Privacy Policy
for ingreedX Studio
Last updated: July 2026
Product revision: 3.1
This Privacy Policy describes how Bebop Flo Private Limited (“Company”, “we”, “us”, or “our”) collects, uses, stores, and protects information when you use ingreedX Studio, including the coach portal (dashboard), WhatsApp-based client flows, meal-edit pages, and related backend services (together, the “Service”).
The Service involves two kinds of users:
- Coaches, who sign in to the coach portal to manage clients, meals, feedback, notes, meal plans, and calendar items; and
- Clients, who interact primarily via WhatsApp (text, photo, or voice) and may also use a tokenized meal-edit web page. Clients do not log in to the coach portal.
This document is aligned with the product as of revision 3.1. It is provided for transparency; it is not a substitute for legal advice.
1. Who We Are
- Service Name: ingreedX Studio
- Company Name: Bebop Flo Private Limited
- Contact Email: [email protected]
- Jurisdiction: India
2. Eligibility
The Service is intended for professional coaches and their adult clients 18 years of age and above.
By using the Service as a Coach, you confirm that you are at least 18 years old and that any Client whose personal data you enter or invite is at least 18 years old (or that you have another lawful basis to process that Client’s data under applicable law).
3. Information We Collect
a) Information You Provide
From Coaches
- Email address
- Authentication identity from Supabase Auth, including:
- Email magic-link (one-time password / link) sign-in
- Google OAuth profile information when you choose Google Sign-In
- Session cookies used to maintain login state
- Coach profile and account metadata (for example timezone, trial or plan-related fields used to operate the Service)
- Content you author in the portal, including:
- Coach feedback (
coach_feedback) - Clinical / coaching notes (
clinical_notes) - Meal plan templates and client meal plans
- Calendar events and tasks
- Coach feedback (
From Clients (provided by their Coach and/or via WhatsApp and related flows)
- Name
- Phone number, stored as country code and national number (used as the WhatsApp identifier; also stored in a combined digit form)
- Stated goals (legacy free-text goal and/or goals list)
- Diet type and food preferences
- Health conditions (
health_conditions) - Allergies and food avoidances
- Medications and free-text profile notes
- Demographics and anthropometrics where entered: date of birth, sex, height, weight, activity level
- Body measurements and InBody-related metrics (structured fields where used)
- Invite-related status and hashed invite tokens (when a Coach invites a Client on WhatsApp)
- Notification pause state (
notifications_paused_until) where set - All inbound WhatsApp messages and media as processed by the Service (text, meal photos, voice notes)
- Meal logs derived from messages or edits, including nutritional fields and structured analysis
- Assistant replies and decision / food-log metadata associated with messages
Health-related data—including health conditions, allergies, medications, anthropometrics, InBody metrics, clinical notes, and health-related inferences that may appear in stored AI outputs—may qualify as Sensitive Personal Data under applicable Indian law (and similar categories such as special-category data under GDPR / UK GDPR) and is handled with enhanced care as described below.
b) Automatically Collected Information
- Device and browser information (as typically available to our hosting and application layers)
- App and API usage data
- Log data (which may include technical details of requests and, in some cases, AI response summaries used for debugging)
- IP address
- Engagement timestamps (for example last message activity)
- Transient conversation state used to operate the WhatsApp flow (short-lived in-memory session state, and limited branch state stored on the client record)
c) WhatsApp Message Processing
When a Client sends or receives WhatsApp messages through the Service:
- Messages are routed via the Meta / WhatsApp Cloud API. Message content, media, and phone numbers pass through Meta-related infrastructure.
- Inbound text, images, and voice notes are processed by our backend and stored with associated metadata as needed to provide the Service.
- Decision or food-log output produced by our engine may be stored as structured data alongside messages or meal records.
- A Coach-initiated invite may use an approved WhatsApp template message.
- If a WhatsApp number contacts the Service and cannot be matched to an existing active client in the expected way, the system may create or update a client record so the conversation can proceed (backend service operations).
