This policy and the Terms are published in English, and English is the version that governs. We do not translate them: a legal text translated without review is not the same text in another language — it is a different promise. If you need help understanding it in your language, write to privacy@tabelingo.com and a person will explain.
Privacy Policy — Tabelingo
Last updated: 6 October 2026
This Privacy Policy explains what personal data Tabelingo processes, why, and the rights you have over that data. It applies to the Tabelingo mobile application and any related services (the "Service"). Please read it together with our Terms of Service.
Language. This Policy is published in English, which is the version that governs. The app itself is available in ten languages. If you need help understanding this Policy in another language, please contact us at the address in Section 12.
1. Who we are
Tabelingo reads photographs of restaurant menus, translates the dishes and assembles orders in Japanese.
- Data controller: MVA SERVICOS ONLINE LTDA, a limited liability company incorporated in the Federative Republic of Brazil
- CNPJ: 47.195.396/0001-33
- Based in: São Paulo, Brazil
- Contact for privacy matters: privacy@tabelingo.com
If you are located in the European Economic Area or the United Kingdom, our representative under Article 27 GDPR is: [to be appointed if and where required].
2. Data minimisation
We collect only the personal data necessary to operate the Service. Categories of data we deliberately do not collect are identified in Section 4.
3. Personal data we process
3.1 Account data
Sessions start anonymous: on first launch we generate a random device identifier. We do not require a name, phone number or password.
You may optionally link an email address to preserve access across devices. It is used to send you a sign-in code and to recognise your account on another device. It is not used for marketing.
3.2 Menu photographs
Photographs you upload are transmitted to our processing infrastructure and retained for up to 90 days, after which they are deleted automatically.
Purpose. Diagnostic and service-quality investigation of menu reading errors.
Safeguards.
- Image location metadata (EXIF, including GPS coordinates) is stripped on your device before upload.
- Storage is private and cannot be read from the app.
- You may disable further uploads under Settings → Data and privacy. Uploads already made are deleted upon account deletion.
Legal basis (GDPR Art. 6(1)(f); LGPD Art. 7, IX): legitimate interest in maintaining and improving a service whose core function is menu reading.
We do not use these photographs for advertising, do not sell them, and do not share them with any third party other than the processing providers listed in Section 6.
3.3 Voice translator data
Audio is not retained. It is transmitted to the transcription provider and discarded after transcription.
Translated text is retained for up to 90 days for translation quality verification, then deleted automatically. This covers both what is transcribed from speech (yours and the restaurant staff's, in both directions) and text you type or correct yourself in the voice translator.
If you correct a transcription, we keep the original transcription alongside your correction, for the same period and under the same conditions. This is the only way to measure how often the transcription is wrong, and in what way — a correction tells us exactly what was misheard.
These records contain no user identifier and are not linked to your account, session or restaurant.
To request deletion of these records before the automatic 90-day expiry, contact us at the address in Section 12 and indicate the approximate date and hour or hours during which you used the voice translator; we will delete all records within that time window.
If you prefer not to generate such records at all, do not use the voice translator feature — neither by voice nor by keyboard. All other features of the Service remain available.
Legal basis (GDPR Art. 6(1)(f); LGPD Art. 7, IX): legitimate interest in verifying translation quality in a service used for restaurant ordering.
3.7 Record of your acceptance of these Terms
When you accept our Terms of Service, we record: the version of the text you accepted, the language it was displayed in, the date and time, your app version, platform, device model, operating system version, device locale, and the IP address the acceptance was sent from.
Purpose. To evidence that you were shown, and accepted, the safety limitations of the Service — in particular the allergen warnings — in a language you could read. Device and network details corroborate that record.
Legal basis (GDPR Art. 6(1)(f); LGPD Art. 7, IX): legitimate interest in establishing, exercising and defending legal claims, and in demonstrating compliance with our obligation to inform users of the limitations of the Service.
We do not use this record for analytics, profiling, advertising or any purpose other than the one stated above.
3.4 Usage records
For each menu reading we record: page count, model used, processing duration, quota outcome and timestamp. These records support fair-use enforcement and diagnostic troubleshooting. Photograph content and location are not stored alongside these records.
3.5 Saved menus
If you save a menu, we retain the parsed dish text and a user-supplied text label for the venue.
3.11 Saved phrases
If you save a phrase from the voice translator, we retain the text you wrote or spoke, in your own language, together with its Japanese translation, linked to your account.
Two points deserve emphasis, because this category differs from §3.3:
- It is linked to you. Voice translator records carry no user identifier, by design. A saved phrase must carry one — it exists precisely so it can be returned to you on another device.
