AI recommendationsAI 点菜推荐AI 點菜推薦Recomendaciones de platos con IA
For eligible simple dish recommendations, ChefBear sends the request text, relevant dietary preferences and candidate menu text to OpenRouter, which routes them to TypeSafe AI’s Jev model to evaluate dish suitability. ChefBear does not attach account IDs, sign-in tokens or menu photos to these requests. Complex requests and unsuccessful evaluations use Google Cloud Vertex AI / Gemini. Content you include in request text or preferences is part of the information processed by these providers.对于适用的简单菜品推荐,ChefBear 会将请求文字、相关饮食偏好和候选菜单文字发送给 OpenRouter,再由其转发给 TypeSafe AI 的 Jev 模型评估菜品匹配度。ChefBear 不会在这些请求中附加账户 ID、登录令牌或菜单照片。复杂请求或未成功完成的评估由 Google Cloud Vertex AI / Gemini 处理。您在请求文字或偏好中填写的内容属于这些服务商处理的信息。對於適用的簡單菜式推薦,ChefBear 會將請求文字、相關飲食偏好和候選菜單文字傳送至 OpenRouter,再由其轉交 TypeSafe AI 的 Jev 模型評估菜式匹配程度。ChefBear 不會在這些請求中附加帳戶 ID、登入權杖或菜單照片。複雜請求或未能完成的評估由 Google Cloud Vertex AI / Gemini 處理。您在請求文字或偏好中填寫的內容屬於這些服務商處理的資訊。Para las recomendaciones sencillas compatibles, ChefBear envía el texto de la solicitud, las preferencias alimentarias pertinentes y el texto de los platos candidatos a OpenRouter, que los remite al modelo Jev de TypeSafe AI para evaluar su adecuación. ChefBear no adjunta identificadores de cuenta, tokens de inicio de sesión ni fotos del menú. Las solicitudes complejas o las evaluaciones fallidas se procesan con Google Cloud Vertex AI / Gemini. El contenido que incluya en la solicitud o las preferencias forma parte de la información procesada por estos proveedores.
1. Identity and Contact Details of the Controller
The data controller responsible for the processing of your personal data is:
| Controller | Awesome-Bears, Inc. doing business as ChefBear |
|---|---|
| Contact Email | contact@awesome-bears.com |
| Data Protection Officer (DPO) | contact@awesome-bears.com |
You may contact the DPO at any time regarding any questions or concerns about the processing of your personal data or the exercise of your rights under the GDPR.
2. Categories of Personal Data We Collect
We collect and process the following categories of personal data when you use ChefBear:
| Category | Specific Data | Source |
|---|---|---|
| Account & Identity Data | Email address, phone number when phone sign-in is used, display name, authentication provider identifiers (phone, Google, or Apple), user ID | Directly from you at registration / sign-in |
| Menu & Scan Data | Photographs of menus, OCR-extracted text, dish names, restaurant names | Directly from you when using the scan feature |
| Preference & Profile Data | Dietary preferences, allergies, cuisine preferences, language settings, dark mode preference | Directly from you via app settings |
| AI Interaction Data | Queries submitted to AI services, AI-generated recommendations, AI-generated dish images | Generated through your use of AI features |
| Purchase & Subscription Data | Subscription status, purchase receipts, entitlement records, transaction identifiers | From Apple App Store via RevenueCat |
| Device & Technical Data | Device model, OS version, app version, IP address, crash logs, performance metrics, security signals, request timing, and subscription-entitlement diagnostics | Automatically collected during app usage |
| Product Analytics Data | In-app usage events (for example, opening the camera, scanning a menu, seeing the paywall, starting or restoring a purchase, signing in, starring a dish, generating an AI image or a nutrition scan) with only non-sensitive category, number and yes/no properties; app version; device and OS information; and, after sign-in, your pseudonymous ChefBear account ID. Never menu photos, menu text, dish names you type, email, name, phone number, precise location or Apple ID | Collected only if you turn on Settings > Share usage analytics (off by default) |
3. Purposes of Processing and Legal Basis (Art. 6 GDPR)
We process your personal data only where we have a valid legal basis under the GDPR. The table below sets out each processing activity, its purpose, and the applicable legal basis:
| Processing Activity | Purpose | Legal Basis |
|---|---|---|
| Account Management | Creating and maintaining your user account, authenticating your identity, managing your profile and preferences | Performance of contract — Art. 6(1)(b) GDPR. Processing is necessary for providing the ChefBear service you requested. |
| Menu Scanning & Dish Recognition | Processing menu photographs via OCR and AI to extract dish names, descriptions, and translations; when you are signed in, privately backing up those photographs to your account so recognition can be completed or retried later and your menus are available on your signed-in devices | Performance of contract — Art. 6(1)(b) GDPR. This is the core service you use ChefBear for. |
