Privacy Policy

Version of 01.09.2026

1. About this document

This Privacy Policy (the “Policy”) explains what data is processed when you use the HiMentor mobile app (the “App”) and the himentor.org website (the “Site”), for what purpose, on what legal basis, how long it is kept, and what rights you have.

The Policy covers the App, the Site and the server-side services behind them. It does not cover third-party resources you may reach through links in the App or on the Site, including partner marketplaces and the payment page of our acquiring bank. Data processing on those resources is governed by their own policies.

By using the App or the Site you confirm that you have read this Policy. If you do not agree with it, please do not use the App.

2. Who we are

HiMentor is operated by HiMentor Ltd, a company incorporated in the Republic of Cyprus (registration number [HE number], registered office: [registered office address], Cyprus). HiMentor Ltd is the developer, the rights holder of the service and the controller of your personal data.

For any question about privacy or your data, write to us at support@himentor.org

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the data protection laws of the Republic of Cyprus. For users located in the Russian Federation we additionally observe Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.

3. Core principles

We follow the principle of data minimisation. In practice this means:

  • We collect only the data the App needs in order to do what it promises
  • Sensitive health data stays on your device by default and is not sent to our servers
  • We do not sell user data and we do not share it with advertisers
  • We do not build advertising profiles from health data
  • Every category of data has a defined purpose and a defined retention period

4. What we collect and where it is stored

On HiMentor servers:

  • Email address: account identification and service-related communication. Kept until the account is deleted
  • Food log (dish names, portions, calculated nutrients, date and time of the entry): running the App and keeping your nutrition history. Kept until the account is deleted
  • AI assistant conversation history: displaying the conversation and keeping context between messages. Kept until the account is deleted, or until you delete the individual chat
  • Internal user identifier: technical linking of your records. Kept until the account is deleted
  • Account settings that affect the server side (for example the answer language or subscription status): correct operation of the service. Kept until the account is deleted
  • Photos of meals that you take or attach for recognition: recognising the dish and estimating its nutrients. The photo is uploaded to our server, passed to the recognition model, and stored only as long as processing the request requires — no more than 30 days, after which it is deleted. We do not use meal photos for advertising, and we do not use them to train models

Technical data processed automatically:

  • IP address, app version, operating system version, device model, request type and timestamp: keeping the service available, protecting it from abuse, and debugging. Kept in server logs for no more than 90 days
  • Error and crash reports: fault diagnosis. Kept for no more than 90 days
  • Push notification token (if you allowed notifications): delivering notifications. Kept until you withdraw the permission or delete your account

Support requests:

  • The text of your request, your email address and any material you attach: handling the request and evidencing that it was handled. Kept for up to three years after the request is closed

On your device only — we neither see nor receive this data:

  • Height, weight and their history
  • Age, sex
  • Physical activity level
  • Apple Health / HealthKit data
  • Supplement list and reminder settings
  • Local interface settings

Data stored on your device may end up in your device backup if you have enabled backups through Apple. Such a backup is controlled by Apple and by your Apple ID; we have no access to it.

5. Purposes and legal bases

We process data only for the purposes listed below, on the following legal bases:

  • Providing the App’s features (food logging, nutrient calculation, history, AI assistant) — performance of our contract with you, namely the Terms of Service (Art. 6(1)(b) GDPR)
  • Account identification and access recovery — performance of the contract
  • Processing payments and providing the paid subscription — performance of the contract and compliance with accounting and tax obligations (Art. 6(1)(b) and 6(1)(c) GDPR)
  • Security, fraud prevention and abuse protection — our legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR)
  • Debugging and improving the App — our legitimate interest in a working product
  • Showing partner offers based on your food log — your consent, which you can withdraw at any time (Art. 6(1)(a) GDPR)
  • Answering support requests — performance of the contract and our legitimate interest
  • Meeting legal obligations — compliance with the law (Art. 6(1)(c) GDPR)

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

6. How data reaches the language model (AI)

When your meals are analysed, and when you talk to the AI assistant, the request is sent from your device to a large language model (LLM).

Before it is sent, biometric data is de-identified: instead of exact values we use ranges — for example “age 25–35”, “weight 70–80 kg”. Exact biometric values never leave your device.

