Last updated: 12 August 2026 · Español · Русский
The short version. Obrok is a food tracker you use through Telegram. To do its job it needs your Telegram profile (ID, username, first name), the food photos and messages you send, and the meal logs and estimates it produces.
When you send a food photo or a meal description, it is sent to our AI provider, Anthropic, to generate the nutrition estimate. Your photos and logs are stored on our servers in Germany (EU) so you can review, correct and export them — and you can delete everything at any time with /deletedata.
We don't run advertising and we don't use third-party analytics or tracking cookies. This page explains exactly what we hold, why, who else is involved, and the rights you have.
Obrok ("Obrok", "we", "us") is a personal nutrition-tracking service delivered through the Telegram bot @ObrokApp_bot and the dashboard at obrok.app. It is operated by an individual operator established in the European Union. Obrok is the controller of the personal data described here.
You can reach us on Telegram at @dubcountry for any privacy question or request.
Because this is the question people ask most, here is the full path of a single photo:
What Anthropic receives is the image and text you submitted. See Use of AI and Who else is involved.
We only collect what the service needs. "Legal basis" refers to the GDPR ground we rely on.
| Data | Why | Legal basis |
|---|---|---|
| Telegram identity (numeric ID, username, first name) | This is your account — we have no email/password login | Contract (Art. 6(1)(b)) |
| Messages, captions and food descriptions you send | To analyse and log your meals | Contract (6(1)(b)); consent where health-related (see §4) |
| Food photos | To analyse them and let you review/correct entries | Contract (6(1)(b)); consent where health-related |
| Meal logs & estimates (foods, portions, kcal, protein/carbs/fat, alcohol units, timestamps, confidence, assumptions) | The tracking product itself | Contract (6(1)(b)); consent where health-related |
| Settings & targets (timezone, calorie/macro goals, weekly alcohol limit, recap preference) | To tailor and show your tracking | Contract (6(1)(b)); consent where health-related |
| Timezone from a location pin (if you share one) | To set your day boundary. Coordinates are turned into a timezone on our server and are not stored | Contract (6(1)(b)) |
| Payment references (a Telegram Stars charge ID, or a Stripe checkout session/customer/subscription ID) and plan/expiry | To grant access, support you and handle refunds. We never receive your card number | Contract (6(1)(b)); legal obligation for records (6(1)(c)) |
| Subscription status and next renewal date (card plans only) | To auto-renew card plans, remind you before each charge, and let you cancel via the billing portal | Contract (6(1)(b)) |
| Usage & technical records (per-analysis token counts and cost; daily analysis count; dashboard session token hash) | Abuse/rate-limit protection, security, and running the service sustainably | Legitimate interests (6(1)(f)) |
| A deletion record (your Telegram ID + date) kept after erasure | To evidence that a deletion happened and prevent abuse | Legitimate interests (6(1)(f)) |
We keep short-lived operational logs (e.g. error diagnostics) for security and debugging. We do not build advertising profiles.
Some of what you log — your meals over time, and especially any alcohol you record — can reveal information about your health. Under the GDPR this can be "special category" data (Article 9).
We process it only to give you the tracking you ask for, and we rely on your consent for this special-category processing (Article 9(2)(a)). You provide that consent by actively choosing to send your meals and drinks to Obrok, and you can withdraw it at any time by deleting your data with /deletedata and stopping use. Withdrawing consent does not affect processing that already took place.
Obrok uses artificial intelligence to identify foods and estimate portions, calories and macronutrients from your photos and descriptions. You are interacting with an AI-powered system, not a person reviewing each meal by hand.
The AI is provided by Anthropic (the Claude API). Your submitted image and text are sent to Anthropic to produce the estimate; the result is returned to us and stored in your account. Anthropic's handling of API data is governed by its own commercial and data-processing terms. Estimates are approximate — see our Terms.
We keep the number of parties small. The ones that can touch your data are:
We do not use third-party analytics, advertising networks, tracking pixels, or an external error-monitoring service. For basic audience measurement we run our own privacy-friendly analytics (self-hosted Umami, on our EU servers): it counts page views without cookies and without cross-site tracking or advertising profiles, recording only coarse, non-identifying details (the page visited, referrer, browser/OS/device type, screen size, and an approximate country derived from your IP, which is not stored). Legal basis: our legitimate interest (Art. 6(1)(f)) in understanding how the site is used.
Your account data, meal logs and photos are stored in the EU (Germany). Some processing does, however, involve organisations outside the European Economic Area (EEA):
Where we send data to a processor outside the EEA, we rely on the safeguards that provider offers — typically the European Commission's Standard Contractual Clauses within that provider's data-processing agreement. We are confirming these agreements for each provider; if you would like the current details, contact us.
Live data: we keep your account, meals, photos, estimates and settings until you delete them. There is no automatic expiry.
You control it:
Backups: we take short-lived backups for disaster recovery — nightly database snapshots kept for about 14 days, and a weekly copy of stored photos, all on our EU infrastructure. After you delete something, any copy that still exists in these backups is overwritten as they rotate (within roughly 14 days for the database; on the next weekly cycle for photos). Sign-in links and dashboard sessions are themselves short-lived (magic links expire in 15 minutes; sessions after 30 days).
Under the GDPR you can:
To make a request, message @dubcountry on Telegram. If you are in the EU/EEA you can also lodge a complaint with your local data-protection authority, or with the authority for the country where Obrok is established.
The dashboard sets one strictly necessary cookie, obrok_session, which keeps you signed in. It holds a random token (only its hash is stored on our side), is HTTP-only, and expires after 30 days or when you sign out. We set no advertising or analytics cookies — our own website analytics is cookieless (see §6).
Traffic to obrok.app is served over HTTPS. Your photos are not publicly reachable — they are streamed only to your own signed-in session. Dashboard sign-in uses Telegram's cryptographically signed login, one-time magic links, or the Telegram Mini App; we store no password. Access to the database and files is restricted to the operator. No method of storage or transmission is perfectly secure, and we do not currently encrypt data at rest beyond the platform-level protections our host provides.
Obrok is for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has used Obrok, contact us and we will delete the account.
If we make a material change to this policy, we will announce it through the bot before it takes effect and update the date at the top.
Privacy questions and requests: Telegram @dubcountry.
Obrok is a personal, independent project. This policy describes the service as it actually works today; some formal details (controller registration, processor agreements) are being finalised and this document is being reviewed by counsel.