Privacy Policy

Last Updated: September 28, 2026

Version 3.0

This Privacy Policy explains how Bazu Technologies, LLC (“Bazu,” “we,” “us”) collects, uses, shares, and protects your personal information when you use the Bazu mobile application, website, and related services (collectively, the “Service”).

This is version 3.0 of the Privacy Policy. It applies to app version 2.3.0 and later and replaces every earlier version. Where an earlier app version did something that app version 2.3.0 and later does not, this policy says so by version number.

Bazu is a wellness and food-rating app for adults (18+), operated from the United States. It rates the food you log, suggests a fix to the meal, and asks how each meal left you. The Service is not designed to diagnose, treat, or manage any medical condition. Please also read our Terms of Service and Medical Disclaimer.

If you are a Washington or Nevada resident, additional disclosures and rights apply to your consumer health data. Please read our separate Consumer Health Data Privacy Policy.

1. Information We Collect

1.1 Information You Provide Directly

Account Information

  • Name (first and last)
  • Email address
  • Username
  • Date of birth
  • Password (stored as a one-way hash; we never see your plaintext password)
  • OAuth provider information if you sign in with Google or Apple (see below)
  • Your timezone, so meals land on the right day
  • How you heard about Bazu, if you tell us during onboarding

OAuth Sign-In Details

If you sign in with Google or Apple, we receive your email address and an authentication token. We do NOT access your Gmail, Google Drive, iCloud, or other Google/Apple services. If you sign in with OAuth, you cannot change your email inside Bazu. Update it with Google or Apple directly.

Wellness Profile

  • Gender
  • Height and weight (with the units you prefer), and a dated history of the weights you log
  • Weight goal (lose / maintain / gain) and how fast you want to get there
  • Wellness goal (steady energy / fewer cravings / etc.)
  • Nutrition goals (cut added sugar / more protein / etc.)
  • Self-reported diabetes status. App versions before 2.3.0 asked one question during onboarding: none, pre-diabetes, Type 2 diabetes, Type 1 diabetes, other, or not sure. App version 2.3.0 and later does not ask. In September 2026 we changed every stored pre-diabetes and Type 2 answer to none. App versions before 2.3.0 can still send those answers, so an account may hold one again. We keep a dated record of what was first reported, and we never rewrite it. We still read the stored answer on every request. We hold the predicted glucose curve back from accounts that reported Type 1. That curve is drawn only by app versions before 2.3.0. Never shared with advertisers, insurers, or any third party.

Meal and Food Data

  • Meal descriptions you type
  • Meal photos you take
  • Barcodes you scan and foods you search for
  • Your energy check-in answer: how a meal left you, in your own words or on a scale. This is your own report. It is stored with that meal and it never enters any score
  • Food ratings and notes
  • Timestamps and meal-type buckets (breakfast / lunch / dinner / snack)

What you log about food, your energy check-in answers, and any diabetes answer an earlier app version stored can allow someone to infer something about your health. We treat all of it as sensitive: it is never used for advertising, never sold, and never shared except as this policy describes.

Optional Health Data (earlier app versions only)

  • Blood glucose readings and insulin doses you entered by hand in app versions before 2.3.0. App version 2.3.0 and later has no screen for either one. Values you entered earlier are still held on your account
  • Continuous glucose monitor (CGM) glucose readings, collected by app versions before 2.3.0, if you enabled CGM integration via Apple Health. That integration has been retired and app version 2.3.0 and later does not offer it (see Section 1.4)

Most users never provided any of the above. It was always optional and never required to use the Service.

Your Acceptance Record

Each time you accept a version of our Terms of Service, this Privacy Policy or our Consumer Health Data Privacy Policy, we record which version you accepted and when. This record is deleted with your account (see Section 6).

Website Forms

The contact form on withbazu.com takes your first name, last name, email address, phone number and message. The newsletter form in the website footer takes your email address. Both are delivered by Formspree (see Section 4.1). Neither form is part of your Bazu account.

