1. Controller and scope
The controller responsible for personal data processed through the LekkoGo mobile application and these support pages is .
Privacy questions and requests can be sent to .
This policy applies to the LekkoGo iOS and Android apps, related backend services, and these public legal and support pages. Apple, Google and other providers also act under their own privacy notices when you use their accounts, stores or payment services.
2. Data we process
Account and authentication
- Email address, confirmation status, account identifier, account dates, preferred language and authentication provider.
- A temporary guest account identifier, consent record and activity dates when you use the one guest scan before permanent registration.
- Name supplied through Sign in with Apple or entered in the app, when available.
- Apple or Google provider identifiers needed to authenticate the account. We do not receive your Apple or Google password.
- Security session data stored in the device Keychain or Keystore and validated by our authentication provider.
Profile and health-related information
- Birth year or age used for calculation, calculation sex, height, current weight, target weight, activity level and nutrition goal.
- Calculated calorie and macronutrient targets and progress measurements that you choose to enter.
- These details can reveal information about health or body characteristics and receive additional protection under EU data-protection law.
Meals, photos and AI results
- Meal diary entries, meal type and time, ingredient names, gram portions, calories, macronutrients, recipe references, favorite-food and favorite-recipe choices, and user corrections.
- Meal photos you take or select. The app converts the selected image to a resized JPEG before uploading it to private storage.
- AI scan jobs, confidence, safe clarification choices, estimated portion ranges, matched catalogue foods and error codes.
- Meal Calculator input needed for the current calculation. Raw ingredient text is sent for normalization but is not retained in product analytics or calculation history.
- Privacy-limited scanner correction metrics and de-identified unsupported-food terms used to evaluate catalogue quality.
Subscriptions and store information
- A pseudonymous account identifier, store, product, entitlement status, purchase and expiry dates, renewal status, billing-grace status and sandbox or production environment.
- Apple or Google handles payment credentials and the underlying store transaction. LekkoGo does not receive or store your complete payment-card number.
- RevenueCat may process device, transaction, receipt or purchase-token information required to verify subscriptions.
Technical, security and support information
- App version, operating system, device type, language, app environment, technical operation code and validated opaque request identifiers.
- Network addresses may be processed transiently by hosting, security or store infrastructure. LekkoGo does not intentionally add account, meal or health data to crash reports.
- Messages and attachments you send to support. Please never send a password, provider token, complete payment details or unnecessary meal and health information.
Optional product analytics and referral data
- When you enable the setting named Optional app analytics, LekkoGo sends a limited set of product events under a randomly generated pseudonymous analytics identifier that is not connected to your LekkoGo account identifier.
- Events use coarse categories such as language, sign-in state, feature result bucket and app environment, plus limited app, device type and operating-system information.
- Optional analytics excludes meal photos, meal names, ingredient text, exact calories, exact weight, email address, display name and health-profile values.
- If you use an approved creator code or referral link, we may store the code, campaign or source and capture time for attribution and fraud prevention.
We obtain data directly from you, from the app and device when you use a feature, from the authentication provider you select, and from Apple, Google or RevenueCat for subscription status. An email address is not required for the one guest scan, but a temporary authenticated identifier is created to isolate and protect that scan. Required account data is otherwise necessary to provide a signed-in service. Profile and meal details are voluntary, but a feature cannot calculate a personalized result without the information it needs.
3. Why we process data
| Purpose | Data | Legal basis in the EEA |
|---|---|---|
| Create and secure your account | Account, provider and session data | Performance of the service contract and legitimate interests in security and abuse prevention |
| Calculate targets and show progress | Profile, body measurements, goals and diary | Performance of the requested service plus explicit consent for health-related data where Article 9 GDPR applies |
| Scan a meal or normalize ingredients | Photo or ingredient input, locale, safety identifier and AI result | Performance of the feature you request plus explicit consent where the content includes health-related data |
| Manage Premium access | Pseudonymous user ID, store product and subscription status | Performance of the subscription contract and compliance with accounting or consumer-law obligations where applicable |
| Keep the service secure and reliable | Limited technical, security, error and request data | Legitimate interests in preventing abuse, diagnosing faults and protecting users |
| Optional product analytics | Random analytics identifier, allowlisted events and coarse categories not connected to the LekkoGo account ID | Your consent, which can be withdrawn in Profile without affecting prior lawful processing |
| Answer support and privacy requests | Contact details and the information you provide | Performance of the service, legal obligations and legitimate interests in customer support |
LekkoGo does not use meal, body or account data for third-party advertising. It does not make decisions that produce legal or similarly significant effects. Calorie, portion and recipe outputs are estimates that you can review and correct.
4. AI meal processing
When you ask LekkoGo to scan a meal, the app uploads the prepared meal photo to private Supabase storage. A protected server function retrieves it and sends the image, selected language, verified food catalogue instructions and a one-way safety identifier to the OpenAI API. OpenAI returns visible food identities and portion ranges. LekkoGo then calculates calories and macronutrients from its reviewed nutrition catalogue.
When you use Meal Calculator, the text you submit is sent to the OpenAI API only to normalize ingredient names and explicit quantities. LekkoGo selects gram portions and calculates nutrition from its own catalogue. Raw ingredient text is not saved in product analytics or the calculation history.
- The server request uses `store: false` and does not ask OpenAI to create a reusable response record for LekkoGo.
- OpenAI API data is not used to train OpenAI models by default under OpenAI's current business-data commitments.
- OpenAI may still retain API input and output for abuse monitoring under the settings and eligibility of the LekkoGo API project. The exact approved retention mode must be verified before publication.
