Privacy Policy

Effective 2026-09-03 · Version 1.0

1. Who controls your data

Rafael Guedes (sole trader, Portugal) is the data controller for the personal data described in this policy. Contact us at support@confibite.app for any privacy question or request.

2. What we collect

The table below lists every category of personal data Confibite stores, why we're allowed to process it, and how long we keep it.

Category
Account identity
Examples
Email address, Supabase authentication user ID, display name
Lawful basis
Contract (GDPR Art. 6(1)(b)) — necessary to create and operate your account
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Diet profile (special category)
Examples
Strictness level, diet type (omnivore/vegetarian/vegan), excluded allergens
Lawful basis
Explicit consent (GDPR Art. 9(2)(a)) — this is health-related special-category data
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Per-food exclusions
Examples
Individual foods you've chosen to avoid, beyond your allergen profile
Lawful basis
Contract (GDPR Art. 6(1)(b)) — necessary to generate a plan that respects your choices
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Generated meal plans and shopping lists
Examples
Weekly meal plans, individual meals and ingredients, shopping-list items
Lawful basis
Contract (GDPR Art. 6(1)(b)) — this is the core service you signed up for
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Meal feedback flags
Examples
Which meals you've flagged, and a snapshot of that meal's ingredients at flag time
Lawful basis
Consent (GDPR Art. 6(1)(a)) — capture-only today, seeding a future analytics feature
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Usage events
Examples
Counts of plan generations and meal swaps, used to enforce the monthly PRO quota
Lawful basis
Contract (GDPR Art. 6(1)(b)) — necessary to enforce the plan you're subscribed to
Retention
For the life of the account, then deleted within 30 days of an erasure request
Category
Billing identifiers
Examples
Polar customer ID, Polar subscription ID, subscription status
Lawful basis
Contract (GDPR Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for tax/accounting records
Retention
For the life of the account; Polar retains statutory billing records for longer, as required by tax law, even after account deletion
Category
Scrubbed error reports
Examples
Application error events with cookies, headers, request bodies, query strings, and full URLs removed; the internal user ID only, never the email address
Lawful basis
Legitimate interest (GDPR Art. 6(1)(f)) — keeping the service reliable and secure
Retention
Per Sentry's own retention window (90 days), then automatically deleted

3. Your health data

Your diet profile — strictness level, diet type, and excluded allergens — reveals information about your health, which the GDPR treats as a special category of personal data (Article 9). We only process it because you explicitly consent to this during onboarding, before any meal plan is generated.

You can withdraw this consent at any time by emailing support@confibite.app. Because Confibite cannot generate a safe meal plan without a diet profile, withdrawing consent means deleting your account rather than continuing to use the Service without one.

4. Where your data goes

We use the following sub-processors to run the Service. None of them may use your data for any purpose other than providing their service to us.

Sub-processor
Purpose
Database, authentication, and session management
Data shared
Account identity, diet profile, allergen exclusions, generated meal plans, shopping lists, meal feedback, and usage events — the full application dataset
Location
EU region (Supabase project hosted in the EU)
Sub-processor
Purpose
Payment processing — acts as Merchant of Record for PRO subscriptions
Data shared
Billing identifiers (customer and subscription IDs) and payment/subscription status; Polar collects and processes card details directly, they are never handled by Confibite
Location
European Union / United States
Sub-processor
Purpose
Large-language-model calls that generate weekly meal plans and single-meal swaps
Data shared
Diet type, strictness level, excluded allergens, and the eligible food pool are sent as part of the prompt; per Anthropic's API terms, prompt data is not used to train models
Location
United States
Sub-processor
Purpose
Error monitoring
Data shared
Scrubbed error reports only — cookies, headers, request bodies, query strings, and full URLs are stripped before an event is sent (see the app's error-monitoring safeguards); the account's internal user ID is retained, never the email address
Location
United States
Sub-processor
Purpose
Application hosting and content delivery network
Data shared
Standard request/access logs (IP address, requested path, timestamps) needed to serve the app
Location
United States (global CDN edge network)
Sub-processor
Purpose
Internal operational notification — alerts the team when a new user confirms their email
Data shared
Display name and email address only; no diet, allergen, or other health-related data is ever included
Location
United States

Generating a meal plan or a single-meal swap sends your diet type, strictness level, and excluded allergens to Anthropic as part of the prompt that produces the plan. Per Anthropic's API terms, prompt data submitted through the API is not used to train their models.

5. International transfers

Anthropic, Sentry, and Vercel are based in the United States. Transferring data to them relies on the European Commission's Standard Contractual Clauses (SCCs) as the transfer safeguard. Supabase, our database and authentication provider, hosts this project's data in the EU.

6. Retention and erasure

We keep your data for as long as your account is active. If you ask us to delete your account and data — email support@confibite.app — we complete the erasure within 30 days, except for billing records that Polar must retain under tax and accounting law, which persist beyond account deletion for the period the law requires.

7. Your rights

Under the GDPR, you have the right to: access the personal data we hold about you; rectify inaccurate data; request erasure; restrict or object to processing; receive your data in a portable format; and not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on you. (Confibite's meal-plan generation always passes through a fixed, deterministic ingredient-safety check before you see a result — it is not used to make any decision about you as a person.)

To exercise any of these rights, email support@confibite.app. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese data protection supervisory authority, at https://www.cnpd.pt.

8. Cookies

Confibite uses a single cookie: the Supabase authentication/session cookie that keeps you signed in, set with the SameSite=Lax attribute. We do not use advertising cookies, analytics cookies, or any other tracking technology.

9. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from them.

10. Changes to this policy

We may update this policy as the Service evolves. We'll update the effective date and version above when we do.

11. Contact

Questions about this policy or your data? Email support@confibite.app. See also our Terms of Service.