Tabelingo

Language of this page

This policy and the Terms are published in English, and English is the version that governs. We do not translate them: a legal text translated without review is not the same text in another language — it is a different promise. If you need help understanding it in your language, write to privacy@tabelingo.com and a person will explain.

Privacy Policy — Tabelingo

Last updated: 10 August 2026 Status: draft — not reviewed by a lawyer

⚠️ A technical draft, written from what the app actually does — every statement below was checked against the schema, the Edge Functions and the app code, not against what we intended to build.

It does not replace legal review. Three parts need it in particular: the legal bases in §3 and §5 (GDPR Art. 6), the international transfers in §6 (the models that read the photo run outside the EU), and the retention of speech in §3.3, which holds words spoken by someone who is not our user.

Language. This document and the Terms of Service are published in English, and English is the version that governs. The app itself ships in ten languages; these two documents deliberately do not, because a legal text translated without review is not the same text in another language — it is a different promise. If you need help understanding either of them in your own language, write to us and a person will explain.

This file must be published at a public URL before submission: both the App Store and Google Play require the link in the form, and without it there is no way to submit.


1. Who we are

Tabelingo is an app that reads a restaurant menu from a photograph, translates the dishes and assembles an order in Japanese.

Data controller: [to fill in — legal name and address] Contact: [to fill in — privacy email]


2. The principle that governs the rest

We collect the minimum that makes the app work, and there are things we decided not to collect even where it would have been convenient. Where that applies, it is stated below in bold — not as a marketing promise, but because the data simply does not exist on our side.


3. What we collect

3.1 Account

Your session starts anonymous: the first time you open the app we create a random identifier. We do not ask for a name, a phone number or a password.

If you want to keep access when you change phones, you can link an email address. It serves one purpose: sending you a sign-in code and recognising your account afterwards. We do not use it for marketing.

3.2 Menu photos

The photo is sent to our server, read, and kept for up to 90 days in a private bucket. After that it is deleted automatically.

What we keep it for. One thing only: working out why a reading came back wrong. The records we hold tell us that a menu was read badly — they do not show whether the photo was blurred, the menu handwritten, or the price column cut off. Without the image, fixing the reading is guesswork. We do not use these photos for advertising, we do not sell them and we do not share them.

Location is stripped before the photo leaves your phone. The app recompresses the image on the device, and that process discards the EXIF metadata, GPS coordinates included. We never receive where the photo was taken.

Who can reach it. The bucket is private and cannot be read from the app, neither with your account nor with anyone else's. Access is restricted to our administration, for investigating reading quality.

You can turn it off. Settings → Data and privacy has a switch that stops further photos from being sent. It does not delete the ones already sent — to remove all of them at once, use Delete account on the same screen, which removes the photos along with everything else.

Legal basis (GDPR Art. 6(1)(f)): legitimate interest in maintaining and improving the quality of a service whose central function is reading menus. [to be validated legally] — the balancing of interests needs to be documented, and one point deserves attention: a photo of a menu taken inside a restaurant may capture other people in the background, who have no relationship with us.

What also stays with us is the resulting text: dish names, prices, translations.

3.3 Voice translator

The audio is not stored, in either direction. It is sent for transcription and discarded.

The text is kept for up to 90 days: what was heard and the translation that came out, in both directions — the waiter's speech and yours. After that it is deleted automatically.

What we keep it for. To check whether a translation is correct, and nothing else. The records we hold say that a translation happened, never whether it was right — and that error is invisible any other way. In a real test, "no prawns, I have an allergy" was heard as "yes prawns" and faithfully translated into Japanese, with the confidence indicator reporting high confidence. Without the pair of texts, an error like that leaves no trace at all.

We do not store who spoke. The table has no user identifier and is not linked to your account, your history or a restaurant. There is no way to tell whose line is whose — not even for us.

