Ate That

Privacy Policy

Ate That stores the account, subscription, meal, and nutrition information needed to provide and synchronise the service. Submitted audio recordings are not retained. Audio recordings awaiting your review remain only on your device, and data from Apple Health is not sent to our servers or OpenAI.

Effective: August 28, 2026

Who We Are

Ate That is provided by Thalassa Softwaraki LTD, a company registered in Cyprus as HE 466541 (VAT 60106502M), based in Limassol, Cyprus. Thalassa Softwaraki LTD is the controller of the personal data described in this policy.

This policy applies to the Ate That iOS app and the online services used by the app.

What We Store

Ate That stores the following categories of information:

  • your account identifier and any email address shared through Sign in with Apple;
  • your subscription status and App Store transaction information;
  • your synchronised meal history, text descriptions, and nutrition results;
  • food corrections and nutrition values you choose for foods; and
  • service information needed for security, reliability, support, and abuse prevention.

Submitted audio recordings are not stored by Ate That. Audio recordings awaiting review may remain locally on your device until you retry or delete them, or remove the app.

Your Account and Subscription

An Ate That account is created when you use Sign in with Apple. Apple gives us a developer-specific identifier and, if you choose to share it, your email address. The address may be an Apple private relay address. We do not receive your Apple Account password.

We store an internal account ID, the Apple identifier, the email information Apple provides, encrypted credentials needed to maintain your connection to Apple, and sign-in session information. The app stores its sign-in credential in the iOS Keychain. See Sign in with Apple & Privacy for information about Apple's processing.

If you subscribe, we store your subscription product, status, purchase and expiration dates, renewal status, trial or offer information, and App Store transaction identifiers. Apple processes your payment. Ate That does not receive or store your payment-card details.

Meal History and Synchronisation

Your meal history is stored with your Ate That account and synchronised to the app. A local copy is cached on your device. Meal history may include meal titles, food items, quantities, preparation and food variants, estimated calories and nutrients, timestamps, text descriptions, edits, and deletion status.

When you delete a meal, it is removed from your active meal history. Ate That may keep a minimal deletion record so that the deletion can be synchronised across your devices. This record is removed when you delete your account.

Voice Entries and Nutrition Results

When you submit a voice entry, the audio is sent securely through Ate That to OpenAI to create a text description. The submitted audio is used only to fulfil that request and is not retained by Ate That. If an entry needs your review, the app may keep its local audio recording on your device so that you can replay, retry, replace, or delete it.

Ate That stores the resulting text description and nutrition result with your account. For meal creation and editing, we also retain the submitted text or edit context, generated nutrition information, and available error information. We use this information to provide meal history, investigate incorrect or failed results, improve reliability, and respond to support requests.

OpenAI processes submitted audio and text as our service provider. OpenAI states that API data is not used to train its models by default unless the customer opts in. Under OpenAI's standard API controls, audio transcription requests are not retained, while text request content may be kept in abuse-monitoring logs for up to 30 days. Learn more in OpenAI's API data controls.

Food Catalogue

To make nutrition estimates more consistent, Ate That maintains a shared food catalogue containing food names, brands, preparation and food variants, and nutrition values. Shared catalogue entries do not contain your account ID, audio recordings, meal timestamps, or meal history.

If you suggest a nutrition correction, Ate That may combine it with suggestions from other users to improve future estimates. Your correction and any nutrition value you choose for a food are stored with your account until you delete it. Information added to the shared catalogue does not identify who suggested a correction and may remain after account deletion.

Technical Service Data

Ate That stores limited technical information about requests made by your account, such as request identifiers, timestamps, app version and build number, response status, error information, processing duration, and service usage. We use this information to secure the service, investigate failures, provide support, enforce usage limits, prevent misuse, and manage service capacity and costs.

Our infrastructure providers may also process technical information such as IP address, network and device information, and service logs for delivery, security, troubleshooting, and abuse prevention.

Apple Health

Apple Health export is optional and requires your permission. If enabled, Ate That writes its estimates for dietary energy, protein, fat, carbohydrates, and alcohol to Apple Health. Ate That does not request access to read your other Apple Health data. It asks Apple Health to update or delete samples created by Ate That when you sync, edit, or delete a meal.

