Back to Home

Privacy Policy

Last Updated: June 9, 2026

1. Introduction

Welcome to Bunbee ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience on our website and in using our apps.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use the Bunbee application. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.

2. Information We Collect

We collect information in three ways: information you provide directly, information collected automatically through your use of the Service, and information from third parties.

INFORMATION YOU PROVIDE

  • Account Data: name, email address, password (securely hashed, never stored in plain text).
  • Onboarding Data: caregiver role, guidance style preferences, focus areas (e.g., sleep, feeding), country/location.
  • Child Profile Data: name or nickname, date of birth, feeding stage, dietary preferences and allergies. Where allergy or medical information is provided, this constitutes "special category data" under UK GDPR Article 9 and is processed only on the basis of your explicit consent provided when you create the profile, for the purpose of giving you age-appropriate and safety-relevant guidance.
  • Scan and Library Data: barcodes you scan, products you save to your Library, recipes and meal guides you save or generate.
  • Chat Data: the text of your conversations with Bee.
  • Payment Data: when you subscribe, your payment details are processed directly by Stripe. We receive only a Stripe customer identifier, subscription status, and billing metadata (last four digits of card, billing country) — we never see or store full payment card numbers.

INFORMATION COLLECTED AUTOMATICALLY

  • Device and Technical Data: device type, operating system, browser, IP address, time zone, language preference.
  • Usage Data: features used, pages viewed, scan and chat frequency, error logs, performance metrics. This is used to operate and improve the Service.
  • Cookies and Similar Technologies: see Section 7A (Cookies) below.

INFORMATION FROM THIRD PARTIES

  • Product Data Providers: ingredient and nutrition data is retrieved from OpenFoodFacts, USDA Branded Foods, and UK retailer data feeds. We do not share your personal data with these sources.
  • Payment Provider: Stripe provides us with subscription status and payment outcomes (success, failure, refund).

3. How We Use Your Information and Legal Basis

Under UK GDPR Article 6 (and Article 9 for special category data such as allergy information), we process your personal data on the following legal bases:

PurposeLegal basis
Creating and maintaining your accountContract (Art 6(1)(b))
Providing scanning, chat, recipes, meal guides, and core Service featuresContract (Art 6(1)(b))
Personalising guidance using your child profile, allergies, dietary needsExplicit consent (Art 6(1)(a) + 9(2)(a))
Processing payments and managing subscriptionsContract (Art 6(1)(b)) + legal obligation (HMRC)
Sending transactional emails (account, billing, security, password reset)Contract (Art 6(1)(b))
Sending marketing emails (where you have opted in)Consent (Art 6(1)(a))
Detecting fraud, abuse, and security incidentsLegitimate interest (Art 6(1)(f))
Aggregated analytics to improve the Service (no personal identification)Legitimate interest (Art 6(1)(f))
Complying with legal obligations (HMRC, court orders, regulator requests)Legal obligation (Art 6(1)(c))

You can withdraw consent at any time via Settings → Privacy & Data, or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.

We do not use your personal data, your child's information, or your Bee chat conversations to train third-party AI models. Our use of Anthropic Claude and Google Gemini is via their APIs, which exclude customer data from model training by default.

4. Data Storage & Security

We use industry-standard security measures to protect your personal information. Your data is stored on secure servers and encrypted both in transit and at rest. For authentication, we use secure HTTP-only JWT session cookies to keep your account safe.

However, please be aware that no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

6. Your Rights — Access, Export, and Deletion

Under UK GDPR (Articles 15–22), you have the right to access, correct, export, delete, restrict, object to, and port your personal data. You also have the right to withdraw consent for processing that relies on consent (without affecting the lawfulness of processing before withdrawal) and the right to lodge a complaint with a supervisory authority (see Section 10).

ACCESS & EXPORT

Settings → Privacy & Data → Export JSON. The export includes your account details, onboarding preferences, child profiles, scan history, chat conversations, saved Library items, and meal guides.

CORRECTION

Update your personal information directly in Settings.

DELETION

Settings → Privacy & Data → Delete Account.

When you delete your account, we erase from our active systems:

  • Your account, login credentials, and contact details
  • Your onboarding preferences and saved settings
  • All child profiles and their associated data (DOB, allergies, preferences)
  • Your scan history and saved Library items
  • Your chat conversations with Bee
  • Your meal guides

We complete this deletion within 30 days of your request.

WHAT WE MAY RETAIN (and why)

  • Transaction records: For users who have made a payment, we retain anonymised invoice and tax records for 6 years to comply with UK HMRC and VAT regulations.
  • Encrypted backups: Backup snapshots may contain residual personal data for up to 35 days after deletion, after which they are overwritten.
  • Legal hold: If we are subject to a legal claim or regulatory request involving your account, we may retain relevant records until the matter is resolved.

