Privacy Policy
Version 2.1 — Effective: August 11, 2026 (replaces the version dated June 10, 2026)
1. Who Is Responsible for Your Data
Rout1 Home Brain is operated by MARIA PRECIOUS PAULA SUARNABA LAPIZAR, an individual developer based in
Tokyo, Japan, who is the data controller (and the person responsible for the handling of personal
information / 個人情報取扱責任者) for the Service. Contact:
paula@rout1.com.
This policy explains what we collect, why, on what legal basis, who processes it, and what rights and
controls you have. The English version is the official text; the Japanese version is a courtesy
translation.
2. Age Requirement
Rout1 Home Brain is intended for users aged 18 and older. By creating an account, you
confirm that you are at least 18 years old. We do not knowingly collect personal information directly from
children under 18.
The app includes family management features that allow adult users (parents/guardians) to manage
information about their family members, including children. All such data is entered and controlled
exclusively by the authenticated adult account holder.
3. Children's Data
Rout1 Home Brain does not collect personal information directly from children. The app's
family management features (Kids Zone, school forms, meal planning) are designed for parents and
guardians to manage their household. Specifically:
- Only authenticated adult users (18+) can create and manage family member profiles.
- Children do not have their own accounts and cannot sign in to the app.
- Any child-related information (names, dietary preferences, school documents) is entered solely by the
parent/guardian account holder, under their parental authority.
- Parents may review, modify, or delete all family member data at any time via Settings > Family
Members or Settings > Data & Privacy.
- We do not use children's information for advertising, profiling, or any purpose other than providing
the household management features requested by the parent.
If you believe a child under 18 has created an account, please contact us immediately at
paula@rout1.com and we will promptly delete the account and
associated data.
4. Data We Collect
- Contact Information: Your name, email address, and authentication metadata from
Firebase, Google, or Apple sign-in. We do not receive your Google or Apple password.
- User Content: Tasks, shopping lists, pantry items, recipes, meal plans, food logs,
family member profiles, status notes, school form templates and drafts, documents, calendar events,
reminders, AI chat messages, voice transcripts, and other notes you add. If you turn on Apple
Calendar sync in the iOS app, events from the device calendars you select (including events created
outside the app) are copied to our servers, and the app propagates deletions in both directions
when it syncs.
- Health & Nutrition Information: Food logs, calorie and macronutrient estimates,
meal history, dietary preferences, allergy or restriction notes, and related family member details you
choose to enter. We process this category only with your explicit consent (see Section 6).
- Photos, Videos, Audio, and Documents: Images or videos of food, receipts, pantry
items, recipes, or school forms; uploaded documents; and audio submitted for transcription when you
use those optional features. Audio files are used to provide transcription and are not intended to be
stored as account content.
- Location Data: If you choose to use weather features, city names or coordinates may
be used to fetch weather and geocoding results. The iOS app is designed around coarse/manual weather
context rather than continuous GPS tracking. The web app may use browser geolocation if you grant
permission.
- Identifiers and Device Data: Firebase user ID, app user ID for RevenueCat,
device-generated sync identifiers, app integrity or App Check tokens, app version, device/browser
information, and authentication or security tokens needed to operate the service.
- Purchase History: Subscription entitlement, product, renewal, cancellation, and
restore status from Apple and RevenueCat. Apple processes your payment details; we do not receive your
full card number.
- Usage Data: Feature interactions, AI quota counts, subscription state, timestamps,
API request metadata, aggregated AI usage such as provider, model, token counts, latency, and success
or error status, and optional web analytics after you grant analytics consent.
- Legal acceptance records: The version and date of the Terms of Service and Privacy
Policy you accepted, and the consents you have given, kept as evidence of your agreement.
"Food DNA" is not genetic data. Despite its name, the Food DNA feature is a
taste-preference profile computed from your family's meal ratings (which ingredients and cuisines each
person likes). It does not involve genetic, biometric, or DNA data of any kind, and the app neither
collects nor processes genetic data.