Health data is handled through Apple's HealthKit framework and is not sent to our servers or OpenAI. You can change Ate That's Health access in iOS Settings or the Health app.

How We Use Data and Our Legal Bases

We process personal data only as needed to:

  • create and secure your account, manage your subscription, and provide meal logging, estimation, editing, and synchronisation;
  • authenticate requests, maintain sessions, and respond to support requests;
  • evaluate results, diagnose failures, protect the service, prevent abuse, and manage capacity and costs; and
  • comply with legal obligations and enforce our terms.

Where EU or EEA law applies, we rely on performance of our contract with you to provide the service, our legitimate interests in operating and securing it, your consent for optional Apple Health access, and legal obligations where applicable. You may withdraw Health permission at any time without affecting earlier processing.

Service Providers and International Processing

We use the following providers to operate Ate That:

  • Apple for Sign in with Apple, subscriptions and payment processing, HealthKit, App Store distribution, and diagnostics you choose to share;
  • Google Cloud for backend compute, database hosting, backups, networking, and operational logging; and
  • OpenAI for audio-to-text conversion and meal estimation or editing.

These providers may process data outside Cyprus or the EEA. Where required, we rely on contractual and other lawful safeguards for international transfers. Provider processing is also governed by their terms and privacy notices, including the Google Cloud Privacy Notice and OpenAI's API data controls linked above.

We do not sell personal data, share it for cross-context behavioural advertising, or disclose it to advertisers.

Retention

Your account information, synchronised meal history, text descriptions, nutrition results, corrections, and nutrition values you choose for foods are generally retained while your account is active. Individual meals are retained until you delete them. Minimal meal deletion records may remain until you delete your account so that deletions can be synchronised. Active app sessions expire after 30 days and may be replaced or revoked sooner.

Submitted audio recordings are not retained by Ate That. Audio recordings awaiting review remain on your device until you retry or delete them, or remove the app. Technical service information and OpenAI's processing may have separate limited retention as described in this policy and the linked provider notices.

Subscription and App Store transaction information is retained while needed to provide subscription access, prevent fraud, resolve payment or entitlement issues, and meet legal, tax, or accounting obligations.

When you delete your account, your account, sessions, synchronised meal history, text descriptions, nutrition results, and account-linked corrections are deleted from the active database. Shared food information that does not identify you may remain. Residual copies may remain in protected rotating database backups until they are overwritten; we currently retain seven backup copies. We may retain information longer where required by law or necessary to establish, exercise, or defend legal claims.

Security

We use technical and organisational safeguards appropriate to the data we process. These include encrypted network connections, encrypted Apple credentials, hashed app refresh tokens, restricted production access, and managed cloud security controls. No method of storage or transmission can be guaranteed completely secure.

Analytics and Tracking

Ate That does not include third-party advertising or behavioural analytics SDKs and does not track you across other companies' apps or websites. Apple may provide standard App Store, TestFlight, performance, and crash diagnostic information according to your Apple settings.

Your Choices and Rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, receive a portable copy, and withdraw consent. To make a request, email ops@thalassa.dev. We may need to verify your identity before completing a request.

You also have the right to lodge a complaint with a data protection authority. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.

Deleting Your Data

You can delete individual meals from Ate That. The meal is removed from your synchronised history and local cache. If Apple Health export is enabled, Ate That also attempts to remove the Health samples it created for that meal.

You can delete your Ate That account from Settings. Account deletion removes your server-side account and account-linked data as described under Retention and signs you out. The app may retain its local cache on that device after account deletion. Removing the app deletes that local cache and any audio recordings awaiting review.

Changes to This Policy

We may update this policy as Ate That changes. We will post the revised policy here, update its effective date, and provide additional notice in the app when a change is material.

Contact

For privacy questions or requests, contact ops@thalassa.dev.

Thalassa Softwaraki LTD
Limassol, Cyprus
Registration HE 466541 · VAT 60106502M