Privacy Policy
Brocco helps you keep a food journal. This page explains what data we collect, why, who we share it with and what your rights are.
1. Who is responsible
The data controller is Onofrei Alexandru. You can reach us at any time at [email protected].
2. What we collect
- Account: your email address and password (stored only in hashed form), or the identifier we receive when you sign in with Apple.
- Profile: display name, sex, age, height, current and target weight, activity level, goal, allergies and meal preferences.
- Journal: meals, foods and amounts, water, logged weights, saved foods and recipes.
- Photos: a photo of a meal or a label reaches our server and our AI provider only to be analyzed. We do not keep it after the analysis. We keep the result: the recognized foods and estimated values.
- The barcodes you scan.
- Notifications: your phone’s notification identifier, its time zone and language, when you last opened the app and which notifications we sent you, so reminders arrive at the right time and not too often. You only get Brocco Plus offers if you turn them on in Profile › Notifications.
- Game progress: XP, level, streak, quests, badges, coins, chests and Brocco’s outfits.
- Your Brocco Plus subscription: type, period and status, received from Apple through RevenueCat. We never see your card details.
- Technical data: error logs and AI feature usage logs (time, type of analysis, duration), to fix bugs and prevent abuse.
3. Apple Health
If you turn on the connection, Brocco reads your weight, steps and active energy from Health and writes the calories, macronutrients, water and weight from your journal.
Data read from Health stays on your phone: we do not send it to our server, use it for advertising or sell it. You can turn off access at any time in Settings › Health.
4. Why we use your data
- To provide the app (performance of a contract): your account, journal, targets, photo analysis, quests and subscription.
- Health data (weight, allergies, what you eat) is sensitive data. We process it only with your explicit consent, which you give when you enter it in the app. You can withdraw it at any time by deleting the data or your account.
- For security and abuse prevention (legitimate interest): daily scan limits and error logs.
- To comply with legal obligations, such as accounting, where applicable.
We do not use your data for advertising, build marketing profiles or sell data.
5. Who we share it with
- Supabase: hosts our database and accounts on servers in the European Union (Ireland).
- OpenAI: receives the photo or text to analyze. Under its API terms, it does not use this data to train its models.
- RevenueCat: keeps track of your Brocco Plus subscription using an account identifier.
- Apple: App Store payments, Sign in with Apple and Apple Health.
- Open Food Facts: receives only the barcode or search text, with no data about you.
- Expo: delivers push notifications to Apple, using your phone’s notification identifier.
These providers process data only on our behalf, under data processing agreements.
6. Transfers outside the EU
Some providers (OpenAI, Google, RevenueCat, Apple) may process data in the United States. These transfers rely on the EU-U.S. Data Privacy Framework or on the Standard Contractual Clauses approved by the European Commission.
7. How long we keep data
- For as long as you have an account. When you delete it (Profile › Delete account), we delete your account, profile, journal, progress and the foods and recipes you created. Backups are overwritten within 30 days.
- We do not keep photos at all.
- Subscription records may be kept for as long as the law requires.
8. Your rights
You have the right to access, correct (much of it directly in the app), delete, restrict and port your data, to object to processing and to withdraw your consent.
Write to us at [email protected] and we will answer within one month. You can also lodge a complaint with your data protection authority; in Romania, that is ANSPDCP (www.dataprotection.ro).
9. Children
If you are under 16, use Brocco only with the consent of a parent or guardian. If we learn that a child’s account was created without consent, we will delete it.
10. Security
Data travels encrypted (HTTPS). In our database, each account can only see its own data. AI service keys live only on the server, never in the app.
11. Changes
If we change this policy, we update the date above. For important changes, we let you know in the app.