MealArt

MealArt Privacy Policy

Version 1.1 · effective from 5 October 2026

In short


1. Who is responsible for your data

MealArt is run by a private individual:

Artem Tatarchenko, Switzerland
Email: [email protected]

I am the controller of your data in the sense of the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR). In this policy, "we" means me.

Which laws apply: the FADP, because MealArt is run from Switzerland; the GDPR for people in the EU and EEA; the UK GDPR for people in the UK; and US state health data laws for people in the US (see the Consumer Health Data Privacy Policy). We apply the stricter rule where they differ.

MealArt is a small project, so there is no data protection officer: the law doesn't require one. I answer all questions about data myself at the address above.

2. If you use MealArt without an account

Your questionnaire, daily target, diary, recipes and everything else are stored in your browser's storage on your device. We don't receive or see this data.

Browsers can delete this storage: when you clear site data, and in Safari on iPhone if you don't open the site for a while and haven't added it to your Home Screen. If you want to keep your entries safe, create an account or save a copy from time to time.

If you scan a barcode, the barcode number is sent to our server to look it up in the shared MealArt product database (section 12). We don't keep a record of what you look up. Only our database provider's technical logs briefly contain the request and your IP address; they are deleted after about a day.

As with any website, your browser connects to our hosting provider, Cloudflare, which sees the technical data of the request (section 3, "Technical data").

The FADP doesn't require a legal basis for every processing activity; the GDPR does. The table shows the GDPR basis, and we follow it for everyone.

DataWhyLegal basis (GDPR)How long we keep it
Email addressLogging you in with a code sent by email, replying to your requestsContract: there is no account without an email address, Art. 6(1)(b)As long as your account exists
Entries without health data: cooking sessions and recipes, your own products, shopping list, app settingsStoring them in your account and showing them on all your devicesContract, Art. 6(1)(b)Until you delete them, or as long as your account exists
Health data (listed in section 4)Storing it in your account, showing it on all your devices, calculating your daily targetYour explicit consent, Art. 9(2)(a) and 6(1)(a) GDPR, Art. 6(7) FADPUntil you withdraw your consent or delete your account
Consent records: what you agreed to (health data or Terms), yes or no, version and language of the text, date and time, app versionProving that consent was given, as required by Art. 7(1) GDPRLegal obligation, Art. 6(1)(c)As long as your account exists
Technical data: IP address, browser and device type, time and address of the request, error messages logged by our providersDelivering the website, logging you in, protecting against attacks and abuseLegitimate interest in keeping the service secure, Art. 6(1)(f)As long as our providers keep it for security purposes, usually from a few days to a few weeks
Messages you send us (the "Contact us" form in Profile or email): your email address, subject and text; for the form also whether you were signed in, the app version and the interface languageReplying to youYour request, Art. 6(1)(b), and our legitimate interest in answering, Art. 6(1)(f)Up to 12 months after our last reply, or earlier if you ask
Spam protection for the contact form: your IP address, stored only in scrambled form (a one-way hash)Limiting how many messages can be sent, to stop spamLegitimate interest in keeping the service secure, Art. 6(1)(f)24 hours
Barcode number (sent to our server and to Open Food Facts, see section 12)Finding the product's nutrition valuesContract, Art. 6(1)(b)We don't record lookups. Our database provider's technical logs contain the request for about a day. The answer is saved on your device
Products you add to the shared database (signed in only): barcode, product name, brand, nutrition values per 100 g or 100 ml, serving size, the date you added it, and your internal account IDFilling in products by barcode for all users. Your ID lets you change or remove your entry, lets us limit spam and count how many people entered the same valuesContract, Art. 6(1)(b), and our legitimate interest in an accurate shared database, Art. 6(1)(f)Linked to you until you delete the product or your account. After you delete your account, the product data stays without any link to you

We don't collect your name, phone number, password, precise location or contacts. Photos you take to read a barcode or a label are never kept (section 12).

About messages. The contact form doesn't use cookies or a captcha, and nothing you write is stored on our server: the form turns your message into an email to our mailbox. If you're signed in, we reply to your account's email address; if not, to the address you enter. Please write only what we need to help you. If you mention your health, we use it only to answer you.

4. Health data

We treat as health data anything that could be used to draw conclusions about your health:

How we ask for consent. When you create an account, we ask for your consent with a separate checkbox. It is not ticked in advance and is separate from accepting the Terms. An account exists to store your diary, and your diary is health data, so an account needs this consent. If you don't give it, you can keep using MealArt without an account: everything stays on your device and nothing is sent to us.

What we do with it. We only store it in your account, sync it between your devices and show it to you. Your daily target is calculated on your device. We don't use your data for advertising or to train AI, we don't sell it, and we don't share it with anyone except the providers in section 5, who store it on our behalf.

