# Privacy Policy / นโยบายความเป็นส่วนตัว — KinD (กินดี)
**Effective date / วันที่มีผลบังคับใช้:** 8 ก.ค. 2026
**Last updated / ปรับปรุงล่าสุด:** 11 ส.ค. 2026 (ลดอายุขั้นต่ำเป็น 13 ปี + เพิ่มข้อผู้ใช้อายุ 13–17 ปี)
**App / แอปพลิเคชัน:** KinD - กินดี
**Data controller / ผู้ควบคุมข้อมูลส่วนบุคคล:** อรรถชัย ใบนานา (an individual developer / นักพัฒนารายบุคคล)
**Contact / ติดต่อ:** [email protected]
> KinD is a prescriptive meal-planning and nutrition app for Thailand. It is **local-first**: your data is created and stored on your device by default, and the app works fully offline. Some optional features (AI Quick Log, community recipe sharing with sign-in, ads, analytics, crash reporting) send limited data to third-party services, and only under the conditions described below.
>
> KinD เป็นแอปวางแผนมื้ออาหารและโภชนาการสำหรับประเทศไทย ทำงานแบบ **local-first** คือข้อมูลของคุณถูกสร้างและเก็บไว้บนเครื่องของคุณเป็นค่าเริ่มต้น และใช้งานแบบออฟไลน์ได้เต็มรูปแบบ ฟีเจอร์บางอย่าง (AI Quick Log, การแชร์สูตรสู่ชุมชนพร้อมการเข้าสู่ระบบ, โฆษณา, การวิเคราะห์การใช้งาน, การรายงานข้อผิดพลาด) จะส่งข้อมูลบางส่วนไปยังผู้ให้บริการภายนอกตามเงื่อนไขที่อธิบายไว้ด้านล่างเท่านั้น
---
# ภาษาไทย (Thai)
## 1. เราคือใคร และนโยบายนี้ครอบคลุมอะไร
นโยบายฉบับนี้อธิบายว่าแอป KinD (กินดี) เก็บ ใช้ เปิดเผย และคุ้มครองข้อมูลส่วนบุคคลของคุณอย่างไร ผู้ควบคุมข้อมูลส่วนบุคคลคือ อรรถชัย ใบนานา ซึ่งเป็นนักพัฒนารายบุคคล (ต่อไปนี้เรียกว่า "เรา")
- แอปนี้มุ่งให้บริการผู้ใช้ในประเทศไทยเป็นหลัก จึงอยู่ภายใต้ **พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)**
- หากคุณใช้งานจากสหภาพยุโรป/เขตเศรษฐกิจยุโรป (EU/EEA) หรือสหราชอาณาจักร ข้อกำหนดตาม **GDPR/UK GDPR** จะมีผลใช้บังคับด้วย (ดูข้อ 11)
- เนื่องจากเราเป็นนักพัฒนารายบุคคล/สตูดิโอขนาดเล็ก จึงยังไม่มีหน้าที่ตามกฎหมายในการแต่งตั้งเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) อย่างเป็นทางการ แต่คุณสามารถติดต่อเราเรื่องข้อมูลส่วนบุคคลได้ที่อีเมล [email protected]
## 2. ข้อมูลที่เราเก็บรวบรวม
**ก. ข้อมูลที่คุณกรอกเอง (เก็บบนเครื่องเป็นค่าเริ่มต้น)**
- ข้อมูลโปรไฟล์และสุขภาพ: ชื่อ (ไม่บังคับ), เพศ, อายุ/วันเกิด, ส่วนสูง, น้ำหนัก, เปอร์เซ็นต์ไขมันในร่างกาย, ระดับกิจกรรม, เป้าหมาย, ความชอบด้านอาหาร, **อาหารที่แพ้**, **โรคประจำตัว/ภาวะสุขภาพ**, งบประมาณต่อวัน, ทักษะการทำอาหาร, เป้าหมายการดื่มน้ำ
- บันทึกอาหาร/กิจกรรม: มื้อที่รับประทาน, ประวัติน้ำหนัก, สถิติต่อเนื่อง (streaks)
ข้อมูลเกี่ยวกับ **อาหารที่แพ้ โรคประจำตัว/ภาวะสุขภาพ** ถือเป็น **ข้อมูลส่วนบุคคลอ่อนไหว** ตาม PDPA มาตรา 26 เราจะประมวลผลข้อมูลนี้บนพื้นฐาน **ความยินยอมโดยชัดแจ้ง** ของคุณ และตามค่าเริ่มต้นข้อมูลนี้จะอยู่บนเครื่องของคุณเท่านั้น (ยกเว้นกรณีฟีเจอร์ซิงก์ข้อมูลเปิดให้บริการและคุณเปิดใช้ในอนาคต — ดูข้อ 2.จ)
