Privacy Policy of the Sito Application

Effective September 27, 2026Updated September 27, 2026

What data the app processes, what stays on the device, what goes to the server when you sign in by email and how to delete all of it.

This document is a courtesy translation. In case of any discrepancy between the English and Russian versions, the Russian version available at https://sito.alexforge.org/legal/privacy/ prevails.

1. General Provisions

1.1. This Privacy Policy (hereinafter the "Policy") describes what data is processed in the Sito mobile application for Android and iOS (hereinafter the "App"), for what purposes, how long it is stored, to whom it is transferred and how the User can manage it, including deleting it.

1.2. By installing and using the App, you agree to the terms of this Policy. If you do not agree with the Policy — do not use the App.

1.3. This Policy applies together with the User Agreement of the App, published in the same place where this Policy is published.

1.4. Personal data is processed in accordance with Federal Law of 27.07.2006 No. 152-FZ "On Personal Data", as well as the requirements of the distribution platforms (Google Play, App Store).

2. Terms

  • Personal data — any information relating to a directly or indirectly identified User of the App.
  • Data processing — any operations with data: collection, recording, storage, modification, use, transfer, deletion.
  • User — a natural person using the App.
  • Device — a smartphone or tablet on which the App is installed.
  • Local storage — the App's private storage on the Device.
  • Operator — the person organizing the processing of data; identified in section 20.
  • Account — a profile of the User on the Operator's server, created upon signing in with an email address.
  • Diary — the set of Days the User keeps in the App.
  • Day — the Entries of one calendar date together with the Day Rating.
  • Entry — a record of a meal: what was eaten and when.
  • Day Rating — the wellbeing mark the User gives a Day at their own discretion: good, so-so or bad, the time it applies from, and an optional note.
  • Insights — the section of the App where the Days of the recent period are counted by their Ratings, and the dishes from the Entries by how often a bad Day followed them.
  • Export — a table with the contents of the Diary that the App builds on the Device at the User's request.

3. How Data Processing Is Organized

3.1. The App divides processing into two parts.

On the Device, everything that makes up the core functionality is performed: keeping Entries and Day Ratings, the calendar, the dish suggestions, the Insights, the Export, the appearance settings. These actions do not require a network connection, and their results stay in the Local storage.

On the server, only what is necessary for the Account and for synchronizing the Diary between the User's Devices is processed (section 5), as well as depersonalized statistics about the App's operation (section 6).

3.2. An Account is not required. Without signing in, the App retains full functionality and does not contact the Operator's server at all: the User's data does not leave the Device.

4. Data Processed on the Device

4.1. Data that you enter or create yourself:

  • Entries: the text about what was eaten, the date and time of the meal, the time of modification and deletion of the Entry;
  • Day Ratings: one of three values, the time the Rating applies from, and the note if you left one;
  • appearance settings: interface language, theme;
  • service identifiers: a random identifier of the Device and a random identifier of the local profile, generated by the App and not linked to your identity, the Device's serial number or advertising identifiers.

4.2. Without an Account, the data listed above does not leave the Device and is not accessible to the Operator. The only exception is the random service identifier of the profile: it is included in the depersonalized statistics to distinguish one installation of the App from another (section 6). When an Account is used, the Diary is synchronized under the terms of section 5.

4.3. The appearance settings are stored only on the Device and are never transferred to the server.

4.4. The dish suggestions and the Insights are computed on the Device from your own Entries and Ratings at the moment they are shown; they are not stored separately and are not transferred to the server or to analytics.

5. Account and Synchronization

5.1. Signing in to the App is performed with an email address confirmed by a one-time code that is valid for a few minutes. No password is used. An Account is created automatically when a code is first requested for a new address.

5.2. When an Account is used, the following is processed:

  • the email address — for signing in, identifying the Account and contacting the User;
  • the User's Diary: the Entries with their texts and times, the Day Ratings with their times and notes — for synchronization between the User's Devices;
  • the date and time of modification of Days and Entries and the deletion marks of Entries — for merging versions during synchronization;
  • the interface language — so that the sign-in code email arrives in the language of the App;
  • service details of the Account: the identifier of the record on the server, the date of its creation, the session key;
  • technical information about requests to the server (IP address, build number of the App, time of the request), recorded in server logs for security and diagnostics.

5.3. The Operator does not read or analyze the Diary, Day Ratings and their notes included, and does not use it for any purpose other than storing it and transferring it between the User's Devices. The Insights are counted only on the Device (clause 4.4). What to write down and whether to rate a Day is decided by the User alone.

