Privacy Policy

Last updated: August 10, 2026 · Effective from: August 10, 2026

Data Controller: Poweron s.r.o., ID No.: 062 05 712

Registered office: Palachova 504/7, 460 01 Liberec, Czech Republic

Represented by: Jakub Miřejovský, Managing Director

Contact e-mail: team@bohemicastudio.com

We take the protection of your personal data seriously. In this Privacy Policy you will learn what data we collect, why we collect it, how we process it and what rights you have. This policy applies to the "What's on the menu" mobile application (the "App") available on Google Play and Apple App Store, and the related back-end services.

If you have any questions regarding the processing of your personal data, please contact us at team@bohemicastudio.com.

1. Definitions

For clarity we provide the following definitions used throughout this document:

  • App – the "What's on the menu" mobile application that helps users discover nearby restaurants, analyse food photos and manage menu items using artificial intelligence.
  • Analytical Data – analytics tools and metrics used to understand how our service is used and to improve it.
  • Personal Data – any information relating to an identified or identifiable natural person.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
  • CCPA – California Consumer Privacy Act of 2018.
  • EEA – European Economic Area.
  • User (also "you") – a natural person who uses the App, whether as a registered or unregistered user.
  • Controller – the entity that determines the purposes and means of processing Personal Data (in relation to your data, this is us).
  • Processor – an entity we use to carry out certain processing of Personal Data on our behalf.
  • Processing – any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • Web – our website www.wotm.cc.

2. Our Approach to Personal Data

Your privacy is our priority. We only collect Personal Data that is strictly necessary for providing the App's services. Our App complies with the standards required by the GDPR. If you entrust your data to us, we commit to handling it in accordance with applicable legal regulations (including GDPR and CCPA).

We DO NOT use any of your data for user profiling, ad targeting or any other marketing purposes.

3. What Personal and Analytical Data We Collect

Depending on how you use the App, we may collect the following categories of data:

3.1 Account & Registration Data

  • E-mail address and password (stored in a securely hashed form) – required for account creation and authentication.
  • Display name (if provided) – for personalisation within the App.
  • Preferred language – so we can display content in your language.

3.2 Device Permissions & Sensor Data

  • Location (GPS): Your approximate location, used solely to find nearby restaurants via Google Places API. Location data is sent to Google's servers for the purpose of the search and is not permanently stored by us.
  • Camera: Access to your device's camera to capture photos of menus and food items for AI analysis. Photos are transmitted to our server for processing and are not retained longer than necessary.
  • Photo gallery: Access to photos stored on your device so you can select existing images for analysis.

3.3 Usage Data

  • Information about which features you use, the items you search for, timestamps of activity and error logs.
  • IP address and basic device information (OS version, app version) for security, debugging and analytics.

3.4 Subscription, Payment & Credit Data

  • Subscription records – the plan you purchased, its status, and start, renewal and expiry dates, together with transaction identifiers we receive from Google Play or the Apple App Store.
  • Credit records – your credit balance and the history of credit purchases and consumption. All payment processing is handled by Google Play or the Apple App Store – we never receive or store your payment card details.

3.5 Analytical Data

  • Web – we use Google Analytics and Microsoft Clarity. Google Analytics helps us understand aggregated traffic and usage patterns, while Microsoft Clarity records user behaviour on screen.
  • App – we use Google Analytics together with our own internal, server-side analytics monitoring.

4. Why and on What Legal Basis We Process Your Data

We process your Personal Data on the following legal bases:

PurposeLegal basis
Account creation and authenticationPerformance of a contract
Finding nearby restaurants (location)Your consent (granted via device permission)
Analysing food photos via AIYour consent (initiated by you uploading/capturing a photo)
Generating AI images for menu itemsPerformance of a contract (credit-based service)
Managing subscriptions, credits and purchase historyPerformance of a contract
Improving the App and fixing bugsLegitimate interest
Compliance with legal obligationsLegal obligation
Web – analytical measurement (Google Analytics, Microsoft Clarity)Your consent (granted on the Web) which we request before this processing takes place and which you may withdraw at any time.
App – analytical measurement (Google Analytics)Your consent (granted in the App) which we request before this processing takes place and which you may withdraw at any time.
App – analytical measurement (internal monitoring)Legitimate interest

5. Third-Party Services (Processors)

We protect your Personal Data and never sell it. To provide a high-quality service we use the following third-party providers who may process your data on our behalf:

5.1 Google Places API

Used for searching restaurants and places near your location. Your approximate GPS coordinates are sent to Google's servers. Subject to Google's Privacy Policy.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

5.2 Google Gemini API

Used for AI-powered analysis of food photos and menu items, and for generating food images. Photos you capture or select are sent to Google's AI servers for processing. Subject to Google's Privacy Policy.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

5.3 Server Infrastructure

Our application and database are hosted on secured servers provided by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). All data is physically stored in data centres within the European Union (Germany/Finland) in compliance with GDPR standards.