1.2 Information We Generate About You

Based on the data you provide, the Service generates algorithmic outputs. These are derived from your inputs and stored alongside your account:

  • The three reads on each food you log: its Nutrition Score, its Energy read (an estimate of how long that food's fuel tends to last), and its Ingredients check
  • AI nutrition estimates (macronutrients, calories, sugar, fiber and similar values) for each meal
  • Your Bazu Score: one number that summarizes the food you logged over the last 30 days
  • Per-meal predicted glucose curves and the 24-hour Estimated Glucose Curve, in app versions before 2.3.0. App version 2.3.0 and later does not generate or show either one
  • XP, streaks, achievements, ranks, and other gamification state
  • Aggregated tracking statistics (e.g., your weekly nutrition averages)

Every one of these is worked out from the food you logged. They describe the food, not your body, and none of them is a diagnosis. The same food gets the same reads for every account. Your energy check-in answers are stored beside these outputs but are never used to compute any of them.

App versions before 2.3.0 also generated outputs from CGM readings imported through Apple Health: per-meal curves matched to your own readings, and time-in-range statistics. Those app versions could read blood glucose from Apple Health. The integration has been retired, and no app version generates these outputs any more.

These outputs are estimates only. See our Medical Disclaimer and Section 3 (Estimates, Not Measurements) of our Terms of Service.

1.3 Information Collected Automatically

Usage Data

  • Activity logs (meal entries, scans, ratings)
  • App interactions and feature usage
  • Session duration and frequency

Device Information

  • Device type and model
  • Operating system version
  • Unique device identifiers (for push notifications and crash diagnostics), and a random install identifier created on your device, used only to count which onboarding screens are reached before signup. It is never linked to your account and never shared.
  • App version, and the version of the app's update bundle
  • Advertising identifier (IDFA), on iOS, only if you grant permission through the App Tracking Transparency prompt (see Section 4.2 and Section 11)

Update Delivery

The app checks for updates to its code through Expo (see Section 4.1). That check sends your device type, operating system version, app version and current update version. It sends no account data and no health data.

Local Device Storage

The following are stored encrypted on your device:

  • Authentication tokens (for automatic sign-in)
  • Cached profile data (for faster app performance)
  • App settings and preferences

Local data is encrypted by your device's operating system and is deleted when you log out or uninstall the app.

We Do NOT Collect

  • Precise geolocation
  • Contact lists
  • Photos or media (except meal photos you choose to upload)
  • Biometric data
  • Voice or microphone data

About Meal Photos

  • Photos are stored in private cloud storage (Supabase). They are never public. The app opens them through short-lived links issued only to your signed-in account
  • Photos are processed by an AI provider (OpenAI) to identify food items and estimate nutrition (see Section 2.2 and Section 4.1)
  • Photos are shown back to you inside the app, with your meal, and to no one else
  • Photos are deleted when your account is deleted (see Section 6)
  • Photos are NOT used for advertising, NOT shared publicly, and NOT used to train any AI model, ours or a vendor's

1.4 Apple Health / CGM Integration (Retired)

This integration has been retired. App version 2.3.0 and later does not offer CGM integration, does not request Apple Health permission, and does not read any data from Apple Health.

App versions before 2.3.0 could read blood glucose from Apple Health, if you chose to enable the integration and granted permission. It was always optional, and most accounts never used it. This section describes what those app versions did, and what happens now to readings they imported.

What Those App Versions Accessed

  • Blood glucose samples stored in Apple Health (timestamp, value, unit, source device/app), and nothing else

What We Have Never Accessed

  • We have never written data to Apple Health
  • We have never accessed any other Apple Health data type (heart rate, steps, sleep, etc.)
  • We have never connected directly to CGM hardware. All data flowed through Apple Health

What Happens Now

  • App version 2.3.0 and later does not offer the integration and does not ask for Apple Health permission
  • App version 2.3.0 and later imports nothing from Apple Health. An app version before 2.3.0 still installed on a device may keep syncing until that device updates; updating is required to keep using the Service
  • If you granted Apple Health permission to an app version before 2.3.0, you can review or revoke it in iOS Settings → Health → Data Access & Devices → Bazu
  • Readings imported before the integration was retired were deleted from every account fourteen days after app version 2.3.0 was released, together with everything computed from them (see Section 6). Each affected account was emailed on release day with the date and the offer of a copy

How CGM Data Was Used

To display glucose trends inside the app and to overlay your own readings on the Estimated Glucose Curve for comparison. We did not use CGM data for advertising. We did not sell CGM data. We have never sent CGM data to any AI model or AI vendor. We have never used it to train a model, and we never will.

