Privacy Policy
This policy explains how Geometry Lab L.L.C-FZ ("Geometry", "we", or "us") handles information when you use Biotile.
Who we are
Data Controller
Geometry Lab L.L.C-FZ, Licence No. 2651608.01,
Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates.
EU Representative (Art 27 GDPR)
Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.
UK Representative (Art 27 UK GDPR)
Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom.
You can exercise privacy rights through the Prighter rights portal, email support@biotile.app, or contact privacy@geometryapps.com. The Geometry app directory is at geometryapps.com.
The short version
Biotile can be used for local catalog-food logging without an account. Meal, portion, supplement, habit, and gut check-in records stay on your device unless you sign in and separately allow health-related cloud processing. Biotile does not show advertising, use IDFA, perform cross-app or cross-site tracking, sell personal information, or share it for behavioral advertising.
If you allow cloud processing, the account service can sync the records you add and process a meal description or photo when you request AI identification. You can withdraw that permission in Settings. Withdrawal stops future sync and requested meal analysis; local catalog logging remains available.
Information you may store
- Food entries, dates, portions, plant identities, fermented-food state, and fiber estimates.
- Supplements, habits, and gut check-ins that you choose to record.
- Saved food templates, goals, reminders, appearance, units, and other app settings.
- Pending meal descriptions and staged photos while an unfinished estimate is waiting for connectivity, permission, or review.
- A record of your health-related cloud-processing choice, including the account, decision, time, and policy version.
On iOS, camera photos are saved to your Photos library after capture, and staged copies are removed after the estimate is confirmed or discarded. Android stores captured and selected meal photos in the app's private device storage. Biotile does not request contacts, location, HealthKit data, or an advertising identifier.
Optional account and cloud processing
Sign-in is optional for local logging. If you sign in with Apple, Google, or an email code, we process the provider subject, Biotile account identifier, email address when supplied, authentication state, and security records needed to protect the session. Accounts are not silently merged by matching email.
Before meal, supplement, or gut check-in records can leave the device, Biotile shows a dedicated cloud-processing choice. If you allow it, those records can be stored in the Cloudflare-hosted account service so they appear on your other devices. The choice is separate from the Terms, AI analysis, and product analytics.
These records may reveal information about diet, digestion, supplements, or health. Where they qualify as health data under Article 9 of the GDPR or UK GDPR, the additional lawful basis is your explicit consent under Article 9(2)(a). The app records the affirmative decision with a timestamp and policy version. You may withdraw in Settings at any time. Withdrawal does not affect processing that was lawful before it was withdrawn.
Requested meal analysis
When you ask Biotile to identify a typed or photographed meal, the selected text or image passes through the authenticated Cloudflare relay to OpenAI. When OpenAI is not configured or its API balance is exhausted, Biotile uses Cloudflare Workers AI as a Cloudflare-hosted fallback. Biotile asks separately before AI analysis and requires review before an estimate adds food or variety credit. Each provider receives only the selected meal input, not the account email or unrelated history.
One inline image can be processed without being stored in Cloudflare R2. For a multi-photo request, metadata is removed before each image is stored temporarily in account-scoped Cloudflare R2 media and loaded for the requested estimate. Each consumed upload is deleted after the extraction attempt, including when the AI provider returns an error. A failed provider delete stays in a retry queue, and any abandoned upload is removed by the hourly sweep after 24 hours. Exact catalog foods and saved templates can be logged locally without AI.
Biotile is a general-wellness service, not a medical device. It does not provide medical advice, diagnosis, prevention, or treatment. Food identification, portions, fiber, and other estimates can be wrong. Do not use them for a medical decision or emergency.
Subscriptions
The store used for your purchase processes payment details: Apple for the App Store, Google for Google Play, or Samsung for Galaxy Store. RevenueCat receives store transaction and entitlement information tied to its customer identifier so Biotile can unlock and restore the membership. When you sign in, that identifier is linked to your Biotile account. Geometry does not receive your full payment-card number or store-account password.
Product analytics and diagnostics
The app contains no PostHog, Firebase, Amplitude, Mixpanel, or Segment analytics SDK. URLSession on iOS and OkHttp on Android send fixed, content-free events to the first-party e.biotile.app relay. Biotile does not use advertising identifiers or cross-app attribution. The event schema allows coarse app opens, screen views, onboarding and feature actions, counts, fixed plan, provider, and source values, and app reliability data. It rejects meal text, photos, food names, notes, symptom values, email addresses, account identifiers, and arbitrary properties.
