This policy explains how Lung Pong Long Pung (the LINE chatbot, the LIFF pages inside LINE, and the website lungpong-longpung.tech) collects, uses, shares and keeps personal data under Thailand's Personal Data Protection Act B.E. 2562 (PDPA). The Thai version is the governing text.
1. Data Controller
Teerachet Piriew, developer and operator of Lung Pong Long Pung. Contact: pipepiriew4@gmail.com
2. Data Collected
- LINE account data: the LINE User ID from the LINE Messaging API or LINE Login. Lung Pong does not request your name, profile picture, phone number or email from LINE.
- Chat text: used to reply and to log food. Text needed for an unfinished step (for example, waiting for a portion choice) is kept temporarily until that step ends.
- Food entries: food name, portion, kcal, protein, carbs, fat, time, source (chat, photo, voice, barcode, buffet receipt) and meals saved for re-logging.
- Food photos: the image file is not stored in the database or written to a file. Lung Pong keeps only the image hash, the LINE message ID and the analysis result (the dish names and kcal the system guessed).
- Buffet receipt photos: read by an OCR system that runs on Lung Pong's own server. The image is not stored; only the items you choose to save are kept.
- Voice: when you choose voice logging, the audio file is not stored. Lung Pong keeps the transcript temporarily and audio job metadata as described in section 5.
- Health data for goal setting (TDEE): age, sex used by the formula, height, weight, activity level, exercise frequency, daily kcal goal, and weight history when you update it.
- Barcodes: the barcode number and the serving you chose.
- Pro membership and payments: plan, expiry date, order reference ID, amount, payment status and early-bird price rights. Lung Pong never sees or stores card numbers, account numbers or passwords, because you pay on Beam's page.
- Consent and terms acceptance: document version, document hash and time of consent or acceptance.
- Feedback sent through the form: message, category and page details.
- Usage and technical data: feature usage counts (for quotas), visits to the Pro upgrade page, LINE webhook IDs, server error logs, and food searches the system could not match.
3. Purpose and Legal Basis
| Data | Purpose | Legal Basis (PDPA) |
|---|---|---|
| LINE User ID, chat text, food entries, photos, voice, barcodes | Provide calorie logging, daily summaries and chat replies you ask for | Contract (§24(3)) |
| TDEE health data and weight history | Calculate a daily kcal goal and show a weight chart | Explicit consent (§26), asked on the goal page before saving |
| Pro membership and payment data | Grant Pro access and keep accounting records | Contract (§24(3)) and legal obligation (§24(6)) |
| Usage data, system logs, unmatched searches, feedback | Quotas, duplicate protection, security, troubleshooting and improving the food database | Legitimate interest (§24(5)) |
Lung Pong does not sell data and does not use it for advertising.
4. Who Receives Data
| Recipient | Data received | Country |
|---|---|---|
| LINE (LY Corporation and LINE Company (Thailand)) | Every message, photo and voice clip sent in the chat, because the chat runs on LINE | Japan and Thailand |
| Hostinger | Lung Pong's entire server and database | Malaysia |
| OpenRouter (routing to Google Gemini models) | Chat text and selected context: kcal goal, today's total and recent food entries. No other TDEE data | United States |
| OpenRouter and Microsoft MAI Transcribe 2 | Voice audio, to transcribe it into text | United States |
| Google Gemini API | Food photos; food entries and kcal goal for the Pro weekly report; receipt item names when ThaiLLM is unavailable | United States |
| ThaiLLM | Food names the system could not match and receipt item names, to estimate kcal | Thailand |
| Beam | Order reference ID and amount. Payment details you enter on Beam's page are governed by Beam's policy | Thailand |
| Open Food Facts | The barcode number only | France |
| Comet (Opik), when enabled | A small random sample of AI reply quality traces, with emails, phone numbers, card numbers and LINE IDs removed before sending and a hashed user ID | United States |
None of the AI calls above include your LINE User ID. Each provider keeps and uses data under its own policy, which is outside Lung Pong's control.
Lung Pong may disclose data when the law or a government order requires it.
5. Data Retention Period
- Food entries and weekly reports: 2 years from the logging date, then deleted automatically.
- TDEE profile, weight history, settings, saved meals, photo analysis results, feedback and consent records: until you delete your account.
- Unmatched food searches: 90 days.
- Webhook IDs used for duplicate protection: 30 days.
- Server error logs: overwritten automatically as log files rotate.
