Privacy Policy
Daysun Labs Pte. Ltd. (hereinafter "the Company") sets out in this policy how it handles users' personal information when providing the mobile app Tasta (hereinafter "the Service").
This is a reference translation; in case of any discrepancy, the Korean version prevails.
Three things to know upfront
- Photos confirmed into food records are stored, for backup and recovery, only as two resized copies made on your device (a display copy and a preview), in a private repository other users cannot see. The original file stays on your device and is never uploaded. This comes in two parts — automatic backup for new photos (uploading photos you take from now on) and cloud photo storage & recovery (keeping and restoring photos already uploaded). You can turn backup off at any time in Settings → Automatic backup for new photos, and when you do, you choose whether to keep or delete the photos already uploaded. If you keep them, storage and recovery continue, and you can delete them at any time from Settings → Delete all cloud photos. During automated operational checks (verifying that photos have not been corrupted), the photos pass through the execution environment of a provider the Company has entrusted — Section 5 names that provider and the scope.
- The location where a photo was taken (GPS) is only stored when you explicitly consent to it. It is not stored before you are asked.
- We do not use or sell your records for advertising. They are not disclosed to other users.
1. Information We Collect
At sign-up
| Item | Required | Description |
|---|---|---|
| Email address | Required | Used for sign-in and account recovery. If you choose to hide your email address when signing in with Apple, a relay address created by Apple is sent instead, and the Company cannot see your actual address. |
| Account identifier | Required | A value the Service generates automatically at sign-up to distinguish accounts (common to all sign-up methods — this is the value retained as a hash in the deletion-request record in Section 4). When you sign in with Apple or Google, an identifier issued by that provider is also received. |
| Sign-in method | Required | Stored on your device to guide you to the same method next time. Which sign-in methods are linked to your account (method type and link time) is also recorded on the server for account-recovery guidance. |
Phone number, date of birth, gender, address, and payment information are not collected. A name is received only when you sign in with Google and Google includes it in the authentication information; it is not collected through other methods. Passwords are not used and therefore not stored.
Generated while using the Service
| Item | Required | Description |
|---|---|---|
| Food records | Required | Food names, tags, ratings, notes, and timestamps recognized from photos. |
| Preference signals | Required | Per-tag food preferences calculated from records, plus allergy tags and dislike tags chosen by the user. Used to generate recommendations and filter allergy items. |
| Recommendation history | Required | Which recommendations were received, saved, or excluded. |
| Resized photo copies and previews | Optional (can be turned off in Settings) | Only the resized copies and previews of photos confirmed into food records are uploaded to private backup storage; the original files are not uploaded. Turn off Settings → Automatic backup for new photos and new photos will not leave the device. Keeping and restoring photos already uploaded is a separate service, removable at any time via Settings → Delete all cloud photos. |
| Information derived from the original photo | Optional (on/off together with photo backup) | The original file itself is never uploaded, but five values derived from it are sent so the same photo can be recognized again — a fingerprint (a one-way value the content cannot be recovered from), the file format, the file size, the pixel dimensions, and the capture time. These are used to reconnect a photo to an existing record after a reinstall and to avoid uploading the same photo twice. The photo cannot be reconstructed from these values. |
| Photo location (GPS) | Optional (separate consent) | Used to open map apps at the precise location. Can be turned off at any time in app settings; when turned off, no new locations are stored from that point on. |
Automatically accumulated
| Item | Description | |
|---|---|---|
| Photo backup consent records (version of the consented document, purpose, retention approach, photo variants, storage region, upload network setting, time of consent, and the time of withdrawal if withdrawn) | While the account exists. Even after you withdraw consent, the record itself is kept to evidence that the withdrawal happened | Deleted together with the account |
| App usage logs | A record of what actions occurred. Used for service improvement and error analysis. These logs carry an account-scoped identifier; when you delete your account, that identifier is replaced with a value from which the original cannot be recovered, and the logs themselves are deleted per the periods in Section 4. | |
| App version · App language | Stored alongside logs to identify the environment in which issues occur. | |
| Country · Region | Stored only at the country and city/district level. Coordinates and detailed addresses are blocked from appearing in these logs by the server. | |
| Installation identifier | Random values created when the app is installed (one for photo uploads, one for usage logs). They are not device serial numbers or advertising identifiers, and on the device they disappear when the app is uninstalled. There are two server records — ① the value stored with upload records of photos is marked inactive when the photo is deleted and removed when the account is deleted; ② the install value attached to app usage logs is replaced with an irreversible value when the account is deleted and then removed with those logs per the periods in Section 4. | |
| Photo analysis count · Last-used time | Used in the summary screen to confirm the account after reinstallation. |
When you contact us
When you write to privacy@tasta.app or support@tasta.app, or exercise your rights, that email (sender address, delivery headers, subject, body, attachments) remains in the Company's mailbox. It is kept to verify how the request was handled and to compare repeat requests; the retention period is stated in the Section 4 table.