**ข. รหัสอุปกรณ์แบบไม่ระบุตัวตน (Anonymous device ID)**
- เมื่อเปิดแอปครั้งแรก ระบบจะสร้างรหัสอุปกรณ์แบบสุ่ม (UUID) เก็บไว้บนเครื่อง ใช้เป็นรหัสผู้ใช้ภายในเครื่อง รหัสนี้ **ไม่ผูกกับตัวตนจริงของคุณ**
**ค. AI Quick Log (ฟีเจอร์เสริม — ต้องยินยอมก่อน)**
- คุณสามารถพิมพ์คำอธิบายอาหาร หรือถ่าย/อัปโหลด **รูปภาพอาหาร** เพื่อให้ระบบประเมินแคลอรี่/สารอาหาร ข้อความหรือรูปภาพนี้จะถูกส่งไปยังโมเดล AI **Google Gemini ผ่านพร็อกซี Supabase Edge Function ของเรา** เพื่อประมวลผลและส่งค่าประเมินกลับมา
- สมาชิก Pro สามารถ **พูดใส่ไมโครโฟน** แทนการพิมพ์ได้ การแปลงเสียงเป็นข้อความทำโดย **ระบบรู้จำเสียงของอุปกรณ์** (Apple/Google ตามนโยบายของแพลตฟอร์มนั้น) — แอปไม่บันทึกหรือเก็บไฟล์เสียงไว้ และส่ง **เฉพาะข้อความที่แปลงแล้ว** ไปประมวลผลแบบเดียวกับการพิมพ์ทุกประการ · ใช้สิทธิ์ไมโครโฟนซึ่งคุณปฏิเสธหรือปิดภายหลังได้ในตั้งค่าเครื่อง
- ก่อนใช้งานครั้งแรกจะมี **หน้าจอขอความยินยอมในแอป** (ค่าเริ่มต้นคือ "ไม่ยินยอม") และคุณสามารถปฏิเสธหรือถอนความยินยอมได้ตลอดเวลา
- ข้อความ/รูปภาพถูกส่งไปเพื่อ **ประมวลผลให้ได้ค่าประเมินโภชนาการเท่านั้น** เราไม่นำไปใช้สร้างโปรไฟล์เพื่อการโฆษณา และพร็อกซีของเราทำหน้าที่ส่งต่อคำขอ (pass-through) ไม่ได้เก็บสำเนารูป/ข้อความไว้เพื่อวัตถุประสงค์อื่น เราใช้ Gemini API แบบมีค่าบริการ (paid tier) ซึ่งตามเงื่อนไขของ Google **ข้อความ/รูปที่ส่งไปประมวลผลจะไม่ถูกนำไปใช้ฝึกหรือปรับปรุงโมเดล/ผลิตภัณฑ์ของ Google และไม่มีการให้มนุษย์ตรวจทานเพื่อการพัฒนาผลิตภัณฑ์** โดย Google จะเก็บบันทึกคำขอ/คำตอบไว้เพียงช่วงเวลาจำกัดเพื่อตรวจจับการใช้งานที่ผิดเงื่อนไขและรักษาความปลอดภัยของบริการเท่านั้น แล้วจึงลบ
- นี่คือ **การส่งข้อมูลไปต่างประเทศ** (เซิร์ฟเวอร์ของ Google/Supabase ซึ่งอาจอยู่นอกประเทศไทย เช่น สหรัฐอเมริกา — ดูข้อ 6)
**ง. การสแกนบาร์โค้ด**
- เมื่อสแกนบาร์โค้ดสินค้า แอปจะส่ง **เฉพาะเลขบาร์โค้ด** ไปยัง **Open Food Facts** เพื่อค้นหาข้อมูลโภชนาการของสินค้า ไม่มีการส่งข้อมูลส่วนบุคคลของคุณ
**จ. บัญชีผู้ใช้ — จำเป็นเฉพาะการแชร์สูตรสู่ชุมชน (ฟีเจอร์เสริม)**
- การลงสูตรสู่ชุมชน (ดูข้อ 2.ฎ) ต้องเข้าสู่ระบบด้วยบัญชี **Google หรือ Apple** ผ่าน **Supabase Auth** ก่อน เราได้รับและเก็บ **อีเมลของบัญชี** นั้นไว้กับระบบยืนยันตัวตน เพื่อยืนยันความเป็นเจ้าของสูตรและป้องกันการแอบอ้าง — อีเมลไม่แสดงต่อผู้ใช้คนอื่น และเราไม่เข้าถึงข้อมูลอื่นใดในบัญชี Google/Apple ของคุณ
- ฟีเจอร์อื่นทั้งหมดของแอปใช้ได้โดยไม่ต้องมีบัญชี · ออกจากระบบได้ทุกเมื่อที่ โปรไฟล์ → บัญชี · การลบบัญชีจะลบอีเมลและสูตรที่แชร์ไว้ออกจากเซิร์ฟเวอร์
- หากในอนาคตเราเปิดฟีเจอร์ **ซิงก์ข้อมูลข้ามอุปกรณ์ (Pro)** ข้อมูลโปรไฟล์ (รวมถึงข้อมูลสุขภาพอ่อนไหวข้างต้น), บันทึกรายวัน และประวัติน้ำหนัก จะถูกจัดเก็บใน **Supabase** และ **ข้อมูลสุขภาพอ่อนไหวจะออกจากเครื่องของคุณ** ในกรณีนั้น — เราจะประมวลผลบนฐาน **ความยินยอมโดยชัดแจ้ง** + การปฏิบัติตามสัญญาบริการ และจะแจ้งในแอปก่อนเปิดใช้ (ปัจจุบันฟีเจอร์นี้ยังไม่เปิดให้บริการ)