The client decides on the device before the first product event leaves. Germany, Austria, and devices whose region is unavailable send no product analytics until you choose Allow. Other regions start enabled and provide a one-tap Settings opt-out. Turning analytics off stops product events and removes the stored app-scoped analytics identifier and queued identity-bearing events.
The relay then applies two server-side branches. EEA, United Kingdom, Switzerland, and unknown Cloudflare regions use an aggregate branch. Each forwarded event gets a new random identifier, carries no forwarded IP or country, creates no person profile, and cannot be linked to another event. Subscription-conversion events are discarded. Cohort, onboarding-answer, dietary-count, fermented-food, and check-in-state properties are removed before forwarding. Other countries use a pseudonymous full branch. The app creates and stores a random app-scoped identifier only after the relay confirms that branch. It is not a name, email address, account ID, IDFA, or cross-app ID.
On iOS, Apple MetricKit crash, hang, CPU-exception, disk-write-exception, app-version, and OS-version counts are sent without meal content or a persistent analytics identifier. These stability diagnostics continue when product analytics is off.
Why information is processed
- Performance of the requested service or steps before a contract for account access, sync, requested AI analysis, subscriptions, support, export, and deletion.
- Explicit consent under Article 9(2)(a) for health-related cloud records where that rule applies.
- Consent for product analytics where the app asks before sending.
- Legitimate interests in account security, abuse prevention, service stability, content-free diagnostics, and answering support requests, subject to data minimization and your rights.
- Legal obligations for records we must retain by law.
Service providers and international transfers
Biotile uses Cloudflare for the account relay, D1 account records, R2 media and backups, security controls, analytics relay, site hosting, email routing, and Cloudflare Workers AI fallback meal analysis; OpenAI for primary meal analysis you request; PostHog Cloud EU for content-free product analytics and stability counts; Apple, Google, or Samsung for store purchases, and RevenueCat for subscriptions and entitlements; Apple and Google for optional identity proof; Resend for email sign-in codes; and Slack for internal support notifications. Support mail is forwarded to a monitored Geometry mailbox. Slack receives the sender and subject, not the message body.
Processing may occur in the European Union, United Kingdom, Switzerland, United Arab Emirates, United States, and the locations listed in each provider's subprocessor notice. The controller operates from the UAE and may access account or support records from Dubai. Where European or UK transfer rules apply, provider agreements and the applicable Standard Contractual Clauses or UK transfer terms must cover the transfer, together with data minimization, transport encryption, access controls, and the transfer review in the operator record.
Retention and deletion
Local records remain until you delete them or remove the app. Synced records remain while the account exists. Email codes expire after ten minutes; expired codes and tokens are removed by scheduled maintenance. A consumed meal upload is deleted after its extraction attempt. An abandoned upload is deleted after 24 hours. If storage deletion fails, the tracking row remains and the hourly maintenance job retries it.
Deleting the account in Settings establishes an account-erasure barrier, rejects new photo reservations, requires the account's full media prefix to be empty, removes live account rows, invalidates sessions, and attempts supported identity-grant revocation. The service reports a visible retry error rather than claiming completion if live media deletion fails. A one-hour durable deletion job covers an upload that was already in flight. Daily operational backups expire after about 35 days and retain the erasure record so restored data cannot make a deleted account active again.
Aggregate analytics events are unlinkable at ingestion. Pseudonymous full-branch events follow the configured PostHog project retention and deletion process. Store purchase records remain subject to the applicable store's and RevenueCat's legal and transaction-retention obligations.
Your choices and rights
Settings provides CSV export, local-data deletion, analytics opt-out, health-related cloud-processing withdrawal, AI-analysis withdrawal, sign-in method management, sign-out, and account deletion. You can manage or cancel a subscription through the Apple Account, Google Play, or Galaxy Store account used for that purchase.
Depending on local law, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about processing. You may also complain to your local data-protection authority. Use the Prighter rights portal or email support@biotile.app. We verify the request before disclosing or deleting account records.
Biotile does not sell personal information or share it for cross-context behavioral advertising. The service is currently expected to remain below US state-law business thresholds, but it honors the controls above regardless.
Children
Biotile is intended for adults and is not offered to anyone under 18. Do not create an account or submit records if you are under 18.
Security and changes
Biotile uses TLS, account-scoped authorization, device attestation for protected native actions, request and spend limits, bounded uploads, metadata removal, hashed or encrypted credentials, and account deletion controls. No security control eliminates all risk.
We may update this policy when processing, providers, or law changes. The effective date above identifies the current version. A material change to health-related processing requires a new affirmative decision in the app.
Contact
Privacy and support: support@biotile.app
Data-protection enquiries: privacy@geometryapps.com
Rights portal: app.prighter.com/portal/geometry