App Store Privacy Summary: For App Store privacy labels, the iOS app collects data linked
to you in these categories: Name, Email Address, Health, Coarse Location, Photos or Videos, Other User
Content, User ID, Device ID, Purchase History, and Product Interaction. We use these categories for App
Functionality. Health, Coarse Location, Photos or Videos, and Other User Content may also be used for
Product Personalization, such as tailored meal, weather, recipe, pantry, calendar, or AI suggestions. We
do not use these categories for tracking, third-party advertising, or developer advertising.
5. Why We Use Your Data, and on What Legal Basis
| Purpose |
Legal basis (GDPR) |
| Creating and securing your account; providing core features (tasks, calendar, meals, family
profiles, school forms, documents) |
Performance of contract (Art. 6(1)(b)) |
| Processing AI requests you initiate (meal plans, document analysis, transcription, chat,
translation) |
Performance of contract (Art. 6(1)(b)) |
| Processing health and nutrition data in optional features (food logs, allergies, dietary
restrictions) |
Your explicit consent (Art. 9(2)(a)) |
| Subscription management, quota enforcement, restore purchases |
Performance of contract (Art. 6(1)(b)) |
| Security, fraud prevention, abuse monitoring, rate limiting |
Legitimate interests (Art. 6(1)(f)) |
| Web analytics and error reporting |
Consent (Art. 6(1)(a)) — off by default |
| Legal compliance and record-keeping (including acceptance records) |
Legal obligation / legitimate interests (Art. 6(1)(c), (f)) |
Under Japan's Act on the Protection of Personal Information (APPI), the above also constitutes our notice
of purposes of use(利用目的).
We do NOT sell your personal data. We do NOT use your data for advertising. We do NOT use your data
to train AI models.
6. Health Data and Explicit Consent
Health-related information (food logs, allergies, dietary restrictions, nutrition estimates) receives
heightened protection under the GDPR (Article 9) and Japan's APPI. We process it only if you
choose to use the related features and give explicit consent through the dedicated consent step in
the app — agreeing to this policy alone does not enable it.
- This data is used solely to provide the features you requested (food logging, meal planning,
nutrition summaries).
- You can withdraw consent and delete this data at any time via Settings; withdrawal does not affect
the rest of your account.
- Rout1 Home Brain is not a medical device and does not provide medical, dietary, or nutritional
advice.
7. AI Features and Providers
Rout1 Home Brain uses AI features powered by third-party large language model (LLM) providers.
AI features are clearly labeled in the app (look for the ✨ sparkle icon or "AI" labels).
The AI assistant in the app is an artificial intelligence system, not a human. You can
ask the AI assistant at any time whether it is a human or AI and it will truthfully confirm it is AI.
AI features remain off until you separately grant the current AI data-sharing consent in the app. When you
use them, the content needed to fulfill your request is sent to the provider below. You can withdraw this
consent at any time in Settings without losing access to core non-AI features.
We do not use your personal data to train AI models, and our AI provider does not use API data to
train its models.
- OpenAI, L.L.C. (United States): Smart assistant responses, meal planning, task
extraction, recipe/image analysis, document processing, translation, and transcription are processed
per-request through OpenAI's API. Per OpenAI's API terms, API data is not used for model training and
may be retained by OpenAI for up to approximately 30 days for abuse and misuse monitoring before
deletion. Photos analyzed for food recognition are used for food or document analysis only, not for
facial recognition or biometric identification.
Images, documents, and audio require an additional confirmation for each upload or recording action.
Server-side validation and abuse controls reduce risk but cannot identify or remove every sensitive detail.
Do not upload government IDs, full payment card numbers, or other highly sensitive material unless strictly
necessary for the feature you choose to use.
AI Training and Profiling: We do not sell your personal data, use it for advertising, or
use it to train AI models. AI features provide suggestions and automation assistance; they do not make
legal, medical, financial, insurance, employment, housing, education, or similarly significant decisions
about you.
