English | EspaƱol
Privacy Policy
Last updated: August 28, 2026
PlateLens is operated by VisionTech Solutions LLC, a Texas limited liability company ("we", "our", or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile and signed-in web applications.
Company Information:
VisionTech Solutions LLC
2001 Timberloch Suite 500
The Woodlands, TX 77380, USA
legal@visionts.io
Summary: We collect data to provide personalized nutrition tracking. Your food photos are analyzed by AI, health data syncs from your device, and your information is stored securely in Firebase. We never sell your data. If you connect an AI assistant such as ChatGPT or Claude, it reads only the categories you authorize, only while you keep it connected, and nothing is sent to it on our initiative.
1. Information We Collect
1.1 Account Information
- Authentication data: Email address, display name, and profile photo (via Apple Sign-In or Google Sign-In)
- Profile information: Username, height, weight, sex, birth date, dietary preferences, allergies, and fitness goals
1.2 Health & Nutrition Data
- Food photos: Images you take of meals for nutritional analysis
- Nutrition logs: Calories, macronutrients, and micronutrients from analyzed meals
- Weight logs: Weight entries and optional progress photos
- Hydration logs: Water intake tracking
- Blood glucose logs: Values, observation times, optional context and notes you enter, plus source-owned readings you choose to synchronize
- Health platform data: Steps, distance, weight, hydration, and blood glucose records from Apple HealthKit (iOS) or Health Connect (Android), with your permission
1.3 Coach Conversations
- Chat messages: Text, voice, and photo messages sent to your AI coach
- Coach memory: Notes the AI stores to personalize your experience
1.4 Location Data
- IP-based location: Country, region, city, and timezone (for localized meal timing)
- Precise location: GPS coordinates (only with explicit permission, for local restaurant recommendations)
1.5 Device & Usage Data
- Device tokens: For push notifications
- App usage: Features used, session duration, and crash reports
- Locale settings: Language and regional preferences
1.6 Website Cookies & Analytics
This subsection describes analytics on the public platelens.app marketing and support website only. The rest of this policy covers the PlateLens mobile and signed-in web applications, except where a section expressly says otherwise.
- What we measure: page views, the page you arrived from, and clicks on our App Store and Google Play links, so we can tell which pages are useful. Unless you arrived from a ChatGPT advertisement, described below, we do not build advertising profiles from your visit to this website.
- Google Analytics 4: performs that measurement and sets a first-party cookie (
_ga) to recognise a returning browser. Privacy Policy
- Google Analytics in the EEA, the United Kingdom and Switzerland: analytics and advertising storage are denied by default. No Google Analytics cookie is written to your device, and Google reports only aggregate, modelled figures for those visits.
- OpenAI advertising measurement: if you arrive from an advertisement we run inside ChatGPT, that link carries a click identifier (
oppref) and we load OpenAI's measurement pixel so we can tell whether the visit led to an app download. It stores that click identifier (__oppref, 30 days) and a randomly generated browser identifier (__obref, 365 days) on your device, and reports to OpenAI the page you landed on, your approximate location, your IP address and your browser's user agent. OpenAI acts as an independent data controller for this information and also uses it to develop and improve its own products and services. Privacy Policy
- We do not load that pixel for anyone who did not arrive from a ChatGPT advertisement, for visitors in the EEA or Switzerland, or for anyone whose browser sends a Global Privacy Control signal. If you visited from one of those advertisements and later fall into any of those groups, both identifiers are deleted from your device on your next visit and nothing further is sent.
- Opting out elsewhere: block cookies for this site in your browser settings, or install Google's Analytics opt-out add-on.
1.7 Connected App Authorizations
If you connect PlateLens to an AI assistant (see section 5), we create an authorization record for that connection: the connecting application's registered identifier and name, the data categories you approved, the time of approval and of the latest use, a salted hash of the connection's access credentials (never the credentials themselves), and an opaque connection identifier you can use to revoke it. These records live in a separate authorization database from your nutrition data.
