Mission Features How it works Join the waitlist

Overview

This Privacy Policy explains how Replate ("we", "us") collects, uses, and protects your personal data when you use our mobile application (the "App"). We comply with the EU General Data Protection Regulation (GDPR).

1. Data We Collect

You provide directly (during onboarding and use):

Collected automatically:

Special-category health data (GDPR Art. 9): Some data you provide — including body metrics (height, weight), food allergies, and health-related dietary goals — may constitute special-category health data. We process this data solely on the basis of your explicit consent (Art. 9(2)(a)), given during onboarding. You may withdraw consent at any time by deleting your profile (Settings → Account).

2. Why We Use It

PurposeDataLawful basis
Create and maintain your accountEmail, passwordArt. 6(1)(b) — performance of a contract
Generate personalised meal plansProfile data, goals, preferencesArt. 6(1)(b) — performance of a contract
Process health data (body metrics, allergies, dietary goals)Health profile fieldsArt. 9(2)(a) — explicit consent
Provide AI meal suggestionsProfile and recipe context sent to AI providerArt. 6(1)(b) — performance of a contract
Automated profiling for meal personalisationAll profile dataArt. 9(2)(a) — explicit consent; Art. 22(2)(c)
App stability and securityDiagnostic and crash dataArt. 6(1)(f) — legitimate interest

We use AI to generate personalised meal plans based on your profile (automated decision-making, Art. 22 GDPR). You have the right to request human review of any automated output, to object to this processing, or to obtain an explanation — contact replateai@gmail.com.

3. Who We Share It With

We use trusted third parties that process data on our behalf under data-processing agreements (GDPR Art. 28):

We do not sell your personal data.

4. International Transfers

Supabase processes data within the EU. Anthropic (US) transfers are covered by Standard Contractual Clauses; RevenueCat (US) transfers are covered by the EU–US Data Privacy Framework. You may request a copy of the applicable safeguards by emailing replateai@gmail.com.

5. Retention

Data typeRetention period
Account and profile dataWhile your account is active
Meal plans and generated contentWhile your account is active
Crash and diagnostic logs90 days
Payment and transaction records5 years (Polish tax law)
Consent recordsDuration of processing + 3 years

If you delete your account, we delete your personal data within 30 days, except where retention is required by law.

6. Your Rights (GDPR)

You have the right to: access your data; rectify inaccuracies; request erasure; restrict or object to processing; receive a portable copy of your data; object to automated profiling (Art. 22); and withdraw consent at any time without affecting prior lawful processing.

7. Data Breach Notification

In the event of a personal data breach posing a high risk to your rights and freedoms, we will notify you without undue delay (GDPR Art. 34) and notify UODO within 72 hours of becoming aware of the breach (GDPR Art. 33).

8. Children

The App is intended for adults aged 18 or over. We do not knowingly collect data from anyone under 18. If we become aware a user is under 18, we will delete their account and data promptly.

9. Security

We use industry-standard measures including encryption in transit (TLS), row-level security in our database, and hashed passwords. No system is 100% secure; we will notify you promptly if your data is compromised.

10. Changes

We may update this policy. Material changes will be notified in-app at least 14 days before taking effect.

11. Contact

Szymon Tabiś · Kuźnicy Kołłątajowskiej 19/2, 31-234 Kraków, Poland · replateai@gmail.com