AI recommendationsAI 点菜推荐AI 點菜推薦Recomendaciones de platos con IA
For eligible simple dish recommendations, ChefBear sends the request text, relevant dietary preferences and candidate menu text to OpenRouter, which routes them to TypeSafe AI’s Jev model to evaluate dish suitability. ChefBear does not attach account IDs, sign-in tokens or menu photos to these requests. Complex requests and unsuccessful evaluations use Google Cloud Vertex AI / Gemini. Content you include in request text or preferences is part of the information processed by these providers.对于适用的简单菜品推荐,ChefBear 会将请求文字、相关饮食偏好和候选菜单文字发送给 OpenRouter,再由其转发给 TypeSafe AI 的 Jev 模型评估菜品匹配度。ChefBear 不会在这些请求中附加账户 ID、登录令牌或菜单照片。复杂请求或未成功完成的评估由 Google Cloud Vertex AI / Gemini 处理。您在请求文字或偏好中填写的内容属于这些服务商处理的信息。對於適用的簡單菜式推薦,ChefBear 會將請求文字、相關飲食偏好和候選菜單文字傳送至 OpenRouter,再由其轉交 TypeSafe AI 的 Jev 模型評估菜式匹配程度。ChefBear 不會在這些請求中附加帳戶 ID、登入權杖或菜單照片。複雜請求或未能完成的評估由 Google Cloud Vertex AI / Gemini 處理。您在請求文字或偏好中填寫的內容屬於這些服務商處理的資訊。Para las recomendaciones sencillas compatibles, ChefBear envía el texto de la solicitud, las preferencias alimentarias pertinentes y el texto de los platos candidatos a OpenRouter, que los remite al modelo Jev de TypeSafe AI para evaluar su adecuación. ChefBear no adjunta identificadores de cuenta, tokens de inicio de sesión ni fotos del menú. Las solicitudes complejas o las evaluaciones fallidas se procesan con Google Cloud Vertex AI / Gemini. El contenido que incluya en la solicitud o las preferencias forma parte de la información procesada por estos proveedores.
1. Introduction
This Privacy Policy describes how ChefBear ("we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in connection with the ChefBear mobile application (the "App") and related services, and explains your rights and choices regarding your personal information. This policy applies to users located in the United States and is intended to comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), and other applicable U.S. state privacy laws.
By using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
Business and data controller: Awesome-Bears, Inc. doing business as ChefBear.
2. Categories of Personal Information Collected
The following table describes the categories of personal information we have collected from consumers in the preceding twelve (12) months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Email address, phone number when phone sign-in is used, unique user ID, Apple ID token, Google account ID, device identifiers | Yes |
| B. Personal Information (Cal. Civ. Code § 1798.80(e)) | Name (if provided during account creation), email address, phone number when phone sign-in is used | Yes |
| C. Protected Classification Characteristics | None | No |
| D. Commercial Information | Subscription purchase history, in-app purchase records managed by Apple App Store and RevenueCat | Yes |
| E. Biometric Information | None | No |
| F. Internet or Network Activity | Crash reports, API security and error logs, request timing, coarse network quality, and subscription-entitlement diagnostics; in-app usage events for product analytics unless you turn it off (see Section 5) | Yes |
| G. Geolocation Data | Approximate location (if granted by user, for restaurant context only). Menu photos uploaded by app versions earlier than 4.4.0 may contain precise location metadata (EXIF) that your camera embedded; ChefBear does not read, extract or use it, and you can delete these photos in the app (see Sections 8 and 11) | Optional |
| H. Sensory Data | Camera images of restaurant menus (processed on your device or for AI analysis; when you are signed in, privately backed up to your account; from app version 4.4.0, location and other EXIF metadata are removed before upload; earlier app versions may upload photos with this metadata, see Category G) | Yes |
| I. Professional or Employment Information | None | No |
| J. Non-Public Education Information | None | No |
| K. Inferences | Dietary preferences, cuisine preferences, allergen profiles (derived from user-provided settings) | Yes |
| L. Sensitive Personal Information | Camera-captured menu images (sensory data processed for core functionality); dietary/allergen preferences you voluntarily provide | Yes |
3. Categories of Sources of Personal Information
We collect personal information from the following categories of sources:
- Directly from you: Information you provide when creating an account, setting preferences, capturing menu images, or contacting support.
