Status: Draft — not for production use. Lawyer review required before Phase 3 public launch (Privacy Act / APPs). Legal entity, contact emails, and Neon region are founder fill-ins.
1. Who we are
- Legal entity: (fill in — legal name or Pty Ltd)
- Product: Food App (working title)
- Contact: (business email)
- Privacy contact: (same or dedicated)
2. What we collect
| Data | Purpose | Storage |
|---|---|---|
| Account email, name, password hash | Authentication | PostgreSQL (Neon) |
| Email verification and password-reset token hashes | Account security | PostgreSQL (hashes only) |
| Recipes, ingredients, meal plans, nutrition logs | Core product | PostgreSQL + local IndexedDB sync |
| Shopping lists, staples, pantry flags, aisle groups | Shopping | PostgreSQL + IndexedDB when synced |
| Settings (targets, timezone, units, optional height/sex/activity) | Personalization | PostgreSQL |
| Body weight (kg/g logs) | Progress tracking | PostgreSQL (+ IndexedDB when synced) |
| Body fat % and optional circumference measurements | Body composition tracking | PostgreSQL |
| Nutrition goal periods and target revisions | Goal tracking | PostgreSQL |
| Product-usage events (first-party intents such as which screen you used) | Reliability and product improvement | PostgreSQL |
| Feedback metadata (category, app version, path — not the message body) | Support | PostgreSQL |
| Terms and Privacy acceptance (document, version, timestamp) | Legal record | PostgreSQL |
| Stripe customer and subscription identifiers, plan, status, period end | Billing | PostgreSQL + Stripe |
We do not store full card numbers.
3. Health-related information
The app stores food and nutrition data you enter, plus optional biometrics you choose to log (body weight, body fat percentage, tape-measure circumferences, height, sex, activity level, and nutrition-goal history). This may be considered health information under Australian privacy law. We use it only to provide the service, not for advertising.
Nutrition estimates in the app are not medical or dietetic advice.
4. Household sharing vs personal data
If you join a household, recipes, meal plans, and shopping lists in that household are visible to the other member. Nutrition logs, settings, and biometrics stay per-user. We do not export a partner's private logs as if they were yours.
When you leave a household, copies of shared recipes or custom ingredients may remain with the household or with you, depending on how leave is processed. Those leftover copies are not deleted just because you left.
5. Food databases (no live USDA / Open Food Facts HTTP)
Ingredient search and barcode lookup use local copies of USDA, Open Food Facts, AUSNUT, and related search projections on our servers. The running app does not send your search queries to USDA or Open Food Facts at runtime.
6. Third-party services
| Service | Data shared | Location |
|---|---|---|
| Neon (PostgreSQL) | All server-side user data | (fill in region when provisioned) |
| Vercel | Request metadata, hosting | |
| Stripe | Account email for Checkout and billing; we store customer and subscription identifiers, plan, status, and period end (not full card numbers) | Stripe |
| Resend | Email address for transactional mail (verify, reset, invites, feedback, trial reminders) | |
| Google Gemini | Recipe photos and, when you use photo macro estimate, the photo used to estimate macros | |
| Sentry | Usage / error data | Not enabled yet |
7. Payments
Stripe is the payment processor. We send your account email to Stripe and we store Stripe customer and subscription identifiers, plan, status, and period end. We do not store full card numbers.
After you delete your account, application rows are removed. Stripe may keep billing records under its own DPA and retention rules. The trial-email record we may keep is a hash used to prevent a second trial after delete; it is not a card record.
8. Retention
- While your account is active: we keep the data needed to run the service.
- After you delete your account: application data for that user is removed. We may keep a hashed trial-email tombstone so a deleted email cannot start a second trial. Stripe may retain billing records under Stripe's rules. Household copies of recipes or ingredients that remain after you leave are not automatically deleted.
- Exact calendar retention periods are draft pending lawyer review.
9. Your rights
- Backup (food snapshot): Settings → Download backup. This is a food-library snapshot while your account stays active. Restore uses this file only.
- Account archive (privacy export): Settings → Download account archive. This is a copy of what we store about you, including account metadata plus a nested food backup. It is not an import file.
- Delete: Settings → Delete account. Download an archive (or backup) first if you want a copy.
10. Security
Encrypted in transit (HTTPS). Access limited to authorized operators. Passwords are stored as hashes, not plaintext.
11. Data breaches
(Draft — notification process; lawyer input for APP requirements)
12. Changes
We may update this policy. Material updates bump the in-app document version and require you to accept again before using the signed-in app. We will keep a draft banner until an Australian lawyer has reviewed these terms.
13. Contact
(business email / privacy contact)