Tasta

Privacy Policy

Effective date 2026-08-01 · Last updated 2026-07-31

Daysun Labs Pte. Ltd. (hereinafter "the Company") sets out in this policy how it handles users' personal information when providing the mobile app Tasta (hereinafter "the Service").

This is a reference translation; in case of any discrepancy, the Korean version prevails.

Three things to know upfront

  • Photos do not go to the server by default. Only photos you separately consent to are stored in a private repository accessible only to you, for backup and recovery purposes.
  • The location where a photo was taken (GPS) is only stored when you explicitly consent to it. It is not stored before you are asked.
  • We do not use or sell your records for advertising. They are not disclosed to other users.

1. Information We Collect

At sign-up

Item Required Description
Email address Required Used for sign-in and account recovery. If you choose to hide your email address when signing in with Apple, a relay address created by Apple is sent instead, and the Company cannot see your actual address.
Account identifier Required A value issued by Apple or Google to distinguish accounts.
Sign-in method Required Stored on your device to guide you to the same method next time.

Name, phone number, date of birth, gender, address, and payment information are not collected. Passwords are not used and therefore not stored.

Generated while using the Service

Item Required Description
Food records Required Food names, tags, ratings, notes, and timestamps recognized from photos.
Preference signals Required Per-tag food preferences calculated from records, plus allergy tags and dislike tags chosen by the user. Used to generate recommendations and filter allergy items.
Recommendation history Required Which recommendations were received, saved, or excluded.
Original and thumbnail photos Optional (separate consent) Only consented photos are uploaded to private storage. Without consent, photos do not leave the device.
Photo location (GPS) Optional (separate consent) Used to open map apps at the precise location. Can be turned off at any time in app settings; when turned off, no new locations are stored from that point on.

Automatically accumulated

Item Description
App usage logs A record of what actions occurred. Used for service improvement and error analysis. User identifiers attached to these logs are stored in a form from which the original value cannot be recovered.
App version · App language Stored alongside logs to identify the environment in which issues occur.
Country · Region Stored only at the country and city/district level. Coordinates and detailed addresses are blocked from appearing in these logs by the server.
Installation identifier A random value created when the app is installed. It is not a device serial number or advertising identifier, and disappears when the app is uninstalled.
Photo analysis count · Last-used time Used in the summary screen to confirm the account after reinstallation.

The advertising identifier (IDFA) is not collected. The app does not include advertising or marketing tracking tools, or external analytics or crash-collection tools.

2. Purposes of Use

We do not use data beyond the above purposes. If purposes change, we will notify you in advance and obtain fresh consent where required.

3. How We Handle Photos

4. Retention Periods

Data While account is active Upon deletion request
Food records · preference signals · recommendation history While the account exists Deleted immediately
Consented uploaded photos While consent is maintained Access blocked immediately; removed after deletion queue processing
App usage logs 90 days Pseudonymised immediately, then fully deleted within 30 days
Server backups Overwritten every 7 days Disappear automatically within 7 days (no separate archive is made)

Data whose retention is required by law is exempted from this table and will be communicated separately. Currently there are no such items in the Service.

5. Service Providers We Entrust

The Company does not sell personal information. Processing is entrusted to the following providers solely to the extent necessary to operate the Service.

Provider Task entrusted Information transferred
Supabase Account & record storage, photo storage, authentication All storage items listed in this policy
Resend Sending verification code emails Email address
Apple Sign in with Apple Authentication credentials as defined by Apple (not requested by the Company)
Google Sign in with Google Authentication credentials as defined by Google (name, email, account identifier)
Anthropic Generating recommendation text (see below) Food tags and publicly available restaurant information only. Email addresses, account identifiers, notes, and similar content are not sent.

What is sent when generating recommendations

The Service may use an external AI service at the recommendation generation stage. What is sent at that point is limited to the following.

Cross-border transfer

Providing the Service involves transferring information outside the Republic of Korea as set out below. The items transferred, recipients, and purposes are as shown in the table above, and retention periods are as set out in Section 4.

Recipient Country of storage When the transfer occurs
Supabase Japan (Tokyo) When accounts, records, and photos are stored
Resend United States When verification code emails are sent
Apple United States and others — Apple Privacy Policy When you sign in with Apple
Google No specific country stated — Google Privacy Policy When you sign in with Google
Anthropic United States When recommendations are generated

Apple and Google do not identify a single country, as their policies allow processing on servers worldwide. What is passed to them is limited to the authentication information required for sign-in; the countries of processing are described in their policies linked above.

If you do not wish this transfer to occur, you may choose not to use the Service or delete your account. Without the transfer, however, sign-in, storage, and restore cannot function, so the Service cannot be provided.

6. Your Rights

Requests are processed within 10 business days from the date received. Users in the Republic of Korea may also contact the Personal Information Dispute Mediation Committee (1833-6972) for assistance.

7. Security Measures

8. Users Under 14 Years of Age

The Service is not available to users under 14 years of age. If we become aware that information from users under 14 has been collected, we will delete it without delay.

9. Changes to This Policy

If this policy changes, we will notify you on this page at least 7 days before the effective date. Material changes will be separately notified within the app, and fresh consent will be obtained where required.

10. Contact

Data Protection Officer KIM DAESUNG (Director)
Contact privacy@tasta.app
Company Daysun Labs Pte. Ltd. · Address 152 Beach Road, #23-02, Gateway East, Singapore 189721