- Automatically from the App: Device technical information and the minimum crash, reliability, security, fraud-prevention, and subscription-entitlement diagnostics needed to operate the App, and, unless you turn it off, in-app usage events for product analytics.
- Third-party authentication providers: Firebase Authentication (phone, Google, Apple Sign-In, email/password) provides account-linked identifiers, authentication tokens, and your phone number when you choose phone sign-in.
- Third-party service providers: RevenueCat provides subscription and purchase status; Firebase Crashlytics provides crash diagnostics.
4. Business and Commercial Purposes for Collecting Personal Information
We collect and use personal information for the following business and commercial purposes:
- Providing the Service: To operate the App's core features, including menu scanning, AI-powered dish recognition, private backup of your menu photos so recognition can be completed or retried later, personalized recommendations, and AI-generated dish images.
- Account management: To create and manage your user account, authenticate your identity, and maintain your preferences.
- Subscription management: To process and manage subscriptions, verify entitlements, and facilitate billing through the Apple App Store and RevenueCat.
- Maintaining the Service: To diagnose technical issues, fix bugs, and improve App reliability and performance using technical diagnostics.
- Product analytics: To understand how App features are used (for example, how many scans are completed or how often the paywall is shown) so we can improve the App. You can turn this off at any time in Settings > Share usage analytics.
- Safety and security: To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity.
- Communications: To respond to your inquiries, send service-related notices, and provide customer support.
- Legal compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
5. Categories of Third Parties with Whom We Share Personal Information
We may disclose personal information to the following categories of third parties for the business purposes described above:
- Firebase Authentication (Google LLC): Receives account-linked identifiers, authentication tokens, and your phone number when you choose phone sign-in to provide sign-in and account management services.
- Firebase Crashlytics (Google LLC): Receives crash logs, device information, and technical reliability data to diagnose and fix application errors. Under Firebase's default retention, Crashlytics data is generally kept for about 90 days before removal begins from live and backup systems; removal is not necessarily immediate.
- RevenueCat, Inc.: Receives a pseudonymous app user ID linked to your ChefBear account and purchase/subscription data to manage subscription entitlements and billing status. Associated customer/account data is included in our deletion process.
- Google Cloud Vertex AI / Gemini (Google LLC): Receives menu text, dish names, user-specified dietary preferences, and menu images solely for the purpose of generating dish information, translations, recommendations, and AI-generated dish images. We do not send your account credentials, name, or device identifiers to AI providers.
- Google Cloud Storage and Cloud Firestore (Google LLC): Store the menu photos privately backed up to your account, your cloud menus, and generated dish images when you are signed in, solely to provide the Service to you.
- Apple Inc. (App Store): Processes subscription and in-app purchase transactions.
- PostHog, Inc. (United States): Receives in-app usage events with only non-sensitive category, number and yes/no properties, app version, device and operating system information, and, after sign-in, your pseudonymous ChefBear account ID, as our service provider for product analytics.
Technical diagnostics: Automatic diagnostics are limited to technical crash, reliability, security, fraud-prevention, and subscription-entitlement information. They exclude menu photos, OCR text, dish names, saved preferences, and assistant conversations and are not used for advertising or cross-context behavioral profiling.
Product analytics (PostHog): The App sends in-app usage events (for example, opening the camera, scanning a menu, seeing the paywall, starting or restoring a purchase, signing in, starring a dish, generating an AI image or a nutrition scan) to PostHog, Inc. in the United States (us.i.posthog.com), into a PostHog project that Awesome-Bears, Inc. uses across its products; each event is labeled with the product so ChefBear data can be separated. Events never include menu photos, menu text, dish names you type, email, name, phone number, precise location or Apple ID. We use them only to improve the App, not for advertising, cross-context behavioral advertising or cross-app tracking, and we do not use the advertising identifier (IDFA). Product analytics is on by default; you can turn it off at any time in Settings > Share usage analytics. Turning it off stops collection and resets the analytics identifier on your device; deleting your account deletes your PostHog profile and its events.
We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising.
RevenueCat customer/account data is included in our deletion process. Apple acts as an independent controller for App Store transactions and may retain transaction records under its own legal and accounting obligations. Deleting your ChefBear account does not cancel an active subscription; you must cancel it in the App Store.
