PhotoCarbs

Privacy Policy

Last updated:

This is a courtesy translation of the Portuguese original. In case of any discrepancy, the Portuguese version prevails.

1. Who we are

PhotoCarbs (“we”, “the app”) is an application that estimates the carbohydrate content of meals from photos, using artificial intelligence. The app is operated by KPTSIMPLE TECNOLOGIA E MARKETING LTDA, CNPJ 13.609.272/0001-35.

Contact: operations@kptsimple.com

2. What data we collect

  • Name and email

    When it is collected
    Account registration
    Why
    Authentication and account identification
  • Password (hash)

    When it is collected
    Account registration
    Why
    Secure login; never stored in plain text
  • Meal photos

    When it is collected
    Use of the camera/gallery in the analysis flow
    Why
    Sent to the AI to estimate carbohydrates and the items in the meal
  • Analysis results (items, grams of carbohydrate, manual corrections)

    When it is collected
    After each analysis
    Why
    History, favorites and calculation of daily goals
  • Daily carbohydrate goal

    When it is collected
    Set by the user in preferences
    Why
    Show the day's progress
  • Blood glucose (manual measurements and readings imported from sensors/meters via Health Connect, Dexcom or LibreLinkUp)

    When it is collected
    When the user logs a reading or connects a device
    Why
    Charts, averages and meal context
  • Insulin (logged doses, type, insulin-to-carbohydrate ratio and other parameters entered by the user)

    When it is collected
    When the user enters or logs them
    Why
    Transparent calculation using the user's own parameters and dose history
  • Session credentials of connected devices (Dexcom / LibreLinkUp token)

    When it is collected
    When the device is connected
    Why
    Sync readings; stored encrypted, and the LibreLinkUp password is not stored
  • App usage data (events such as login, meal analysis, blood glucose logging)

    When it is collected
    During use
    Why
    Measure how the product works and its quality; no advertising

Blood glucose and insulin are health data: they are used only for the app's own features and never for advertising.

We do not collect location data, contacts or other installed apps.

3. How we use the data

  • Authenticate the user and keep the session active (JWT tokens).
  • Send meal photos for AI analysis (see section 4) and return the estimated carbohydrates.
  • Save the user's own meal history and favorites.
  • Calculate progress toward the daily carbohydrate goal.
  • Optional, with explicit consent: if the user chooses to contribute to improving the product, the food items (name, portion, carbohydrates) from meals they have already confirmed may be included in an anonymous statistical aggregation (for example, “average carbohydrates of white rice, based on N contributions from distinct users”). This aggregation never links the data back to a specific account and never includes blood glucose, insulin or any other clinical data. Consent may be withdrawn at any time in the app's preferences; without explicit consent, none of the user's data is included in this aggregation.

We do not use the data for advertising and we do not sell data to third parties.

4. Sharing with third parties

  • Google (Gemini API)

    Data shared
    Meal photos sent at the time of analysis
    Purpose
    AI processing to identify foods and estimate carbohydrates. Google processes the image as part of the API processing and does not use it to train general-purpose models, according to the Gemini API terms.
  • Amazon Web Services (S3)

    Data shared
    Meal photos (storage)
    Purpose
    Hosting of uploaded photos, in a private bucket with access only through signed, temporary URLs
  • Amazon Web Services (RDS PostgreSQL)

    Data shared
    All account data and history
    Purpose
    Structured storage of the app's data
  • Dexcom / Abbott (LibreLinkUp) / Health Connect

    Data shared
    Only if the user connects the device: the app reads blood glucose readings from these sources
    Purpose
    Import readings into the app; nothing is sent to these services other than the connection credentials/authorization

We do not share data with advertisers, data brokers or social networks.

5. Storage and security

  • Photos are kept in a private S3 bucket (no public access); every access URL is signed and expires automatically.
  • Communication between the app and the server is always carried out over HTTPS.
  • Passwords are stored as hashes (never in plain text).
  • Access tokens (JWT) expire after 60 minutes; refresh tokens after 30 days.

6. Data retention and deletion

  • Data is stored for as long as the account exists.
  • Delete within the app: Preferences → Account → “Delete account”. The account and all associated data (photos, meals, favorites, blood glucose, insulin, personal memory) are permanently erased.
  • By email: you can also request deletion at operations@kptsimple.com; we respond within 7 days.
  • Usage and AI cost records may remain without any link to the account (the user identifier is removed upon deletion).
  • Database backups are overwritten in the provider's normal retention cycle.

7. Health and nutrition data

Carbohydrate estimates and other nutritional information are not medical advice. The app is a support tool for dietary management and does not replace the guidance of a healthcare professional.

8. Children

PhotoCarbs is not directed at children under 13 and we do not knowingly collect data from children in that age group.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated within the app.

10. Contact

Questions about privacy or data deletion requests: operations@kptsimple.com