The advertising identifier (IDFA) is not collected. The app does not include advertising or marketing tracking tools, or external analytics or crash-collection tools.
2. Purposes of Use
- To create accounts and to sign in and recover accounts
- To save food records and restore them even when changing devices
- To recognize food in photos and automatically fill in records
- To recommend restaurants that match your preferences
- To identify errors and improve the Service
- To respond to inquiries
We do not use data beyond the above purposes. If purposes change, we will notify you in advance and obtain fresh consent where required.
3. How We Handle Photos
- Photo library access is used only to find food photos and create records. With full access, the app scans the accessible photos on the device to find food photos automatically (the auto-organize feature described in the permission primer — this analysis stays on the device). With limited access, only the photos you select are read. In neither case are photos transmitted to the server during this scan.
- Food recognition processing takes place on your device. We use Apple's on-device image analysis capabilities; photos are not sent to a server or external AI service for recognition. Reading the location embedded in photos also takes place on the device.
- Photos uploaded to the server are not accessible via a public URL. They are only served via a short-lived temporary URL (valid for 60 seconds) issued after verifying ownership.
- The Company does not use photos uploaded by users to train AI models without separate consent. Photos are handled in three distinct layers — ① food recognition (inference) happens entirely on the device, ② only photos you consent to back up go to the server, and ③ only those among them for which you separately consent to training use could ever be used for training. No such training-consent process currently exists, so no user photos are used for training. If a training feature is introduced, it will use a separate opt-in consent that is off by default, and declining does not limit any feature.
- The app does not delete originals from your photo library.
4. Retention Periods
| Data | While account is active | Upon deletion request |
|---|---|---|
| Account information (email address, account identifier, sign-in method and link records, and the name received when signing in with Google) | While the account exists | Deleted immediately when you delete your account |
| Food records · preference signals · recommendation history | While the account exists | Deleted immediately |
| Photos held in cloud storage | While you use storage & recovery. If you turn automatic backup off and choose ‘Keep existing photos’, storage continues; if you choose ‘Delete all existing photos’ or run Delete all cloud photos, they are deleted then | Access blocked immediately; removed after deletion queue processing |
| App usage logs | 90 days | Pseudonymised immediately and cleaned up daily; deleted within 30 days of the request |
| Inquiry and rights-request email | 3 years after the request is handled (the period needed to verify handling and compare repeat requests) | On request, the body and attachments are deleted, leaving the handling record (request type, date received, outcome) and the sender address needed to compare repeat requests |
| Server backups | No separate automatic backup operated by the Company | No restore copy is created separately from the operational data |
There are two exceptions to this table. ① The account-deletion request record — an irreversible hash of the account identifier plus the request time — is retained as evidence that deletion was carried out. It contains no original personal information such as an email address. ② The photo-deletion processing record — when a server photo is deleted, the deletion queue keeps a processing entry containing the storage path of the removed file (which includes an account-distinguishing value) and the processing time, retained as evidence that the deletion was actually carried out. The photo content itself is not retained. Should any legally mandated retention items arise, they will be communicated as further exceptions to this table.