- Payment information: 5 years to comply with the Thai Revenue Code (§87, §105 bis). When you delete your account, payment records are pseudonymized by removing the link to your LINE User ID, but kept as the law requires.
- The application does not store a copy of the voice recording in its database or as an application file. It holds audio temporarily in memory while retrieving, normalizing, and sending it for transcription. We do not claim verifiable physical memory zeroization.
- A standalone transcript needed for processing is stored for up to 10 minutes after admission, then cleared on completion, failure, or recovery. Expired transcripts are not reused. Food entries produced from voice follow the same retention as typed entries.
- Audio job metadata such as status, source type/size/hash/duration, and reported usage/cost is scheduled for deletion 30 days after admission. Physical deletion may be delayed during service downtime until maintenance runs after service resumes. Reply payloads and reply tokens are cleared after delivery or when their delivery window expires.
6. International Data Transfers
Lung Pong's database runs on a Hostinger server in Malaysia, and the AI providers in section 4 process data in the United States or other countries they choose. These transfers are necessary to provide the service you request (PDPA §28(3)). Lung Pong chooses providers with data security measures and sends only the data needed, without your identity. We do not guarantee that data is processed or stored in Thailand.
7. Your Rights
You may request access to and a copy of your data, correction, deletion, restriction, objection and data portability, and you may withdraw consent at any time. Withdrawal does not affect processing already done.
- View: type "ดูข้อมูลของฉัน" in the chat to see what Lung Pong keeps. Email us for a full copy as a file.
- Correct: edit or delete food entries on the meals page, and edit TDEE data on the goal page.
- Delete your account: type "ลบข้อมูลของฉัน" in the chat and confirm. Food entries, TDEE profile, settings and all other account data are deleted immediately, except payment records, which are pseudonymized as described in section 5. While Pro has not yet expired, deletion from the chat is blocked; email us instead.
- Other requests: email pipepiriew4@gmail.com. We reply within 30 days.
8. Minors
Users under 20 should get a parent's or guardian's consent before entering health data on the goal page. The service is not designed for children under 13.
9. Security
Lung Pong verifies the signature of every message from LINE, verifies the LINE Login token on every LIFF request, sends data over HTTPS, keeps secrets out of the code and limits server access. No online system is completely secure. If a data breach puts users at risk, Lung Pong will notify the Personal Data Protection Committee office within 72 hours and inform affected users as the law requires.
10. Facebook, Instagram and TikTok Posting Apps
This section does not concern chatbot users. The data controller in section 1 uses their own Meta app and TikTok app with a self-hosted scheduling system to publish posts only to the Facebook Pages, Instagram business accounts and TikTok accounts of businesses they own or manage: Lung Pong Long Pung and Red Cos (Vietnamese food). No one else can connect an account to these apps.
- Data received when a Page owner connects through Facebook Login: the authorizing Facebook user's name and ID; the ID, name and profile picture of the Page and Instagram business account; and the access token issued by Meta.
- Data received when an account owner connects through TikTok Login Kit: open ID, display name, avatar, profile link, aggregate account stats (such as follower and like counts), the account's public video list, and the access token issued by TikTok, under the scopes user.info.basic, user.info.profile, user.info.stats, video.list, video.upload and video.publish.
- Data the system creates: scheduled post text, images and videos, publish times, and the post IDs and links returned by Meta or TikTok.
- Aggregate Page and post statistics such as reach and engagement. The system does not store personal data about followers or commenters.
The purpose is to publish and manage the owner's posts and review their results. This data is not sold, not used for advertising, and not shared with anyone except Meta and TikTok to publish posts. Access tokens are kept server-side only, until the account is disconnected or deletion is requested.
11. Data Deletion Instructions for the Posting Apps
- Remove the app at any time in Facebook: Settings & privacy > Settings > Business Integrations, or in TikTok: Profile > Settings and privacy > Security > Apps and services.
- Then email pipepiriew4@gmail.com asking for deletion, with the Page or account name.
- All data for that account, including access tokens and post history in the scheduling system, is deleted within 30 days, and we confirm by email. Posts already published can be deleted by the owner on the platform.
12. Changes to This Policy
When this policy changes, the "Last Updated" date above changes. If the use of health data that needs consent changes, the system asks for consent again before the next goal is saved.
13. Contact and Complaints
- Email: pipepiriew4@gmail.com
- If you believe your data is handled improperly, you can complain to the Personal Data Protection Committee office at www.pdpc.or.th