Privacy Policy
Invictus Logic LLC ("we," "us," or "our") operates the Sito mobile application ("Sito" or the "App"). This Privacy Policy describes how we collect, use, store, and protect your information when you use our App.
By using Sito, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
1. Overview
Sito is a nutrition tracking application designed for parents and legal guardians ("you" or "Users") to monitor and manage their children's daily nutritional intake. The App is intended for use by adults aged 18 and older who are the parent or legal guardian of the children whose information they enter into the App.
Geographic scope: The App is offered through the Apple App Store and Google Play in the United States, the United Kingdom, Ireland, Canada, Australia and New Zealand. If you access the App from another country, you do so at your own initiative and are responsible for compliance with local laws. Nothing in this policy limits any rights over your personal data that the law of your country gives you.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (hashed using industry-standard methods; we never store or have access to your plaintext password)
- Authentication data from third-party sign-in providers (Google or Apple), if you choose to sign in using those services
2.2 Profile Information
- Preferred unit system (metric or imperial)
- Parenting concerns and motivations you select during onboarding
- Your time zone, and the time of day you choose for the daily check-in reminder
- The date you last used the App
- How you heard about Sito, when you tell us (for example from a leaflet or from your paediatrician)
2.3 Children's Information
For each child you add to the App, we collect information that you provide, including:
- Basic information: Name (a nickname or initials is fine — see 4.3), gender, and birthdate
- Physical measurements: Height and weight (used to calculate BMI)
- Health information: Activity level, allergies, and medical conditions
- Nutrition preferences: Priority nutrients you select for tracking
- Goal and eating profile: The goal you set for the child, whether you told us they are a picky eater, and the BMI category we calculate from their height and weight
2.4 Meal and Nutrition Data
When you log meals, we collect:
- Meal type, date, and time
- Food items, serving sizes, and nutritional breakdowns
- Meal photographs you choose to take or upload, and photographs of nutrition labels you scan. Uploading an existing photo asks for access to your photo library; the App reads only the picture you pick.
- Leftover/portion information
- Daily nutrition summaries and historical nutrition data
2.5 AI Chat Data
When you use Sito's AI nutrition assistant, we collect your chat messages and the assistant's responses, along with chat session metadata. To provide personalized responses, the AI assistant accesses your child's profile data, current nutrition intake, and recent nutrition history during your conversation.
2.6 Recipes and Food Preferences
- Custom recipes you create, including ingredients and nutritional information
- Foods you mark as favorites
- Your most frequently logged foods
- Which foods each child has accepted or refused, when you record that
2.7 Product Scanning
When you scan a barcode, search for a packaged product, or re-open something from My Scans, we record the lookup: the barcode number, which of our data sources answered it, whether the lookup succeeded, how long it took, and whether it came from the camera, from search, or from your history. These records are tied to your account so we can tell where the scanner is failing parents and fix it.
Your scan history itself — the last 100 products you looked at — is kept on your device, not on our servers. Deleting the App removes it.
2.8 Product Contributions
When a scan finds a product we do not have, the App offers to let you photograph the nutrition label and the front of the pack so we can add it. If you choose to do that, we collect:
- The nutrition-label photograph, and the front-of-pack photograph if you choose to take it — that step is skippable — stored in private cloud storage in a folder named with your account identifier
- The product's barcode, name, brand and the nutrition values read from the label
- Your account identifier, recorded as the submitter
Contributions are a permanent record: they are reviewed by us before they go anywhere, and once submitted you cannot edit or withdraw one from inside the App. Section 4.4 explains what happens to a contribution after we review it, and Section 9 explains what happens to it when you delete your data.
2.9 Voice Input
If you dictate a recipe instead of typing it, the App asks for microphone access and sends the recording to your phone's speech service — Apple's on iOS, Google's on Android — to be turned into text. That means the audio leaves your device and goes to Apple or Google under their own privacy policies. We receive only the transcribed text, and we do not store the recording.
2.10 Feedback and Support Data
If you submit feedback through the App, we collect feedback type and message content, app version and device information.