**ฉ. การซื้อ/การสมัครสมาชิก Pro**
- การชำระเงินดำเนินการผ่าน **Google Play Billing / Apple App Store** และตรวจสอบใบเสร็จผ่าน **RevenueCat** เราไม่เก็บหมายเลขบัตรของคุณ แต่จะทราบสถานะการสมัครสมาชิก (เช่น ใช้งานอยู่/หมดอายุ) และตัวระบุการซื้อ
**ช. โฆษณา (เฉพาะผู้ใช้ฟรี)**
- แอปแสดงโฆษณาผ่าน **Google AdMob** ซึ่งอาจเก็บ **ตัวระบุเพื่อการโฆษณา (advertising ID)** และข้อมูลอุปกรณ์
- บน iOS เราจะแสดง **App Tracking Transparency (ATT)** และใช้ **Google UMP** เพื่อขอความยินยอม หากคุณไม่ยินยอม จะแสดงเฉพาะ **โฆษณาแบบไม่ปรับตามความสนใจ (non-personalized)**
- ผู้ใช้ Pro และช่วง 3 วันแรกหลังติดตั้งจะไม่เห็นโฆษณา และจะไม่มีโฆษณาบนหน้า Today, onboarding, หน้าความปลอดภัย หรือหน้าชำระเงิน
**ซ. การวิเคราะห์การใช้งาน (ขึ้นกับความยินยอม)**
- เราอาจใช้ **PostHog** เพื่อเข้าใจการใช้งานแอปในภาพรวม การวิเคราะห์นี้ **ปิดอยู่เป็นค่าเริ่มต้น** และทำงานเฉพาะเมื่อคุณยินยอมเท่านั้น
**ฌ. การรายงานข้อผิดพลาด/การวินิจฉัย**
- เราอาจใช้ **Sentry** เพื่อรับรายงานการขัดข้องและข้อมูลวินิจฉัยทางเทคนิค (เช่น รุ่นอุปกรณ์, เวอร์ชัน OS, stack trace) เพื่อแก้ไขข้อบกพร่อง
**ญ. สิทธิ์การเข้าถึงบนอุปกรณ์**
- **กล้อง** — สำหรับสแกนบาร์โค้ดและถ่ายรูปอาหาร
- **การแจ้งเตือน / การตั้งปลุกแบบตรงเวลา (exact alarm)** — สำหรับการเตือนการทำ Intermittent Fasting และการแจ้งเตือนภายในเครื่อง (local notifications)
**ฎ. การแชร์สูตรอาหารสู่ชุมชน (เลือกได้ ไม่บังคับ)**
เมื่อคุณเลือก **"แชร์ให้ทุกคน"** กับสูตรอาหารของคุณ ข้อมูลต่อไปนี้จะถูกส่งไปเก็บบนเซิร์ฟเวอร์ของเรา (Supabase) และ **แสดงต่อผู้ใช้คนอื่นแบบสาธารณะ**:
- เนื้อหาสูตร: ชื่อเมนู วัตถุดิบ ปริมาณ ขั้นตอนทำ และค่าโภชนาการ
- รูปภาพเมนู (ถ้าคุณใส่ไว้)
- ชื่อที่แสดง (ชื่อจากโปรไฟล์ของคุณ) — เราแนะนำให้ใช้ชื่อเล่น
- รหัสอุปกรณ์แบบไม่ระบุตัวตน และรหัสบัญชีของคุณ (ใช้ผูกความเป็นเจ้าของสูตร ไม่แสดงต่อผู้อื่น)
สิ่งที่ควรทราบ:
- สูตรที่แชร์จะผ่าน **การตรวจอัตโนมัติด้วย AI** ก่อนเผยแพร่ (ตรวจว่าเป็นสูตรอาหารจริง ไม่มีเนื้อหาไม่เหมาะสม/อันตราย/ข้อมูลส่วนตัว) — เนื้อหาสูตรจะถูกส่งไปยังบริการ AI (Google Gemini) เพื่อการตรวจนี้ เช่นเดียวกับฟีเจอร์ AI อื่นในแอป
- สูตรที่กรอกโภชนาการเองโดยไม่ผ่าน AI จะ **แชร์ไม่ได้** (เก็บส่วนตัวเท่านั้น)
- คุณ **ถอนการแชร์ได้ทุกเมื่อ** — เปลี่ยนสูตรกลับเป็น "เก็บส่วนตัว" หรือใช้ปุ่มถอนแชร์/ลบสูตรในหน้าแก้ไขสูตร ระบบจะลบสูตรและรูปออกจากเซิร์ฟเวอร์
- ผู้ใช้คนอื่นสามารถ **รายงาน** สูตรที่ไม่เหมาะสมได้ สูตรที่ถูกรายงานจากหลายอุปกรณ์จะถูกซ่อนโดยอัตโนมัติระหว่างรอทีมงานตรวจสอบ (ภายใน 24 ชั่วโมง)
- ค่าโภชนาการของสูตรชุมชนเป็น **ค่าประมาณโดย AI** ไม่ใช่คำแนะนำทางการแพทย์
- การลบบัญชี/ข้อมูล (ดูข้อ 8) ครอบคลุมสูตรที่คุณแชร์ไว้ด้วย — หรือแจ้งลบเฉพาะสูตรได้ที่อีเมลติดต่อในข้อ 12
## 3. เราใช้ข้อมูลเพื่ออะไร และฐานทางกฎหมาย
| วัตถุประสงค์ | ฐานทางกฎหมาย (PDPA / GDPR) |
|---|---|
| ให้บริการหลักของแอป (คำนวณเป้าหมาย, แนะนำเมนู, บันทึกอาหาร, งบประมาณ) | การปฏิบัติตามสัญญา / ประโยชน์โดยชอบด้วยกฎหมาย |
