Privacy Policy
Last updated: 13 August 2026
MealSync lets you log a real meal from text, photos, files, or a voice note, review the nutrition estimate, and sync the reviewed nutrition record to Google Health if you connect Google Health. This policy explains what data is processed for that workflow.
Controller
The controller responsible for MealSync is Magdalena Bachinger, Fuerstallergasse 7, 5020 Salzburg, Austria. For privacy requests or questions, contact info@getmealsync.app.
Data MealSync processes
- Account data: Google sign-in identifier, email address, display name where provided, session cookie, plan status, and account settings.
- Meal data: typed meal descriptions; uploaded photos, receipts, menus, labels or other files; voice recordings and transcripts; meal time and meal type; and any other notes, context, content, or information you choose to enter or upload in the meal logging workflow, including information that may not be strictly meal-related. This also includes AI assumptions, nutrition estimates, user edits, saved meal history, and sync/deletion state.
- Google Health connection data: OAuth tokens, granted scope, connected-account metadata, and external nutrition record IDs needed to sync or delete reviewed records.
- Consent records: timestamps, consent event type, legal-basis summary, copy version, and non-sensitive workflow metadata showing when the user consented to meal estimation or Google Health connection.
- Billing data: subscription status, plan, Polar customer or subscription IDs, checkout metadata, Terms/Privacy acceptance, digital-service acknowledgement, and invoices and payment details handled by Polar.
- Contact and support data: messages you send to us by email or through the contact form, including your name, email address, selected topic where applicable, message content, and related reply metadata needed to answer and document the request.
- Technical data: request metadata, security events, rate-limit counters, error information, abuse-prevention signals, and first-party aggregate funnel events needed to operate and improve the service. Funnel events can include the event category, page path, input category, success or failure category, estimate latency, token counts, configured AI cost estimate, source byte totals, and an allowlisted aggregate acquisition-source label such as Google Ads or founder outreach. They do not contain meal descriptions, filenames, source contents, nutrition values, Google Health records, account identifiers, or access tokens.
Purposes and legal bases
- Provide MealSync, create estimates, save reviewed meals, sync reviewed records to Google Health when requested, and manage the user account: Article 6(1)(b) GDPR, performance of a contract or steps requested before entering a contract. Where meal inputs, nutrition estimates, voice notes, or Google Health sync records qualify as data concerning health, MealSync also relies on explicit consent under Article 9(2)(a) GDPR.
- Keep consent records for meal-estimation and Google Health workflows: Article 6(1)(c) GDPR where records are needed to meet GDPR accountability and consent-proof obligations, and Article 6(1)(f) GDPR for MealSync's legitimate interest in demonstrating compliance and handling disputes.
- Manage subscription access, checkout state, billing support, legal checkout acknowledgements, and Polar subscription metadata: Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR where legal obligations apply. Polar handles buyer payment, invoice, tax, refund, and merchant-of-record records under Polar's own terms.
- Keep the service secure, prevent abuse, investigate failures, and protect the product from misuse: Article 6(1)(f) GDPR, MealSync's legitimate interests in security, abuse prevention, and reliable service operation, and Article 6(1)(c) GDPR where legal obligations apply.
- Measure aggregate product usage, funnel completion, reliability, and operating cost without meal content or account identifiers: Article 6(1)(f) GDPR, MealSync's legitimate interest in improving the service and keeping its operating costs viable.
- Respond to privacy requests and legal claims: Article 6(1)(c) GDPR where required by law, and Article 6(1)(f) GDPR for MealSync's legitimate interest in establishing, exercising, or defending legal claims.
- Respond to contact form and support requests: legitimate interests under Article 6(1)(f) GDPR for general support, Article 6(1)(b) GDPR where the request concerns an account or subscription, and Article 6(1)(c) GDPR where the request concerns statutory rights.
Health data and explicit user control
Meal and nutrition data can be sensitive. MealSync asks for affirmative consent before processing meal inputs for a nutrition estimate. Users can review and edit the estimate before anything is saved as final or synced.
MealSync is not a medical service and does not provide diagnosis, treatment, or medical advice. Meal inputs and nutrition estimates are primarily processed to provide the user-requested nutrition self-tracking service. Because meal data, nutrition estimates, voice notes, and Google Health sync records can be sensitive and may in some contexts reveal health-related information, MealSync treats them as sensitive health-adjacent data. Where this information qualifies as data concerning health under Article 9 GDPR, MealSync relies on the user's explicit consent for the meal estimation and Google Health sync workflows.