One Offline Copy

In September 2026 we exported the stored readings of two accounts. That was part of retiring this integration. The copy is encrypted and held offline. No third party has it, and it was never sent to any AI model or AI vendor. A scheduled job destroys it on December 14, 2026.

2. How We Use Your Information

2.1 Provide and Operate the Service

  • Create and manage your account
  • Display the meals, reads, scores and history you log
  • Generate the AI nutrition estimates and the three reads described in Section 1.2
  • Suggest a fix to a meal you logged, based on the food in it
  • Ask how a meal left you, and show your answers back to you beside that meal and in your history
  • Personalize the Service to your goals and demographics
  • Award XP, streaks, and achievements
  • Process subscription state through the Apple App Store and RevenueCat
  • Hold the predicted glucose curve back from accounts that reported Type 1 diabetes. Our servers check the stored answer on every request. App versions before 2.3.0 are the only ones that draw a curve

In app versions before 2.3.0 we also used blood glucose readings imported from Apple Health to show glucose trends in the app and to overlay your own readings on the Estimated Glucose Curve. That integration has been retired, and we no longer use CGM data for this or any other purpose (see Section 1.4).

2.2 AI Features

We use third-party AI providers for two jobs. Today those providers are OpenAI and Anthropic.

Reading your meals. OpenAI receives the meal text you typed, the meal photo you took, and the food names you search. That is what identifies the food and estimates its nutrition. Nothing else is sent with it.

Writing your score summaries. Anthropic receives a summary of your recent logging, so it can write the sentences on your Bazu Score screens. That summary carries your meal names, your score numbers and your nutrient averages. Nothing about glucose goes once the readings older app versions imported are deleted, fourteen days after app version 2.3.0 was released.

Neither provider receives your name, email address, account identifier, date of birth, weight, diabetes answer, energy check-in answers or an insulin dose. A request carries the food and the numbers, and nothing that says who you are.

We do not use your data to train AI models, ours or anyone else's. OpenAI and Anthropic confirm in their API terms that data submitted via API is not used to train their models by default. We rely on those commitments and never opt in to training-data programs. Each provider may hold API inputs for up to 30 days for abuse monitoring under its own API policy, then deletes them. Where a provider offers a zero-retention option for API traffic, we use it.

We may use aggregated, de-identified data, meaning data that cannot reasonably be linked back to you, to evaluate and improve our own scoring methods and product features.

2.3 Communication

  • Meal logging reminders, energy check-in reminders and gentle streak nudges (you can disable these in app settings)
  • Achievement and gamification notifications
  • Important service updates, security alerts, and policy changes
  • Responses to your support requests

2.4 Service Improvement, Security, and Fraud Prevention

  • Diagnose crashes and errors, using Sentry
  • Count which features are opened, in our own database, to improve features and fix bugs
  • Detect and prevent fraud, abuse, and unauthorized access
  • Maintain the security of the Service and its infrastructure

2.5 Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to lawful legal requests
  • Enforce our Terms of Service and other policies

3. We Do Not Sell Your Health Data

We do not sell, rent, or trade your health-related data, including meals, meal photos, nutrition data, energy check-in answers, weight, any diabetes answer, or any glucose or insulin value an earlier app version stored, to advertisers, data brokers, insurers, or anyone else, ever.

We never use data about your health for marketing. Nothing you log about food, nothing you answer about how a meal left you, and no diabetes answer ever reaches an advertising platform, an ad audience, or a marketing segment.

