Your data, plainly.
Privacy Policy

Version 1.1 · last updated 3 August 2026

Who is responsible

Orzio is operated by Lev Zolotarov, an individual based in Cyprus (the “controller”). Contact: levzo@pm.me.

What we collect

Photos you submit for meal, barcode, or nutrition-label logging, retained while your account exists. The current browser logger does not retain a camera capture you discard without submitting it. Private snap archives made by an earlier browser version, if any, remain covered by account deletion. Model outputs: identified foods, portions, macro estimates, confidence values, and structured model responses. Your logs: meals, snacks, portions, timestamps, water and weight entries, goals, diet rules, allowed and banned foods, and saved products. Messages you send to the bot, including captions, text descriptions of meals, questions, and recent conversation needed for continuity. Usage telemetry: commands and buttons used, which model served each request, latency, token counts, cost, errors, and which surface (Telegram, Discord, Shortcut, or web) was used. On the public homepage only, anonymous page, tap, scroll, and sampled pointer positions are sent to thatlev.com so the referring portfolio can show one continuous visit. No form values or raw IP address are stored by that analytics service. Account identifiers: your Telegram and/or Discord user id and display name, timezone, day-start setting, and a hash of your shortcut secret. To prevent a retried Telegram, Discord, Shortcut, or web request from logging the same meal twice, Orzio stores an opaque delivery id or a one-way, account-scoped request hash. It contains no message or photo content. One copy is attached to the resulting meal while that meal remains in your account so even a late retry cannot create it again; a separate short-lived processing claim tracks whether a live request is still running or finished. Orzio does not retain a new meal input submitted before you accept the current Terms and Privacy Policy; it asks you to accept and resend. Meal inputs already parked by an earlier release can replay once after you accept, after which any stored photo bytes in that pending record are cleared. An Orzio account does not require an email, password, address, or payment data. If you submit the optional early-access waitlist form, we store the email address you enter and your browser user-agent so we can contact you about access and protect the form from abuse.

What we use it for

Providing the service: analysing and logging food, answering your questions with the relevant part of your log, commenting on meals and days, showing history and summaries, and applying your chosen goals and food rules. Fixing bugs and diagnosing failures. Improving the service: evaluating and comparing models, tuning prompts, and improving accuracy and the compliance engine, using stored photos, model outputs and telemetry for that purpose. Nothing else. No advertising, no profiling for third parties, no sale of data.

Who processes it

Vercel (hosting and image storage), Prisma Postgres (database), Anthropic, OpenAI and Google (AI analysis and replies), Telegram and Discord (message delivery), and Open Food Facts and other barcode libraries (barcode lookups; a barcode you scan may be queried against them). We do not sell personal data and do not share it for advertising.

What is sent to AI providers

The information sent depends on the request. Analysing a photo or food description can include the image or text, its caption, your applicable goals and diet rules, and recent bot conversation needed to understand the message. A question or comment about today can include the relevant tracking day’s meals, foods, portions, timestamps, macro estimates, compliance results, water entries, weight entries, goals, allowed and banned foods, guidelines, timezone, and day-start setting. A question about the week can include the same data for the previous full week and the current week through today, including days with no entries. Automatic meal and daily comments can use the current tracking day and a small number of recent automatic comments so they do not simply repeat themselves. Recent user and assistant messages can be included for conversational continuity.

OpenAI also receives a one-way SHA-256 value derived from your internal Orzio user id as a stable pseudonymous safety identifier. It does not contain your Telegram or Discord id, name, or message text; OpenAI receives it for abuse and safety monitoring.

Orzio first sends a request to the configured AI provider. A transient failure can cause the same request to be retried with that provider and then sent to a configured provider from the list above as a failover. This means more than one AI provider may process the same request when a retry or failover is needed. For conversational replies and food comments, Orzio redacts the prompt and response bodies from its separate model-call telemetry; your original message and the reply still remain in your bot message history.

Private chat surfaces

Orzio accepts Telegram messages and button presses only in a private chat with the bot. Discord interaction replies are visible only to the person who invoked them; scheduled or out-of-band Discord messages are delivered by direct message. The messaging platforms still process those communications to deliver them, so protect access to your Telegram and Discord accounts.

Legal basis

Under the GDPR, Orzio relies on your consent (Article 6(1)(a)) to process the personal data you provide for nutrition tracking and AI features. To the extent your food intake, weight, goals, diet rules, messages or resulting inferences are data concerning health, Orzio relies on your explicit consent (Article 9(2)(a)). This consent covers storing and using those data to provide and improve the personalised service described above, and sending request-relevant data to the AI processors OpenAI, Anthropic and Google, including retries and failover. For non-health-related processing, Orzio also relies on performance of the service you requested and legitimate interests in security and debugging. If you join the waitlist, we use your email to take the pre-contractual step you requested and the user-agent under our legitimate interest in preventing abuse.

You may withdraw consent at any time by emailing levzo@pm.me. You can separately schedule permanent account deletion in Settings. Withdrawal does not affect processing that was lawful before withdrawal. Because the personalised service depends on this processing, Orzio cannot continue providing it after you withdraw consent.

How long we keep it

Data is kept while your account exists, and deleted after the account-deletion flow completes (Settings → Delete my account: scheduled 30 days out, cancellable during that window). Backups may persist for up to 30 further days. After deletion, Orzio retains a pseudonymous deletion receipt containing a SHA-256 hash of your internal Orzio user id and the deletion timestamp. The receipt has no fixed expiry and is kept only as evidence that the deletion was completed. It does not contain your name, Telegram or Discord id, messages or nutrition history, but the hash is pseudonymous personal data rather than anonymous aggregate data. As a narrow exception, short-lived processing claims containing delivery ids or one-way request hashes may remain after account deletion and are removed no later than 30 days after their last processing activity. The idempotency reference attached to a saved meal remains while that meal and account exist, and is deleted with them. A legacy pending-meal reference, caption and other metadata may remain with the account after replay, but its stored photo bytes are cleared; the remaining record is deleted with the account. The delivery ids and request hashes themselves contain no message or photo content. Orzio may also retain counters that are truly anonymous and cannot be linked back to you. Waitlist email and user-agent records are kept only while Orzio is managing early access and are deleted when no longer needed; you can request deletion at any time using the contact address above.

Your rights

Access, correction, deletion, export, and objection, plus the right to complain to the Cyprus data protection authority. Deletion is available in Settings or by emailing levzo@pm.me; requests are honoured within one month. The deletion flow can send an in-chat JSON nutrition-history export containing profile settings, goals and diet rules, meals and adjustments, water and weight logs, and saved products; photos are referenced by URL. That file does not include bot message history or technical telemetry. To access those records or any other personal data Orzio holds, email the address above.

Age

Orzio is for users 18 and over. Accounts identified as belonging to someone under 18 are deleted.

International transfers

The processors above may handle data outside the EEA under their standard safeguards.

Changes

Material changes bump the policy version and re-prompt you for acceptance in the chat.