8. Service Providers (Subprocessors)
| Provider |
Country |
What they process |
Purpose |
| OpenAI, L.L.C. |
USA |
Content of your AI requests (text, images, documents, audio) |
AI processing |
| Google LLC / Firebase |
USA |
Email address, authentication tokens |
Sign-in and sessions
(privacy) |
| Cloudflare, Inc. |
USA (global network) |
All Service data |
Hosting, API delivery, database (D1), bot protection on the contact form (Turnstile) |
| Apple Inc. |
USA |
Subscription and payment status |
In-app purchases |
| RevenueCat, Inc. |
USA |
App user ID, subscription status |
Subscription management
(privacy) |
| Open-Meteo / Nominatim (OSM Foundation) |
Germany / UK |
City names or coordinates |
Weather and geocoding
(privacy) |
| Resend, Inc. |
USA |
Name, email address, message, and the category you select in the contact form |
Delivery of contact form notification emails
(privacy) |
| Google Analytics |
USA |
Usage statistics (only with your consent) |
Web analytics — consent defaults to denied; not used for advertising |
| Sentry (Functional Software, Inc.) |
USA |
Error reports, IP address, browser/device info (only with your consent) |
Crash reporting
(privacy) |
Each provider processes data under a data processing agreement or equivalent terms, and only for the
purposes above.
9. International Data Transfers
We operate from Japan, which the European Commission has recognized as providing an
adequate level of data protection, so transfers of EU/EEA users' data to us are covered by that adequacy
decision. Onward transfers to our US-based providers are protected by the EU-US Data Privacy
Framework (for certified providers) or equivalent contractual safeguards.
For users in Japan: our provision of data to foreign service providers is conducted as entrustment(委託)
under appropriate supervision pursuant to the APPI. The providers, countries, and data items involved are
listed in Section 8 above.
You can avoid optional AI, photo analysis, transcription, and weather requests by not using those optional
features, but core account, hosting, and subscription services will still involve the infrastructure
providers listed above.
10. Data Security
- Encryption in transit using HTTPS/TLS for API communications.
- Authentication tokens stored in device secure storage (Keychain on iOS).
- Server-side validation, authorization checks, and abuse controls on AI endpoints.
- Per-action confirmation before raw images, documents, or audio are sent to OpenAI.
- App integrity verification (Firebase App Check) and rate limiting.
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute
security.
11. Data Retention & Deletion
- User content (tasks, recipes, family data): Retained while your account is active.
- AI usage logs: Retained for 60 days for security monitoring, then deleted by
scheduled cleanup.
- Account deletion: You may delete your account at any time via Settings > Data
& Privacy > Delete Account. This removes account data from primary systems and schedules backup
deletion within 30 days. Security and audit logs, fraud-prevention records, and legal acceptance
records may be retained for the limited periods required for those purposes or by law, then
deleted.
- AI provider retention: OpenAI may retain API request data for up to approximately 30
days for abuse monitoring, then deletes it (see Section 7).
- Data export: You may export a copy of all your data at any time via Settings.
12. Your Rights
Built into the app, regardless of where you live:
- Access your data (via the in-app data export feature).
- Correct your data (by editing your profile, family members, and content directly in
the app).
- Delete your data (via Settings > Clear All Data or Delete Account).
- Withdraw consent (health data features, OpenAI data sharing, analytics) at any time without affecting
prior processing.
- Manage permissions for camera, photo library, microphone, speech recognition,
calendar, and browser geolocation through your device or browser settings.
Depending on where you live, you also have legal rights to access, correct, delete, restrict, object to, or
receive a portable copy of your personal data. To exercise any of these rights, contact
paula@rout1.com; we respond within the timelines required by
applicable law.
- EU/EEA and UK users additionally have the right to lodge a complaint with their local
data protection supervisory authority.
- Users in Japan may make disclosure, correction, and cessation-of-use requests under
the APPI, and may contact the Personal Information Protection Commission(個人情報保護委員会).
We do not sell personal data, share it for targeted advertising, or use it for cross-app tracking.
13. Analytics and Cookies
Web analytics (Google Analytics) and error reporting (Sentry) are off by default and load
only after you grant analytics consent via the consent banner. Consent mode defaults to denied. We do not
use analytics for advertising. You can withdraw consent at any time in the site's privacy settings.
14. Changes to This Policy
We will announce changes in the app or on our website before they take effect, including the new content
and effective date. For material changes — especially any change to how health data is handled — we will
ask for your renewed acceptance in the app rather than relying on continued use.
15. Contact
If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, please
contact:
MARIA PRECIOUS PAULA SUARNABA LAPIZAR (Tokyo, Japan)
Email: paula@rout1.com