We have not sold or shared any personal information for cross-context behavioral advertising in the preceding twelve (12) months, with one limited exception: if you grant permission through the iOS App Tracking Transparency prompt, your device's advertising identifier (IDFA) and standard non-health app events may be shared with Meta Platforms, Inc. and TikTok (Bytedance Ltd.) for app-install advertising attribution. Under the California Consumer Privacy Act (CCPA/CPRA), this activity may be considered a “sale” or “share” of personal information. It involves only the advertising identifier and non-health events; it never involves your health data. You can opt out at any time (see Section 4.2 and Section 8).

4. How We Share Your Information

4.1 Service Providers

We share data with trusted third-party service providers who help us operate the Service. Each is contractually obligated to protect your data and use it only for the purposes we specify. This list is complete: no provider outside it receives your data.

Supabase: cloud database, storage, and authentication

  • Stores account data, profile data, meal data, photos, and any optional health data an earlier app version collected
  • Located in the United States
  • Row-Level Security ensures users can only access their own data
  • Privacy Policy: https://supabase.com/privacy

Railway: backend application hosting

  • Runs the Bazu API servers in the United States
  • Processes your requests but does not retain your data outside the request lifecycle
  • Privacy Policy: https://railway.com/legal/privacy

Expo: app update delivery

  • Delivers updates to the app's code between App Store releases
  • Receives your device type, operating system version, app version and current update version when the app checks for an update
  • Does NOT receive your account data, your meals, or any health data
  • Privacy Policy: https://expo.dev/privacy

OpenAI and Anthropic: AI nutrition, meal parsing, and score summaries

  • OpenAI receives meal descriptions (text), meal photos (images) and the food names you search, to identify foods and estimate nutrition
  • Anthropic receives the logging summary described in Section 2.2, to write the sentences on your score screens
  • Neither receives your name, email address, account identifier, date of birth, weight, diabetes answer, energy check-in answers, an individual glucose reading, or an insulin dose
  • Do NOT use data submitted via API to train their models, per their API terms
  • Your data is processed and not retained for our use beyond the request
  • Privacy Policies: https://openai.com/api-data-privacy and https://www.anthropic.com/legal/privacy

Edamam and Open Food Facts: food databases

  • Receive food names and barcode scans from your meal searches
  • Do NOT receive your health data or personal information
  • Privacy Policies: https://www.edamam.com/privacy-policy and https://world.openfoodfacts.org/privacy

Apple App Store and RevenueCat: subscription payment and processing

  • Apple takes your payment. Bazu never sees your card number or billing address
  • RevenueCat manages subscription state for purchases made through the Apple App Store
  • RevenueCat receives your Bazu user ID, the App Store receipt, your subscription status, and purchase events
  • Neither receives your health data or meals through this flow
  • Privacy Policies: https://www.apple.com/legal/privacy/ and https://www.revenuecat.com/privacy

OneSignal: push notification delivery

  • Receives device identifier and notification preferences to deliver push notifications
  • Does NOT receive your health data or meals
  • Privacy Policy: https://onesignal.com/privacy_policy

Vercel: website hosting and website analytics

  • Hosts withbazu.com and counts page views and visits on the website only, not in the app
  • Uses no cookies and does not track you across other sites; visitors are counted with a rotating, non-reversible identifier
  • Does NOT receive your account details, meals, or any health data
  • Privacy Policy: https://vercel.com/legal/privacy-policy

Sentry: crash and error monitoring

  • Receives stack traces, device context, and minimal user identifiers when the app crashes or hits an error
  • Does NOT receive the contents of your meals or your health data
  • Privacy Policy: https://sentry.io/privacy

Resend: transactional email

  • Sends account verification, password reset, and subscription emails
  • Receives your email address to deliver messages
  • Does NOT receive your health data
  • Privacy Policy: https://resend.com/legal/privacy-policy

Formspree: website form delivery

  • Delivers the contact form and the newsletter form on withbazu.com to our inbox
  • From the contact form, receives the first name, last name, email address, phone number and message you type
  • From the newsletter form, receives only the email address you type
  • Does NOT receive your account data, your meals, or any health data
  • Privacy Policy: https://formspree.io/legal/privacy-policy

Google: OAuth (if you sign in with Google)

  • Authenticates your identity; we receive your email and an auth token
  • Privacy Policy: https://policies.google.com/privacy