2.11 Device and Technical Data
Authentication tokens (stored securely on your device) and cached data for offline functionality and performance optimization.
IP address. Like any app that talks to a server, Sito's servers see the IP address your phone connects from. Two things then happen to it that are worth naming: our analytics provider records it and derives an approximate location from it (Section 5), and when someone enters a partner access code we store a one-way scrambled form of the IP for up to 24 hours to stop people guessing codes.
We do not collect GPS or any other precise location, your contacts, or your browsing history. The approximate location described above is the city-level estimate derived from an IP address, not a reading from your phone's location services, and the App never asks for location permission.
3. How We Use Your Information
We use the information we collect to:
- Provide the App's core functionality: Track your children's nutrition, calculate personalized nutrition targets, generate daily summaries, and display progress
- Power AI features: Provide personalized nutrition guidance and meal suggestions
- Calculate health metrics: Compute BMI and age-appropriate nutrition targets
- Improve the App: Analyze how the App is used — which screens and features people open, and where things fail (see Section 5)
- Build the product database: Review the label photos and nutrition values parents contribute, and add the products to the shared database every user scans against (see 4.4)
- Keep the scanner honest: Use scan records to find the barcodes we are failing to answer and the sources that are answering them badly
- Communicate with you: Respond to your feedback and support requests
- Process subscriptions: Manage your subscription status
- Measure our advertising: Understand which campaigns bring parents to Sito, as described in Section 5
4. How We Share Your Information
We do not sell your personal information or your children's information. We never send health, nutrition, meal, photo, or child information to any advertising network or data broker; the only data any advertising partner receives is described in Section 5 below. We share information only in the limited circumstances below.
4.1 Service Providers
These are all of the companies that receive information from Sito, and exactly what each one gets:
- Supabase — hosting, database, file storage, and authentication. Receives your account data, children's profiles, meal and nutrition data, chat history, and meal and nutrition-label photos.
- Google (Gemini API) — AI meal-photo analysis, nutrition-label reading, chat, meal ideas, and weekly reports. Receives meal and nutrition-label photos, your chat messages, and your child's profile context (see 4.2 and 4.3).
- OpenAI — the same AI features, used as our alternative provider and for analyses that need a stronger model. Receives the same information as Gemini.
- FatSecret Platform API — per-serving nutrition data. Receives food search terms and barcode numbers only; no account, parent, or child information is sent. Use of food and nutrition data in the App is also subject to the fatsecret Platform API Terms of Use.
- Cloudflare — the network our FatSecret requests pass through. Receives the same food search terms and barcode numbers, and nothing else.
- RevenueCat — subscription management and receipt validation. Receives your account identifier, your email address, and device and advertising identifiers, and passes your subscription events on to PostHog and Meta. On Android it also receives, once, the Google Play install referrer: the campaign labels on the link the app was installed from (which of our pages, profiles or flyers it was), never a search query or anything about you. No child or nutrition data.
- PostHog — product usage analytics. Receives which screens are opened and which features are used, along with your IP address and the approximate location derived from it, your device model, operating system, app version and screen size. Through the RevenueCat connection above it also receives your email address, your advertising identifiers and your subscription status. It never receives your child's name, health information, food data, chat content or photos. On Android it also receives the same Google Play install referrer described under RevenueCat, once, at first launch. Section 5 sets this out in full.
- Meta (Facebook) — measuring our app-install and subscription advertising. Receives the events we send it (account registration, free-trial start, subscription and purchase), the app-install and app-open events its SDK logs at launch, and your device's advertising identifier — on iOS only if you allow it at Apple's tracking prompt, on Android by default. Never health, nutrition, meal, photo, or child data.
- Apple (Apple Ads) — measuring the App Store ads we run. On iOS the App collects Apple's attribution token at launch and passes it to Apple and RevenueCat, which tells us which ad campaign an install came from. It does not identify you to us personally.
- Expo — two jobs. It delivers our push notifications, and it serves the over-the-air updates that let us fix the App without a store release; the update check tells Expo your IP address, platform and app version.
