Snugmeal

Privacy Policy

Short and jargon-free: what data the Snugmeal website and mobile app collect, why, and what your rights are. We collect only what is necessary — we don’t sell data and we don’t use trackers.

Effective from 25 August 2026. The previous version was effective from 24 August 2026 — we corrected the description of the contact form (the message goes to our server, not through your email app) and added sign-in with Google. The data we collect has not changed — its description has. The description of receipt scanning will return to this policy before we make the feature available. This is a courtesy translation; the Polish version at /polityka-prywatnosci is the binding one.

1. Who is responsible for your data

The data controller is Olivier Babula, the creator of Snugmeal, a natural person residing in Poland. For anything related to your data, write to contact@snugmeal.com. A postal correspondence address is provided without delay upon request sent to that address.

2. What this policy covers

The snugmeal.com website (waitlist, contact form, blog) and the Snugmeal mobile app (account, meal plans, shopping list).

3. The snugmeal.com website

  • Waitlist: your email address, country and a record of consent (date, consent text version, signup source) — based on your consent (Art. 6(1)(a) GDPR), with double opt-in (confirmation link valid for 48 hours).
  • Server logs: standard technical logs (IP address, browser type, request time) — our legitimate interest (Art. 6(1)(f) GDPR): security and stability.
  • Contact form: your browser submits the message to our server — your email app is not involved. We receive your email address, an optional subject and the body of the message, and we process them in order to reply (Art. 6(1)(f) GDPR). Your IP address reaches the server in the proxy headers, where it serves only as an anti-spam rate limit, and is recorded in the server logs (see above) — we do not store it in a database or include it in the message. Delivery to our mailbox is handled by Resend (Section 6), and your address goes into the “reply-to” field so that we can respond.

4. The app: account and profile

  • Account created with an email address: email, password (stored only as a cryptographic hash), 2FA login codes — necessary to provide the service (Art. 6(1)(b) GDPR).
  • Account created with Google: instead of a password you can sign in with your Google account — in that case there is no password at all. From the signed token issued by Google we store against your account: your email address, your display name, the URL of your profile picture, whether Google has verified that email, and your Google account identifier, which links it to your Snugmeal account (Art. 6(1)(b) GDPR). Beyond that we take nothing from your Google account — no contacts, no mail, no files — we keep no access tokens to it, and we never see your Google password.
  • Nutritional profile: including age, weight, height, weight goal, activity level, diet and allergies — this data can reveal health information, so we process it solely on the basis of your explicit consent(Art. 9(2)(a) GDPR), given in the app before you fill in the profile. Without this consent we cannot generate a plan — that is the only feature that requires it.
  • Plans, shopping list, tick-offs: functional account data (Art. 6(1)(b) GDPR).

5. Receipt scanning — a planned feature

The current version of the app does not have a receipt scanning feature — we plan to add it in the future. Before the feature reaches the app, we will update this policy with a full description of the processing (including processors and retention periods), and the app will ask you for a separate, voluntary consent (Art. 6(1)(a) GDPR) — without it nothing is sent.

The feature was briefly available in test builds of the app (TestFlight). If you used it then — with your consent, which you can withdraw in the settings: the receipt photo was deleted automatically at the latest after 7 days (short-term storage: Cloudflare R2, an EU-jurisdiction bucket; reading: Google Vertex AI in an EU region — both processors under data processing agreements with SCCs, certified under the EU-U.S. Data Privacy Framework), and the items and amounts read from it remain with your account until you delete them or delete the account. Prices from your receipts do not go into any shared price database — we have abandoned that feature. Older test builds may still allow scanning on the same terms until they are updated.

6. Who we share data with (processors)

We use trusted processors under data processing agreements (Art. 28 GDPR). App data is, as a rule, processed in the European Union:

  • Railway — API and database hosting (region: Amsterdam, EU); data processing agreement with standard contractual clauses (SCCs).
  • Resend — transactional emails (login codes) and contact-form messages delivered to our mailbox; a US company certified under the EU-U.S. Data Privacy Framework — delivery metadata may be processed in the USA.
  • OVH — hosting of the snugmeal.com website and the mailbox (EU).

Google as a login provider is a different case — not a processor, but a separate controller. If you choose “Sign in with Google”, Google authenticates you on its own terms (and learns that you are signing in to Snugmeal), and passes us a signed token carrying the data listed in Section 4. Nothing travels the other way: Google receives none of your nutritional profile, plans or shopping list from us. The route is optional — you can also create an account with an email address and password alone.

Some processors are US companies — we safeguard transfers with standard contractual clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, the EU-U.S. Data Privacy Framework. We do not sell data and do not share it with anyone except where required by law.

7. How long we keep data

  • Profile, plans, tick-offs (and items from receipts scanned in test builds): for as long as the account exists; deleting the account erases them irreversibly.
  • Waitlist: until you withdraw consent, and no longer than the end of launch communications.
  • Server logs: around 14 days. Correspondence: for as long as needed to handle the matter.

8. Cookies and tracking

The website does not use analytics or advertising cookies, does not rely on tools like Google Analytics or Meta Pixel, and does not profile users. The app contains no ads and no advertising SDKs.

9. Your rights

You have the right to:

  • access your data and get a copy of it (in the app: data export),
  • rectify, erase or restrict its processing,
  • data portability,
  • withdraw any consent at any time — in the app settings, without affecting the lawfulness of processing carried out before the withdrawal,
  • object to processing based on legitimate interest,
  • lodge a complaint with the President of the Polish Personal Data Protection Office (uodo.gov.pl) or your local supervisory authority.

You can delete your account in the app (Me → settings) — the account data is erased irreversibly. We make no automated decisions about you that produce legal effects (Art. 22 GDPR); meal plans are generated solely at your request.

10. Changes to this policy

If the scope of processing changes, we will update this document and the date at the top of the page, and we will announce significant changes in the app.

← Back to the homepage