🚀 Eatper is currently in development — Download the app when we launch!

Eatper Privacy Policy

Version: 1.0.0

Effective date: 12 August 2026

Last updated: 12 August 2026

This Privacy Policy explains how Perplatform Oy processes personal data when you use the Eatper mobile application, an Eatper account, the Eatper website and contact form, reports, exports, support, and other services that link to this policy (together, the Service).

1. Controller and contact details

The controller is:

Perplatform Oy

Business ID: 3568783-4

Vilkastuksenkatu 7

20320 Turku

Finland

Email: support@eatper.com

In this policy, Eatper, we, us, and our mean Perplatform Oy.

Contact support@eatper.com with privacy questions or to exercise a privacy right. Please do not send health details or identity documents by ordinary email unless we specifically ask for information through an appropriate channel.

2. Key points

3. Where personal data comes from

We receive personal data:

We do not obtain your medical records, precise GPS location, contacts, microphone recordings, advertising identifiers, or data from Apple Health or Android Health Connect.

4. Personal data we process

4.1 Account and sign-in data

Depending on how you register or sign in, we process:

We do not receive your Apple or Google password. A password you create directly for Eatper is processed by the authentication system in protected verification form, not stored by us in readable text.

4.2 Profile, settings, and eligibility data

We process your self-declared date of birth, country or food-catalogue country, language or locale, timezone, onboarding state, dietary preferences, notification settings, analytics choice, consent status, and application settings.

The date of birth is used to check that you declare yourself to be 18 or older and, when relevant, to calculate requested nutrition estimates. Eatper does not verify age using an identity document.

4.3 Nutrition, body, diary, and wellness data

Information you choose to record may include:

This information may constitute or reveal special-category health data under European data-protection law. Section 7 explains the explicit consents used for cloud processing and personalized reports.

4.4 Shared food-catalogue contributions

When you create a custom food, we process the product name, brand, barcode, country, nutrient values, serving information, and other product facts. The custom food is public to other authenticated Eatper users in the shared catalogue. The public entry does not display your Eatper identity, but we keep an internal owner link while the item is user-owned.

Do not enter personal data, private notes, or health information in custom-food fields. User-owned custom foods are removed through the account-deletion process.

4.5 Food-data reports and evidence photographs

If you report a catalogue problem, we process the report type, product or barcode reference, search context, before-and-after product values, source name or source URL you provide, correction notes, status, and resolution messages. The report types can include incorrect nutrition or serving information, wrong barcode, duplicate product, missing product, or discontinued product.

You may optionally upload photographs of product packaging or labels as evidence. Eatper normalizes accepted files to JPEG and removes embedded EXIF and similar device metadata before storage. Evidence photographs are private and are available only to you and authorized Eatper personnel for moderation and support. They are not placed in the public catalogue.

Factual corrections may be incorporated into the catalogue. If your account is deleted, the account link to a retained correction is removed.

4.6 Reports and exports

With separate report consent, Eatper processes weekly and monthly report snapshots, daily nutrition or weight series, targets, averages, adherence measures, comparisons, and personalized text insights. We also process report generation, view, export, and notification status.

If you request an account export or a report export, we create a temporary package and process request status, expiry information, a short-lived email token, and download authorization. Account exports can include the personal data associated with your account, including retained private evidence photographs.

4.7 Subscription and purchase data

Apple App Store or Google Play handles payment-card and billing details. We do not receive your full card number. We process the store, product and plan identifier, transaction or purchase token, original transaction or purchase reference, subscription state, start and expiry times, renewal or cancellation status, storefront where available, verification results, and account-entitlement link needed to provide and restore paid access and prevent fraud.

Apple and Google process purchases under their own privacy policies and act as independent controllers for parts of their store relationship with you.

4.8 Notifications and local reminders

If you enable remote report-ready notifications, we process a device registration token, platform, application environment, notification preferences, last-active time, and delivery status. The report-ready push contains generic wording such as “Your weekly report is ready,” an opaque report reference, and technical routing information. It does not contain calories, weight, food names, diary entries, or report text. Your operating system may display the generic message on a lock screen depending on your settings.