6. We Do Not Sell or Share Your Personal Information
ChefBear does not sell your personal information. We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We also do not "share" your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
Because we do not sell or share personal information, we are not required to offer an opt-out mechanism for the sale or sharing of personal information. However, if our practices change in the future, we will update this policy and provide appropriate notice and opt-out mechanisms.
7. Your California Privacy Rights
If you are a California resident, you have the following rights under the CCPA/CPRA. You may exercise these rights free of charge, and we will not discriminate against you for doing so:
Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which personal information is collected, the business or commercial purposes for collecting personal information, and the categories of third parties with whom we share personal information.
Right to Delete
You have the right to request that we delete personal information we have collected from you, subject to certain exceptions provided by law (e.g., where retention is necessary to complete a transaction, detect security incidents, comply with legal obligations, or for certain internal uses compatible with the context in which the information was provided).
Right to Correct
You have the right to request that we correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes for processing it.
Right to Opt-Out of Sale/Sharing
As stated above, we do not sell or share your personal information. Should this change, you will have the right to opt out of such sale or sharing.
Right to Limit Use of Sensitive Personal Information
You have the right to limit our use of sensitive personal information to purposes necessary to provide the services you request. The sensitive personal information we collect (camera-captured menu images, any location metadata embedded in photos uploaded by app versions earlier than 4.4.0, and dietary preferences) is used solely for the App's core functionality and is not used for purposes that would require offering this right under the CCPA/CPRA. Nevertheless, you may contact us to make such a request.
How to Exercise Your Rights
To submit a verifiable consumer request to know, delete, or correct your personal information, please contact us at:
- Business: Awesome-Bears, Inc. doing business as ChefBear
- Email: contact@awesome-bears.com
We will verify your identity before fulfilling your request by matching information you provide with information we have on file. We will respond to your request within forty-five (45) days. If we need more time, we will inform you of the reason and the extension period (up to an additional 45 days). You may designate an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization.
8. Sensitive Personal Information
Under the CCPA/CPRA, certain types of personal information are considered "sensitive." The sensitive personal information we process includes:
- Camera data (sensory data): When you use the menu scanning feature, the App accesses your device camera to capture images of restaurant menus. These images are processed to extract menu text and are transmitted to our AI service providers solely for the purpose of dish recognition, translation, and recommendation. When you are signed in, menu photos are also privately backed up to your account so recognition can be completed or retried later. Starting with app version 4.4.0, location and other EXIF metadata are removed before upload; earlier app versions may upload photos with this metadata. Backed-up photos are kept as described in Section 11, and you can delete them in the app whenever you are online, except while your connection comes from mainland China. While you use the App as a guest or signed out, photos are not backed up; menus scanned as a guest may be backed up after you upgrade to a full account. With app versions earlier than 4.4.0, menus scanned while your service region had not been determined, while your connection came from mainland China or while signed out may also be backed up the first time you open them while signed in to an international account from outside mainland China. Temporary processing may occur in the AI provider's infrastructure subject to their data handling policies.
- Precise geolocation (embedded in older photo uploads): Menu photos uploaded by app versions earlier than 4.4.0 may contain precise location metadata (EXIF) that your camera embedded, for example in photos chosen from your photo library or shared into the App. ChefBear does not read, extract or use this metadata, and does not use it to infer characteristics about you; it stays inside the stored photo file until the photo is deleted. Starting with app version 4.4.0, it is removed before upload. You can delete these photos in the app as described in Section 11.
- Dietary/allergen preferences: You may voluntarily provide dietary restrictions and allergen information. This is used solely to personalize dish recommendations and is stored in your user profile.
We use sensitive personal information only as necessary to provide the services you request and do not use it for purposes that would require offering you the right to limit its use under the CCPA/CPRA.
9. Biometric Information
We do not collect biometric identifiers or biometric information. The App does not use facial recognition, fingerprint scanning, voiceprint analysis, or any other biometric technology. While the App uses your device camera to capture menu images, no biometric data is extracted, generated, or stored from these images.
10. Artificial Intelligence and Machine Learning Disclosure
ChefBear uses artificial intelligence (AI) and machine learning (ML) technologies to provide its core services. We believe in transparency about how these technologies process your data:
- Menu text extraction: AI models analyze camera-captured images of restaurant menus to identify and extract dish names, descriptions, and prices.