5. Service Providers We Entrust
The Company does not sell personal information. Processing is entrusted to the following providers solely to the extent necessary to operate the Service. Apple and Google are not among them: they are not providers the Company entrusts with processing but providers of sign-in, and they are listed separately below. That said, Google is also the processor for the Company's mailbox (Google Workspace), which receives inquiry email — that role appears in the tables below.
What applies to every recipient — by the nature of internet communication, the parties your device connects to directly (Supabase; Cloudflare when you open these pages; Apple and Google when you sign in; Google when a map opens as a web URL; Apple when the App Store opens because the Naver Map app is missing) receive your device's connection information (IP address, time of access, request data) each time. Parties reached through processing servers rather than from your device (Resend, Anthropic, GitHub, Google as the Company's mailbox provider) do not communicate with your device directly, so the connection information they see belongs to the connecting server, not to your device. Each recipient decides how long it keeps that information under its own policy; the Company does not separately receive and store it (records on the Company's own server follow the period set by the app usage logs row in Section 4). The tables below do not repeat this common point and list only what is specific to each party.
| Provider | Task entrusted | Information transferred |
|---|---|---|
| Supabase Pte. Ltd. (Singapore entity) |
Account & record storage, photo storage, authentication | All app and server storage items listed in this policy (inquiry email does not use this route — see the Google row below) |
| Plus Five Five, Inc. (trading as Resend · US entity) |
Sending verification code emails | Email address and the one-time verification code contained in the message body |
| Cloudflare, Inc. (US entity) |
Serving this policy and terms pages (web hosting) | Connection information exchanged when a page is opened (request information
such as IP address). Where deployment is connected to the repository, the
repository copy also goes here and includes operator contact
details in current operational and historical records and the previous administrator address in change history; deploying by uploading only the
web/ directory transfers no repository copy |
| Google (the Company's mailbox, Google Workspace — contracting entity Google Asia Pacific Pte. Ltd., a Singapore entity) |
Providing the Company's mailbox — receiving and storing inquiry email | The entire inquiry email sent to privacy@tasta.app or support@tasta.app (sender address, headers, subject, body, attachments) — it arrives directly from the sender's own mail service |
| GitHub, Inc. (US entity · Microsoft group) |
Photo integrity checks and the recording of training eligibility from their results (once-daily scheduled runs plus manual operator runs), and administrator account verification when the Company runs server bootstrap | The resized copies and previews being checked and their asset identifiers, the account identifier and storage path (the leading path segment is the account identifier), the bucket name, the stored fingerprint, and the file size. Photos only pass through during the check and disappear with the execution environment when it ends; the execution log retains asset identifiers, and when a check fails the storage path (which contains the account identifier) is also written to the error message. When the Company runs server bootstrap, the administrator account's email address is also processed (it is masked so that it does not remain in new execution logs; past execution logs may still contain the previous value) |
| Anthropic, PBC | Generating recommendation text (see below) The recommendation feature is not connected to the app, so no transfer currently occurs. |
Food tags, tags of recently eaten food, dislike tags, the list of restaurants you saved, publicly available restaurant information together with its internal identifier, price band and authenticity tier, the distance band computed from your location, time of day, day of week and city, the app display language, and the adventurousness level and previous choice you selected, and per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role. Email addresses, account identifiers, notes, and similar content are not sent. |
Sign-in providers
The two providers below are not entrusted with processing by the Company. They process information on their own terms and privacy policies when you sign in with their accounts.
| Provider | What it does | Information exchanged |
|---|---|---|
| Apple Inc. | Sign in with Apple | Authentication credentials as defined by Apple — the Company requests the email scope (a relay address is delivered if you choose to hide your email) |
| Google LLC | Sign in with Google | Authentication credentials as defined by Google (name, email, account identifier) |
What is sent when generating recommendations
The Service may use an external AI service at the recommendation generation stage. What is sent at that point is limited to the following.
- What is sent — Food category tags and their preference levels, tags of recently eaten food, dislike tags, the names and identifiers of restaurants you have saved, publicly available information about candidate restaurants (name, menu, internal identifier, price band, authenticity tier) and the distance band computed from your location (not public information but derived from you), context such as time of day, day of week and city, and the app display language, the adventurousness level and previous choice you selected, per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role. The recommendation role is computed from your preference signals and saved list (familiar, bridge, depth, saved, recently suppressed), so it is not public restaurant information.
