Privacy Policy

This privacy policy is applicable to the Allerlog: Baby Meal Tracker app for mobile devices, together with any related services operated by Arai Tech L.L.C-FZ (collectively, the "Application"). Arai Tech L.L.C-FZ is hereinafter referred to as the "Service Provider".


Data Controller Information

Arai Tech L.L.C-FZ acts as the Data Controller responsible for the processing of your personal data.

For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.

EU Representative: Oaca Stefanita Cornel, oacastefanita@gmail.com


What information does the Application obtain and how is it used?

The Application does not require you to create an account or register, and it does not ask for your name, email address, or phone number. The information you enter — such as your baby's profile (name and date of birth), meals, ingredients, notes, and the mood, sleep, and stool ratings you record — is stored locally on your device to provide the tracking, history, and reminder features. Except for the optional AI Insights feature described below, this content stays on your device and is not transmitted to the Service Provider. The Application also collects usage analytics and crash reports that describe how you interact with the Application — see "What information does the Application collect automatically?" below — but these do not include the content you enter. The Service Provider does not send marketing communications.


Legal basis for processing your personal data

Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:


Cookies and similar technologies

The Application is a native mobile app and does not use cookies, tracking pixels, or advertising identifiers. The Application does include an analytics and crash-reporting SDK (Google Firebase), which relies on a randomly generated app-instance identifier rather than the device's advertising identifier, as described under "What information does the Application collect automatically?". If you open a web link from within the Application (such as this Privacy Policy), the web page you open may use its own standard cookies.


Automated decision-making and profiling

If the Application uses automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, you have the right to request human review, express your point of view, and contest the decision. Information about the logic involved and the likely consequences of that processing will be provided where required by law.


What information does the Application collect automatically?

The Application collects usage analytics and crash reports through Google Firebase (Firebase Analytics and Firebase Crashlytics), services operated by Google LLC ("Google"). This data describes how you interact with the Application; it does not include the content you enter, such as your baby's name, date of birth, photos, free-text notes, or ingredient names.

The data collected includes:

Your device's IP address is received by Google as part of standard internet communication when this data is transmitted. The Application does not collect or use the advertising identifier (IDFA), does not use this data for advertising, and does not sell it. The Service Provider uses this data solely to understand how the Application's features are used, to diagnose crashes and errors, and to improve the Application.

Where the GDPR applies, this processing is based on the Service Provider's legitimate interests in maintaining, securing, and improving the Application (Article 6(1)(f)). You have the right to object to this processing at any time; see "What are my opt-out rights?" below.

Google processes this data on the Service Provider's behalf under Google's data processing terms and its own privacy documentation, which we encourage you to review: Privacy and Security in Firebase and the Google Privacy Policy. Analytics and crash data is processed on Google servers, which may be located in the United States and other countries outside the EEA; where the GDPR applies, these transfers rely on safeguards such as the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. Analytics data associated with your app instance is retained for a limited period (currently up to 14 months), and crash reports are retained for approximately 90 days, after which they are deleted or aggregated.

Separately, when you use an online feature — namely optional AI Insights, or opening a web link — the third party you connect to (for example, DeepSeek or the website behind a link) necessarily receives your device's IP address as part of standard internet communication. The Service Provider does not itself log or retain your IP address.


Does the Application collect precise real time location information of the device?

This Application does not gather precise information about the location of your mobile device.


Does the Application use Artificial Intelligence (AI) technologies?

The Application offers an optional "AI Insights" feature. It is turned OFF by default and runs only after you give explicit in-app consent. If you do not enable it, no data is sent to any AI provider.

When you enable AI Insights, the Application sends the following data to DeepSeek (operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) via its API to generate a short note about possible food-intolerance patterns:

DeepSeek receives this data in order to generate your insight. The Service Provider does not sell, monetize, or share this data for advertising or profiling purposes. DeepSeek processes the data it receives under its own privacy policy and terms of use, which we encourage you to review: DeepSeek Privacy Policy.

Because this information can relate to your child's health, we treat it as sensitive personal data and process it only on the basis of your explicit consent (GDPR Article 6(1)(a) and, where applicable, Article 9(2)(a)). You can withdraw your consent at any time by turning AI Insights off in the Application's Settings, which stops all further transmission of data to DeepSeek.

