Tasta

Privacy Policy

Effective date 2026-10-01 · Last updated 2026-09-08

Daysun Labs Pte. Ltd. (hereinafter "the Company") sets out in this policy how it handles users' personal information when providing the mobile app Tasta (hereinafter "the Service").

This is a reference translation; in case of any discrepancy, the Korean version prevails.

Three things to know upfront

  • Photos confirmed into food records are stored, for backup and recovery, only as two resized copies made on your device (a display copy and a preview), in a private repository other users cannot see. The original file stays on your device and is never uploaded. This comes in two parts — automatic backup for new photos (uploading photos you take from now on) and cloud photo storage & recovery (keeping and restoring photos already uploaded). You can turn backup off at any time in Settings → Automatic backup for new photos, and when you do, you choose whether to keep or delete the photos already uploaded. If you keep them, storage and recovery continue, and you can delete them at any time from Settings → Delete all cloud photos. During automated operational checks (verifying that photos have not been corrupted), the photos pass through the execution environment of a provider the Company has entrusted — Section 5 names that provider and the scope.
  • The location where a photo was taken (GPS) is only stored when you explicitly consent to it. It is not stored before you are asked.
  • We do not use or sell your records for advertising. They are not disclosed to other users.

1. Information We Collect

At sign-up

Item Required Description
Email address Required Used for sign-in and account recovery. If you choose to hide your email address when signing in with Apple, a relay address created by Apple is sent instead, and the Company cannot see your actual address.
Account identifier Required A value the Service generates automatically at sign-up to distinguish accounts (common to all sign-up methods — this is the value retained as a hash in the deletion-request record in Section 4). When you sign in with Apple or Google, an identifier issued by that provider is also received.
Sign-in method Required Stored on your device to guide you to the same method next time. Which sign-in methods are linked to your account (method type and link time) is also recorded on the server for account-recovery guidance.

Phone number, date of birth, gender, address, and payment information are not collected. A name is received only when you sign in with Google and Google includes it in the authentication information; it is not collected through other methods. Passwords are not used and therefore not stored.

Generated while using the Service

Item Required Description
Food records Required Food names, tags, ratings, notes, and timestamps recognized from photos.
Preference signals Required Per-tag food preferences calculated from records, plus allergy tags and dislike tags chosen by the user. Used to generate recommendations and filter allergy items.
Recommendation history Required Which recommendations were received, saved, or excluded.
Resized photo copies and previews Optional (can be turned off in Settings) Only the resized copies and previews of photos confirmed into food records are uploaded to private backup storage; the original files are not uploaded. Turn off Settings → Automatic backup for new photos and new photos will not leave the device. Keeping and restoring photos already uploaded is a separate service, removable at any time via Settings → Delete all cloud photos.
Information derived from the original photo Optional (on/off together with photo backup) The original file itself is never uploaded, but five values derived from it are sent so the same photo can be recognized again — a fingerprint (a one-way value the content cannot be recovered from), the file format, the file size, the pixel dimensions, and the capture time. These are used to reconnect a photo to an existing record after a reinstall and to avoid uploading the same photo twice. The photo cannot be reconstructed from these values.
Photo location (GPS) Optional (separate consent) Used to open map apps at the precise location. Can be turned off at any time in app settings; when turned off, no new locations are stored from that point on.

