Privacy Policy
Last updated: 24 July 2026
Bocco is an AI calorie-counting app. This Privacy Policy explains what personal data we collect, why we collect it, who processes it, and the rights you have over it. We've tried to keep it in plain language.
Bocco is operated by Artem Grebenkin, an individual based in Dubai, United Arab Emirates (“Bocco”, “we”, “us”). Although we are based in the UAE, we offer Bocco to people in the European Union (including Italy), so the EU General Data Protection Regulation (GDPR) applies and EU users have the rights described below.
1. Who we are & how to contact us
The data controller is Artem Grebenkin, the sole developer of Bocco, based in Dubai, United Arab Emirates. For any privacy question or request, email support@bocco.app. As a small, independent operation we don't have a separate Data Protection Officer; the controller handles all requests personally.
2. What data we collect, why, and our legal basis
We only collect what Bocco needs to work. Under the GDPR, each use of your data has a “legal basis” โ we've noted it for each group.
- Waitlist (before launch): your email address and your device language. Purpose: to email you once, when Bocco launches. Legal basis: your consent.
- Your account: your email address and a unique identifier from your sign-in provider when you sign in with Apple or Google; if you register with email, a securely hashed (bcrypt) version of your password โ we never store your password in readable form. Purpose: to create and secure your account. Legal basis: performance of our contract with you.
- Your health & goal profile: your sex, date of birth, height, weight, activity level and goal (lose / maintain / gain), and optionally a goal weight, a pregnancy or breastfeeding status, and a free-text note about any medical condition you choose to tell us. Purpose: to calculate your personal calorie and macronutrient targets. Some of this is health data โ a “special category” under GDPR Article 9 โ which we process only with your explicit consent, given when you enter it. You can withdraw that consent at any time by deleting your account.
- Your meals & food data: the meals you log (food names, weights/portions, calories and macros, the meal type, the date and time, and the AI's notes/assumptions), any weigh-ins (weight and date), and any custom foods or saved meals you create. Purpose: to show your daily log, totals and trends, and to let you re-log meals in one tap. Legal basis: performance of our contract with you.
- Food photos: when you log a meal by photo, the image you upload. Purpose: to estimate the food and its nutrition (see section 3). Legal basis: our contract with you, plus your explicit consent for the health-related estimate.
- Basic technical data: like any web service, our hosting and security providers process limited technical information (such as your IP address) to deliver and protect the service. We do not use this to track you across other sites.
- App usage analytics (Google Firebase): the Bocco iOS app records how the app is used โ events such as viewing an onboarding screen, signing in, viewing the subscription screen, starting a trial, scanning or logging a meal โ together with your answers to a few onboarding questions (how you found Bocco, whether you've counted calories before, what matters most to you, your goal and diet style), basic device information (device model, iOS version, app version), a random app identifier, and a derived audience label based on your age group, sex and goal. These events are tied to that random identifier, not to your name or email, and they never include your meal photos, your meals, or your weight and height. Our subscription provider (RevenueCat) receives the same identifier so a subscription can be attributed to the same app install. Purpose: to understand which features are used and where people get stuck, so we can improve Bocco. Legal basis: our legitimate interest in improving Bocco. We do not use this data for advertising and we never sell it.
- Product analytics & session replay (PostHog): the app sends the same usage events described above to PostHog, whose servers are in the European Union. Once you sign in, these events are linked to your Bocco account identifier (not to your name or email) so that a funnel can be followed across your devices; signing out unlinks them again. PostHog also records session replays โ a reconstruction of what the screen looked like as you moved through the app โ in which everything you type and every image, including your meal photos, is masked out on your device before the replay is sent. Purpose: to see where people get stuck and fix it. Legal basis: our legitimate interest in improving Bocco. We never use it for advertising and we never sell it.
- Crash & error diagnostics (Google Firebase Crashlytics): when the app crashes or runs into a handled error, we receive a diagnostic report โ the type of error, where in the app it happened, a short trail of the preceding steps, and basic device information (device model, iOS version, app version). These reports never contain your meal photos, your meals, or your health profile. Purpose: to find and fix bugs. Legal basis: our legitimate interest in keeping Bocco working.
