AI recommendationsAI 点菜推荐AI 點菜推薦Recomendaciones de platos con IA
For eligible simple dish recommendations, ChefBear sends the request text, relevant dietary preferences and candidate menu text to OpenRouter, which routes them to TypeSafe AI’s Jev model to evaluate dish suitability. ChefBear does not attach account IDs, sign-in tokens or menu photos to these requests. Complex requests and unsuccessful evaluations use Google Cloud Vertex AI / Gemini. Content you include in request text or preferences is part of the information processed by these providers.对于适用的简单菜品推荐,ChefBear 会将请求文字、相关饮食偏好和候选菜单文字发送给 OpenRouter,再由其转发给 TypeSafe AI 的 Jev 模型评估菜品匹配度。ChefBear 不会在这些请求中附加账户 ID、登录令牌或菜单照片。复杂请求或未成功完成的评估由 Google Cloud Vertex AI / Gemini 处理。您在请求文字或偏好中填写的内容属于这些服务商处理的信息。對於適用的簡單菜式推薦,ChefBear 會將請求文字、相關飲食偏好和候選菜單文字傳送至 OpenRouter,再由其轉交 TypeSafe AI 的 Jev 模型評估菜式匹配程度。ChefBear 不會在這些請求中附加帳戶 ID、登入權杖或菜單照片。複雜請求或未能完成的評估由 Google Cloud Vertex AI / Gemini 處理。您在請求文字或偏好中填寫的內容屬於這些服務商處理的資訊。Para las recomendaciones sencillas compatibles, ChefBear envía el texto de la solicitud, las preferencias alimentarias pertinentes y el texto de los platos candidatos a OpenRouter, que los remite al modelo Jev de TypeSafe AI para evaluar su adecuación. ChefBear no adjunta identificadores de cuenta, tokens de inicio de sesión ni fotos del menú. Las solicitudes complejas o las evaluaciones fallidas se procesan con Google Cloud Vertex AI / Gemini. El contenido que incluya en la solicitud o las preferencias forma parte de la información procesada por estos proveedores.
1. Introduction
ChefBear ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the ChefBear mobile application and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
Data Controller: Awesome-Bears, Inc. doing business as ChefBear
Contact: contact@awesome-bears.com
2. Data We Collect
We collect the following categories of personal data:
| Category | Data Collected | Collection Method |
|---|---|---|
| Account | Email address, phone number (when you choose phone sign-in), display name, profile photo (optional), authentication tokens | User-provided at registration or via phone or third-party sign-in (Apple, Google) |
| Device | Device model, operating system version, unique device identifiers, language & locale settings | Automatically collected |
| Camera | Menu images captured for scanning. For signed-in international accounts, photos are privately backed up to your account so recognition can be completed or retried later (from app version 4.4.0, location and other EXIF metadata are removed before upload); otherwise they stay on your device (see Section 7 and “Menu photos, cloud menus and sharing” below) | User-initiated camera capture |
| Purchase | Subscription status, purchase receipts, transaction IDs (payment details are handled entirely by the Apple App Store) | Via Apple App Store APIs |
| Crash & Diagnostics | Crash logs, performance metrics, error reports, stack traces | Automatically collected via crash reporting SDKs |
| Product Analytics | In-app usage events (for example, opening the camera, scanning a menu, seeing the paywall, starting or restoring a purchase, signing in, starring a dish, generating an AI image or a nutrition scan) with only non-sensitive category, number and yes/no properties; app version; device and operating system information; and, after sign-in, your pseudonymous ChefBear account ID. Never menu photos, menu text, dish names you type, email, name, phone number, precise location or Apple ID | Automatically collected via PostHog, subject to your choice in Settings > Share usage analytics (see Section 6); never collected in the mainland China service region |
| AI Interaction | Menu scan inputs, AI-generated dish descriptions and images, user feedback on AI results, prompt metadata | Generated during AI feature usage |
3. How We Use Your Data
We use the collected data for the following purposes:
| Purpose | Data Categories Used |
|---|---|
| Provide and maintain the Service | Account, Device, Camera, AI Interaction |
| Process menu scans and generate AI dish descriptions & images | Camera, AI Interaction, Device |
| Privately back up menu photos to your account so recognition can be completed or retried later and your menus are available on your signed-in devices | Camera, Account |
| Personalize your experience and recommendations | AI Interaction, Account |
| Process and manage subscriptions | Account, Purchase |
| Improve and optimize the Service | Crash & Diagnostics, AI Interaction, Product Analytics |
| Communicate with you (support, updates, announcements) | Account |
| Ensure security and prevent fraud | Device, Account, Crash & Diagnostics |
| Comply with legal obligations | All categories as required |
4. Legal Basis for Processing
Depending on your jurisdiction, we process your personal data on one or more of the following legal bases:
- Consent: Where you have given explicit consent (e.g., camera access, or product analytics in regions where it is off by default). You may withdraw consent at any time.
