Eatper Privacy Policy

Version: 1.0.2
Effective date: 2 September 2026
Last updated: 2 September 2026

This Privacy Policy explains how Perplatform Oy processes personal data when you use the Eatper mobile application, an Eatper account, the Eatper website and contact form, reports, exports, support, and other services that link to this policy (together, the Service).

1. Controller and contact details

The controller is:

Perplatform Oy
Business ID: 3568783-4
Vilkastuksenkatu 7
20320 Turku
Finland
Email: support@eatper.com

In this policy, Eatper, we, us, and our mean Perplatform Oy.

Contact support@eatper.com with privacy questions or to exercise a privacy right. Please do not send health details or identity documents by ordinary email unless we specifically ask for information through an appropriate channel.

2. Key points

  • Eatper is for adults aged 18 or older.
  • Diary entries, weight, body details, goals, and nutrition information are private account data. They are not shown in the shared food catalogue.
  • Because this information may reveal health information, Eatper asks for explicit consent before processing it in the cloud.
  • Personalized weekly and monthly reports use a separate optional consent.
  • A custom food is saved as your private food. If you choose to submit it for catalogue review, authorized Eatper personnel may review its product facts and may publish corrected or standardized facts as a separate public catalogue entry. Your Eatper identity is not shown with that entry.
  • Optional PostHog product analytics is off by default and starts only after opt-in. It uses a random analytics identifier rather than your Eatper account identifier.
  • Essential Sentry error monitoring is privacy-minimized and does not intentionally include account, diary, food, body, or nutrition values.
  • The public contact form uses Cloudflare Turnstile to prevent automated abuse and Resend to deliver your message to Eatper support. Turnstile does not receive the contact-form fields.
  • Eatper does not sell personal data, use it for targeted advertising, or provide health information to employers, insurers, data brokers, or healthcare providers.
  • You can export or delete your account in the application. Withdrawing cloud-health consent or report consent triggers deletion of the affected data and disables the dependent features. Copies may remain temporarily in isolated backups for up to 90 days and expire automatically through normal backup rotation; they are unavailable through the Service and are not used to restore a deleted account.

3. Where personal data comes from

We receive personal data:

  • directly from you when you register, complete onboarding, record information, create foods, submit reports, contact support, or make privacy choices;
  • from your device and the application when the Service synchronizes, secures, diagnoses, or delivers requested features;
  • from Apple or Google when you choose their sign-in, subscription, purchase, or notification services;
  • from app stores when they send subscription entitlement and transaction status needed to provide paid access;
  • from Open Food Facts when a barcode lookup or catalogue import returns public food-product data; and
  • from our service providers when they return delivery, security, diagnostic, or support information.

We do not obtain your medical records, precise GPS location, contacts, microphone recordings, advertising identifiers, or data from Apple Health or Android Health Connect.

4. Personal data we process

4.1 Account and sign-in data

Depending on how you register or sign in, we process:

  • email address, authentication account identifier, authentication status, and password-verification data managed by our authentication provider;
  • connected sign-in method, provider identity identifier, and tokens needed to authenticate or link the account;
  • for Google sign-in, email and basic profile information made available through the requested email and profile scopes; and
  • for Apple sign-in, the email address or Apple private relay address that Apple makes available.

We do not receive your Apple or Google password. A password you create directly for Eatper is processed by the authentication system in protected verification form, not stored by us in readable text.

4.2 Profile, settings, and eligibility data

We process your self-declared date of birth, country or food-catalogue country, language or locale, timezone, onboarding state, dietary preferences, notification settings, analytics choice, consent status, and application settings.

The date of birth is used to check that you declare yourself to be 18 or older and, when relevant, to calculate requested nutrition estimates. Eatper does not verify age using an identity document.

