Privacy Policy
Last updated: 19 August 2025
Introduction

This Privacy Notice for SHINE DEVELOPMENT AND AI TECHNOLOGIES LTD (doing business as Shine AI) (‘we’, ‘us’, or ‘our’) describes how and why we may access, collect, store, use, and/or share (‘process’) your personal information when you use our services (‘Services’), including when you:

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for deciding how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@shine-official.net or median.ai.official@gmail.com.

Summary of Key Points

This section highlights key points from our Privacy Notice. For details, follow the links at the end of each point or use the table of contents to jump to the relevant section.

Want to learn more about what we do with the information we collect? Review the Privacy Notice in full.

Table of Contents
  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on to process your personal information?
  4. When and with whom do we share your personal information?
  5. Do we offer artificial intelligence-based products?
  6. Is your information transferred internationally?
  7. How long do we keep your information?
  8. How do we keep your information safe?
  9. Do we collect information from minors?
  10. What are your privacy rights?
  11. Controls for Do-Not-Track features
  12. Do United States residents have specific privacy rights?
  13. AI-based nutrition analysis
  14. No medical advice disclaimer
  15. WhatsApp-based communication
  16. Third-party services used
  17. Data retention
  18. Do we make updates to this Notice?
  19. How can you contact us about this Notice?
  20. How can you review, update, or delete the data we collect from you?
1. What Information Do We Collect?
Personal information you disclose to us

In short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you register or sign in, use the Services, request support, make purchases or manage subscriptions, or otherwise contact us. The types of information we collect depend on your interactions and the features you use.

Categories of personal information
Sensitive (special category) information

Where required by law, we process health-related inputs only with your consent and solely to provide personalised nutrition analysis and educational insights. You may delete these inputs at any time in-app or by contacting us. See Your privacy rights.

Payment data

Purchases are processed by the applicable app store or our payment provider. On Android and iOS, transactions are handled by Google Play Billing and Apple In-App Purchases; where applicable on web, payments may be processed by Paddle. We do not receive or store your full payment card number or security code. We receive limited information such as transaction identifiers and subscription status necessary to provide the Service and manage your purchases.

Information we do not collect
Accuracy of your information

All personal information you provide must be true, complete, and accurate, and you should notify us of any changes to such information.

For how we use these categories, see How do we process your information?. For sharing with service providers (e.g. Firebase us-central1, Twilio, Apple/Google/Paddle), see When and with whom we share information.

2. How Do We Process Your Information?

In short: We process your information to provide, improve, and administer the Services; communicate with you; prevent fraud and abuse; and comply with law. We process personal information only when we have a valid legal basis and, where required, your consent.

Purposes of processing
AI-assisted nutrition analysis and content
4. When and With Whom Do We Share Your Personal Information?

In short: We share information only in specific situations and with service providers that help us operate the Services. These third parties act on our instructions under contracts that require confidentiality, appropriate safeguards, and deletion at our direction. We do not sell or “share” personal information for cross-context behavioural advertising, and we do not use advertising or analytics SDKs.

Service providers and partners
Category Vendor(s) Purpose Location/Notes
Cloud platform & database Google Cloud – Firebase (Realtime Database) Primary hosting and storage; authentication; security rules; service logs United States (us-central1); encrypted in transit/at rest; Firebase Security Rules & App Check
Phone verification & WhatsApp Twilio Phone verification and administrative WhatsApp messages (no marketing) Administrative communications only; content limited to service matters
App-store billing Google Play Billing (Android), Apple In-App Purchases (iOS) Process purchases, subscriptions, refunds We do not receive full card numbers or CVV
Payments (where applicable) Paddle Payment processing for eligible web transactions Limited transaction metadata to operate subscriptions
AI content services OpenAI, Google De-identified, generic content generation (e.g., phrasing of tips) No health or personal data sent; no training on our data
Other situations where sharing may occur
5. Do We Offer Artificial Intelligence-Based Products?

In short: Yes. Certain features use AI to generate educational guidance and explanations. These features are governed by this Privacy Notice and are not a substitute for professional medical advice. See No medical advice.

Use of AI technologies
What our AI features do
How we process data using AI

All AI-related processing aligns with this Notice and our vendor agreements. We apply technical and organisational safeguards and restrict prompts to de-identified content. We may analyse aggregate, de-identified usage patterns to improve our features; this analysis does not train third-party models and does not identify you.