- Do not photograph people, documents, addresses, screens or any content that is not needed to estimate a meal.
5. Service providers and international transfers
We use providers only for defined technical purposes. Depending on the feature, the following recipients or categories may process data on our behalf or as independent providers:
| Provider | Purpose | Typical data |
|---|---|---|
| Supabase | Authentication, EU-region database, private file storage and server functions | Account, profile, meals, photos, AI jobs, entitlement and request data |
| OpenAI | Requested meal-image understanding and ingredient normalization | Prepared meal image or submitted ingredients, selected language and one-way safety identifier |
| RevenueCat | Subscription products, receipt validation and entitlement status | Pseudonymous app user ID, device, store and transaction metadata |
| Apple and Google | App distribution, authentication and store payments | Provider account data, device/store data and purchase records under their own notices |
| Sentry | Sanitized crash and operational diagnostics | Technical exception, stack trace, app environment, device/OS, locale and approved operation code |
| PostHog EU Cloud | Optional privacy-limited product analytics after opt-in | Allowlisted event name and coarse, code-owned categories without account or health content |
| Resend | Authentication email delivery | Email address, authentication-message content and delivery metadata |
| Cloudflare Pages and the business email provider | Deliver these legal and support pages and receive support or privacy messages | Connection and security logs, plus information you send in a message |
The Development environment is hosted in Supabase's West EU region in Ireland. The separate Production environment is hosted in the Central EU region in Frankfurt, Germany. Some providers or subprocessors may process data outside Poland or the European Economic Area. The controller documents the applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and reviews material provider changes.
We do not sell personal data. We may disclose limited information when required by law, to protect users and the service, or in a business transfer subject to applicable safeguards and notice duties.
6. Retention and deletion
| Data | Planned launch rule |
|---|---|
| Account, profile, goals, diary and saved AI results | Until you delete the item or your account, unless a shorter period is stated in the app. Deleted database records may remain in the protected daily backup for up to 7 days |
| Saved private meal-photo bytes | Until you delete the item or your account. LekkoGo does not keep a backup copy of the private photo bytes |
| Failed, cancelled or abandoned scan photos and jobs | Removed immediately where the app completes cancellation; an automatic cleanup must remove any orphaned copy within 24 hours before this promise is published |
| Temporary guest account and private guest data | Deleted after 30 days of inactivity; an unsaved prepared scan photo remains subject to the 24-hour maximum above |
| Scanner correction and catalogue-gap metrics | Up to 90 days, then deleted or irreversibly de-identified; the purge schedule must be enabled before publication |
| Optional product analytics | |
| Sanitized crash diagnostics | |
| Security and service logs | |
| Support and privacy correspondence | |
| Authentication email and delivery logs | 30 days, with provider backups for 7 days, subject to final Production verification |
| OpenAI API abuse-monitoring data | Up to 30 days under the current default control; the exact Production mode must be verified before publication |
| Store and payment records | Retained by Apple, Google and relevant payment providers under their policies and legal duties |
Deleting a LekkoGo account removes the account and associated data from Supabase, private meal-photo storage and the separate LekkoGo RevenueCat customer record. Deletion does not cancel or refund an Apple or Google subscription. Store billing must be managed separately.
Production database records are protected by daily backups that expire after 7 days. These backups include database records and Storage metadata, but not the private meal-photo bytes. A deleted database record may remain in a protected backup only until that backup expires, unless law requires longer retention. A missing private photo does not remove the saved calorie and meal record.
7. Your choices and rights
Subject to applicable law and any exceptions, you may request access, a copy, correction, deletion, restriction, portability or objection. Where processing is based on consent, you may withdraw consent at any time without affecting processing already carried out lawfully.
- Export: In LekkoGo, open Profile, then Privacy and your data, then Create data file.
- Health-data consent: In the same area, choose Withdraw consent and delete health data. LekkoGo deletes body measurements, nutrition goals, diary entries, private meal photos, progress, custom foods, favorite-food and favorite-recipe choices, and AI meal records, then stops personalization. Your login, creator attribution and Apple or Google subscription remain. You can later consent again and create a new plan.
- Delete: In the same area, choose Delete my account, or use the direct account-deletion page if you cannot access the app.
- Analytics: Turn Optional app analytics off in Profile. It is off by default. The app stops collection, rotates the random identifier and requests deletion of its historical events.
- Meal photo: Delete the saved meal to remove its private photo.
- Contact: Email . We may ask for proportionate account verification before acting.
You may lodge a complaint with the President of the Personal Data Protection Office in Poland. Information is available at uodo.gov.pl. We encourage you to contact us first so we can investigate promptly.
8. Security and privacy controls
- Encrypted network transport and platform encryption at rest.
- Private meal-photo storage with short-lived signed links.
- Row-level access rules that restrict users to their own account data.
- Session storage in the device Keychain or Keystore.
- Server-only OpenAI, RevenueCat and account-administration secrets.
- Allowlisted analytics events, privacy-limited opt-in analytics and disabled session replay.
- Sanitized crash reporting that removes user, request, meal, photo, ingredient, email and health fields before delivery.
- Authenticated export and permanent account-deletion endpoints.
No security method is perfect. If we confirm a personal-data breach, we will assess it and notify affected people and authorities when required by law.
Adults only
LekkoGo is designed for adults aged 18 or over. We do not knowingly offer the service to children. Contact us if you believe a child has provided personal data.
Changes to this policy
We may update this policy when features, providers, law or retention rules change. We will update the effective date and provide additional notice in the app when a change materially affects users or requires new consent.
9. Contact
Controller: