This policy explains what personal data f*rk processes, why, on what legal basis, who we share it with and which rights you have under the EU General Data Protection Regulation (GDPR) and equivalent laws.
Controller. The controller for your data is [Legal entity / sole trader name], [street, postal code, city, country], contact support.banter477@passmail.com. Data protection officer: [DPO name/contact, or “not required”]. Complete these placeholders with your real details before public launch — the GDPR requires an identifiable controller.
1. Data we process
- Account data: email address, authentication identifiers (email/password or Google/Microsoft/Apple sign-in), display name, chosen account type, language, avatar or badge image.
- Food and progress data: logged foods, meal type, timestamps, weekly plant/fermented/polyphenol scores, goals, quests, badges, shopping list, saved recipe links, food preferences.
- Sharing data: family group membership and invitations, class/student entries created by teachers, challenge participation and standings.
- Subscription data: plan, status, billing period, provider identifiers from Stripe/Apple. We never receive or store full payment card numbers.
- Feature inputs: photos, voice recordings, barcodes or free text you submit to recognition features, and approximate location or country if you enable seasonality/availability features.
- Technical data: device and browser type, language, IP address, timestamps, error and diagnostic logs, and locally stored app state (including offline cache).
Health-related data. Food logs can reveal information about your diet. We treat this as sensitive and process it only to provide the tracking features you ask for, on the basis of your explicit consent, which you can withdraw at any time by deleting the data or your account.
2. Why we process it and on what legal basis
- Providing the app and your account — performance of our contract with you (Art. 6(1)(b) GDPR).
- Food, goal and progress tracking (diet-related data) — your explicit consent (Art. 9(2)(a) GDPR), given by choosing to log this information.
- Subscriptions, invoicing and fraud prevention — contract and legal obligations (Art. 6(1)(b) and (c) GDPR).
- Security, abuse prevention, moderation and service improvement — our legitimate interests in a safe, working service (Art. 6(1)(f) GDPR).
- Non-essential cookies, analytics and personalised or measured advertising — your consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive), withdrawable at any time.
- AI-assisted recognition, translation and recipe discovery — performance of the contract when you use the feature; inputs are sent to our AI processors only for that purpose.
We do not sell your personal data.
3. Recipients and processors
We use carefully selected service providers who act as processors under Art. 28 GDPR data processing agreements and only on our instructions:
- Cloud hosting, database, authentication and file storage (Supabase infrastructure).
- Application hosting and content delivery (Lovable / Cloudflare).
- Payment processing (Stripe; Apple for in-app purchases; RevenueCat for receipt validation).
- AI model providers used for recognition, translation and recipe discovery.
- Advertising and measurement providers, where you have consented.
Family, teacher and challenge features share limited data with people you choose: family adults can see a child’s progress unless privacy mode is on, teachers see their class entries, and challenge participants see each other’s challenge-relevant foods (which you can hide with the viewing toggle).
4. International transfers
Some providers process data outside the EU/EEA. Where that happens we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest. You can request details of the safeguards used.
5. Retention
- Account, food and progress data: until you delete the item, reset your progress, or delete your account.
- Deleted accounts: erased from live systems promptly and from backups within 30 days.
- Invoicing and tax records: kept for the statutory retention period (typically 6–10 years).
- Security and error logs: normally up to 12 months.
- Recognition inputs (photos, audio, text): processed transiently and not stored longer than needed to return a result.
6. Children
Own accounts are for users aged 16 and over (or the local digital-consent age). Child profiles may only be created by a parent or guardian, who controls the profile and its data and can delete it at any time. Child profiles are not shown personalised advertising. We do not knowingly collect data from children outside this framework; if you believe we have, contact us and we will delete it.
7. Cookies and local storage
We use strictly necessary storage for sign-in sessions, your preferences and offline use of the app — these do not require consent. Any analytics or advertising cookies are set only after you consent, and you can change or withdraw your choice at any time. Clearing your browser storage removes locally cached data.
8. Security
We apply appropriate technical and organisational measures: encryption in transit (TLS) and at rest, row-level access rules so each account can reach only its own data, restricted administrative access, hashed credentials and passcodes, private file storage with signed access, and logging of security-relevant events. No system is perfectly secure; we notify you and the competent authority of qualifying personal-data breaches as required by Art. 33 and 34 GDPR.
9. Your rights
- Access to your data and a copy of it (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure — “right to be forgotten” (Art. 17).
- Restriction of processing (Art. 18).
- Data portability in a machine-readable format (Art. 20).
- Objection to processing based on legitimate interests (Art. 21).
- Withdrawal of consent at any time, without affecting past lawful processing (Art. 7(3)).
You can exercise most rights directly in the app (edit your profile and goals, delete individual foods, reset progress, delete your account) or by contacting us at support.banter477@passmail.com. We respond within one month. You also have the right to lodge a complaint with your local data protection authority.
10. Automated decision-making
We do not carry out automated decision-making that produces legal effects or similarly significantly affects you. AI features only generate suggestions you remain free to accept or reject.
11. Changes to this policy
We will update this policy when our processing changes and will inform you of material changes in the app or by email. The date at the top shows the current version.
This document is a carefully prepared template aligned with the GDPR and EU ePrivacy rules. It is not legal advice — have it reviewed by a qualified lawyer and complete the controller details before launch.