2. How We Use Your Information
| Purpose |
Data Used |
| Analyze food photos for nutrition |
Food photos, user profile |
| Personalize calorie/macro targets |
Height, weight, age, activity level, goals |
| Track your health metrics |
Weight, hydration and blood glucose logs; HealthKit/Health Connect data |
| Provide AI coaching |
Chat history, relevant nutrition and health context, coach memory |
| Send personalized notifications |
Location, timezone, activity patterns |
| Process subscriptions |
Account ID (via RevenueCat) |
| Answer read requests from an AI assistant you connected (section 5) |
Only the categories you authorized: profile targets, meals and nutrition, hydration, activity, weight |
3. Third-Party Services
We use the following third-party services to operate PlateLens:
- Firebase (Google): Authentication, database, file storage, and analytics. Privacy Policy
- OpenAI: AI analysis of food photos and descriptions, meal corrections, exercise descriptions and estimates, and coach conversations. Privacy Policy
- RevenueCat: Subscription management. Privacy Policy
- Open Food Facts: Barcode product database (open source, no personal data shared)
- Expo: Push notification delivery. Privacy Policy
- Google Analytics: Traffic measurement on the platelens.app website, as described in section 1.6. Privacy Policy
- Google Cloud (Cloud Run, Firestore, Secret Manager): Hosting of the Connected Apps connector and its authorization records, in the United States (section 5). Privacy Policy
- Cloudflare: Network edge for the Connected Apps connector (TLS, proxying and abuse protection using hashed network identifiers). Privacy Policy
- OpenAI (advertising measurement): Conversion measurement for advertisements we run inside ChatGPT, as described in section 1.6. This is a separate role from the AI processing above: for it, OpenAI is an independent data controller, not our processor. Privacy Policy
- AI assistants you connect (for example OpenAI ChatGPT or Anthropic Claude): Recipients of the data you authorize them to read through Connected Apps (section 5). They act on your instruction and are independent controllers, not our processors.
4. AI Data Processing & Third-Party AI Disclosure
Important: PlateLens uses third-party AI services to provide core functionality. By using AI-powered features, you consent to this data processing.
We use OpenAI (OpenAI, L.L.C., San Francisco, CA, USA) to power the following features:
- Food analysis: Photos or descriptions of meals are sent to OpenAI to identify food items and estimate nutrition. When you record a meal description in the mobile app, the audio recording is first sent to OpenAI for transcription; Apple Watch system dictation provides text to PlateLens instead of an audio recording
- Meal corrections: Your correction instructions and the current meal details may be sent to OpenAI; the meal photo may also be processed again when the correction requires image analysis
- Exercise analysis: Your exercise description and current weight, when available, may be sent to OpenAI to estimate the activity and calories burned
- AI coaching: Your chat messages and relevant profile, goal, nutrition, hydration, blood glucose, activity, and weight context may be processed by OpenAI to generate personalized responses. Blood-glucose context is requested only when it is relevant to your Coach conversation. Context can include data you chose to synchronize from Apple Health or Health Connect.
What data is sent to OpenAI
- Food photos (images only, no metadata), meal descriptions, mobile-app meal voice recordings submitted for transcription, and meal-correction instructions and context
- Exercise descriptions and your current weight, when available, when you request an exercise estimate
- AI Coach text and photo messages, voice recordings submitted for transcription, and conversation history
- Relevant profile context (dietary preferences, goals, allergies) to personalize responses
- When you use the AI Coach, relevant nutrition, hydration, blood glucose, activity, and weight context, including synchronized health-platform data. For imported hydration, this can include amounts, times, and the platform type, but not native record identifiers or source-app names. When a glucose question or related context calls for it, this can include bounded glucose values, observation instants, occurrence-local dates, clock times and UTC offsets, source platform type, reported measurement method, and observed coverage. For one exact day, PlateLens may send a bounded event-level list of confirmed timed meals (occurrence time, calories, carbohydrates, protein and fat) and PlateLens-logged exercise (start and end times, duration and estimated calories) from that day. For a 7-, 30- or 90-day analysis, meal and exercise context is instead sent as aggregate eligibility counts, observation windows and summary statistics, not as an event list. Coach glucose context never includes glucose record IDs, meal or exercise record IDs, native/provider identifiers, source-app names, private glucose notes or private exercise descriptions.
How OpenAI handles your data
- Processing location: United States
- Training: Per OpenAI's API Data Usage Policy, data sent via the API is not used to train OpenAI's models
- Retention: By default, OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect its services or third parties from harm. Some API features may also retain application state according to their endpoint-specific settings.