- What is not sent — Account identifiers and email addresses, free-text input such as notes, menu names, and place names written directly by the user, photos, and allergy information. Allergy items are filtered by the server before the recommendation stage.
Cross-border transfer
The Company is a Singapore entity and its servers are located in Japan, so providing the Service involves transferring information outside the Republic of Korea as set out below. The five items required by law are stated in full for the providers the Company currently entrusts with processing (Supabase Pte. Ltd., Plus Five Five, Inc., GitHub, Inc., and Cloudflare, Inc.). Google, as the Company's mailbox, is among them. The Anthropic row gives advance notice of the terms that will apply if the recommendation feature is activated; the feature is not connected, so no transfer to Anthropic currently occurs. The Apple and Google sign-in rows and the Google Maps row are not transfers made by the Company: they are information exchanged directly with those companies when you choose that sign-in method, listed here for reference so that you know information leaves the country, with retention determined by their own policies.
| Recipient (entity & address) | Country of storage | Items transferred | Timing & method | Recipient's purpose of use | Retention & use period |
|---|---|---|---|---|---|
|
Supabase Pte. Ltd. Singapore · 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 |
Japan (Tokyo) | All app and server storage items in Section 1 (inquiry email does not use this route) — account information, food records, taste signals, recommendation history, backed-up resized photo copies and previews, the photo capture location (GPS coordinates) where separately consented, app usage logs. The authentication tokens that keep you signed in (access and refresh tokens) are also sent with requests. When you sign in with Google, the authorization code returned by Google and the verifier generated by the app also go to the authentication server. When a photo is uploaded, the file is accompanied by its checksum, media type, byte size, pixel dimensions and capture time, together with the identifier of that photo inside your photo library so the app can find it again on the device. When you consent to backup, the consent record (version of the consented document, purpose, retention approach, which photo variants are uploaded, storage region, the network setting you chose for uploading, and the time of consent) is stored on the server. Records that remain after deletion also live on this server: the account deletion request record (hash and timestamp) and the photo deletion execution record (including the storage path), described in exceptions ① and ② under the Section 4 table | When an account is created, each time you sign in again (the email address and verification code, the token issued by Apple, or the authorization code from Google together with the app's verifier, are sent to the authentication server), each time you link an additional sign-in method to the account (the same credentials are sent), each time the session is refreshed automatically (the refresh token is sent to the authentication server), and each time records and photos are stored or loaded (the access token accompanies each request). App usage logs are also sent asynchronously while you use the app, including actions that save no record. All transfers use an encrypted connection (TLS) | Storing accounts and records, photo backup and restore, and authentication on the Company's behalf | As set out in the Section 4 table. If the contract between the Company and the recipient ends, copies are deleted after the 30 days following termination have passed (those 30 days are the window in which the Company may retrieve a copy; deletion follows once it closes) |
|
Plus Five Five, Inc. (trading as Resend) United States · 2261 Market Street #5039, San Francisco, CA 94114 |
United States | Email address, and the one-time verification code (6 digits) contained in the message body | When verification code emails are sent, over TLS | Sending email and recording delivery results | The verification code expires shortly after the email is sent and cannot be used to sign in after that. Email data, including delivery records, is retained for 30 days (all plans — per Resend's official documentation) |
| Cloudflare, Inc. United States · 101 Townsend St., San Francisco, CA 94107 Cloudflare Privacy Policy |
The United States (headquarters and primary processing country) and servers distributed worldwide to serve pages quickly — this varies with where you connect from, so no single country can be identified (see the linked policy). The Company checked whether region-restriction settings (Regional Services) were available and found that they are not offered on the Company's plan (an enterprise-only feature — confirmed 2026-08-19) | Page connection information (such as IP address) and, where deployment is connected to the repository, the repository copy (not transferred when only the directory is uploaded) | When this page is opened and when the Company deploys the pages | Serving the pages and processing the repository copy for deployment | Deployed copies of the pages remain until the Company deletes them — a new deployment does not delete earlier copies but keeps them in the deployment history, where each copy stays reachable at its own address. Retention of connection records follows Cloudflare's own policy, as set out in the common note at the top of this section |
| Google (the Company's mailbox, Google Workspace) Contracting entity: Google Asia Pacific Pte. Ltd. (Singapore) · 70 Pasir Panjang Road, #03-71, Mapletree Business City II, Singapore 117371 · Processing: Google LLC and affiliates |
