Last updated: 10 September 2026
This Privacy Notice for Crescendo Labs Limited (doing business as Bite) (“we”, “us”, or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at contact@crescendolabs.co.uk.
This summary provides key points from our Privacy Notice. You can find more detail on any of them by following the link after each point, or by using the table of contents below.
What personal information do we process? When you use our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? Yes. The dietary and allergy information you choose to give us is health information, which is treated as “special category” or “sensitive” data in the UK and many other places. We use it for one purpose only: filtering which recipes we show you. Giving it to us is optional, the app works without it, and clearing it stops the processing. We do not collect information about your racial or ethnic origin, sexual orientation, religious beliefs, biometrics, or precise location. Learn more about sensitive information we process.
Do we collect any information from third parties? No. We do not buy personal information, and we do not obtain it from data brokers or marketing lists.
How do we process your information? To provide, improve, and administer our Services, to communicate with you, for security and fraud prevention, and to comply with the law. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information? With the service providers who run parts of the app for us, listed by name in section 4. We do not sell your personal information, and we do not share it for advertising. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We have organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
What are your rights? Depending on where you live, applicable privacy law may give you rights over your personal information. Learn more about your privacy rights.
How do you exercise your rights? Most of it you can do yourself in the app, without asking us — open the You tab. You can also email us. We will consider and act on any request in accordance with applicable data protection law.
In short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
The first time you open Bite, the app creates a guest account for you automatically and signs you in. You are not asked for an email address, a password or a name, and you never have to create a real account — but the guest account is still an account, with an identifier of its own, and everything described below is stored against it: your preferences and allergies, your fridge contents, your saved recipes, your subscription and your allowance counters.
We say this plainly because “I never signed up” is a reasonable thing to assume means “they hold nothing about me”, and here it does not. What it does mean is that we hold no name, no email address and no way to contact you unless you choose to sign in with Google or Apple later. Your rights below — including deleting everything — apply to the guest account exactly as they do to a registered one, and You → Delete account works without signing in.
Personal information provided by you. The personal information we collect may include the following:
We never ask you for a password. Bite has no email-and-password sign-up: the only ways in are the automatic guest account, Sign in with Google, or Sign in with Apple. So we hold no password of yours to lose, and there is no password for anyone to reset or steal.
Sensitive information. We process one category of sensitive information:
Exactly how and when we ask. During setup we show a screen headed “Any allergies or dietary needs?” with the note “We'll keep these out of your feed.” You can select as many or as few as you like, including none, and continue either way. Whatever you select is saved to your profile on our servers and used to filter the recipe catalogue. There is no separate consent box on that screen, and this notice is not shown to you before it — we are telling you that plainly rather than describing a step that does not exist. You can change or clear your answer at any time in You → Edit preferences; clearing it removes the information and stops the filtering.
Payment data. If you subscribe to Bite Pro, Apple processes the payment through the App Store as merchant of record. Apple takes the payment, handles local taxes and currency, and manages refunds. We never receive or store your card details. From our subscription provider we receive only your account identifier, purchase and renewal events, and the date your subscription expires. You may find Apple's privacy notice here: https://www.apple.com/legal/privacy/.
To manage or cancel your subscription, or to request a refund, use your Apple ID settings or reportaproblem.apple.com.
Social media login data. We give you the option to register using Sign in with Google or Sign in with Apple. If you choose one of these, we receive your email address and an account identifier from that provider — nothing more. We do not receive a friends list, a profile picture, contacts, or any other content from your account. See the section called HOW DO WE HANDLE YOUR SOCIAL LOGINS? below.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
If you use our application, we may also collect the following information if you choose to provide us with access or permission:
This information is primarily needed to maintain the security and operation of our application and for troubleshooting.
In short: Some information — such as your IP address and device characteristics — is collected automatically when you use our Services.
We automatically collect certain information when you use the Services. This information does not reveal your specific identity (like your name) but may include device and usage information. It is primarily needed to maintain the security and operation of our Services.
The information we collect includes:
What we do not record. Which recipes you look at, which you skip or hide, which you have cooked, and the taste profile the app builds from your swiping stay on your device. There is nowhere on our servers to put them. If that ever changes we will update this notice before it does, not afterwards.
