Zebite · Privacy
Zebite Privacy Policy
How Zebite handles your account, your pantry, your meal plans, and the photos you scan.
- Effective
- 24 July 2026
- Last updated
- 24 July 2026
The short version
- Your data lives on your phone first. The cloud copy exists so you can restore it on a new device.
- We do not sell your data, show you ads, or embed any analytics or tracking SDK. There are none in the app.
- Meal planning and photo scanning send your pantry, your profile and your photo to OpenAI to be processed. Nothing is used to train anyone's model.
- Receipt and shelf photos are analysed and discarded. We never store the image.
- Sharing grocery prices with other users is opt-in, off by default, and anonymous.
- You can ask us to delete your account and everything in it, at any time, by email.
A summary for skimming. The full text below is what actually applies.
Who we are
Zebite is made by Zhevion, an independent studio operated by Zendrex Adversalo. Zhevion is not a company — it is two people building apps they use themselves. Zendrex Adversalo is the person responsible for the data described here, and hello@zhevion.com reaches them directly.
This policy covers the Zebite mobile app (app id com.zhevion.grocery) on iOS and Android. The Zhevion website and RepForge are covered by their own separate documents.
An account is required
Zebite needs an account to work. The features that make it useful — generating a meal plan, scanning a receipt — run on a server that has to know who is asking, both to return your data and to stop one person burning through everyone's AI budget. There is no anonymous or guest mode.
You can sign up with an email address and password, or with Google or Facebook. If you use email, we send you a six-digit confirmation code to check the address is yours. If you use Google or Facebook, we receive only the basic profile they hand over — your email address, your name, and your profile picture — and never your password or your contacts, posts or friends.
What we collect, and why
Everything below is something you type, choose, or photograph inside the app. We collect nothing in the background.
| What | Specifically | Why we need it |
|---|---|---|
| Account | Email address; a password (stored only as a hash by our authentication provider, never in plain text); or your Google/Facebook email, name and avatar if you sign in that way | To create your account, sign you in, and let you restore your data on a new phone |
| Nutrition profile | Name, height, weight, age, sex, activity level, goal (lose / maintain / gain), weekly budget, plan length, meals per day | To calculate your calorie and macro targets, and to size a meal plan to your budget |
| Food preferences | Diet type, allergies, ingredients you avoid, ingredients you like | So generated plans exclude what you can't or won't eat |
| Pantry | Items, quantities, units, categories and expiry dates you add or scan | So the app plans around what you already own instead of buying it again |
| Plans and lists | Generated meal plans and recipes, grocery lists, meals you log as cooked | They are the app — this is the content you came for |
| Spending history | Store name, date, items and amounts from receipts you scan or enter | To show weekly spending against your budget on the Insights screen |
| AI usage counters | A timestamp and a type ('plan' or 'scan') for each AI request. No prompt, no reply, no image is kept | To enforce the daily limits and show you how many requests you have left |
| Subscription tier | 'free', 'plus' or 'pro', and how it was granted | To know what your account is entitled to. No paid tier is currently sold — see the Terms |
Some of this is health-related information: your weight, your age, your sex, your goal, and especially your allergies. We treat it as sensitive. It is used only to generate your plans and targets, it is never shared with anyone for advertising or profiling, and it is never sold.
What we do not collect
To be specific, because privacy policies are usually vague about this:
- No analytics SDK. There is no Firebase, no Google Analytics, no Amplitude, no PostHog, no Mixpanel in the app.
- No advertising. No ad SDK, no advertising identifier (IDFA / AAID), no ad network, no attribution or install tracking.
- No location. The app never requests or reads your location, coarse or fine.
- No contacts, calendar, microphone, or health-app data. The app requests only camera and photo-library access, and only when you tap to scan.
- No crash-reporting SDK, so we do not receive automatic crash reports containing your data.
- No data brokers, no profile enrichment, no purchase of information about you from anyone.
Photos you scan
When you photograph a receipt or your shelf, the app resizes the image on your device (to at most 1600 pixels wide), sends it to our server, which forwards it to OpenAI to be read, and receives back a list of items. That list is what gets saved to your pantry.
The image itself is never written to our database and never uploaded to any file storage. It exists only for the seconds the request takes. If a scan fails, nothing is kept at all. The photo also remains in your own camera roll if your phone saved it there — that copy is yours and we have no access to it.
A receipt can contain more than groceries. We only extract food and drink lines, but the whole image is transmitted for analysis, so if your receipt shows something you would rather not send, crop it or type the items in by hand instead.
Where your data lives
Your phone is the source of truth. Zebite writes everything to a local database on your device first, which is why the app keeps working with no signal. That local copy sits in the app's private storage, readable only by Zebite.
While you are signed in, the app also mirrors that data to our backend so a new or reset phone can restore it. The backend runs on Supabase, and every table enforces row-level security: your rows are readable and writable only by your own signed-in account. Not by other users, and not by an app rebuilt to try.