The United States and other regions Google determines (the Company's Google Workspace plan does not allow choosing a storage region) | The entire inquiry email sent to privacy@tasta.app or support@tasta.app (sender address, headers, subject, body, attachments) | When inquiry email arrives (it is transmitted directly from the sender's own mail service to the Company's mailbox) | Providing the Company's mailbox — receiving and storing inquiry email | As set out in the inquiry and rights-request email row of the Section 4 table |
| GitHub, Inc. United States · Microsoft group 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States |
Country where the execution environment (GitHub-hosted runner) is located: the United States and other regions GitHub determines — the runner's location cannot be chosen by the user. The repository itself is stored in countries determined by GitHub (see their policy linked above) | The resized copies and previews being checked, their asset identifiers, the account
identifier and storage path (the leading path segment is the account
identifier), the bucket name, the stored fingerprint, and the file size. For server bootstrap
runs, the administrator account's email address (stored in encrypted
form as the GitHub Actions secret HOSTED_ADMIN_EMAIL and masked before
its first use during the run so that it does not remain in the execution log;
past change history and past execution logs may still contain the previous
value — execution logs follow the retention limit below) |
When the daily scheduled check runs, and when an operator runs the
check manually (a manual run downloads up to 1,000 pending photos per round, 100 by
default. The default check-only run stops after one round; a run
that also applies results repeats for up to 20 rounds by default, so a single
execution can move more than that). The server bootstrap task occurs only when the
Company runs it. The administrator address has been removed from the inputs
and default values in the current hosted-bootstrap workflow file and is
passed to the execution environment from a GitHub Actions secret managed by the Company. The previous value remains
in past change history. All transfers use TLS. Photos only pass through during the check and
are not stored in the execution environment |
Verifying that photos held on the server have not been corrupted or replaced (integrity check), and administrator account verification during server bootstrap. The result is also recorded as a precondition that a future photo-training feature would require — but no consent flow for training exists, so no photo is used for training today, and this record alone creates no basis for training | Photos disappear with the execution environment when the run ends. Retention limit for the execution log containing asset identifiers:
90 days (the repository's configured value).
The administrator-address default was removed from the
hosted-bootstrap workflow file; the value in
past change history is left in place without rewriting (the repository is
private, and rewriting history carries greater side effects). Addresses in past
execution logs disappear once the retention limit above passes. The
HOSTED_ADMIN_EMAIL secret remains stored by GitHub until the Company
deletes or replaces it |
| Anthropic, PBC United States |
United States | Food category tags and preference levels, tags of recently eaten food with how many days ago and their confidence, and dislike tags, the names and identifiers of restaurants you have saved, publicly available information about candidate restaurants together with their internal identifiers, price bands, authenticity tiers and the distance band computed from your location, time of day, day of week and city, the app display language, the adventurousness level and previous choice you selected, per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role (account identifiers, email addresses, notes, and photos are not sent) | When recommendations are generated, over TLS. This feature is not currently wired into the app, so no transfer actually occurs. | Generating recommendation text | This feature is not currently wired into the app, so no transfer occurs. The actual retention period will be stated in this cell before the feature is enabled |
| Google LLC (Maps) United States |
No specific country stated — Google Privacy Policy | Where a place identifier is recorded, the place name and that identifier; where only coordinates exist, the coordinates (without the name); where neither exists, the place name. Opening the web URL also passes your device's connection information (request data such as the IP address) to Google | When you tap Open in maps, carried in the map URL | To show that location on a map | Not determined by the Company; Google's own policy governs (see link) |
| Apple Inc. United States |
United States and others — Apple Privacy Policy | Authentication credentials required for sign-in | When you sign in with Apple. Your device's connection information also reaches Apple when the App Store page opens because the Naver Map app is missing | Sign-in authentication | Not determined by the Company; Apple's own policy governs (see link) — this row is listed for reference, as it is not a transfer made by the Company |
| Google LLC United States |
No specific country stated — Google Privacy Policy | Authentication credentials required for sign-in | When you sign in with Google | Sign-in authentication | Not determined by the Company; Google's own policy governs (see link) — this row is listed for reference, as it is not a transfer made by the Company |
Apple and Google do not identify a single country, as their policies allow processing on servers worldwide. For sign-in, what is passed to them is limited to authentication information. Google additionally receives the place name and, where you tap Open in maps, either the recorded place identifier together with the place name (this does not depend on location consent) or, where no identifier exists and you consented to capture-location use, the coordinates alone (without the name) — that is the Google Maps row above. The countries of processing are described in their policies linked above.