| ประมวลผลข้อมูลสุขภาพอ่อนไหว (อาหารที่แพ้, โรคประจำตัว) | **ความยินยอมโดยชัดแจ้ง** |
| AI Quick Log (ส่งข้อความ/รูปไปประมวลผลข้ามประเทศ) | **ความยินยอมโดยชัดแจ้ง** |
| บัญชีผู้ใช้ (อีเมล) สำหรับการแชร์สูตร | การปฏิบัติตามสัญญา + ประโยชน์โดยชอบด้วยกฎหมาย (ป้องกันการแอบอ้าง) |
| การแชร์สูตรสู่ชุมชน (เผยแพร่เนื้อหาสาธารณะ + ตรวจด้วย AI ก่อนเผยแพร่) | การปฏิบัติตามสัญญา (ตามที่คุณเลือกแชร์) |
| การซื้อ/สมัครสมาชิก | การปฏิบัติตามสัญญา |
| โฆษณาแบบปรับตามความสนใจ | **ความยินยอม** (ATT/UMP) |
| โฆษณาแบบไม่ปรับตามความสนใจ | ประโยชน์โดยชอบด้วยกฎหมาย |
| การวิเคราะห์การใช้งาน | **ความยินยอม** |
| การรายงานข้อผิดพลาด/ความปลอดภัย | ประโยชน์โดยชอบด้วยกฎหมาย |
| ปฏิบัติตามกฎหมายและตอบสนองคำขอใช้สิทธิ | หน้าที่ตามกฎหมาย |
## 4. การเปิดเผยและผู้ให้บริการภายนอก
เราไม่ขายข้อมูลส่วนบุคคลของคุณ เราเปิดเผย/แบ่งปันข้อมูลกับผู้ให้บริการภายนอกเท่าที่จำเป็นตามฟีเจอร์ที่คุณใช้เท่านั้น ดังนี้
| ผู้ให้บริการ | วัตถุประสงค์ | ข้อมูลที่เกี่ยวข้อง | นโยบายความเป็นส่วนตัว |
|---|---|---|---|
| Google (Gemini AI) | ประเมินโภชนาการจากข้อความ/รูป + ตรวจสูตรที่แชร์ก่อนเผยแพร่ | ข้อความ/รูปอาหารที่คุณส่ง, เนื้อหาสูตรที่แชร์ | <https://policies.google.com/privacy> |
| Google (AdMob) | แสดงโฆษณา (ผู้ใช้ฟรี) | advertising ID, ข้อมูลอุปกรณ์ | <https://policies.google.com/privacy> |
| Google (Sign-In) | เข้าสู่ระบบ (จำเป็นเฉพาะการแชร์สูตร) | อีเมล | <https://policies.google.com/privacy> |
| Apple (Sign in with Apple) | เข้าสู่ระบบ (iOS — จำเป็นเฉพาะการแชร์สูตร) | อีเมล/relay email | <https://www.apple.com/legal/privacy/> |
| Supabase | ระบบหลังบ้าน (พร็อกซี AI + auth + สูตรชุมชน) | อีเมล, สูตรที่แชร์ + รูป + ชื่อที่แสดง | <https://supabase.com/privacy> |
| RevenueCat | ตรวจสอบใบเสร็จ/สถานะสมาชิก | ตัวระบุการซื้อ, สถานะสมาชิก | <https://www.revenuecat.com/privacy> |
| Open Food Facts | ค้นหาข้อมูลสินค้าจากบาร์โค้ด | เลขบาร์โค้ด (ไม่มีข้อมูลส่วนบุคคล) | <https://world.openfoodfacts.org/terms-of-use> |
| Sentry | รายงานข้อผิดพลาด/วินิจฉัย | ข้อมูลการขัดข้อง, ข้อมูลอุปกรณ์ | <https://sentry.io/privacy/> |
| PostHog | วิเคราะห์การใช้งาน (เมื่อยินยอม) | เหตุการณ์การใช้งานแบบรวม | <https://posthog.com/privacy> |
ลิงก์นโยบายของผู้ให้บริการข้างต้นเป็นลิงก์ทางการ ณ วันที่จัดทำเอกสารนี้
## 5. การเก็บรักษาข้อมูล
- **ข้อมูลบนเครื่อง** — เก็บไว้จนกว่าคุณจะลบในแอป หรือถอนการติดตั้งแอป (การถอนการติดตั้งจะลบข้อมูลในเครื่อง)
- **สูตรที่แชร์สู่ชุมชน** — เก็บไว้จนกว่าคุณจะถอนการแชร์/ลบสูตร หรือลบบัญชี (ระบบลบสูตรและรูปออกจากเซิร์ฟเวอร์ทันที)
- **ข้อมูลบัญชี** — เก็บไว้ตราบเท่าที่บัญชียังใช้งาน และจะถูกลบออกจากฐานข้อมูลที่ใช้งานทันทีเมื่อคุณลบบัญชี (ดูข้อ 8) สำเนาที่อาจคงอยู่ในระบบสำรองข้อมูลตามปกติจะถูกลบภายในรอบการเก็บสำรองมาตรฐานของผู้ให้บริการ
