Privacy Policy

Last updated: 10 September 2026

This Privacy Notice for Crescendo Labs Limited (doing business as Bite) (“we”, “us”, or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at contact@crescendolabs.co.uk.

Summary of key points

This summary provides key points from our Privacy Notice. You can find more detail on any of them by following the link after each point, or by using the table of contents below.

What personal information do we process? When you use our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use. Learn more about personal information you disclose to us.

Do we process any sensitive personal information? Yes. The dietary and allergy information you choose to give us is health information, which is treated as “special category” or “sensitive” data in the UK and many other places. We use it for one purpose only: filtering which recipes we show you. Giving it to us is optional, the app works without it, and clearing it stops the processing. We do not collect information about your racial or ethnic origin, sexual orientation, religious beliefs, biometrics, or precise location. Learn more about sensitive information we process.

Do we collect any information from third parties? No. We do not buy personal information, and we do not obtain it from data brokers or marketing lists.

How do we process your information? To provide, improve, and administer our Services, to communicate with you, for security and fraud prevention, and to comply with the law. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.

In what situations and with which parties do we share personal information? With the service providers who run parts of the app for us, listed by name in section 4. We do not sell your personal information, and we do not share it for advertising. Learn more about when and with whom we share your personal information.

How do we keep your information safe? We have organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.

What are your rights? Depending on where you live, applicable privacy law may give you rights over your personal information. Learn more about your privacy rights.

How do you exercise your rights? Most of it you can do yourself in the app, without asking us — open the You tab. You can also email us. We will consider and act on any request in accordance with applicable data protection law.

Table of contents

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on to process your personal information?
  4. When and with whom do we share your personal information?
  5. Do we offer artificial intelligence-based products?
  6. How do we handle your social logins?
  7. Is your information transferred internationally?
  8. How long do we keep your information?
  9. How do we keep your information safe?
  10. Do we collect information from minors?
  11. What are your privacy rights?
  12. Controls for Do-Not-Track features
  13. Do United States residents have specific privacy rights?
  14. Do other regions have specific privacy rights?
  15. Do we make updates to this notice?
  16. How can you contact us about this notice?
  17. How can you review, update, or delete the data we collect from you?

1. What information do we collect?

Personal information you disclose to us

In short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

You get an account whether or not you make one

The first time you open Bite, the app creates a guest account for you automatically and signs you in. You are not asked for an email address, a password or a name, and you never have to create a real account — but the guest account is still an account, with an identifier of its own, and everything described below is stored against it: your preferences and allergies, your fridge contents, your saved recipes, your subscription and your allowance counters.

We say this plainly because “I never signed up” is a reasonable thing to assume means “they hold nothing about me”, and here it does not. What it does mean is that we hold no name, no email address and no way to contact you unless you choose to sign in with Google or Apple later. Your rights below — including deleting everything — apply to the guest account exactly as they do to a registered one, and You → Delete account works without signing in.

Personal information provided by you. The personal information we collect may include the following:

We never ask you for a password. Bite has no email-and-password sign-up: the only ways in are the automatic guest account, Sign in with Google, or Sign in with Apple. So we hold no password of yours to lose, and there is no password for anyone to reset or steal.

Sensitive information. We process one category of sensitive information:

Exactly how and when we ask. During setup we show a screen headed “Any allergies or dietary needs?” with the note “We'll keep these out of your feed.” You can select as many or as few as you like, including none, and continue either way. Whatever you select is saved to your profile on our servers and used to filter the recipe catalogue. There is no separate consent box on that screen, and this notice is not shown to you before it — we are telling you that plainly rather than describing a step that does not exist. You can change or clear your answer at any time in You → Edit preferences; clearing it removes the information and stops the filtering.

Payment data. If you subscribe to Bite Pro, Apple processes the payment through the App Store as merchant of record. Apple takes the payment, handles local taxes and currency, and manages refunds. We never receive or store your card details. From our subscription provider we receive only your account identifier, purchase and renewal events, and the date your subscription expires. You may find Apple's privacy notice here: https://www.apple.com/legal/privacy/.

To manage or cancel your subscription, or to request a refund, use your Apple ID settings or reportaproblem.apple.com.

Social media login data. We give you the option to register using Sign in with Google or Sign in with Apple. If you choose one of these, we receive your email address and an account identifier from that provider — nothing more. We do not receive a friends list, a profile picture, contacts, or any other content from your account. See the section called HOW DO WE HANDLE YOUR SOCIAL LOGINS? below.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Application data

If you use our application, we may also collect the following information if you choose to provide us with access or permission:

This information is primarily needed to maintain the security and operation of our application and for troubleshooting.

Information automatically collected

In short: Some information — such as your IP address and device characteristics — is collected automatically when you use our Services.