Meal and weight reminders are scheduled locally on your device. Their schedule and settings remain in the application’s local database and are not sent to Eatper’s server merely to deliver the local reminder.

4.9 Optional product analytics

If you opt in, Eatper uses PostHog Cloud EU to process a randomly generated analytics identifier and coarse product events such as:

Analytics events are designed not to contain your Eatper account identifier, email, provider identifier, food name, search text, barcode, diary contents, nutrition or body values, receipt, or report content. We disable session replay, autocapture, user profiles, location enrichment, and feature-flag collection in this integration.

Analytics is off by default. Withdrawing analytics consent stops new collection immediately and queues deletion of the existing PostHog analytics identifier. If you opt in again later, Eatper creates a new random identifier.

4.10 Essential diagnostics, security, and service records

We process technical information needed to operate and protect the Service, which may include application version, device platform and operating-system version, time, request or response status, sanitized error type, sanitized stack trace, coarse performance measures, synchronization state, security events, IP address or network metadata processed by hosting systems, and server or audit logs.

Eatper uses Sentry Cloud EU for essential error and performance monitoring. The integration is configured without user identity, request or response bodies, headers, cookies, query strings, application breadcrumbs, local variables, or Eatper domain values. Production performance sampling is limited. Network addressing may still be processed transiently when a device connects to the service.

We also record privacy notices shown, consent version and choice, Terms version and acceptance time, export or deletion workflow status, and limited operational evidence needed to demonstrate requests and secure the system.

4.11 Website and support data

If you use the Eatper website contact form or email us, we process your name, email address, message, attachments you choose to send, correspondence, support status, and network or anti-abuse metadata generated by the website, hosting, or email systems. Do not include health details unless they are necessary for the request.

5. Device permissions and device-only processing

Camera and barcode scanning

If you choose barcode scanning, Eatper asks for camera permission. Camera frames are analyzed on the device to decode the barcode and are not uploaded as video or stored as photographs. The decoded barcode is used to search Eatper’s catalogue. If the barcode is missing locally, Eatper’s backend may ask Open Food Facts for that exact barcode; it does not include your Eatper account identifier, diary, body, or nutrition data in that request.

Photo library or camera evidence

If you choose to attach packaging evidence to a food-data report, Eatper asks for the relevant camera or photo-library permission. Only the photograph you select or take for the report is uploaded.

Local application data, widgets, and reminders

Eatper keeps a local application database to make the application responsive and support offline use. Some locally stored data may also be synchronized to the cloud if the relevant cloud consent is active. Local reminders remain device-only. If you enable a home-screen widget or similar system surface, nutrition or progress values may be visible to anyone who can view that device surface.

Uninstalling the application normally removes its application storage from that device but does not delete your Eatper cloud account. Deleting the account begins cloud deletion; to remove all copies under your control, also clear or uninstall Eatper on devices that may retain local data.

6. Why we process data and our legal bases

The legal bases below apply where the EU General Data Protection Regulation or a similar lawful-basis framework applies.

PurposePersonal dataLegal basis
Create, authenticate, secure, and administer an accountAccount, sign-in, profile, eligibility, settings, and basic technical recordsPerformance of the Eatper contract; legitimate interests in preventing abuse and securing accounts
Provide local and cloud Service features requested by youProfile, settings, diary, food, recipe, nutrition, weight, target, and synchronization dataPerformance of the contract for ordinary service data; for health-related cloud data, your consent under Article 6(1)(a) and explicit consent under Article 9(2)(a) GDPR
Generate personalized weekly and monthly reports and insightsDiary, nutrition, weight, target, and derived report dataSeparate consent under Article 6(1)(a) and explicit consent under Article 9(2)(a) GDPR
Operate the shared food catalogue and moderate contributionsCustom foods, product facts, internal ownership link, correction reports, and evidencePerformance of the contract; legitimate interests in maintaining an accurate and safe catalogue; consent is not used to make private health data public
Verify and provide subscriptionsStore, plan, transaction, purchase-token, entitlement, and anti-fraud dataPerformance of the contract; compliance with accounting, tax, and consumer-law duties; legitimate interests in fraud prevention and legal claims
Deliver notifications you enableDevice token, preferences, report type and opaque identifier, delivery statusYour request and consent or device permission; performance of requested Service features
Run optional product analyticsRandom analytics identifier and coarse product eventsConsent under Article 6(1)(a) GDPR
Diagnose, secure, and maintain the ServiceSanitized error, performance, request, network, security, audit, and system recordsLegitimate interests in providing a reliable and secure Service and preventing misuse; legal obligations where applicable
Handle exports, deletion, privacy choices, and legal evidenceRequest status, temporary files and tokens, Terms and notice versions, consent records, and deletion auditPerformance of the contract; compliance with privacy and consumer-law obligations; legitimate interests in demonstrating compliance and defending legal claims
Respond to website, support, or business enquiriesName, email, message, correspondence, and support metadataSteps requested before a contract or performance of the contract; legitimate interests in responding to enquiries and operating support
Comply with law and protect rightsRelevant account, transaction, security, support, and legal recordsLegal obligation; legitimate interests in establishing, exercising, or defending legal claims

