生效日期:2026 年 9 月 29 日

一句話版本

不登入的話,你的飲食紀錄、身體資料和目標都只存在你的裝置上。只有在你按下快門、選了相簿照片,或在「找食物」輸入文字時,那張照片或那段文字才會送到我們的伺服器,轉交 AI 服務辨識,辨識完就不留。如果你選擇用 Apple 或 Google 登入,餐點、照片和目標會備份到我們的伺服器,只有你的帳號看得到,隨時可以在 app 內刪除帳號連同全部雲端資料;登入後,AI 從營養標示讀到的產品名稱和數字會用來建立共享營養標示,不含照片,別人也看不到是誰拍的(見「共享營養標示」)。你怎麼修正辨識結果,會以匿名統計回報,用來改進辨識準確度(見「使用統計與當機報告」)。沒有廣告,不追蹤你。

存在你裝置上的資料

Feastie 不需要登入就能完整使用。沒有登入時,下面這些資料全部儲存在你自己的裝置上,不會上傳到任何伺服器,我們看不到:

  • 每一餐的紀錄:食物、分量、營養數值、補充說明,以及辨識時用的照片
  • 你在「認識一下你」或「目標設定」填的身高、體重、年齡、性別、活動量,以及由此估算的每日熱量與營養素目標
  • 語言、每日提醒、Feastie Pro 狀態等 app 設定

刪除 app,這些資料就跟著刪除了;登入備份到雲端的部分除外,見下面「帳號與雲端備份」。

相機與相簿權限

相機只用來拍餐點照片。相簿權限用來在拍照畫面角落顯示你最新的一張照片,讓你可以直接用別的 app 拍好的餐點照片;app 不會掃描或上傳你相簿裡的其他照片。兩個權限都可以拒絕,拒絕後仍然可以手動輸入或用「找食物」記錄。

帳號與雲端備份(選用)

登入是選用的:不登入,app 的每個功能都照常運作。你可以在「設定 → 帳號」用 Sign in with Apple 或 Google 帳戶登入,之後餐點、照片和目標會備份到我們的伺服器,換手機或重新安裝後登入就能拿回來,同一個帳號也可以在多台裝置上使用。

登入時我們拿到什麼。登入提供者(Apple 或 Google)會給我們一個只用來認出你帳號的識別碼,以及你同意提供的 Email 與姓名。姓名只在帳號頁顯示,Email 用來在帳號頁顯示與辨認帳號;Apple 的「隱藏我的電子郵件」一樣可以用。我們不會拿 Email 去比對別的帳號,也不會寄行銷信。Apple 登入時,app 還會把 Apple 給的一次性授權碼交給伺服器換成一組憑證,只用於你刪除帳號時向 Apple 撤銷授權。

備份什麼。每一餐的紀錄(食物、分量、營養數值、補充說明)、餐點照片與補充照片、你的目標與身體資料、AI 推估或你修正過的食物,以及每日提醒的開關與時間。不備份:語言等裝置設定。為了讓多台裝置的紀錄合併,每筆紀錄會帶著一個隨機的裝置識別碼和修改時間。

訂閱。登入後,若你在 App Store 或 Google Play 訂閱了 Feastie Pro,我們會在你的帳號下記錄這筆訂閱的交易編號(Google Play 則為購買憑證)、方案與到期日,讓同一個帳號的其他裝置也能使用;不含任何付款資料。登入後每天的 AI 辨識次數也以帳號計算。刪除帳號時這筆記錄會一併刪除,但訂閱本身不會取消,需到購買時的商店取消。

存在哪裡、誰看得到。備份存在我們位於 Cloudflare 的伺服器:紀錄在 D1 資料庫,照片在 R2 儲存空間,依帳號隔離,傳輸全程加密。每個帳號免費有 1 GB 照片空間。只有你登入的裝置能讀取;我們不查看、不分析、不分享,伺服器也不會把備份的紀錄或照片交給任何 AI 服務——AI 辨識仍然只在你按下快門時送出當下那張照片。

手機上保留多久。登入後,手機只保留最近 30 天的照片檔案,更早的照片需要顯示時才從雲端載入,並暫存在裝置的快取裡。紀錄本身一直留在手機上。

登出與刪除帳號。登出後,手機上的紀錄保留,雲端的備份也保留,直到你刪除帳號。在 app 內「設定 → 帳號 → 刪除帳號」會立即讓帳號失效並撤銷 Apple/Google 的登入授權,伺服器上的紀錄、照片與帳號資料會在幾分鐘內清除完畢;手機上的紀錄保留,但只在雲端的舊照片就拿不回來了。

