Privacy Policy

Effective 7 September 2026

This policy explains how Geometry Lab L.L.C-FZ ("Geometry", "we", or "us") handles information when you use Biotile.

Who we are

Data Controller
Geometry Lab L.L.C-FZ, Licence No. 2651608.01,
Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.

EU Representative (Art 27 GDPR)
Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.

UK Representative (Art 27 UK GDPR)
Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom.

You can exercise privacy rights through the Prighter rights portal, email support@biotile.app, or contact privacy@geometryapps.com. The Geometry app directory is at geometryapps.com.

The short version

Biotile can be used for local catalog-food logging without an account. Meal, portion, supplement, habit, and gut check-in records stay on your device unless you sign in and separately allow health-related cloud processing. Biotile does not show advertising, use IDFA, perform cross-app or cross-site tracking, sell personal information, or share it for behavioral advertising.

If you allow cloud processing, the account service can sync the records you add and process a meal description or photo when you request AI identification. You can withdraw that permission in Settings. Withdrawal stops future sync and requested meal analysis; local catalog logging remains available.

Information you may store

On iOS, camera photos are saved to your Photos library after capture, and staged copies are removed after the estimate is confirmed or discarded. Android stores captured and selected meal photos in the app's private device storage. Biotile does not request contacts, location, HealthKit data, or an advertising identifier.

Optional account and cloud processing

Sign-in is optional for local logging. If you sign in with Apple, Google, or an email code, we process the provider subject, Biotile account identifier, email address when supplied, authentication state, and security records needed to protect the session. Accounts are not silently merged by matching email.

Before meal, supplement, or gut check-in records can leave the device, Biotile shows a dedicated cloud-processing choice. If you allow it, those records can be stored in the Cloudflare-hosted account service so they appear on your other devices. The choice is separate from the Terms, AI analysis, and product analytics.

These records may reveal information about diet, digestion, supplements, or health. Where they qualify as health data under Article 9 of the GDPR or UK GDPR, the additional lawful basis is your explicit consent under Article 9(2)(a). The app records the affirmative decision with a timestamp and policy version. You may withdraw in Settings at any time. Withdrawal does not affect processing that was lawful before it was withdrawn.

Requested meal analysis

When you ask Biotile to identify a typed or photographed meal, the selected text or image passes through the authenticated Cloudflare relay to OpenAI. When OpenAI is not configured or its API balance is exhausted, Biotile uses Cloudflare Workers AI as a Cloudflare-hosted fallback. Biotile asks separately before AI analysis and requires review before an estimate adds food or variety credit. Each provider receives only the selected meal input, not the account email or unrelated history.

One inline image can be processed without being stored in Cloudflare R2. For a multi-photo request, metadata is removed before each image is stored temporarily in account-scoped Cloudflare R2 media and loaded for the requested estimate. Each consumed upload is deleted after the extraction attempt, including when the AI provider returns an error. A failed provider delete stays in a retry queue, and any abandoned upload is removed by the hourly sweep after 24 hours. Exact catalog foods and saved templates can be logged locally without AI.

If an estimate is offensive or wrong, the confirm screen offers Report this estimate. A report sends the reason you chose, the estimate text shown on that screen, and the optional sentence you type. It sends no photo and no other part of your history.

Biotile is a general-wellness service, not a medical device. It does not provide medical advice, diagnosis, prevention, or treatment. Food identification, portions, fiber, and other estimates can be wrong. Do not use them for a medical decision or emergency.

Subscriptions

The store used for your purchase processes payment details: Apple for the App Store, Google for Google Play, or Samsung for Galaxy Store. RevenueCat receives store transaction and entitlement information tied to its customer identifier so Biotile can unlock and restore the membership. When you sign in, that identifier is linked to your Biotile account. Geometry does not receive your full payment-card number or store-account password.

Product analytics and diagnostics

The app contains no PostHog, Firebase, Amplitude, Mixpanel, or Segment analytics SDK. URLSession on iOS and OkHttp on Android send fixed, content-free events to the first-party e.biotile.app relay. Biotile does not use advertising identifiers or cross-app attribution. The event schema allows coarse app opens, screen views, onboarding and feature actions, counts, fixed plan, provider, source, result, and reason values, and app reliability data. It rejects meal text, photos, food names, notes, symptom values, email addresses, account identifiers, and arbitrary properties.

The client decides on the device before the first product event leaves. Germany, Austria, and devices whose region is unavailable send no product analytics until you choose Allow. Other regions start enabled and provide a one-tap Settings opt-out. Turning analytics off stops product events and removes the stored app-scoped analytics identifier and queued identity-bearing events.

The relay then applies two server-side branches. EEA, United Kingdom, Switzerland, and unknown Cloudflare regions use an aggregate branch. Each forwarded event gets a new random identifier, carries no forwarded IP or country, creates no person profile, and cannot be linked to another event. Seven paywall and subscription events are discarded on this branch: paywall views, purchase and restore taps, subscription starts, and offering, purchase, and restore results. Cohort, onboarding-answer, dietary-count, fermented-food, and check-in-state properties are removed before forwarding. Other countries use a pseudonymous full branch. The app creates and stores a random app-scoped identifier only after the relay confirms that branch. It is not a name, email address, account ID, IDFA, or cross-app ID.