- Apple (APNs) and Google (FCM) — delivering push notifications to your device. Receive the notification text and your device's push token. Reminder notifications can include your child's first name, which is visible on your lock screen.
- Apple and Google speech services — turning dictated recipes into text, as described in 2.9. Receive the audio recording.
- Loops — sending our account, support and cancellation-survey email. Receives your email address; when you send us feedback, your message along with your app version and device model; and, when a subscription actually lapses, the fact that it has ended, so we can send a short survey.
- Apple / Google — Sign in with Apple / Google, and all billing. Receive your email address and authentication tokens.
- Open Food Facts — the open product database our catalogue is built from. It receives nothing about you or your children. If we accept a product you contributed, the product facts themselves — barcode, name, brand, nutrition values — may be published back to it under its open licence, with no link to you (see 4.4).
- Google Analytics and Convex — website analytics on sito.kids only, described in Section 5. They receive nothing from the App.
We use these companies as service providers, and their terms limit them to using the information to provide their service to us.
4.2 AI Data Processing
Sito's AI features run on models operated by Google (Gemini) and OpenAI. Two kinds of information are sent to them:
- Photos. When you photograph a meal or scan a nutrition label, that photo is sent to Google or OpenAI so the model can identify the food or read the label. Children are sometimes in these photos. Photos are sent for that analysis only.
- Text. When you use the AI assistant, ask for meal ideas, or receive a weekly report, your messages and your child's profile and nutrition context are sent to the same providers to generate the response (see 4.3).
We use these providers' paid APIs, whose terms state that information submitted through them is not used to train their models. Providers may still retain information for a limited period for abuse prevention, security, or legal compliance, in accordance with their then-current data usage and retention policies. We do not control those policies, which may change.
4.3 Your Child's Name and Profile in AI Features
So that AI answers are about your child rather than generic, we send your child's first name and the profile details relevant to the request to Google or OpenAI. Depending on the feature, that can include age, gender, height, weight, BMI, activity level, allergies, medical conditions, nutrition targets, and recent nutrition history. Meal-photo analysis receives your child's age and nothing else, and nutrition-label reading receives only the photograph of the label — no information about your child at all.
If you would rather not send your child's real name, enter a nickname or their initials instead of their legal first name when you add or edit a child. The App works exactly the same way, and everything you see will use the name you entered.
4.4 What You Contribute Becomes Part of a Shared Database
Sito scans against a product database we build from public food databases — chiefly Open Food Facts and the USDA's FoodData Central — plus the products parents contribute. Where our food data comes from, and the licences it carries, are set out on our food data sources page.
If you contribute a product (2.8) and we approve it, that product's barcode, name, brand and nutrition values become part of that shared database and are shown to every other Sito user who scans the same item. Your name, email address and account identifier are never shown alongside it; the contribution appears as coming from the Sito community, not from you. We keep the record of who submitted it internally, so we can trace a bad entry back and correct it.
Because the underlying databases are published under open licences, a contribution we accept may be redistributed under those licences too. Section 5 of our Terms of Service is the licence you grant us to do this, and you should read it before contributing.
4.5 Sharing Access With a Partner
Sito lets you generate a six-digit code so a second parent can use the account. Please understand exactly what that code does before you share it: it signs the other person in as you. There is no separate, limited partner account. Whoever redeems the code sees everything you see — every child's profile, allergies, medical conditions and measurements, every meal and photo, every AI conversation, and your subscription — and can change or delete any of it.
The code can only be used once, and it expires 30 minutes after you create it. We store the code, when it was created and when it was used, plus a one-way scrambled form of the IP address of anyone who tries a code, kept for up to 24 hours, so that nobody can guess codes by brute force.
You can end a partner's access whenever you want: Profile → Settings → "Sign out other devices" signs out every device on your account except the one in your hand. It is not instant — the other phone stays signed in until the session token it already holds expires, which can take up to an hour. Changing your password also works and is immediate, but it signs you out everywhere too. Only share a code with someone you would give your password to.
