AIEat 隱私權政策
AIEat 是一款幫你在外食時同時算好「剩餘營養素額度、預算、今天的口味」的 App。 這份政策說明我們收集哪些資料、為什麼收、傳給誰,以及你怎麼把它們刪掉。
先講三件最重要的:
- 我們不販售、不出租、不交換你的個人資料,也沒有安裝任何廣告或行為追蹤 SDK。
- 你的位置座標不會被保存:它只在你按下「找餐點」的那一刻用來找附近分店與計算車程,用完即丟。
- 你可以在 App 內直接刪除整個帳號(設定 → 刪除帳號),不需要寄信給我們。
1. 我們收集哪些資料
| 類別 | 具體內容 | 為什麼需要 |
|---|---|---|
| 帳號 | 使用 Google 登入時:你的 Google 帳號識別碼、電子郵件、顯示名稱。 使用 Apple 登入時:Apple 提供的匿名識別碼;名稱與電子郵件僅在你第一次授權時提供(可選擇隱藏)。 不登入時:一組在你裝置上產生的訪客識別碼。 |
讓你的資料跟著帳號走,換手機還在。 |
| 身體資料 | 性別、生日、身高、體重、每週運動頻率、目標(增重/維持/減脂)、達成節奏、食量。 | 算出你每天的熱量與三大營養素目標。這是整個 App 的基礎,不填就算不出「你今天還能吃什麼」。 |
| 飲食紀錄 | 你記下的每一筆:店名、品名、熱量、蛋白質、碳水、脂肪、花費、時間,以及你回報的完食比例與「這餐偏油嗎」。 | 扣掉今天已經吃掉的額度,並讓推薦愈來愈貼近你。 |
| 偏好與限制 | 飲食限制(吃素、不吃牛、過敏、體質等)、你標記的喜歡與不喜歡的品項。 | 把你吃不了的東西擋在推薦之外。 |
| 位置 | 你按下「找餐點」時的經緯度,或你在「我的位置」自己釘的座標。 | 找出附近有哪幾家分店、以及騎車過去要幾分鐘。不存進你的帳號、不建立位置歷史。 |
| 你主動輸入的內容 | 用「一句話記一餐」打或說出來的文字;自己新增的蛋白粉、調味料、容器;搜尋沒找到東西時的關鍵字。 | 把你的一句話拆成營養素;補上資料庫沒有的品項。詳見第 3 與第 4 節。 |
| 步數(選用,預設關閉) | 「健康」App 的步數。 | 走得比平常多的日子多給一些額度。只在你的裝置上讀取與計算,不會上傳到我們的伺服器,也不讀取身高、體重或運動消耗。 |
| 使用統計 | 哪一張推薦卡被看到、你按了哪一張的「出發去吃」、搜尋落空的關鍵字,以及當地的小時數。 | 知道哪些餐點真的被選走,並拿去跟店家談合作。這些事件不包含你的帳號識別碼,我們無法從中看出是誰。 |
我們沒有收集的
- 你的相簿:從相簿挑圖時走的是 iOS 系統的相片選擇器 —— 我們只拿得到你親手挑的那一張,看不到你的相簿裡還有什麼。
相機只有一個用途:記一餐時那顆「拍照辨識營養標示」。按下去才會開,拍完那張圖只走第 3 節說的辨識那一趟;除非你另外勾了第 4 節說的分享,否則我們不保存它。 - 通訊錄、行事曆、簡訊、其他 App 的資料:完全不索取。
- 健康資料:除了上面那項你自己打開的步數以外,一律不讀。
- 廣告識別碼(IDFA)與跨 App 追蹤:沒有,App 裡沒有任何廣告 SDK。
2. 位置:只在那一刻用,用完就丟
你按下「找餐點」時,App 會把當下的座標送到我們的伺服器。伺服器拿它做兩件事: 向 Google Maps Platform 查詢附近有哪幾家分店,以及計算走路、機車、開車各要多久。
算完之後那組座標就消失了 —— 它不會被寫進你的帳號、不會累積成移動軌跡。 你也可以完全不給定位權限:到「設定 → 我的位置」在地圖上自己釘一個點, 之後每次找餐點都從那裡出發(那個座標只存在你的手機裡)。
3. 語音與 AI:你打的字會經過哪裡