We do not collect your location. The app never requests location permission and contains no location tracking.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Sign-In only to create and access your account. We do not read your Gmail, contacts, calendar or files, we never use this information for advertising, and no human at Crescendo Labs Limited reads it.
In short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
In short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e. legal basis) to do so under applicable law — like with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfil our legitimate business interests.
If you are located in the UK or the EU, this section applies to you.
The UK GDPR and the General Data Protection Regulation (GDPR) require us to explain the valid legal bases we rely on in order to process your personal information. We may rely on the following:
We do not use automated decision-making that produces legal or similarly significant effects. We personalise which recipes you see, but that has no legal or significant effect, and you can clear it at any time in You → Privacy → Reset personalisation.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.
In some exceptional cases we may be legally permitted under applicable law to process your information without your consent, including for investigations and fraud detection and prevention, for business transactions provided certain conditions are met, if disclosure is required to comply with a subpoena, warrant or court order, or if the information is publicly available and specified by the regulations.
In short: We may share information in the specific situations described in this section and with the third parties listed below.
Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers or contractors who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with them, designed to safeguard your personal information. This means they cannot do anything with your personal information unless we have instructed them to do it, and they will not share it with any other organisation. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
The third parties we may share personal information with are as follows:
| Purpose | Provider | What they receive |
|---|---|---|
| AI service providers | OpenAI | Your AI chef questions and recipe context; the photograph you take with Scan |
| Cloud computing and database | Supabase | Your account (or guest account), preferences including allergies, pantry, saved recipes, subscription state and allowance counters |
| User account registration and authentication | Supabase, Google Sign-In, Sign in with Apple | Your email address and an account identifier |
| Invoicing and billing | Apple, RevenueCat | Purchase, renewal and expiry events. No card details reach us. |
| Content delivery | Cloudinary | Your IP address, because your phone requests recipe images directly |
| Performance monitoring | Sentry | Crash reports and diagnostics. Not tagged with your account, and web addresses are stripped of their query before they are sent, so a crash report cannot carry your dietary filter |
| App delivery, updates and push routing | Expo | Device and push identifiers |
We also may need to share your personal information in the following situations:
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We show no adverts, we use no advertising identifiers, and we do not track you across other apps or websites. There is no offer wall and no advertising network in this app.
In short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
As part of our Services, we offer features powered by artificial intelligence (“AI Products”). The terms in this Privacy Notice govern your use of the AI Products within our Services.
We provide the AI Products through a third-party service provider, OpenAI. Your input, output, and personal information will be shared with and processed by them to enable your use of our AI Products, for the purposes set out in WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?. You must not use the AI Products in any way that violates the terms or policies of that provider.
Our AI Products are designed for the following functions:
All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreement with our provider.
We do not store Scan photographs. The image is sent to identify ingredients and is not saved on our servers. OpenAI keeps a copy for up to 30 days to check for misuse of its service, after which it is deleted. OpenAI does not use anything sent through its API to train or improve its models. One exception applies to everyone: images are automatically screened for child sexual abuse material on submission, and an image the screening flags is kept for human review.
We believe in giving you the power to decide how your data is used. The AI chef and Scan are both optional, and each asks your permission separately before anything is sent. Agreeing to one does not agree to the other — a photograph of your kitchen is a broader disclosure than a typed question, so we ask twice.
You can withdraw either permission at any time: open the app, go to You → Privacy, and turn off AI chef or Scan photos. The feature will ask again before it works. The rest of the app works normally without either.
In short: If you choose to register or log in to our Services using a Google or Apple account, we may have access to certain information about you.
Our Services offer you the ability to register and log in using Sign in with Google or Sign in with Apple. Where you choose to do this, we receive your email address and an account identifier from that provider. We do not receive a friends list, a profile picture, your contacts, or any other content from your account.
We will use the information we receive only for the purposes described in this Privacy Notice. Please note that we do not control, and are not responsible for, other uses of your personal information by Google or Apple. We recommend that you review their privacy notices to understand how they collect, use, and share your personal information.
In short: We may transfer, store, and process your information in countries other than your own.