5. Advertising & Analytics
When this starts. Analytics and advertising measurement begin the first time you open the App, before you create an account. Until you sign up those records are held against an anonymous identifier; when you create an account, that identifier is joined to it, so the screens you visited before signing up become part of your account's record. Apple's tracking permission prompt also appears during onboarding, before signup.
PostHog — product analytics. We use PostHog to understand how the App is used: which screens are opened, which features are used, and where things fail. Those records never contain your child's name, age, measurements, allergies, medical conditions, food items, chat content or photos. They do contain more than the screen name, and we would rather say so plainly than let you assume otherwise. Each event also carries your IP address, and PostHog derives an approximate location from it — country, region, city and postal code — which it stores against your profile. It also records your device model and manufacturer, operating system version, app version and screen size. Separately, our RevenueCat connection sends your subscription events to PostHog, and those carry your email address, your device and advertising identifiers, whether you allowed tracking, and your subscription status.
Meta (Facebook) — advertising measurement. Meta's SDK is in the App to measure our advertising. It receives the events we send it deliberately — account registration, free-trial start, subscription and purchase — plus the app-install and app-open events its own SDK records at launch before we switch its automatic logging off. Beyond those, it does not receive a stream of your activity. On iOS it also receives your device's advertising identifier (IDFA), and only if you allow it at Apple's App Tracking Transparency prompt. On Android there is no equivalent prompt, and the advertising ID your device provides is collected by default; you can reset or limit it in your Android privacy settings.
Apple Ads — install attribution. On iOS we collect Apple's advertising attribution token at launch and share it with Apple and RevenueCat, which tells us which App Store ad campaign an install came from.
Our website. sito.kids uses Google Analytics and a second analytics service, Convex, for aggregate page views and traffic sources. For visitors in the United Kingdom, the EU/EEA and Switzerland, Google Analytics runs in consent mode with storage denied, so it sets no analytics cookies for them. This applies to the website only and touches nothing in the App.
We do not send your personal health data, your children's nutrition data, meal or label photos, or any other app content to Meta or to any other advertising network.
6. Subscriptions and Billing
All billing and payment processing is handled entirely by Apple (App Store) or Google (Google Play). We do not collect, process, or store any payment information.
7. Children's Privacy
Sito is designed for parents and legal guardians — not for use by children independently. Only individuals aged 18 or older who are the parent or legal guardian of the children they add may create an account, and before you can sign up you have to confirm that this is you. That confirmation is a condition of opening an account rather than a record we store, so there is nothing about it in Section 2. We comply with the Children's Online Privacy Protection Act (COPPA).
8. Data Storage and Security
Your data is stored on secure servers provided by Supabase, located in the United States. We protect it with the following measures:
- Encryption: Passwords are hashed using industry-standard methods; we do not store plaintext or reversibly encrypted passwords. Data is transmitted using HTTPS/TLS encryption.
- Row-level security: Our database enforces row-level security policies, so the App returns only your own data and your children's data to your signed-in account.
- Authentication: All API requests to our database require valid authentication tokens.
- Meal photo storage: Meal photos and the nutrition-label photos attached to a meal are kept in cloud storage. Today one of these can be opened by anyone who has its exact link, so treat those links as private. We are moving this storage to fully private access, where a photo can only be opened through a short-lived link created for your account.
- Contribution photo storage: The label and pack photos you submit through the contribution flow (2.8) are already in fully private storage. They cannot be opened by a link and are readable only by us.
- Account sharing: Row-level security protects your data from other accounts. It cannot protect it from someone signed in to your own account, which is what a partner access code creates — see 4.5.
While we take reasonable measures, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
9. Data Retention
We keep information only for as long as we need it for the purpose you gave it to us — running Sito for you and your children — and then we delete it. We do not keep children's information indefinitely for any other purpose, and we do not keep it after you delete it.
- Account and parent profile (email, unit preference, concerns you selected) — while your account exists.
- Children's profiles, measurements, and nutrition targets — while your account exists, or until you delete the child or your data.