- You choose the content, and it may be sensitive. People save what they need to repeat at a table, and that includes sentences such as "no shrimp, I have an allergy". We do not interpret this text, match it against dishes, or build any profile from it — see §4.1. It is stored so it can be shown back to you and read aloud.
You can delete any saved phrase from within the app at any time, which removes it from the device and from our servers. All saved phrases are deleted when the account is deleted.
3.6 Purchases
Our payment processor communicates the plan you have purchased and its validity period. We do not receive or store payment card details — those are handled directly by Apple or Google.
3.8 Install attribution
When the app is first launched, our attribution provider (AppsFlyer) records that an installation occurred and the campaign, channel or link it came from. It also receives a limited set of app events — for example, that a menu was read or an order was generated — as counts, without any content.
What is never sent: your advertising identifier, your account identifier, menu photographs, dish text, voice transcripts, or location. The events carry shape and count only, never content.
Legal basis (GDPR Art. 6(1)(f); LGPD Art. 7, IX): legitimate interest in understanding which channels bring users to the Service, so that we do not spend on channels that do not work.
Retention: per the provider's standard retention for attribution data.
3.9 Record of menus returned to you
For each menu reading we retain a copy of what the app returned to your screen — dish names, translations, possible allergens, dietary information and prices — together with your account identifier, an installation identifier, the IP address of the request, the language you read it in, and the date.
Purpose. Evidence. A complaint about allergen information typically arrives as a screenshot; without our own copy we cannot establish what the app actually displayed, or whether the screenshot is authentic.
Legal basis (GDPR Art. 6(1)(f) and Art. 17(3)(e); LGPD Art. 7, IX and Art. 16, III): legitimate interest in, and necessity for, the establishment, exercise and defence of legal claims.
Retention: 5 years, matching the limitation period for consumer claims under Brazilian law.
⚠️ This record is not deleted when you delete your account, for the same reason: a claim may be brought after deletion. It is not used for analytics, recommendation or any purpose other than defence of claims.
Installation identifier. A random value generated when the app is first installed and stored on your device. It is not derived from device hardware, is not an advertising identifier, is shared with no third party, and changes if the app is reinstalled.
3.10 Affiliate referrals
If you open the app through a referral link, we store a short code identifying who referred you, together with a random identifier generated on your device. Both are kept on your device for 7 days.
If you make a purchase in that period, the code travels with the purchase record through our payment processor (RevenueCat) to our affiliate provider (Insert Affiliate), so the referrer can be credited. That transfer includes your account identifier and the state of the purchase.
We do not send your email address, your location, menu content, or any advertising identifier for this purpose, and on iPhone we do not collect device characteristics for it.
3.12 Visits to our website
Our website, tabelingo.com, is hosted by Cloudflare. To count visits, it uses Cloudflare Web Analytics, which measures page views, the page that referred the visit, country, browser type and page load times.
It does not set cookies, does not use local storage, does not fingerprint your device and does not track you across websites. The measurement is not applied to visitors in the European Union. We see only aggregated figures; we cannot identify an individual visitor from them.
4. Data we do not collect
4.1 Health data
The Service does not collect, process or store health data of any kind. There is no allergy profile, dietary restriction record or medical history — neither on the device nor on our servers.
The Service displays possible allergens for each dish as general information common to all users, together with pre-written questions in Japanese for confirmation with the restaurant.
We do not process special category personal data under Article 9 GDPR, or sensitive personal data under Article 5, II of the LGPD.
4.2 GPS coordinates
Latitude and longitude never leave your device. Where you grant location access, your device's operating system converts the coordinate into a place name locally, and only that text is transmitted to us.
4.3 Cross-app tracking and advertising identifiers
The Service does not access the advertising identifier of your device (IDFA on iOS, Advertising ID on Android), does not track you across other apps or websites, and does not present an App Tracking Transparency prompt.
We do not sell or share personal data for advertising purposes, and the Service displays no advertising.
Referrals are not tracking. If you install the app through a link shared by someone who recommends it, the app stores a short referral code on your device for 7 days and attaches it to a purchase, so that the person who recommended us can be paid. That code is not an advertising identifier, it is not used to build a profile, and it does not identify you across other apps or websites. On iPhone, the app deliberately does not use the device-fingerprinting method this kind of service commonly offers — it collects no device characteristics for this purpose.
We do use an install attribution provider (AppsFlyer) to learn which campaign or channel an installation came from — see Section 3.8. Attribution tells us where an install originated; it does not tell us who you are, and it is not linked to your account.