International transfer: DeepSeek processes this data on servers located in China, which is outside the European Economic Area (EEA) and is not covered by a European Commission adequacy decision. Where the GDPR applies, this transfer takes place on the basis of your explicit consent under Article 49(1)(a); if you do not enable AI Insights, no such transfer occurs. Countries outside the EEA, including China, may not provide the same level of data protection as the EEA.


Do third parties see and/or have access to information obtained by the Application?

The content you enter stays on your device. The circumstances in which data leaves your device are: (1) the optional AI Insights feature, which you must explicitly enable, sends the meal data described above to DeepSeek; (2) subscription purchases, which are processed by Apple under Apple's own privacy policy (the Service Provider receives confirmation of your subscription status from Apple, not your payment details); and (3) usage analytics and crash reports, which are sent to Google Firebase as described above. The Service Provider does not use advertising services and does not otherwise transmit your personal data to third parties, except as described in this privacy statement (for example, where required by law).


International Data Transfers

The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V.

Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

The Service Provider may disclose User Provided and Automatically Collected Information:

Where the Service Provider engages a third party to process personal data on its behalf, it seeks to put appropriate data protection terms in place as required by applicable law.


What are my opt-out rights?

Because your information is stored on your device, you can remove it at any time by deleting it within the Application or by uninstalling the Application, which deletes the data held on your device. Information you previously chose to send to DeepSeek through AI Insights is subject to DeepSeek's own retention and deletion practices.

Usage analytics and crash reporting do not currently have an in-app toggle. You can object to this processing, or request deletion of the analytics data associated with your app instance, by contacting the Service Provider at admin@arai-tech.com; uninstalling the Application stops all further collection. Analytics and crash data already collected is deleted in line with the retention periods described above.

To request deletion of your personal data, withdraw consent, or exercise any of your rights, contact the Service Provider at admin@arai-tech.com.


What is the data retention policy and how can you manage your information?

Because your data is stored locally on your device, the Service Provider does not retain it on its own servers. Your information remains on your device until you delete it within the Application or uninstall the Application. Data sent to DeepSeek for AI Insights is retained and deleted by DeepSeek under its own policies. Usage analytics and crash data is retained on Google's servers for the limited periods described above (currently up to 14 months for analytics data associated with your app instance and approximately 90 days for crash reports).

You have the right to request deletion of your personal data at any time, except where retention is required by law. If you'd like the Service Provider to delete User Provided Data that you have provided via the Application, please contact them at admin@arai-tech.com and they will respond within the time required by applicable law. Please note that some User Provided Data may be required in order for the Application to function properly.


How does the Application address children's privacy?

The Application is not intended for children under 16 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.


The Service Provider does not knowingly collect personally identifiable information from children. The Service Provider encourages all children to never submit any personally identifiable information through the Application and/or Services. The Service Provider encourages parents and legal guardians to monitor their children's Internet usage and to help enforce this Policy by instructing their children never to provide personally identifiable information through the Application and/or Services without their permission. If you have reason to believe that a child has provided personally identifiable information to the Service Provider through the Application and/or Services, please contact the Service Provider (admin@arai-tech.com) so that they will be able to take the necessary actions. If you are under 16 years of age, or where a higher age of digital consent is established by applicable law, your parent or guardian must provide consent on your behalf where permitted by law.


How is your information kept secure?

The Service Provider is committed to safeguarding the confidentiality of your information. Because your data is stored locally, it is protected primarily by your device's own security features, such as your passcode or biometric lock and the operating system's data protection. Data transmitted for the optional AI Insights feature and for analytics and crash reporting is sent over encrypted (HTTPS) connections. No method of storage or transmission is completely secure, and the Service Provider cannot guarantee absolute security.


Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay, providing information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach.


How will you be informed of changes to this Privacy Policy?

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.


Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at admin@arai-tech.com.


This privacy policy is effective as of 2026-07-15


What are your GDPR data protection rights?

Under the GDPR, you have the following rights:

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country's Data Protection Authority can be found at: https://edpb.ec.europa.eu/about-edpb/members_en

If you are located in the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk


What are your California privacy rights (CCPA/CPRA)?

If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

To exercise any of these rights, please contact the Service Provider at admin@arai-tech.com. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.


How do you give your consent?

Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.


How can you contact the Data Controller?

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at admin@arai-tech.com.

To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.


This privacy policy page was generated by App Privacy Policy Generator