共享營養標示(登入後)

登入後,如果你拍的包裝食品照片裡有清楚的營養標示和條碼,AI 從標示上讀到的產品名稱和數字(每 100 公克的熱量與營養素),會在你儲存這一餐時,以你的帳號記在這個條碼底下。至少兩個帳號讀到一致的數字後,這組數字會成為共享營養標示,提供給之後拍到同一個條碼的所有使用者;別人看到的只有產品名稱、營養數字,以及有幾個帳號讀過,不會知道是誰拍的。

為了在你儲存時對得上 AI 讀到的內容,伺服器會把那一次辨識從標示上讀到的產品名稱與數字暫存最多一天,不含照片、補充說明或其他菜色;有寫補充說明的那一次不暫存,沒登入時也不暫存。刪除帳號時,你貢獻的紀錄會一併刪除。免費方案每天第一次貢獻,會多送 1 次 AI 辨識。

會離開裝置的資料

除了上面說的雲端備份(只在你登入後發生),只有下面三種情況,資料會從你的裝置送出,而且每一種都要你主動做一個動作才會發生。

1. AI 辨識餐點照片。你按下快門或從相簿選一張照片後,那張照片(連同你在「確認照片」加的補充照片與說明)會送到我們的伺服器(Cloudflare Workers),再由伺服器轉交 AI 服務(OpenAI 或 Google Gemini 的模型,依方案而定)辨識食物與估算分量。我們的伺服器不儲存照片,也不記錄請求內容;AI 服務依其 API 資料政策處理,可能為了濫用偵測短暫保存,但不用於訓練模型。請求裡只有照片、說明和固定的指令,沒有你的紀錄、身體資料或目標。如果照片裡拍到商品條碼,app 會在你的裝置上讀出條碼號碼,另外用這個號碼向我們的伺服器查詢是否已有共享營養標示(見「共享營養標示」);查詢只帶條碼號碼,不帶任何能認出你的資訊。

2. 找食物。你在「找食物」輸入的文字先在 app 內建的資料庫(衛福部食品營養成分資料庫與 USDA 常見食物;日文與韓文介面另含日本食品標準成分表與韓國食藥處的食品營養資料)比對。只有當內建資料庫的結果不到五筆、而且輸入看起來像食物名稱時,那段文字才會送到我們的伺服器:非英文會先請 AI 服務翻成英文名稱,再以英文向美國農業部的 FoodData Central(api.data.gov)查詢。FoodData Central 會保留自己的請求紀錄,這不在我們控制範圍內。如果內建資料庫和線上查詢都找不到,畫面會提供「讓 AI 用這段文字推估熱量」,只有你點了,那段文字才會送給 AI 服務推估。

3. Feastie Pro 訂閱驗證。購買由 Apple 處理,我們拿不到你的付款資料。訂閱後,app 會把 App Store 簽發的交易憑證送到我們的伺服器驗證,伺服器只記住這筆交易的識別碼、訂閱是否有效,以及已用掉的 AI 辨識次數;憑證裡沒有任何能認出你是誰的資訊。app 會產生一個隨機識別碼附在購買紀錄上,只有 Apple 留存,我們不拿它和 Feastie 帳號做任何比對。

如果你打開「每日提醒」,app 會把推播用的裝置 token 和你選的時間、語言交給伺服器,只用來在那個時間送一則固定文案的提醒;關掉提醒就會刪除。為了提供服務與防止濫用,我們的伺服器會短暫處理標準的連線紀錄(例如 IP 位址)以限制請求頻率,僅用於此目的。

使用統計與當機報告

為了知道 app 有沒有正常運作、AI 辨識準不準,我們使用 Google Firebase(Analytics、Crashlytics、Performance)收集匿名的使用統計、當機報告與效能數據。

會收的:裝置型號、系統版本、由 IP 推算的大概地區、一個匿名的安裝識別碼、當機紀錄、app 啟動與網路請求的耗時,以及「介面發生了什麼」的事件——例如完成了一次辨識(來源是相機或相簿、結果是成功或失敗)、存了一餐(來自相機或找食物)、看到了付費牆、要求了文字推估、辨識結果被存下時每一道菜的修改類型、你存下的熱量與 AI 估的熱量之間的比例,以及登入是否完成(用的是 Apple 還是 Google)、同步是否成功。