Messages are not publicly visible and are not sold.
d) Meal-edit web page
Clients may receive a link to a public meal-edit page (path form /m/{meal_id} with a secret token). That token allows editing the related meal without a coach portal login. Tokens are stored as hashes, expire after a limited period (currently 14 days), and are intended only for the Client who received the link.
e) AI & Analytics Processing
We use artificial intelligence systems via OpenAI to:
- Analyze meal descriptions and related inputs (OpenAI Responses API)
- Transcribe voice notes (Whisper / transcription models)
- Interpret meal photos (vision-capable models)
- Generate structured meal guidance and logs
- Support reliability and performance of these features
Meal descriptions, photos, voice audio (for transcription), and selected user profile context—such as goals, health conditions, diet type, allergies, food avoidances, and demographic/activity fields used for analysis—may be sent to OpenAI. Under OpenAI’s API terms applicable to business API usage, OpenAI states that it does not use API inputs and outputs to train OpenAI’s models; you should review OpenAI’s current terms and data processing documentation for the definitive position.
Structured meal payloads may be stored on meal records (including a raw JSON field). Application logs may contain AI response material used for operations and debugging and are treated as confidential operational data.
We do not operate a separate third-party product-analytics SDK (for example PostHog or similar) in the Service as of this revision.
g) Nutrition reference data (OpenNutrition)
Meal nutrition estimates and food lookups may use reference data from OpenNutrition Foods, a public nutritional database made available by OpenNutrition under the Open Database License. OpenNutrition: https://www.opennutrition.app/.
That dataset is used as a local or application-side nutrition reference to support analysis in the Service. As of this revision, using OpenNutrition Foods in this way does not involve sending your personal data to OpenNutrition as a processing destination in the same manner as providers such as OpenAI or Meta.
Some processing is performed by third-party service providers under contractual data protection obligations. These providers:
- Cannot use your data for their own marketing (except as their own privacy terms allow for platform operation)
- Cannot sell your data as part of our instructions
- May only process data on our instructions to the extent required to provide their service
f) Cookies & Local Storage
We use:
- Session cookies and related mechanisms to maintain Coach login state (Supabase Auth, including PKCE-related cookies where applicable)
- Local storage for coach portal unit preferences (for example height/weight display units) where used
These are essential or convenience features for Coaches. We do not use CSRF tokens as a separate named mechanism in the current product.
4. How We Use Your Information
We use your data to:
- Provide and improve the coaching portal and backend
- Deliver WhatsApp-based meal logging and guidance to Clients
- Process text, photo, and voice meal inputs with AI
- Display messages, meals, feedback, notes, meal plans, and calendar items to Coaches
- Send Coach-initiated invites and Service-related WhatsApp notifications or nudges
- Maintain Coach accounts and authentication (including magic-link emails via Supabase Auth)
- Operate trial / account access controls for Coaches
- Communicate important Service updates
- Ensure security and prevent misuse
- Respond to privacy and support requests
Outputs may be reviewed or supplemented by Coaches (for example feedback and clinical notes). The Service is coaching support tooling; it is not solely automated decision-making without human involvement for coaching workflows, and it is not a substitute for medical care or a medical device.
5. Legal Basis for Processing (India – DPDP Act)
We process personal data based on:
- Your consent (including acceptance of this Policy and, for Coaches, sign-up / continued use of the portal)
- Legitimate use necessary to provide the Service requested
- Where required, appropriate consent or other lawful basis for sensitive health-related data—including Client health conditions, allergies, medications, anthropometrics, and related AI outputs—obtained through the Coach’s lawful onboarding of each Client and/or the Client’s voluntary use of WhatsApp with the Service
You may withdraw consent at any time by asking us to delete or restrict processing (where available), asking your Coach to remove your Client profile (for Clients), or contacting us at [email protected].
6. Data Storage & Location
Your data may be stored on secure cloud infrastructure including:
- Supabase — database and authentication
- Cloudflare — frontend hosting and related edge services
- Bebop Flo–operated backend hosting — API and background jobs (for example notification cron runners)
- OpenAI — AI processing (transient processing; outputs may be stored by us as described above)
- Meta — WhatsApp Cloud API channel
Data may be processed in India and other jurisdictions where our providers operate.