How to opt out

If you prefer not to use AI-assisted features, you may limit your use of those features and/or contact us at median.ai.official@gmail.com or info@shine-official.net to discuss options. You can also delete your health inputs or your account at any time; see How to review, update, or delete data.

6. Is Your Information Transferred Internationally?

In short: Yes. We may transfer, store, and process your information in countries other than your own.

Our primary hosting is provided by Google Firebase in the United States (us-central1). If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and in other countries where our service providers (see When and with whom we share information) operate.

If you are located in the EEA, UK, or Switzerland, please note that these countries may not provide the same level of data protection as your home jurisdiction. We implement appropriate safeguards to protect your personal information in accordance with this Notice and applicable law.

Standard Contractual Clauses (SCCs)

For transfers of personal information from the EEA/UK to countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum where applicable) with our service providers. These require recipients to protect personal information in line with European data protection laws. Details of these safeguards can be provided upon request.

Note: We do not currently use EU-region Firebase hosting; data is hosted in us-central1 with SCCs and vendor safeguards in place.

7. How Long Do We Keep Your Information?

In short: We keep personal information only as long as necessary for the purposes described in this Notice, unless a longer retention is required or permitted by law (e.g., tax or accounting obligations).

Our retention approach

When we no longer have an ongoing legitimate business need to process your personal information, we will delete or de-identify it. If immediate deletion is not possible (for example, because data resides in backup archives), we will securely store it and isolate it from further processing until deletion is possible.

You can request deletion or access your data at any time; see How to review, update, or delete your data.

8. How Do We Keep Your Information Safe?

In short: We protect your personal information with a combination of organisational and technical measures.

Despite our safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee that unauthorised third parties will never defeat our security. Transmission of personal information to and from the Services is at your own risk; please access the Services in a secure environment.

9. Do We Collect Information from Minors?

In short: We do not knowingly collect data from or market to children under 13 years of age (or 16 in the EEA/UK, where required).

By using the Services, you represent that you are at least 13 years old (or 16 in the EEA/UK, as applicable), or that you are the parent or legal guardian of a minor and consent to their use of the Services. If we learn that we have collected personal information from a child under the applicable minimum age, we will deactivate the account and take reasonable steps to delete the data promptly.

If you believe we may have collected data from a child under the applicable age, please contact us at median.ai.official@gmail.com or info@shine-official.net.

10. What Are Your Privacy Rights?

In short: Depending on your location (e.g., EEA, UK, Switzerland, Canada, certain US states), you may have rights that give you greater control over your personal information. You may review, change, or terminate your account at any time.

Your rights may include
How to exercise your rights

We will consider and act upon any request in accordance with applicable data protection laws, typically within 30 days (and longer where permitted).

Supervisory authorities

If you are in the EEA, you may lodge a complaint with your local supervisory authority. If you are in the UK, you may contact the Information Commissioner’s Office (ICO). If you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC).

Account information

If you have questions or comments about your privacy rights, contact us at median.ai.official@gmail.com.

11. Controls for Do-Not-Track Features

Most web browsers and some mobile operating systems and applications include a Do-Not-Track (“DNT”) setting you can activate to signal that you prefer not to be tracked online. At present, no uniform standard for recognising and responding to DNT signals has been finalised, and we do not currently respond to such signals or similar mechanisms.

If an industry or legal standard for online tracking is adopted that we must follow, we will update this Privacy Notice to describe our response. California law requires us to state how we respond to browser DNT signals; because there is no recognised standard, we do not respond at this time.

12. Do United States Residents Have Specific Privacy Rights?

In short: Depending on your U.S. state of residence, you may have rights to access, correct, obtain a copy of, or delete personal information we maintain about you, as well as rights to opt out of certain processing. These rights may be limited by applicable law.

