bocco

Privacy Policy

Last updated: 24 July 2026

Bocco is an AI calorie-counting app. This Privacy Policy explains what personal data we collect, why we collect it, who processes it, and the rights you have over it. We've tried to keep it in plain language.

Bocco is operated by Artem Grebenkin, an individual based in Dubai, United Arab Emirates (“Bocco”, “we”, “us”). Although we are based in the UAE, we offer Bocco to people in the European Union (including Italy), so the EU General Data Protection Regulation (GDPR) applies and EU users have the rights described below.

1. Who we are & how to contact us

The data controller is Artem Grebenkin, the sole developer of Bocco, based in Dubai, United Arab Emirates. For any privacy question or request, email support@bocco.app. As a small, independent operation we don't have a separate Data Protection Officer; the controller handles all requests personally.

2. What data we collect, why, and our legal basis

We only collect what Bocco needs to work. Under the GDPR, each use of your data has a “legal basis” โ€” we've noted it for each group.

3. AI photo & text analysis (Google Gemini)

When you log a meal by photo or by description, Bocco sends that photo and/or text from our backend server to the Google Gemini API, which estimates the food and its nutrition and returns the result to us. This happens server-side โ€” your app talks to Bocco, and Bocco talks to Google, not your phone directly. We send only what's needed for the estimate (the meal photo or description). Google processes it under its API terms. We keep the resulting nutrition estimate as part of your meal log; we don't use your photos for advertising and we don't sell them.

4. Who processes your data for us

We use a small number of trusted service providers to run Bocco. They process data only to provide their service to us:

ProviderWhat they doWhere
Google (Gemini API)AI nutrition analysis of meal photos & textUSA
Apple (Sign in with Apple)Account sign-inUSA
Google (Google Sign-In)Account sign-inUSA
MongoDB AtlasDatabase โ€” stores your account, profile & logsCloud (EU/US region)
Google (Firebase Analytics)App usage analytics (feature-usage events from the iOS app)USA
PostHogProduct analytics & session replay (masked) from the iOS appEU
Google (Firebase Crashlytics)Crash & error diagnostics from the iOS appUSA
RevenueCatSubscription status (runs in the iOS app)USA
ResendSends account emails (e.g. the welcome email)USA
RailwayApplication hostingUSA
CloudflareDNS, HTTPS & security (WAF)Global
USDA FoodData CentralPublic food-nutrition lookupsUSA (public dataset)

The bocco.app website uses no advertising or analytics trackers and sets no tracking cookies. The Bocco app uses Google Firebase Analytics, PostHog (including masked session replay) and Firebase Crashlytics as described in section 2 โ€” used only to improve Bocco and keep it working, never for third-party advertising, and never sold.

5. International data transfers

Because we are based in the UAE and some of our providers are in the United States (for example Google/Gemini, Firebase Analytics, Firebase Crashlytics, Apple, Google Sign-In, RevenueCat, Resend and Railway), your data may be transferred outside your country, including outside the European Economic Area. PostHog is the exception: we use its European hosting, so its data stays in the EU. Where that happens for EU users, we rely on the providers' appropriate safeguards (such as Standard Contractual Clauses or equivalent data-transfer frameworks). You can ask us for more detail at support@bocco.app.

6. How long we keep your data

We keep your account and the data in it for as long as your account is active. Sign-in sessions expire after 60 days. When you delete your account (in the app's settings), we erase your data. Waitlist emails are kept until we've told you Bocco has launched, and we'll remove yours sooner on request.

7. Your privacy rights

If you are in the EU/EEA (and in many cases wherever you are), you have the right to: access the data we hold about you; correct it; delete it (the “right to be forgotten”); restrict or object to how we use it; receive a copy in a portable format; and withdraw consent at any time (for example for your health profile). To exercise these:

A self-service data export isn't available yet, but you can request a copy of your data by email and we'll provide it. If you are in the EU, you also have the right to lodge a complaint with your local data protection authority โ€” in Italy, the Garante per la protezione dei dati personali.

8. Children

Bocco isn't intended for children. You must be at least 16 to use it. We don't knowingly collect data from anyone under 16; if you believe a child has given us their data, email support@bocco.app and we'll delete it.

9. How we protect your data

Passwords are stored only as bcrypt hashes; traffic to Bocco is encrypted over HTTPS; and access to our database is restricted. No online service can be 100% secure, but we take reasonable steps to protect your data.

10. Changes to this policy

We may update this policy as Bocco evolves. When we make material changes, we'll update the “Last updated” date at the top and, where appropriate, let you know in the app.

11. Contact

Questions about this policy or your data? Email support@bocco.app. See also our Terms of Service.