「一句話記一餐」有三段會離開你的手機,三段都不送你的身分:
- 語音轉文字由 iOS 的語音辨識服務處理,可能將你的語音傳送至 Apple 進行辨識 (這是 Apple 提供的系統功能,適用 Apple 的隱私權政策)。 我們不保存錄音,只保留轉出來的文字。
- 把「滷肉飯加顆滷蛋」拆成營養素,會把那句文字送到我們的伺服器, 再由伺服器轉送給 Google 的 Gemini 模型(以及為了查營養標示而進行的網路搜尋)處理。 送出去的只有那句話與菜名,不含你的帳號、身體資料或位置。
- 拍營養標示(記一餐時那顆「拍照辨識營養標示」)會把那張照片 送到我們的伺服器,再由伺服器轉送給 Google 的 Gemini 模型讀出上面的數字。 照片只在辨識的那一刻經手,我們不保存它,除非你另外勾了下一節說的那個分享 (勾了才會留下來)。送出去的只有那張圖,不含你的帳號、身體資料或位置。 這一段只在你親手按下那顆按鈕、親手挑了那張照片時才會發生。
不想讓任何東西離開手機的話,用「找餐點」與從清單裡挑品項這兩條路徑記錄, 並且不要按拍營養標示,就不會觸發上面三段。
4. 你手動新增的內容會成為公開資料
在 App 裡自己新增一款蛋白粉時,你填的那幾格(品牌、品名、口味、一勺幾克、每勺的熱量與三大營養素) 會送交我們審核;通過之後,這一款會成為所有使用者都搜得到的公開品項。
上傳的只有那幾格資料本身,不含你的帳號、名字或位置, 所以其他使用者看得到那款蛋白粉,但無從得知是誰新增的。這件事在你按下送出前, 表單上也會再說明一次。
你改掉我們估的熱量時也一樣。 記一餐時,我們替某些餐點提供的是估算值 (畫面上會寫「我們估的」)。你把那個數字改掉之後,我們會把 品名、店名、你填的熱量,以及我們原本估的那個數字送回去, 讓同一道菜的估算對所有人都變準一點 ——「我們估了多少」是算出「我們偏了幾成」的分母, 少了它就只有那一道菜受惠,從來沒有人記過的新菜色永遠等不到修正。 你把我們算的份量克數改掉時同理,送回去的是改了幾倍(例如 1.4), 用來校正「一個拳頭大的飯大概幾克」那張共用的表。 上傳的不含你的帳號、名字或位置,也不含你吃了幾份、花了多少錢或什麼時候吃的。
這件事會在你第一次改動時問你一次,你答應了才會開始送。 之後可以隨時在「設定 → 偏好設定 → 幫忙讓估算變準」關掉;關掉的那一刻, 還沒送出去的那幾筆會從你的手機上刪除。
你分享營養標示掃描時也一樣。 拍完營養標示的那張卡底下有一格 「分享營養資訊與照片,幫助完善公開資料庫」。維持勾選並按下記下來時, 我們會把你拍的那張營養標示照片、商品名稱與商家名稱、標示上的熱量與三大營養素、 價格,以及那組數字對應多大一份上傳到我們的伺服器,交給人工審核; 通過之後,那個品項會成為所有使用者都搜得到的公開資料。
上傳的不含你的帳號、名字或位置,也不含你吃了幾份、什麼時候吃的。 一起送的只有一個去識別化的代號(由這台裝置的匿名識別碼雜湊而來, 連不回你的帳號),用途只有一個:讓審核的人分得出「五個人都這麼說」與「一個人說了五次」。
沒有填商家名稱的那幾項一律不會送出—— 自己煮的、朋友家吃的、路邊無名攤子是你的私事;有商家名稱的則是「某一家店賣什麼」的公開事實。 把那一格的勾取消掉,這一項就完全不會上傳;那一格只在你真的拍過營養標示、 或掃過條碼的卡片上出現。
掃條碼那條路也一樣。 你掃了一支條碼、而我們查不到那個商品時, 你接著填的那組數字可以留給下一個掃到同一包的人。維持那一格勾選並按下記下來 (食材庫是按下存起來)時,我們會把那支條碼、商品名稱,以及換算成每 100 公克的 熱量與三大營養素上傳,成為所有使用者掃得到的公開資料。
