Privacy Policy
What we collect, why, who receives it, how long we keep it, and how you get rid of it.
Last updated: 1 August 2026
1. Who is responsible
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
{{FULL_LEGAL_NAME}}{{STREET_AND_HOUSE_NUMBER}}
{{POSTAL_CODE}} {{CITY}}
Deutschland
Email: {{PRIVACY_EMAIL}}
Full provider details are in the Impressum. We have not appointed a data protection officer; questions go to the address above.
2. What this policy covers
This policy covers the ShredPlate web app and the services behind it. ShredPlate is a tracking and planning tool for food, recipes and groceries. It is not a medical device, and it does not diagnose, treat or monitor any condition.
3. What we collect
- Account data — your email address and profile name, managed by our self-hosted identity provider (Keycloak). We never see or store your password.
- Kitchen and food data — pantry and inventory items, saved and generated recipes, meal plans, grocery lists, and the food, water and meal entries you log.
- Photos you upload — pictures of your kitchen, fridge, shelves or ingredients. These often show more than food: rooms, packaging, handwriting, sometimes people. Upload only what you are comfortable sharing.
- Body and nutrition metrics — body weight over time, body fat percentage, gender, age, activity level, calculated energy requirements, and your goal phase (for example cutting or bulking).
- Free text you write — goal notes, recipe prompts, excluded ingredients, dietary preferences, and your messages to the AI assistant.
- Payment data — if you subscribe, your payment details are collected and processed by our payment provider. We receive the subscription status, the invoice and a payment reference; we never receive your full card number.
- Technical data — authentication tokens, IP address and server logs needed to run and secure the service. We run no advertising, no third-party analytics and no tracking pixels.
4. Health data and other special categories
Some of what ShredPlate stores is special category personal data under Art. 9 GDPR, and we treat it as such. Specifically:
- Body metrics. A weight series over time, together with body fat, calculated energy requirements and a cut or bulk phase, permits inferences about your health. Following the Court of Justice of the European Union in case C-184/20, data from which health status can be inferred is itself health data.
- Free text about diet and health. Goal notes, dietary preferences, excluded ingredients and assistant messages routinely contain statements such as “coeliac”, “diabetic”, “pregnant” or “lactose intolerant” (health data), and “halal” or “kosher” (data revealing religious belief).
- Kitchen photos. A photo of a fridge or a shelf can reveal medication, medical nutrition products, an observant diet and — if someone is in frame — images of identifiable people.
We process this category only on your explicit consent under Art. 9(2)(a) GDPR, given separately from your acceptance of the terms and never bundled with it. The features that depend on it — body-metric tracking, the AI assistant, and photo-to-ingredient recognition — are optional. The pantry, recipe and grocery features work without them.
You can withdraw that consent at any time, with effect for the future, without giving reasons, and with no disadvantage beyond losing the features that depend on it. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Please do not put health details into free-text fields that do not need them, and do not upload photos of anything you would not want processed.
5. What we use it for
- Operating the core app: pantry, recipes, meal plans and grocery lists.
- Recording the nutrition and body metrics you choose to log, and showing them back to you.
- Generating recipes, answering assistant messages and identifying ingredients in photos — all of which involve sending data to OpenAI, described below.
- Billing, invoicing, and meeting our tax and accounting obligations.
- Keeping accounts secure, preventing abuse, and diagnosing faults.
We do not sell personal data, do not use it for advertising, and do not use your content to train AI models.
6. Legal bases
- Art. 6(1)(b) — performance of the contract: providing the app, your account, and the paid subscription.
- Art. 6(1)(a) together with Art. 9(2)(a) — your explicit consent, for body metrics, dietary and health free text, kitchen photos, and the AI features that process them.
- Art. 6(1)(c) — legal obligations, above all retaining invoices and accounting records.
- Art. 6(1)(f) — our legitimate interest in keeping the service secure and available (log data, abuse prevention).
7. OpenAI, and the transfer to the United States
Three features send your data to OpenAI for processing. OpenAI acts as our processor under Art. 28 GDPR:
- Recipe generation — your ingredients, dietary preferences and excluded ingredients, and your energy and macro targets. Prompts can include body-derived figures such as your calculated daily energy requirement, gender, age and weight.
- AI assistant — your messages, plus the context needed to answer them, which may include pantry contents and nutrition data.
- Photo recognition — the kitchen and ingredient photos you upload are transmitted to OpenAI's vision models to identify items.
This is a transfer to a third country. OpenAI is established in the United States. The transfer is safeguarded by the EU Standard Contractual Clauses concluded with OpenAI as part of our data processing agreement, together with supplementary technical and organisational measures. Where OpenAI is certified under the EU–US Data Privacy Framework, that certification applies in addition.
