Home › Privacy Policy
Privacy Policy
Variety 20 Limited (“Variety 20”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (the “App”). We comply with the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020.
By using Variety 20, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use the App.
1. Information We Collect
1.1 Information you provide directly
Account information: email address (required), display name (optional), password (encrypted, never stored in plain text).
Dietary profile: dietary preferences (e.g. omnivore, vegetarian, vegan, pescatarian), dietary modifiers (dairy-free, gluten-free, keto, etc.), food allergies and restrictions (free text), goals and motivations.
Food logging data: the foods you log, variant notes, logging method (manual, photo, voice), and frequency of consumption.
Photos and voice recordings: photos you take for food identification (processed by AI and deleted within 24 hours), voice recordings (transcribed and deleted after processing).
Library and preferences: items you save, custom notes, app settings.
Communication data: support requests, feedback, and survey responses you choose to send us.
1.2 Information collected automatically
Usage data: features used, screens visited, time spent, actions taken, errors and crash reports.
Device information: device type and model, operating system and version, app version, anonymised device identifiers, time zone and language.
Analytics: aggregated usage patterns, feature engagement, onboarding completion, retention metrics.
1.3 Information from third-party services
If you sign in with Apple or Google, we receive your email address, your name (if you choose to share it), and a unique identifier from the sign-in provider. We never receive your password from these services.
2. How We Use Your Information
2.1 To provide and improve our services
- Deliver core App functionality (variety tracking, food logging, dashboard)
- Personalise your experience based on dietary preferences
- Generate AI-powered food identification from photos and voice
- Calculate your weekly variety progress
- Provide personalised insights and recommendations
- Improve App features based on usage patterns; fix bugs and technical issues
2.2 To communicate with you
- Send service-related notifications (streak reminders, weekly summaries)
- Respond to support requests and feedback
- Send important updates about the App or this policy
- Send marketing communications only if you opt in — unsubscribe anytime
2.3 To process transactions
- Handle subscription payments and billing
- Provide access to premium features
- Process refund requests where applicable
2.4 To ensure security and compliance
- Detect and prevent fraud, abuse, and security threats
- Enforce our Terms of Service
- Comply with legal obligations
3. AI-Powered Features and Data Processing
Variety 20 uses artificial intelligence to power several features. We believe in transparency about how AI processes your data.
3.1 Photo recognition
- Your photo is uploaded to our secure servers.
- Our AI analyses the image to identify foods.
- Results are returned to your device.
- Photos are not permanently stored on our servers — they are deleted after processing (typically within 24 hours).
- We may retain anonymised, aggregated data to improve AI accuracy.
3.2 Voice logging
- Your voice recording is uploaded to our secure servers.
- Audio is transcribed using speech-to-text technology.
- Our AI extracts food names from the transcription.
- Voice recordings are not permanently stored — they are deleted after processing (typically within 24 hours).
3.3 How we improve AI
We may use anonymised, aggregated data from AI interactions to improve food recognition, expand our food database, and train better models. Your individual photos, recordings, and data are never used to train AI models without explicit consent.
4. Data Storage and Security
4.1 Where your data is stored
On your device (local storage): food logs, variety counts, dietary preferences, settings, and cached data for offline use.
On our servers: account information, synced logs (if cloud sync enabled), Library items, and subscription records.
4.2 Security measures
- Encryption in transit: TLS 1.2 or higher
- Encryption at rest: AES-256 for sensitive data
- Secure authentication: passwords hashed with bcrypt; Apple and Google sign-in supported
- Access controls: employee access strictly limited and logged
- Regular audits: security assessments and penetration testing
- Secure infrastructure: SOC 2-compliant cloud service providers
4.3 Data retention
| Data type | Retention | Notes |
|---|---|---|
| Account information | Until account deletion | Required for service |
| Food logs | Until account deletion | Core app data |
| Photos for recognition | 24 hours maximum | Deleted after processing |
| Voice recordings | 24 hours maximum | Deleted after processing |
| Analytics data | 2 years | Aggregated and anonymised |
| Support communications | 3 years | Legal and service purposes |
5. Sharing Your Information
We do not sell your personal information. We share information only in the following limited circumstances.
5.1 Service providers
| Provider type | Purpose | Data shared |
|---|---|---|
| Cloud hosting | Data storage and processing | Encrypted user data |
| AI services | Photo and voice recognition | Photos, voice (temporarily) |
| Payment processing | Subscription billing | Handled by app store |
| Analytics | Usage insights | Anonymised usage data |
| Push notifications | Sending reminders | Device tokens |
All service providers are bound by data processing agreements and must handle your data securely.
5.2 Legal requirements
We may disclose your information if required by law — including to comply with a court order, subpoena, or legal process; to respond to lawful requests from government authorities; to protect our rights, privacy, safety, or property; or to enforce our Terms of Service.
5.3 Business transfers
If Variety 20 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
6. Your Rights and Choices
Under the New Zealand Privacy Act 2020, you have the following rights:
6.1 Right to access
You can view most of your data directly in the App (Settings › My Data) or request a full data export. We will respond within 20 working days.
6.2 Right to correction
You can edit your dietary preferences, logs, and Library items directly in the App, or contact us for corrections to other data.
6.3 Right to deletion
You can delete individual food logs, delete your entire account (Settings › Delete Account), or contact us for complete data deletion. Account deletion is permanent. We will delete your data within 30 days, except where retention is required by law.
6.4 Right to withdraw consent
You may opt out of marketing communications, disable notifications, or revoke camera/microphone permissions at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
6.5 Right to complain
If you are not satisfied with how we handle your data, you may lodge a complaint with the Office of the New Zealand Privacy Commissioner: privacy.org.nz · 0800 803 909.
6.6 Exercising your rights
Contact us at [email protected] or through Settings › Contact Support › Privacy Request. We may need to verify your identity before processing requests.
7. Children's Privacy
Variety 20 is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
8. International Data Transfers
Variety 20 is based in New Zealand. If you access the App from outside New Zealand, your information may be transferred to and processed in New Zealand and other countries where our service providers operate. We ensure that international transfers comply with the New Zealand Privacy Act 2020.
For users in the European Economic Area (EEA): we rely on adequacy decisions (New Zealand has EU adequacy status) and standard contractual clauses for international data transfers.
9. Third-Party Links and Services
The App may contain links to third-party websites or services. This Privacy Policy does not apply to third-party services. We encourage you to read the privacy policies of any third-party services you access.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date, notify you via email and/or in-app notification, and for significant changes may ask you to re-consent. Your continued use of the App after changes become effective constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
- Privacy enquiries: [email protected]
- General support: [email protected]
We aim to respond to all enquiries within 5 working days.
Summary
| Topic | Summary |
|---|---|
| What we collect | Account info, dietary preferences, food logs, photos/voice (temporarily), usage data |
| Why we collect it | To provide the service, personalise your experience, improve the App |
| AI processing | Photos and voice are processed by AI and deleted within 24 hours |
| Data selling | We never sell your personal information |
| Your control | You can access, correct, or delete your data anytime |
| Security | Industry-standard encryption and security measures |
| Children | Not intended for users under 16 |
| Contact | [email protected] |
Thank you for trusting Variety 20 with your data. We're committed to protecting your privacy while helping you eat a healthier variety of foods.