- **AI Quick Log** — ข้อความ/รูปถูกใช้เพื่อสร้างค่าประเมินแล้วไม่ถูกเก็บโดยเราเพื่อวัตถุประสงค์อื่น สำหรับ Gemini API แบบมีค่าบริการ Google จะเก็บบันทึกไว้เพียงช่วงเวลาจำกัด (ปัจจุบันประมาณ 55 วันตามเงื่อนไขของ Google) เพื่อตรวจจับการใช้งานที่ผิดเงื่อนไขเท่านั้น แล้วจึงลบ และไม่นำไปใช้ฝึกโมเดล
- **โฆษณา / วิเคราะห์ / รายงานข้อผิดพลาด** — เป็นไปตามระยะเวลาที่ผู้ให้บริการแต่ละราย (Google/PostHog/Sentry) กำหนดไว้ในนโยบายของตน (ดูลิงก์ในข้อ 4)
## 6. การส่งหรือโอนข้อมูลไปต่างประเทศ
เมื่อคุณใช้ฟีเจอร์ที่พึ่งพาผู้ให้บริการภายนอก (AI Quick Log, การซิงก์ Pro, โฆษณา, การวิเคราะห์, การรายงานข้อผิดพลาด) ข้อมูลบางส่วนอาจถูกประมวลผล **นอกประเทศไทย** โดยระบบหลังบ้าน Supabase ของเราตั้งอยู่ในภูมิภาค **สิงคโปร์ (ap-southeast-1)** และผู้ให้บริการรายอื่น (Google/Gemini/AdMob, Sentry, PostHog) อาจประมวลผลในสหรัฐอเมริกาหรือภูมิภาคอื่น เราดำเนินการโอนข้อมูลดังกล่าวบนพื้นฐาน **ความยินยอมของคุณ** และ/หรือมาตรการคุ้มครองตามสัญญาของผู้ให้บริการ (เช่น Standard Contractual Clauses) ตามที่ PDPA และ GDPR กำหนด
## 7. ความปลอดภัยของข้อมูล
เราใช้มาตรการทางเทคนิคและองค์กรที่เหมาะสมตามสมควร เช่น การเข้ารหัสระหว่างการรับส่งข้อมูล (HTTPS/TLS), การจำกัดสิทธิ์การเข้าถึงฝั่งเซิร์ฟเวอร์ (Supabase Row-Level Security ผูกกับบัญชีผู้ใช้) และการเข้ารหัสข้อมูลขณะจัดเก็บ (at rest) ที่ผู้ให้บริการ Supabase จัดให้เป็นค่าเริ่มต้น ข้อมูลในเครื่องได้รับการปกป้องโดยระบบความปลอดภัยของอุปกรณ์คุณ อย่างไรก็ตาม ไม่มีระบบใดปลอดภัย 100% เราจึงไม่สามารถรับประกันความปลอดภัยได้อย่างสมบูรณ์
## 8. สิทธิของคุณ
**สิทธิของเจ้าของข้อมูลตาม PDPA** — คุณมีสิทธิ: เข้าถึงและขอสำเนาข้อมูล, แก้ไขให้ถูกต้อง, ลบ/ทำลาย, ระงับการใช้, คัดค้านการประมวลผล, ขอให้โอนย้ายข้อมูล (data portability), และ **ถอนความยินยอม** ได้ทุกเมื่อ
- **เข้าถึง/แก้ไข** — ข้อมูลส่วนใหญ่อยู่บนเครื่องและแก้ไขได้โดยตรงในแอป (หน้าโปรไฟล์/แก้ไขข้อมูล)
- **ลบบัญชีและข้อมูล** — แอปมีฟังก์ชันลบบัญชีที่จะลบข้อมูลฝั่งเซิร์ฟเวอร์และข้อมูลในเครื่อง
- **ถอนความยินยอม** — คุณปิด AI Quick Log และการวิเคราะห์ได้ในหน้า About/การตั้งค่า; การถอนการติดตั้งจะลบข้อมูลในเครื่อง
- คุณมีสิทธิ **ร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส. / PDPC)** หากเห็นว่าการประมวลผลไม่ชอบด้วยกฎหมาย
หากต้องการใช้สิทธิที่ทำผ่านแอปไม่ได้ ติดต่อ [email protected]
## 9. เด็กและเยาวชน
KinD มีไว้สำหรับผู้ใช้ **อายุ 13 ปีขึ้นไป** แอปมีการตรวจสอบอายุ (age gate) ที่บล็อกผู้ใช้อายุต่ำกว่า 13 ปี เราไม่ได้มุ่งให้บริการเด็กอายุต่ำกว่า 13 ปี และไม่เก็บข้อมูลจากผู้ที่อายุต่ำกว่า 13 ปีโดยเจตนา หากทราบว่ามีการเก็บข้อมูลของเด็กอายุต่ำกว่า 13 ปีโดยไม่ตั้งใจ เราจะดำเนินการลบ