We implement reasonable technical and organizational safeguards including:
- Encrypted storage (including platform-level encryption where provided by our providers)
- Row Level Security (RLS) on our database for coach-scoped portal access
- Access controls
- Secure cloud infrastructure
- TLS for data in transit
7. Data Retention
We retain:
- Coach account information while your account is active and as needed to provide the Service
- Client profiles, messages, meals, feedback, notes, meal plans, calendar items, and related records while the Coach–client relationship is active and as needed to operate the Service
Deletion in the product is often implemented as logical deletion first (for example deleted_at on client, meal, meal-plan, or calendar records; Client removal unlinks the Coach and tombstones the profile so a number can be reclaimed later). Logical deletion hides data from normal Coach workflows but does not by itself guarantee immediate irreversible erasure of all underlying personal data.
As of this revision, automated hard purge or anonymization after a fixed number of days is not yet implemented. After logical deletion, or when you request erasure, we aim to delete, anonymize, or restrict remaining personal data through our operational processes within a reasonable period, unless a longer retention period is required by law, security, fraud prevention, or dispute resolution.
Meal-edit tokens expire after a limited period (currently 14 days). Transient WhatsApp conversation session state is short-lived.
8. Account Deletion & User Rights
You have the right to:
- Access your personal data
- Correct inaccuracies
- Request erasure
- Request restriction or objection to certain processing
- Request data portability, where applicable
- Withdraw consent, where processing is consent-based
Coaches may request account deletion by contacting [email protected]. Self-serve coach account deletion is not available in the portal as of this revision (you can sign out at any time).
Clients should contact their Coach to exercise rights in the first instance, because Clients do not have a direct portal login. Clients may also contact us at [email protected] for privacy requests. Removing a Client in the portal typically performs a logical unlink/tombstone; for complete erasure beyond that, contact us.
We will respond to requests in accordance with applicable law.
9. Data Sharing
We do not sell your personal data.
We may share data with sub-processors only to the extent necessary to operate the Service:
| Provider | Role |
|---|---|
| Supabase | Database, authentication, Row Level Security |
| OpenAI | AI analysis, transcription, and vision processing |
| Meta / WhatsApp | WhatsApp Cloud API channel and related messaging features |
| Optional Google Sign-In for Coaches | |
| Cloudflare | Frontend hosting and related services |
| Backend host / job runners | API hosting and scheduled notification jobs operated for Bebop Flo |
Separately from the sub-processors above, meal nutrition estimates may rely on reference data from OpenNutrition Foods (https://www.opennutrition.app/), as described in Section 3(g).
International transfers may occur; where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by our providers.
10. Communications
We may send:
- Service-related emails to Coaches (including authentication magic links via Supabase Auth)
- Important product or security updates
- WhatsApp messages to Clients as part of the coaching flow initiated by their Coach (including invites, meal guidance, feedback delivery, and operational nudges such as inactivity or missed-meal reminders where enabled)
You may opt out of non-essential email communications where applicable.
Clients who no longer wish to interact with the Service may stop messaging, ask their Coach to remove or pause their profile, or contact us. Coaches (or operators) may pause outbound notifications for a Client using notification pause controls where available. A dedicated automated WhatsApp “STOP” / unsubscribe keyword handler is not yet implemented and is intended to be added as the product matures. Meta’s own WhatsApp user controls may also apply.
11. Security
We use industry-standard security measures, including:
- Row Level Security (RLS) so that, in normal portal operation, Coaches can access only their own clients, messages, meals, feedback, notes, meal plans, and calendar data
- Verification of Coach session tokens against Supabase Auth for portal API access
- TLS for data in transit
- Restricted handling of secrets (API keys for OpenAI, Supabase, WhatsApp, and job tokens) by the operator
- Webhook signature verification for Meta where configured
- Hashed tokens for Client invites and meal-edit links
Certain backend operations (such as WhatsApp webhook processing and background jobs) use a Supabase service role key that bypasses RLS so the system can write on behalf of Clients who have no portal session. Operational staff with access to backend environments or logs could, in principle, access data processed through these paths—access is limited to what is needed to run the Service.
Health and wellness fields are stored in the database as structured fields; we do not apply additional application-layer encryption beyond what Supabase and the database platform provide by default.
However, no system is completely secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated via the Service or email where appropriate. The “Last updated” date at the top of this Policy will be revised when changes are published.
13. Contact Us
If you have questions or concerns about this Privacy Policy or your personal data:
Email: [email protected]
Bebop Flo Private Limited
India