這一條同樣不含你的帳號、名字或位置,也不含你吃了多少、什麼時候吃的; 一起送的只有上面那個去識別化的代號,用途只有一個:讓畫面上說得出 「1 位使用者提供」還是「37 位使用者提供」。 你自己憑印象打的數字不會送出——只有從營養標示(拍的或掃到的)來的那一組會。
5. 資料傳給誰
我們只在為了讓功能運作的必要範圍內,把資料交給以下服務:
| 對象 | 拿到什麼 | 為什麼 |
|---|---|---|
| Google(Maps Platform) | 你當下的座標、附近的店家名稱 | 找出分店位置與計算車程 |
| Google(登入) | 登入時的驗證 | 用 Google 帳號登入 |
| Google(Gemini) | 你輸入的菜名文字;你拍的營養標示照片 | 把一句話拆解成營養素;讀出標示上的數字 |
| Apple | 登入時的驗證;語音辨識的語音 | 用 Apple 帳號登入、語音轉文字 |
| Railway | 上述所有存放於伺服器的資料 | 我們的伺服器與資料庫託管在它的機房 |
我們不會為了廣告、行銷或任何商業目的把你的個人資料賣給、租給或交換給第三方。 我們可能會發布彙總後、無法識別個人的統計(例如「這家店的餐點被選走幾次」), 拿去跟餐飲品牌談合作 —— 那份報告裡沒有任何一個帳號、姓名或裝置識別碼。
6. 資料存在哪裡、留多久
- 伺服器上的資料存放在 Railway 位於美國的機房。
- 只要你的帳號還在,資料就留著 —— 因為「今天還能吃什麼」需要看得到你過去吃了什麼。
- 你刪掉單筆飲食紀錄時,那一筆會從你的帳號移除。
- 你刪除帳號時,見下一節。
7. 你的權利:怎麼刪、刪掉什麼
到 設定 → 刪除帳號,確認之後我們會刪除:
- 你的個人資料、身體數據、每日目標、飲食紀錄、飲食限制與口味偏好;
- 你回報過的油量資料;
一件要先講清楚的例外:
- 你先前提交、且已經通過審核成為公開品項的內容(例如一款蛋白粉的營養數據), 會留在公開資料庫裡。它不含任何能連回你的資訊,且已經是其他使用者正在使用的資料。
同一個動作也會清掉這台手機上的所有本機資料。若你想要一份自己資料的副本, 或有任何刪除上的問題,寫信到下面的信箱,我們會在 30 天內處理。
8. 兒童
AIEat 不以 13 歲以下兒童為對象,也不會刻意收集他們的資料。 若你認為有 13 歲以下的兒童向我們提供了個人資料,請來信告知,我們會刪除。
9. 安全
App 與伺服器之間的連線一律走 HTTPS。登入憑證存放在 iOS 的 Keychain 裡。 但沒有任何一種網路傳輸或儲存方式是百分之百安全的,我們無法保證絕對的安全性。
10. 這份政策的變更
政策若有更動,我們會更新這一頁最上方的「最後更新」日期。 涉及重大變更(例如開始收集新類型的資料)時,我們會在 App 內告知。
11. 聯絡我們
對這份政策、或對你的資料有任何疑問,請寄信到 jeremy950514@gmail.com。
AIEat Privacy Policy
AIEat helps you decide what to eat out by balancing three things at once: your remaining nutrition allowance, your budget, and what you actually feel like today. This policy explains what we collect, why, who we share it with, and how you delete it.
