Privacy Policy – Meal Planner
Effective Date: September 27, 2026
Your privacy matters to us. This Privacy Policy explains how we, Multiapps SL, B27858174, based in Spain, handle your personal data when you use Meal Planner, whether on mobile or web. We’re committed to protecting your data and being transparent about how it’s used.
You can view this policy anytime under: Settings → Privacy & Permissions → Privacy Policy
1. Who’s Responsible for Your Data?
Multiapps SL is the data controller for the purposes of the General Data Protection Regulation (GDPR). If you have questions, you can reach us via the app or at: 📧 [email protected]
2. What Data Do We Process?
We collect and process your personal data in the following situations:
2.1 When You Download the App
When you install Meal Planner from the App Store or Google Play, your device shares information with those platforms, such as your email address, payment method, and device ID. This is handled solely by the app store and is beyond our control.
2.2 When You Use the App
You can create notes, meal plans, and upload photos from your device. These may include personal information such as names, dietary habits, or other private content. If you're not signed in, your data stays only on your device. If you log in, we store it securely on our private servers (Parse Server) to enable cross-device syncing.
📌 Legal basis: Art. 6(1)(b) GDPR – contract performance.
2.3 When You Use Sync Features
When signed in, we use your email and login credentials to authenticate and sync your content across your devices using our Parse Server backend.
📌 Legal basis: Art. 6(1)(b) GDPR.
2.4 When You Use Our AI Tools (in development)
If you activate AI-powered features, we may send the content you submit (e.g. text entries or questions) to OpenAI to generate suggestions or assistance.
📌 Legal basis: Art. 6(1)(b) GDPR.
Full details are available in our Data Processing Agreement.
2.5 When You Opt-In to Donate Data
You can choose to share anonymized usage data and entries with us to help improve features like AI meal suggestions.
📌 Legal basis: Art. 6(1)(a) GDPR – consent. You can withdraw this consent anytime in: Settings → Privacy & Permissions → Donate Your Data
2.6 When You Connect Apple Health or Health Connect
Meal Planner can sync with Apple Health (HealthKit, on iPhone and iPad) and Health Connect (on Android). The integration is off by default. Each type of data has its own switch in Settings → Apple Health (or Settings → Health Connect), and we only access the data types you turn on and allow on the system permission screen.
Data we read from Apple Health or Health Connect, and why:
- Weight, body fat percentage, height and waist circumference (waist on iPhone only): added to your weight diary and body measurements, so weigh-ins from smart scales and other apps appear without typing them again. When you connect, we also import your earlier records so your history and charts are complete.
- Water: added to your water tracker, without counting twice what you already logged in the app.
- Workouts and their active calories, recorded by your watch or other apps: shown in the calorie counter and added to the calories you burned that day.
- Sex and date of birth (iPhone only): used only to fill in your body profile when it's empty, to calculate your calorie needs. We keep only the year of birth.
Data we write to Apple Health or Health Connect: your weigh-ins, height, body fat percentage, waist circumference and BMI (waist and BMI on iPhone only), water, the calories and nutrients (protein, fat, carbohydrates, fiber, sugar and sodium) of each meal in your calorie counter, and the exercise you log (as workouts or active calories). We only write data you recorded in the app.
How this data is stored and used:
- Weigh-ins, body measurements, water and profile data imported from Apple Health or Health Connect become part of your diaries. They are stored on your device and, if you're signed in, on our Parse Server to sync your devices, like any other content you add (see sections 2.2 and 2.3).
- Workouts read from other apps are kept only on your device, only for the current week, and are never sent to our servers.
- We use this data only to provide these features to you. We never sell it, never use it for advertising, marketing or profiling, never use it for data mining, never share it with third parties (including the AI providers in section 3) and never store it in iCloud. Nobody at Multiapps SL reads it, except with your permission, for security purposes or to comply with the law.
Your control: you can turn each switch off at any time, or revoke the permissions in the Health app (your profile → Apps) or in Health Connect (App permissions). Turning a switch off stops the sync; data already saved in Apple Health or Health Connect stays there until you delete it from those apps. Imported data stays in your diaries until you delete it there or delete your account (see section 4).
Our use of information received from Health Connect adheres to the Health Connect Permissions policy, including its Limited Use requirements. Our use of HealthKit data follows Apple's App Store Review Guidelines for health data (section 5.1.3).
📌 Legal basis: Art. 6(1)(a) and Art. 9(2)(a) GDPR – your explicit consent, given when you turn on each data type and allow it in Apple Health or Health Connect. You can withdraw it anytime by turning off the switch or revoking the permission.
2.7 When You Visit Our Website
We collect standard log data, including:
- IP address, browser type, and OS
- Time and date of access
- Pages visited
- Device type and location data (if enabled)
📌 Legal basis: Art. 6(1)(f) GDPR – legitimate interest (security, analytics, troubleshooting)
2.8 When You Contact Us
If you reach out via contact form, email, or social media, we process your details to handle your request. We keep these communications only as long as needed to respond.
📌 Legal basis: Art. 6(1)(b) or (f) GDPR – contract or legitimate interest.
3. Who Has Access to Your Data?
We never sell your data. But we work with trusted service providers (“processors”) to run the app:
| Processor | Purpose | Notes |
|---|---|---|
| Parse Server | Cloud storage & syncing | Hosted privately by us |
| Firebase (Google LLC) | Analytics & crash reports | Covered by Standard Contractual Clauses |
| OpenAI | AI features (optional, beta) | Data processed outside the EU – SCCs apply |
All third-party providers are carefully selected, contractually bound, and only process data on our instructions.
Data read from Apple Health or Health Connect is never shared with Firebase, OpenAI or any other third party; it is only stored on our own Parse Server to sync your diaries when you're signed in (see section 2.6).
4. How Long Do We Keep Your Data?
We retain your data only as long as needed to provide the service or until you delete your account. Backups may be kept for up to 30 days for recovery purposes. Workouts read from Apple Health or Health Connect are kept only on your device, only for the current week.
5. Your Rights Under GDPR
You have the right to:
- Access your data (Art. 15)
- Correct inaccurate data (Art. 16)
- Delete your data (Art. 17)
- Restrict processing (Art. 18)
- Port your data (Art. 20)
- Withdraw consent (Art. 7(3))
- Object to processing (Art. 21)
To exercise any of these rights, contact us through the app or via the email listed above.
6. Right to File a Complaint
You have the right to lodge a complaint with a data protection authority in your country (Art. 77 GDPR) if you believe your data is being misused.
7. Data Security
We use encryption (TLS) to protect your data during transmission. We also apply industry-standard security measures for storage and access control.
If you have questions, contact us at [email protected].