Privacy
Short version: bite stores what it needs to give you your bites back, keeps it in the EU, sells none of it, and deletes all of it the moment you ask.
Who is responsible
Philipp Tschauner, Berlin, Germany. Postal address and contact details are in the imprint.
What is stored
- Your account. The email address and name your sign-in provider hands over when you use Sign in with Apple or Google. bite never sees your password.
- What you saved. The address, title and timestamp of each link, whether you read, skipped or kept it, and any lists you filed it on.
- The bites themselves. The text extracted from a source and the summary written from it. Summaries are shared between everyone who saved the same address — they contain nothing about you, and that sharing is why the second person to save an article gets it instantly.
- Your preferences. Summary language, reading font and size, appearance.
- A push token, if you allowed notifications, so bite can tell you when something is ready.
- Your subscription status — whether you are on pro, and when that ends. Payment details belong to Apple; bite never receives them.
- Your email address, if you asked for a beta inviteon this website. That is all that is kept — the address and the date you asked. It is not connected to an account, because at that point there isn't one, and it is used for nothing except sending you the invite. Ask us to delete it at any time and it is gone.
The browser extension
The Chrome extension can see the tabs you have open, so it can list them for you to pick from. That list never leaves your machine. Nothing is sent anywhere until you choose a link and save it.
When you do, three things go to bite: the address, the title, and the text of the page itself — because reading the page is the whole job. For a site you are signed in to, the extension asks for permission to read that page first, and you can refuse or withdraw it in Chrome at any time.
Signing in pairs the extension with your phone by QR code. It stores the resulting sign-in token in the browser, and nothing else — no password ever passes through it, because it never asks for one.
The extension does not watch you browse. It keeps no history of the pages you visited but did not save, records no clicks, scrolling or keystrokes, and carries no analytics of any kind.
Usage analytics
bite counts how the app is used, so the parts nobody gets through can be found and fixed. It records a short, fixed list of moments — onboarding pages seen, sign-in started and finished, a briefing begun and completed, the purchase screen opened — with nothing but counts and outcomes attached.
It never records what you save or read. Not a title, not an address, not a summary. There is no automatic capture of taps or screens, no session recording, and no advertising or cross-app tracking of any kind. Nothing is sold or shared for advertising.
This runs on PostHog's European servers. You can switch it off in the app under Settings → Usage analytics, and it stops at the next start.
Who processes it
- Supabase — database and sign-in, hosted in Ireland (EU).
- Vercel — this website. Its servers log the usual request data, including your IP address, in order to serve the page and absorb attacks.
- Mailjet (France) — the service that delivers the few emails bite sends: your beta invite, a note when your account is created, and — at most five times ever — a message when the reading time bite has saved you passes a round number (an hour, a day, a week, a month, a year). That last kind has an unsubscribe link in it and stopping them changes nothing else. Mailjet receives your email address and nothing else; the numbers in the message are put together here and sent as finished text.
- Railway — the server that does the summarising, hosted in the EU.
- Anthropic and OpenAI — the models that write the summaries, and, for pro features, the narration and podcast transcription. They receive the text of the source and the summary. They do not receive your name, your email or any account identifier.
- RevenueCat — subscription status, plus a device identifier it needs to match a purchase to an account.
- Apple — notifications and, if you subscribe, the payment itself. Google — only if you choose to sign in with it.
- PostHog (EU) — the usage counts described above, tied to your account id once you sign in. Unless you switched them off.
Processing outside the EU happens where these providers operate. In each case it rests on the European Commission's standard contractual clauses.
Why, and on what basis
Everything above exists to provide the service you asked for — Article 6(1)(b) GDPR, performance of a contract. Notifications rest on your consent, which iOS asks for and you can withdraw at any time in Settings. Usage analytics rest on a legitimate interest in knowing which parts of the app fail people — Article 6(1)(f) — which is why the switch to turn them off sits in Settings rather than behind a request. The beta waitlist rests on your consent — Article 6(1)(a) — given by typing your address into a form that says what it is for.
How long
As long as your account exists. Delete it in the app under Settings, and everything of yours goes with it: your saves, lists, preferences, push tokens and the account itself. The summaries stay, because they belong to everyone who saved the same address and hold nothing about you.
A waitlist address is kept until the beta is over, then deleted — it has no purpose after that. Write to us before then and it goes immediately.
Your rights
You can ask for access, correction, deletion, restriction, a copy of your data, or object to processing. Use the address in the imprint, or, if you have the app, Settings → Support and feedback. You may also complain to a supervisory authority; for Berlin that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.