Last updated August 6, 2026
This policy explains what personal data Bitewise collects, why, and what rights you and your clients have over it. It is written for both practitioners (our direct customers) and their clients (whose records practitioners keep in Bitewise).
Before launch
This is a working draft, not a lawyer-reviewed final policy. It describes the product accurately as of the date above, but should get a proper data-protection review before anyone relies on it in a dispute.
Bitewise is operated by [Bitewise's operating entity — legal name, form, country and registered address to confirm before launch]. For data we control ourselves — your account, your practice's billing and settings — we are the data controller. For the client records you keep in Bitewise, we are a processor acting on your instructions; see Section 2.
If you are a practitioner: you control your clients' data, and Bitewise processes it on your behalf under a standard controller–processor arrangement. Your own obligations to your clients — a lawful basis, transparency, honouring their rights — are yours to meet; Bitewise gives you the tools (export, deletion, an audit log) to do so.
If you are a client of a practitioner who uses Bitewise: your practitioner is the controller of your data. Direct your own access, correction, or deletion requests to them in the first instance — they hold the record, and Bitewise carries out their instructions about it.
Account data: your name, email, phone, professional details, and practice information. Client data: whatever a practitioner records about their client — contact details, assessments, meal plans, notes, and documents — entered by the practitioner, not by us. Usage data: product analytics (see Section 7) and technical logs needed to run and secure the service.
A client's dietary and health information can be special-category data under GDPR Article 9. We process it only because the practitioner's client has, in the practitioner's own records, given the basis the practitioner relies on (typically explicit consent or necessity for healthcare provision) — Bitewise does not independently collect or use this data for its own purposes.
We process your account data to perform our contract with you (running the service you signed up for), for our legitimate interest in keeping Bitewise secure and improving it, and, where you have opted in, to send product updates. We process client data solely as your processor, on the legal basis you as the controller have established.
To provide the features you use, to secure and maintain the service, to respond when you contact us, and — for account data only, never client data — to understand how the product is used so we can improve it. We do not sell personal data, and we do not use client data to train any model or feature outside your own practice.
Database and authentication: Supabase, hosted in Frankfurt, Germany. Hosting: Vercel. Transactional email: Resend. Error monitoring and product analytics: Sentry and PostHog, both on EU-region hosting. Payments, once you subscribe: Stripe. Each acts under a data-processing agreement and only within the instructions this policy describes.
Our primary data storage is in the EU. Where a subprocessor listed in Section 7 requires a transfer outside the EU/EEA for a specific function, we rely on that provider's Standard Contractual Clauses or an equivalent safeguard recognised under GDPR.
Account data is kept for as long as your account is open, and for a limited period after closure to meet legal and accounting obligations. Client data is kept for as long as the practitioner's own record-keeping requires, and is deleted or exported at the practitioner's instruction — practitioners can permanently erase a client's record at any time.
We use two kinds of cookie: one that keeps you signed in (strictly necessary — the product cannot work without it) and one that remembers your chosen language. Neither is an advertising or third-party tracking cookie, and neither is set until you use the product.
Subject to who controls your data (Section 2), you can ask to access, correct, delete, restrict, or receive a copy of your personal data, and you can object to certain processing. If you are a practitioner, most of this is self-service inside Settings. If you are a client, start with your practitioner; if we hold data as controller and you are not satisfied, you may also complain to your local data-protection supervisory authority.
Every practice's data is isolated at the database level: row-level security keyed to the practice, so one practice's records are never reachable from another's account, even by accident. Data is encrypted in transit. Access to production data by our own team is limited and logged.
Bitewise accounts are for practitioners acting in a professional capacity, not for children. A client's record may belong to a minor; in that case the practitioner is responsible for the appropriate legal basis, exactly as they would be for any other record they keep about that minor outside Bitewise.
We may update this policy as the product or the law changes. For a material change, we will tell you inside the product or by email before it takes effect.
Questions about this policy, or a rights request: [privacy contact email to confirm].