**ผู้ใช้อายุ 13–17 ปี:** ตาม PDPA มาตรา 20 การให้ความยินยอมของผู้เยาว์ที่ยังไม่บรรลุนิติภาวะ อาจต้องได้รับความยินยอมจากผู้ปกครองด้วย เราแนะนำให้ผู้ใช้อายุต่ำกว่า 18 ปี **ใช้งานแอปโดยได้รับความเห็นชอบจากผู้ปกครอง** และผู้ปกครองสามารถอีเมลมาที่ [email protected] เพื่อขอดู แก้ไข หรือลบข้อมูลของบุตรหลานได้ทุกเมื่อ
> **หมายเหตุด้านสุขภาพ:** เครื่องคำนวณพลังงานของแอปอิงสูตรสำหรับผู้ใหญ่ ผู้ใช้อายุต่ำกว่า 18 ปีมีความต้องการพลังงานและสารอาหารต่างออกไป **ควรวางแผนการกินร่วมกับแพทย์หรือนักโภชนาการ**
## 10. การเปลี่ยนแปลงนโยบาย
เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราว เมื่อมีการเปลี่ยนแปลงที่มีนัยสำคัญ เราจะปรับ "วันที่มีผลบังคับใช้" ด้านบน และแจ้งภายในแอปตามความเหมาะสม เวอร์ชันล่าสุดจะเผยแพร่ที่ URL นี้เสมอ
## 11. ผู้ใช้ในสหภาพยุโรป/สหราชอาณาจักร (GDPR)
หากคุณอยู่ใน EU/EEA หรือสหราชอาณาจักร คุณมีสิทธิเทียบเท่ากับ PDPA (เข้าถึง, แก้ไข, ลบ, จำกัด, คัดค้าน, โอนย้ายข้อมูล, ถอนความยินยอม) และมีสิทธิร้องเรียนต่อหน่วยงานกำกับดูแลในประเทศของคุณ ฐานทางกฎหมายที่เราใช้เป็นไปตามตารางในข้อ 3
## 12. ติดต่อเรา
อรรถชัย ใบนานา — [email protected]
---
# English
## 1. Who we are and what this policy covers
This policy explains how the KinD (กินดี) app collects, uses, discloses, and protects your personal data. The data controller is Attachai Bainana, an individual developer ("we", "us").
- The app primarily serves users in Thailand and is therefore governed by the **Personal Data Protection Act B.E. 2562 (2019) ("PDPA")**.
- If you use the app from the EU/EEA or the UK, **GDPR/UK GDPR** also applies (see Section 11).
- As an individual developer / small studio, we are not legally required to appoint a formal Data Protection Officer (DPO). You may contact us about any data matter at [email protected].
## 2. Data we collect
**a. Data you enter yourself (stored on-device by default)**
- Profile and health data: name (optional), gender, age/birthday, height, weight, body-fat %, activity level, goal, dietary preferences, **food allergies**, **medical conditions**, daily budget, cooking skill, water goal.
- Food/activity logs: meals eaten, weight history, streaks.
Data about **food allergies and medical conditions** is **sensitive personal data** under PDPA Section 26. We process it on the basis of your **explicit consent**, and by default it stays only on your device (unless a future cloud-sync feature is offered and you enable it — see 2.e).
**b. Anonymous device ID**
- On first launch the app generates a random device ID (UUID) stored on your device and used as your local user ID. It is **not tied to your real-world identity**.
**c. AI Quick Log (optional feature — consent required)**
- You may type a food description or take/upload a **food photo** to get an estimate of calories/macros. That text or photo is sent to the **Google Gemini** AI model **through our Supabase Edge Function proxy** for processing, and an estimate is returned.