We automatically collect certain information when you use the Services. This information does not reveal your specific identity (like your name) but may include device and usage information. It is primarily needed to maintain the security and operation of our Services.

The information we collect includes:

What we do not record. Which recipes you look at, which you skip or hide, which you have cooked, and the taste profile the app builds from your swiping stay on your device. There is nowhere on our servers to put them. If that ever changes we will update this notice before it does, not afterwards.

We do not collect your location. The app never requests location permission and contains no location tracking.

Google API

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Sign-In only to create and access your account. We do not read your Gmail, contacts, calendar or files, we never use this information for advertising, and no human at Crescendo Labs Limited reads it.

2. How do we process your information?

In short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes only with your prior explicit consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

3. What legal bases do we rely on to process your information?

In short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e. legal basis) to do so under applicable law — like with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfil our legitimate business interests.

If you are located in the UK or the EU, this section applies to you.

The UK GDPR and the General Data Protection Regulation (GDPR) require us to explain the valid legal bases we rely on in order to process your personal information. We may rely on the following:

What we do not do

We do not use automated decision-making that produces legal or similarly significant effects. We personalise which recipes you see, but that has no legal or significant effect, and you can clear it at any time in You → Privacy → Reset personalisation.

If you are located in Canada, this section applies to you.

We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.

In some exceptional cases we may be legally permitted under applicable law to process your information without your consent, including for investigations and fraud detection and prevention, for business transactions provided certain conditions are met, if disclosure is required to comply with a subpoena, warrant or court order, or if the information is publicly available and specified by the regulations.

4. When and with whom do we share your personal information?

In short: We may share information in the specific situations described in this section and with the third parties listed below.

Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers or contractors who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with them, designed to safeguard your personal information. This means they cannot do anything with your personal information unless we have instructed them to do it, and they will not share it with any other organisation. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.

The third parties we may share personal information with are as follows:

PurposeProviderWhat they receive
AI service providersOpenAIYour AI chef questions and recipe context; the photograph you take with Scan
Cloud computing and databaseSupabaseYour account (or guest account), preferences including allergies, pantry, saved recipes, subscription state and allowance counters
User account registration and authenticationSupabase, Google Sign-In, Sign in with AppleYour email address and an account identifier
Invoicing and billingApple, RevenueCatPurchase, renewal and expiry events. No card details reach us.
Content deliveryCloudinaryYour IP address, because your phone requests recipe images directly
Performance monitoringSentryCrash reports and diagnostics. Not tagged with your account, and web addresses are stripped of their query before they are sent, so a crash report cannot carry your dietary filter
App delivery, updates and push routingExpoDevice and push identifiers

We also may need to share your personal information in the following situations:

What we never do

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We show no adverts, we use no advertising identifiers, and we do not track you across other apps or websites. There is no offer wall and no advertising network in this app.

5. Do we offer artificial intelligence-based products?

In short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer features powered by artificial intelligence (“AI Products”). The terms in this Privacy Notice govern your use of the AI Products within our Services.

Use of AI technologies

We provide the AI Products through a third-party service provider, OpenAI. Your input, output, and personal information will be shared with and processed by them to enable your use of our AI Products, for the purposes set out in WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?. You must not use the AI Products in any way that violates the terms or policies of that provider.

Our AI Products

Our AI Products are designed for the following functions:

How we process your data using AI

All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreement with our provider.

We do not store Scan photographs. The image is sent to identify ingredients and is not saved on our servers. OpenAI keeps a copy for up to 30 days to check for misuse of its service, after which it is deleted. OpenAI does not use anything sent through its API to train or improve its models. One exception applies to everyone: images are automatically screened for child sexual abuse material on submission, and an image the screening flags is kept for human review.

How to opt out

We believe in giving you the power to decide how your data is used. The AI chef and Scan are both optional, and each asks your permission separately before anything is sent. Agreeing to one does not agree to the other — a photograph of your kitchen is a broader disclosure than a typed question, so we ask twice.

You can withdraw either permission at any time: open the app, go to You → Privacy, and turn off AI chef or Scan photos. The feature will ask again before it works. The rest of the app works normally without either.

6. How do we handle your social logins?

In short: If you choose to register or log in to our Services using a Google or Apple account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using Sign in with Google or Sign in with Apple. Where you choose to do this, we receive your email address and an account identifier from that provider. We do not receive a friends list, a profile picture, your contacts, or any other content from your account.

We will use the information we receive only for the purposes described in this Privacy Notice. Please note that we do not control, and are not responsible for, other uses of your personal information by Google or Apple. We recommend that you review their privacy notices to understand how they collect, use, and share your personal information.

7. Is your information transferred internationally?

In short: We may transfer, store, and process your information in countries other than your own.

