computed from our food database, not by the model.
Under OpenAI's API terms, data sent through the API is not used to train their models. We send the minimum needed for recognition: the photo without metadata and the description. We never send your name, email or health data.
The photo stays attached to the meal so you can see it in your history. It is deleted when you delete the meal or your account.
5. Apple Health and Health Connect data
If you grant access, we read steps, active energy and workouts from Apple Health on iPhone or Health Connect on Android to include them in your daily energy expenditure. Access is read-only. We never write to either.
Health data is used solely for the calculations in your own account. It is never sold, never used for advertising and never shared with third parties other than the hosting providers that store it on our behalf.
You can revoke access at any time: on iPhone in Settings → Health → Data Access & Devices, on Android in Health Connect → App permissions. That stops further reading; samples already synced can be removed by deleting your account.
6. Legal basis
We process your data on the following bases under the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)): everything needed to provide the app to you.
- Explicit consent (Art. 9(2)(a)): health data from Apple Health or Health Connect and your weight and goal data. You can withdraw it at any time.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure and improving accuracy from your corrections.
- Legal obligation (Art. 6(1)(c)): where the law requires it.
8. Transfers outside the EU
Food recognition is performed by OpenAI, which may process data in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. We limit what is transferred to the metadata-free photo and the description text.
9. How long we keep data
- Your account data is kept for as long as the account is active.
- When you delete your account it is anonymised immediately and every session is revoked. Permanent erasure runs automatically 30 days later. That window lets an accidental tap be reversed by writing to us.
- Data export files are deleted 7 days after they are created.
- Server logs containing IP addresses are kept for a short period for security purposes.
10. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. Most of them are built into the app:
- Access and portability: Profile → Account Actions → Export my data. You receive one JSON file with everything you have logged.
- Rectification: edit your profile, goals and any meal directly in the app.
- Erasure: Profile → Account Actions → Delete account…. No email to us required. You can also request it by email without the app, as described at hapkaai.app/en/delete-account.
- Withdrawing consent for health data: in the iPhone Health settings or in Health Connect on Android.
For anything else, write to us. If you believe we process your data unlawfully, you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (www.cpdp.bg) or with the supervisory authority in the country where you live.
11. Security
All communication is encrypted (HTTPS). Account access uses short-lived tokens that renew automatically and are revoked on sign-out or deletion. Photos are uploaded through temporary signed URLs, so they never pass through the application server in raw form. We rate-limit requests to limit abuse. No system is perfectly secure, but if an incident affects your data we will notify you as the law requires.
12. Children
Hapka AI is not intended for anyone under 16 and we do not knowingly collect data from them. If we learn that we have, we will delete it.
13. This website
The site hapkaai.app is static. It uses no cookies, contains no analytics or advertising scripts, loads its fonts from its own server and collects no personal data. Like any web server, the hosting provider (Cloudflare) processes your IP address to deliver pages and protect the site from abuse.
14. Changes to this policy
If we change this policy we will publish the new version here with a new date. For material changes we will notify you in the app before they take effect.
Contact
For privacy questions or to exercise your rights, write to redjep.molaahmed.rm@gmail.com.