Our database is hosted by Supabase in Ireland (region eu-west-1). Most of our other providers — OpenAI, RevenueCat, Cloudinary, Sentry and Expo — process information in the United States, and some use sub-processors in other countries.
If you are a resident in the United Kingdom, the European Economic Area, or Switzerland, some of these countries may not have data protection laws as comprehensive as those in your own. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.
We have implemented measures to protect your personal information, including using the European Commission's Standard Contractual Clauses together with the UK Addendum, or the UK International Data Transfer Agreement (IDTA), for transfers between us and our third-party providers. These require all recipients to protect personal information originating from the UK or the EEA in accordance with applicable data protection law. Copies can be provided on request.
In short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. Almost everything we hold is deleted when you delete your account. One small record deliberately outlives it, so that deleting and re-installing cannot be used to claim a second free trial — it is described in full in the table below, and it is erased after twelve months.
| What | How long |
|---|---|
| Your account, preferences, allergies, pantry and saved recipes | While you have an account. Deleting your account deletes them immediately, not on a queue — the row is gone the moment the request completes. Encrypted backups are overwritten within 30 days. |
| Your push notification token | Only while notifications are switched on. Deleted with your account. |
| Allowance counters (AI messages and Scans used this month) | Reset monthly. Deleted with your account. |
| Scan photographs | Not stored by us at all. OpenAI keeps a copy for up to 30 days for misuse checks. |
| AI chef messages | Not kept by us once you have your answer. OpenAI keeps a copy for up to 30 days for misuse checks. |
| Your taste profile | Stored only on your device. It stays there until you reset it in the app, sign out, or delete the app. It is not stored on our servers. |
| Rate-limiting records | Deleted after 1 day. |
| Free-trial record — the one thing that outlives your account |
12 months from the day you delete your account, then erased automatically by a job that runs every night. It contains: a device identifier; the identifier your Apple or Google sign-in gave us, if you used one; the date your free trial started and the date you deleted your account; and how many AI chef messages and Scan photographs you had used.
It exists for one reason — without it, deleting your account and signing up again would hand out a fresh free trial and a fresh AI allowance every time. It is never used to build a profile of you, it is not linked to your recipes, preferences or allergies (those are deleted), and nothing in it is shared with anyone. |
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if this is not possible (for example, because it has been stored in backup archives), we will securely store it and isolate it from any further processing until deletion is possible.
In short: We aim to protect your personal information through a system of organisational and technical security measures.
We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. These include row-level access controls on our database, so one account cannot read another's data; storing your sign-in session in your device's secure keychain; enforcing your AI, Scan and recipe allowances on our servers rather than trusting a counter on your phone; and never letting our AI provider's key reach your device.
However, despite our safeguards, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk.
If a breach ever put your rights or freedoms at high risk, we will tell you, and we will report it to the Information Commissioner's Office where the law requires it.
In short: We do not knowingly collect data from or market to children under 13 years of age.
Bite is not designed for young children. You must be at least 13 years old to create an account, or older if the law where you live sets a higher minimum age for using an online service without a parent's permission. If you are under 18, you should have your parent or guardian's permission to use the app and to buy anything in it.
We do not knowingly collect, solicit data from, or market to children under that age, nor do we knowingly sell such personal information. If we learn that personal information from a user under that age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from a child, please contact us at contact@crescendolabs.co.uk.
In short: Depending on where you live, applicable privacy law may give you rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
In some regions (like the UK, the EEA, Switzerland, and Canada) you have certain rights under applicable data protection law. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure, (iii) to restrict the processing of your personal information, (iv) if applicable, to data portability, and (v) not to be subject to automated decision-making. In certain circumstances you may also have the right to object to processing.
These rights are free to use — we will not charge you — and we will respond within one month. You can make a request by contacting us using the details in HOW CAN YOU CONTACT US ABOUT THIS NOTICE? below.
If you are located in the UK and are unhappy with how we have handled your personal information, you can make a complaint directly to us. This is in addition to your rights under the UK GDPR and the Data Protection Act 2018.
What happens after you complain: we will acknowledge your complaint within 30 days of receiving it, investigate without unjustifiable delay, and keep you informed of progress and the outcome.
You do not have to come to us first. You can complain to the Information Commissioner's Office at any time.