The three things that matter most:
- We do not sell, rent, or trade your personal data, and the app contains no advertising or behavioural tracking SDKs.
- Your location is never stored. It is used at the moment you tap “Find a meal” to locate nearby branches and estimate travel time, then discarded.
- You can delete your entire account from inside the app (Settings → Delete account). No email required.
1. What we collect
| Category | What exactly | Why |
|---|---|---|
| Account | Google sign-in: your Google account ID, email, display name. Apple sign-in: the anonymous identifier Apple provides; name and email only on first authorisation (and you may hide them). Not signed in: a guest identifier generated on your device. | So your data follows your account across devices. |
| Body data | Sex, date of birth, height, weight, weekly exercise frequency, goal, pace, appetite. | To calculate your daily calorie and macronutrient targets — the basis of every recommendation. |
| Meal log | For each entry: store name, dish name, calories, protein, carbs, fat, spend, time, how much of it you finished, and whether you found it oily. | To subtract what you have already eaten today and improve future recommendations. |
| Preferences & restrictions | Dietary restrictions (vegetarian, no beef, allergies, etc.) and dishes you marked liked/disliked. | To keep food you cannot eat out of your recommendations. |
| Location | Your coordinates when you tap “Find a meal”, or a point you pinned yourself. | To find nearby branches and travel times. Not attached to your account; no location history is kept. |
| Content you enter | Text you type or dictate into one-line logging; protein powders, seasonings and containers you add; keywords from searches that returned nothing. | To turn your sentence into nutrition values and to fill gaps in our database. See sections 3 and 4. |
| Step count (optional, off by default) | Step count from Apple Health. | To grant extra allowance on days you walk more than usual. Read and calculated entirely on your device; never uploaded. We do not read height, weight or active energy. |
| Usage analytics | Which recommendation cards were seen, which ones you tapped “Go eat” on, keywords that found nothing, and the local hour. | To learn which meals are actually chosen and to negotiate with restaurant brands. These events carry no account identifier — we cannot tell who they came from. |
What we do not collect
- Your photo library. When you pick an image, iOS’s system photo picker hands us only the single image you chose — we cannot see the rest of your library.
The camera has exactly one use: the “Scan nutrition label” button when logging a meal. It opens only when you tap it, and the photo it takes makes only the recognition trip described in section 3; we do not keep it unless you also leave the sharing box in section 4 ticked. - Contacts, calendar, messages, or data from other apps. Never requested.
- Health data other than the step count you explicitly enable.
- Advertising identifiers (IDFA) or cross-app tracking. There are no ad SDKs in the app.
2. Location: used in the moment, then discarded
When you tap “Find a meal”, the app sends your current coordinates to our server, which uses them to ask Google Maps Platform which branches are nearby and how long walking, scooter and driving would take. After that calculation the coordinates are gone — they are never written to your account and never accumulated into a movement history. You may also decline location access entirely and pin a starting point yourself in Settings → My location; that pin stays on your phone.
3. Voice and AI: where your words travel
- Speech-to-text is handled by iOS speech recognition, which may send your speech to Apple for processing (a system feature governed by Apple’s Privacy Policy). We do not keep the audio — only the resulting text.
- Breaking a sentence down into nutrition values sends that text to our server, which forwards it to Google’s Gemini model (and performs a web search to find nutrition labels). Only the sentence and dish names are sent — never your account, body data or location.
- Scanning a nutrition label (the “Scan nutrition label” button when logging a meal) sends the photo itself to our server, which forwards it to Google’s Gemini model to read the figures printed on it. The photo passes through for that one recognition and is not stored, unless you also leave the sharing box described in the next section ticked — that is the only case in which it is kept. Only the image is sent: never your account, body data or location. This happens only when you tap that button and choose that photo yourself.
If you would rather nothing left your phone, log meals through “Find a meal” or by picking items from the list, and do not scan a label; none of those paths triggers the above.