Automatically accumulated

Item Description
Photo backup consent records (version of the consented document, purpose, retention approach, photo variants, storage region, upload network setting, time of consent, and the time of withdrawal if withdrawn) While the account exists. Even after you withdraw consent, the record itself is kept to evidence that the withdrawal happened Deleted together with the account
App usage logs A record of what actions occurred. Used for service improvement and error analysis. These logs carry an account-scoped identifier; when you delete your account, that identifier is replaced with a value from which the original cannot be recovered, and the logs themselves are deleted per the periods in Section 4.
App version · App language Stored alongside logs to identify the environment in which issues occur.
Country · Region Stored only at the country and city/district level. Coordinates and detailed addresses are blocked from appearing in these logs by the server.
Installation identifier Random values created when the app is installed (one for photo uploads, one for usage logs). They are not device serial numbers or advertising identifiers, and on the device they disappear when the app is uninstalled. There are two server records — ① the value stored with upload records of photos is marked inactive when the photo is deleted and removed when the account is deleted; ② the install value attached to app usage logs is replaced with an irreversible value when the account is deleted and then removed with those logs per the periods in Section 4.
Photo analysis count · Last-used time Used in the summary screen to confirm the account after reinstallation.

When you contact us

When you write to privacy@tasta.app or support@tasta.app, or exercise your rights, that email (sender address, delivery headers, subject, body, attachments) remains in the Company's mailbox. It is kept to verify how the request was handled and to compare repeat requests; the retention period is stated in the Section 4 table.

The advertising identifier (IDFA) is not collected. The app does not include advertising or marketing tracking tools, or external analytics or crash-collection tools.

2. Purposes of Use

We do not use data beyond the above purposes. If purposes change, we will notify you in advance and obtain fresh consent where required.

3. How We Handle Photos

4. Retention Periods

Data While account is active Upon deletion request
Account information (email address, account identifier, sign-in method and link records, and the name received when signing in with Google) While the account exists Deleted immediately when you delete your account
Food records · preference signals · recommendation history While the account exists Deleted immediately
Photos held in cloud storage While you use storage & recovery. If you turn automatic backup off and choose ‘Keep existing photos’, storage continues; if you choose ‘Delete all existing photos’ or run Delete all cloud photos, they are deleted then Access blocked immediately; removed after deletion queue processing
App usage logs 90 days Pseudonymised immediately and cleaned up daily; deleted within 30 days of the request
Inquiry and rights-request email 3 years after the request is handled (the period needed to verify handling and compare repeat requests) On request, the body and attachments are deleted, leaving the handling record (request type, date received, outcome) and the sender address needed to compare repeat requests
Server backups No separate automatic backup operated by the Company No restore copy is created separately from the operational data

There are two exceptions to this table. ① The account-deletion request record — an irreversible hash of the account identifier plus the request time — is retained as evidence that deletion was carried out. It contains no original personal information such as an email address. ② The photo-deletion processing record — when a server photo is deleted, the deletion queue keeps a processing entry containing the storage path of the removed file (which includes an account-distinguishing value) and the processing time, retained as evidence that the deletion was actually carried out. The photo content itself is not retained. Should any legally mandated retention items arise, they will be communicated as further exceptions to this table.

5. Service Providers We Entrust

The Company does not sell personal information. Processing is entrusted to the following providers solely to the extent necessary to operate the Service. Apple and Google are not among them: they are not providers the Company entrusts with processing but providers of sign-in, and they are listed separately below. That said, Google is also the processor for the Company's mailbox (Google Workspace), which receives inquiry email — that role appears in the tables below.

What applies to every recipient — by the nature of internet communication, the parties your device connects to directly (Supabase; Cloudflare when you open these pages; Apple and Google when you sign in; Google when a map opens as a web URL; Apple when the App Store opens because the Naver Map app is missing) receive your device's connection information (IP address, time of access, request data) each time. Parties reached through processing servers rather than from your device (Resend, Anthropic, GitHub, Google as the Company's mailbox provider) do not communicate with your device directly, so the connection information they see belongs to the connecting server, not to your device. Each recipient decides how long it keeps that information under its own policy; the Company does not separately receive and store it (records on the Company's own server follow the period set by the app usage logs row in Section 4). The tables below do not repeat this common point and list only what is specific to each party.