Stability and failure diagnostics continue when product analytics is off and are sent without the app-scoped persistent analytics identifier. On iOS, Apple MetricKit supplies crash, hang, CPU-exception, disk-write-exception, app-version, and OS-version counts. On Android, system exit records supply crash, application-not-responding, abnormal-exit, app-version, and OS-version counts.

When an action fails, Biotile can send the event time and platform, a fixed surface, action and error code, app and OS versions, and whether an account was signed in. This diagnostic contains no free text, account ID, email address, meal content, photo, note, symptom value, stack trace, or persistent analytics identifier.

The analytics relay assigns these diagnostics a fresh random event identifier and forwards them to PostHog Cloud EU. It also stores closed client-failure and crash-or-hang rows in Cloudflare D1 for 90 days and writes sanitized warnings to Cloudflare Workers Logs, which are retained for 7 days. A separate Cloudflare alert service sends Slack a fixed client-failure summary containing platform, surface, action, and code; or a crash summary containing platform, build, and crash or hang counts. Each message is limited to those closed values and allow-listed operational fields. It does not forward request or response bodies, headers, query strings, email addresses, user IDs, IP addresses, App Attest key IDs, raw Tail objects, stack traces, meal content, photos, notes, symptoms, raw exception or error text, or persistent analytics identifiers.

Why information is processed

Service providers and international transfers

Biotile uses Cloudflare for the account relay, D1 account records, R2 media and backups, security controls, analytics relay, site hosting, email routing, and Cloudflare Workers AI fallback meal analysis; OpenAI for primary meal analysis you request; PostHog Cloud EU for content-free product analytics and diagnostics; Apple, Google, or Samsung for store purchases, and RevenueCat for subscriptions and entitlements; Apple and Google for optional identity proof; Resend for email sign-in codes; and Slack for internal support and operational notifications. Support mail is a separate flow: it is forwarded to a monitored Geometry mailbox, and Slack receives the sender and subject, not the message body.

Processing may occur in the European Union, United Kingdom, Switzerland, United Arab Emirates, United States, and the locations listed in each provider's subprocessor notice. The controller operates from the UAE and may access account or support records from Dubai. Where European or UK transfer rules apply, provider agreements and the applicable Standard Contractual Clauses or UK transfer terms must cover the transfer, together with data minimization, transport encryption, access controls, and the transfer review in the operator record.

Retention and deletion

Local records remain until you delete them or remove the app. Synced records remain while the account exists. Email codes expire after ten minutes; expired codes and tokens are removed by scheduled maintenance. A consumed meal upload is deleted after its extraction attempt. An abandoned upload is deleted after 24 hours. If storage deletion fails, the tracking row remains and the hourly maintenance job retries it.

Deleting the account in Settings establishes an account-erasure barrier, rejects new photo reservations, requires the account's full media prefix to be empty, removes live account rows, invalidates sessions, and attempts supported identity-grant revocation. The service reports a visible retry error rather than claiming completion if live media deletion fails. A one-hour durable deletion job covers an upload that was already in flight. Daily operational backups expire after about 35 days and retain the erasure record so restored data cannot make a deleted account active again.

A report you send about an AI estimate is kept so the complaint can be answered. Deleting your account replaces the account reference on that report, so the report remains without a link to you.

Aggregate analytics events are unlinkable at ingestion. Pseudonymous full-branch events follow the configured PostHog project retention and deletion process. Closed client-failure and crash-or-hang rows in Cloudflare D1 are deleted after 90 days, and their source warnings remain in Cloudflare Workers Logs for 7 days. Store purchase records remain subject to the applicable store's and RevenueCat's legal and transaction-retention obligations.

Your choices and rights

Settings provides CSV export, local-data deletion, analytics opt-out, health-related cloud-processing withdrawal, AI-analysis withdrawal, sign-in method management, sign-out, and account deletion. You can manage or cancel a subscription through the Apple Account, Google Play, or Galaxy Store account used for that purchase.

Depending on local law, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about processing. You may also complain to your local data-protection authority. Use the Prighter rights portal or email support@biotile.app. We verify the request before disclosing or deleting account records.

Biotile does not sell personal information or share it for cross-context behavioral advertising. The service is currently expected to remain below US state-law business thresholds, but it honors the controls above regardless.

Children

Biotile is intended for adults and is not offered to anyone under 18. Do not create an account or submit records if you are under 18.

Security and changes

Biotile uses TLS, account-scoped authorization, device attestation for protected native actions, request and spend limits, bounded uploads, metadata removal, hashed or encrypted credentials, and account deletion controls. No security control eliminates all risk.

We may update this policy when processing, providers, or law changes. The effective date above identifies the current version. A material change to health-related processing requires a new affirmative decision in the app.

Contact

Privacy and support: support@biotile.app
Data-protection enquiries: privacy@geometryapps.com
Rights portal: app.prighter.com/portal/geometry