5.4. Synchronization applies only to your own Diary. The App does not publish it, does not show it to other Users and does not provide for data exchange between Users.

5.5. When the versions of one Day diverge between Devices, the versions are merged: the Entries of both Devices are kept, of two versions of one Entry the one edited later remains, the deletion of an Entry on either Device is kept, and of two Ratings of one Day the one given later remains.

5.6. A sign-in session is renewed automatically while you use the App. If the server stops accepting the session, the App offers to sign in again; the Diary and unsynchronized edits stay on the Device.

5.7. The Operator does not request or process passwords for your email. Access to the Account is protected by control over access to the mailbox specified at sign-in.

5.8. The server side of the App is hosted in the territory of the Russian Federation.

6. Analytics and Diagnostics

6.1. To assess operational stability and understand which features are in demand, the App uses the Yandex AppMetrica service (the right holder is YANDEX LLC).

6.2. The following is processed via this service:

  • the App installation identifier assigned by the service, and the service identifier of the profile: a random one for a local profile, the Account identifier after signing in. It allows the Operator to match a crash report with a User's enquiry in which the User quoted their identifier (section 17); the email address is not transferred to analytics;
  • technical information about the Device: model, operating system version, language, screen resolution, connection type;
  • information about the App version, installations, updates and launches;
  • usage events: which screens were opened and which actions were performed (sign-in and sign-out, adding, editing and deleting an Entry, rating a Day, opening the Insights, the Export, changing settings), as well as aggregated counters (for example, the number of Entries of a Day or the number of Days in an Export) — in depersonalized form, without the texts of Entries and notes and without the Day Ratings themselves;
  • information about errors and crashes, including the log of technical events of the App preceding the failure; the contents of the Diary are not written to the log;
  • the IP address, from which the servers of the service determine the approximate location down to the region. The App does not request or receive access to the geolocation of the Device.

6.3. The texts of Entries and notes, the Day Ratings and the results of the Insights are not transferred to analytics.

6.4. Collection of advertising identifiers (IDFA on iOS, Advertising ID on Android) is disabled. The App does not track Users across other apps and websites and does not transfer data to advertising networks.

6.5. The AppMetrica servers are located in the territory of the Russian Federation.

6.6. Terms of use of the service: https://yandex.ru/legal/appmetrica_termsofuse/

7. Export of the Diary

7.1. At the User's request, the App builds the Diary into a table file (date, time, food, wellbeing, since when, note) right on the Device and hands it to the system "Share" menu. The file is not sent to the Operator's server; the Export works without an Account and without a network connection.

7.2. Where the file goes next — to mail, a messenger, a file storage or another application — is chosen by the User; further processing of the file is governed by the terms of the chosen application.

8. What Is Not Processed

  • the geolocation of the Device (location access permission is not requested);
  • the camera, photographs and media library, microphone, contact list, the Device's calendar, files outside the App's Local storage — the App does not request access to any of these;
  • information from health apps and fitness trackers, readings of the Device's sensors;
  • advertising identifiers and any cross-service identifiers for transfer to advertising networks;
  • payment data and bank card data — the App has no paid features;
  • biometric personal data.

The App does not ask the User for information about diagnoses, prescriptions, medications or medical measurements. A Day Rating is one of three values at the User's discretion, and its note is free text; the Operator does not read or analyze them (clause 5.3).

9. Purposes of Processing

Data is processed solely so that:

  • the App performs its functions: shows your Diary and the Insights over it, preserves the Entries, Ratings and settings between launches, builds the Export;
  • when an Account is used — the User is identified at sign-in and their Diary is transferred between their Devices;
  • the stability and security of the App's operation are ensured, and errors are found and fixed;
  • enquiries from Users are answered.

Profiling, legally significant automated decision-making, marketing mailings and transfer of data for advertising purposes are not carried out.

11. Transfer of Data to Third Parties

11.1. The Operator does not sell personal data and does not transfer it for marketing purposes.

11.2. Data may be transferred to the following categories of recipients, and only to the extent necessary for the operation of the App:

  • YANDEX LLC (the AppMetrica service) — the depersonalized technical, diagnostic and behavioral data listed in section 6. Servers in the Russian Federation;
  • technical infrastructure providers engaged by the Operator to host the server side of the App and to deliver sign-in code emails. Such providers act on the instructions of the Operator, process data solely to the extent necessary to provide the respective service and may not use it for their own purposes. The servers are located in the territory of the Russian Federation;
  • app stores (Google Play, App Store) — with respect to the distribution of the App and aggregated download statistics, under their own policies;
  • authorized state bodies — in cases expressly provided for by law.

