Ogurchik.aiOgurchik.ai

Privacy Policy

Version 0.4. Published 22 September 2026, effective 22 September 2026.

1. Scope and controller

This Policy explains how data is processed through ogur.app and the Ogurchik.ai web, iOS and Android applications (“Service”). The controller (“Controller”, “we”) is George Babayan, individual developer; address: 305 Adams Ave, State College, PA 16803-3606, United States; privacy email: [email protected].

The Service is intended for users aged 18 or older and provides nutrition and wellness tracking. It is not a medical device and does not provide diagnosis or treatment.

2. Data we process

Depending on the features used, we process:

  1. Account information: name, email, account identifier, sign-in method and session data. If you sign in with a password, Auth0 stores it as a hash; we never receive it.
  2. Profile and wellness information: sex selection, age, height, current and target weight, goals, activity level, food preferences, avoided foods, allergies and restrictions.
  3. Diary information: meals, calories, macronutrients, steps, workouts, sleep and progress.
  4. User content: chat messages, food photos and optional voice recordings voluntarily submitted for recognition.
  5. Technical data: IP address, device and browser type, OS/app version, language, diagnostic logs and security events.
  6. Product analytics: usage events, viewed pages and screens, referral source and a pseudonymous identifier (Section 5, PostHog). Health parameters, chat texts, names and emails are not sent to analytics.
  7. Support requests and consent records.

The user’s device stores: in the browser, a sign-in session cookie, the profile questionnaire (before sign-in, and after sign-in as a copy of the account profile), the account identifier and analytics markers with the PostHog identifier (cookies and local storage); in the mobile app, sign-in session data in the device’s secure storage and analytics markers.

We do not request precise location, contacts, medical records or payment credentials unless a clearly disclosed feature is introduced and this Policy is updated first.

3. Purposes and legal bases

We use data to create and secure accounts; provide approximate nutrition calculations; recognize submitted images, audio and text; maintain diaries and progress; personalize suggestions; suggest groceries; provide support; prevent abuse; comply with law; and improve the Service using aggregated statistics and product analytics.

Legal bases include performance of the Terms, separate informed consent, legal obligations and other bases permitted by applicable law. Sensitive wellness or health-related data is processed only after separate affirmative consent; the consent wording is published at https://ogur.app/consent/en. Marketing consent, if introduced, is optional and separate.

4. AI processing

Chat messages and the profile details the user has provided (sex, age, height, weight, goal, activity level, preferences, allergies and restrictions) are sent to a language model so that answers take them into account. The model is accessed through the OpenRouter gateway (United States), which forwards requests to the model provider OpenAI (United States); the model used is GPT-4o. Photos and audio are not yet sent to the Service’s servers: on the website, voice input is recognized by the browser using its vendor’s service, and we receive only the recognized text.

Outputs are probabilistic and may be inaccurate. The Service does not make decisions producing legal or similarly significant effects. The Controller does not use identifiable user data to train public general-purpose models.

5. Processors and recipients

We disclose only necessary data to providers acting on our instructions:

  • Railway (United States, US West region) — hosting of the website and server, PostgreSQL database, technical logs: account and profile data, technical data; chat messages also pass through the server but are not stored.
  • Cloudflare (United States) — DNS, protection and delivery of traffic to ogur.app and api.ogur.app, forwarding of email sent to @ogur.app addresses: requests to the website and API pass through Cloudflare together with their content and IP address, as do support emails.
  • Auth0 (Okta, United States; tenant in the US region) — sign-in and account management: email, name, account identifier, password hash for password sign-in, sign-in records (IP address, device, time).
  • Resend (United States) — delivery of the emails Auth0 sends (sign-in codes, address confirmation, password reset): email address and message text.
  • OpenRouter (United States) — language model gateway: chat messages and the profile details provided by the user.
  • OpenAI (United States) — language model, receives the same data through OpenRouter.
  • PostHog (EU region, Frankfurt, Germany) — product analytics for the website, mobile app and server: funnel and usage events (for example, a page opened, a questionnaire step completed, a message sent with only its length recorded, the outcome of an answer), page addresses and screen names, referral source and UTM tags, a pseudonymous identifier (the account identifier after sign-in), device type, browser, OS, language, app version and IP address, which PostHog uses to estimate approximate location (country, city). Health parameters, chat texts, names, emails and other contact details are not sent to PostHog.

If the user chooses to sign in with Google or Yandex, that service passes the name, email address and account identifier to Auth0 and processes data on its side under its own terms.

A separate recipient is VkusVill, a grocery retailer. Through its public MCP server, the chat finds groceries, recipes and stores and creates a cart link. VkusVill receives the search queries, filters (for example, allergens to exclude, a city or metro station when searching for a store) and cart contents that the model composes during the conversation, so they may reflect food preferences and restrictions the user mentioned in the chat. We do not send VkusVill the account identifier, name, email or the full profile. Product photos in chat answers are loaded by the browser directly from VkusVill servers, so VkusVill sees the user’s IP address and browser details. The user opens the cart link on the VkusVill website, where VkusVill’s own terms apply.

We do not sell personal data or use health/wellness data for advertising or unrelated profiling.

6. International transfers

Data is hosted in Railway (US West region, United States) and processed by the providers listed in Section 5, including in the United States and the European Union.

7. Retention

  • Account, profile and diary: while active; removal from the primary database occurs within 30 days after a verified request.
  • Diary/content: until deleted by the user or with the account.
  • Source photos/audio: deleted after recognition and no later than 24 hours unless the user separately opts to retain them.
  • Ordinary technical logs: 30 days; security logs: 12 months without message, photo or audio content.
  • Closed support requests: 12 months; consent evidence: 3 years after account deletion.
  • Backups: overwritten within 35 days after removal from the primary database.

Longer retention is limited to legal obligations, disputes and fraud prevention. Data is then deleted or irreversibly anonymized.

8. Security and rights

We use access controls, encryption in transit, secure password hashing, logging, backups and component updates. No method guarantees absolute security. Users may request information, access, a copy, correction, restriction or deletion, withdraw consent and object or complain where applicable by contacting [email protected]. We may verify identity to protect the account.

Account deletion is requested from the account email address at [email protected]; the procedure is described at https://ogur.app/delete-account/en. Uninstalling the app does not delete the account.

9. Changes and contact

The current date and version appear above. Material changes are announced in the Service and renewed consent is requested where required. The Controller’s details are listed in Section 1; privacy: [email protected]; support: [email protected]; security: [email protected].

Documents

  • Terms of Use
  • Consents
  • Account deletion
  • Support
Ogurchik.ai
  • Privacy Policy
  • Terms of Use
  • Consents
  • Account deletion
  • Support
© 2026 · Product concept · Not medical advice