Google Health is connected in a separate step. MealSync requests only the Google Health permission needed for the visible feature: writing and, where supported by the stored record ID, deleting the user-reviewed nutrition records. MealSync does not read unrelated Google Health data for hidden profiling or analytics.
Google Health limited-use disclosure
MealSync’s use and transfer of information received from Google Health APIs will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements. MealSync does not sell Google Health data, use it for advertising, transfer it to data brokers, use it for lending or credit decisions, use it for medical-device functionality, or use it for unrelated analytics.
Processors and third parties
MealSync is the controller for MealSync account data, meal data, app history, and app-side Google Health connection records. MealSync uses the following providers only where needed to run the product:
- Cloudflare acts as a hosting, security, database, object-storage, and email routing provider. Cloudflare may process account/session data, saved meal records in D1, uploaded meal source files in R2, and technical/security metadata. Where Cloudflare processes data for MealSync, MealSync treats Cloudflare as a processor. Cloudflare also has its own privacy notices for data it processes as an independent controller. Relevant terms: Cloudflare DPA and Cloudflare Privacy Policy.
- OpenAI provides nutrition-estimation processing. MealSync sends the user-provided meal context and selected source content needed to generate an estimate. MealSync does not send Google Health OAuth tokens or Polar payment details to OpenAI. Where OpenAI processes MealSync API requests under business/API terms, MealSync treats OpenAI as a processor. Relevant terms: OpenAI DPA and OpenAI Privacy Policy.
- Google provides Google sign-in and the optional Google Health OAuth/API workflow. Google may process Google account identifiers, OAuth consent and scope information, Google Health write/delete requests, and Google-controlled account or health-service data. MealSync remains controller for the MealSync app data it stores; Google acts separately as the provider of Google account, OAuth, API, and Google Health services. Relevant terms: Google API Services User Data Policy, Google APIs Terms, and Google Privacy Policy.
- Polar is MealSync's merchant of record/reseller for paid subscriptions. This means that when you buy a MealSync subscription, you buy it through Polar checkout from Polar, and Polar is responsible for checkout, payment processing, invoices, applicable taxes, refunds, disputes, and buyer billing records under Polar's buyer terms. MealSync does not receive full payment-card details and remains controller for MealSync app account and meal data. Polar may process customer email/name, plan, checkout metadata, legal acknowledgement metadata, Polar customer and subscription IDs, buyer payment records, invoices, taxes, refunds, and disputes. Polar may act as an independent controller for buyer/payment/tax/refund records and as a processor or service provider for some seller-integration data where Polar's DPA applies. Relevant terms: Polar Buyer Terms, Polar Privacy Policy, Polar DPA, and Polar sub-processors.
MealSync does not sell meal, health, or account data. If we add a new provider or materially change how a provider processes your personal data, we will update this Privacy Policy before that change takes effect.
International transfers
Some providers may process data outside Austria or the European Economic Area. Where MealSync transfers personal data to a provider in a country that does not have an applicable adequacy decision, MealSync relies on appropriate safeguards such as EU Standard Contractual Clauses, UK or Swiss transfer terms where relevant, provider data-processing agreements, supplementary security measures, or another valid transfer mechanism required by data protection law.
Cloudflare, OpenAI, and Polar publish data-processing terms or addenda that include international transfer safeguards. Google account, OAuth, API, and Google Health processing is also subject to Google's own terms and privacy policy. The provider links above identify the current public terms MealSync relies on or asks users to review.
Cookies, analytics, and tracking
MealSync currently uses cookies or similar technologies that are necessary for sign-in, security, checkout continuation, and service operation. These include the MealSync session cookie, Google OAuth state cookie, and pending-checkout cookie. MealSync records a small first-party aggregate funnel in its own database without setting an analytics cookie or persistent browser identifier. MealSync does not currently use advertising cookies, tracking pixels, session replay, or behavioral advertising analytics. If optional analytics or marketing cookies are added later, the notice and consent flow must be updated before they are used.
Retention and deletion
MealSync keeps personal data only for as long as needed for the relevant purpose. The product uses the deletion and anonymisation flows below where MealSync controls the data. Some infrastructure, payment, AI, email, and Google systems may keep their own security, billing, abuse-prevention, or account records under their own terms and legal obligations.
