Privacy Policy

Last updated August 6, 2026

This policy explains what personal data Bitewise collects, why, and what rights you and your clients have over it. It is written for both practitioners (our direct customers) and their clients (whose records practitioners keep in Bitewise).

Before launch

This is a working draft, not a lawyer-reviewed final policy. It describes the product accurately as of the date above, but should get a proper data-protection review before anyone relies on it in a dispute.

1. Who we are

Bitewise is operated by [Bitewise's operating entity — legal name, form, country and registered address to confirm before launch]. For data we control ourselves — your account, your practice's billing and settings — we are the data controller. For the client records you keep in Bitewise, we are a processor acting on your instructions; see Section 2.

2. Two different roles

If you are a practitioner: you control your clients' data, and Bitewise processes it on your behalf under a standard controller–processor arrangement. Your own obligations to your clients — a lawful basis, transparency, honouring their rights — are yours to meet; Bitewise gives you the tools (export, deletion, an audit log) to do so.

If you are a client of a practitioner who uses Bitewise: your practitioner is the controller of your data. Direct your own access, correction, or deletion requests to them in the first instance — they hold the record, and Bitewise carries out their instructions about it.

3. What we collect

Account data: your name, email, phone, professional details, and practice information. Client data: whatever a practitioner records about their client — contact details, assessments, meal plans, notes, and documents — entered by the practitioner, not by us. Usage data: product analytics (see Section 7) and technical logs needed to run and secure the service.

4. Health and nutrition data

A client's dietary and health information can be special-category data under GDPR Article 9. We process it only because the practitioner's client has, in the practitioner's own records, given the basis the practitioner relies on (typically explicit consent or necessity for healthcare provision) — Bitewise does not independently collect or use this data for its own purposes.

5. Our legal basis

We process your account data to perform our contract with you (running the service you signed up for), for our legitimate interest in keeping Bitewise secure and improving it, and, where you have opted in, to send product updates. We process client data solely as your processor, on the legal basis you as the controller have established.

6. How we use it

To provide the features you use, to secure and maintain the service, to respond when you contact us, and — for account data only, never client data — to understand how the product is used so we can improve it. We do not sell personal data, and we do not use client data to train any model or feature outside your own practice.

7. Who processes data on our behalf

Database and authentication: Supabase, hosted in Frankfurt, Germany. Hosting: Vercel. Transactional email: Resend. Error monitoring and product analytics: Sentry and PostHog, both on EU-region hosting. Payments, once you subscribe: Stripe. Each acts under a data-processing agreement and only within the instructions this policy describes.

8. International transfers

Our primary data storage is in the EU. Where a subprocessor listed in Section 7 requires a transfer outside the EU/EEA for a specific function, we rely on that provider's Standard Contractual Clauses or an equivalent safeguard recognised under GDPR.

9. How long we keep data

Account data is kept for as long as your account is open, and for a limited period after closure to meet legal and accounting obligations. Client data is kept for as long as the practitioner's own record-keeping requires, and is deleted or exported at the practitioner's instruction — practitioners can permanently erase a client's record at any time.

10. Cookies

We use two kinds of cookie: one that keeps you signed in (strictly necessary — the product cannot work without it) and one that remembers your chosen language. Neither is an advertising or third-party tracking cookie, and neither is set until you use the product.

11. Your rights

Subject to who controls your data (Section 2), you can ask to access, correct, delete, restrict, or receive a copy of your personal data, and you can object to certain processing. If you are a practitioner, most of this is self-service inside Settings. If you are a client, start with your practitioner; if we hold data as controller and you are not satisfied, you may also complain to your local data-protection supervisory authority.

12. How we protect data

Every practice's data is isolated at the database level: row-level security keyed to the practice, so one practice's records are never reachable from another's account, even by accident. Data is encrypted in transit. Access to production data by our own team is limited and logged.

13. Children

Bitewise accounts are for practitioners acting in a professional capacity, not for children. A client's record may belong to a minor; in that case the practitioner is responsible for the appropriate legal basis, exactly as they would be for any other record they keep about that minor outside Bitewise.

14. Changes to this policy

We may update this policy as the product or the law changes. For a material change, we will tell you inside the product or by email before it takes effect.

15. Contact

Questions about this policy, or a rights request: [privacy contact email to confirm].