How to withdraw consent. Delete your account: Profile → Account → "Delete account". Your email address, entries and consent records are deleted from the server immediately. Your diary stays on this device. Withdrawing consent doesn't affect the lawfulness of processing before the withdrawal.

5. Who helps us process data

We don't sell your data or pass it on to third parties. It is processed only by providers that the service can't work without. Each has a data processing agreement with us and may use the data only on our instructions.

ProviderWhat it doesWhat data it seesWhere
Supabase, Inc. (USA)Database and account loginEmail address, your entries, consent record, the shared product database, technical dataServer in Ireland (EU). Supabase's support team may access it from other countries
Cloudflare, Inc. (USA)Website hosting, domain, protection against attacks, forwarding emails to our mailbox, the contact formIP address and technical data of requests to mealart.app, emails and messages you send us (in transit)Global network of data centres, including countries outside Europe
Plus Five Five, Inc. (Resend, USA)Sending emails with login codesEmail address, code, time of sendingEmails are sent from Ireland (EU); Resend stores its account data and logs in the USA

These services handle data under their own terms and privacy policies, not as our processors:

ServiceWhenWhat it receives
Open Food Facts (France)You scan a barcode that isn't among your own productsThe barcode number and your IP address
jsDelivr (public network for software files)The first time you use the cameraYour IP address and the request for the recognition software
Google (Gmail, USA)You email us or use the contact form: our mailbox is hosted by GoogleYour email address and your message

We will disclose data to public authorities only if the law requires it, and only to the extent necessary.

6. Transfers abroad

Your entries are stored in Ireland. Switzerland recognises the EU as having adequate data protection.

Our three providers, and Google, which hosts our mailbox, are US companies. Data may reach the USA if a provider's support team accesses it, and email logs are stored there. Technical data may also reach other countries where Cloudflare has data centres. For the USA we rely on the providers' certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023), the Swiss-U.S. Data Privacy Framework (recognised by the Swiss Federal Council from 15 September 2024) and the UK Extension. Their contracts also include the EU standard contractual clauses.

7. What is stored on your device

We don't use advertising or analytics cookies, pixels or similar technologies. Only what the app can't work without is stored on your device:

WhatWhy
Your entries and the queue of changes waiting to be sent (browser storage, localStorage)The app opens instantly and works offline
Login sessionYou don't have to enter a code every time you open the app
App files, font and images (service worker cache)The app works offline and opens quickly
Recognition software and Open Food Facts answers (browser cache, localStorage)Scanning works faster and, for barcodes you've scanned before, offline
Cloudflare technical cookie (only if bot protection kicks in)Telling a human apart from an automated attack

All of this is strictly necessary for the service you have chosen to open, so no consent banner is needed. "Sign out" erases the copy of your account data from the device. You can delete everything else in your browser settings.

8. How long we keep data

9. Your rights

RightHow to use it
Find out what data we hold and get a copyProfile → Account → "Save a copy" (all your entries), or email [email protected] for everything we hold, including consent records
Correct your dataDirectly in the app
Delete your dataProfile → Account → "Delete account". Products you added to the shared database stay there anonymously; delete those products first if you don't want that
Receive your data in a machine-readable format"Save a copy": a JSON file
Withdraw consentProfile → Account → "Delete account"
Restrict processing, or object to processing based on legitimate interest (technical data, spam protection)Email [email protected]
Complain to a supervisory authoritySwitzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch. EU and EEA: the data protection authority of the country where you live or work. UK: the ICO

We respond free of charge within 30 days. To make sure a request really comes from you, we may ask you to write from your account's email address.

We don't make automated decisions that have legal effects on you or affect you in a similarly significant way. Your daily target is a guideline, calculated on your device.

If you live in the USA, your rights under state health data laws are described in our Consumer Health Data Privacy Policy. If we decline your request, you can appeal: reply to our email with the word "Appeal". We will respond within 60 days.

10. Age

MealArt accounts are for people aged 16 and over. If the age you enter is under 16, the app doesn't offer an account, so we receive nothing. If we find out that an account belongs to someone under 16, we will delete it.

11. Security

If a data breach is likely to put your rights at risk, we will report it to the FDPIC and, where the GDPR applies, to the competent EU authority within 72 hours. If the risk is high, we will also tell you without undue delay.

12. Camera, barcodes and products

13. Changes to this policy

If we change this policy, we will update the version and date at the top. We will tell you about significant changes in the app in advance. If what we do with health data changes, we will ask for your consent again.

14. Language

This policy is written in English. If we publish translations, the English version prevails, unless the law requires otherwise.

15. Contact

Artem Tatarchenko · [email protected]