For more information, review OpenAI's Privacy Policy and Enterprise Privacy documentation.
5. Connected Apps (MCP Connector)
PlateLens offers an optional, read-only connection for AI assistants that support the Model Context Protocol (MCP), such as OpenAI's ChatGPT and Anthropic's Claude. Nothing in this section happens unless you explicitly connect an assistant. The PlateLens mobile app does not use this connection, and the connector is never used for advertising.
How a connection is established
You start the connection from the assistant. It sends you to auth.platelens.app, where you sign in with the same Google or Apple account you use in PlateLens and approve, category by category, what that assistant may read. Your identity is derived solely from that sign-in: a connection cannot be pointed at another account, and no part of the connector accepts an account identifier, email address or file path as input.
What a connected assistant can read
- Profile & targets (
profile.read): goal, activity level, unit system, calorie, macro, hydration and step targets, stored BMR/TDEE estimate, target weight
- Meals & nutrition (
nutrition.read): completed meals, ingredient names and portions, calories, macronutrients and micronutrients, hydration totals, nutrition trends
- Activity (
activity.read): steps and active energy synchronized from your health platform, manual exercise entries and their estimated calories
- Weight (
weight.read): weight and optional body-fat entries and trends
- Energy balance: estimated intake versus expenditure, deficit or surplus and adherence to your plan, derived from the categories above when you grant profile, nutrition and activity; there is no additional hidden category
- Background access (
offline_access): lets the assistant keep reading without asking you to sign in again, within the limits described under "Retention" below
A connected assistant can never read meal or progress photos, audio, private notes, coach conversations, your email address, your internal account identifier, payment or subscription details, location, or device identifiers, and it cannot create, edit or delete anything in your account.
Why we process it
We process these categories only to answer the specific read request that the assistant makes on your behalf during your conversation. Reads never trigger AI analysis, exports, translations or background jobs, and they are logged only as described under "Retention".
Where the data goes
The result of each read is returned to the assistant you connected. From that moment it is handled by that assistant's provider under its own terms and privacy policy — for example OpenAI for ChatGPT, or Anthropic for Claude — and may be stored in your conversation history there. Depending on your settings with that provider, it may also be used to improve its models (for example, ChatGPT's "Improve the model for everyone" setting). These providers are independent data controllers, not our processors. PlateLens does not send your data to any assistant on its own initiative.
Retention
- Access credentials for a connection expire after 10 minutes and are renewed silently while the connection remains active
- A connection expires after 90 days without use and, in any case, one year after you approved it; after that the assistant must ask you to reconnect
- A connecting application that is never authorized is deleted after 24 hours; once authorized, its non-personal registration metadata (name, redirect addresses) is kept so the same application can request your consent again — it carries no access by itself
- Pending sign-in sessions expire within 10 minutes
- Records of a revoked or expired connection are deleted automatically no later than that connection's one-year ceiling
- Operational logs for the connector contain request identifiers, tool names, timing, status codes, hashed identifiers and bounded counters, and are kept for 30 days. They never contain access credentials, tool arguments or results, meal text, weight values, email addresses or sign-in tokens
Revoking and deleting
Revoke any connection at any time in the PlateLens app under More → Preferences → Connected Apps, or at auth.platelens.app. Revocation is enforced on the assistant's very next request, including before any credential renewal, and disconnecting an assistant never affects your PlateLens sign-in. You can also remove PlateLens from the assistant's own settings. Requesting deletion of your PlateLens account immediately revokes every connection, and the final erasure deletes the authorization records.
Service providers for this feature
The connector runs on Google Cloud (Cloud Run, Firestore and Secret Manager, United States), sign-in uses Firebase Authentication, and Cloudflare provides the network edge (TLS, proxying and abuse protection using hashed network identifiers). See section 3.
Legal basis and more information
Your explicit, category-by-category authorization is the legal basis for every read; you withdraw it by revoking the connection. Technical details, the full list of what can and cannot be read, and connection instructions are published at platelens.app/mcp.