Apple: OAuth and Apple Health

  • Authenticates your identity (Sign in with Apple); we receive your email and an auth token
  • Provided the Apple Health data flow described in Section 1.4, in the app versions that offered it. Apple never received any data from Bazu through it
  • Privacy Policy: https://www.apple.com/legal/privacy/

4.2 Advertising Attribution (Meta and TikTok SDKs)

Bazu uses two third-party advertising services, integrated solely for app-install advertising attribution: the Meta (Facebook) SDK and the TikTok Business SDK. Neither is initialized for users in the European Economic Area, the United Kingdom, or Switzerland.

What Meta and TikTok Receive

  • Your device's advertising identifier (IDFA), on iOS
  • Three standard app events logged by each SDK: app install, app launch, and account registration. Nothing else

What Meta and TikTok Do NOT Receive

  • Your health data: meals, photos, nutrition info, energy check-in answers, weight, any diabetes answer, or any glucose or insulin value
  • Your purchases or subscription: no purchase, trial or subscription event is sent to either one
  • Your profile information (name, email, date of birth, etc.)
  • Any health-related events. We send only each provider's standard, non-health events, as listed above

Your Control

  • On iOS, this is gated by the App Tracking Transparency (ATT) prompt. If you choose “Ask App Not to Track,” no advertising identifier is collected or shared with Meta or TikTok.
  • You can change your choice anytime in iOS Settings → Privacy & Security → Tracking.
  • Declining tracking does not affect any feature of Bazu.

Provider Privacy Policies

  • Meta: https://www.facebook.com/privacy/policy
  • TikTok: https://www.tiktok.com/legal/page/us/privacy-policy/en

Meta and TikTok receive no health data from Bazu. Only the advertising identifier and standard non-health events, and only with your permission.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or lawful government request, or if we reasonably believe disclosure is necessary to:

  • Comply with legal obligations
  • Protect our rights or property
  • Prevent fraud or security issues
  • Protect the safety of our users or the public

4.4 Business Transfers

If Bazu is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

5. Data Security

We use industry-standard security measures to protect your information:

  • Encryption in transit (TLS) and at rest
  • Secure authentication, including OAuth options
  • Row-Level Security in the database so users can only access their own data
  • Principle-of-least-privilege access controls for our team
  • Ongoing monitoring for vulnerabilities and threats

No method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We keep your information only as long as needed to provide the Service and meet legal obligations:

  • Account data (name, email, profile, weight history): Retained while your account is active.
  • Meal data, photos, reads, scores, energy check-in answers: Retained while your account is active.
  • Optional health data entered by hand in app versions before 2.3.0 (glucose, insulin): Retained while your account is active.
  • CGM readings imported from Apple Health: Deleted from every account fourteen days after app version 2.3.0 was released, after an email to each affected account, together with everything computed from them. App version 2.3.0 and later imports no readings.
  • The dated record of your diabetes answer: Retained while your account is active. It holds what was first reported, including answers the app no longer offers, and it is never rewritten.
  • Your acceptance record (which policy versions you accepted and when): Retained for five years after your account is deleted, as the record that you agreed to our terms. It holds no name, no email and nothing about your health.
  • Crash and error logs: Held by Sentry for up to 90 days, then automatically purged.
  • In-app usage events (which features you opened): Retained while your account is active.
  • Onboarding progress before signup (a random install identifier and the screen names reached): Deleted after 90 days. Not collected in the EEA, the UK or Switzerland.
  • Account-deletion record: When you ask us to delete your account, and again when the erasure completes, we keep one row each: the account's internal identifier and the date. It holds no name, no email, no meals and no health data. Kept for five years, as the record of your request (California requires at least 24 months).
  • Payment and subscription records: Held by Apple and RevenueCat under their own retention for tax and refund purposes. Bazu never holds your card details.
  • Aggregated, de-identified statistics: Retained indefinitely.