Provider Task entrusted Information transferred
Supabase Pte. Ltd.
(Singapore entity)
Account & record storage, photo storage, authentication All app and server storage items listed in this policy (inquiry email does not use this route — see the Google row below)
Plus Five Five, Inc.
(trading as Resend · US entity)
Sending verification code emails Email address and the one-time verification code contained in the message body
Cloudflare, Inc.
(US entity)
Serving this policy and terms pages (web hosting) Connection information exchanged when a page is opened (request information such as IP address). Where deployment is connected to the repository, the repository copy also goes here and includes operator contact details in current operational and historical records and the previous administrator address in change history; deploying by uploading only the web/ directory transfers no repository copy
Google
(the Company's mailbox, Google Workspace — contracting entity Google Asia Pacific Pte. Ltd., a Singapore entity)
Providing the Company's mailbox — receiving and storing inquiry email The entire inquiry email sent to privacy@tasta.app or support@tasta.app (sender address, headers, subject, body, attachments) — it arrives directly from the sender's own mail service
GitHub, Inc.
(US entity · Microsoft group)
Photo integrity checks and the recording of training eligibility from their results (once-daily scheduled runs plus manual operator runs), and administrator account verification when the Company runs server bootstrap The resized copies and previews being checked and their asset identifiers, the account identifier and storage path (the leading path segment is the account identifier), the bucket name, the stored fingerprint, and the file size. Photos only pass through during the check and disappear with the execution environment when it ends; the execution log retains asset identifiers, and when a check fails the storage path (which contains the account identifier) is also written to the error message. When the Company runs server bootstrap, the administrator account's email address is also processed (it is masked so that it does not remain in new execution logs; past execution logs may still contain the previous value)
Anthropic, PBC Generating recommendation text (see below)
The recommendation feature is not connected to the app, so no transfer currently occurs.
Food tags, tags of recently eaten food, dislike tags, the list of restaurants you saved, publicly available restaurant information together with its internal identifier, price band and authenticity tier, the distance band computed from your location, time of day, day of week and city, the app display language, and the adventurousness level and previous choice you selected, and per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role. Email addresses, account identifiers, notes, and similar content are not sent.

Sign-in providers

The two providers below are not entrusted with processing by the Company. They process information on their own terms and privacy policies when you sign in with their accounts.

Provider What it does Information exchanged
Apple Inc. Sign in with Apple Authentication credentials as defined by Apple — the Company requests the email scope (a relay address is delivered if you choose to hide your email)
Google LLC Sign in with Google Authentication credentials as defined by Google (name, email, account identifier)

What is sent when generating recommendations

The Service may use an external AI service at the recommendation generation stage. What is sent at that point is limited to the following.

Cross-border transfer

The Company is a Singapore entity and its servers are located in Japan, so providing the Service involves transferring information outside the Republic of Korea as set out below. The five items required by law are stated in full for the providers the Company currently entrusts with processing (Supabase Pte. Ltd., Plus Five Five, Inc., GitHub, Inc., and Cloudflare, Inc.). Google, as the Company's mailbox, is among them. The Anthropic row gives advance notice of the terms that will apply if the recommendation feature is activated; the feature is not connected, so no transfer to Anthropic currently occurs. The Apple and Google sign-in rows and the Google Maps row are not transfers made by the Company: they are information exchanged directly with those companies when you choose that sign-in method, listed here for reference so that you know information leaves the country, with retention determined by their own policies.

