BiteJot AI supports weight management through food, weight, activity, water and fasting records. These records and coach conversation history are stored on your device. We do not require an account or collect an advertising identifier. The app generates a random installation identifier and an authentication token; our Cloudflare server stores the identifier, a hash of the token, creation and last-use dates, and AI usage records associated with the installation. These are device-linked records, not fully anonymous data.
AI processing and your choice
Only after you agree, photo recognition, AI food parsing and the coach send the content needed for the request through our Cloudflare server to OpenAI GPT-6 Luna through Cloudflare AI. Food input can include a meal photo, typed or dictated food text, and candidate food names. The coach can include your question, recent conversation messages and a profile/recent-record summary: birth year/age, height, supplied sex, weight and trends, goal and target date, intake goal, tracking difficulty, habits, common foods and diet, activity and water summaries. It is not a full raw meal-history export.
Dictation uses Apple Speech recognition, which may use Apple servers depending on device and service availability. We send the resulting text, not the audio, to the AI service. You can decline AI or withdraw consent in Settings → AI & privacy. Manual search, barcode lookup and local matching remain available.
Providers, logs and retention
Our application server does not intentionally persist AI photos, prompts or replies. Its diagnostic events contain status/error categories, counts and timings rather than this content. We have disabled AI Gateway log collection and enabled the gateway's Zero Data Retention setting. That setting applies to eligible Unified Billing calls using Cloudflare-managed credentials; it is not a promise that every provider record or legally required safety record is eliminated. OpenAI states that API content is not used for model training unless the customer opts in; its standard abuse-monitoring retention and safety exceptions can apply according to the service configuration. We do not promise that processing stays in a specific country.
Older AI usage rows are eligible for opportunistic cleanup after a seven-day cutoff; deletion is not guaranteed on day seven. Installation/authentication records have no automatic expiry in the current implementation. Service providers may retain operational and security metadata under their policies. In Settings → Server data, you can copy your random installation identifier or confirm deletion of the current installation’s server authentication, entitlement and AI allowance records. The request is authenticated by the app; we do not ask you to email a token. Deletion turns off AI and leaves local food, weight and activity records intact. Opening an online feature again may register a new installation. Provider operational records and backups follow their separate retention policies. Contact us for access, correction or other privacy requests; the identifier helps locate records but is not proof of ownership. Deleting the app removes app records from the device but does not automatically delete server records or backups held by you or your platform.
Online search sends search terms to our server. Barcode lookup sends barcode digits through our server to USDA FoodData Central and/or Open Food Facts. Nutrition comes from food databases, not AI-generated calories. If you allow Apple Health access, we read the supported weight, activity and sleep data you choose; weight is written only when you request it. Only the summary needed for the coach can leave the device with AI consent.
Other uses and your rights
We do not sell your data, use it for advertising or track you across other apps and websites. No advertising or third-party analytics SDK is included. If you voluntarily email support, we receive the information you include and use it to address your request; do not send photos, health records or credentials unless needed and requested. Depending on your location, you may have rights to access, correct, delete or restrict processing, and complain to a data-protection authority. Contact us to exercise them.
The app is intended for adults aged 18 and over. It provides estimates and general wellbeing information, not medical diagnosis or treatment. We will update this page when our practices change.
BiteJot AI 隐私政策
更新日期:2026年10月7日。联系邮箱:hardwalker1212@gmail.com。
记录与设备标识
饮食、体重、运动、饮水、轻断食和助手对话保存在设备上,不要求注册账号,不使用广告标识。App 生成随机安装编号和认证令牌;Cloudflare 服务器保存安装编号、令牌哈希、创建和最近使用时间,以及与安装关联的 AI 使用记录。这些记录关联设备,不是完全匿名数据。
AI 与同意
只有同意后,AI 才把完成请求需要的内容经我们的 Cloudflare 服务器和 Cloudflare AI 发送给 OpenAI GPT-6 Luna。食物输入包括餐食照片、输入或说出的饮食文字、候选食物名称。助手可能包括问题、近期对话消息,以及出生年份/年龄、身高、已填写性别、体重及变化、目标和目标日期、摄入目标、记录困难、习惯、常见食物、饮食/运动/饮水摘要,不是完整逐餐记录。
语音由 Apple Speech 转成文字,视设备和服务情况可能使用 Apple 服务器;发送给 AI 的是文字,不是录音。可拒绝或在设置的“AI 与隐私”撤回同意,手动搜索、条码和本机匹配仍可用。
服务商、日志与保留
我们的应用服务器不主动持久化 AI 照片、提示或回答,诊断事件只记录状态、错误分类、计数和耗时。已关闭 AI Gateway 日志采集,开启网关零数据保留设置;后者适用于符合条件、使用 Cloudflare 托管凭证的 Unified Billing 调用,不代表所有运营记录或依法需要的安全记录都不保留。OpenAI 说明 API 内容默认不用于训练,除非客户主动选择;标准滥用监测保留及安全例外按实际服务配置适用。不承诺全部处理在某个国家进行。服务商政策链接见上方英文部分。
超过七天截止日期的 AI 使用记录可被概率清理,不保证第七天删除。安装认证记录目前没有自动过期机制。服务商按政策可能保留运营和安全元数据。可在“设置 → 服务器数据”复制随机安装编号,或确认删除当前安装的服务器认证、权益和 AI 额度记录。App 通过身份认证提交删除请求,不需要通过邮件发送令牌。删除会关闭 AI,保留本机饮食、体重和运动记录;再次主动使用在线功能可能注册新的安装。服务商运营记录和备份按各自保留政策处理。访问、更正及其他隐私请求可联系邮箱;安装编号有助于定位记录,但不能单独证明身份。删除 App 会清除设备内 App 记录,但不自动清除服务器记录、你或平台保留的备份。
食品数据与健康
在线食物搜索词发送到我们的服务器;条码数字经服务器查询 USDA FoodData Central 和/或 Open Food Facts。营养来自数据库,AI 不编造热量。经授权读取你选择的 Apple 健康体重、活动和睡眠数据,仅在你请求时写入体重;只有经 AI 同意、用于助手的必要摘要可能离开设备。