MealArt Privacy Policy
Version 1.1 · effective from 5 October 2026
In short
- Without an account, everything you enter is stored only on your device. We can't see it.
- With an account, your email address and your entries are stored on a server in the EU (Ireland), so they are available on all your devices.
- Health data (weight, food diary, allergies, pregnancy, illnesses, medicines) goes into your account only with your separate consent. Without it, you can use MealArt without an account, and everything stays on your device.
- Photos you take to read a barcode or a label are never kept: they are read on your device and discarded.
- Products with a barcode that you save while signed in go into a shared MealArt product database: only the product's name, brand and nutrition values. Nobody sees who added them.
- No ads, no trackers, no analytics. We don't sell your data or share it with advertisers, insurers or employers.
- You can save a copy of your data and delete your account in Profile.
1. Who is responsible for your data
MealArt is run by a private individual:
Artem Tatarchenko, Switzerland
Email: [email protected]
I am the controller of your data in the sense of the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR). In this policy, "we" means me.
Which laws apply: the FADP, because MealArt is run from Switzerland; the GDPR for people in the EU and EEA; the UK GDPR for people in the UK; and US state health data laws for people in the US (see the Consumer Health Data Privacy Policy). We apply the stricter rule where they differ.
MealArt is a small project, so there is no data protection officer: the law doesn't require one. I answer all questions about data myself at the address above.
2. If you use MealArt without an account
Your questionnaire, daily target, diary, recipes and everything else are stored in your browser's storage on your device. We don't receive or see this data.
Browsers can delete this storage: when you clear site data, and in Safari on iPhone if you don't open the site for a while and haven't added it to your Home Screen. If you want to keep your entries safe, create an account or save a copy from time to time.
If you scan a barcode, the barcode number is sent to our server to look it up in the shared MealArt product database (section 12). We don't keep a record of what you look up. Only our database provider's technical logs briefly contain the request and your IP address; they are deleted after about a day.
As with any website, your browser connects to our hosting provider, Cloudflare, which sees the technical data of the request (section 3, "Technical data").
3. What we process, why, and on what legal basis
The FADP doesn't require a legal basis for every processing activity; the GDPR does. The table shows the GDPR basis, and we follow it for everyone.
| Data | Why | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Email address | Logging you in with a code sent by email, replying to your requests | Contract: there is no account without an email address, Art. 6(1)(b) | As long as your account exists |
| Entries without health data: cooking sessions and recipes, your own products, shopping list, app settings | Storing them in your account and showing them on all your devices | Contract, Art. 6(1)(b) | Until you delete them, or as long as your account exists |
| Health data (listed in section 4) | Storing it in your account, showing it on all your devices, calculating your daily target | Your explicit consent, Art. 9(2)(a) and 6(1)(a) GDPR, Art. 6(7) FADP | Until you withdraw your consent or delete your account |
| Consent records: what you agreed to (health data or Terms), yes or no, version and language of the text, date and time, app version | Proving that consent was given, as required by Art. 7(1) GDPR | Legal obligation, Art. 6(1)(c) | As long as your account exists |
| Technical data: IP address, browser and device type, time and address of the request, error messages logged by our providers | Delivering the website, logging you in, protecting against attacks and abuse | Legitimate interest in keeping the service secure, Art. 6(1)(f) | As long as our providers keep it for security purposes, usually from a few days to a few weeks |
| Messages you send us (the "Contact us" form in Profile or email): your email address, subject and text; for the form also whether you were signed in, the app version and the interface language | Replying to you | Your request, Art. 6(1)(b), and our legitimate interest in answering, Art. 6(1)(f) | Up to 12 months after our last reply, or earlier if you ask |
| Spam protection for the contact form: your IP address, stored only in scrambled form (a one-way hash) | Limiting how many messages can be sent, to stop spam | Legitimate interest in keeping the service secure, Art. 6(1)(f) | 24 hours |
| Barcode number (sent to our server and to Open Food Facts, see section 12) | Finding the product's nutrition values | Contract, Art. 6(1)(b) | We don't record lookups. Our database provider's technical logs contain the request for about a day. The answer is saved on your device |
| Products you add to the shared database (signed in only): barcode, product name, brand, nutrition values per 100 g or 100 ml, serving size, the date you added it, and your internal account ID | Filling in products by barcode for all users. Your ID lets you change or remove your entry, lets us limit spam and count how many people entered the same values | Contract, Art. 6(1)(b), and our legitimate interest in an accurate shared database, Art. 6(1)(f) | Linked to you until you delete the product or your account. After you delete your account, the product data stays without any link to you |
We don't collect your name, phone number, password, precise location or contacts. Photos you take to read a barcode or a label are never kept (section 12).
