LEGAL & SECURITY

BiteAI Privacy Policy

Privacy-First Promise

BiteAI is designed around data minimization. We only collect anonymized spending totals to populate your charts and companion responses. We never ask for your passwords, store cookies on our server, or collect physical addresses.

1. Zero Credential Storage

The BiteAI Chrome Extension runs completely local order history scans using your active web cookies. We **never** request, store, or transmit your passwords or credentials. Authentication is handled on your own browser session.

2. Client-Side Location Scrubbing

Your physical home addresses, coordinates, and street names are private. The extension automatically scrubs and zeroes out the delivery location field locally in your browser before any data is sent to our servers.

3. Data We Store

We store only the anonymized order metadata required to populate your dashboard charts and rule engine:

  • Order Metadata: Platform name (Swiggy/Zomato/Blinkit/Zepto), Order ID (hashed), Date, Payment Method, and Total Amount.
  • Cost Breakdown: taxes, discounts, and delivery fees.
  • Order Items: Name of items and quantities ordered (to calculate favorite dishes and cafe splits).

4. Tenant Isolation & Security

All database schemas use Supabase Row-Level Security (RLS) policies. Your data is strictly sandboxed. No user can read, query, or modify another user's synced records.

🗑️ 5. Absolute User Deletion Control (GDPR / DPDP Compliance)

You retain the absolute "Right to be Forgotten" under GDPR (Art. 17) and the DPDP Act (Sec. 12). You can permanently wipe all your profile details, orders, and item history instantly by clicking the "Reset Dashboard" button inside your dashboard.

© 2026 BiteAI. Built in alignment with GDPR and DPDP Act 2023.