When you open a map app
Tapping Open in maps on a record makes the app build and open a map service URL. What that URL carries depends on the service and on what is recorded for the place.
- Google Maps — (1) where a Google-assigned place identifier is recorded, the place name and that identifier; (2) where there is no identifier but consented coordinates exist, the coordinates only (the name is not carried); (3) where neither exists, the place name only.
- Naver Map — where coordinates exist, the coordinates and the place name; otherwise the place name only.
Nothing is sent unless you tap. Google Maps opens as a web URL, so that step also passes your device's connection information (such as the IP address) to Google. Naver Map opens an app installed on your device, so no connection information goes to the Company or to Naver's servers at this step. If the Naver Map app is missing or fails to open, the App Store page for Naver Map opens instead, and your device's connection information is passed to Apple at that moment.
- Google Maps (Google LLC · United States) — opened as a web URL. This is a transfer out of the country, so it is listed in the table below.
- Naver Map (NAVER Corporation · Republic of Korea) — opens the Naver Map app installed on your device, without passing through the Company's servers. As a domestic provider, this is not a cross-border transfer.
If you do not want this, simply do not tap Open in maps. Turning off capture-location use in app settings means records created after that store no coordinates, so their map URLs carry none. However, records that already have coordinates keep them, and opening a map from those records still carries the coordinates — to remove those, delete the record itself (Section 6).
Sub-processors engaged by the recipients
The recipients also engage other providers to operate their services. The place where user accounts, records, and photos physically reside is storage provided by Amazon Web Services, Inc. (a US entity) in its Japan (Tokyo) region. In other words, the recipients' country of incorporation (Singapore, United States) and the country where the information is stored (Japan) are different. The sending infrastructure for verification emails is provided by the same company (Amazon Web Services, Inc.).
For the features the Company uses (database, file storage, sign-in authentication, signed URL issuance), that one company is the only sub-processor confirmed to be involved in storing or processing user information. The recipients also engage providers for purposes such as support and monitoring; the full list is published in the sub-processor list published by Supabase. Whether those providers touch the information of the Company's users cannot be determined from the public list alone, so the Company verifies this as part of its contract review and will amend this policy if the answer differs. The contract provides a procedure under which the recipient gives advance notice of any change to its sub-processors and the Company may object. The Company reviews those changes and will amend this policy if a change differs from what is stated above.
Recipient contacts
Privacy contacts are published by Supabase, Resend (privacy@resend.com), Anthropic, and the Apple and Google policies linked above. Anthropic maintains a Korean domestic representative, Anthropic Korea, Limited (41F, 152 Teheran-ro, Gangnam-gu, Seoul · +82-2-6252-2080). GitHub's data protection contact is dpo@github.com, at 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States (GitHub Privacy Statement). You may also write to privacy@tasta.app and the Company will handle the request on your behalf.
Legal basis for the transfer
- Storage necessary for the contract — the transfers above are the entrusted processing and storage necessary to provide the service you requested (account and record storage, photo backup and restore, sign-in email delivery). Under Article 28-8(1)(3) of the Personal Information Protection Act, disclosure in this policy takes the place of separate consent.