| AI-Powered Recommendations | Generating personalised dish recommendations based on your dietary preferences, allergies, and cuisine interests | Performance of contract — Art. 6(1)(b) GDPR, as personalised recommendations are a core feature of the service. Legitimate interest — Art. 6(1)(f) GDPR, to improve recommendation quality and relevance. Our legitimate interest is providing a better user experience; we have assessed that this does not override your rights and freedoms given the non-sensitive nature of dietary preference data and the direct benefit to you. |
| AI Image Generation | Creating AI-generated visual representations of dishes when no photograph is available on the menu | Performance of contract — Art. 6(1)(b) GDPR. AI image generation is a feature you actively invoke within the service. |
| Crash Diagnostics & Reliability Monitoring | Collecting crash reports, performance metrics, and error logs to maintain service stability, diagnose issues, and improve app reliability | Legitimate interest — Art. 6(1)(f) GDPR. Our legitimate interest is ensuring the stability and security of our application. We have conducted a balancing test and concluded that this processing is proportionate, as only technical data is collected and it directly benefits you through a more reliable service. |
| In-App Purchases & Subscriptions | Processing subscription purchases, managing entitlements, verifying receipts, handling billing inquiries, and maintaining financial records | Performance of contract — Art. 6(1)(b) GDPR, to fulfil the subscription agreement. Legal obligation — Art. 6(1)(c) GDPR, to comply with tax, accounting, and consumer protection laws applicable in EU member states. |
| Product Analytics | Understanding how app features are used (for example, how many scans are completed or how often the paywall is shown) so we can improve ChefBear; not used for advertising, cross-app tracking or decisions about you | Consent — Art. 6(1)(a) GDPR. Off by default; collected only after you turn on Settings > Share usage analytics. You can withdraw consent at any time by turning the switch off, which stops collection and resets the analytics identifier on your device. |
Right to Object: Where we rely on legitimate interest (Art. 6(1)(f)), you have the right to object to such processing at any time. Upon receiving your objection, we will cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims. Contact contact@awesome-bears.com to exercise this right.
4. Recipients and Third-Party Processors
We share personal data with the following categories of recipients, each acting as a data processor on our behalf (unless otherwise noted). Appropriate data processing agreements (Art. 28 GDPR) are in place with each processor:
| Recipient | Purpose | Data Types Shared | Transfer Safeguards |
|---|---|---|---|
| Google Firebase (Google LLC) | Authentication, cloud database (Firestore), private cloud storage for menu photo backups and cloud menus, and crash reporting (Crashlytics) | Account-linked identifiers and authentication tokens, phone number when phone sign-in is used, backed-up menu photos, cloud menus, device info, and crash logs | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs); Google Cloud data processing terms |
| RevenueCat (RevenueCat, Inc.) | Subscription management, receipt validation, entitlement tracking | Pseudonymous app user ID linked to your ChefBear account, purchase receipts, subscription status, and transaction IDs; associated customer/account data is included in our deletion process | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs); RevenueCat DPA |
| Google Cloud Vertex AI / Gemini (Google LLC) | Menu text analysis, dish recognition, AI recommendations, AI image generation | Menu text/photographs, dish queries, dietary preferences, prompt content. No account credentials, real names, or device identifiers are transmitted. | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs); API data not used for model training (per provider policies) |
| Apple Inc. | App distribution, in-app purchase processing, Apple Sign-In | Purchase data, Apple ID tokens (when using Apple Sign-In) | EU-US Data Privacy Framework (DPF); Apple acts as independent controller for App Store purchases |
| PostHog (PostHog, Inc.) | Product analytics, only after you consent in Settings (off by default) | Product Analytics Data (see Section 2), stored in the United States (us.i.posthog.com) in a PostHog project that Awesome-Bears, Inc. uses across its products; each event is labeled with the product so ChefBear data can be separated | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) |
Technical diagnostics: Automatic diagnostics are limited to technical information necessary for core service delivery or our proportionate legitimate interests in reliability, fraud prevention, security, and subscription-entitlement operations. They exclude menu photos, OCR text, dish names, saved preferences, and assistant conversations and are not used for advertising or cross-service profiling.
