Legal
Last updated: September 26, 2026
What personal data MealVerve collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have.
The controller of your personal data is Charalambos Rotsides, trading as MealVerve, Cyprus, who operates MealVerve on the web and in the Android app (“we”, “us”). For privacy questions, requests and general support, email support@mealverve.com.
We are not required to appoint a Data Protection Officer. Privacy requests are handled by the person named above at support@mealverve.com.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and run your account, save your recipes, plans and lists, social features and chat | Account, preferences, content | Contract (Art. 6(1)(b)) |
| Generate personalised recipes, meal plans, grocery lists and photo imports with AI | Preferences, content, photos you submit; body/health details only with your explicit consent | Contract (Art. 6(1)(b)); explicit consent for health details (Art. 9(2)(a)) |
| Sell and manage subscriptions, apply AI usage limits, prevent payment fraud | Account, subscription, AI usage | Contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Service messages: account, security, billing and email-verification emails | Email, account | Contract (Art. 6(1)(b)) |
| Meal-planning and grocery reminders by email or push | Email, push registration, notification settings | Legitimate interest in helping you use the service you signed up for (Art. 6(1)(f)); you can switch them off at any time |
| Security, abuse prevention, content moderation and handling reports | Technical data, content, reports | Legitimate interest (Art. 6(1)(f)); legal obligation where EU law requires (e.g. Digital Services Act) |
| Error monitoring and keeping the service reliable | Technical data, error reports | Legitimate interest (Art. 6(1)(f)) |
| Product analytics (PostHog) and advertising measurement (Meta Pixel and Meta Conversions API) | Pages viewed, events, device data, hashed email and IP for Meta | Consent (Art. 6(1)(a) and ePrivacy rules), which you can withdraw at any time |
| Publishing recipes you make public, and showing them in search engines | Public recipe, your display name | Contract (Art. 6(1)(b)), at your choice per recipe |
| Complying with law, answering authorities, defending legal claims | As needed | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest, you can object at any time (section 10). We never sell personal data and we do not use your data to train AI models.
Your height, weight, body-fat percentage, goal weight, goal type and allergies can reveal information about your health, which the GDPR treats as a special category of data. We process them only with your explicit consent (Art. 9(2)(a) GDPR), which you give by ticking a separate, unticked box in onboarding or your profile. We record when you consented and to which version of the wording.
When you use an AI feature, we send the relevant request to OpenAI: for example your recipe request, the photo you chose to import, your food preferences, and (only with your consent) your body and health details. OpenAI processes this as our processor, does not use API data to train its models, and may keep it for up to 30 days for abuse monitoring before deletion. AI-generated recipes, images and nutrition estimates are labelled as AI-assisted and can be wrong; see our Health & AI Disclaimer. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
Recipes are private unless you make them public. Public recipes, with your display name and photo, can be viewed by anyone, shared, and indexed by search engines. Other users can find your profile to follow you and message you; a private profile requires your approval for follows. Chat messages are visible to the people in that conversation. Your email address, preferences and health details are never shown to other users.
We use strictly necessary cookies and storage to sign you in and remember your choices. Optional analytics (PostHog) and advertising measurement (Meta Pixel, and the matching server-side Meta Conversions API for sign-ups and subscriptions) run only after you accept them in the privacy-choices panel, and stop when you withdraw. Ads are not currently shown. Details and the full list are in our Cookie Policy.
We use the service providers below to run MealVerve. They process data only on our instructions under data processing agreements, except Stripe, Google and Meta, which are independent controllers for parts of their own processing (e.g. fraud prevention, payments and their own advertising products) under their own privacy policies.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Auth0 (Okta) | Sign-in and account security; Google sign-in | United States | EU–US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs) |
| Supabase | Database hosting | EU (Frankfurt, Germany) | SCCs where data leaves the EU |
| Render | Application hosting | EU (Frankfurt, Germany) | SCCs where data leaves the EU |
| OpenAI | AI recipe, meal plan, grocery, photo import and image generation | USA | DPF / SCCs |
| Cloudinary | Storing and delivering images | USA | DPF / SCCs |
| Stripe | Web payments and subscriptions | EU (Ireland) and USA | DPF / SCCs |
| Google (Play Billing, Google sign-in) | Android payments and sign-in | EU and USA | DPF / SCCs |
| Resend | Sending emails | USA | SCCs |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Delivering push notifications you enabled | Various | Encrypted payload; provider terms |
| Google Fonts | Delivering web fonts (receives your IP address when a page loads) | Global | DPF / SCCs |
| Sentry | Error monitoring (personal-data collection disabled by default) | EU (Germany) | DPF / SCCs |
| PostHog (with consent) | Product analytics | USA | DPF / SCCs |
| Meta Platforms (with consent) | Measuring our advertising (Pixel, Conversions API with hashed email) | Ireland and USA | DPF / SCCs |
We may also disclose data to professional advisers, to a buyer if the business is sold, or where the law requires. Transfers outside the European Economic Area rely on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or the European Commission’s Standard Contractual Clauses. Ask us for a copy of the relevant safeguards at support@mealverve.com.
Under the GDPR you have the right to:
You can do most of this yourself: edit your profile, change notification settings, change privacy choices, and in Profile › Your data download all your data or delete your account (also explained on our account deletion page). For anything else, email support@mealverve.com. We reply within one month and may need to verify your identity.
You also have the right to complain to a data protection authority. In Cyprus this is the Commissioner for Personal Data Protection (dataprotection.gov.cy), or you can contact the authority where you live or work. We would appreciate the chance to resolve your concern first.
An email address is needed to create an account, and payment details are needed to buy a subscription. Everything else, including preferences and health details, is optional, though AI suggestions are less personal without it.
We use encryption in transit, access controls, row-level restrictions on the database, and providers with recognised security certifications. No system is perfectly secure; if a breach is likely to put you at high risk, we will tell you without undue delay.
MealVerve is for people aged 16 and over. The digital age of consent in Cyprus is 14, but we apply 16 across the EU. We do not knowingly collect data from younger children; if you believe a child has an account, contact us and we will delete it.
We will post changes here and update the date above. If a change is significant, we will tell you by email or in the app before it applies and, where the law requires, ask for your consent again.