5.4 Google Play / Apple App Store

In-app purchases (subscriptions and credits) and payment processing are handled entirely by Google Play or the Apple App Store, including automatic renewal of recurring subscriptions. We only receive confirmation and identifiers of the purchase – we never access your payment card details. Subject to Google's and Apple's Privacy Policy.

5.5 Public Authorities

In specific cases required by law, we may be obliged to provide your Personal Data to public authorities (e.g. law enforcement, courts, tax authorities).

5.6 Google Analytics

Used for analytical measurement on both the Web and the App – only when we have your consent.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

5.7 Microsoft Clarity

Used for analytical measurement on the Web – only when we have your consent.

Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.

6. Data Retention

We process your Personal Data only for as long as is necessary:

  • Account data: For the duration of your account. When you delete your account, we erase your data within 30 days (unless legal obligations require longer retention).
  • Photos submitted for analysis: Processed in real-time and not stored on our servers longer than necessary for the analysis (typically seconds to minutes).
  • Location data: Used in real-time for restaurant search and not permanently stored.
  • Subscription, transaction & credit history: Retained for the duration of your account and up to 3 years after deletion for accounting and legal purposes.
  • Server logs (IP, errors): Retained for up to 90 days for debugging and security.

7. Data Security

The security of your Personal Data is very important to us. We have implemented a range of technical and organisational measures:

Technical measures

  • All data is transmitted over encrypted connections (SSL/TLS, HTTPS).
  • Passwords are stored using strong one-way hashing (bcrypt).
  • Data at rest on our servers is encrypted.
  • Regular data backups in case of technical failure.
  • API keys and sensitive credentials are stored in environment variables, never in source code.
  • Systems and applications are developed with privacy by design principles.

Organisational measures

  • Access to systems containing Personal Data is limited to authorised personnel only.
  • All team members are bound by confidentiality obligations.
  • Access credentials are individualised and regularly reviewed.

8. International Data Transfers

When we use Processors located outside the EEA (e.g. Google's AI services), we ensure compliance with applicable data protection regulations. For transfers from the EEA to countries without an adequacy decision by the European Commission, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards to guarantee a high level of protection for your Personal Data.

9. Children and Minors

Our App is intended for users aged 16 years and older. We do not knowingly collect Personal Data from children under 16. If we become aware that we have received personal data from a child without parental consent, we will take reasonable steps to delete such information as quickly as possible. If you believe we may have collected data from a minor, please contact us at team@bohemicastudio.com.

10. Your Rights under GDPR

If you are located in the EEA, you may exercise the following rights by contacting us at team@bohemicastudio.com. We will respond without undue delay, and no later than 1 month from receipt of your request (in exceptional cases this may be extended by 2 additional months).

  • Right of access: You have the right to obtain confirmation as to whether we process your Personal Data, and if so, to receive a copy of such data along with information about the purposes, categories, recipients and retention periods.
  • Right to rectification: You may request the correction of inaccurate or incomplete Personal Data.
  • Right to erasure ("right to be forgotten"): You may request deletion of your Personal Data when it is no longer necessary, when you withdraw consent, or when processing was unlawful. If another legal ground for retention exists, we will inform you accordingly.
  • Right to restriction of processing: You may request that we restrict the processing of your data (e.g. while verifying accuracy or if processing is unlawful but you do not wish to delete the data).
  • Right to data portability: You may request your Personal Data in a structured, commonly used and machine-readable format, or ask us to transmit it directly to another controller where technically feasible.
  • Right to object: If we process your data based on legitimate interest, you may object at any time. If the objection concerns direct marketing, we will always cease processing.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • Right not to be subject to automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not carry out such automated individual decision-making.

11. Your Rights under CCPA (California Residents)

If you are a California resident, the CCPA grants you the following rights:

  • Right to know: You may request information about what Personal Data we collect, use, disclose or sell, where we obtained it and for what purpose.
  • Right to delete: You may request that we delete your Personal Data (subject to legal exceptions).
  • Right to opt-out of sale/sharing: We do not sell your Personal Data. If we share data with Processors, it is solely for the purpose of providing the App's services.
  • Right to correction: You may request correction of inaccurate Personal Data.
  • Right to non-discrimination: You have the right not to be discriminated against for exercising any of your CCPA rights.

To exercise your CCPA rights, contact us at team@bohemicastudio.com. We may request identity verification to process your request.

12. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy. Changes will be posted on this page and, where appropriate, communicated within the App. By continuing to use the App after a change, you acknowledge the updated policy. We recommend checking this page periodically.

13. Contact Us & Complaints

If you have any questions about this Privacy Policy or the processing of your Personal Data, please contact us:

Poweron s.r.o.

Palachova 504/7, 460 01 Liberec, Czech Republic

E-mail: team@bohemicastudio.com

If you are dissatisfied with our approach to personal data protection, you have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (ÚRad pro ochranu osobních údajů, Pplk. Sochora 727/27, 170 00 Praha 7, www.uoou.cz). You may also contact the supervisory authority in your country of habitual residence.