Product analytics (PostHog): Product analytics is off by default. It runs only if you turn on Settings > Share usage analytics (Art. 6(1)(a) GDPR), and you can withdraw that consent at any time with the same switch; withdrawal stops collection and resets the analytics identifier on your device. Events never include menu photos, menu text, dish names you type, email, name, phone number, precise location or Apple ID, are not used for advertising or cross-app tracking, and we do not use the advertising identifier (IDFA). Deleting your account deletes your PostHog profile and its events.
We do not sell your personal data to any third party. We do not share your data with data brokers or advertising networks.
RevenueCat customer/account data is included in our deletion process. Apple acts as an independent controller for App Store transactions and may retain transaction records under its own legal and accounting obligations. Deleting your ChefBear account does not cancel an active subscription; you must cancel it in the App Store.
5. International Data Transfers
Some of our processors are located outside the European Economic Area (EEA), primarily in the United States. For each such transfer, we ensure an adequate level of data protection through one or more of the following safeguards as required by Chapter V of the GDPR:
- EU-US Data Privacy Framework (DPF): Where the recipient is certified under the EU-US Data Privacy Framework, as recognised by the European Commission's adequacy decision of 10 July 2023.
- Standard Contractual Clauses (SCCs): We use the European Commission's approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as a transfer mechanism, supplemented with additional technical and organisational measures where necessary following a Transfer Impact Assessment.
- Supplementary Measures: Where appropriate, we implement additional safeguards such as encryption in transit and at rest, pseudonymisation, and access controls.
You have the right to obtain a copy of the safeguards relating to international transfers by contacting us at contact@awesome-bears.com.
6. Data Retention Periods
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. The following table sets out our retention periods:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account & Identity Data | Until a deletion request is accepted; deletion is then irreversible. Only a minimal deletion-fulfilment and security tombstone is retained, normally for no more than 30 days. | The tombstone cannot restore the account. If a processor deletion is still awaiting verification, it is retained only until verification completes so the request can finish and data cannot be recreated; it is then deleted. |
| Menu & Scan Data | Signed-in users: menu photos are privately backed up to your account. Photos of a scan that has not been recognized are deleted 365 days after its last activity; photos and content of a recognized cloud menu are kept until 365 days after its last successful content change. You can delete a scan or cloud menu in the app whenever you are online, except while your connection comes from mainland China, and all server-side data becomes immediately unavailable and irrecoverable when account deletion is accepted. While you use ChefBear as a guest or signed out: not backed up and kept on the device until deleted; menus scanned as a guest may be backed up after you upgrade to a full account. With app versions earlier than 4.4.0, menus scanned while your service region had not been determined, while your connection came from mainland China or while signed out may also be backed up the first time you open them while signed in to an international account from outside mainland China. | Needed to complete or retry recognition and to make your menus available on your signed-in devices. Deletion is irreversible; asynchronous erasure from supporting systems may continue after access ends. |
| Preference & Profile Data | Duration of account existence; deleted upon account deletion | Necessary for personalisation while account is active |
| AI Interaction Data | Recognition and other AI requests are recorded with your account for up to 35 days: a fingerprint of the request (not its content) together with the AI result. Menu text attached to a cloud-photo recognition job is kept with that job for up to 37 days. Recognized menus are kept as cloud menus (see Menu & Scan Data). Locally cached results: until app cache is cleared. | Needed so that an interrupted recognition or other AI request can be resumed or answered again without charging your quota twice |
| Purchase & Subscription Data | RevenueCat customer/account data enters our deletion process; Apple may retain App Store transaction records for legally required periods. | Apple is an independent controller for App Store transactions. Account deletion does not cancel a subscription; cancellation must be completed in the App Store. |
| Crash Logs & Technical Diagnostics | Under Firebase's default retention, Crashlytics data is generally kept for about 90 days before removal begins from live and backup systems; removal is not necessarily immediate. | Debugging, reliability, security, fraud prevention, and subscription-entitlement operations |
| Product Analytics Data | As long as needed for product analytics while your consent is in place; deleted, together with your PostHog profile, when you delete your account. Withdrawing consent stops new collection. | Understanding feature usage to improve the app (Art. 6(1)(a)) |
| Device & Technical Data | 90 days | Security monitoring and incident response |
When retention periods expire, data is securely deleted or irreversibly anonymised.