- Demo uploads, typed inputs, voice inputs, and generated demo estimates are not saved to a MealSync account or MealSync upload storage. They are processed transiently to return the requested estimate. Temporary processing or security logs may exist in infrastructure or AI-provider systems under their own retention rules.
- Uploaded source files for paid accounts are kept while the related meal or account exists. When a meal or account is deleted, MealSync attempts to delete the related uploaded source files and source metadata before completing the local deletion. If a storage operation fails, deletion is paused or the leftover object is handled through MealSync's storage cleanup process.
- Saved meals, nutrition estimates, AI assumptions, user edits, meal time, meal type, and sync state are kept until the user deletes the meal or the MealSync account is deleted. Meal deletion removes the meal from normal MealSync history by marking it as deleted.
- Google Health OAuth tokens and connection metadata are kept until the user disconnects Google Health, deletes the MealSync account, or the connection is invalidated. Disconnecting Google Health deletes the stored Google Health connection. Account deletion also deletes the stored Google Health connection before the MealSync profile is anonymised.
- Consent records for meal estimation and Google Health connection are kept so MealSync can show which consent was recorded for a requested meal-estimation or Google Health workflow. After account deletion, these records may remain linked to the anonymised MealSync account identifier where needed for legal, consumer-rights, or dispute-handling purposes.
- Rate-limit and abuse-prevention records are kept only as needed to operate the service, prevent misuse, investigate security issues, or resolve provider disputes. MealSync minimises these records where practical, for example by using hashed request fingerprints for demo and contact-form rate limits.
- Identifier-free aggregate funnel events are kept for up to 13 months so MealSync can compare launch cohorts, reliability, and operating cost. Older funnel events are deleted as new events are recorded.
- Privacy request audit records are kept as long as needed to show that privacy requests were received and handled, including for legal, consumer-rights, or dispute-handling purposes.
- Contact form and support messages are kept while needed to answer the request and handle follow-up. The contact form sends the message by email; support-message retention is therefore managed in MealSync's email/support workflow and may be longer where needed for legal claims, consumer-rights issues, billing questions, or security incidents.
- MealSync keeps Polar customer IDs, subscription IDs, plan, and entitlement status, checkout metadata, and legal acknowledgements while needed to provide paid access, handle support, prevent hidden renewals during account deletion, and resolve subscription or consumer-rights disputes. Polar separately handles buyer payment, invoice, tax, refund, and merchant-of-record records under Polar's terms.
Deleting a meal removes it from normal MealSync history and, if the meal was already synced and MealSync has the external record ID, attempts to delete the matching nutrition record from Google Health. Account deletion is irreversible once completed: MealSync attempts to cancel any active Polar subscription known to MealSync at period end, deletes MealSync-controlled uploaded source files, removes source metadata, deletes the stored Google Health connection, soft-deletes saved meals, anonymizes the MealSync profile, and signs the user out. If Polar cancellation or file deletion fails, account deletion is paused so the user is not left with a hidden active subscription or orphaned uploaded files.
Google Health records are controlled through Google Health and Google account permissions; if automatic deletion fails, the user may need to manage those records in Google Health or Google account settings.
Security
MealSync uses Google sign-in rather than passwords managed by MealSync, secure cookies, CSRF protection on authenticated actions, size and type checks for uploads, Cloudflare platform protections, encrypted storage for Google Health tokens, signed Polar webhook verification, and rate limits. No internet service can be perfectly secure, so users should only upload meal inputs they want processed for nutrition estimation.
GDPR rights
Users can delete meals, disconnect Google Health, manage billing through Polar, and delete the MealSync account in the app. Users can contact info@getmealsync.app to exercise rights that may apply under GDPR, including access, correction, deletion, restriction, objection, portability, and the right to complain to a supervisory authority. Synced nutrition records should be deleted by deleting the corresponding meal in MealSync. MealSync will then attempt to delete the matching Google Health nutrition record where the Google Health connection and stored record ID allow this. If that deletion is not completed through MealSync, users should contact MealSync support.
Not medical advice
MealSync provides nutrition estimates for personal self-tracking. It is not medical advice, not a diagnosis or treatment tool, and not a substitute for a qualified medical or dietetic professional.