4. Content you add becomes public
When you add a protein powder yourself, the fields you fill in (brand, product, flavour, grams per scoop, and the calories and macros per scoop) are submitted for review; once approved, that product becomes a public entry every user can find.
Only those fields are uploaded — not your account, name or location — so other users see the product but cannot tell who added it. The form tells you this before you submit.
The same applies when you correct a calorie figure we estimated. Some meals are logged with an estimate (the card says so). When you change that number, we send back the dish name, store name, the figure you entered and the figure we had estimated so the estimate gets better for everyone — what we guessed is the denominator that tells us how far off we were, without which only that one dish improves and a brand-new dish nobody has logged never does. The same goes for the portion weight we calculated: if you change it, we send how far off it was (say 1.4×) to correct the shared table behind “roughly how many grams is a fistful of rice”. Nothing else goes with it — not your account, name or location, and not how many servings, how much you paid or when you ate.
We ask you once, the first time you make such a correction, and only send anything if you agree. You can turn it off at any time under Settings → Preferences; turning it off deletes any corrections still waiting on your phone.
The same applies when you share a nutrition label scan. After you scan a label, that card shows a checkbox reading “Share the nutrition information and photo to help improve the public database”. If you leave it ticked and save the meal, we upload the nutrition label photo you took, the product and store names, the calories and macros printed on the label, the price, and what size of serving those figures refer to to our server for human review; once approved, that product becomes public data every user can find.
Nothing that identifies you goes with it — not your account, name or location, and not how many servings you had or when you ate. The one thing sent alongside is a de-identified token (a hash of this device’s anonymous identifier, which cannot be traced back to your account), used for a single purpose: so the reviewer can tell “five people said this” apart from “one person said it five times”.
Items with no store name are never sent — food you cooked yourself, ate at a friend’s place or bought from an unnamed stall is your private business, whereas an item with a store name is a public fact about what that shop sells. Unticking the box means the item is not uploaded at all, and the box appears only on cards where you actually scanned a label.
5. Who we share data with
| Recipient | What they receive | Why |
|---|---|---|
| Google (Maps Platform) | Your coordinates, nearby store names | Branch locations and travel times |
| Google (Sign-In) | Sign-in verification | Signing in with Google |
| Google (Gemini) | Dish text you entered; the nutrition label photo you took | Turning a sentence into nutrition values; reading the figures off a label |
| Apple | Sign-in verification; speech audio for recognition | Signing in with Apple; speech-to-text |
| Railway | All server-side data listed above | Our server and database are hosted there |
We never sell, rent or trade your personal data for advertising, marketing or any other commercial purpose. We may publish aggregated, non-identifiable statistics (for example, how many times a store’s meals were chosen) when working with restaurant brands; those reports contain no account, name or device identifier.
6. Where data lives and for how long
- Server-side data is stored in Railway’s US data centres.
- Data is retained while your account exists, because “what can I still eat today” depends on what you ate before.
- Deleting a single meal entry removes that entry from your account.
- Deleting your account: see the next section.
7. Your rights: how to delete, and what gets deleted
Go to Settings → Delete account. On confirmation we delete:
- Your profile, body data, daily targets, meal log, dietary restrictions and taste preferences;
- Your oiliness reports;
One exception, stated plainly:
- Content you submitted that has already been approved as a public entry (for example a protein powder’s nutrition data) remains in the public database. It contains nothing that links back to you, and other users already rely on it.
The same action clears all local data on this phone. If you would like a copy of your data, or have any question about deletion, email us at the address below and we will respond within 30 days.
8. Children
AIEat is not directed at children under 13 and we do not knowingly collect their data. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
9. Security
All traffic between the app and our servers uses HTTPS, and sign-in credentials are stored in the iOS Keychain. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
10. Changes to this policy
If this policy changes we will update the “Last updated” date at the top of this page. For material changes — such as beginning to collect a new category of data — we will also tell you inside the app.
11. Contact
Questions about this policy or your data: jeremy950514@gmail.com.