11.3. No cross-border transfer of personal data takes place: the server side and the analytics service are hosted in the territory of the Russian Federation.

12. Retention Periods

12.1. Data on the Device is stored until the User deletes it (section 14) or deletes the App.

12.2. Account data is stored for as long as the Account exists. After its deletion, personal data is deleted; individual records may be retained for a limited period where required by law or for the resolution of disputes, after which they are deleted or depersonalized.

12.3. A deleted Entry stops being shown, is left out of the Insights and does not go into the Export; its text is erased, and only a deletion mark with its time is kept inside the Day — so that the deletion reaches the User's other Devices and is not undone by an older copy. Such marks are erased together with the Days when the Account is deleted.

12.4. Server logs are kept for a limited period needed to ensure security and fix errors, after which they are deleted.

12.5. Information in AppMetrica is stored in accordance with the terms of the service.

13. Data Storage and Protection

13.1. On the Device, data is stored in the private (sandbox) directory of the App, inaccessible to other apps.

13.2. The Local storage is encrypted; the encryption key is generated on the Device and kept in the protected system storage of the operating system.

13.3. Data exchange with the server and the analytics service is performed over the secure HTTPS protocol.

13.4. The Operator applies organizational and technical measures to protect data from unauthorized access, modification, disclosure and destruction.

13.5. Absolute protection cannot be guaranteed: the safety of data also depends on the physical safety of the Device, on it being locked with a passcode and on the User's control over the mailbox specified at sign-in.

14. Data Deletion

14.1. The Account can be deleted in the App itself: Settings → "Account" → "Delete the account" → "Delete". The Account and its whole Diary are erased on the server immediately and irreversibly. The Diary on this Device is kept in that case — as a local one, without an Account; it can be erased by removing the App (clause 14.4). Deleting the Account requires a network connection.

14.2. Signing out of the Account — Settings → "Account" → "Sign out" — sends unsynchronized edits to the server and stops synchronization on this Device, so it requires a network connection. The Account and its Diary on the server are kept, and signing in with the same address resumes synchronization; the Diary on the Device is kept as a local one.

14.3. An individual Entry can be deleted at any moment by opening it and tapping the delete icon, with a confirmation; the deletion is passed on to the other Devices during synchronization (clause 12.3). A Day Rating and its note can be changed at any moment. A deleted Entry cannot be restored.

14.4. Removing the App from the Device erases all of its Local storage: the Diary — including one left local after the Account was deleted — and the settings. It is the only way to erase the Diary from the Device entirely.

14.5. You can also send a deletion request to sito@alexforge.org from the email address specified in the Account.

15. User Rights

The User has the right to:

  • receive information about the processing of their personal data;
  • demand the rectification, blocking or deletion of their data;
  • withdraw consent to data processing by deleting the Account, as well as by ceasing to use the App and removing it from the Device;
  • file a complaint with the authorized body for the protection of the rights of personal data subjects.

To exercise these rights, send a request to sito@alexforge.org. A response is provided within the period established by law.

16. Device Permissions

PermissionWhen requestedPurpose
Internetno prompt, standard accesssign-in, synchronization, transfer of statistics
Network stateno prompt, standard accessknow whether there is a connection and not attempt to synchronize without one

The App requests no other permissions — camera, photographs, geolocation, contacts, notifications, health app data. Passing the Export on goes through the system "Share" menu and needs no separate permission. Keeping the Diary works without a network connection.

17. Feedback

The "Send feedback" item in the settings opens your mail client with a draft message to the Operator's address. The identifier of your profile is inserted into the draft — it allows the Operator to match your enquiry with crash reports (section 6). If you do not want to share it, delete this block before sending. The email you send is processed in order to answer your enquiry.

18. Children

The App is not intended for use by persons under the age at which independent consent to the processing of personal data is permitted under applicable law. The Operator does not knowingly collect data of minors. If you become aware that a minor's data has been provided without the consent of a legal representative, report this to sito@alexforge.org so that it can be deleted.

19. Changes to This Policy

The Operator may update this Policy. The current version is always available at the address where the Policy is published; the date of the last update is indicated at the beginning of the document. Material changes are communicated to Users by means of the App or in another available way.

20. Contacts

For all questions related to this Policy and data processing:

Operator: Alexander Sergeevich Seednov
Status: individual (natural person)
Email: sito@alexforge.org