Recipient (entity & address) Country of storage Items transferred Timing & method Recipient's purpose of use Retention & use period
Supabase Pte. Ltd.
Singapore · 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513
Japan (Tokyo) All app and server storage items in Section 1 (inquiry email does not use this route) — account information, food records, taste signals, recommendation history, backed-up resized photo copies and previews, the photo capture location (GPS coordinates) where separately consented, app usage logs. The authentication tokens that keep you signed in (access and refresh tokens) are also sent with requests. When you sign in with Google, the authorization code returned by Google and the verifier generated by the app also go to the authentication server. When a photo is uploaded, the file is accompanied by its checksum, media type, byte size, pixel dimensions and capture time, together with the identifier of that photo inside your photo library so the app can find it again on the device. When you consent to backup, the consent record (version of the consented document, purpose, retention approach, which photo variants are uploaded, storage region, the network setting you chose for uploading, and the time of consent) is stored on the server. Records that remain after deletion also live on this server: the account deletion request record (hash and timestamp) and the photo deletion execution record (including the storage path), described in exceptions ① and ② under the Section 4 table When an account is created, each time you sign in again (the email address and verification code, the token issued by Apple, or the authorization code from Google together with the app's verifier, are sent to the authentication server), each time you link an additional sign-in method to the account (the same credentials are sent), each time the session is refreshed automatically (the refresh token is sent to the authentication server), and each time records and photos are stored or loaded (the access token accompanies each request). App usage logs are also sent asynchronously while you use the app, including actions that save no record. All transfers use an encrypted connection (TLS) Storing accounts and records, photo backup and restore, and authentication on the Company's behalf As set out in the Section 4 table. If the contract between the Company and the recipient ends, copies are deleted after the 30 days following termination have passed (those 30 days are the window in which the Company may retrieve a copy; deletion follows once it closes)
Plus Five Five, Inc. (trading as Resend)
United States · 2261 Market Street #5039, San Francisco, CA 94114
United States Email address, and the one-time verification code (6 digits) contained in the message body When verification code emails are sent, over TLS Sending email and recording delivery results The verification code expires shortly after the email is sent and cannot be used to sign in after that. Email data, including delivery records, is retained for 30 days (all plans — per Resend's official documentation)
Cloudflare, Inc.
United States · 101 Townsend St., San Francisco, CA 94107
Cloudflare Privacy Policy
The United States (headquarters and primary processing country) and servers distributed worldwide to serve pages quickly — this varies with where you connect from, so no single country can be identified (see the linked policy). The Company checked whether region-restriction settings (Regional Services) were available and found that they are not offered on the Company's plan (an enterprise-only feature — confirmed 2026-08-19) Page connection information (such as IP address) and, where deployment is connected to the repository, the repository copy (not transferred when only the directory is uploaded) When this page is opened and when the Company deploys the pages Serving the pages and processing the repository copy for deployment Deployed copies of the pages remain until the Company deletes them — a new deployment does not delete earlier copies but keeps them in the deployment history, where each copy stays reachable at its own address. Retention of connection records follows Cloudflare's own policy, as set out in the common note at the top of this section
Google (the Company's mailbox, Google Workspace)
Contracting entity: Google Asia Pacific Pte. Ltd. (Singapore) · 70 Pasir Panjang Road, #03-71, Mapletree Business City II, Singapore 117371 · Processing: Google LLC and affiliates
The United States and other regions Google determines (the Company's Google Workspace plan does not allow choosing a storage region) The entire inquiry email sent to privacy@tasta.app or support@tasta.app (sender address, headers, subject, body, attachments) When inquiry email arrives (it is transmitted directly from the sender's own mail service to the Company's mailbox) Providing the Company's mailbox — receiving and storing inquiry email As set out in the inquiry and rights-request email row of the Section 4 table
GitHub, Inc.
United States · Microsoft group