Supabase Inc. is based in the United States and runs on cloud data centres, so your data is processed outside the Philippines. Transmission is encrypted in transit (HTTPS/TLS) and the database is encrypted at rest by the provider.
How AI processing works
Two features use AI: generating a meal plan, and reading a photo of a receipt or your groceries. Both run through our own server, which holds the AI provider's key. The app never talks to the AI provider directly and never holds a key that could be extracted from the installed app.
For a meal plan, what is sent is the information the plan has to be built from: your pantry contents, your calorie and macro targets, your diet type, your allergies and avoided ingredients, your weekly budget and the number of days and meals you asked for. For a scan, what is sent is the photo and an instruction describing what to extract.
Your name, your email address and your account identifier are not part of these requests. The AI provider is OpenAI, and under their API terms the content sent through it is not used to train their models; they retain requests for a limited period for abuse monitoring and then delete them.
AI requests are rate limited per account — currently five meal plans and twenty scans per rolling 24 hours, with a short cooldown between requests. To enforce that we record the time and type of each request, and nothing else about it.
AI output is an estimate and can be wrong. Check anything that matters, especially allergens. See the Terms of Service for the full disclaimer.
Community grocery prices (opt-in)
Zebite can show what other users recently paid for an ingredient, so budgets are based on real local prices. Contributing to that pool is a setting you turn on yourself — it is off by default, and turning it off stops any further contribution immediately.
If you turn it on, what is shared is a single price observation at a time: the ingredient, the price, the quantity and unit, the store and branch, and the date. Each price is stored as its own separate row, never grouped by receipt or by shopping trip, so nobody can reconstruct a basket or a shopping pattern from the pool.
Your account id is attached to a row only so the database can enforce that you may edit and delete your own contributions. It is never shown to other users, and the app has no screen anywhere that displays who submitted a price. You can delete your own contributions at any time.
Notifications
If you enable expiry reminders, Zebite schedules a notification on your device for the morning before a pantry item expires. These are local notifications: they are created and fired by your phone, from data already on your phone.
There is no push server, no push token, and no notification is ever sent by us. We cannot send you a notification even if we wanted to, and we have no way to know whether you saw one. Turning reminders off, in the app or in your system settings, cancels them.
Keeping and deleting your data
We keep your data for as long as your account exists, because it is your data — your pantry and your history are only useful if they persist. AI usage counters are only meaningful for a day and age out on their own.
To remove the local copy, sign out or uninstall the app, or clear the app's data in your system settings. To delete your account and everything stored for it, email hello@zhevion.com from the address on the account and ask. We will delete it within 30 days and confirm when it is done. Deleting your account removes your profile, your synced app data, your AI usage records and your subscription record.
Prices you contributed to the community pool are detached from your account rather than deleted, since other users' budgets already rely on them and they carry nothing identifying. If you want them removed too, say so in the same email and we will remove them.
We are working on making account deletion available inside the app. Until it ships, email is the way, and it works.
Your rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to be informed about how your data is used, to access it, to correct it, to object to its processing, to have it erased or blocked, to obtain a copy in a portable format, and to be compensated for damage caused by its misuse.
Most of these you can exercise directly in the app: your profile and preferences are editable on the Profile screen, and your pantry, plans and history are yours to edit or clear. For anything else — a full export, an erasure request, or a question about how something is processed — email hello@zhevion.com and we will act on it within 30 days.
If you are not satisfied with how we handled your request, you may lodge a complaint with the National Privacy Commission of the Philippines.
Children
Zebite is not designed for or directed at children under 13, and calculates nutrition targets using formulas intended for adults. Do not create an account if you are under 13. If you are between 13 and 18, use it with a parent or guardian's involvement.
We do not knowingly collect information from a child under 13. If you believe a child has created an account, email hello@zhevion.com and we will delete it.
Security
- All traffic between the app and our backend is encrypted with HTTPS/TLS.
- Every cloud table enforces row-level security, so a request can only ever read or write rows belonging to the signed-in account that made it.
- The AI provider's key lives on the server as a secret. It is not in the app, so it cannot be extracted from an installed or repackaged build.
- Your subscription tier is server-authoritative — the app can ask, but only the server can grant it. A modified app cannot upgrade itself.
- Passwords are stored only as hashes by our authentication provider. We never see your password, and we cannot recover it for you.
No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, email hello@zhevion.com and we will take it seriously and credit you if you want the credit.
Changes to this policy
We update this document when the app changes, and we date every version at the top. If a change materially affects how your information is handled, we will say so in the app or by email before it takes effect — not quietly, and not retroactively.
Continuing to use the app after a change takes effect means you accept the updated document.
Contact us
Zhevion is an independent studio operated by Zendrex Adversalo. For anything in this document — questions, corrections, or a request about your data — email hello@zhevion.com with "Zebite privacy" in the subject line. We are two people, so we answer personally, usually within a few days.