Cotto — Privacy Policy
Point Six Labs (“we”, “us”) operates the Cotto mobile app. This policy explains what personal data Cotto processes, why, on what legal basis, who it is shared with, and the rights you have. We are the data controller for the processing described here.
Cotto is a nutrition-tracking app. Some of the data it handles — what you eat, your body weight, your calorie goals — is personal and health-adjacent, so we have written this policy to be specific about where that data actually goes.
1. Quick summary
- Your food log, saved recipes, body weight, and goals live on your device first. The app works this way whether or not you create an account.
- If you create an account, that data also syncs to our cloud backend (Supabase) so you can restore it on another device. Using Cotto as a guest keeps everything on-device only, with no cloud sync.
- When you scan a meal photo or type a meal description, that photo or text is sent to Google’s Gemini AI (through our backend) to estimate the nutrition. It is used to produce the estimate and is not stored by us for that purpose.
- Meal photos are not uploaded to our cloud database. They stay on your device; only the estimate is stored.
- We use privacy-first, EU-hosted product analytics (PostHog) that record which features are used — never what you ate, your weight, or your goals. You can turn analytics off in Settings.
- Subscriptions are handled by Google Play and RevenueCat. We never see or store your card details.
2. Data residency
Cotto is operated from the European Union and is configured for EU data processing:
- Cloud database and accounts (Supabase): hosted in the EU.
- Product analytics (PostHog): the EU region (
eu.i.posthog.com).
Some subprocessors are global providers (Google, RevenueCat) and may process limited data outside the EU under the safeguards described in Section 7. Where that happens, it is governed by the appropriate transfer mechanisms (such as the EU Standard Contractual Clauses) operated by those providers.
3. What we collect, why, and the legal basis
We only process what the app needs to function. We do not sell your data and we do not use it for advertising.
3.1 Account data
- What: your email address and an encrypted password credential (handled by our authentication provider — we never store your password in readable form).
- Why: to create and secure your account and to sync your data across devices.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
3.2 Your nutrition and body data
- What: meals you log (dish name, calories, protein, carbs, fat, meal type, time), saved recipes, body weight entries, and your goal settings (calorie target, goal type, activity level, units).
- Why: the core function of the app — to record and show your food log, trends, and progress.
- Where: stored locally on your device always. With an account it also syncs to our EU cloud database so you can restore it. Guests keep it on-device only.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Because weight and dietary intake can reveal information about your health, where this is treated as special-category data we rely on your explicit consent (Art. 9(2)(a) GDPR), which you give by choosing to enter it and, for cloud sync, by creating an account. You can withdraw it by deleting the data or your account (Section 6).
3.3 Meal photos
- What: photos you take to scan a meal.
- Why: to estimate the meal’s nutrition using AI.
- Where: the photo is sent to our backend and on to Google Gemini to produce the estimate (Section 3.5). The photo is kept on your device; it is not stored in our cloud database. A local file reference may be saved so the app can show the photo next to the entry on your device.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR); explicit consent for any health-related content (Art. 9(2)(a) GDPR).
3.4 Typed meal descriptions
- What: text you type describing what you ate.
- Why: to parse it into food items and estimate nutrition.
- Where: sent to our backend and on to Google Gemini for parsing.
- Legal basis: as Section 3.3.
3.5 AI processing (Google Gemini)
When you scan a photo or type a description, our backend forwards the photo or the text to Google’s Gemini API to generate the nutrition estimate. Only the photo or text needed for that request is sent. The AI credential used for this is held only as a server-side secret in our backend and is never included in the app. Google processes this data as our subprocessor to return the estimate (Section 7).
3.6 Barcode lookups (Open Food Facts)
- What: when you scan a product barcode, the barcode number is sent to the Open Food Facts database to retrieve product nutrition information.
- What is not sent: no account information, photos, or body data.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
3.7 A device identifier for abuse prevention
- What: the app generates a random device identifier (not linked to your name) and sends it with scan/parse requests so our backend can rate-limit usage and prevent abuse of the AI service.