6. Data Retention
- Account data: Retained until you delete your account
- Food photos: Retained until you delete your account
- Chat history: Retained until you delete your account
- Analytics: Aggregated data retained for up to 14 months
- Backup copies: After your data is erased, copies may remain in secure backup and recovery storage for up to 100 days before they are permanently overwritten. These copies are not used to provide the service and are not accessible from the app.
- Connected app authorizations: As described in section 5 (10-minute credentials, 90 days of inactivity, one-year ceiling, 30-day operational logs)
7. Your Rights
You have the right to:
- Access: Request a copy of your data
- Correction: Update inaccurate information
- Deletion: Delete your account and all associated data (via Profile > Settings > Delete Account)
- Portability: Export your data in a machine-readable format
- Opt-out: Disable push notifications or revoke Apple Health or Health Connect permissions at any time
- Revoke connected apps: Disconnect any AI assistant at any time under More > Preferences > Connected Apps or at auth.platelens.app (section 5)
8. Data Security
We implement industry-standard security measures:
- All data transmitted via HTTPS/TLS encryption
- Firebase Security Rules restrict data access to authenticated users
- Sensitive fields (subscription status, streak data) are protected from client modification
- Photos are stored in private Firebase Storage buckets
9. Children's Privacy
PlateLens is not intended for users under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10. International Data Transfers
Your data may be processed in the United States where our servers are located. By using PlateLens, you consent to this transfer. We ensure appropriate safeguards are in place for international data transfers.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about the categories of personal information we collect, the purposes for collection, and the categories of third parties with whom we share your data
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions
- Right to Correct: You can request correction of inaccurate personal information
- Right to Opt-Out: You have the right to opt out of the sale or sharing of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
We do not sell your personal information for money, and we never use the personal information inside your PlateLens account for advertising. If you arrive from an advertisement we run inside ChatGPT, we share a pseudonymous advertising identifier with OpenAI so that we can measure whether that advertisement led to a download, and OpenAI may also use it for its own purposes; under California law this may count as “sharing” for cross-context behavioral advertising. If you connect an AI assistant through Connected Apps, the data it reads is disclosed to that assistant's provider at your direction, as described in section 5; that is not a sale.
To opt out (Do Not Sell or Share My Personal Information): send a Global Privacy Control signal from your browser — we honour it automatically and load nothing — or block cookies for this site.
To exercise your California privacy rights, contact us at privacy@platelens.app or use the in-app deletion feature.
12. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
| Processing Activity |
Legal Basis |
| Account creation and authentication |
Contract performance |
| Food photo analysis and nutrition tracking |
Contract performance |
| AI coaching and personalization |
Contract performance + Consent |
| Push notifications |
Consent (opt-in) |
| HealthKit/Health Connect sync |
Explicit consent |
| Analytics and crash reporting |
Legitimate interest |
| Website advertising measurement (OpenAI pixel, section 1.6) |
Not performed for visitors in the EEA or Switzerland |
| Connected Apps reads by an AI assistant you connect (section 5) |
Explicit consent (category-by-category authorization) |
| Fraud prevention and security |
Legitimate interest + Legal obligation |
You may withdraw your consent at any time by adjusting your app settings or contacting us.
13. Health Data Protection
We take special care with health and fitness data collected through Apple HealthKit and Google Health Connect:
Prohibited Uses: Health and fitness data is
never used for:
- Advertising or marketing purposes
- Sale to third parties, data brokers, or information resellers
- Credit determination or lending decisions
- Employment or insurance eligibility decisions
Health data is only used to provide you with personalized nutrition tracking and wellness insights within the app.
If you connect an AI assistant through Connected Apps (section 5), health and nutrition data is shared with it only within the categories you approved, only on that assistant's request, and never with photos, notes or conversations. The prohibited uses above continue to apply to us; the assistant's own use is governed by its provider's policy.
14. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via in-app notification or email. Continued use after changes constitutes acceptance of the updated policy.
15. Contact Us
For privacy-related questions or data requests:
- Company: VisionTech Solutions LLC
- Address: 2001 Timberloch Suite 500, The Woodlands, TX 77380, USA
- Email: privacy@platelens.app
- Phone: (857) 847-4668
Data Deletion Requests: You can
delete your account and all associated data directly in the app via Profile > Settings > Delete Account. Your account will enter a 30-day grace period before permanent deletion.