Privacy Policy

Effective 21 August 2026

This policy explains how Geometry Lab L.L.C-FZ ("Geometry", "we", or "us") handles information when you use Biotile.

Information you choose to add

Biotile stores meal entries, portions, check-ins, templates, settings, and optional meal notes on your device. Meal photos are also kept on your device. If you choose to sign in, these records sync to our Cloudflare-hosted service so they can appear on your other devices.

Meal analysis

When you ask Biotile to estimate a typed or photographed meal, the relevant text or image is sent through our Cloudflare service to OpenAI for food identification. Images sent inline for estimation are not saved by our service. Photos you explicitly upload for account-backed analysis can be stored in Cloudflare R2 under your account after metadata is removed. You review every estimate before it counts.

Account information

If you sign in, we process an account identifier and the email address supplied by Apple, Google, or email-code sign-in. Sign-in proofs are used to authenticate you. We do not silently merge accounts based on email address.

Subscriptions

Apple processes purchases and payment details. RevenueCat receives purchase and entitlement information so Biotile can unlock the membership you bought. We do not receive your full payment-card details.

Product analytics

Biotile uses first-party product analytics to count app opens, onboarding steps, membership actions, logged-meal counts, and coarse reliability metrics. It never sends meal text, photos, food names, symptoms, notes, email addresses, or account identifiers as analytics properties. Germany, Austria, and devices with an unknown region are asked before any product analytics leaves the device. Other regions can opt out in Settings.

Our relay sends EEA, UK, Swiss, and unknown-location analytics as unlinkable aggregate events with a new random identifier for each event. In other regions, it may use an app-scoped random identifier after the relay confirms that mode. Apple MetricKit may provide aggregate crash and performance counts without user content.

Service providers and transfers

We use Cloudflare for hosting, storage, security, email routing, and backups; OpenAI for requested meal analysis; PostHog EU Cloud for product analytics; RevenueCat and Apple for subscriptions; Apple and Google for optional sign-in; Resend for email sign-in codes; and Slack for internal support notifications. Support emails are forwarded to Geometry's monitored support mailbox. Slack receives the sender address and subject, but not the email body. These providers process information under their terms and may operate in countries other than yours.

Retention and deletion

Local records remain until you delete them or remove the app. Synced account records remain while your account exists. Short-lived sign-in codes and expired tokens are removed on a schedule. Account deletion in Settings removes account records and account media from our live service and revokes supported sign-in grants. Operational backups age out according to our backup schedule.

Your choices

You can use core local logging without an account, turn product analytics off in Settings, export your records as CSV, delete local data, remove linked sign-in methods, sign out, or delete your account. You can manage subscriptions through your Apple Account.

Children

Biotile is not directed to children under 13. If local law requires parental permission for a younger person to use an online service, a parent or guardian must provide it.

Security and changes

We use transport encryption, device-bound account protections where available, request limits, and access controls. No security measure eliminates every risk. We may update this policy when the product or law changes and will update the effective date.

Contact

Questions or privacy requests: support@biotile.app.