You should know what this means in practice: United States authorities may in principle have powers of access to data held by US providers that go beyond what EU law permits, and the routes of redress available to you there are more limited than in the EU. Because these features run on explicit consent, you can decline them and still use the rest of the app.
We send only what the requested feature needs, and we do not permit OpenAI to use your content to train its models.
8. Other recipients
- {{HOSTING_PROVIDER_LEGAL_NAME}} — hosting of the servers, database and object storage the service runs on. Location: {{HOSTING_DATACENTRE_LOCATION}}.
- Keycloak — the identity provider that handles sign-in. We host it ourselves on the infrastructure above; it is not a separate recipient.
- {{PAYMENT_PROVIDER_LEGAL_NAME}} — payment processing, invoicing and subscription management.
- {{EMAIL_PROVIDER_LEGAL_NAME}} — sending transactional email such as sign-up verification and password resets.
- Public authorities — only where we are legally obliged to disclose.
Each processor is engaged under a written data processing agreement (Art. 28 GDPR).
9. International transfers
Our own infrastructure is located in the European Union. The transfer to OpenAI in the United States, described in section 7, is the only routine transfer outside the EU and EEA, and it takes place on the basis of Standard Contractual Clauses and your explicit consent to the features concerned.
10. How long we keep things
| Data | Retention |
|---|---|
| Account (email, profile name), held in Keycloak | While the account exists; removed when you delete the account |
| Body metrics: weight log, body fat, gender, age, energy targets | While the account exists, so your history stays intact; removed with the account, or earlier on request |
| Food, water and meal logs | While the account exists; removed with the account |
| Pantry, inventory, recipes, meal plans, grocery lists | While the account exists; removed with the account |
| Kitchen and ingredient photos (object storage) | Until you delete the photo, or the account is deleted |
| AI assistant conversations | While the account exists; you can delete individual conversations |
| Server and security logs | Short-term, for operating and securing the service |
| Invoices and payment records | Kept for the statutory period of up to 10 years (§147 AO, §257 HGB) — we cannot delete these on request |
| Encrypted database backups | Rotated after a fixed window — see “Deletion, and the backup carve-out” below |
Where a statutory retention period applies — chiefly to invoices and accounting records — we restrict processing of that data instead of deleting it, and delete it once the period ends.
11. Deletion, and the backup carve-out
You can delete your account at any time from Profile → Account in the app, or by asking us at the address below. Deletion removes your account and the personal data associated with it from our live systems.
Backups are the exception, and we would rather be plain about it. We take encrypted backups of the production database so the service can be restored after a failure. A backup taken before your deletion still contains your data, and an individual record cannot be surgically edited out of a backup archive without destroying its integrity as a restore point.
So: your data may persist in encrypted backups for up to {{BACKUP_RETENTION_DAYS}} days after deletion, after which those backups are rotated out and destroyed. During that window the backups are encrypted, access is restricted to restoring the service, and the data is used for no other purpose. If a backup ever has to be restored, we re-apply outstanding deletions to the restored system.
12. Your rights
Under the GDPR you have the right to:
- Access your data (Art. 15) — in the app under Profile → Account.
- Rectify inaccurate data (Art. 16).
- Erasure (Art. 17) — see section 11, including its limits.
- Restriction of processing (Art. 18).
- Data portability (Art. 20) — export a machine-readable copy.
- Object to processing based on legitimate interests (Art. 21), on grounds relating to your particular situation.
- Withdraw consent at any time (Art. 7(3)), including the Art. 9(2)(a) consent for health data, with effect for the future.
To exercise any of these, use the in-app tools or write to {{PRIVACY_EMAIL}}. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority (Art. 77). The authority competent for us is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin. You may also complain to the authority where you live or work.
13. Storage and security
Structured data — account, pantry, recipes, plans, metrics, messages — is held in a PostgreSQL database; uploaded photos are held in S3-compatible object storage. Connections are encrypted in transit, backups are encrypted at rest, and access is limited to what is needed to operate the service.
14. Cookies and local storage
We store authentication tokens in your browser's local storage so you stay signed in. That is strictly necessary for a service you explicitly requested, so no consent banner is required under §25(2) no. 2 TDDDG. We set no advertising cookies and use no third-party analytics.
15. Automated decision-making
We make no decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Art. 22 GDPR. The AI features generate suggestions — recipes, estimated nutrition figures, assistant answers — which you are free to ignore. They are generated automatically, can be wrong, and are not medical, nutritional or dietary advice.
16. Children
ShredPlate is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
17. Changes to this policy
We may update this policy. We will revise the “last updated” date above, and for material changes — particularly any change to what we do with health data, or to who receives it — we will notify you in the app or by email before the change takes effect.
18. Contact
Privacy questions and data-subject requests: {{PRIVACY_EMAIL}}. Postal address and provider details are in the Impressum. See also our Terms of Service.