A request to the model may contain: text you type yourself; a meal photo you submitted for recognition; food log entries relevant to that request; de-identified biometric ranges; and the service’s technical instructions. We do not pass your email address, payment data, or raw Apple Health data to the model.

Meal photo recognition works the same way. The photo goes from your device to our server, and from there to the recognition model. Please avoid capturing faces, documents or other people’s data in the frame: whatever is in the photo is sent to the model along with the dish.

Requests are logged through Langfuse Cloud (US region) — our technical sub-processor — solely for debugging and improving the quality of the App. Logs are not used for commercial, analytical or advertising purposes. Access to them is restricted by internal policy and granted only to staff who need it for their work.

Langfuse — Privacy Policy. Data is transferred over a secure channel (TLS).

We do not make your data available to model providers for training their models, and we use the operating modes in which such training is switched off.

Model answers are generated automatically, but they are not decisions producing legal effects for you: they are informational, they do not restrict your access to any feature of the App, and they do not affect your rights. The final decisions about your nutrition are yours.

7. Payments and subscription

How a subscription is paid for depends on where you bought it.

In-app purchase through the App Store. This is the standard route for the iOS app. The payment is handled entirely by Apple: card details, billing and refunds stay on Apple’s side and never reach us. Apple sends us confirmation that the subscription is active, tied to your account through an anonymous identifier. Managing and cancelling such a subscription is done in your Apple ID settings. Apple’s processing of your data is governed by Apple’s privacy policy.

Payment on the website. Where a subscription is bought outside the App Store, it is processed through our acquiring bank, T-Bank (JSC “TBank”). Payment takes place on the bank’s secure side.

What matters in both cases:

  • Your card details are entered on the bank’s payment page and never reach us. We do not see, receive or store the card number, expiry date or security code
  • On our side we keep: the internal user identifier, the plan identifier and name, the amount, the payment status, the date and time of the transaction, and a technical token issued by the bank for recurring charges
  • That technical token cannot be used to obtain your card details; it is used only to charge your subscription
  • The bank’s processing of your payment is governed by the bank’s own documents and by payment scheme requirements, including the PCI DSS standard
  • Payment records are kept for the periods required by accounting and tax law — at least five years. That period continues to apply after you delete your account, because retaining these records is a legal obligation

8. Apple Health / HealthKit data

Apple Health data is used solely to produce recommendations on your device. This data:

  • is not sent to HiMentor servers;
  • is not shared with third parties;
  • is never used for advertising or marketing;
  • is not used to generate partner offers;
  • does not appear in the logs of our services.

This follows Apple’s requirements for apps that work with HealthKit. You can revoke access to Apple Health at any time in iOS settings.

9. Advertising and partner offers

The App may show recommendations for partner products — supplements and food — when it detects nutrient imbalances in your diet.

What you should know:

  • Recommendations are generated solely from your food log
  • Apple Health data, biometrics and activity data are never used for advertising — this follows Apple’s HealthKit requirements
  • We do not pass your data to advertisers or partners
  • We do not use third-party ad networks or trackers to show these offers
  • We do not ask for permission to track you across other companies’ apps and websites
  • Partner offers are links to marketplaces carrying products that HiMentor has vetted for quality
  • Following such a link takes you to a third-party resource that processes your data under its own policy
  • All advertising material is clearly marked as advertising
  • Ignoring an offer has no effect on how the App works

10. Sub-processors

We use the following technical sub-processors to run the App. Each relationship is covered by a contract, and the data shared is limited to what the purpose requires.

  • OpenAI: processing language model requests — meal analysis and the AI assistant. Shared: the request text, relevant food log entries, de-identified biometric ranges
  • Langfuse Cloud (United States): logging language model requests for debugging only. Shared: the content of the request and the model’s answer
  • JSC “TBank”: accepting payments and running recurring charges. Shared: the amount, the payment description, the internal user identifier
  • Server infrastructure provider: hosting the App’s servers and databases. Processes data within an encrypted channel, for and on the instructions of HiMentor

This section is our current sub-processor list. When we engage a new sub-processor that handles personal data, we update it.

11. International transfers

Some of our sub-processors are located outside the European Economic Area — in particular, request logging runs on Langfuse Cloud in the United States, and language model providers may process requests outside the EEA. This means that when a request goes to the language model, data may be processed in those countries.