不會收的:你吃了什麼、任何食物名稱、搜尋文字、照片、營養數值、身體資料或目標。使用統計裡沒有你的 Feastie 帳號、Email 或姓名,也沒有任何能對應到帳號的識別碼;不使用廣告識別碼(IDFA),不用於跨 app 或網站追蹤。

這些資料只用來改善 app。Google 如何處理這些資料,請見 Google 隱私權政策。

官網 feastie.ai。我們的官網使用 Google Analytics 了解有多少人造訪、看了哪些段落、有沒有點下載連結。它會收到瀏覽的頁面、捲動與點擊外部連結等事件、瀏覽器與裝置類型、由 IP 推算的大概地區,並在你的瀏覽器存放 Google Analytics 的 cookie(名稱以 _ga 開頭)。歐洲經濟區、英國與瑞士的訪客預設不存放 cookie,只送出不帶 cookie 的統計訊號。官網不放廣告,這些資料也不用於廣告。網站所在的 Cloudflare 另外會以不使用 cookie 的方式統計造訪次數與載入速度。你可以在瀏覽器封鎖 cookie,或安裝 Google Analytics 停用外掛(tools.google.com/dlpage/gaoptout)。

第三方服務

  • Cloudflare:我們的伺服器所在,以及雲端備份的資料庫(D1)與照片儲存空間(R2)
  • OpenAI 與 Google Gemini:照片辨識、名稱翻譯與文字推估
  • USDA FoodData Central(經 api.data.gov):線上食物查詢
  • Apple:App Store 購買與訂閱、Sign in with Apple、推播通知
  • Google:Google 帳戶登入,以及 Firebase 的使用統計、當機報告與效能數據

我們不做的事

  • 不強制註冊:不登入也能完整使用
  • 沒有廣告
  • 不追蹤你在其他 app 或網站的行為
  • 不販售任何資料;除了共享營養標示上的數字(不含你是誰),不分享任何資料
  • 沒登入時,不會把你的飲食紀錄、照片或身體資料傳到任何伺服器保存;登入後的備份只有你的帳號看得到
  • 不會查看或分析你備份的紀錄和照片,也不拿它們訓練任何模型

兒童

Feastie 不是為 13 歲以下兒童設計的,我們也不會刻意收集兒童的資料。

刪除資料與你的權利

沒登入的話,刪除 app,你的紀錄、照片、身體資料與設定就跟著刪除了。登入過的話,在 app 內刪除帳號就會清除伺服器上屬於你的全部資料。除此之外我們的伺服器沒有保存任何能對應到你的資料:辨識用的照片與文字處理完即丟,訂閱驗證的紀錄只對應到 App Store 的交易識別碼並會自動過期,使用統計是匿名的。依《個人資料保護法》你有查詢、更正、刪除等權利;如果你認為我們持有你的個人資料,寫信給我們,我們會處理。

政策變更

如果這份政策有變更,我們會更新這個頁面並修改生效日期。重大變更會在 app 內提示。

聯絡我們

有任何問題,寫信給我們:[email protected]


Privacy Policy (English)

Effective date: September 29, 2026

The short version: Unless you sign in, your meals, body data and goals stay on your device. Only when you press the shutter, pick a photo from your library, or type into Search does that one photo or that piece of text go to our server, which passes it to an AI service for recognition and keeps nothing. If you choose to sign in with Apple or Google, your meals, photos and goals are backed up to our server, visible to your account alone, and you can delete the account with everything in the cloud from inside the app at any time; once you are signed in, the product name and numbers the AI reads off a nutrition label help build the shared nutrition labels, with no photo and without anyone else seeing who took it (see Shared nutrition labels). How you correct a result is reported as anonymous statistics, used to improve recognition accuracy (see Usage stats and crash reports). No ads, no tracking.

Data that stays on your device. Feastie works in full without signing in. While you are not signed in, every meal you log (foods, portions, nutrition values, notes and the photo it was recognised from), the height, weight, age, sex and activity level you enter, the daily calorie and macro targets estimated from them, and your app settings are stored only on your device. They are never uploaded to any server and we cannot see them. Delete the app and they are gone — except what you backed up by signing in, described under Account and cloud backup.

