Privacy Policy
This Privacy Policy explains how your personal data is collected, used, and protected when you use Señor Bistec, an AI nutrition coaching bot on Telegram. We process your data in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Table of Contents
1. Data controller
| Controller | Ilia Lapin (autónomo / self-employed) |
|---|---|
| NIF | Z1780472R |
| Address | Plaza Equipo Cronica 5, PTA 30A, 46023 Valencia, Spain |
| mrolcheg@gmail.com | |
| Phone | +34 641 963 970 |
2. Data we collect
We collect the following categories of personal data when you interact with Señor Bistec:
2.1 Account and profile data
- Telegram ID and display name
- Language preference
- Timezone
- City
2.2 Body and health data
- Height, weight, age, sex
- Health notes and food preferences
- Body measurements
- Water intake
- Nutritional goal (e.g. weight loss, maintenance, muscle gain)
- Activity level
In addition to the data listed above, we may request the following additional health data to better personalise the service. This data is only collected if you voluntarily provide it:
- Additional body measurements (waist, hip, chest, arms circumference)
- Food allergies and intolerances
- Medical conditions relevant to nutrition (diabetes, coeliac disease, irritable bowel syndrome, etc.)
- Medications affecting metabolism or appetite
- Exercise and training data (type, duration, intensity)
- Pregnancy or breastfeeding status
- Sleep patterns
- Menstrual cycle data
- Dietary and food principles (vegan, vegetarian, halal, kosher, intermittent fasting, etc.) — this data may reveal religious or philosophical beliefs (Art. 9(1) GDPR) and receives the same protection as health data
2.3 Meal and nutrition data
- Food photos
- Text descriptions of meals
- Voice messages about meals
- AI-generated calorie and macronutrient estimates
2.4 Conversation and usage data
- Conversation history with the bot
- Subscription status and payment information
- Referral code
- Achievements and streaks
- Reminder settings
- Feature requests
- LLM usage data (token counts)
3. Purposes and legal bases
The following table outlines each processing purpose, the data involved, and the legal basis under GDPR:
| Purpose | Data categories | Legal basis (GDPR) |
|---|---|---|
| Provide the nutrition coaching service (analyse meals, calculate calories and macros, track progress). Text messages, meal photos, and voice messages may be processed by Anthropic (Claude) and/or OpenAI (GPT, Whisper) | Account data, meal photos/text/voice, body data, conversation history | Art. 6(1)(b) — performance of contract |
| Process health-related data to personalise nutritional advice | Weight, height, age, sex, health notes, food preferences, body measurements, water intake, meal photos, AI nutrition insights | Art. 9(2)(a) — explicit consent |
| Manage subscriptions and billing | Telegram ID, subscription status, referral code | Art. 6(1)(b) — performance of contract |
| Send reminders and notifications you configured | Telegram ID, reminder settings, timezone | Art. 6(1)(b) — performance of contract |
| Gamification (achievements, streaks) | Achievements, streaks, usage patterns | Art. 6(1)(b) — performance of contract |
| Improve the service and fix bugs | Feature requests, LLM usage data (tokens), anonymised conversation data | Art. 6(1)(f) — legitimate interest |
| Comply with legal obligations (tax, consumer protection) | Subscription and billing records | Art. 6(1)(c) — legal obligation |
4. Special category data (health data)
Important: Some of the data you provide to Señor Bistec qualifies as special category data under Article 9 GDPR, specifically data concerning health. This includes your weight, height, age, sex, health notes, food preferences, body measurements, water intake, meal photos (which may reveal dietary habits and health conditions), AI-generated nutritional insights, and any additional health data you voluntarily provide (such as food allergies, medical conditions, medications, exercise data, pregnancy or breastfeeding status, sleep patterns, and menstrual cycle data).
We process this health-related data solely to provide you with personalised nutrition coaching. We rely on your explicit consent (Art. 9(2)(a) GDPR) as the legal basis for this processing. You provide this consent when you start using the bot and submit your body data and health information.
