Privacy Policy
Effective 2026-09-03 · Version 1.0
1. Who controls your data
Rafael Guedes (sole trader, Portugal) is the data controller for the personal data described in this policy. Contact us at support@confibite.app for any privacy question or request.
2. What we collect
The table below lists every category of personal data Confibite stores, why we're allowed to process it, and how long we keep it.
| Category | Examples | Lawful basis | Retention |
|---|---|---|---|
| Account identity | Email address, Supabase authentication user ID, display name | Contract (GDPR Art. 6(1)(b)) — necessary to create and operate your account | For the life of the account, then deleted within 30 days of an erasure request |
| Diet profile (special category) | Strictness level, diet type (omnivore/vegetarian/vegan), excluded allergens | Explicit consent (GDPR Art. 9(2)(a)) — this is health-related special-category data | For the life of the account, then deleted within 30 days of an erasure request |
| Per-food exclusions | Individual foods you've chosen to avoid, beyond your allergen profile | Contract (GDPR Art. 6(1)(b)) — necessary to generate a plan that respects your choices | For the life of the account, then deleted within 30 days of an erasure request |
| Generated meal plans and shopping lists | Weekly meal plans, individual meals and ingredients, shopping-list items | Contract (GDPR Art. 6(1)(b)) — this is the core service you signed up for | For the life of the account, then deleted within 30 days of an erasure request |
| Meal feedback flags | Which meals you've flagged, and a snapshot of that meal's ingredients at flag time | Consent (GDPR Art. 6(1)(a)) — capture-only today, seeding a future analytics feature | For the life of the account, then deleted within 30 days of an erasure request |
| Usage events | Counts of plan generations and meal swaps, used to enforce the monthly PRO quota | Contract (GDPR Art. 6(1)(b)) — necessary to enforce the plan you're subscribed to | For the life of the account, then deleted within 30 days of an erasure request |
| Billing identifiers | Polar customer ID, Polar subscription ID, subscription status | Contract (GDPR Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax/accounting records | For the life of the account; Polar retains statutory billing records for longer, as required by tax law, even after account deletion |
| Scrubbed error reports | Application error events with cookies, headers, request bodies, query strings, and full URLs removed; the internal user ID only, never the email address | Legitimate interest (GDPR Art. 6(1)(f)) — keeping the service reliable and secure | Per Sentry's own retention window (90 days), then automatically deleted |
3. Your health data
Your diet profile — strictness level, diet type, and excluded allergens — reveals information about your health, which the GDPR treats as a special category of personal data (Article 9). We only process it because you explicitly consent to this during onboarding, before any meal plan is generated.
You can withdraw this consent at any time by emailing support@confibite.app. Because Confibite cannot generate a safe meal plan without a diet profile, withdrawing consent means deleting your account rather than continuing to use the Service without one.
4. Where your data goes
We use the following sub-processors to run the Service. None of them may use your data for any purpose other than providing their service to us.
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Database, authentication, and session management | Account identity, diet profile, allergen exclusions, generated meal plans, shopping lists, meal feedback, and usage events — the full application dataset | EU region (Supabase project hosted in the EU) |
| Polar | Payment processing — acts as Merchant of Record for PRO subscriptions | Billing identifiers (customer and subscription IDs) and payment/subscription status; Polar collects and processes card details directly, they are never handled by Confibite | European Union / United States |
| Anthropic | Large-language-model calls that generate weekly meal plans and single-meal swaps | Diet type, strictness level, excluded allergens, and the eligible food pool are sent as part of the prompt; per Anthropic's API terms, prompt data is not used to train models | United States |
| Sentry | Error monitoring | Scrubbed error reports only — cookies, headers, request bodies, query strings, and full URLs are stripped before an event is sent (see the app's error-monitoring safeguards); the account's internal user ID is retained, never the email address | United States |
| Vercel | Application hosting and content delivery network | Standard request/access logs (IP address, requested path, timestamps) needed to serve the app | United States (global CDN edge network) |
| Slack | Internal operational notification — alerts the team when a new user confirms their email | Display name and email address only; no diet, allergen, or other health-related data is ever included | United States |
Generating a meal plan or a single-meal swap sends your diet type, strictness level, and excluded allergens to Anthropic as part of the prompt that produces the plan. Per Anthropic's API terms, prompt data submitted through the API is not used to train their models.
5. International transfers
Anthropic, Sentry, and Vercel are based in the United States. Transferring data to them relies on the European Commission's Standard Contractual Clauses (SCCs) as the transfer safeguard. Supabase, our database and authentication provider, hosts this project's data in the EU.
6. Retention and erasure
We keep your data for as long as your account is active. If you ask us to delete your account and data — email support@confibite.app — we complete the erasure within 30 days, except for billing records that Polar must retain under tax and accounting law, which persist beyond account deletion for the period the law requires.
7. Your rights
Under the GDPR, you have the right to: access the personal data we hold about you; rectify inaccurate data; request erasure; restrict or object to processing; receive your data in a portable format; and not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on you. (Confibite's meal-plan generation always passes through a fixed, deterministic ingredient-safety check before you see a result — it is not used to make any decision about you as a person.)
To exercise any of these rights, email support@confibite.app. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese data protection supervisory authority, at https://www.cnpd.pt.
8. Cookies
Confibite uses a single cookie: the Supabase authentication/session cookie that keeps you signed in, set with the SameSite=Lax attribute. We do not use advertising cookies, analytics cookies, or any other tracking technology.
9. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them.
10. Changes to this policy
We may update this policy as the Service evolves. We'll update the effective date and version above when we do.
11. Contact
Questions about this policy or your data? Email support@confibite.app. See also our Terms of Service.