- Meal logs, nutrition history, custom recipes, and food preferences — while your account exists, or until you delete them.
- Meal photos and the label photos attached to a meal — until you delete the meal, your data, or your account.
- Product contributions — kept indefinitely, and this is the one thing on this page that our delete buttons do not remove. Once a contribution is submitted it becomes part of a shared product database that other parents' scans depend on, so withdrawing it would take a product away from them. When you delete your account we clear the submitter field, so the contribution is no longer attributed to you. One trace does remain and we would rather name it than let you assume otherwise: the two photo files were saved in a folder named with your account identifier, and that path is written into the contribution record, so the identifier survives in the file path even after the submitter field is cleared. If you want a specific contribution and its photos removed outright, email us and we will take them out.
- Product scan records (2.7) — kept while your account exists. When you delete your account we unlink these from you, and the barcode-lookup record stays without your identifier so we can keep measuring where the scanner fails. We are working to put a fixed retention period on these; until we do, treat them as retained indefinitely in that unlinked form.
- Partner access codes and the scrambled IP addresses of code attempts — a code stops working 30 minutes after you create it. The expired codes and the scrambled addresses are then swept out, but the sweep runs the next time somebody creates or redeems a code rather than on a timer, so on a quiet week a dead row can sit for longer than a day before it is cleared.
- Your device's scan history — the last 100 products, stored only on your phone and removed when you delete the App.
- AI chat sessions and messages — while your account exists, or until you delete your data.
- Push notification tokens — while your account exists; removed when you delete your account, and only then. Turning notifications off on your phone, or deleting the App, stops the notifications reaching you but does not by itself remove the token we hold.
- Feedback and support messages — removed from the App's database when you delete your data or your account; a copy may remain in our support email records.
- A deleted account — your records and photos are purged from our live systems when the deletion runs: immediately when you delete in the App, or promptly after we process an emailed request. The two exceptions are the contributions and scan records above, which are unlinked from you rather than deleted. Backup copies rotate out within 30 days, except where the law requires us to keep something longer.
- Cached FatSecret nutrition data on our servers — no more than 24 hours, in compliance with the fatsecret Platform API Terms of Use.
- Cached nutrition data on your device — stored locally for offline use, and removed when you delete the App or clear its cache.
- Anonymous, aggregated records — for example counts of how often a feature is used or succeeds — kept without any link to you or your child.
- Information held by the providers listed in 4.1 — under each provider's own retention policy, which we do not control.
10. Your Rights and Choices
10.1 Access, Edit, and Delete Your Data
You can view and edit your profile, your children's profiles, and your meal logs directly within the App at any time. The App's Profile screen also gives you two deletion options. Both are permanent and cannot be undone.
"Delete all my data" removes everything you have logged but keeps your account, so you can start over with the same login and subscription. It removes all children's profiles (including measurements, allergies, medical conditions, and nutrition targets), all meal logs, nutrition summaries and food preferences, all AI chat sessions and messages, all custom recipes, and all meal photos and the label photos attached to a meal, and resets your unit preference, your selected concerns and your time zone. Your login, email address and subscription are kept, and so are two smaller settings — your daily check-in time and how you told us you heard about Sito.
"Delete all my data & account" removes everything above and then deletes your account itself. Once the request reaches our servers the purge completes there and your login is removed at the end, whatever your phone does next; it refuses to delete the login unless every other step succeeded. If you force-quit the App in the seconds before the request goes out, some data may already be gone while the account still exists — reopen the App and tap it again, or email us. Your subscription is billed by Apple or Google and is not cancelled by deleting your account — cancel it in your App Store or Google Play account settings.
What neither button removes. Products you contributed (2.8) and the record of barcodes you looked up (2.7) are not deleted by either button, for the reasons given in Section 9. Account deletion clears your identifier from both, though the contribution's photo file paths still contain it. To have a specific contribution and its photos taken out of the product database, email us.
If you are unable to open the App, follow the instructions on our account deletion page or email us at berkay@sitonutri.com from the address on your account. We will confirm by email once your data has been deleted.