⚠️ The consequence of that, said plainly: because the rows are not attributable to anyone, we cannot delete them on request. The 90-day limit is the only deletion mechanism. If you would rather not create that record, do not use the voice translator — the rest of the app works without it.

About other people's speech. The waiter is not a user of this app and has not agreed to anything. That is why what we keep is text only: no voice recording, no identification of who spoke, and no link to you or to the restaurant.

Legal basis (GDPR Art. 6(1)(f)): legitimate interest in verifying the quality of a translation used to order food — including conversations about allergies, where an error has physical consequences. [to be validated legally]

3.4 Usage records

For each menu reading we store: how many pages, which model answered, how long it took, whether the quota accepted or refused it, and the date. This supports the fair-use cap and failure diagnosis. We do not store the content of the photo or your location alongside it.

3.5 Saved menus

If you save a menu, we store the dishes and a text label for the place ("Izakaya in Ginza, Tokyo").

3.6 Purchases

When you subscribe, our payment processor tells us which plan is active and until when. We neither receive nor store card details — those go straight to Apple or Google.


4. What we do NOT collect, and it is an architectural decision

4.1 Allergies and dietary restrictions

The app stores no health data. There is no screen for declaring an allergy and no table for it — not on the server, not on the device.

This changed deliberately: an earlier version kept a dietary profile on the device and highlighted dishes against it. It was removed. The app now shows the possible allergens of each dish, the same for everyone, and offers ready-made questions in Japanese so you can confirm with the restaurant. You decide; the kitchen is who knows what went into the pan.

Legal consequence: we do not process special category data under GDPR Art. 9.

4.2 GPS coordinates

Latitude and longitude never leave the device. When you allow location, the operating system itself turns the coordinate into a place name, on the phone, and only that text reaches us.

Permission is asked at the moment it is useful — when the menu's name field is blank — never at launch.

4.3 Tracking and advertising

There is no advertising SDK, no cross-app tracking, no advertising identifier. We do not sell or share data for advertising.


5. Why we process each kind of data

Data Purpose Legal basis (GDPR)
Anonymous identifier Make the app work without sign-up Performance of a contract
Email (optional) Recover access on another device Performance of a contract
Menu text Deliver the translation and the order Performance of a contract
Reading records Apply the fair-use cap; diagnose failures Legitimate interest
Subscription state Unlock what was purchased Performance of a contract

[to be validated legally] — the choice between legitimate interest and performance of a contract for the reading records deserves an opinion.


6. Who we share with

Third party What it receives Where
Supabase Database and authentication project region
Ollama Cloud The menu photo, for reading outside the EU [to validate]
Groq The spoken audio, for transcription outside the EU [to validate]
Google Places The text you type when naming a restaurant
RevenueCat Account identifier and purchase state
frankfurter.dev Nothing of yours — only the exchange-rate query

[to be validated legally] — the international transfer (GDPR Chapter V) needs a declared mechanism: standard contractual clauses or an adequacy decision, depending on the provider.


7. How long we keep things


8. Your rights

Inside the app, in Settings → Delete account, you can erase your account and everything attached to it. Deletion is immediate and cascading — saved menus, favourites, reading records and recorded subscriptions go with it.

Under the GDPR you also have the right of access, rectification, portability, objection, and to complain to the data protection authority in your country. Under Brazil's LGPD, the equivalent rights in Art. 18. Write to [privacy email].


9. Children

The app is not intended for children under 13 and we do not knowingly collect their data.


10. Changes

We will publish the new version here with an updated date. A change that materially affects processing will be announced inside the app before it takes effect.


11. One caveat that is not legal, and matters more

The app shows the possibility that a dish contains an ingredient. It does not verify, does not certify and cannot guarantee. The information comes from a curated library and from the automatic reading of a photograph, and neither of them knows the recipe of this restaurant, on this day.

If you have a food allergy, always confirm with the restaurant. The ready-made questions in Japanese on the phrases screen exist for exactly that.