Information Commissioner's OfficeIf you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Where we are relying on your consent to process your personal information, you have the right to withdraw it at any time, and it is as easy to withdraw as it was to give. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
You can withdraw consent yourself, in the app:
Or email us and we will do it for you.
You can opt out at any time by turning off notifications for Bite in your device settings, by using You → Privacy → Notification settings in the app, or by emailing us. We do not send marketing emails. We may still send you service-related messages that are necessary for the administration of your account, such as a notice that these terms have changed.
If you would at any time like to review or change the information in your account, or terminate your account, you can:
Upon your request to terminate your account, we will delete your account and information from our active databases and from your device — including your allergies and dietary preferences, which are removed from the phone as well as the server. The only thing we keep is the free-trial record set out in HOW LONG DO WE KEEP YOUR INFORMATION?, and we may also retain information where we need it to assist with an investigation, enforce our legal terms, or comply with a legal requirement.
If you have questions or comments about your privacy rights, you may email us at contact@crescendolabs.co.uk.
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals.
In practice this changes nothing: we do not track you across other apps or websites at all. California law requires us to tell you how we respond to DNT signals, and this is that statement. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
In short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent. These rights may be limited in some circumstances by applicable law.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Online identifier, Internet Protocol address, email address, and account name | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, and financial information | NO |
| C. Protected classification characteristics under state or federal law | Gender, age, date of birth, race and ethnicity, national origin, marital status | NO |
| D. Commercial information | Transaction information, purchase history, and payment information | YES |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other similar network activity | Interactions with our application | YES |
| G. Geolocation data | Device location | NO |
| H. Audio, electronic, sensory, or similar information | Images created in connection with our business activities | YES — Scan photographs only. No audio, video or call recordings. |
| I. Professional or employment-related information | Job title, work history | NO |
| J. Education information | Student records and directory information | NO |
| K. Inferences drawn from collected personal information | A profile or summary about an individual's preferences | YES — your taste profile, stored only on your device |
| L. Sensitive personal information | Account login information and health data | YES |
We only collect sensitive personal information as permitted by law or with your consent. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories to service providers for a business purpose: A (identifiers), D (commercial information), F (network activity), H (images), and L (sensitive personal information). The service providers who receive them are named in WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?.
Most of it you can do yourself in the app, in the You tab — edit your preferences, reset personalisation, or delete your account. You can also email us at contact@crescendolabs.co.uk, or write to us at the address at the bottom of this notice.
Under certain US state data protection laws, you can designate an authorised agent to make a request on your behalf. We may deny a request from an authorised agent that does not submit proof that they have been validly authorised to act on your behalf.
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity. If we cannot verify your identity from information already held, we may request additional information for verification and fraud-prevention purposes.
If we decline to take action regarding your request, you may appeal by emailing us at contact@crescendolabs.co.uk. A person will review it. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons. If your appeal is denied, you may submit a complaint to your state attorney general.
California Civil Code Section 1798.83 permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. We do not disclose personal information for third parties' direct marketing purposes, so there is nothing to report — but you are welcome to ask, in writing, using the contact details below.
In short: You may have additional rights based on the country you reside in.
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020.
This Privacy Notice satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information.
If you do not wish to provide the personal information necessary to fulfil their applicable purpose, it may affect our ability to offer you the products or services that you want, respond to or help with your requests, manage your account with us, and confirm your identity and protect your account.
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us using the details in HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
If you believe we are unlawfully processing your personal information, you have the right to complain to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
In short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated “Last updated” date at the top of this Privacy Notice. If we make material changes, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. If we ever want to use your information for a genuinely new purpose, we will update this notice and tell you before we start, not afterwards. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
If you have questions or comments about this notice, you may email us at contact@crescendolabs.co.uk or contact us by post at:
Crescendo Labs LimitedWe do not operate a telephone line. Email is monitored and is the fastest way to reach us.
You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.
You can do most of this yourself, in the app, without asking us:
To request anything else, email contact@crescendolabs.co.uk. We will respond within one month, free of charge.
Crescendo Labs Limited · 128 City Road, London EC1V 2NX, United Kingdom · contact@crescendolabs.co.uk
Privacy Policy · Terms of Use · Support · Last updated 10 September 2026