- Contract: Processing necessary to perform our contract with you (e.g., providing the Service, managing your subscription).
- Legitimate Interest: Processing necessary for our legitimate interests (e.g., improving the Service, including product analytics where it is on by default and you can turn it off, security, fraud prevention), provided these interests do not override your fundamental rights.
- Legal Obligation: Processing necessary to comply with applicable laws and regulations.
5. AI & Automated Processing
ChefBear uses artificial intelligence and machine learning to provide core features including menu text recognition, dish identification, description generation, and AI-generated illustrative images of dishes.
- Menu images you capture are sent to our AI processing services to extract text, identify dishes, and generate descriptions.
- AI-generated images are illustrative representations and are not photographs of actual dishes. They are clearly labeled as AI-generated within the app.
- No profiling for legal effects: We do not use automated decision-making that produces legal or similarly significant effects on you.
- AI training: We may use aggregated, de-identified interaction data to improve our AI models. Individual menu images are not used to train third-party AI models without your explicit consent.
- You have the right not to be subject to decisions based solely on automated processing. Contact us if you wish to request human review of any automated decision.
6. Third-Party Services
We use the following third-party services that may receive your data:
| Service | Provider | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|---|
| Firebase Authentication | Google LLC | Email, phone number when phone sign-in is used, account-linked authentication identifiers and tokens | User authentication | Link |
| Firebase Crashlytics | Google LLC | Crash logs, device info | Crash reporting & stability | Link |
| RevenueCat | RevenueCat, Inc. | Pseudonymous app user ID linked to your ChefBear account, purchase receipts, and subscription status; associated customer/account data is included in our deletion process | Subscription management and deletion fulfilment | Link |
| PostHog | PostHog, Inc. (United States) | Product Analytics data described in Section 2 | Product analytics; not used for advertising or cross-app tracking | Link |
| Google Cloud Vertex AI / Gemini | Google LLC | Menu images and text, dish queries, dietary preferences needed for a request, and image-generation prompts; no account credentials are sent | AI dish recognition & image generation | Link |
| Google Cloud Storage & Cloud Firestore | Google LLC | Backed-up menu photos, cloud menus and generated dish images of signed-in international accounts | Private storage for photo backups and cloud menus | Link |
| Apple App Store | Apple Inc. | Purchase & subscription data | Payment processing | Link |
These third-party services have their own privacy policies governing how they handle your data. We encourage you to review them.
Technical diagnostics: Automatic diagnostics are limited to the technical crash, reliability, security, fraud-prevention, and subscription-entitlement information described above. They do not include menu photos, OCR text, dish names, saved preferences, or assistant conversations and are not used for advertising or cross-service profiling.
Product analytics (PostHog): The ChefBear app sends the Product Analytics data described in Section 2 to PostHog, Inc. in the United States (us.i.posthog.com), into a PostHog project that Awesome-Bears, Inc. uses across its products; each event is labeled with the product so ChefBear data can be separated. We use it only to understand how features are used and to improve the Service. It is not used for advertising or cross-app tracking, and we do not use the advertising identifier (IDFA). In most regions product analytics is on by default and you can turn it off at any time in Settings > Share usage analytics. In Canada, the EU/EEA, the United Kingdom, Switzerland and South Korea, or when your device region cannot be determined, it is off unless you turn that switch on. It is never collected in the mainland China service region or while ChefBear has not yet determined your service region. Turning the switch off stops collection and resets the analytics identifier on your device; deleting your account deletes your PostHog profile and its events.