88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States
Country where the execution environment (GitHub-hosted runner) is located: the United States and other regions GitHub determines — the runner's location cannot be chosen by the user. The repository itself is stored in countries determined by GitHub (see their policy linked above) The resized copies and previews being checked, their asset identifiers, the account identifier and storage path (the leading path segment is the account identifier), the bucket name, the stored fingerprint, and the file size. For server bootstrap runs, the administrator account's email address (stored in encrypted form as the GitHub Actions secret HOSTED_ADMIN_EMAIL and masked before its first use during the run so that it does not remain in the execution log; past change history and past execution logs may still contain the previous value — execution logs follow the retention limit below) When the daily scheduled check runs, and when an operator runs the check manually (a manual run downloads up to 1,000 pending photos per round, 100 by default. The default check-only run stops after one round; a run that also applies results repeats for up to 20 rounds by default, so a single execution can move more than that). The server bootstrap task occurs only when the Company runs it. The administrator address has been removed from the inputs and default values in the current hosted-bootstrap workflow file and is passed to the execution environment from a GitHub Actions secret managed by the Company. The previous value remains in past change history. All transfers use TLS. Photos only pass through during the check and are not stored in the execution environment Verifying that photos held on the server have not been corrupted or replaced (integrity check), and administrator account verification during server bootstrap. The result is also recorded as a precondition that a future photo-training feature would require — but no consent flow for training exists, so no photo is used for training today, and this record alone creates no basis for training Photos disappear with the execution environment when the run ends. Retention limit for the execution log containing asset identifiers: 90 days (the repository's configured value). The administrator-address default was removed from the hosted-bootstrap workflow file; the value in past change history is left in place without rewriting (the repository is private, and rewriting history carries greater side effects). Addresses in past execution logs disappear once the retention limit above passes. The HOSTED_ADMIN_EMAIL secret remains stored by GitHub until the Company deletes or replaces it
Anthropic, PBC
United States
United States Food category tags and preference levels, tags of recently eaten food with how many days ago and their confidence, and dislike tags, the names and identifiers of restaurants you have saved, publicly available information about candidate restaurants together with their internal identifiers, price bands, authenticity tiers and the distance band computed from your location, time of day, day of week and city, the app display language, the adventurousness level and previous choice you selected, per-tag exposure counts, how many days ago each recent record was made with its confidence, a per-candidate recently-suppressed flag, and a per-candidate recommendation role (account identifiers, email addresses, notes, and photos are not sent) When recommendations are generated, over TLS. This feature is not currently wired into the app, so no transfer actually occurs. Generating recommendation text This feature is not currently wired into the app, so no transfer occurs. The actual retention period will be stated in this cell before the feature is enabled
Google LLC (Maps)
United States
No specific country stated — Google Privacy Policy Where a place identifier is recorded, the place name and that identifier; where only coordinates exist, the coordinates (without the name); where neither exists, the place name. Opening the web URL also passes your device's connection information (request data such as the IP address) to Google When you tap Open in maps, carried in the map URL To show that location on a map Not determined by the Company; Google's own policy governs (see link)
Apple Inc.
United States
United States and others — Apple Privacy Policy Authentication credentials required for sign-in When you sign in with Apple. Your device's connection information also reaches Apple when the App Store page opens because the Naver Map app is missing Sign-in authentication Not determined by the Company; Apple's own policy governs (see link) — this row is listed for reference, as it is not a transfer made by the Company
Google LLC
United States
No specific country stated — Google Privacy Policy Authentication credentials required for sign-in When you sign in with Google Sign-in authentication Not determined by the Company; Google's own policy governs (see link) — this row is listed for reference, as it is not a transfer made by the Company