7. Your Rights Under the GDPR
As a data subject in the European Union, you have the following rights. You may exercise any of these rights free of charge by contacting contact@awesome-bears.com. We will respond within 30 days (extendable by up to 60 additional days for complex requests, with notification).
7.1 Right of Access (Art. 15)
You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, to access that data together with the following information: the purposes of processing, the categories of data, the recipients, the retention periods, the existence of your other rights, the source of the data (if not collected from you), and the existence of automated decision-making. You may request a copy of your personal data free of charge (reasonable fees may apply for further copies).
7.2 Right to Rectification (Art. 16)
You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
7.3 Right to Erasure ("Right to Be Forgotten") (Art. 17)
You have the right to obtain the erasure of your personal data without undue delay where one of the following grounds applies:
- The data is no longer necessary for the purposes for which it was collected;
- You withdraw consent (where processing was based on consent);
- You object to the processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required for compliance with a legal obligation under EU or member state law.
This right does not apply where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for other grounds specified in Art. 17(3).
7.4 Right to Restriction of Processing (Art. 18)
You have the right to obtain restriction of processing where:
- The accuracy of the data is contested (for a period enabling us to verify accuracy);
- The processing is unlawful and you oppose erasure, requesting restriction instead;
- We no longer need the data but you need it for legal claims;
- You have objected to processing under Art. 21(1) pending verification of our legitimate grounds.
7.5 Right to Data Portability (Art. 20)
You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format (such as JSON or CSV), and to transmit that data to another controller without hindrance, where the processing is based on consent or contract and is carried out by automated means.
7.6 Right to Object (Art. 21)
You have the right to object at any time to the processing of your personal data based on our legitimate interests (Art. 6(1)(f)). We shall cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or processing is necessary for the establishment, exercise, or defence of legal claims.
7.7 Rights Related to Automated Decision-Making and Profiling (Art. 22)
See Section 8 below for full details on automated decision-making and your associated rights.
7.8 Right to Withdraw Consent (Art. 7(3))
Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw consent by contacting us at contact@awesome-bears.com or by adjusting your settings within the app; for product analytics, turn off Settings > Share usage analytics.
7.9 Right to Lodge a Complaint (Art. 77)
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. A list of supervisory authorities is available at the European Data Protection Board website.
How to Exercise Your Rights: Send your request to contact@awesome-bears.com. We may need to verify your identity before processing your request. We will not charge a fee unless requests are manifestly unfounded or excessive. If we refuse a request, we will inform you of the reasons and your right to lodge a complaint with a supervisory authority.
8. Automated Decision-Making and Profiling (Art. 22)
ChefBear uses artificial intelligence to provide the following automated features:
- AI Dish Recommendations: Based on your stated dietary preferences, allergies, and cuisine interests, our AI algorithms analyse menu items and generate personalised dish recommendations. This constitutes profiling as defined in Art. 4(4) GDPR.
- AI Dish Recognition: Our AI models analyse photographs of menus to identify and classify dishes.
- AI Image Generation: When dish photographs are unavailable, AI generates representative images of dishes.
8.1 Nature and Significance
The AI-powered recommendations are designed to assist and enhance your dining experience. They do not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1). The recommendations are suggestions only — you always retain full autonomy over your dining choices.
8.2 Logic Involved
The recommendation system analyses your stated preferences (dietary restrictions, allergies, favourite cuisines) against menu item attributes (ingredients, preparation style, cuisine type) to rank dishes by predicted relevance. No special categories of personal data (Art. 9) are used for profiling purposes.
8.3 Your Rights Regarding Automated Processing
Even though our automated processing does not fall within the scope of Art. 22(1), we voluntarily offer you the following rights as a matter of best practice:
- Right to human intervention: You may request that a human reviews any AI-generated recommendation or decision by contacting contact@awesome-bears.com.