Our database is hosted by Supabase in Ireland (region eu-west-1). Most of our other providers — OpenAI, RevenueCat, Cloudinary, Sentry and Expo — process information in the United States, and some use sub-processors in other countries.

If you are a resident in the United Kingdom, the European Economic Area, or Switzerland, some of these countries may not have data protection laws as comprehensive as those in your own. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.

Standard Contractual Clauses

We have implemented measures to protect your personal information, including using the European Commission's Standard Contractual Clauses together with the UK Addendum, or the UK International Data Transfer Agreement (IDTA), for transfers between us and our third-party providers. These require all recipients to protect personal information originating from the UK or the EEA in accordance with applicable data protection law. Copies can be provided on request.

8. How long do we keep your information?

In short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. Almost everything we hold is deleted when you delete your account. One small record deliberately outlives it, so that deleting and re-installing cannot be used to claim a second free trial — it is described in full in the table below, and it is erased after twelve months.

WhatHow long
Your account, preferences, allergies, pantry and saved recipesWhile you have an account. Deleting your account deletes them immediately, not on a queue — the row is gone the moment the request completes. Encrypted backups are overwritten within 30 days.
Your push notification tokenOnly while notifications are switched on. Deleted with your account.
Allowance counters (AI messages and Scans used this month)Reset monthly. Deleted with your account.
Scan photographsNot stored by us at all. OpenAI keeps a copy for up to 30 days for misuse checks.
AI chef messagesNot kept by us once you have your answer. OpenAI keeps a copy for up to 30 days for misuse checks.
Your taste profileStored only on your device. It stays there until you reset it in the app, sign out, or delete the app. It is not stored on our servers.
Rate-limiting recordsDeleted after 1 day.
Free-trial record — the one thing that outlives your account 12 months from the day you delete your account, then erased automatically by a job that runs every night. It contains: a device identifier; the identifier your Apple or Google sign-in gave us, if you used one; the date your free trial started and the date you deleted your account; and how many AI chef messages and Scan photographs you had used.

It exists for one reason — without it, deleting your account and signing up again would hand out a fresh free trial and a fresh AI allowance every time. It is never used to build a profile of you, it is not linked to your recipes, preferences or allergies (those are deleted), and nothing in it is shared with anyone.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if this is not possible (for example, because it has been stored in backup archives), we will securely store it and isolate it from any further processing until deletion is possible.

9. How do we keep your information safe?

In short: We aim to protect your personal information through a system of organisational and technical security measures.

We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. These include row-level access controls on our database, so one account cannot read another's data; storing your sign-in session in your device's secure keychain; enforcing your AI, Scan and recipe allowances on our servers rather than trusting a counter on your phone; and never letting our AI provider's key reach your device.

However, despite our safeguards, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorised third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk.

If a breach ever put your rights or freedoms at high risk, we will tell you, and we will report it to the Information Commissioner's Office where the law requires it.

10. Do we collect information from minors?

In short: We do not knowingly collect data from or market to children under 13 years of age.

Bite is not designed for young children. You must be at least 13 years old to create an account, or older if the law where you live sets a higher minimum age for using an online service without a parent's permission. If you are under 18, you should have your parent or guardian's permission to use the app and to buy anything in it.

We do not knowingly collect, solicit data from, or market to children under that age, nor do we knowingly sell such personal information. If we learn that personal information from a user under that age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from a child, please contact us at contact@crescendolabs.co.uk.

11. What are your privacy rights?

In short: Depending on where you live, applicable privacy law may give you rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.

In some regions (like the UK, the EEA, Switzerland, and Canada) you have certain rights under applicable data protection law. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure, (iii) to restrict the processing of your personal information, (iv) if applicable, to data portability, and (v) not to be subject to automated decision-making. In certain circumstances you may also have the right to object to processing.

These rights are free to use — we will not charge you — and we will respond within one month. You can make a request by contacting us using the details in HOW CAN YOU CONTACT US ABOUT THIS NOTICE? below.

Complaining

If you are located in the UK and are unhappy with how we have handled your personal information, you can make a complaint directly to us. This is in addition to your rights under the UK GDPR and the Data Protection Act 2018.

What happens after you complain: we will acknowledge your complaint within 30 days of receiving it, investigate without unjustifiable delay, and keep you informed of progress and the outcome.

You do not have to come to us first. You can complain to the Information Commissioner's Office at any time.

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom

Helpline: 0303 123 1113
Make a complaint: ico.org.uk/make-a-complaint

If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent

Where we are relying on your consent to process your personal information, you have the right to withdraw it at any time, and it is as easy to withdraw as it was to give. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.

You can withdraw consent yourself, in the app:

Or email us and we will do it for you.

