Privacy policy
Last updated: 21 September 2026
1. Controller
The controller for personal data processed on the website getabite.app and in the GetaBite app for iOS is:
52N34S Group – Steffen Giebler
Steffen Giebler
Schwedter Str. 25
10119 Berlin
Germany
Email: support@52n34s.com
2. Overview
GetaBite analyses photographed menus, lets you search for restaurants nearby, can link a menu to a place, and reads product data for barcodes. This notice covers the website and the iOS app. No user account is required.
Personal data is processed only where needed for the respective action: when you join the waiting list, when analyses and other short-term limits apply, for location and address searches, for reports, and — in the app — when camera, photo and location permissions are used. We do not store menu photographs. Stored analysis results contain no identifier that would link them to a person.
3. Menu analysis
When you upload a photograph of a menu, it is resized in the browser or on the device and stripped of metadata (including GPS). We then send it to the image-analysis provider we engage, currently Anthropic, PBC, USA, via their programming interface. Anthropic processes the image solely on our instructions and for that one analysis. We do not store the photograph, do not share it, do not use it for advertising, and make it available to no one for training machine-learning models.
The legal basis is Article 6(1)(b) GDPR (performance of the contract of use) and, to the extent the transfer is to the United States, Article 46 GDPR together with the European Commission’s standard contractual clauses.
After the analysis we do not retain the image. Any storage at the processor is limited to the short-term technical extent of that processing.
4. Anonymous storage of analysis results
We store the machine-generated result of an analysis in the `scans` table. Only the following are stored:
- a random record key with no personal reference
- the time of storage
- the detected menu language, if the model provides one
- the name of the model used
- the duration of the analysis in milliseconds
- the recognised dishes and unreadable lines as structured data
No IP address, hash, location, photograph or other identifier is stored. The records cannot be attributed to a person. They are not personal data within the meaning of the GDPR.
The purpose is to improve the service, for example recognition quality. They are not combined with the waiting list, the rate limit or a nearby search.
5. Rate limiting of analyses
Analyses are limited to 20 images in 24 hours per connection. What is counted is the number of uploaded images in a request, not the number of requests. A SHA-256 hash is computed from the IP address and a secret that exists only on the server. The IP address itself is not stored for this purpose, is not logged, and is not linked to analysis results.
Only the hash, a counter and the start of the time window are stored. Rows older than 24 hours are deleted.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is preventing abuse and controlling the cost of image analysis.
6. Waiting list
If you sign up for news, we process your email address and the language you are using. The sign-up takes effect only when you click the confirmation link in the email (double opt-in).
We also store the IP address and time of sign-up and — after you click the confirmation link — the IP address and time of confirmation. This is to show that the sign-up came from you and to prevent abuse.
Unconfirmed sign-ups are deleted after 14 days. After confirmation we keep the address until you unsubscribe. Every message contains an unsubscribe link. You may also write informally to support@52n34s.com.
Sending is handled by Resend, Inc., USA, as a processor. The legal basis for the sign-up is Article 6(1)(b) GDPR (contract for sending messages) and Article 6(1)(f) GDPR for IP address and timestamps. Transfers to the United States rest on Article 46 GDPR together with standard contractual clauses.
You must be at least 16 years old to sign up.
7. Nearby search
The browser or the app is asked for your location only when you expressly start a nearby search — never on page load and never on app launch. Before the permission dialog we explain what the coordinates are used for.
The coordinates are sent to our server, compared once with the restaurant database, and then discarded. They are not stored, not logged, and not linked to analysis results.
Without location permission you can search by place, city or address. If you enter an address and submit the search, our server sends the text you entered to Nominatim, the geocoding service of the OpenStreetMap Foundation, Cambridge, United Kingdom. Your IP address is not sent to Nominatim. For this map search the request is made only when you submit, not while you type. We cache results without linking them to you, for at most 24 hours.
If fewer than five places for the searched area are in our database, our server queries public map data from an OpenStreetMap Overpass server (overpass-api.de, operated by FOSSGIS e. V., Germany). The search area is transmitted, not your IP address. Places found are added to our database; your coordinates are not.
The legal basis is Article 6(1)(b) GDPR insofar as the search is part of the service you request.
The map view on the website loads vector tiles from OpenFreeMap. Your IP address is sent to that tile provider. OpenFreeMap does not require an access key. We do not store this transfer. For the map in the app, see section 11.
8. Linking and creating places
You can link an analysis to a restaurant. What is stored is the place identifier and the link to the analysis, not your location.
If a place is missing, you can create it with a name and a position on the map. To check the position, our server sends the chosen map coordinates to Nominatim (reverse geocoding). Your IP address is not sent to Nominatim.
During place selection after a scan you can type a name or an address in one field. While you type, only our own database is queried. Nominatim is called only when you expressly choose “Look up address” or confirm a pasted address or map URL. Your IP address is not sent to Nominatim. Results are cached as in section 7.
Newly created places appear in the public search only after an analysis has been linked to them or we publish them. To prevent abuse, creation is limited to five places in 24 hours per connection; the same hashing method as in section 5 applies.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is building the place collection and preventing abuse.
9. Reports
You can report dishes, analyses and places. What is stored is the chosen reason, the reported item and the time. For dish reports and abuse reports we also store a hash of the IP address and a server-side secret. The hash prevents the same connection from reporting the same item repeatedly; the IP address itself is not stored. Place-only reports do not store such a hash.
Open reports are kept until we have handled them — a deadline must not sweep away an unhandled complaint. Handled reports are deleted six months after they were handled, whether we upheld or dismissed them; the effect of an upheld report lies in its outcome, not in the report itself. Deletion runs automatically as part of the daily cleanup job.