5. Legal bases (summary)
| Data | Purpose | Legal basis (GDPR / LGPD) |
|---|---|---|
| Anonymous identifier | Enable the Service without registration | Contract performance / Art. 7, V |
| Email (optional) | Restore access on another device | Contract performance / Art. 7, V |
| Menu text | Deliver translation and ordering | Contract performance / Art. 7, V |
| Menu photographs | Quality assurance | Legitimate interest / Art. 7, IX |
| Voice translator text (transcribed and typed) | Translation quality verification | Legitimate interest / Art. 7, IX |
| Usage records | Fair-use enforcement; diagnostics | Legitimate interest / Art. 7, IX |
| Terms acceptance record (incl. IP, device) | Evidence of informed acceptance; legal claims | Legitimate interest / Art. 7, IX |
| Install attribution (campaign, app events) | Know which channels bring users | Legitimate interest / Art. 7, IX |
| Menu returned to you (content, IP, installation id) | Evidence in a claim about allergen information | Legitimate interest + legal claims / Art. 7, IX + Art. 16, III |
| Subscription state | Grant purchased access | Contract performance / Art. 7, V |
| Referral code (affiliate) | Credit the person who recommended the app | Legitimate interest / Art. 7, IX |
6. Recipients and international transfers
| Recipient | Data transferred | Location |
|---|---|---|
| Supabase | Database and authentication | Region of project deployment |
| Ollama Cloud | Menu photograph, for reading | United States |
| Groq | Voice audio, for transcription | United States |
| Google Places | Restaurant name text you enter | Global (Google infrastructure) |
| RevenueCat | Account identifier and purchase state | United States |
| Insert Affiliate | Referral code, account identifier and purchase state — forwarded by RevenueCat when a purchase occurs | United States |
| AppsFlyer | Install attribution signals and app events (no advertising identifier, no account identifier) | Israel / United States |
| Apple / Google | Payment processing | Per store policy |
| Cloudflare | Website hosting and aggregated visit measurement (§3.12) | Global (Cloudflare network) |
International transfers. For personal data of individuals in the European Economic Area, the United Kingdom or Switzerland transferred outside those regions, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) — together with any supplementary technical or organisational measures required by the receiving jurisdiction. A copy of the applicable transfer mechanism is available on request.
For users in Brazil, international transfers of personal data are made under mechanisms recognised by the ANPD in accordance with Articles 33 and 35 of the LGPD.
7. Retention periods
| Category | Retention |
|---|---|
| Menu photographs | Up to 90 days (automatic deletion) |
| Voice audio | Not retained |
| Voice translator text (transcribed and typed) | Up to 90 days (automatic deletion) |
| Referral code (on your device) | 7 days from the moment the link was opened |
| Usage records | Duration of the account (required for lifetime fair-use enforcement) |
| Terms acceptance record | Duration of the account; a copy is retained for 5 years after deletion, for defence of claims |
| Menus returned to you | 5 years |
| Saved menus | Until deleted by the user or upon account termination |
| Saved phrases | Until deleted by the user or upon account termination |
| Purchase records | For the period required by applicable tax law — typically 5 years under Brazilian law |
| Account and linked email | Until the account is deleted |
8. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (subject to legal retention obligations);
- receive your data in a portable format;
- object to processing based on legitimate interest;
- withdraw consent, where processing is based on consent;
- lodge a complaint with a supervisory authority — the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil, or your local data protection authority in the EEA or the UK.
Account deletion is available directly in the Service, under Settings → Delete account. Deletion is immediate and includes all data linked to your account, with two documented exceptions retained for the defence of legal claims: your acceptance of these Terms and the menus the app returned to you (Section 3.9). Where you have linked an email address, it is preserved with the acceptance record so that the record remains attributable.
To exercise any other right — including early deletion of voice transcripts (see Section 3.3) — write to privacy@tabelingo.com. We respond within 15 days under the LGPD and within one month under the GDPR.
9. Security
We implement industry-standard technical and organisational measures to protect personal data, including encryption in transit, access controls on storage, and restricted administrative access.
No system is completely secure. Where a security incident materially affects your rights, we will notify you and the relevant supervisory authority within the timeframes required by applicable law.
10. Children
The Service is not directed to children under 13 (or the equivalent minimum age under your local law) and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us.
11. Changes to this Policy
We may update this Policy from time to time. The current version is always available inside the app and at our published URL. Where a change materially affects processing, we will notify you inside the app before it takes effect.
12. Contact
For any question about this Policy or the processing of your personal data:
MVA SERVICOS ONLINE LTDA CNPJ: 47.195.396/0001-33 São Paulo, Brazil Email: privacy@tabelingo.com
13. Important non-legal note about allergen information
The Service indicates the possibility that a dish contains a given ingredient. It does not verify, certify or guarantee the composition of any dish. The information is derived from a curated general library and from automatic reading of a photograph — neither of which knows the recipe used by a specific restaurant on a specific day.
If you have a food allergy, always confirm with the restaurant. The Service provides pre-written questions in Japanese for this purpose.