10.2 Email Communications
We do not send unsolicited third-party marketing emails. Emails are limited to account verification, essential account-related updates, and periodic feedback requests or customer research inquiries to help us improve the App. All non-essential communications will include a clear, functional opt-out (unsubscribe) link, and you can opt out of these communications at any time.
11. California Privacy Rights
California residents have additional rights under the CCPA, including the right to know, delete, opt out of sale (we do not sell data), and non-discrimination. Contact us at berkay@sitonutri.com to exercise these rights.
12. International Users: United Kingdom, EU/EEA, Canada, Australia, New Zealand
This section adds what the law of your country requires us to tell you. Where it says more than the rest of this policy, this section applies.
12.1 Who is responsible for your data
Invictus Logic LLC, 1444 Rhode Island Ave NW APT 212, Washington, DC 20005-5421, United States, is the data controller for the information described in this policy. Contact: berkay@sitonutri.com. For Québec, the person in charge of the protection of personal information is Berkay Yenilmez, founder, at the same address.
12.2 Why we may process your information (lawful bases)
- Performing our contract with you — running the App: your account, your children's profiles, meal logs, nutrition targets, the scanner and the AI features you use.
- Your explicit consent — for the health-related information you enter about your children (allergies, medical conditions, measurements, meals and photos). You give it by entering the information and you can withdraw it at any time by deleting the child, your data or your account (Section 10). Withdrawing it does not affect processing that happened before.
- Our legitimate interests — keeping the App secure, preventing abuse, understanding how the App is used (the product analytics in Section 5, which never contain your child's health information) and improving it. You can object to processing based on legitimate interests.
- Consent — for advertising measurement where your country requires it (Section 5), which you can refuse or withdraw through your device's tracking settings.
- Legal obligations — where we must keep or disclose information by law.
12.3 Children as the people the data is about
The health-related information in Sito is about your children, and you provide it as their parent or legal guardian. We process it on the basis of your consent as their parent or guardian and only for the purposes in Section 3. We do not verify identities beyond the guardian confirmation at sign-up (Section 7).
12.4 Your rights
If you are in the United Kingdom or the EU/EEA you have the right to access your information, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, to withdraw consent, and not to be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (Sito's scores and suggestions are informational and do not have such effects). You can exercise most of these directly in the App (Section 10) or by email; we answer within one month. You also have the right to complain to a data protection authority, for example the Information Commissioner's Office in the United Kingdom, the CNIL in France or the authority in your own country, although we would appreciate the chance to help first.
If you are in Canada you have the rights of access and correction under PIPEDA and, in Québec, under the Act respecting the protection of personal information in the private sector, and you may complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec. If you are in Australia the Australian Privacy Principles apply, you have rights of access and correction, and you may complain to the Office of the Australian Information Commissioner; we will notify you and the Commissioner of any eligible data breach as the Notifiable Data Breaches scheme requires. If you are in New Zealand the Privacy Act 2020 applies, you have rights of access and correction, and you may complain to the Office of the Privacy Commissioner.
12.5 Where your information is stored and how it travels
Our servers are in the United States (Section 8), and the providers in Section 4.1 process information there or in their own regions. When information about people in the United Kingdom, the EU/EEA or Switzerland leaves those areas, we rely on our data processing agreements with each provider, which incorporate the EU Standard Contractual Clauses and the UK addendum or International Data Transfer Agreement where required, together with the security measures in Section 8. You can ask us for details of these safeguards.
12.6 How long we keep it
The retention periods in Section 9 apply everywhere.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App before the changes take effect.
14. Contact Us
Invictus Logic LLC
1444 Rhode Island Ave NW APT 212, Washington, DC 20005-5421, United States
Email: berkay@sitonutri.com
15. Consent
By using Sito, you consent to the collection, use, and processing of your information and your children's information as described in this Privacy Policy. As Section 5 explains, the analytics and advertising measurement described there begin when you first open the App, before you create an account; everything about you and your children in Sections 2.1 through 2.9 is collected only once you sign up and enter it.