When You Delete Your Account

Deleting your account starts a 30-day grace period. During those 30 days your data is kept but inactive, and logging back in restores the account. When the 30 days end, a scheduled job permanently erases your personal data in one pass: your account and profile, every meal, every photo file, every read and score, every energy check-in answer, your weight history, your XP and streaks, the dated diabetes record, and any glucose or insulin value or CGM reading an earlier app version stored. Your login is deleted with it. Backups are purged within 90 days.

Like every service, we keep a small set of records after that, to comply with legal obligations, resolve disputes and enforce our agreements: the record that you accepted our terms and policies, the record of your deletion request, and the payment records Apple and RevenueCat hold. None of them contains your name, your email, your meals or anything about your health. Statistics that identify nobody are kept as well.

7. Your Rights and Choices

7.1 Access and Correct

You can view and edit most of your profile information directly in the app (Settings and Update Your Profile). For other access or correction requests, email hello@withbazu.com.

7.2 Delete Your Account

You can delete your account using the “Delete Account” option in Settings, or by emailing hello@withbazu.com. Deletion starts a 30-day grace period in which logging back in restores your account. After that, everything is permanently erased as described in Section 6.

7.3 Export Your Data

To request a copy of your data in a structured, machine-readable format, email hello@withbazu.com with your account email. We will respond within 30 days. The copy includes your meals and the reads and scores stored with them. An in-app export feature is in development.

7.4 Opt Out of Communications

  • App notification settings (per-category controls)
  • Device notification settings (iOS Settings)
  • Email unsubscribe links (transactional emails like security alerts cannot be opted out)

7.5 Opt Out of Ad Attribution

The iOS App Tracking Transparency prompt is your opt-out for advertising-identifier sharing with Meta and TikTok. Choose “Ask App Not to Track,” or change your choice anytime in iOS Settings → Privacy & Security → Tracking. Section 8 lists your California rights and how to exercise them.

8. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

Your Rights

  • Right to know: Request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: Request deletion of your personal information.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt out: Opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising (see Section 7.5 for our only such activity).
  • Right to limit use of sensitive personal information: We do not use your sensitive personal information beyond what is necessary to provide and improve the Service.
  • Right to non-discrimination: We will not discriminate against you for exercising your rights.

“Sale” and “Sharing” Disclosure

We do not exchange your personal information for money. The only activity that may be considered a “sale” or “share” under CCPA/CPRA is the sharing of your IDFA and standard non-health app events with Meta and TikTok for app-install advertising attribution, and only when you grant permission via the iOS ATT prompt. See Section 4.2.

How to Exercise Your Rights

This section is our Your Privacy Choices notice. Everything you need is here.

To opt out of the only sharing we do. On your iPhone, open Settings, then Privacy & Security, then Tracking. Turn Bazu off. No advertising identifier is collected or shared after that. You can also choose “Ask App Not to Track” on the prompt itself. Declining does not affect any feature of Bazu.

To know, correct, delete, or appeal. Email hello@withbazu.com. Include your full name, the email address on your account, and what you want. We will respond within 45 days. We may extend that once when reasonably necessary, and we will tell you why.

To delete everything yourself. Open the Bazu app, then Settings, then Delete Account.

You may use an authorized agent. Send us written proof that you authorized them.

9. Washington and Nevada: Consumer Health Data

If you are a Washington or Nevada resident, the health-related information you provide to Bazu is treated as “consumer health data” under Washington's My Health My Data Act (MHMDA) and Nevada's SB 370.

Please read our separate Consumer Health Data Privacy Policy for the full disclosures and rights that apply to that data, including your rights to access, delete, withdraw consent, and appeal.

We provide the Consumer Health Data Privacy Policy as a separate, distinctly linked document as required by Washington law.

10. Health Information and HIPAA

Bazu is not a HIPAA-covered entity and is not a business associate of one. The health-related information you enter into Bazu is:

  • Entered voluntarily by you
  • Not received from a healthcare provider
  • Not used for medical diagnosis or treatment
  • Not shared with healthcare providers unless you explicitly do so yourself

Your information is instead protected by general consumer-privacy laws (such as CCPA/CPRA and, where applicable, Washington MHMDA and Nevada SB 370, see Section 9) and by this Privacy Policy. We strongly recommend that you do not rely solely on Bazu for any health-related decision and that you consult a qualified healthcare provider when needed.

