Let's Fit.
PRIVACY & DATA PROTECTION

Privacy Policy

At Let's Fit, your privacy is fundamental. We design our AI vision nutrition tools with zero-storage principles and minimal data footprint.

Effective Date: September 2026 • Scope: letsfit.online • Storage Model: Zero-Retention Ephemeral
Table of Contents
  1. 1. Introduction & Purpose
  2. 2. Information We Process
  3. 3. AI & Third-Party Processors
  4. 4. Cookies & Local Storage
  5. 5. Data Retention & Security Protocols
  6. 6. Your Rights, Indian Regulatory Compliance & Grievance Redressal

1. Introduction & Purpose

Welcome to Let's Fit (accessible at letsfit.online). We operate an educational nutrition database, recipe index, and computer vision meal analysis utility designed to make whole food nutritional intelligence transparent, accessible, and scientifically grounded.

This Privacy Policy sets forth our strict data processing practices, clarifying what minimal data is required to deliver AI meal scanning, how external inference engines are integrated, and why your meal photographs are never permanently stored, indexed, or commodified.

Our Core Privacy Promise: Zero persistent image storage, no biometric data harvesting, and no sale of personal data.

2. Information We Process

Let's Fit operates on a principle of data minimization. When you interact with our platform, we only process technical data strictly required for immediate feature execution:

A. User-Uploaded Meal Images

When you utilize the AI Meal Scanner, you upload an image of a food plate. Before transmission, images are compressed and downscaled client-side within an offscreen browser canvas. The resulting image payload is transmitted to our serverless endpoint (/api/scan) strictly for real-time computer vision segmentation and nutritional inference.

B. Ephemeral IP Addresses (Rate Limiting)

To prevent automated abuse, denial of service attacks, and API quota depletion, our serverless layer extracts the client's IP address (from standard headers such as x-forwarded-for). This IP address is used exclusively as a cache key in Upstash Redis to enforce a 5-scans-per-6-hour fair usage window.

C. Anonymous Technical Telemetry

Like standard web applications, our web hosting provider (Vercel) automatically logs transient technical metrics, including browser user agent, operating system type, HTTP status codes, and referrers, for performance and uptime monitoring.

3. AI & Third-Party Processors

To deliver real-time nutritional intelligence and reliable global edge hosting, Let's Fit coordinates with select, industry-standard infrastructure providers:

Service Provider Role & Purpose Data Handled Retention Period
Google Gemini API
(Google LLC)
Computer Vision & Macro Estimation via Gemini 3.6 Flash Transient Base64 plate image & vision prompt Processed in memory; zero retention per enterprise API terms
Vercel Inc. Edge Hosting & Serverless Function Execution (/api/scan) HTTP request headers, client IP, payload Ephemeral runtime logs (auto-purged)
Upstash Inc. Distributed Redis cache for rate limiting (5 scans / 6 hrs) Hashed/prefixed client IP key & integer scan counter 6 hours (enforced via automatic TTL)

None of our third-party infrastructure partners are permitted to sell, broker, or market any data processed through Let's Fit.

4. Cookies & Local Storage

Let's Fit does not deploy intrusive advertising cookies, third-party behavioral trackers, or cross-site tracking pixels.

5. Data Retention & Security Protocols

We implement robust modern security standards to safeguard the integrity of our platform and user interactions:

6. Your Rights, Indian Regulatory Compliance & Grievance Redressal

Under the Digital Personal Data Protection Act (DPDPA) of India, alongside applicable international standards (such as GDPR and CCPA), you hold statutory rights concerning access, correction, and erasure of personal data. Because Let's Fit operates on a strictly ephemeral, zero-retention architecture without registered user accounts, personal identity tracking, or permanent image storage, we do not maintain persistent personal records or user profiles that can be retrieved or altered.

Grievance Redressal Officer (IT Rules, 2021): In compliance with the Information Technology Act, 2000 and the Intermediary Guidelines and Digital Media Ethics Code Rules framed thereunder, any data concerns, inquiries, or formal grievances regarding our technical practices should be directed to our designated Grievance Officer:

Designated Grievance & Privacy Officer
Email: support@letsfit.online
Response Timeline: Formal inquiries receive a response within 48 to 72 business hours.
Contact Grievance Officer