Operators of a place can report via a contact form. We then process the chosen reason, your message, your email address and the place identifier. The message is forwarded to us by email (Resend, Inc., USA, as processor).
Legal basis: Article 6(1)(f) GDPR; the legitimate interest is moderating user-generated content. Where an email address is provided, sending rests on Article 6(1)(b) or (f) GDPR and, for transfers to the United States, Article 46 GDPR together with standard contractual clauses.
10. Product scanner
If you scan a barcode, our server sends the number to Open Food Facts, a non-profit database based in France. Your IP address is not sent to Open Food Facts. Product data come from Open Food Facts and are under the Open Database License. We cache retrieved products without linking them to you; older entries are refetched when needed (guideline: 30 days).
Legal basis: Article 6(1)(b) GDPR insofar as the scan is part of the service you request.
11. The iOS app
The app asks for camera, photo and location access only when you use the respective feature. Photographs are processed as in section 3. Favourites, saved receipts, hidden items and the chosen language stay on your device (local storage) and are not sent to us.
The map in the app is provided through Apple’s system map library (`MapKit` / Apple Maps). Map data and technical connection data may go to Apple; Apple’s privacy policy applies. Unlike the website, the app does not load tiles from OpenFreeMap.
Error diagnostics via Sentry apply to the app as in section 13.
12. Reach measurement
We measure page views on the website with Umami. We operate the software ourselves on our own domain. The script is loaded from that domain, not from a third party. The iOS app does not take part in this measurement.
Umami sets no cookies and stores no personal identifiers. No usage profile is created. A consent banner is not required for this.
Typically recorded are pages viewed, referrer, device type, browser, operating system, an approximate geographic region at country level, and language — without an IP address in readable form.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is understanding which pages are used without identifying individuals.
13. Error diagnostics
We use Sentry to find faults — on the website and in the iOS app. The provider is Functional Software, Inc. (“Sentry”), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Processing takes place in Sentry’s EU region; reports go to an ingest address inside the European Union. A data processing agreement is in place.
What is transmitted is technical information about a fault that occurred: the error message, the call stack, the page or screen reference without query parameters, browser or device type, and the time.
Expressly not transmitted:
- Photographs and image data. A fault in the analysis path transmits no image content. The report is stripped before it is sent.
- Location data. Coordinates from the nearby search and the query parameters of the corresponding endpoint are removed. Search terms and addresses in fault reports are removed.
- Raw responses from the analysis model.
- IP addresses. Storage is switched off on the client and in the Sentry project.
- Device name. The device name supplied by the operating system (on iOS often a personal name) is removed before sending.
- Screen recordings. Session replay is fully disabled, including on errors. In the app, crash screenshots and view hierarchies are also not attached.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the stable and secure operation of the application. Retention is 30 days.
14. Hosting and other recipients
The website is hosted by Vercel Inc., USA. Application data is held with Supabase (Supabase, Inc.) in a data centre in Frankfurt am Main, except where a processor is named in sections 3 or 6. The database for reach measurement is separate from the application tables.
Vercel and Supabase process data as processors. Where a transfer to a third country takes place, it rests on Article 46 GDPR together with standard contractual clauses.
Further recipients, as described in the sections above:
- Anthropic, PBC (image analysis)
- Resend, Inc. (email delivery)
- OpenStreetMap Foundation (Nominatim geocoding)
- FOSSGIS e. V. (Overpass API at overpass-api.de)
- OpenFreeMap (map tiles on the website)
- Open Food Facts (product data for barcodes)
- Apple (map display in the iOS app)
- Functional Software, Inc. / Sentry (error diagnostics)
Disclosure outside this processing on our behalf and the lookups named above occurs only if we are legally obliged to do so or you have consented.
15. Retention
- Menu photographs: not stored.
- Analysis results (`scans`): not personal data, so no GDPR erasure period.
- Image-analysis rate limiting: 24 hours.
- Short-term limits on other endpoints (hash, counter, window): after the respective window; cleaned-up rows are removed hourly where the cleanup job runs.
- Waiting list unconfirmed: 14 days.
- Waiting list confirmed: until you unsubscribe or ask us to delete.
- Nearby-search coordinates: not stored.
- Geocoding results (Nominatim): cache without personal reference, at most 24 hours.
- Created places: remain in the database until we remove them or you ask us to delete; unpublished places become public when an analysis is linked or we publish them.
- Product data (Open Food Facts): cache without personal reference; refetch when needed, guideline 30 days.
- Reports (`reports`): open ones until handled; handled ones — upheld or dismissed — six months after they were handled.
- Host server logs: according to the host’s rules, typically a few days where they arise. We do not write nearby-search coordinates to our application logs.
- Error diagnostics (Sentry): 30 days.
- On-device in the app (favourites, receipts, hidden items, language): until you delete them on the device or remove the app.
16. Your rights
Where we process personal data, you have the right of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on Article 6(1)(f) GDPR. You may withdraw consent with effect for the future. Withdrawal does not affect the lawfulness of processing up to that point.
A message to support@52n34s.com is sufficient to exercise these rights.
17. Complaint to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany.
18. Obligation to provide data, automated decisions
You can use analysis and nearby search without giving your name. An email address is required for the waiting list; without it we cannot perform the messaging contract. The operator contact form requires a message and an email address.
There is no automated decision-making including profiling within the meaning of Article 22 GDPR. Classification of dishes and products is a technical analysis, not a decision producing legal effects concerning you.
19. Changes
We will adapt this notice if the service or the law changes. The current version is available at getabite.app/privacy. If you are signed up to the waiting list, we will inform you of material changes by email.