Camera and photo library. The camera is used only to photograph meals. Photo library access is used only to show your most recent picture on the camera screen, so a meal photographed in another app is one tap away; the app does not scan or upload other pictures in your library. Both permissions can be declined, and manual entry and Search keep working without them.

Account and cloud backup (optional). Signing in is optional; without it every feature works as before. Settings → Account offers Sign in with Apple and Google sign-in. Once signed in, your meals, photos and goals are backed up to our server, a new phone or a reinstall gets them back the moment you sign in, and one account can be used on several devices.

What we receive when you sign in. The provider (Apple or Google) gives us an identifier used only to recognise your account, plus the email address and name you agree to share. The name is shown on the account screen only; the email is shown there and used to recognise the account; Apple’s Hide My Email works too. We never match the email against other accounts and never send marketing mail. With Apple, the app also hands Apple’s one-time authorisation code to our server, which exchanges it for a credential used only to revoke the authorisation when you delete the account.

What is backed up. Each meal (foods, portions, nutrition values, notes), the meal photos and extra photos, your goals and body data, the foods the AI estimated or you corrected, and the daily reminder’s switch and time. Not backed up: device settings such as the language. So that records from several devices can be merged, each record carries a random device identifier and its modification time.

The subscription. When you sign in, if you subscribe to Feastie Pro on the App Store or Google Play, we keep the subscription’s transaction ID (for Google Play, its purchase token), plan and expiry under your account so the account’s other devices can use it; no payment details. Once signed in, the day’s AI recognitions are counted per account too. Deleting the account deletes this record, but does not cancel the subscription itself, which is cancelled in the store it was bought from.

Where it lives and who can see it. Backups are stored on our servers at Cloudflare — records in a D1 database, photos in R2 storage — separated by account and encrypted in transit. Each account has 1 GB of photo space, free. Only the devices signed in to your account can read it; we do not look at, analyse or share it, and the server never hands backed-up records or photos to any AI service — recognition still sends only the photo you take, when you take it.

How long the phone keeps photos. Once signed in, the phone keeps only the last 30 days of photo files; older photos are loaded from the cloud when shown and held in the device’s cache. The records themselves always stay on the phone.

Signing out and deleting the account. Signing out keeps the records on your phone and the backup in the cloud until you delete the account. Settings → Account → Delete account makes the account unusable at once, revokes the Apple or Google authorisation, and clears your records, photos and account data from our server within minutes; the records on the phone stay, but photos that lived only in the cloud cannot be brought back.

Shared nutrition labels (signed in). Once signed in, if a photo of a packaged food shows a legible nutrition label and its barcode, the product name and the numbers the AI read off the label (calories and nutrients per 100 g) are recorded under that barcode with your account when you save the meal. Once at least two accounts have read matching numbers, they become a shared nutrition label, offered to everyone who later photographs the same barcode; others see only the product name, the numbers and how many accounts read them, never who did.

So that saving can be matched to what the AI read, our server keeps the product names and numbers read off the label in that recognition for up to a day — no photo, no note, no other dish; nothing is kept for a recognition with a note, or while you are not signed in. Deleting the account deletes the readings you gave. On the free plan, the first reading you give each day earns one more AI recognition.

Data that leaves your device. Apart from the cloud backup above, which happens only after you sign in, data is sent from your device in exactly three situations, and each one needs an action from you.

1. AI meal recognition. When you press the shutter or pick a photo from your library, that photo — with any extra photos and the note you add on the confirmation screen — is sent to our server (Cloudflare Workers), which forwards it to an AI service (an OpenAI or Google Gemini model, depending on your plan) to identify the foods and estimate portions. Our server stores no photos and logs no request bodies. The AI service handles the request under its API data policy: it may be retained briefly for abuse monitoring and is not used to train models. The request contains only the photo, the note and a fixed instruction, never your records, body data or goals. If a photo shows a product barcode, the app reads the barcode number on your device and also asks our server whether a shared nutrition label exists for it (see Shared nutrition labels); the lookup carries only the barcode number, nothing that identifies you.