- Transfer to provide the recommendation feature — sending data to an external AI service to generate recommendation text is also entrusted processing to provide a feature you requested, on the same statutory basis. What is sent is limited to food tags, tags of recently eaten food, dislike tags, the names and identifiers of restaurants you have saved, publicly available restaurant information with its internal identifier, price band and authenticity tier, the distance band computed from your location, time of day, day of week and city, the app display language, the adventurousness level and previous choice you selected, per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role (no account identifiers, email addresses, notes, or photos), and the Company does not make this transfer for model training purposes. This feature is not currently wired into the app.
- Transfer to serve these pages and receive inquiry email — publishing this legally required policy requires web hosting (Cloudflare), and receiving your inquiries and rights requests requires the Company's mailbox (Google Workspace). Where deployment is connected to the repository, the repository copy transferred with it serves the same purpose (work needed to publish this notice); under the current direct-upload method, only the finished page directory is transferred. This is entrusted processing needed to provide the service you requested and to meet a statutory obligation, on the same basis.
- Transfer for photo integrity checks — verifying that photos held on the server have not been corrupted or replaced requires reading each photo once and recomputing its fingerprint. This check runs once a day in the automated execution environment the Company uses (GitHub Actions) on a daily schedule and whenever an operator runs it manually; it is entrusted processing to keep the storage and restore service you requested working correctly, on the same statutory basis. Photos only pass through during the check and disappear with the execution environment when it ends. The result is also recorded as a precondition that a future training feature would require, but that record is not a basis for training — training requires the separate opt-in consent described below. When the Company runs server bootstrap, the administrator account's email address also passes through the same execution environment; that too rests on the same statutory basis, as it is an administrative task required to operate the Service.
- Opening a map — when you tap Open in maps, the place name and, where consented, values go to the map service (Google Maps: the name and the place identifier where one is recorded, otherwise the consented coordinates alone, otherwise the name alone; Naver Map: the coordinates and the name where coordinates exist, otherwise the name alone). That too is not a transfer the Company makes as entrusted processing but the result of your request; the Company's basis is provision of the map-opening feature you asked for, and each map provider's own policy governs their processing.
- Information exchanged with sign-in providers — what goes to Apple and Google is not a transfer the Company makes as entrusted processing; it is the authentication information exchanged directly with those companies when you choose that method. The Company's basis is provision of the sign-in feature you requested, and their own policies govern their processing. It is not a transfer by the Company, but information still leaves the country, so it is listed in the table above.
- Transfer for AI training — none at present. The Company does not send user photos abroad for AI model training. Should this be introduced, the contractual basis above will not be reused; separate opt-in consent explaining the purpose will be obtained.
How to refuse the transfer, and what happens if you do
- How — send your refusal to privacy@tasta.app, or delete your account in the app. For photos specifically, turning off Settings → Automatic backup for new photos stops new photos from leaving the device.
-
The effect differs by recipient.
- Supabase — refusing this transfer means accounts and records cannot be kept on the server, so the Service cannot be provided.
- Automatic backup for new photos — turning it off in Settings leaves every other feature working, and photos already uploaded can be removed using the methods in Section 6.
- Apple and Google — if you would rather not use a particular sign-in provider, choose another. The sign-in screen offers Apple, Google, and email verification codes, so avoiding one still lets you use the Service. Note that using email verification codes sends mail through Resend.
- Cloudflare — used when you open these pages and when the Company deploys the pages (deployment happens independently of anything you do). If you do not open the pages, no connection information is transferred either.
- The Company's mailbox (Google) — used when inquiry email is received. To exercise your rights without going through email, write to the Company's postal address in Section 10: postal mail is an accepted intake channel, and it is handled within 10 business days of receipt, as in Section 6 (identity verification happens within that period).
- GitHub — used for integrity checks of photos held on the server and for administrator account verification when the Company runs server bootstrap. The way to stop the photo transfer is to turn off automatic backup for new photos and delete the photos already uploaded (from the turn-off screen or Settings → Delete all cloud photos): with nothing left to check, the transfer does not occur. If you email a refusal, the Company handles it through the same route (there is currently no per-account switch that skips only the check). Administrator account verification is an operational task of the Company and is not something users refuse.