Where we rely on legitimate interests, we consider the necessity of the processing, its impact on you, and the safeguards available. You may object as described in Section 14.

7. Explicit consent for health-related data and reports

7.1 Core cloud processing

Before Eatper sends diary, nutrition, weight, body-detail, or goal information to the cloud, it asks for a specific explicit consent. This consent is separate from agreement to the Terms.

If you do not consent, cloud synchronization and server-dependent features using that data are unavailable. If you withdraw the consent in Settings, Eatper stops new cloud processing for that purpose, restricts affected features, and queues the affected cloud health and nutrition data for erasure. Withdrawal does not affect processing that was lawful before withdrawal.

7.2 Personalized reports and insights

Eatper asks separately for consent to create personalized weekly and monthly reports and insights. If you do not consent, your core diary and target features can still operate to the extent otherwise enabled, but personalized reports are not generated.

If you withdraw report consent, future report processing stops and stored report snapshots and derived insights are queued for deletion. The underlying diary or target data is retained only if the separate core-cloud consent remains active.

7.3 Other optional choices

Product analytics, push notifications, and device permissions use separate controls. You may change them in Eatper Settings or the device operating-system settings. Analytics withdrawal also queues deletion of the existing random analytics identity. Turning off push permission stops display by the operating system; Eatper also removes or expires the associated registration when it is no longer active.

You may withdraw consent at any time without charge. A feature that technically requires the withdrawn data may stop working, but withdrawal does not cancel an app-store subscription.

8. When we disclose personal data

We disclose personal data only as needed for the purposes in this policy, under appropriate contractual and security safeguards.

Recipient or categoryRole and purposeTypical data
SupabaseAuthentication, database, storage, and related backend infrastructureAccount data, synchronized Service data, reports, private evidence, settings, and operational records
VercelBackend application hosting, API execution, delivery, and technical logsRequests needed to provide server features and associated technical metadata
Apple and GoogleSign-in when chosen, app distribution, subscription billing and verification, and independent app-store servicesAuthentication data selected by you; product, transaction, token, entitlement, device, and store data
Firebase Cloud Messaging and Apple Push Notification serviceDelivery of generic report-ready notificationsDevice registration token, application environment, generic message, opaque report reference, and delivery data
PostHog Cloud EUOptional product analyticsRandom analytics identifier and minimized product events described in Section 4.9
Sentry Cloud EUEssential privacy-minimized diagnostics and performance monitoringSanitized error, stack, platform, version, timing, and performance data described in Section 4.10
ResendTransactional and security email delivery, including export noticesEmail address, message template and delivery metadata, and short-lived action link or token where needed
Website hosting, form, and email providersHost eatper.com, transmit contact forms, prevent abuse, and deliver or store correspondenceName, email, message, network or anti-abuse metadata, and correspondence
Professional advisers and authoritiesLegal, accounting, audit, security, insurance, dispute, or regulatory mattersOnly data reasonably necessary for the matter, under confidentiality or legal controls
Business successorA merger, reorganization, financing, or sale involving the ServiceRelevant records subject to confidentiality, notice, and continuing privacy obligations

Our providers may use approved subprocessors. Some recipients, such as Apple and Google for their app-store relationship, determine certain purposes independently and provide their own privacy notices.