- Dish recognition and information: AI models process extracted menu text to provide dish descriptions, ingredient information, preparation methods, and translations.
- Personalized recommendations: AI models use your stated dietary preferences, allergen information, and cuisine preferences to generate personalized dish recommendations.
- AI-generated dish images: When a menu does not include photographs, AI image generation models create illustrative images based on dish names and descriptions. These images are AI-generated illustrations, not actual photographs of specific dishes.
Data sent to AI providers for processing is used solely to generate responses for you. As of the effective date of this policy, our AI providers' API terms state that data submitted through their APIs is not used to train or improve their models unless the customer explicitly opts in. We have not opted in to any such training programs.
AI-generated content (including dish descriptions, recommendations, and images) is provided for informational and illustrative purposes only. It should not be relied upon as medical advice, dietary guidance, or a guarantee of any restaurant's actual offerings, ingredients, or preparation methods.
11. Data Retention
We retain personal information for the following periods:
| Data Type | Retention Period |
|---|---|
| Account information (email, user ID) | Until a deletion request is accepted; deletion is then irreversible and the account and its content are immediately unavailable and unrecoverable. Only a minimal deletion-fulfilment and security tombstone is retained, normally for no more than 30 days, and it cannot restore the account. If a processor deletion is still awaiting verification, the tombstone is retained only until verification completes so the request can finish and data cannot be recreated; it is then deleted. |
| User preferences (dietary, allergens, language) | Duration of account existence |
| Camera-captured menu images | When you are signed in, privately backed up to your account: photos of a scan that has not been recognized are deleted 365 days after its last activity, and photos of a recognized menu are kept until 365 days after the menu's last successful content change. You can delete them in the app whenever you are online, except while your connection comes from mainland China. While you use the App as a guest or signed out: not backed up and kept on your device until you delete them; menus scanned as a guest may be backed up after you upgrade to a full account. With app versions earlier than 4.4.0, menus scanned while your service region had not been determined, while your connection came from mainland China or while signed out may also be backed up the first time you open them while signed in to an international account from outside mainland China. |
| AI processing inputs (menu text, prompts) | Menu text attached to a cloud-photo recognition job is kept with that job for up to 37 days. For recognition and other AI requests, a fingerprint of the request (not its content) and the AI result are kept with your account for up to 35 days so an interrupted request can be resumed or answered again without charging you twice; recognized menus are kept as described above. Other inputs are not stored beyond the request/response cycle. AI providers may retain for up to 30 days for abuse monitoring per their policies |
| Crash reports and diagnostics | Under Firebase's default retention, Crashlytics data is generally kept for about 90 days before removal begins from live and backup systems; removal is not necessarily immediate. |
| Product analytics events (PostHog) | As long as needed for product analytics; deleted, together with your PostHog profile, when you delete your account. |
| Subscription and purchase records | RevenueCat customer/account data enters our deletion process. Apple may retain App Store transaction records as an independent controller for periods required by law; account deletion does not cancel the subscription. |
| Cached dish data (on-device) | Until you clear app data, uninstall the App, or accepted account deletion triggers local cleanup. Cloud menus of signed-in users are kept as described in “Menu photos, cloud menus and sharing” below. |
When personal information is no longer needed for the purposes for which it was collected, or upon a verified deletion request, we will securely delete or anonymize such information, unless retention is required by law.
12. Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights under the CCPA/CPRA or other applicable law. Specifically, unless permitted by law, we will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
- Provide you a different level or quality of goods or services; or
- Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
13. Children's Privacy
This App is not intended for children under 13. We do not knowingly collect personal information from children under the age of 13. If we learn that we have inadvertently collected personal information from a child under 13, we will promptly take steps to delete such information. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@awesome-bears.com so we can take appropriate action.
We also do not knowingly sell or share the personal information of consumers under 16 years of age.
14. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest;
- Secure authentication via Firebase Authentication;
- Access controls limiting employee and contractor access to personal information;
- Regular security assessments of third-party service providers.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy within the App or on our website with a revised "Last updated" date. If the changes are significant, we may provide additional notice (e.g., an in-app notification). Your continued use of the App after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
- Email: contact@awesome-bears.com
When contacting us, please include sufficient detail to help us understand and respond to your request. We will make every effort to respond to your inquiry within a reasonable timeframe.