- Resend — used only when you sign in with an email verification code. Choosing Apple or Google sign-in sends no mail through Resend, so you can avoid this transfer alone and still use the Service as normal.
- Anthropic — this is used only to generate recommendation text, so refusing it leaves records, backup, sign-in, and the rest of the Service unchanged. Recommendation wording may differ or may not be offered (this feature is not currently wired into the app).
Protection comparable to Singapore standards
Because the Company is a Singapore entity, the Singapore Personal Data Protection Act (PDPA) also applies. That Act requires the Company to ensure by contract, or by equivalent means, that overseas recipients provide protection comparable to Singapore standards. The Company has confirmed the following safeguards in the published contract documents of Supabase Pte. Ltd., GitHub, Inc., Cloudflare, Inc., and Google as the Company's mailbox. The Company is confirming how the published data processing addendum of Plus Five Five, Inc. (Resend) applies to its current account and will complete any required acceptance, execution, or change of processing route based on that result. Anthropic, PBC is not yet receiving any transfer because the recommendation feature is not wired into the app; before enabling that feature, the Company will confirm that an agreement with the same contents applies.
- Technical and organizational security measures
- Notification to the Company without undue delay upon becoming aware of a breach
- Return or deletion of data, including copies, when the contract ends
- Prior authorization, notice, and an objection procedure for sub-processors
- Security audits and provision of supporting evidence
- Assistance in responding to your requests to exercise your rights
Securing these safeguards is separate from the disclosure in this policy and is not replaced by it.
Apple's sign-in and Google's sign-in and Maps roles are not covered by those agreements. In those roles they are not providers the Company entrusts with processing; they process information on their own terms and privacy policies when you use those features (Google as the Company's mailbox is the exception — that role is included in the agreements above). For sign-in, what passes to them is limited to authentication information; Google Maps additionally receives the place name plus either the Google-assigned place identifier or, where it is absent, the consented coordinates when you tap Open in maps. Either way, their own policies linked above govern that processing.
6. Your Rights
- View & edit — Your records can be viewed and edited at any time within the app.
- Delete — Records can be deleted individually; deleting a record also sends its uploaded photo to the deletion queue. To delete photos only, use Settings → Delete all cloud photos (설정 → 클라우드 사진 전체 삭제) — your account and food records stay, and only the photos held on our servers are deleted (this works even while automatic backup is on). Your entire account can be deleted via Settings → Account → Delete account (설정 → 계정 → 계정 삭제) in the app.
- Withdraw consent — Automatic backup for new photos and location tracking can be turned off at any time in app settings. Turning off automatic backup stops new uploads and cancels uploads in progress; at that point you choose whether to keep or delete the photos already uploaded, and even if you keep them you can delete them later via Settings → Delete all cloud photos. Photo-library access can be revoked in iOS settings (the app uses no iOS location permission — photo locations are read from the photo files themselves, and their use is controlled by the in-app toggle).
- Download · Suspension of processing — If needed, please request via privacy@tasta.app. Handled after identity verification.
Requests are processed within 10 business days from the date received. Users in the Republic of Korea may also contact the Personal Information Dispute Mediation Committee (1833-6972) for assistance.
7. Security Measures
- Communications between devices and the server are encrypted.
- Row-level access controls are applied to the database to prevent access to other users' records.
- Photos uploaded to the server are stored in private storage and served only via short-lived temporary URLs.
- When an account is deleted, the identifiers in app usage logs are replaced with irreversible values.
- Administrative access is granted to the minimum number of personnel.
8. Users Under 14 Years of Age
The Service is not available to users under 14 years of age. If we become aware that information from users under 14 has been collected, we will delete it without delay.
9. Changes to This Policy
If this policy changes, we will notify you on this page at least 7 days before the effective date. Material changes will be separately notified within the app, and fresh consent will be obtained where required.
10. Contact
Data Protection Officer
KIM DAESUNG (Director)
Contact privacy@tasta.app
Company Daysun Labs Pte. Ltd. ·
Address 152 Beach Road, #23-02, Gateway East, Singapore 189721