Categories of personal information collected (past 12 months)
Category Examples Collected
A. Identifiers Phone number; IP address; account identifiers Yes
B. Protected classification characteristics Race, ethnicity, religion, etc. No
C. Commercial information Transaction identifiers; subscription status Yes (limited)
D. Biometric information Fingerprints, voiceprints No
E. Internet or other network activity Service logs (e.g., device/app events, timestamps, IP) Yes
F. Geolocation data Precise device location No
G. Audio/visual/electronic Images; audio or call recordings No
H. Professional or employment-related Job title; work history (outside recruiting) No
I. Education information Student records; directory information No
J. Inferences Derived insights such as nutrition balance indicators Yes
K. Sensitive personal information Health data you provide (e.g., conditions, allergies) Yes

We collect personal information directly from you (including your entries in the app) and from your device/service logs. We do not use advertising or analytics SDKs and do not collect precise geolocation.

Use, sharing, and retention
Your U.S. state privacy rights
How to exercise your rights

You may designate an authorised agent to submit a request on your behalf, subject to verification and applicable law. We will verify requests using information already on file and may request additional details to confirm identity or authority.

13. AI-Based Nutrition Analysis

We use artificial intelligence (AI) and rules-based algorithms to analyse the health and lifestyle information you provide in order to generate personalised, educational nutrition guidance. This includes drawing inferences such as estimated nutrient intake and dietary needs derived from your logged meals and profile data.

See also Third-party services and No medical advice.

14. No Medical Advice Disclaimer

Median is for educational purposes only. It is not a medical device and does not replace professional medical advice, diagnosis, or treatment. The app does not recommend medications or herbs. Always consult your physician.

15. WhatsApp-Based Communication

We may contact users through WhatsApp for service-related purposes, such as confirming subscription status, sending payment instructions, or providing technical support. These communications are administrative in nature and do not include marketing content.

WhatsApp messaging is facilitated via our provider Twilio. See Third-party services.

16. Third-Party Services Used

We engage service providers under contract to help us operate the Services. They process personal information only on our instructions and subject to confidentiality and security obligations.

Service Provider What they do Notes
Hosting & database Google Cloud – Firebase (Realtime Database) Primary storage/hosting; authentication; service logs United States (us-central1); encryption in transit/at rest; Security Rules & App Check
Phone verification & WhatsApp Twilio WhatsApp verification and administrative messaging (no marketing) Message content limited to service purposes
App-store billing Google Play Billing (Android), Apple In-App Purchases (iOS) Process purchases, subscriptions, refunds No access to full card numbers/CVV
Payments (web, where applicable) Paddle Payment processing for eligible web transactions Limited transaction metadata for subscription management
AI content services OpenAI, Google De-identified, generic content generation (e.g., phrasing of tips) No health/personal data sent; no training on our data
17. Data Retention

We retain personal data—including AI-generated insights—only while your account is active and as needed to operate the Service. When you delete your account, we delete personal data from production systems promptly. Operational backups may persist for up to 30 days and are then purged automatically.

To prevent repeat free-trial abuse, we keep a one-way hashed token derived from your phone number for 12 months. This hash is stored separately, cannot be used to contact you, and is deleted after the retention period. Limited transaction records may be retained as required by law.

For full details, see How long do we keep your information?.

18. Do We Make Updates to This Notice?

In short: Yes. We will update this Notice as necessary to remain compliant and transparent.

We may update this Privacy Notice from time to time. The updated version will be indicated by a revised date at the top of this page. If we make material changes, we may provide additional notice (e.g., in-app banner, email, or WhatsApp administrative notice). We encourage you to review this Notice periodically to stay informed about how we protect your information.

19. How Can You Contact Us About This Notice?

If you have questions or comments about this Notice, please email us at median.ai.official@gmail.com or info@shine-official.net, or contact us by post at:

SHINE DEVELOPMENT AND AI TECHNOLOGIES LTD
71–75 Shelton Street
Covent Garden
London WC2H 9JQ
England

Website: https://shine-official.net/

If you are a resident in the United Kingdom, SHINE DEVELOPMENT AND AI TECHNOLOGIES LTD is the data controller of your personal information. You can contact us using the details above regarding our processing of your information.

20. How Can You Review, Update, or Delete the Data We Collect From You?

Depending on your country, province, or U.S. state of residence, you may have the right to request access to the personal information we hold about you, learn how it has been processed, correct inaccuracies, delete your personal information, or withdraw consent where applicable. These rights may be limited in some circumstances by law.

How to make a request

We will verify your request and respond in accordance with applicable data protection laws (typically within 30 days). For more details on your rights, see What are your privacy rights?.