You may withdraw your consent at any time by:
- Sending the
/deletecommand in the bot to erase your health data. - Contacting us at mrolcheg@gmail.com to request deletion.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Recipients and third-party processors
Your personal data may be shared with the following third-party processors, who act on our behalf under data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude) | Meal analysis, nutritional estimates, and conversational responses | United States |
| OpenAI (GPT, Whisper) | Text and image analysis, voice message transcription | United States |
| Google (Gemini) | AI-powered text and image analysis | United States / EU |
| Mistral AI | AI-powered text analysis | France (EU) |
| xAI (Grok) | AI-powered text analysis | United States |
| Telegram | Messaging platform through which you interact with the bot | Various (see Telegram Privacy Policy) |
| Hosting VPS provider | Server infrastructure and database storage | Europe |
We do not use all listed AI providers simultaneously. At any given time, your data is sent only to the providers actively used by our service. We reserve the right to change, add, or discontinue AI providers based on quality, cost, or availability, provided that the data protection safeguards described in this policy are maintained.
We do not sell your personal data to third parties. Data is shared with processors only to the extent necessary to provide the service.
6. International data transfers
When your data is processed by AI providers located outside the European Economic Area (EEA), it constitutes an international transfer. These transfers are protected by:
- EU-US Data Privacy Framework (DPF) — Applicable to certified US providers (Anthropic, OpenAI, Google, xAI). The DPF provides an adequacy basis for transfers under Art. 45 GDPR.
- Standard Contractual Clauses (SCCs) — As a supplementary or alternative safeguard, we rely on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR).
- EU-based providers — Mistral AI operates from France and does not require an additional international transfer mechanism.
You may request a copy of the relevant safeguards by contacting us at the email address above.
7. Data retention
We retain your personal data for as long as necessary to fulfil the purposes described in this policy:
| Data category | Retention period |
|---|---|
| Account and profile data | Duration of your active subscription + 2 years after account deletion |
| Health and body data | Until you withdraw consent or delete your account |
| Meal photos, text, and voice messages | Duration of your active subscription; deleted upon account deletion |
| Conversation history | Duration of your active subscription; deleted upon account deletion |
| Subscription and billing records | Duration of subscription + 5 years (Spanish tax law obligations) |
| LLM usage data (tokens) | Aggregated and anonymised; retained indefinitely for analytics |
8. Your rights
Under the GDPR (Articles 15–22), you have the following rights regarding your personal data:
- Right of access (Art. 15) — You may request confirmation of whether we process your personal data and obtain a copy of it.
- Right to rectification (Art. 16) — You may request the correction of inaccurate personal data or the completion of incomplete data.
- Right to erasure (Art. 17) — You may request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
- Right to restriction of processing (Art. 18) — You may request that we limit the processing of your data in certain circumstances (e.g. while we verify the accuracy of your data).
- Right to data portability (Art. 20) — You may request to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to object (Art. 21) — You may object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)) — Where processing is based on consent (including health data), you may withdraw your consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at mrolcheg@gmail.com. We will respond within one month, as required by Article 12(3) GDPR.
Right to lodge a complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Spain, the competent authority is the Agencia Española de Protección de Datos (AEPD): www.aepd.es. If you reside in another EU/EEA member state, you may also contact your local data protection authority.
9. Automated decision-making and profiling
Señor Bistec uses artificial intelligence (AI) to analyse your meal photos, text, and voice messages and produce estimated calorie and macronutrient values. This constitutes automated processing of your data within the meaning of Article 22 GDPR.
However, these AI-generated estimates:
- Are approximate and provided for informational purposes only.
- Do not produce legal effects or similarly significantly affect you.
- Do not replace professional dietary or medical advice.
The AI processes your meal data through the Anthropic Claude API and/or the OpenAI GPT API to generate nutritional estimates and coaching responses. Voice messages are transcribed via the OpenAI Whisper API before analysis. Text messages and meal photos may also be processed by OpenAI in addition to Anthropic. No fully automated decisions with legal or similarly significant effects are made about you.
You always have the right to request human review of any AI-generated output by contacting us at mrolcheg@gmail.com.
10. Children's data
Señor Bistec is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe that a child under 16 has provided us with personal data, please contact us so that we can delete it.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will notify you through the bot or via the email associated with your account. The “Effective from” date at the top of this page indicates when the latest version took effect.
12. Contact
For any questions or requests regarding this Privacy Policy or the processing of your personal data, please contact:
- Email: mrolcheg@gmail.com
- Phone: +34 641 963 970
- Address: Plaza Equipo Cronica 5, PTA 30A, 46023 Valencia, Spain