- Pro members can **speak into the microphone** instead of typing. Speech-to-text is performed by your **device's speech recognizer** (Apple/Google, under that platform's terms) — the app does not record or retain audio, and only the **resulting transcript text** is processed exactly like typed input. This uses the microphone permission, which you can decline or revoke in your device settings.
- Before first use, an **in-app consent screen** appears (default is "do not consent"), and you can decline or withdraw consent at any time.
- The text/photo is sent **solely to generate the nutrition estimate**. We do not use it to build an advertising profile, and our proxy is pass-through (it does not retain a copy for any other purpose). We use the paid tier of the Gemini API. Under Google's terms, content sent for processing is **not used to train or improve Google's models or products, and is not reviewed by humans for product development**; Google logs prompts and responses only for a limited period, solely to detect and prevent abuse and to keep the service secure, after which they are deleted.
- This is an **international data transfer** (Google/Supabase servers, likely outside Thailand, e.g. the US — see Section 6).
**d. Barcode scanning**
- When you scan a product barcode, the app sends **only the barcode number** to **Open Food Facts** to look up product nutrition. No personal data is sent.
**e. Account — required only for sharing recipes (optional feature)**
- Publishing a recipe to the community (see 2.k) requires signing in with a **Google or Apple** account via **Supabase Auth**. We receive and store that account's **email address** with our authentication provider to verify recipe ownership and prevent impersonation. Your email is never shown to other users, and we access nothing else in your Google/Apple account.
- Every other feature of the app works without an account. You can sign out any time (Profile → Account); deleting your account removes your email and your shared recipes from our servers.
- If we launch **cross-device sync (Pro)** in the future, your profile (including the sensitive health data above), day logs, and weight history would be stored in **Supabase**, and **sensitive health data would leave your device** in that case — processed on the basis of **explicit consent** plus performance of the service contract, with in-app notice before the feature is enabled. (This feature is not currently offered.)
**f. Pro purchases / subscription**
- Payments are processed through **Google Play Billing / Apple App Store**, with receipt validation via **RevenueCat**. We do not store your card number, but we do know your subscription status (e.g. active/expired) and purchase identifiers.
**g. Advertising (free tier only)**
- The app shows ads via **Google AdMob**, which may collect an **advertising identifier** and device information.
- On iOS we show **App Tracking Transparency (ATT)** and use **Google UMP** to request consent. If you decline, only **non-personalized ads** are shown.
- Pro users and the first 3 days after install see no ads, and ads never appear on the Today screen, onboarding, safety screens, or the paywall.
**h. Analytics (consent-gated)**
- We may use **PostHog** to understand aggregate app usage. Analytics is **off by default** and runs only if you consent.
**i. Crash reporting / diagnostics**
- We may use **Sentry** for crash reports and technical diagnostics (e.g. device model, OS version, stack trace) to fix bugs.
**j. Device permissions**
- **Camera** — for barcode scanning and food photos.
- **Notifications / exact alarm** — for Intermittent Fasting reminders and local notifications.
**k. Sharing recipes to the community (optional)**
- When you choose **"Share with everyone"** on a recipe, its content (name, ingredients, steps, nutrition), the photo you attached, your display name (from your profile — we recommend a nickname), an anonymous device identifier, and your account identifier (used to bind ownership; never shown to others) are stored on our servers (Supabase) and the recipe becomes **publicly visible** in the app.
- Shared recipes pass an **automated AI review** before publishing (food content only — no profanity, unsafe content, or personal data); the recipe text is sent to the AI service (Google Gemini) for this check, like other AI features in the app.
- Recipes with manually-entered nutrition (not AI-checked) **cannot be shared** (private only).
- You can **withdraw a shared recipe at any time** — switch it back to private, or use the withdraw/delete buttons on the recipe edit screen; the recipe and its photo are then deleted from our servers.
- Other users can **report** inappropriate recipes; recipes reported from multiple devices are hidden automatically pending review within 24 hours.
- Community nutrition values are **AI estimates**, not medical advice.
- Account/data deletion (Section 8) also covers your shared recipes — or you can request deletion of a specific recipe via the contact email in Section 12.