- Right to express your point of view: You can provide feedback on recommendations directly within the app or by emailing us.
- Right to contest the outcome: If you believe an AI recommendation is incorrect or inappropriate, you may contact us to request a review.
- Right to opt out: You may disable personalised recommendations in your app settings and use ChefBear in a non-personalised mode.
9. Cookies, Tracking, and Similar Technologies
ChefBear is a native mobile application and does not use browser cookies. However, the following tracking-related technologies may be in use:
| Technology | Purpose | Legal Basis |
|---|---|---|
| Firebase Crashlytics (device identifiers) | Crash detection and debugging | Legitimate interest (Art. 6(1)(f)) |
| PostHog (pseudonymous analytics identifier and usage events) | Product analytics to improve the app | Consent (Art. 6(1)(a)); off until you turn on Settings > Share usage analytics |
| Local storage / device cache | Caching scan results, preferences, and AI responses for performance | Strictly necessary for service delivery |
We do not use advertising trackers, cross-app tracking, or fingerprinting technologies. We do not participate in any advertising ID programmes.
For our website (seeplate.app), we may use essential cookies only. If we introduce non-essential cookies in the future, we will implement a compliant cookie consent mechanism in accordance with the ePrivacy Directive (2002/58/EC) and applicable member state law.
10. Children's Privacy
ChefBear is not directed at children. We do not knowingly collect personal data from children under the age of 16 years (or such lower age as provided by the applicable EU member state under Art. 8 GDPR, but in no case below 13 years).
If we become aware that we have collected personal data from a child below the applicable age without valid parental consent, we will take immediate steps to delete that data. If you believe that a child has provided us with personal data, please contact us at contact@awesome-bears.com.
11. Data Protection by Design and by Default (Art. 25)
In accordance with Art. 25 GDPR, ChefBear implements the following principles:
- Data minimisation: We collect only the data strictly necessary for each processing purpose. AI queries are kept only as far as needed to deliver them and to resume them after an interruption: a fingerprint of each request (not its content) and the AI result are kept with your account for up to 35 days so a request can be answered again without charging your quota twice, and menu text attached to a cloud-photo recognition job is kept with that job for up to 37 days. Menu photos are backed up to your account only so that recognition can be completed or retried later and your menus are available on your signed-in devices (Art. 6(1)(b)); from app version 4.4.0, location and other EXIF metadata are removed before photos are uploaded (earlier app versions may upload them with this metadata), the backup is used for no other purpose, and photos of a scan that is never recognized are deleted 365 days after its last activity. Photos are not backed up while you use ChefBear as a guest or signed out; menus scanned as a guest may be backed up after you upgrade to a full account, and with app versions earlier than 4.4.0, menus scanned while signed out, while your service region had not been determined or while your connection came from mainland China may be backed up the first time you open them while signed in to an international account from outside mainland China.
- Pseudonymisation: Where possible, data is pseudonymised. AI providers receive only the minimum data required (menu text, dish queries) and never receive your account credentials or identity.
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest. Firebase and our infrastructure employ industry-standard encryption.
- Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis.
- Privacy by default: The most privacy-protective settings are applied by default. Product analytics is off unless you turn it on. Features that involve additional data processing (e.g., personalised recommendations) can be disabled by the user.
- Regular review: We periodically review and update our technical and organisational measures to ensure ongoing compliance.
12. Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33 GDPR);
- Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms (Art. 34 GDPR), describing the nature of the breach, the likely consequences, and the measures taken or proposed to address the breach.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes through:
- An in-app notification;
- An updated version posted at this URL with a revised effective date;
- Email notification (where you have provided an email address and the change is significant).
We encourage you to review this Privacy Policy periodically. Continued use of ChefBear after changes become effective constitutes your awareness of the updated Privacy Policy. Where required by law, we will seek your renewed consent before applying material changes to data processing.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:
| General Privacy Inquiries | contact@awesome-bears.com |
|---|---|
| Data Protection Officer | contact@awesome-bears.com |
| Data Subject Rights Requests | contact@awesome-bears.com |
Effective Date: This Privacy Policy is effective as of 5 October 2026.