- Legal basis: our legitimate interest in keeping the service available and preventing abuse (Art. 6(1)(f) GDPR). It is a random value, not your account id, and is not shared with the AI provider for identification.
3.8 Subscriptions and billing
- What: if you subscribe, purchase and entitlement status is processed by Google Play Billing and by RevenueCat (our subscription-management provider). Your account identifier is shared with RevenueCat so your subscription follows your account.
- What we never receive: your payment card or bank details. Those stay with Google.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
3.9 Product analytics (PostHog)
- What: anonymous, event-level usage analytics recording that
actions happen — not their content. The complete list of events we record is:
app_opened,onboarding_step_viewed,onboarding_completed,scan_started,scan_completed(method, success, duration only),correction_made,recipe_recalled,scan_clarified,meal_logged(method only),paywall_shown. - What we never attach: your weight, calorie counts, macro values, food names, photos, goals, or anything describing what you ate or your body. Event properties are limited to structural values such as the input method (camera / text / barcode), whether an action succeeded, and how long it took.
- Identity: events are associated with your account identifier once you sign in (the same identifier used for sync and subscriptions). No email, name, or other profile trait is attached.
- Region: the EU PostHog region.
- Legal basis: your consent (Art. 6(1)(a) GDPR). Analytics is on by default and you can turn it off at any time in Settings → Share anonymous analytics; when off, no events are sent.
3.10 On-device storage
Your session token and the random device identifier are stored securely on your device (in the platform secure store). Your food log and settings are stored in a local database on your device.
4. What we do NOT do
- We do not sell your personal data.
- We do not use your data for third-party advertising or ad targeting.
- We do not put your health, food, body, or goal data into analytics events.
- We do not store your meal photos in our cloud database.
- We do not store your payment card details.
5. Retention
- On-device data remains until you delete individual entries, clear the app’s data, sign out (which clears local data), or uninstall the app.
- Cloud account data (for account holders) is retained for as long as your account exists. When you delete your account, the associated records (entries, saved recipes, weight logs, settings) are deleted.
- AI request content (a photo or text sent for a single estimate) is processed to return that estimate and is not retained by us in our database. Google’s handling of API request data is governed by its own terms as our subprocessor.
- Analytics events are retained by PostHog according to our project’s retention configuration.
6. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time.
In the app you can already:
- Access / view all your data (visible in the app and stored on your device).
- Edit or delete individual meals, recipes, and weight entries.
- Delete everything via Settings → Clear all data.
- Turn off analytics via Settings → Share anonymous analytics.
- Sign out, which clears the local copy of your data from the device.
To exercise any right that the in-app controls do not cover — including a full export or the deletion of your cloud account and its data — contact us at pointsixlabs@gmail.com and we will respond within one month. You also have the right to lodge a complaint with your local data protection authority.
7. Third-party subprocessors
| Provider | Purpose | Data it receives |
|---|---|---|
| Supabase | Accounts, authentication, cloud database (EU-hosted) | Email, and — for account holders — meals, saved recipes, weight logs, goals/settings |
| Google (Gemini API) | AI nutrition estimation | The meal photo or typed meal text for a scan request |
| Open Food Facts | Barcode product database | The scanned barcode number only |
| RevenueCat | Subscription management | Your account identifier and subscription status |
| Google Play Billing | Payment processing | Your purchase and payment details (handled entirely by Google) |
| PostHog | Product analytics (EU region) | Anonymous usage events and your account identifier — never health/food/body data |
8. Children
Cotto is not directed to children. You must be at least 16 years old to use Cotto. We do not knowingly collect data from anyone under this age. If you believe a child has provided us data, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the app changes. Material changes will be reflected by an updated “Last updated” date and, where appropriate, an in-app notice.
10. Contact
Point Six Labs
Email: pointsixlabs@gmail.com
This document is a plain-language privacy policy. It is not legal advice. Have it reviewed by a qualified data-protection professional before publication.