Open Food Facts is a public data source, not the host of your Eatper account. When a missing exact barcode is queried, Open Food Facts receives the barcode and technical server request information, not your Eatper account identifier, email, diary, body, nutrition, or report data.

We may disclose information if required by law, a binding court or authority order, or where necessary and proportionate to protect users, the public, Perplatform Oy, or the Service. We will assess requests and disclose only what is legally required where permitted.

We do not:

9. Open Food Facts data

Eatper’s catalogue includes data from Open Food Facts. Food product data is © Open Food Facts contributors and is used under the Open Database License 1.0; individual database contents are available under the Database Contents License. Eatper does not import Open Food Facts product images.

Open Food Facts-derived catalogue data is kept logically separate and may be provided in a separately identified export where licence obligations require it. Public product data is not your personal data merely because you viewed or logged a product; your diary association with that product remains private account data.

10. International transfers

Eatper is operated from Finland. The primary Supabase project is configured in an EU region, and PostHog and Sentry are configured for their EU cloud regions. Some providers or their subprocessors may nevertheless process data outside Finland or the European Economic Area, including in the United States, for hosting, support, security, app-store, email, or notification functions.

When European personal data is transferred to a country that does not have an applicable European Commission adequacy decision, we use an appropriate transfer mechanism such as the European Commission’s Standard Contractual Clauses, together with supplementary technical or organizational measures where required. A provider may instead rely on an applicable adequacy framework. You may contact us for more information about the relevant safeguards.

11. How long we keep data

We keep personal data only for the period needed for the purposes described below, then delete or irreversibly de-identify it unless law requires a longer period. Retention runs may be asynchronous, and isolated backups expire on their normal rotation rather than being edited record by record.

DataRetention
Account identity, basic profile, and non-health settingsWhile the account is active; queued for deletion when the account is deleted, subject to the limited exceptions below
Diary, recipes, meals, nutrition profile and targets, weight, body details, goals, and other synchronized health-related Service dataWhile the account is active and the relevant cloud-health consent remains valid; queued for deletion when the account is deleted or that consent is withdrawn, subject to the limited exceptions below
Personalized report snapshots and insightsWhile the account and separate report consent remain active; deleted after report-consent withdrawal or account deletion
User-owned custom foodsUntil you delete or deactivate them where supported, or until account deletion; account deletion removes the custom food from the shared catalogue
Factual catalogue correctionsFor as long as the corrected fact remains useful to catalogue integrity; the author link is removed on account deletion
Open food-data report and private evidence photographWhile needed to investigate the open report, no more than 180 days for the evidence photograph
Resolved, rejected, withdrawn, or otherwise terminal food-report evidenceNo more than 30 days after terminal status; de-identified factual corrections may remain in the catalogue
Account-export or report-export packageUp to 7 days after creation, then deleted
Account-export email tokenUp to 24 hours; signed download authorization is limited to approximately 5 minutes
Active push registrationWhile needed for an enabled device; inactive registrations are removed after up to 90 days
Push outbox and delivery historyUp to 30 days after terminal delivery state
Optional PostHog analytics eventsUp to 12 months; earlier deletion is queued when consent is withdrawn
Analytics activation-delivery recordsDelivered records up to 30 days; an undelivered activation record remains only until accepted or analytics consent is withdrawn
Sentry diagnostic events and sampled tracesUp to 90 days
Ordinary server and security logsUp to 30 days, unless an event must be isolated for investigation
Security-incident, fraud, abuse, or legal-claim recordsFor the investigation and up to 24 months afterward, or longer where a live claim or law requires it
Website contact and support correspondenceWhile the matter is active and up to 12 months after resolution, unless a contract, dispute, or law requires longer
Subscription entitlement and transaction evidenceWhile needed to provide or restore access and for the accounting, tax, consumer, fraud-prevention, and claims periods required by law; accounting records are commonly retained for up to six years or the longer applicable statutory period
Terms acceptance, privacy-notice presentation, and consent recordsWhile the account is active; deleted with the account unless limited evidence is needed to meet a legal duty or resolve a live claim
Minimal deletion auditFor the period reasonably necessary to verify that the deletion workflow completed and protect the integrity of the system; designed not to identify the former user directly
Isolated backupsOverwritten or expired on a rolling schedule of no more than 90 days; backups are not used to restore deleted data into the live Service

The 12-month PostHog, 90-day Sentry, 30-day ordinary-log, 12-month resolved-enquiry, and 90-day backup limits are maximum retention periods that Perplatform Oy applies to the Service.