11. App Tracking Transparency (iOS)

On iOS, Bazu uses Apple's App Tracking Transparency (ATT) framework. The first time it is relevant, iOS will show you a prompt asking whether you allow Bazu to track you across apps and websites owned by other companies.

What the Prompt Controls

  • If you allow tracking, Bazu may collect your IDFA and share it with Meta and TikTok for app-install attribution as described in Section 4.2.
  • If you choose “Ask App Not to Track,” no advertising identifier is collected and nothing is shared with Meta or TikTok for tracking purposes.

Important

  • Granting permission is entirely optional.
  • Declining tracking does not affect any feature of Bazu.
  • You can change your choice anytime in iOS Settings → Privacy & Security → Tracking.
  • The ATT choice never affects your health data, which is never used for tracking or advertising regardless of your choice.

12. Children's Privacy

Bazu is for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and if we learn that we have, we will close that account and delete the information promptly.

If you believe a person under 18 has provided us personal information, contact us at hello@withbazu.com.

13. Users Outside the United States

Bazu is operated from the United States and is available worldwide. If you use the Service from outside the U.S., your data is transferred to and processed in the United States, as described in Section 14. We protect it the same way wherever you are.

Why we process your data. If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on your consent to process your health data (the food, weight, and check-in data you log), which you give at signup and can withdraw at any time. We process your account data because it is needed to provide the Service you signed up for, and we send service emails and keep security logs because we have a legitimate interest in running the Service safely. We do not run advertising SDKs on your device in these regions (Section 4.2).

Your rights. You may ask us for access to your personal data, correction, erasure, a copy in a portable format, or restriction of processing, and you may object to processing based on our legitimate interest. You may withdraw your consent to health data processing at any time by deleting your account in the app under Settings or by emailing us. Withdrawing consent does not affect processing that happened before you withdrew it. To exercise any of these rights, email hello@withbazu.com with your full name and the email address on your account. We will respond within 30 days. We do not charge for these requests and we will not treat you differently for making one.

Complaints. If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the data protection authority in the country where you live or work. We would appreciate the chance to address your concern first at hello@withbazu.com.

Transfers. Because our servers and service providers are in the United States, using the Service means your data leaves your country. Where the law requires a transfer mechanism, we rely on your explicit consent given at signup and, with our service providers, on standard contractual clauses.

14. Data Processing Location

All personal data collected by Bazu is processed and stored in the United States. We do not intentionally transfer your data outside the United States. By using the Service, you consent to this processing location.

15. Breach Notification

If we experience a security breach involving your personal information, we will notify you and the relevant authorities as required by applicable law, including the FTC Health Breach Notification Rule (16 CFR Part 318) for breaches involving identifiable health information, and applicable state breach-notification statutes. Notice will be given without unreasonable delay and, in any event, within the timeframes those laws require.

16. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for their privacy practices. Review their privacy policies before providing any information.

17. Automated Processing

The reads, scores and suggestions in the Service are produced automatically from the food you log, as described in Section 1.2. They are ratings of food. They are not decisions about you, they are not used to decide what you may access or pay, and none of them produces a legal or similarly significant effect on you. We do not profile you for advertising, and we make no automated decision about you based on your health data.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the version number and the “Last Updated” date at the top.
  • For material changes, we will notify you in the app or by email before they take effect, and we may ask you to accept the updated policy in the app before you continue using the Service.
  • We record which version you accepted and when (see Section 1.1).
  • For changes that do not require a new acceptance, continued use of the Service after the changes take effect means you accept the updated Privacy Policy.

19. Contact Us

For questions, concerns, or requests about this Privacy Policy or our data practices:

Bazu Technologies, LLC

Email: hello@withbazu.com

Website: https://withbazu.com

For data subject requests (access, deletion, etc.), please include your full name, the email address on your account, and the specific request. We will respond within 30 to 45 days, depending on the applicable law.

20. Your Consent

By creating an account or using Bazu, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.

© 2026 Bazu Technologies, LLC. All rights reserved.