RevenueCat customer/account data is included in our deletion process. Apple acts as an independent controller for App Store transactions and may retain transaction records under its own legal and accounting obligations. Deleting your ChefBear account does not cancel an active subscription; you must cancel it in the App Store.
7. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
- Account data and content: Retained while your account is active. Once a deletion request is accepted, deletion is irreversible and the account and its content are immediately unavailable and unrecoverable. Only a minimal deletion-fulfilment and security tombstone is retained, normally for no more than 30 days; it cannot restore the account. If a processor deletion is still awaiting verification, the tombstone is retained only until verification completes so the request can finish and data cannot be recreated; it is then deleted.
- Camera/menu images: For signed-in international accounts, menu photos are privately backed up to your account: right after you tap Recognize when backup is available for your account, otherwise after the menu is recognized. Photos of a scan that has not been recognized are deleted 365 days after its last activity; photos of a recognized menu are kept until 365 days after the menu's last successful content change. You can delete them in the app whenever you are online, except while your connection comes from mainland China. In the mainland China service region, photos are kept only on your device; while your service region has not been determined, as a guest, while signed out or while your connection comes from mainland China, photos are not backed up. Menus scanned as a guest may be backed up after you upgrade to a full account; with app versions earlier than 4.4.0, menus scanned while your service region had not been determined, while your connection came from mainland China or while signed out may also be backed up the first time you open them while signed in to an international account from outside mainland China (see “When photos are not backed up” below). Cached images on-device are managed by the app and can be cleared at any time.
- Product analytics data: Kept in PostHog for as long as needed for product analytics, and deleted, together with your PostHog profile, when you delete your account.
- Crash logs: Under Firebase's default retention, Crashlytics data is generally kept for about 90 days before removal begins from live and backup systems; removal is not necessarily immediate.
- Purchase records: RevenueCat customer/account data enters our deletion process. Apple may retain App Store transaction records as an independent controller for periods required by law; deleting your account does not cancel the subscription.
- AI interaction data: Recognition and other AI requests are recorded with your account for up to 35 days (a fingerprint of the request, not its content, together with the AI result) so an interrupted request can be resumed or answered again without charging your quota twice; menu text attached to a cloud-photo recognition job is kept with that job for up to 37 days. Prompt/response pairs may be retained in de-identified form for up to 12 months for quality improvement. Images sent only for AI processing are deleted within 30 days of processing; menu photos backed up to your account are kept as described under Camera/menu images.
When data is no longer needed, it is securely deleted or irreversibly anonymized.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States and other jurisdictions where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
Where required by applicable law, we ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) approved by relevant authorities
- Adequacy decisions by relevant data protection authorities
- Binding Corporate Rules where applicable
- Your explicit consent where other safeguards are not available
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights for all users to the maximum extent practicable:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete personal data.
- Deletion: Request that we delete your personal data, subject to legal retention requirements.
- Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
- Object: Object to the processing of your personal data for certain purposes, including direct marketing.
- Restriction: Request that we restrict the processing of your personal data under certain circumstances.
- Withdraw Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.
- Automated Decisions: Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you.
- Complaint: Lodge a complaint with your local data protection authority if you believe your rights have been violated.
To exercise any of these rights, contact us at contact@awesome-bears.com. We will respond within 30 days (or sooner if required by applicable law).
10. Children's Privacy
ChefBear is not intended for children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at contact@awesome-bears.com, and we will take steps to delete such information promptly.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication for internal systems
- Regular security assessments and monitoring
- Secure development practices
While we strive to protect your personal data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any breach in accordance with applicable laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the app or by other appropriate means before the changes take effect. The "Effective Date" at the top of this policy indicates when it was last revised.
Update effective October 5, 2026: backup right after you tap Recognize, and with it the 365-day deletion period for photos of scans that have not been recognized, applies to your account only after the ChefBear app has shown you an in-app notice about this change. Until then, your menu photos are not backed up before the menu has been recognized.
Your continued use of the Service after any changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ChefBear Privacy Team
Email: contact@awesome-bears.com