Privacy Policy
Last updated 5 August 2026
RareBites is a real-life food index for iOS. You photograph a dish, the app cuts it out and identifies it, and it joins your collection.
This policy explains what the RareBites iOS app and this website collect, why, and the choices you have. We do not sell your data or use it for advertising or cross-app tracking, and we try to collect as little as possible.
Who we are
RareBites is an independent app built by Florian Burkhardt (the "data controller" under GDPR), trading as Florian Burkhardt Digital Solutions in Aichach, Germany. The full postal address is in the Imprint. For any privacy question or request, contact support@rarebites.app.
What the app collects
Accounts (optional)
You can catch and collect without an account, and most people never need one. If you do sign in, you can use Apple, Google, or an email address and password, and we store a small profile so that it works across devices: your email address, the handle you claim, a display name, an avatar, a title, and an account identifier issued by our authentication provider. With Sign in with Apple you can use Hide My Email, in which case we only ever see the relay address.
Leaderboards and following
Signing in puts you on the leaderboards, and that makes part of your profile public. Your handle, display name, avatar, level, title, and your totals for dishes, catches, countries and the last seven days can be read by any other signed in player. Your individual catches, your photos and the places you ate are not: only the counts are published. You can also follow other players by handle, and the list of who you follow is stored on our server. If you never sign in, none of this exists for you.
Your collection
Your catches, the photos, the cards, your level and XP are stored on your iPhone. The photos and the cards themselves are never uploaded, which also means they do not sync between devices and are gone if you delete the app. Back up your phone if you want to keep them. If you are signed in, the running totals described above are sent to your profile after a catch so the leaderboards stay current.
Photos you take
When you catch a dish, the app uses your camera to take a photo. The dish is cut out from the background on your device, and only that cut-out is sent to our identification service. We do not read your camera roll, and we do not store the images you send — a photo is identified and discarded in the same request.
Saving a sticker
If you save a sticker to Photos, the app asks for add-only access to your photo library. That permission lets it write the one image and nothing else; it cannot read your library.
Device identifier
Each catch is sent with your device's vendor identifier (Apple's identifierForVendor). We use it only to enforce fair-use limits, to prevent abuse and control costs. It is tied to your device, not to your name, and it resets if you delete the app.
Location (optional)
If you grant location permission, a catch is tagged with the coordinates where you made it, so you can see your finds on the map. Those coordinates are also sent with the catch and kept with our usage record of it. If you deny location, RareBites works fully and catches are simply not tagged with a place.
Catch records
For each identification we log a small event, so the service keeps working and we can decide which dishes to add. An event contains: the device identifier above, your subscription identifier, whether you were subscribed, the identified dish name and the confidence, and the optional location. These events never contain your photos.
Subscriptions (RareBites+)
RareBites+ is sold through the Apple App Store. Apple processes your payment, and we never receive your card or payment details. We use RevenueCat to manage subscriptions and receive only your subscription status — for example active or expired, the product, and renewal dates — under an identifier that is not linked to your name.
What the website collects
- No analytics: this site has no analytics, no tracking pixels and no cookies. It does not ask for your email or any personal details.
- Fonts: pages load the Nunito typeface from Google Fonts, so Google receives your IP address when a page loads.
- Server logs: our host keeps standard access logs for security and troubleshooting.
Why we're allowed to use this data (legal bases)
Under the GDPR, we rely on:
- Performance of the service: to identify dishes, run the app, manage your account and subscription, and place you on the leaderboards if you have signed in.
- Consent: for camera access, optional location, and adding to your photo library. You can withdraw consent at any time in iOS Settings.
- Legitimate interests: to keep the service secure, prevent abuse, and improve the app, balanced against your rights.
Who we share data with
We do not sell your data. We share the minimum necessary with service providers ("processors") that help us run RareBites:
- Apple distributes the app, provides Sign in with Apple, and handles App Store subscription billing.
- Google provides Sign in with Google, if you choose it, and serves the typeface used on this website.
- OpenAI processes the cut-out image to identify the dish. OpenAI does not use data submitted through its API to train its models by default.
- Supabase hosts our backend, the sign-in and account system, the profile and leaderboard database, and the function that performs identification.
- RevenueCat manages subscriptions.
Some of these providers may process data outside your country, including in the United States, under appropriate safeguards such as Standard Contractual Clauses.
How long we keep it
- Your collection stays on your device until you delete it or remove the app. We never hold a copy of your photos or cards.
- Account and profile data (email, handle, display name, avatar, leaderboard totals, and who you follow) is kept for as long as the account exists, and is deleted when the account is deleted.
- Your photos are not retained at all — they are discarded as soon as a dish has been identified.
- Catch records are kept only as long as needed to operate and improve the service, then deleted or aggregated.
Your rights
Almost everything stays on your phone. Deleting the app deletes your entire collection, and it also resets the device identifier, which is what ties the remaining catch records to you.
If you created an account, deleting the app does not remove it. Email support@rarebites.app from the address on the account and we will delete the account itself along with your profile, handle, display name, avatar, leaderboard entry and follows. Signing out instead leaves the collection on your phone untouched.
Depending on where you live (for example under the GDPR or California's CCPA/CPRA), you can request access to your data, correction, deletion, a copy of it, or object to certain processing. We do not sell or "share" personal information for cross-context behavioural advertising. To make a request, email support@rarebites.app and we will respond. You may also revoke camera, location or photo permissions at any time in iOS Settings.
Children
RareBites is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
Security
Data is transmitted over encrypted connections (HTTPS/TLS), and our API keys stay on the server rather than inside the app. Access to backend data is restricted by per-user security rules, so you can only change your own profile and your own follows. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your information.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new "last updated" date.
Contact
Questions or requests: support@rarebites.app.