3. AI photo & text analysis (Google Gemini)
When you log a meal by photo or by description, Bocco sends that photo and/or text from our backend server to the Google Gemini API, which estimates the food and its nutrition and returns the result to us. This happens server-side โ your app talks to Bocco, and Bocco talks to Google, not your phone directly. We send only what's needed for the estimate (the meal photo or description). Google processes it under its API terms. We keep the resulting nutrition estimate as part of your meal log; we don't use your photos for advertising and we don't sell them.
4. Who processes your data for us
We use a small number of trusted service providers to run Bocco. They process data only to provide their service to us:
| Provider | What they do | Where |
|---|---|---|
| Google (Gemini API) | AI nutrition analysis of meal photos & text | USA |
| Apple (Sign in with Apple) | Account sign-in | USA |
| Google (Google Sign-In) | Account sign-in | USA |
| MongoDB Atlas | Database โ stores your account, profile & logs | Cloud (EU/US region) |
| Google (Firebase Analytics) | App usage analytics (feature-usage events from the iOS app) | USA |
| PostHog | Product analytics & session replay (masked) from the iOS app | EU |
| Google (Firebase Crashlytics) | Crash & error diagnostics from the iOS app | USA |
| RevenueCat | Subscription status (runs in the iOS app) | USA |
| Resend | Sends account emails (e.g. the welcome email) | USA |
| Railway | Application hosting | USA |
| Cloudflare | DNS, HTTPS & security (WAF) | Global |
| USDA FoodData Central | Public food-nutrition lookups | USA (public dataset) |
The bocco.app website uses no advertising or analytics trackers and sets no tracking cookies. The Bocco app uses Google Firebase Analytics, PostHog (including masked session replay) and Firebase Crashlytics as described in section 2 โ used only to improve Bocco and keep it working, never for third-party advertising, and never sold.
5. International data transfers
Because we are based in the UAE and some of our providers are in the United States (for example Google/Gemini, Firebase Analytics, Firebase Crashlytics, Apple, Google Sign-In, RevenueCat, Resend and Railway), your data may be transferred outside your country, including outside the European Economic Area. PostHog is the exception: we use its European hosting, so its data stays in the EU. Where that happens for EU users, we rely on the providers' appropriate safeguards (such as Standard Contractual Clauses or equivalent data-transfer frameworks). You can ask us for more detail at support@bocco.app.
6. How long we keep your data
We keep your account and the data in it for as long as your account is active. Sign-in sessions expire after 60 days. When you delete your account (in the app's settings), we erase your data. Waitlist emails are kept until we've told you Bocco has launched, and we'll remove yours sooner on request.
7. Your privacy rights
If you are in the EU/EEA (and in many cases wherever you are), you have the right to: access the data we hold about you; correct it; delete it (the “right to be forgotten”); restrict or object to how we use it; receive a copy in a portable format; and withdraw consent at any time (for example for your health profile). To exercise these:
- The fastest way to erase everything is to delete your account in the app โ this wipes your data.
- For anything else, email support@bocco.app and we'll respond.
A self-service data export isn't available yet, but you can request a copy of your data by email and we'll provide it. If you are in the EU, you also have the right to lodge a complaint with your local data protection authority โ in Italy, the Garante per la protezione dei dati personali.
8. Children
Bocco isn't intended for children. You must be at least 16 to use it. We don't knowingly collect data from anyone under 16; if you believe a child has given us their data, email support@bocco.app and we'll delete it.
9. How we protect your data
Passwords are stored only as bcrypt hashes; traffic to Bocco is encrypted over HTTPS; and access to our database is restricted. No online service can be 100% secure, but we take reasonable steps to protect your data.
10. Changes to this policy
We may update this policy as Bocco evolves. When we make material changes, we'll update the “Last updated” date at the top and, where appropriate, let you know in the app.
11. Contact
Questions about this policy or your data? Email support@bocco.app. See also our Terms of Service.