Legal

Privacy policy

Last updated August 26, 2026 · applies to the Lipsis app (Google Play, App Store), the nutritionist workspace and the website lipsis.app

In short

1. Who we are and what this document covers

The Lipsis app (the “App”) and the web workspace for nutritionists (the “Workspace”, together the “Service”) are owned and operated by Quantrol LLC, identification number 405580250, registered address: 2 Givi Kartozia St., apt. 47, Saburtalo district, Tbilisi, Georgia (“we”, “Lipsis”). We are the controller of the personal data of the Service's users.

This policy explains what data we collect, why, who we share it with, where and for how long we store it, and what rights you have. It applies to the App on Google Play and the App Store, to the Workspace and to the website lipsis.app.

For any questions about your data, write to support@quantrol.ge.

2. What data we collect

2.1. Data you provide yourself

CategoryWhat exactlyRequired?
AccountData passed by the sign-in method you choose: with Google — your name, email address and Google account identifier; with Apple — your name, email (or Apple's private relay address) and Apple ID identifier; with Telegram — your name and Telegram identifier; with phone sign-up — your phone number. We never receive or store your passwords for these servicesOne sign-in method — yes
Body and goalsDate of birth, sex, height, weight and weight history, activity level, goal (e.g. losing or maintaining weight), daily calorie targetNeeded to calculate your target
NutritionFood photos, meal entries, dishes and their weight, recipes, task completion marksAt your discretion
HealthAllergies, intolerances and dietary restrictions, diagnoses, test results and any other health information you choose to enterNo — only with your separate consent
CommunicationChat messages with your nutritionist, comments on entriesAt your discretion

Health information is a special (sensitive) category of data. We process it only on the basis of your explicit consent, which you give when filling in the relevant section, and only to tailor your diet and support your nutritionist's work. You can delete this information or withdraw consent at any time — in the App's settings or by writing to us.

Signing in to the Service goes through external providers (currently Google; Apple, Telegram and phone-number sign-in will be added as the Service develops). The wording “if you sign in with…” applies to whichever method you use.

2.2. Data collected automatically

We do not collect precise location and do not access your contacts, photo library or microphone, other than the photos you take or choose yourself for a diary entry.

2.3. Payments

The Service is currently free. If paid features are introduced, purchases will go through Google Play Billing or the App Store. We do not receive or store card details — only the transaction identifier, the product purchased and its status, so that we can give you access.

3. Why we use data and on what legal basis

PurposeDataLegal basis (GDPR)
Create your account and give you access to the ServiceAccountPerformance of a contract (Art. 6(1)(b))
Calculate your calorie target, keep the diary, count what's left, suggest mealsBody and goals, NutritionPerformance of a contract (Art. 6(1)(b))
Recognize dishes and count calories from photosFood photosPerformance of a contract (Art. 6(1)(b))
Take restrictions and health conditions into account when tailoring your diet, and show them to your nutritionistHealthExplicit consent (Art. 9(2)(a))
Give your nutritionist access to your diary, progress and chatAll categories you keepPerformance of a contract and your action of connecting a nutritionist
Send reminders and notificationsPush token, reminder settingsPerformance of a contract; you can turn them off in settings
Improve the Service, fix bugs, keep it secureDevice, usage and crash data, logsLegitimate interest (Art. 6(1)(f))
Respond to your requestsContact details, content of the requestLegitimate interest (Art. 6(1)(f))
Comply with the law (accounting, lawful requests)Transaction data, accountLegal obligation (Art. 6(1)(c))

We do not sell personal data, do not show advertising and do not use your diary for advertising profiling.

4. Your nutritionist and your data

The App works without a nutritionist. If you connect one — via their invite link or code, or by confirming an addition on their side — you give them access to your diary, photos, progress, health information (if you have entered it) and chat. Access remains until you disconnect the nutritionist in the App's settings or delete your account.

Nutritionists are independent professionals, not Lipsis employees. When they use your data to advise you, they act as independent controllers and must comply with applicable law and professional ethics. Lipsis provides them with a tool but does not control the content of their recommendations. If you have concerns about how a nutritionist handles your data, write to us — we will look into it and restrict access if necessary.

A nutritionist sees only the clients who have connected them and cannot see other users.

5. Who we share data with

We share data only with providers who help us run the Service, and only to the extent needed for their task. We have a data processing agreement with each of them.

WhoWhyWhat dataWhere
Cloud AI recognition service providerRecognizing dishes and estimating portions from photos or text descriptionsThe food photo and description, without your name or contact details. The provider processes this data for analysis and recognitionUSA / EU
Google (Google sign-in; Firebase Analytics, Crashlytics, Cloud Messaging)Authentication, pseudonymized analytics, crash reports, push notification deliveryAccount identifier at sign-in; device and usage data, push tokenUSA / EU
Apple (Sign in with Apple, Apple Push Notification service)Apple ID sign-in (if you choose it), push notification delivery on iOSApple ID identifier at sign-in; push tokenUSA / EU
Google Play, App StoreProcessing purchases (if paid features are introduced)Transaction data without card detailsPer the stores' rules
Zomro (hosting provider)Hosting servers and the databaseAll Service data in encrypted storagePoland (EU)
TelegramSign-in with Telegram, if you choose itTelegram identifier and namePer Telegram's rules

We may also disclose data when required by law or by a lawful request from a public authority, and in the event of a reorganization or sale of the company — subject to the terms of this policy.

6. Where data is stored and international transfers

Service data is stored on servers in a data centre in Poland (European Union). Our company is registered in Georgia, and our staff access data from Georgia to the extent needed for support and development. Some providers listed in section 5 process data in the United States.

When transferring data outside the EU/EEA, we rely on safeguards provided by law: the European Commission's Standard Contractual Clauses, the provider's participation in the EU-U.S. Data Privacy Framework, or other recognized mechanisms. You can request a copy of the applicable safeguards at support@quantrol.ge.

7. How long we keep data

8. How we protect data

Data is transmitted over encrypted connections (TLS) and stored encrypted. Sign-in goes through trusted providers (Google, with Apple and Telegram to follow) — your passwords for those services are never passed to us or stored by us. Staff access is limited to what their work requires and is logged. We keep software up to date and make regular backups. No system can guarantee absolute security, so if you notice anything suspicious, write to support@quantrol.ge — we will respond without delay.

9. Your rights

At any time you can:

To exercise your rights, write to support@quantrol.ge from the address your account is registered with. We will respond within 30 days. If you are in the EU/EEA or the UK, you may also lodge a complaint with your country's data protection authority. In Georgia, this is the Personal Data Protection Service.

California residents. We do not sell personal data and do not share it for targeted advertising. You have the right to know what data we collect, to request its deletion, and not to be discriminated against for exercising your rights.

10. Age

The Service is intended for people aged 18 and over. We do not knowingly collect data from children. If you become aware that a child has registered for the Service, write to us — we will delete the account and the data.

11. Deleting your account

You can delete your account and all data in the App (Settings → Account → Delete account) or by request to support@quantrol.ge. Step-by-step instructions, timelines and the list of what is deleted are on the “Delete your account” page.

12. Changes to this policy

We may update this policy. We will notify you of material changes in the App or by email at least 14 days before they take effect. The current version is always available at lipsis.app/en/privacy.html; the date of the last update is shown at the top of the page.

13. Contact

Quantrol LLC, identification number 405580250, registered address: 2 Givi Kartozia St., apt. 47, Saburtalo district, Tbilisi, Georgia

Data questions: support@quantrol.ge