Privacy Policy
At Let's Fit, your privacy is fundamental. We design our AI vision nutrition tools with zero-storage principles and minimal data footprint.
1. Introduction & Purpose
Welcome to Let's Fit (accessible at letsfit.online). We operate an educational nutrition database, recipe index, and computer vision meal analysis utility designed to make whole food nutritional intelligence transparent, accessible, and scientifically grounded.
This Privacy Policy sets forth our strict data processing practices, clarifying what minimal data is required to deliver AI meal scanning, how external inference engines are integrated, and why your meal photographs are never permanently stored, indexed, or commodified.
2. Information We Process
Let's Fit operates on a principle of data minimization. When you interact with our platform, we only process technical data strictly required for immediate feature execution:
A. User-Uploaded Meal Images
When you utilize the AI Meal Scanner, you upload an image of a food plate. Before transmission, images are compressed and downscaled client-side within an offscreen browser canvas. The resulting image payload is transmitted to our serverless endpoint (/api/scan) strictly for real-time computer vision segmentation and nutritional inference.
- Transient Processing: Photos are held in volatile serverless memory only for the duration of the API call (typically under 2 seconds).
- Zero Storage: Photos are never saved to disk, object storage, databases, or training datasets.
- No Facial or Biometric Harvesting: We only process food plates and beverages. Non-food images are programmatically rejected.
B. Ephemeral IP Addresses (Rate Limiting)
To prevent automated abuse, denial of service attacks, and API quota depletion, our serverless layer extracts the client's IP address (from standard headers such as x-forwarded-for). This IP address is used exclusively as a cache key in Upstash Redis to enforce a 5-scans-per-6-hour fair usage window.
- IP addresses in Redis automatically expire and delete upon expiration of the 6-hour TTL (Time-To-Live).
- IP addresses are never linked to personal profiles, names, email addresses, or physical locations.
C. Anonymous Technical Telemetry
Like standard web applications, our web hosting provider (Vercel) automatically logs transient technical metrics, including browser user agent, operating system type, HTTP status codes, and referrers, for performance and uptime monitoring.
3. AI & Third-Party Processors
To deliver real-time nutritional intelligence and reliable global edge hosting, Let's Fit coordinates with select, industry-standard infrastructure providers:
| Service Provider | Role & Purpose | Data Handled | Retention Period |
|---|---|---|---|
| Google Gemini API (Google LLC) |
Computer Vision & Macro Estimation via Gemini 3.6 Flash | Transient Base64 plate image & vision prompt | Processed in memory; zero retention per enterprise API terms |
| Vercel Inc. | Edge Hosting & Serverless Function Execution (/api/scan) |
HTTP request headers, client IP, payload | Ephemeral runtime logs (auto-purged) |
| Upstash Inc. | Distributed Redis cache for rate limiting (5 scans / 6 hrs) | Hashed/prefixed client IP key & integer scan counter | 6 hours (enforced via automatic TTL) |
None of our third-party infrastructure partners are permitted to sell, broker, or market any data processed through Let's Fit.
4. Cookies & Local Storage
Let's Fit does not deploy intrusive advertising cookies, third-party behavioral trackers, or cross-site tracking pixels.
- Local Storage (Browser): We may use your browser's
localStorageto store client-side UI preferences (such as selected recipe filters) and developer diagnostic bypass tokens (e.g.,admin_test_secret). This data stays entirely on your local device. - No Cross-Site Ad Tracking: We do not participate in advertising networks or retargeting campaigns.
5. Data Retention & Security Protocols
We implement robust modern security standards to safeguard the integrity of our platform and user interactions:
- End-to-End TLS Encryption: All communications between your browser and
letsfit.onlineare strictly encrypted in transit using HTTPS and TLS 1.3. - Client-Side Downscaling: Photos are downscaled to 1024px maximum resolution before leaving your device, preventing transmission of unnecessarily large biometric or background detail.
- Immediate Memory Eviction: Image buffers are garbage-collected immediately upon response generation. No photo archives or historical libraries exist on our servers.
6. Your Rights, Indian Regulatory Compliance & Grievance Redressal
Under the Digital Personal Data Protection Act (DPDPA) of India, alongside applicable international standards (such as GDPR and CCPA), you hold statutory rights concerning access, correction, and erasure of personal data. Because Let's Fit operates on a strictly ephemeral, zero-retention architecture without registered user accounts, personal identity tracking, or permanent image storage, we do not maintain persistent personal records or user profiles that can be retrieved or altered.
Grievance Redressal Officer (IT Rules, 2021): In compliance with the Information Technology Act, 2000 and the Intermediary Guidelines and Digital Media Ethics Code Rules framed thereunder, any data concerns, inquiries, or formal grievances regarding our technical practices should be directed to our designated Grievance Officer: