Privacy Policy
How EatMe processes your data, protects your privacy, and keeps your kitchen information secure.
1. Data Controller
The controller responsible for processing personal data on this website (https://eatme-app.com) and within the EatMe mobile application under the General Data Protection Regulation (GDPR) is:
EatMe — Leon Gött
Am Bug 36, 86757 Wallerstein, Germany
Phone: +49 159 0 266 7509
Email: hello@eatme-app.com
Website: https://eatme-app.com
2. Processing Overview
EatMe helps you keep track of groceries in your household, track best-before dates, synchronize shopping lists, and organize recipes. We follow strict data minimization principles: we only collect and process data strictly required to deliver our core services reliably and securely.
3. Collected Data Categories and Purposes
a) Registration, Authentication & Account
Sign-in is passwordless via email (magic link or 6-digit one-time code). We store your email address and issue secure session tokens so your pantry inventory and shopping lists synchronize seamlessly across your devices.
b) Pantry, Household & Recipe Data
We store the pantry items you record (item name, quantity, storage location, expiry date, category), shopping lists, household memberships, and your created or imported recipes. When you share a recipe, a cryptographic token is generated to allow recipe previewing and importing.
c) Camera & Media Permissions (Barcodes, Expiry Dates & Recipe Photos)
The app only accesses your camera when you actively trigger a scanning feature:
- Barcode Scanning: Recognizes barcodes directly on-device to fetch product information.
- Best-Before OCR: Reads printed expiry dates on packaging using on-device optical character recognition. Live camera streams are never sent to remote servers.
- Recipe Photo Import & Uploads: When you upload a photo of a dish or recipe text, the image is stored in encrypted cloud storage for your household access.
d) Push Notifications & Local Timers
Enabling notifications registers a device push token used solely to notify you when groceries are approaching their expiry date. Active cooking timers run locally on your device.
e) Server Logs & Technical Telemetry
When accessing web services, standard server access logs (IP address, request timestamp, browser user agent, operating system) are captured temporarily for system stability, fraud prevention, and DDoS mitigation.
4. Subprocessors & Third-Party Services
We rely on vetted infrastructure providers bound by GDPR Data Processing Agreements (Art. 28 GDPR):
Supabase (Database, Auth & Storage)
Supabase Inc. provides our managed PostgreSQL database, user authentication, and object storage. Our database instance is hosted in the EU region Frankfurt (AWS eu-west-1). Data is encrypted in transit and at rest.
AWS Lambda (Amazon Web Services)
Serverless compute functions handle recipe URL parsing, photo text recognition, and AI-assisted recipe generation based on your ingredients. Only text and photo payloads required for processing are transmitted.
Open Food Facts (Product Catalog)
To match scanned barcodes with grocery names and categories, we query the Open Food Facts open database through our secure server proxy. No personal user information is passed to Open Food Facts.
Cloudflare (Hosting & Edge Delivery)
Cloudflare Inc. serves eatme-app.comand protects our web endpoints against DDoS attacks and security threats.
5. Legal Bases under the GDPR
- Art. 6(1)(b) GDPR (Performance of a contract):Processing account information, pantry inventories, shopping lists, and recipes to provide EatMe's core services.
- Art. 6(1)(a) GDPR (Consent):Voluntary permissions including push notifications and camera permissions for scanning barcodes or expiry dates. Consent can be revoked anytime in your device settings.
- Art. 6(1)(f) GDPR (Legitimate interests):Ensuring technical security, fraud prevention, and service reliability.
6. Data Retention and Account Deletion
Your data is retained for as long as your account remains active. You can delete your account and all associated household inventories, lists, and recipes at any time directly in the app settings or by emailing hello@eatme-app.com.
7. Your Rights as a Data Subject
Under GDPR provisions, you have the following rights:
- Right of access (Art. 15 GDPR): Request a copy of your personal data.
- Right to rectification (Art. 16 GDPR): Correct inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): Delete your personal data.
- Right to restriction of processing (Art. 18 GDPR): Restrict further processing.
- Right to data portability (Art. 20 GDPR): Receive data in a structured format.
- Right to object (Art. 21 GDPR): Object to processing based on legitimate interests.
- Right to lodge a complaint (Art. 77 GDPR): Lodge a complaint with a supervisory authority.
You do not have to ask us for the first two: sign in at your account and download a copy of your data as a JSON file, or open Settings › Privacy & Legal in the app. Deleting your account, and everything in it, works the same way from the app. For anything else write to hello@eatme-app.com; we answer within one month.
8. Security and Contact
We employ strict encryption (TLS), role-based database row-level security (RLS), and modern development practices to safeguard your information.
If you have privacy questions, please contact hello@eatme-app.com.