2. Search. Text you type into Search is first matched against the database bundled with the app (Taiwan FDA nutrition data and common USDA foods, plus Japan’s Standard Tables of Food Composition and Korea’s MFDS food composition data in Japanese and Korean). Only when the bundled database returns fewer than five hits and the text looks like a food name is it sent to our server: text that is not English is first translated into an English food name by the AI service, and that English name is then looked up in the U.S. Department of Agriculture’s FoodData Central (api.data.gov). FoodData Central keeps its own request logs, which are outside our control. When neither source has the food, the screen offers to let AI estimate calories from your text; only if you tap that is the text sent to the AI service for an estimate.

3. Feastie Pro subscription verification. Purchases are handled by Apple; we never receive your payment details. After you subscribe, the app sends the transaction signature issued by the App Store to our server for verification. The server keeps only the transaction identifier, whether the subscription is active, and how many AI recognitions have been used; nothing in the signature identifies you. The app attaches a random identifier to the purchase, which only Apple retains and which we never match against a Feastie account.

If you turn on the daily reminder, the app gives our server the device’s push token and the time and language you chose, used only to send one fixed-text reminder at that time; turning the reminder off deletes them. To provide the service and prevent abuse, our server transiently processes standard connection data (such as IP addresses) for rate limiting, and for nothing else.

Usage stats and crash reports. To know whether the app is working properly and how accurate the recognition is, we use Google Firebase (Analytics, Crashlytics and Performance) to collect anonymous usage statistics, crash reports and performance data.

What we collect: device model, OS version, an approximate region derived from your IP address, an anonymous installation identifier, crash logs, app start and network request timings, and events describing what the interface did, for example: a recognition completed (from the camera or the library; success or failure), a meal was saved (from the camera or Search), the paywall was shown, a text estimate was requested, the kind of change made to each dish when a recognition result is saved, the ratio between the calories you saved and the calories the AI estimated, whether a sign-in completed (with Apple or with Google) and whether a sync succeeded.

What we don’t collect: what you ate, any food name, search text, photo, nutrition value, body data or goal. Usage statistics carry no Feastie account, email or name and no identifier that maps to an account; the advertising identifier (IDFA) is not used, and nothing is used to track you across other apps or websites.

This data is used only to improve the app. See the Google Privacy Policy for how Google handles it.

The website, feastie.ai. Our website uses Google Analytics to learn how many people visit, which sections they read and whether they follow the download link. It receives the pages viewed, events such as scrolling and clicks on outside links, the browser and device type, and an approximate region derived from your IP address, and it stores Google Analytics cookies (named starting with _ga) in your browser. For visitors in the European Economic Area, the UK and Switzerland no cookie is stored by default and only cookieless pings are sent. The website shows no ads, and none of this is used for advertising. Cloudflare, which hosts the site, also counts visits and load times without cookies. You can block cookies in your browser or install the Google Analytics opt-out browser add-on (tools.google.com/dlpage/gaoptout).

Third-party services: Cloudflare (hosts our server, and the cloud backup’s database, D1, and photo storage, R2), OpenAI and Google Gemini (photo recognition, name translation and text estimates), USDA FoodData Central via api.data.gov (online food search), Apple (App Store purchases and subscriptions, Sign in with Apple, push notifications), and Google (Google sign-in, and Firebase for usage statistics, crash reports and performance data).

What we don’t do: no mandatory account (everything works without signing in), no ads, no tracking across other apps or websites, no selling of data, and no sharing of it apart from the numbers on a shared nutrition label, which never say who read them, no storing of your meals, photos or body data on any server while you are not signed in — and once you are, the backup is visible to your account alone, never looked at, analysed or used to train any model.

Children. Feastie is not designed for children under 13, and we do not knowingly collect data from them.

Deleting your data and your rights. Without an account, delete the app and your records, photos, body data and settings go with it. If you signed in, deleting the account inside the app clears everything of yours from our server. Beyond that our server holds nothing that maps back to you: photos and text sent for recognition are discarded once processed, subscription records refer only to an App Store transaction identifier and expire on their own, and usage statistics are anonymous. Under Taiwan’s Personal Data Protection Act you have the right to access, correct and delete your personal data; if you believe we hold any, write to us and we will act on it.

Changes. If this policy changes, we will update this page and its effective date. Significant changes will be announced in the app.

Contact: [email protected]

Categories:

Discover more from LikeABossApp

Subscribe now to keep reading and get access to the full archive.

Continue reading