Opting out of marketing and promotional communications

You can opt out at any time by turning off notifications for Bite in your device settings, by using You → Privacy → Notification settings in the app, or by emailing us. We do not send marketing emails. We may still send you service-related messages that are necessary for the administration of your account, such as a notice that these terms have changed.

Account information

If you would at any time like to review or change the information in your account, or terminate your account, you can:

Upon your request to terminate your account, we will delete your account and information from our active databases and from your device — including your allergies and dietary preferences, which are removed from the phone as well as the server. The only thing we keep is the free-trial record set out in HOW LONG DO WE KEEP YOUR INFORMATION?, and we may also retain information where we need it to assist with an investigation, enforce our legal terms, or comply with a legal requirement.

If you have questions or comments about your privacy rights, you may email us at contact@crescendolabs.co.uk.

12. Controls for Do-Not-Track features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals.

In practice this changes nothing: we do not track you across other apps or websites at all. California law requires us to tell you how we respond to DNT signals, and this is that statement. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

13. Do United States residents have specific privacy rights?

In short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent. These rights may be limited in some circumstances by applicable law.

Categories of personal information we collect

CategoryExamplesCollected
A. IdentifiersOnline identifier, Internet Protocol address, email address, and account nameYES
B. Personal information as defined in the California Customer Records statuteName, contact information, education, employment, and financial informationNO
C. Protected classification characteristics under state or federal lawGender, age, date of birth, race and ethnicity, national origin, marital statusNO
D. Commercial informationTransaction information, purchase history, and payment informationYES
E. Biometric informationFingerprints and voiceprintsNO
F. Internet or other similar network activityInteractions with our applicationYES
G. Geolocation dataDevice locationNO
H. Audio, electronic, sensory, or similar informationImages created in connection with our business activitiesYES — Scan photographs only. No audio, video or call recordings.
I. Professional or employment-related informationJob title, work historyNO
J. Education informationStudent records and directory informationNO
K. Inferences drawn from collected personal informationA profile or summary about an individual's preferencesYES — your taste profile, stored only on your device
L. Sensitive personal informationAccount login information and health dataYES

We only collect sensitive personal information as permitted by law or with your consent. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you.

How long we keep each category

Sale, sharing, and disclosure

We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories to service providers for a business purpose: A (identifiers), D (commercial information), F (network activity), H (images), and L (sensitive personal information). The service providers who receive them are named in WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?.

Your rights

The three opt-outs, and why they are empty

How to exercise your rights

Most of it you can do yourself in the app, in the You tab — edit your preferences, reset personalisation, or delete your account. You can also email us at contact@crescendolabs.co.uk, or write to us at the address at the bottom of this notice.

Under certain US state data protection laws, you can designate an authorised agent to make a request on your behalf. We may deny a request from an authorised agent that does not submit proof that they have been validly authorised to act on your behalf.

Request verification

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity. If we cannot verify your identity from information already held, we may request additional information for verification and fraud-prevention purposes.

Appeals

If we decline to take action regarding your request, you may appeal by emailing us at contact@crescendolabs.co.uk. A person will review it. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons. If your appeal is denied, you may submit a complaint to your state attorney general.

California “Shine the Light” law

California Civil Code Section 1798.83 permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes, and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. We do not disclose personal information for third parties' direct marketing purposes, so there is nothing to report — but you are welcome to ask, in writing, using the contact details below.

14. Do other regions have specific privacy rights?

In short: You may have additional rights based on the country you reside in.

Australia and New Zealand

We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020.

This Privacy Notice satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information.

If you do not wish to provide the personal information necessary to fulfil their applicable purpose, it may affect our ability to offer you the products or services that you want, respond to or help with your requests, manage your account with us, and confirm your identity and protect your account.

At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us using the details in HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

If you believe we are unlawfully processing your personal information, you have the right to complain to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.

15. Do we make updates to this notice?

In short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated “Last updated” date at the top of this Privacy Notice. If we make material changes, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. If we ever want to use your information for a genuinely new purpose, we will update this notice and tell you before we start, not afterwards. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

16. How can you contact us about this notice?

If you have questions or comments about this notice, you may email us at contact@crescendolabs.co.uk or contact us by post at:

Crescendo Labs Limited
128 City Road
London EC1V 2NX
United Kingdom

We do not operate a telephone line. Email is monitored and is the fastest way to reach us.

17. How can you review, update, or delete the data we collect from you?

You have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.

You can do most of this yourself, in the app, without asking us:

To request anything else, email contact@crescendolabs.co.uk. We will respond within one month, free of charge.


Crescendo Labs Limited · 128 City Road, London EC1V 2NX, United Kingdom · contact@crescendolabs.co.uk
Privacy Policy · Terms of Use · Support · Last updated 10 September 2026