Privacy Policy
Daysun Labs Pte. Ltd. (hereinafter "the Company") sets out in this policy how it handles users' personal information when providing the mobile app Tasta (hereinafter "the Service").
This is a reference translation; in case of any discrepancy, the Korean version prevails.
Three things to know upfront
- Photos do not go to the server by default. Only photos you separately consent to are stored in a private repository accessible only to you, for backup and recovery purposes.
- The location where a photo was taken (GPS) is only stored when you explicitly consent to it. It is not stored before you are asked.
- We do not use or sell your records for advertising. They are not disclosed to other users.
1. Information We Collect
At sign-up
| Item | Required | Description |
|---|---|---|
| Email address | Required | Used for sign-in and account recovery. If you choose to hide your email address when signing in with Apple, a relay address created by Apple is sent instead, and the Company cannot see your actual address. |
| Account identifier | Required | A value issued by Apple or Google to distinguish accounts. |
| Sign-in method | Required | Stored on your device to guide you to the same method next time. |
Name, phone number, date of birth, gender, address, and payment information are not collected. Passwords are not used and therefore not stored.
Generated while using the Service
| Item | Required | Description |
|---|---|---|
| Food records | Required | Food names, tags, ratings, notes, and timestamps recognized from photos. |
| Preference signals | Required | Per-tag food preferences calculated from records, plus allergy tags and dislike tags chosen by the user. Used to generate recommendations and filter allergy items. |
| Recommendation history | Required | Which recommendations were received, saved, or excluded. |
| Original and thumbnail photos | Optional (separate consent) | Only consented photos are uploaded to private storage. Without consent, photos do not leave the device. |
| Photo location (GPS) | Optional (separate consent) | Used to open map apps at the precise location. Can be turned off at any time in app settings; when turned off, no new locations are stored from that point on. |
Automatically accumulated
| Item | Description |
|---|---|
| App usage logs | A record of what actions occurred. Used for service improvement and error analysis. User identifiers attached to these logs are stored in a form from which the original value cannot be recovered. |
| App version · App language | Stored alongside logs to identify the environment in which issues occur. |
| Country · Region | Stored only at the country and city/district level. Coordinates and detailed addresses are blocked from appearing in these logs by the server. |
| Installation identifier | A random value created when the app is installed. It is not a device serial number or advertising identifier, and disappears when the app is uninstalled. |
| Photo analysis count · Last-used time | Used in the summary screen to confirm the account after reinstallation. |
The advertising identifier (IDFA) is not collected. The app does not include advertising or marketing tracking tools, or external analytics or crash-collection tools.
2. Purposes of Use
- To create accounts and to sign in and recover accounts
- To save food records and restore them even when changing devices
- To recognize food in photos and automatically fill in records
- To recommend restaurants that match your preferences
- To identify errors and improve the Service
- To respond to inquiries
We do not use data beyond the above purposes. If purposes change, we will notify you in advance and obtain fresh consent where required.
3. How We Handle Photos
- Photo library access is used only to read the photos you select. The app does not covertly scan your entire photo library.
- Food recognition processing takes place on your device. We use Apple's on-device image analysis capabilities; photos are not sent to a server or external AI service for recognition. Reading the location embedded in photos also takes place on the device.
- Photos uploaded to the server are not accessible via a public URL. They are only served via a short-lived temporary URL (valid for 60 seconds) issued after verifying ownership.
- The Company does not use photos uploaded by users to train new AI models.
- The app does not delete originals from your photo library.
4. Retention Periods
| Data | While account is active | Upon deletion request |
|---|---|---|
| Food records · preference signals · recommendation history | While the account exists | Deleted immediately |
| Consented uploaded photos | While consent is maintained | Access blocked immediately; removed after deletion queue processing |
| App usage logs | 90 days | Pseudonymised immediately, then fully deleted within 30 days |
| Server backups | Overwritten every 7 days | Disappear automatically within 7 days (no separate archive is made) |
Data whose retention is required by law is exempted from this table and will be communicated separately. Currently there are no such items in the Service.
5. Service Providers We Entrust
The Company does not sell personal information. Processing is entrusted to the following providers solely to the extent necessary to operate the Service.
| Provider | Task entrusted | Information transferred |
|---|---|---|
| Supabase | Account & record storage, photo storage, authentication | All storage items listed in this policy |
| Resend | Sending verification code emails | Email address |
| Apple | Sign in with Apple | Authentication credentials as defined by Apple (not requested by the Company) |
| Sign in with Google | Authentication credentials as defined by Google (name, email, account identifier) | |
| Anthropic | Generating recommendation text (see below) | Food tags and publicly available restaurant information only. Email addresses, account identifiers, notes, and similar content are not sent. |
What is sent when generating recommendations
The Service may use an external AI service at the recommendation generation stage. What is sent at that point is limited to the following.
- What is sent — Food category tags and their preference levels, tags of recently eaten food, dislike tags, publicly available information about candidate restaurants (name, menu, distance range), and context such as time of day and city.
- What is not sent — Account identifiers and email addresses, free-text input such as notes, menu names, and place names written directly by the user, photos, and allergy information. Allergy items are filtered by the server before the recommendation stage.
Cross-border transfer
Providing the Service involves transferring information outside the Republic of Korea as set out below. The items transferred, recipients, and purposes are as shown in the table above, and retention periods are as set out in Section 4.
| Recipient | Country of storage | When the transfer occurs |
|---|---|---|
| Supabase | Japan (Tokyo) | When accounts, records, and photos are stored |
| Resend | United States | When verification code emails are sent |
| Apple | United States and others — Apple Privacy Policy | When you sign in with Apple |
| No specific country stated — Google Privacy Policy | When you sign in with Google | |
| Anthropic | United States | When recommendations are generated |
Apple and Google do not identify a single country, as their policies allow processing on servers worldwide. What is passed to them is limited to the authentication information required for sign-in; the countries of processing are described in their policies linked above.
If you do not wish this transfer to occur, you may choose not to use the Service or delete your account. Without the transfer, however, sign-in, storage, and restore cannot function, so the Service cannot be provided.
6. Your Rights
- View & edit — Your records can be viewed and edited at any time within the app.
- Delete — Photos and records can be deleted individually, and your entire account can be deleted via Settings → Account → Delete account (설정 → 계정 → 계정 삭제) in the app.
- Withdraw consent — Photo backup and location tracking can be turned off at any time in app settings. Photo library and location permissions can be revoked in iOS settings.
- Download · Suspension of processing — If needed, please request via privacy@tasta.app. Handled after identity verification.
Requests are processed within 10 business days from the date received. Users in the Republic of Korea may also contact the Personal Information Dispute Mediation Committee (1833-6972) for assistance.
7. Security Measures
- Communications between devices and the server are encrypted.
- Row-level access controls are applied to the database to prevent access to other users' records.
- Photos uploaded to the server are stored in private storage and served only via short-lived temporary URLs.
- When an account is deleted, the identifiers in app usage logs are replaced with irreversible values.
- Administrative access is granted to the minimum number of personnel.
8. Users Under 14 Years of Age
The Service is not available to users under 14 years of age. If we become aware that information from users under 14 has been collected, we will delete it without delay.
9. Changes to This Policy
If this policy changes, we will notify you on this page at least 7 days before the effective date. Material changes will be separately notified within the app, and fresh consent will be obtained where required.
10. Contact
Data Protection Officer
KIM DAESUNG (Director)
Contact privacy@tasta.app
Company Daysun Labs Pte. Ltd. ·
Address 152 Beach Road, #23-02, Gateway East, Singapore 189721