Privacy policy
Built to ask for very little.
Bite China is designed around data minimisation: menu photographs are processed on your device, dietary selections stay local, and there are no advertising or behavioural tracking tools in the app or on this website.
Last updated: August 2026
Who we are
The data controller.
For data-protection purposes, Menu Mate China Ltd is the controller of the personal data described in this policy.
- Company
- MENU MATE CHINA LTD
- Company number
- 17385027 · Registered in England and Wales
- Registered office
- 167–169 Great Portland Street, London, England, W1W 5PF
- Privacy contact
- support@menumatechina.com
Deliberately not collected
What we don't ask you for.
The shortest way to protect information is not to gather it. Bite China does not ask for the following, and does not request the related device permissions.
Gender
We do not ask for your gender and do not infer it.
Age or date of birth
No date of birth or age band is requested at sign-up.
Medical records
No diagnoses, prescriptions, or health-platform data. Please don't send medical records to our support address.
Precise location
The app does not request GPS or precise location permission.
Microphone or contacts
Mandarin audio plays through the speaker. Nothing is recorded, and your contacts are never accessed.
Advertising identifiers
No advertising ID, ad SDK or behavioural tracking is used, and personal data is not sold.
On dietary selections
Allergy and intolerance choices can amount to health information under UK and EU data-protection law, so we treat them carefully. In Bite China they function as display filters, chosen by you, held on your device — they are not collected as a medical record, are not used to profile you, and are not shared with restaurants automatically.
What we process
The data the app actually touches.
This describes how Bite China is currently designed. Where a practice changes, we update this policy before or when the new processing begins.
-
Account and authentication data
If you create an account, we and our authentication provider process your email address, your password in protected form through Firebase Authentication (we do not receive or view your plain-text password), a Firebase user identifier, whether your email has been verified, and sign-in security information such as timestamps, IP address and user-agent.
An email address and password are needed to create an account. Without them we cannot provide account features.
-
Dietary and allergen preferences
Selections such as lactose intolerance, peanut allergy, vegetarian, no beef, no pork or gluten-free are processed on your device at your request, so relevant flags can be shown alongside dish information. They are not used for advertising, profiling, or automated decisions with legal or similarly significant effects.
If a future version offers optional cloud synchronisation of these preferences, it will come with a separate, explicit opt-in explaining the data, purpose, recipients and how to withdraw.
-
Menu photographs and recognised text
When you grant permission and take or choose a menu photograph, the app receives a local reference so it can display and process that image during your session. Text recognition is designed to run on the device, and recognised text is compared locally against reviewed dish records. The photograph itself is not uploaded to our servers.
Your operating system, camera app, device backup or photo library may keep its own copy according to your device settings. Menu photographs can accidentally capture faces, payment details or other people's information — please frame the menu only.
-
Camera and photo-library permissions
Camera access is requested only when you choose to photograph a menu, and photo-library access only when you pick a saved image. Permission is managed by iOS and can be withdrawn at any time in device settings, though the scan feature will not work without it.
-
App interactions and technical data
Ordinary navigation and in-app search are handled locally. When the app signs you in or downloads reviewed dish records, Firebase and network infrastructure process technical request data such as IP address, user-agent, request time and service-security logs.
-
Correspondence with us
If you contact us we process your name, email address, message and any attachments, together with our reply, so we can answer you and keep a record of the matter.
-
Links to other services
Where the app or site links to a third-party website, that third party may receive technical information such as your IP address and browser or device details, governed by its own privacy notice. We do not control those practices.
Lawful bases
Why we're allowed to process it.
Where UK GDPR or EU GDPR applies, we rely on the following grounds.
Creating and managing your account
Performance of a contract, or steps requested before entering one — email, password credential, user ID, verification and sign-in data.
Keeping accounts secure
Our interest in a secure, reliable service — authentication and technical request data used to prevent abuse and troubleshoot faults.
Scanning a menu
Performance of a contract and the action you asked for — the local image and the text recognised from it.
Dietary preferences
Your consent, with explicit consent where the selection amounts to health data. You can withdraw at any time by deselecting the preference.
We also process personal data where necessary to comply with legal obligations, or to establish, exercise or defend legal claims. Withdrawing consent does not affect processing already carried out lawfully.
How we share personal data
We do not sell personal data. We disclose it only as set out here:
- Google Firebase — Firebase Authentication provides account and email-verification functions; Cloud Firestore supplies reviewed dish records. Google acts as our processor for this data under its data-processing terms.
- Professional and technical suppliers — hosting, IT, legal and accounting advisers, where reasonably necessary to operate, secure or defend the service.
- Authorities and legal recipients — where reasonably necessary to comply with law, a binding request or a regulatory duty, to protect rights and safety, or in connection with legal claims.
- Business transactions — if the company is reorganised, financed, sold or transferred, under appropriate confidentiality and data-protection safeguards.
Restaurants do not receive your account or dietary information automatically. Showing a translated phrase to a member of staff is an action you take.
International transfers
Firebase Authentication is operated from data centres in the United States, and Cloud Firestore processes data in its configured region and other locations permitted by Google's terms. This can involve processing outside the United Kingdom or the country where you live.
Where a restricted international transfer takes place, we use a lawful transfer mechanism appropriate to the destination — such as applicable adequacy regulations, the UK International Data Transfer Addendum, or approved standard contractual clauses. You can request information about the safeguards in place by emailing us.
How long we keep it
- Account information — kept while your account is open. After deletion of the Firebase user is initiated, Google states authentication data is removed from live and backup systems within 180 days; authentication IP logs may be held for a few weeks for security.
- Dietary preferences — held on your device, and removed when you deselect them or remove the app.
- Menu photographs and recognised text — not retained by us; the app's local reference is cleared when you remove the photo or the session ends. Copies held by your device or photo library follow your own settings.
- Support correspondence — normally up to 24 months after the matter is closed, unless longer is needed for an unresolved dispute or legal duty.
- Legal and security records — for the period required by limitation periods, regulatory duties or the defence of claims.
Security
We use reasonable technical and organisational measures to protect personal data, including on-device image processing, Firestore security rules, authenticated account access, transport encryption provided by Firebase, and read-only app access to reviewed dish records.
No system is completely secure. Please use a strong, unique password, keep your device and login details safe, and contact us promptly if you suspect unauthorised access to your account.
Your rights
What you can ask us to do.
Depending on where you are and the circumstances, you may have the right to be informed about our processing, to access your personal data, to have inaccurate data corrected, to request deletion, to restrict processing, to object to processing based on legitimate interests, to receive certain data in a portable format, to withdraw consent where consent is our basis, and to complain to a data-protection regulator.
To exercise a right, email support@menumatechina.com. We may need to verify your identity, and we normally respond within one month, subject to lawful extensions. Some rights can be limited in particular circumstances.
If you are in the United Kingdom you may complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to address your concern first, but this does not affect your right to complain. If you are in the EEA, you may complain to the supervisory authority for your country of residence, place of work, or the alleged infringement.
Children
Bite China is not designed for independent use by children, and is not a substitute for adult supervision where food allergies or other dietary risks are involved. Anyone under 18 should use the app with the involvement of a parent or guardian. We do not knowingly use children's personal data for advertising or profiling. If you believe a child has provided account information without appropriate authorisation, please contact us.
Changes to this policy
We may update this policy to reflect product, legal or operational changes, and will post the new version with an updated date. Where a change materially affects how personal data is used, we will provide a prominent notice and seek consent where required. This policy describes Bite China as it is currently being built, and will be reviewed and updated ahead of the app's public release.
Questions about privacy