Apple and Google do not identify a single country, as their policies allow processing on servers worldwide. For sign-in, what is passed to them is limited to authentication information. Google additionally receives the place name and, where you tap Open in maps, either the recorded place identifier together with the place name (this does not depend on location consent) or, where no identifier exists and you consented to capture-location use, the coordinates alone (without the name) — that is the Google Maps row above. The countries of processing are described in their policies linked above.

When you open a map app

Tapping Open in maps on a record makes the app build and open a map service URL. What that URL carries depends on the service and on what is recorded for the place.

Nothing is sent unless you tap. Google Maps opens as a web URL, so that step also passes your device's connection information (such as the IP address) to Google. Naver Map opens an app installed on your device, so no connection information goes to the Company or to Naver's servers at this step. If the Naver Map app is missing or fails to open, the App Store page for Naver Map opens instead, and your device's connection information is passed to Apple at that moment.

If you do not want this, simply do not tap Open in maps. Turning off capture-location use in app settings means records created after that store no coordinates, so their map URLs carry none. However, records that already have coordinates keep them, and opening a map from those records still carries the coordinates — to remove those, delete the record itself (Section 6).

Sub-processors engaged by the recipients

The recipients also engage other providers to operate their services. The place where user accounts, records, and photos physically reside is storage provided by Amazon Web Services, Inc. (a US entity) in its Japan (Tokyo) region. In other words, the recipients' country of incorporation (Singapore, United States) and the country where the information is stored (Japan) are different. The sending infrastructure for verification emails is provided by the same company (Amazon Web Services, Inc.).

For the features the Company uses (database, file storage, sign-in authentication, signed URL issuance), that one company is the only sub-processor confirmed to be involved in storing or processing user information. The recipients also engage providers for purposes such as support and monitoring; the full list is published in the sub-processor list published by Supabase. Whether those providers touch the information of the Company's users cannot be determined from the public list alone, so the Company verifies this as part of its contract review and will amend this policy if the answer differs. The contract provides a procedure under which the recipient gives advance notice of any change to its sub-processors and the Company may object. The Company reviews those changes and will amend this policy if a change differs from what is stated above.

Recipient contacts

Privacy contacts are published by Supabase, Resend (privacy@resend.com), Anthropic, and the Apple and Google policies linked above. Anthropic maintains a Korean domestic representative, Anthropic Korea, Limited (41F, 152 Teheran-ro, Gangnam-gu, Seoul · +82-2-6252-2080). GitHub's data protection contact is dpo@github.com, at 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States (GitHub Privacy Statement). You may also write to privacy@tasta.app and the Company will handle the request on your behalf.

Legal basis for the transfer

How to refuse the transfer, and what happens if you do

Protection comparable to Singapore standards

Because the Company is a Singapore entity, the Singapore Personal Data Protection Act (PDPA) also applies. That Act requires the Company to ensure by contract, or by equivalent means, that overseas recipients provide protection comparable to Singapore standards. The Company has confirmed the following safeguards in the published contract documents of Supabase Pte. Ltd., GitHub, Inc., Cloudflare, Inc., and Google as the Company's mailbox. The Company is confirming how the published data processing addendum of Plus Five Five, Inc. (Resend) applies to its current account and will complete any required acceptance, execution, or change of processing route based on that result. Anthropic, PBC is not yet receiving any transfer because the recommendation feature is not wired into the app; before enabling that feature, the Company will confirm that an agreement with the same contents applies.

Securing these safeguards is separate from the disclosure in this policy and is not replaced by it.

Apple's sign-in and Google's sign-in and Maps roles are not covered by those agreements. In those roles they are not providers the Company entrusts with processing; they process information on their own terms and privacy policies when you use those features (Google as the Company's mailbox is the exception — that role is included in the agreements above). For sign-in, what passes to them is limited to authentication information; Google Maps additionally receives the place name plus either the Google-assigned place identifier or, where it is absent, the consented coordinates when you tap Open in maps. Either way, their own policies linked above govern that processing.

6. Your Rights

Requests are processed within 10 business days from the date received. Users in the Republic of Korea may also contact the Personal Information Dispute Mediation Committee (1833-6972) for assistance.

7. Security Measures

8. Users Under 14 Years of Age

The Service is not available to users under 14 years of age. If we become aware that information from users under 14 has been collected, we will delete it without delay.

9. Changes to This Policy

If this policy changes, we will notify you on this page at least 7 days before the effective date. Material changes will be separately notified within the app, and fresh consent will be obtained where required.

10. Contact

Data Protection Officer KIM DAESUNG (Director)
Contact privacy@tasta.app
Company Daysun Labs Pte. Ltd. · Address 152 Beach Road, #23-02, Gateway East, Singapore 189721