About messages. The contact form doesn't use cookies or a captcha, and nothing you write is stored on our server: the form turns your message into an email to our mailbox. If you're signed in, we reply to your account's email address; if not, to the address you enter. Please write only what we need to help you. If you mention your health, we use it only to answer you.
4. Health data
We treat as health data anything that could be used to draw conclusions about your health:
- sex, age, height, weight, body measurements, body fat percentage;
- your goal (lose weight, maintain weight, gain weight) and target weight, activity level and workouts;
- your food and water diary, your calculated daily target;
- allergies, intolerances, type of diet and foods you don't eat;
- pregnancy and breastfeeding;
- illnesses and medicines you mark: diabetes and diabetes medicines, kidney disease, weight-loss medicines, a past eating disorder, other chronic illnesses.
How we ask for consent. When you create an account, we ask for your consent with a separate checkbox. It is not ticked in advance and is separate from accepting the Terms. An account exists to store your diary, and your diary is health data, so an account needs this consent. If you don't give it, you can keep using MealArt without an account: everything stays on your device and nothing is sent to us.
What we do with it. We only store it in your account, sync it between your devices and show it to you. Your daily target is calculated on your device. We don't use your data for advertising or to train AI, we don't sell it, and we don't share it with anyone except the providers in section 5, who store it on our behalf.
How to withdraw consent. Delete your account: Profile → Account → "Delete account". Your email address, entries and consent records are deleted from the server immediately. Your diary stays on this device. Withdrawing consent doesn't affect the lawfulness of processing before the withdrawal.
5. Who helps us process data
We don't sell your data or pass it on to third parties. It is processed only by providers that the service can't work without. Each has a data processing agreement with us and may use the data only on our instructions.
| Provider | What it does | What data it sees | Where |
|---|---|---|---|
| Supabase, Inc. (USA) | Database and account login | Email address, your entries, consent record, the shared product database, technical data | Server in Ireland (EU). Supabase's support team may access it from other countries |
| Cloudflare, Inc. (USA) | Website hosting, domain, protection against attacks, forwarding emails to our mailbox, the contact form | IP address and technical data of requests to mealart.app, emails and messages you send us (in transit) | Global network of data centres, including countries outside Europe |
| Plus Five Five, Inc. (Resend, USA) | Sending emails with login codes | Email address, code, time of sending | Emails are sent from Ireland (EU); Resend stores its account data and logs in the USA |
These services handle data under their own terms and privacy policies, not as our processors:
| Service | When | What it receives |
|---|---|---|
| Open Food Facts (France) | You scan a barcode that isn't among your own products | The barcode number and your IP address |
| jsDelivr (public network for software files) | The first time you use the camera | Your IP address and the request for the recognition software |
| Google (Gmail, USA) | You email us or use the contact form: our mailbox is hosted by Google | Your email address and your message |
We will disclose data to public authorities only if the law requires it, and only to the extent necessary.
6. Transfers abroad
Your entries are stored in Ireland. Switzerland recognises the EU as having adequate data protection.
Our three providers, and Google, which hosts our mailbox, are US companies. Data may reach the USA if a provider's support team accesses it, and email logs are stored there. Technical data may also reach other countries where Cloudflare has data centres. For the USA we rely on the providers' certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023), the Swiss-U.S. Data Privacy Framework (recognised by the Swiss Federal Council from 15 September 2024) and the UK Extension. Their contracts also include the EU standard contractual clauses.
7. What is stored on your device
We don't use advertising or analytics cookies, pixels or similar technologies. Only what the app can't work without is stored on your device:
| What | Why |
|---|---|
| Your entries and the queue of changes waiting to be sent (browser storage, localStorage) | The app opens instantly and works offline |
| Login session | You don't have to enter a code every time you open the app |
| App files, font and images (service worker cache) | The app works offline and opens quickly |
| Recognition software and Open Food Facts answers (browser cache, localStorage) | Scanning works faster and, for barcodes you've scanned before, offline |
| Cloudflare technical cookie (only if bot protection kicks in) | Telling a human apart from an automated attack |
All of this is strictly necessary for the service you have chosen to open, so no consent banner is needed. "Sign out" erases the copy of your account data from the device. You can delete everything else in your browser settings.
8. How long we keep data
- Your account and entries are kept until you delete your account. "Delete account" in Profile immediately and permanently erases your email address and all your entries from the server. Products you added to the shared database stay there without any link to you (section 12).
- Unfinished sign-up. If you requested a code but never signed in, your email address is deleted within 30 days.
