English | EspaƱol

Privacy Policy

Last updated: August 28, 2026

PlateLens is operated by VisionTech Solutions LLC, a Texas limited liability company ("we", "our", or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile and signed-in web applications.

Company Information:
VisionTech Solutions LLC
2001 Timberloch Suite 500
The Woodlands, TX 77380, USA
legal@visionts.io
Summary: We collect data to provide personalized nutrition tracking. Your food photos are analyzed by AI, health data syncs from your device, and your information is stored securely in Firebase. We never sell your data. If you connect an AI assistant such as ChatGPT or Claude, it reads only the categories you authorize, only while you keep it connected, and nothing is sent to it on our initiative.

1. Information We Collect

1.1 Account Information

1.2 Health & Nutrition Data

1.3 Coach Conversations

1.4 Location Data

1.5 Device & Usage Data

1.6 Website Cookies & Analytics

This subsection describes analytics on the public platelens.app marketing and support website only. The rest of this policy covers the PlateLens mobile and signed-in web applications, except where a section expressly says otherwise.

1.7 Connected App Authorizations

If you connect PlateLens to an AI assistant (see section 5), we create an authorization record for that connection: the connecting application's registered identifier and name, the data categories you approved, the time of approval and of the latest use, a salted hash of the connection's access credentials (never the credentials themselves), and an opaque connection identifier you can use to revoke it. These records live in a separate authorization database from your nutrition data.

2. How We Use Your Information

Purpose Data Used
Analyze food photos for nutrition Food photos, user profile
Personalize calorie/macro targets Height, weight, age, activity level, goals
Track your health metrics Weight, hydration and blood glucose logs; HealthKit/Health Connect data
Provide AI coaching Chat history, relevant nutrition and health context, coach memory
Send personalized notifications Location, timezone, activity patterns
Process subscriptions Account ID (via RevenueCat)
Answer read requests from an AI assistant you connected (section 5) Only the categories you authorized: profile targets, meals and nutrition, hydration, activity, weight

3. Third-Party Services

We use the following third-party services to operate PlateLens:

4. AI Data Processing & Third-Party AI Disclosure

Important: PlateLens uses third-party AI services to provide core functionality. By using AI-powered features, you consent to this data processing.

We use OpenAI (OpenAI, L.L.C., San Francisco, CA, USA) to power the following features:

What data is sent to OpenAI

How OpenAI handles your data

For more information, review OpenAI's Privacy Policy and Enterprise Privacy documentation.

5. Connected Apps (MCP Connector)

PlateLens offers an optional, read-only connection for AI assistants that support the Model Context Protocol (MCP), such as OpenAI's ChatGPT and Anthropic's Claude. Nothing in this section happens unless you explicitly connect an assistant. The PlateLens mobile app does not use this connection, and the connector is never used for advertising.

How a connection is established

You start the connection from the assistant. It sends you to auth.platelens.app, where you sign in with the same Google or Apple account you use in PlateLens and approve, category by category, what that assistant may read. Your identity is derived solely from that sign-in: a connection cannot be pointed at another account, and no part of the connector accepts an account identifier, email address or file path as input.

What a connected assistant can read

A connected assistant can never read meal or progress photos, audio, private notes, coach conversations, your email address, your internal account identifier, payment or subscription details, location, or device identifiers, and it cannot create, edit or delete anything in your account.

Why we process it

We process these categories only to answer the specific read request that the assistant makes on your behalf during your conversation. Reads never trigger AI analysis, exports, translations or background jobs, and they are logged only as described under "Retention".

Where the data goes

The result of each read is returned to the assistant you connected. From that moment it is handled by that assistant's provider under its own terms and privacy policy — for example OpenAI for ChatGPT, or Anthropic for Claude — and may be stored in your conversation history there. Depending on your settings with that provider, it may also be used to improve its models (for example, ChatGPT's "Improve the model for everyone" setting). These providers are independent data controllers, not our processors. PlateLens does not send your data to any assistant on its own initiative.

Retention

Revoking and deleting

Revoke any connection at any time in the PlateLens app under More → Preferences → Connected Apps, or at auth.platelens.app. Revocation is enforced on the assistant's very next request, including before any credential renewal, and disconnecting an assistant never affects your PlateLens sign-in. You can also remove PlateLens from the assistant's own settings. Requesting deletion of your PlateLens account immediately revokes every connection, and the final erasure deletes the authorization records.

Service providers for this feature

The connector runs on Google Cloud (Cloud Run, Firestore and Secret Manager, United States), sign-in uses Firebase Authentication, and Cloudflare provides the network edge (TLS, proxying and abuse protection using hashed network identifiers). See section 3.

Legal basis and more information

Your explicit, category-by-category authorization is the legal basis for every read; you withdraw it by revoking the connection. Technical details, the full list of what can and cannot be read, and connection instructions are published at platelens.app/mcp.

6. Data Retention

7. Your Rights

You have the right to:

8. Data Security

We implement industry-standard security measures:

9. Children's Privacy

PlateLens is not intended for users under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

10. International Data Transfers

Your data may be processed in the United States where our servers are located. By using PlateLens, you consent to this transfer. We ensure appropriate safeguards are in place for international data transfers.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

We do not sell your personal information for money, and we never use the personal information inside your PlateLens account for advertising. If you arrive from an advertisement we run inside ChatGPT, we share a pseudonymous advertising identifier with OpenAI so that we can measure whether that advertisement led to a download, and OpenAI may also use it for its own purposes; under California law this may count as “sharing” for cross-context behavioral advertising. If you connect an AI assistant through Connected Apps, the data it reads is disclosed to that assistant's provider at your direction, as described in section 5; that is not a sale.

To opt out (Do Not Sell or Share My Personal Information): send a Global Privacy Control signal from your browser — we honour it automatically and load nothing — or block cookies for this site.

To exercise your California privacy rights, contact us at privacy@platelens.app or use the in-app deletion feature.

12. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

Processing Activity Legal Basis
Account creation and authentication Contract performance
Food photo analysis and nutrition tracking Contract performance
AI coaching and personalization Contract performance + Consent
Push notifications Consent (opt-in)
HealthKit/Health Connect sync Explicit consent
Analytics and crash reporting Legitimate interest
Website advertising measurement (OpenAI pixel, section 1.6) Not performed for visitors in the EEA or Switzerland
Connected Apps reads by an AI assistant you connect (section 5) Explicit consent (category-by-category authorization)
Fraud prevention and security Legitimate interest + Legal obligation

You may withdraw your consent at any time by adjusting your app settings or contacting us.

13. Health Data Protection

We take special care with health and fitness data collected through Apple HealthKit and Google Health Connect:

Prohibited Uses: Health and fitness data is never used for:

Health data is only used to provide you with personalized nutrition tracking and wellness insights within the app.

If you connect an AI assistant through Connected Apps (section 5), health and nutrition data is shared with it only within the categories you approved, only on that assistant's request, and never with photos, notes or conversations. The prohibited uses above continue to apply to us; the assistant's own use is governed by its provider's policy.

14. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via in-app notification or email. Continued use after changes constitutes acceptance of the updated policy.

15. Contact Us

For privacy-related questions or data requests:

Data Deletion Requests: You can delete your account and all associated data directly in the app via Profile > Settings > Delete Account. Your account will enter a 30-day grace period before permanent deletion.