Privacy
Short version: bite stores what it needs to give you your bites back, keeps it in the EU, sells none of it, and deletes all of it the moment you ask.
Who is responsible
Philipp Tschauner, Berlin, Germany. Postal address and contact details are in the imprint.
What is stored
- Your account. The email address and name your sign-in provider hands over when you use Sign in with Apple or Google. bite never sees your password.
- What you saved. The address, title and timestamp of each link, whether you read, skipped or kept it, and any lists you filed it on.
- The bites themselves. The text extracted from a source and the summary written from it. Summaries are shared between everyone who saved the same address — they contain nothing about you, and that sharing is why the second person to save an article gets it instantly.
- Your preferences. Summary language, reading font and size, appearance.
- A push token, if you allowed notifications, so bite can tell you when something is ready.
- Your subscription status — whether you are on pro, and when that ends. Payment details belong to Apple; bite never receives them.
Usage analytics
bite counts how the app is used, so the parts nobody gets through can be found and fixed. It records a short, fixed list of moments — onboarding pages seen, sign-in started and finished, a briefing begun and completed, the purchase screen opened — with nothing but counts and outcomes attached.
It never records what you save or read. Not a title, not an address, not a summary. There is no automatic capture of taps or screens, no session recording, and no advertising or cross-app tracking of any kind. Nothing is sold or shared for advertising.
This runs on PostHog's European servers. You can switch it off in the app under Settings → Usage analytics, and it stops at the next start.
Who processes it
- Supabase — database and sign-in, hosted in Ireland (EU).
- Railway — the server that does the summarising, hosted in the EU.
- Anthropic and OpenAI — the models that write the summaries, and, for pro features, the narration and podcast transcription. They receive the text of the source and the summary. They do not receive your name, your email or any account identifier.
- RevenueCat — subscription status, plus a device identifier it needs to match a purchase to an account.
- Apple — notifications and, if you subscribe, the payment itself. Google — only if you choose to sign in with it.
- PostHog (EU) — the usage counts described above, tied to your account id once you sign in. Unless you switched them off.
Processing outside the EU happens where these providers operate. In each case it rests on the European Commission's standard contractual clauses.
Why, and on what basis
Everything above exists to provide the service you asked for — Article 6(1)(b) GDPR, performance of a contract. Notifications rest on your consent, which iOS asks for and you can withdraw at any time in Settings. Usage analytics rest on a legitimate interest in knowing which parts of the app fail people — Article 6(1)(f) — which is why the switch to turn them off sits in Settings rather than behind a request.
How long
As long as your account exists. Delete it in the app under Settings, and everything of yours goes with it: your saves, lists, preferences, push tokens and the account itself. The summaries stay, because they belong to everyone who saved the same address and hold nothing about you.
Your rights
You can ask for access, correction, deletion, restriction, a copy of your data, or object to processing. Use the address in the imprint, or, if you have the app, Settings → Support and feedback. You may also complain to a supervisory authority; for Berlin that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.