- Backups. We don't make backups at the moment. If we start, deleted data will also disappear from the backups within 30 days at the latest.
- Messages to us are deleted from our mailbox no later than 12 months after our last reply, or earlier if you ask.
- Spam-protection data for the contact form (the scrambled IP address) is deleted after 24 hours.
- Technical logs are kept by our providers under their own rules.
9. Your rights
| Right | How to use it |
|---|---|
| Find out what data we hold and get a copy | Profile → Account → "Save a copy" (all your entries), or email [email protected] for everything we hold, including consent records |
| Correct your data | Directly in the app |
| Delete your data | Profile → Account → "Delete account". Products you added to the shared database stay there anonymously; delete those products first if you don't want that |
| Receive your data in a machine-readable format | "Save a copy": a JSON file |
| Withdraw consent | Profile → Account → "Delete account" |
| Restrict processing, or object to processing based on legitimate interest (technical data, spam protection) | Email [email protected] |
| Complain to a supervisory authority | Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch. EU and EEA: the data protection authority of the country where you live or work. UK: the ICO |
We respond free of charge within 30 days. To make sure a request really comes from you, we may ask you to write from your account's email address.
We don't make automated decisions that have legal effects on you or affect you in a similarly significant way. Your daily target is a guideline, calculated on your device.
If you live in the USA, your rights under state health data laws are described in our Consumer Health Data Privacy Policy. If we decline your request, you can appeal: reply to our email with the word "Appeal". We will respond within 60 days.
10. Age
MealArt accounts are for people aged 16 and over. If the age you enter is under 16, the app doesn't offer an account, so we receive nothing. If we find out that an account belongs to someone under 16, we will delete it.
11. Security
- All connections are encrypted (HTTPS).
- In the database, each account can see only its own entries: this is enforced on the server, not just in the app.
- There are no passwords, so there is nothing to steal or guess. The code from the email is valid for 15 minutes.
- We collect only what the service needs.
If a data breach is likely to put your rights at risk, we will report it to the FDPIC and, where the GDPR applies, to the competent EU authority within 72 hours. If the risk is high, we will also tell you without undue delay.
12. Camera, barcodes and products
- Scan photos are never kept. When you take a photo of a barcode or a nutrition label, or pick one from your gallery, the app reads it right on your phone and then discards it. It is not saved on your device, not uploaded to us or anyone else, and never turned into a product picture.
- Product picture (optional). If you add a picture to your own product with the Photo button, the app keeps a small copy (192 × 192 pixels) as the product's icon. It is stored on your device; with an account, it syncs like your other entries and is included in "Save a copy". Remove the picture or delete the product to delete it.
- Your own products. A product you save, with its barcode, nutrition values and your optional description and picture, is stored on your device; with an account, it syncs like your other entries. The description and picture are never shared with anyone.
- Barcode search goes in this order: (1) your own products, on your device; (2) the shared MealArt product database on our server; (3) Open Food Facts, an open food database run by a non-profit in France. Steps 2 and 3 receive only the barcode number, never your email address, photos or diary. We don't record what you look up; only our database provider's technical logs contain the request and your IP address for about a day. Open Food Facts sees your IP address and handles it under its own privacy policy. The answer is kept on your device.
- Shared MealArt product database. When you save a product with a barcode while signed in, the app sends its barcode, name, brand, nutrition values per 100 g or 100 ml and serving size to our server in Ireland (Supabase). Never its picture or description, your email address or your diary. Other users who scan the same barcode see these values marked "Added by MealArt users", and never see who added them. Your entry is linked to your internal account ID so that you can change or remove it, so we can limit spam, and so we can count how many people entered the same values. We check entries automatically (for example, calories must match protein, fat and carbohydrates) and may correct or remove wrong ones.
- Removing your entries. Delete the product, or remove its barcode, and your entry disappears from the shared database. If you delete your account, your entries stay in the database without any link to you, so they are no longer personal data.
- Recognition software. The barcode and text recognition tools (ZXing and Tesseract) are downloaded from the public jsDelivr network the first time you need them, and then kept in your browser. Like any server you load files from, jsDelivr sees your IP address. Your photos are never sent there.
- Camera access. The camera opens only when you tap the camera button. The app doesn't record video and doesn't use the camera in the background.
- Check the numbers. Label reading and barcode data can contain mistakes, so compare the numbers with the package before saving.
13. Changes to this policy
If we change this policy, we will update the version and date at the top. We will tell you about significant changes in the app in advance. If what we do with health data changes, we will ask for your consent again.
14. Language
This policy is written in English. If we publish translations, the English version prevails, unless the law requires otherwise.
15. Contact
Artem Tatarchenko · [email protected]