12. Account deletion, local copies, and subscription status

You can request account deletion in Eatper Settings. Once submitted, Eatper restricts account access and begins an asynchronous process that deletes or de-identifies account data across the relevant service stores. This includes cloud diary, nutrition, body, weight, target, report, private evidence, device-registration, and user-owned custom-food data. Catalogue-correction authorship is removed if a factual correction remains.

Deletion may retain only limited information described in Section 11, such as records required by tax or accounting law, evidence needed for a live security or legal matter, and a minimal non-identifying completion audit. Backup copies expire within the stated rotation and are not used to recreate an erased account.

Before deletion, you may request an account export. The temporary package, token, and signed link expire according to Section 11.

Deleting an account does not cancel an Apple App Store or Google Play subscription. You must cancel through the store to prevent future renewal. Uninstalling Eatper does not delete the cloud account; after deleting the account, also remove local copies from any device you control.

13. Security

We use technical and organizational safeguards designed for the sensitivity of the data, including:

No service can guarantee absolute security. Keep your device and sign-in methods secure, use a unique password where you create one, and contact support@eatper.com if you suspect unauthorized access. Do not send passwords, store receipts, or unnecessary health details by email.

14. Your privacy rights

Depending on where you live and the law that applies, you may have the right to:

Many records can be viewed or corrected in the application. Account and report exports are available through Eatper’s export features. To make another request, email support@eatper.com from the address connected to your account and describe the request.

We may request information reasonably necessary to confirm your identity and protect the account. We normally respond without undue delay and within one month where the GDPR applies; a lawful extension may apply for a complex or numerous request. Requests are normally free, although applicable law may allow a reasonable fee or refusal for a manifestly unfounded or excessive request.

Rights are not absolute. For example, we may retain transaction records required by law or information needed for a legal claim. If we cannot fulfill a request, we will explain the applicable reason and available complaint route.

Our lead supervisory authority is the Office of the Data Protection Ombudsman of Finland. You may report suspected unlawful processing or contact the Office of the Data Protection Ombudsman. If you live elsewhere in the EEA, you may also complain to your local supervisory authority.

15. Automated calculations and decisions

Eatper uses rule-based formulas to estimate calorie and macronutrient targets and automated processing to create trends, comparisons, and reports when enabled. It also uses the date of birth you provide to enforce the 18+ eligibility rule. These features do not diagnose you and are not used to make a solely automated decision that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

You can change manual targets where the feature allows, stop using a calculation, withdraw report consent, or contact support if you believe an input or result is wrong.

16. Children

Eatper is not intended for anyone under 18, and we do not knowingly offer accounts to children. The age check relies on the date of birth entered by the user; Eatper does not collect identity documents for age verification.

If you believe a person under 18 has created an account, contact support@eatper.com. We will investigate and restrict or delete the account as appropriate.

17. Cookies, software development kits, and similar technology

The mobile application uses software development kits needed for authentication, subscriptions, notifications, optional analytics, and essential diagnostics as described in this policy. Eatper does not use an advertising SDK or advertising identifier.

The public website is not intended to use advertising or behavioural-analytics cookies. It may use strictly necessary cookies or similar technical storage for security, form delivery, load balancing, or basic website operation. If we add non-essential website analytics or advertising technology, we will provide any required consent control and update this policy before using it.

18. U.S. consumer health data notice

This Section supplements the rest of the policy for consumer health data laws that apply to wellness information outside traditional healthcare settings, including Washington’s My Health My Data Act and Nevada’s consumer health data law. It applies to Washington residents, people whose consumer health data is collected in Washington, Nevada consumers, and others entitled to similar rights under applicable law.

