Privacy Policy

This privacy policy applies to the SeEat service (hereby referred to as the "Service") — the iOS application published on the App Store and the companion website at seeat.ai — created by Causally Inc. (hereby referred to as "Service Provider") as a Commercial service. The Service is intended for use "AS IS".

Information Collection and Use

The Service collects information when you visit and use it. This information may include:

  • Your device's Internet Protocol address (e.g. IP address)
  • A randomly-generated device identifier (X-Device-ID) stored in the iOS Keychain or the website's local storage and sent with backend requests to enforce guest quota, prevent abuse, and link signed-out menu uploads to your account when you sign in
  • The pages of the Service that you visit, the time and date of your visit, and the time spent on those pages
  • The operating system and browser you use to access the Service
  • Menu images you upload, and the structured menu data the Service generates from them
  • Your profile image and food preferences, including dietary choices, allergens, custom ingredients to avoid, language, and display-currency settings
  • When you sign in: your Firebase account identifier (UID), email, phone number for SMS sign-in, Apple-issued opaque identifier, Google account identifier and email, and an identity-provider display name when available
  • Subscription identifiers, plan and status for Apple App Store or website subscriptions

The Service does not gather precise location information about your device.

The Service sends menu images and derived menu text to AI model providers to extract, translate, classify, recommend, and generate dish previews. Depending on service availability, those processors may include Google Gemini and configured fallback providers such as Alibaba Cloud/DashScope or fal.ai. Do not upload private or sensitive images that are not menus.

The Service Provider may use the information you provided to contact you with important information and required notices.

Third Party Access

The Service sends the identifiers, content, interaction events, and subscription information described above to processors only for the purposes stated here. Analytics data may be linked to your account: On the current iOS app and Web App, PostHog receives product events and the Firebase UID after sign-in, without email or display name. Older client versions may also send email and display name as profile properties. Firebase Analytics on iOS receives the Firebase UID and app interaction events, but not email or display name. SeEat does not use these events to track you across apps or websites owned by other companies.

The Web App also sends product events, Firebase UID, browser/session identifiers, sanitized page/referrer information and campaign labels to Firebase Analytics (GA4). Its analytics exclude names, email, phone numbers, verification codes, auth tokens, raw URL queries/fragments and user-entered text. Session replay, enhanced-conversion identifiers and ad personalization are disabled for the Web App.

Please note that the Service utilizes third-party providers that have their own Privacy Policy about handling data. Below are links to the Privacy Policy of the third-party providers used by the Service:

  • Apple (App Store and in-app purchase) processes iOS subscription payments and provides transaction status.
  • Google Firebase (authentication, analytics, hosting) authenticates users; Firebase Analytics receives iOS interaction events for product measurement and advertising-conversion attribution; Firebase Hosting serves website assets.
  • Google Sign-In is used only when you choose it.
  • Resend delivers email one-time codes.
  • Stripe processes website subscription payments; SeEat does not receive your payment card.
  • Superwall presents paywalls, manages purchase and entitlement state, and receives the account identifier and, for website checkout, email needed to link the subscription.
  • PostHog — On the current iOS app and Web App, PostHog receives product events and the Firebase UID after sign-in, without email or display name. Older client versions may also send email and display name as profile properties.
  • Google Gemini, Alibaba Cloud/DashScope, and fal.ai process menu images or derived menu text when selected by SeEat's AI routing.

The Service Provider may disclose User Provided and Automatically Collected Information:

  • as required by law, such as to comply with a subpoena, or similar legal process;
  • when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • with their trusted services providers who work on their behalf, do not have an independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this privacy statement.

Opt-Out Rights

Signing out disconnects future analytics events from your signed-in PostHog identity, but the Service may still process device-scoped events and quota records while you continue using it. To permanently delete your account, use Delete Account in Account settings. A successful deletion is irreversible. Active App Store subscriptions must be cancelled separately in Apple subscription settings.

Data Retention Policy

Account deletion removes the Firebase Auth identity, account profile, history, subscription and Stripe account records, and account avatar. Shared menu extraction artifacts — menus, menu_hashes, original menu images, and generated dish images — may remain available for other users to share and reuse. SeEat also retains minimal opaque device-quota, deletion-tombstone, App Store token, and subscription-ownership records needed to prevent abuse, duplicate benefits, financial inconsistency, or entitlement resurrection; these records cannot reconstruct the deleted Auth identity or account profile.

Children

The Service Provider does not use the Service to knowingly solicit data from or market to children under the age of 13.

The Service does not address anyone under the age of 13. The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age. In the case the Service Provider discovers that a child under 13 has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact the Service Provider (support@causally.xyz) so that they will be able to take the necessary actions.

Security

The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information the Service Provider processes and maintains.

Changes

This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to the Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

This privacy policy is effective as of 2026-07-28.

Your Consent

By using the Service, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.

Contact Us

If you have any questions regarding privacy while using the Service, or have questions about the practices, please contact the Service Provider via email at support@causally.xyz.