CHILD PROFILE DELETION (without deleting your account)

Settings → Child Profiles → [profile] → Delete. This permanently removes the profile and associated guidance context. Note that historical chat conversations that referenced this child will retain those references unless you also delete your chat history.

OTHER RIGHTS

You can also:

  • Restrict processing: ask us to stop using your data for particular purposes while keeping it stored.
  • Object to processing: where we rely on legitimate interest (e.g., analytics).
  • Data portability: receive a copy of your data in a structured, commonly used format (the JSON export covers this).

To exercise any of these rights, use Settings or contact hello@bunbee.app. We will respond within one month.

7. Third-Party Service Providers

We work with the following providers to deliver the Service. We share only the data necessary for each provider to perform its function.

INFRASTRUCTURE

  • Supabase (database, authentication, file storage). Data hosted in the EU region. Personal data processed: all account, profile, scan, chat, and Library data.
  • Cloudinary (image storage). Data: product images and uploaded scan images.
  • Resend (transactional email delivery). Data: email address, recipient name, email content for transactional emails.

AI SERVICES

  • Anthropic (Claude API) — Bee chat. Data: your chat messages and related context for response generation. Anthropic does not use API data to train its models.
  • Google (Gemini API) — image and text analysis. Data: scanned images and ingredient text. Google does not use API data to train its models.

PRODUCT DATA PROVIDERS

  • OpenFoodFacts (food product database). We retrieve product data from them; we do not share personal data with them.
  • USDA Branded Foods (food product database). Same as above.

PAYMENT PROCESSING

  • Stripe (payment processing). Data: card details (collected and stored by Stripe, not by us), billing address, subscription status. Stripe is a separate data controller for the payment data it collects.

7A. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Service and to improve it.

ESSENTIAL COOKIES

These are required for the Service to work and do not need your consent under the UK Privacy and Electronic Communications Regulations:

  • Authentication cookies (to keep you signed in)
  • Session cookies (to maintain your in-app state)
  • Security cookies (to protect against fraud and CSRF attacks)

ANALYTICS AND PERFORMANCE COOKIES

We may use these to understand how the Service is used and improve it. Where used, we will ask for your consent the first time you visit the Service and will not set non-essential cookies until you consent. You can change your cookie preferences at any time in Settings → Privacy & Data → Cookie Preferences.

We do not currently use marketing or advertising cookies. If this changes, we will update this Policy and ask for your consent.

7B. International Data Transfers

Some of our service providers are based outside the UK and EEA:

  • Anthropic, Google, Stripe, and Resend may process data in the United States.
  • Cloudinary may process data in the United States or other regions.

Where we transfer personal data outside the UK, we rely on one of the following safeguards under UK GDPR:

  • The UK Government's adequacy decision for the destination country, where one is in place; or
  • The UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, with each provider.

You can request a copy of the relevant safeguards by contacting hello@bunbee.app.

8. Children's Data and the Age Appropriate Design Code

Bunbee is intended for use by adults — parents, guardians, and caregivers. To create a Bunbee account you must be at least 18 years old.

CHILD PROFILES YOU CREATE

The Service allows you to create profiles for children in your care. When you do so, the information you provide (the child's name, date of birth, feeding stage, dietary preferences, and any allergies) constitutes personal data — and where allergy or medical information is included, it is special category data under UK GDPR Article 9.

By creating a child profile, you confirm that:

  • You are the child's parent or legal guardian, or otherwise have parental responsibility for them;
  • You consent to the processing of the child's personal data (including special category data such as allergies) for the purpose of providing personalised guidance through the Service;
  • You may withdraw this consent at any time by deleting the child profile (see Section 6).

ICO AGE APPROPRIATE DESIGN CODE

We design the Service in line with the ICO's Age Appropriate Design Code (the "Children's Code"), including: privacy-protective defaults for child-profile data, minimisation of data collection about children, and clear explanations of how children's data is used.

DIRECT USE BY CHILDREN

The Service is not designed for direct use by children under 18. We do not knowingly collect data directly from children. If you become aware that a child has created an account, please contact us at hello@bunbee.app and we will delete it.

9. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

10. Contact Us and Your Right to Complain

CONTROLLER IDENTITY

The data controller for personal data processed through the Service is:

Emaloua Limited
128 City Road, London, EC1V 2NX
Company number: 17118671
Registered in England and Wales

CONTACT

For questions about this Privacy Policy or to exercise any of your rights, contact:

  • General privacy queries: hello@bunbee.app
  • Billing-specific privacy queries: billing@bunbee.app

We do not currently appoint a Data Protection Officer because we are not required to under UK GDPR Article 37. If this changes, we will update this Policy.

RIGHT TO COMPLAIN

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

  • Web: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact Us