Categories of consumer health data and how we use them

Eatper may collect the following consumer health data, as those laws define it:

CategorySourcesPurposes and manner of processing
Body and physical characteristicsDirectly from youRecord height, weight, target weight, weight history, body-fat estimate, age-related input, and sex selection used in formulas; synchronize when consented; calculate requested targets and trends
Nutrition, food, and dietary informationDirectly from you, Eatper catalogue records you select, and calculations from your entriesMaintain diary and meal records, calculate nutrient totals, support recipes and targets, synchronize requested features, and provide reports when separately consented
Goals, activity, and wellness preferencesDirectly from youPersonalize targets, settings, progress views, and separately consented reports
Inferences and derived wellness informationGenerated from the information aboveProduce totals, adherence measures, trends, comparisons, and general wellness insights; never diagnose a condition
Health-related Service and notification metadataYour device and the ServiceSynchronize requested data, secure the account, generate or export reports, record that a report is ready, and deliver a generic notification if enabled

The categories of sources are you, your device and Eatper application, catalogue data you choose to associate with your diary, calculations performed by Eatper, and the processors that return operational status for a requested feature. Eatper does not collect consumer health data from data brokers, advertising networks, precise location providers, medical records, or connected health platforms.

Consumer health data disclosed or shared

Eatper discloses the categories above only to processors needed to provide a feature you request:

Resend receives an email address and a temporary action link for transactional mail, not the health content of an export or report. PostHog is configured to exclude body, nutrition, diary, food, search, barcode, and report values. Sentry is configured to exclude Eatper domain values and account identity. Apple and Google receive purchase and store-entitlement data but not your Eatper diary, body measurements, or nutrition values.

We do not disclose consumer health data to an affiliate. We do not share it with a third party for that party’s own advertising, profiling, data-broker, insurance, employment, healthcare, or other independent commercial purpose. We do not sell consumer health data. We do not use a geofence around a healthcare facility or collect precise location. No third party is permitted by Eatper to collect consumer health data over time across unrelated websites or online services when you use Eatper.

Consent and requests

Eatper obtains affirmative explicit consent before cloud processing of the core health-related categories and a separate consent before personalized report processing. Disclosures to processors are limited to what is necessary to provide the requested Service and are governed by processing contracts. If a future use or disclosure requires a separate consent under applicable law, Eatper will obtain it before the use or disclosure.

You may:

Use the Settings controls for consent withdrawal, export, correction, or account deletion, or email support@eatper.com with Consumer Health Data Request in the subject. You do not have to create a new account to submit a request, although we may ask you to use an existing account or provide information reasonably necessary to authenticate it.

We will respond within the period required by applicable law. For a Washington request, this is generally within 45 days, with one additional 45-day extension where reasonably necessary and properly notified. Consumer health data in archived backups is deleted within the shorter 90-day rotation promised in Section 11. Requests are free at least as often as required by law.

To appeal, reply to the decision or email support@eatper.com with Privacy Appeal in the subject and explain why you believe the decision should be changed. We will respond in writing within the applicable appeal period. If a Washington appeal is denied, you may contact the Washington Attorney General. If a Nevada appeal is denied, you may contact the Nevada Attorney General.

19. Information for residents outside the EEA

Perplatform Oy applies the core safeguards in this policy to Eatper users worldwide. Local law may provide additional rights or different terminology.

Where a United States state privacy law applies to Perplatform Oy and your data, you may request access, correction, deletion, or a portable copy and may appeal a denied request by replying to our decision. We will not discriminate against you for exercising an applicable privacy right. We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use health-related data for purposes incompatible with providing the Service. We do not offer a financial incentive in exchange for personal data.

Because Eatper does not engage in sale or targeted-advertising sharing, it does not provide a “Do Not Sell or Share” link. You may still contact support@eatper.com with an applicable request. Authorized agents may act where local law permits, subject to verification of the request and authorization.

20. Changes to this policy

We may update this policy to reflect changes in the Service, providers, law, or data practices. We will make the current version available on the Eatper Privacy Policy page and in the application.

For a material change, we will provide prominent in-app notice before the change takes effect where practicable. If a new purpose requires consent, we will ask for that consent rather than treating continued use as consent. A privacy-policy presentation record shows that a version was displayed; it is not treated as your acceptance of the policy.

21. Contact us

Privacy questions and requests may be sent to:

Perplatform Oy

Vilkastuksenkatu 7

20320 Turku

Finland

support@eatper.com