## 3. How we use data and our legal bases
| Purpose | Legal basis (PDPA / GDPR) |
|---|---|
| Core app functionality (targets, meal recommendations, logging, budget) | Performance of contract / legitimate interest |
| Processing sensitive health data (allergies, medical conditions) | **Explicit consent** |
| AI Quick Log (cross-border processing of text/photo) | **Explicit consent** |
| Account (email) for recipe sharing | Contract + legitimate interest (preventing impersonation) |
| Sharing recipes to the community (public content + AI pre-publish review) | Performance of contract (at your choice to share) |
| Purchases / subscription | Performance of contract |
| Personalized ads | **Consent** (ATT/UMP) |
| Non-personalized ads | Legitimate interest |
| Usage analytics | **Consent** |
| Crash reporting / security | Legitimate interest |
| Legal compliance and handling rights requests | Legal obligation |
## 4. Disclosure and third-party processors
We do not sell your personal data. We share it with third-party service providers only as needed for the features you use:
| Provider | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Google (Gemini AI) | Nutrition estimate from text/photo + pre-publish review of shared recipes | Food text/photo you submit, shared recipe content | <https://policies.google.com/privacy> |
| Google (AdMob) | Ads (free tier) | Advertising ID, device info | <https://policies.google.com/privacy> |
| Google (Sign-In) | Sign-in (required only for recipe sharing) | Email | <https://policies.google.com/privacy> |
| Apple (Sign in with Apple) | Sign-in (iOS — required only for recipe sharing) | Email / relay email | <https://www.apple.com/legal/privacy/> |
| Supabase | Backend (AI proxy + auth + community recipes) | Email, shared recipes + photos + display name | <https://supabase.com/privacy> |
| RevenueCat | Receipt validation / subscription status | Purchase identifiers, subscription status | <https://www.revenuecat.com/privacy> |
| Open Food Facts | Barcode → product data lookup | Barcode number (no personal data) | <https://world.openfoodfacts.org/terms-of-use> |
| Sentry | Crash reporting / diagnostics | Crash data, device info | <https://sentry.io/privacy/> |
| PostHog | Product analytics (on consent) | Aggregate usage events | <https://posthog.com/privacy> |
The provider policy links above are the official links as of this document's date.
## 5. Data retention
- **On-device data** — kept until you delete it in the app or uninstall (uninstalling removes local data).
- **Shared community recipes** — kept until you withdraw/delete the recipe or delete your account (the recipe and its photo are removed from our servers immediately).
- **Account data** — kept while your account is active; deleted from the live database immediately when you delete your account (see Section 8). Any residual copies in routine encrypted backups are removed within the provider's standard backup-retention cycle.
- **AI Quick Log** — text/photo is used to produce the estimate and is not retained by us for other purposes. On the paid Gemini API tier, Google logs data only for a limited period (currently around 55 days under Google's terms) to detect abuse, then deletes it, and does not use it for training.
- **Ads / analytics / crash reporting** — retained per each provider's own retention policy; see their privacy policies linked in Section 4.
## 6. International data transfers
When you use features that rely on third-party providers (AI Quick Log, Pro sync, ads, analytics, crash reporting), some data may be processed **outside Thailand**, for example, our Supabase backend is hosted in the **Singapore (ap-southeast-1)** region, while other providers (Google/Gemini/AdMob, Sentry, PostHog) may process data in the US or other regions. We carry out such transfers on the basis of **your consent** and/or the providers' contractual safeguards (e.g. Standard Contractual Clauses), as required by PDPA and GDPR.
## 7. Data security
We apply reasonable technical and organizational measures, such as encryption in transit (HTTPS/TLS) and server-side access controls (Supabase Row-Level Security bound to the user account), with encryption at rest provided by Supabase by default. On-device data is protected by your device's own security. However, no system is 100% secure, so we cannot guarantee absolute security.
## 8. Your rights
**PDPA data-subject rights** — you have the right to: access and obtain a copy, rectify, erase, restrict processing, object to processing, request data portability, and **withdraw consent** at any time.
- **Access / correct** — most data lives on your device and is directly editable in the app (Profile / Edit details).
- **Delete account & data** — the app has an account-deletion feature that deletes server-side data and local data.
- **Withdraw consent** — you can turn off AI Quick Log and analytics in About/Settings; uninstalling removes local data.
- You may **lodge a complaint with Thailand's Personal Data Protection Committee (PDPC)** if you believe processing is unlawful.
To exercise a right you cannot exercise in-app, contact [email protected].
## 9. Children
KinD is intended for users **13 and older**. The app enforces an age gate that blocks users under 13. It is not directed to children under 13, and we do not knowingly collect data from anyone under 13. If we learn that we have inadvertently collected the data of a child under 13, we will delete it.
**Users aged 13–17:** under PDPA section 20 (and equivalent GDPR provisions), a minor's consent may require the consent of a parent or guardian. We recommend that users under 18 **use the app with a parent's or guardian's approval**. A parent or guardian may email [email protected] at any time to access, correct, or delete their child's data.
> **Health note:** the app's energy calculations are based on an adult formula. Users under 18 have different energy and nutrient needs, and **should plan their diet with a doctor or dietitian.**
## 10. Changes to this policy
We may update this policy from time to time. For material changes we will update the "Effective date" above and give in-app notice where appropriate. The latest version is always published at this URL.
## 11. EU/UK users (GDPR)
If you are in the EU/EEA or the UK, you have rights equivalent to those under PDPA (access, rectification, erasure, restriction, objection, portability, withdrawal of consent) and the right to complain to your local supervisory authority. Our legal bases are set out in the table in Section 3.
## 12. Contact us
Attachai Bainana — [email protected]
---
*This document was prepared by an automated compliance assistant. Have a qualified lawyer review before publication. / เอกสารนี้จัดทำโดยผู้ช่วยด้านการปฏิบัติตามข้อกำหนดแบบอัตโนมัติ โปรดให้นักกฎหมายที่มีคุณสมบัติตรวจสอบก่อนเผยแพร่*
---