Only the data described in section 6 is transferred; exact biometric values are not. Transfers take place over a secure channel (TLS) and under contracts containing data protection obligations, including the European Commission’s Standard Contractual Clauses where applicable.

12. The Site, cookies and similar technologies

himentor.org is used to publish information about the service, to host this Policy and the Terms of Service, and to take you to subscription checkout.

We do not use advertising or tracking cookies, we do not embed third-party analytics counters, and we do not build profiles of visitors.

The Site sets exactly two kinds of technically necessary storage:

  • A language cookie (`himentor_locale`), which remembers the language you picked in the switcher so that the Site opens in it next time. It stores nothing but the language code, and it lives for up to one year or until you clear your browser data
  • Session storage for a payment in progress — used only to complete a checkout you have started, for example to show you the result after you return from the bank’s page. It is cleared when your browser session ends

The Site’s web server keeps standard technical access logs (IP address, request time, page address, browser type) for security and diagnostics. Retention: no more than 90 days.

13. Retention periods

We keep data no longer than the purpose it was collected for requires:

  • Account data and food log — until the account is deleted
  • Meal photos — up to 30 days from upload
  • AI assistant conversation history — until the account or the individual chat is deleted
  • Technical logs and error reports — up to 90 days
  • Language model request logs — up to 90 days
  • Support requests — up to three years after the request is closed
  • Payment and subscription records — at least five years, as required by law

Once the retention period ends, data is deleted or anonymised. Data in server backups is removed as part of the normal backup rotation — no later than 30 days after deletion from the live system.

14. Deleting your account

You can ask us to delete your account at any time — from within the App or by contacting support.

Deleting the account removes your email address, food log and conversation history from our servers in full. Data stored on your device is removed by you, together with the App. Records we are legally required to keep — primarily records of completed payments — are retained for the statutory period, and only to the extent needed to meet that obligation.

Deleting your account does not automatically cancel an active paid subscription; the cancellation procedure is described in the Terms of Service.

15. Your rights

Under the GDPR and other applicable law you have the right to:

  • Obtain confirmation that we process your data, and a copy of it — on request to support
  • Have inaccurate or incomplete data corrected
  • Have all your data erased — deleting the account removes your email and food log from our servers in full; data on your device you delete yourself
  • Restrict processing — for example while the accuracy of your data is being checked
  • Receive your data in a structured, machine-readable format and transfer it to another service
  • Object to processing based on our legitimate interest
  • Withdraw your consent at any time — by contacting support or deleting your account
  • Lodge a complaint with a supervisory authority: in Cyprus, the Office of the Commissioner for Personal Data Protection; elsewhere in the EEA, the authority of your country; in Russia, Roskomnadzor

To exercise any of these rights, write to support@himentor.org from the email address registered to your account. We may ask for further information where we have reasonable doubts that the request comes from the data subject — this protects you from having your data handed to someone else.

We respond to data subject requests within 30 days, as required by the GDPR. This is free of charge; for manifestly unfounded or repetitive requests we may refuse to act, explaining why.

16. Security

We protect data with the following measures:

  • Data is transmitted over an encrypted channel (TLS)
  • Access to server data is limited to people who need it for their work, and is logged
  • Access to infrastructure is protected by individual credentials and multi-factor authentication
  • Biometric data never leaves the device
  • Bank card details are neither processed nor stored on our side
  • Server data is backed up regularly, and access to backups is restricted
  • Changes to infrastructure and code are reviewed before release

No service can guarantee absolute security. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it and, without undue delay, inform affected users of the nature of the incident and the measures we recommend.

17. Age of users

The App is intended for people aged 16 and over. We do not knowingly collect data from anyone younger, and we do not direct the service at them.

If you believe a minor’s data has reached us by mistake, contact support. We will delete such data after verification.

18. Changes to this Policy

We may update this Policy — for example when the App’s functionality, our sub-processors or the law change.

The current version is always available on the Site, with its version date at the top. For material changes — such as collecting additional categories of data, changing the purposes of processing, or engaging a new sub-processor — we will notify you through an App update or by email at least 14 days before the change takes effect, unless the law requires us to apply it sooner.

Continuing to use the App after a change takes effect means you accept the updated version. If you do not accept it, you may stop using the App and delete your account.

19. Contact

Email: support@himentor.org

We reply within one business day, excluding weekends and public holidays. Requests concerning data subject rights are handled within the period stated in section 15.