4.3 Nutrition, body, diary, and wellness data

Information you choose to record may include:

  • date of birth, sex selection used in formulas, height, current and target weight, weight history, body-fat estimate, and activity level;
  • goals, rate-of-change preference, dietary preferences, calorie or macronutrient targets, manual target adjustments, and target history;
  • diary dates, meals, food entries, quantities, recipes, ingredients, steps, reusable meals or foods, recurring meal settings, pins, recents, and copied entries;
  • nutrition totals, adherence measures, trends, report inputs, report outputs, and report-view status; and
  • optional notes attached to weight or food records.

This information may constitute or reveal special-category health data under European data-protection law. Section 7 explains the explicit consents used for cloud processing and personalized reports.

4.4 Private custom foods and catalogue review

When you create a custom food, we process the product name, brand, barcode, country, category, section or subcategory, nutrient values, serving information, and other product facts. The account-owned custom food is saved as private and is not shown to other users. We keep an internal owner link so that you can find, use, edit, or remove it.

The application provides an optional Submit for catalogue review control. If you choose it, Eatper copies relevant product facts—such as the name, brand, barcode, and nutrient values—into a moderation record linked internally to your account. Authorized Eatper personnel can review the submitted facts and the review status, add internal moderation notes, reject the submission, match it to an existing product, or correct and standardize the facts before publication. The private custom food remains private during review.

If a submission is approved, Eatper may create a separate public catalogue entry from the accepted factual product information. Other authenticated Eatper users may find and use that public entry. The public entry does not display your account identity, diary, private custom-food record, or moderation notes. Because the published entry is a separate de-identified catalogue record, accepted product facts may remain in the shared catalogue after you change or delete the private custom food or delete your account; the account link to the retained submission is removed through account deletion.

Do not enter personal data, private notes, health information, or confidential information in custom-food fields. Your private, account-owned custom foods are removed through the account-deletion process.

4.5 Food-data reports and evidence photographs

If you report a catalogue problem, we process the report type, product or barcode reference, search context, before-and-after product values, source name or source URL you provide, correction notes, status, and resolution messages. The report types can include incorrect nutrition or serving information, wrong barcode, duplicate product, missing product, or discontinued product.

You may optionally upload photographs of product packaging or labels as evidence. Eatper normalizes accepted files to JPEG and removes embedded EXIF and similar device metadata before storage. Evidence photographs are private and are available only to you and authorized Eatper personnel for moderation and support. They are not placed in the public catalogue.

Factual corrections may be incorporated into the catalogue. If your account is deleted, the account link to a retained correction is removed.

4.6 Reports and exports

With separate report consent, Eatper processes weekly and monthly report snapshots, daily nutrition or weight series, targets, averages, adherence measures, comparisons, and personalized text insights. We also process report generation, view, export, and notification status.

If you request an account export or a report export, we create a temporary package and process request status, expiry information, a short-lived email token, and download authorization. Account exports can include the personal data associated with your account, including retained private evidence photographs.

4.7 Subscription and purchase data

Apple App Store or Google Play handles payment-card and billing details. We do not receive your full card number. We process the store, product and plan identifier, transaction or purchase token, original transaction or purchase reference, subscription state, start and expiry times, renewal or cancellation status, storefront where available, verification results, and account-entitlement link needed to provide and restore paid access and prevent fraud.

Apple and Google process purchases under their own privacy policies and act as independent controllers for parts of their store relationship with you.

4.8 Notifications and local reminders

If you enable remote report-ready notifications, we process a device registration token, platform, application environment, notification preferences, last-active time, and delivery status. The report-ready push contains generic wording such as “Your weekly report is ready,” an opaque report reference, and technical routing information. It does not contain calories, weight, food names, diary entries, or report text. Your operating system may display the generic message on a lock screen depending on your settings.

Meal and weight reminders are scheduled locally on your device. Their schedule and settings remain in the application's local database and are not sent to Eatper's server merely to deliver the local reminder.

4.9 Optional product analytics

If you opt in, Eatper uses PostHog Cloud EU to process a randomly generated analytics identifier and coarse product events such as:

  • application session and onboarding milestones;
  • whether a food search or barcode scan succeeded and coarse result-count buckets;
  • creation or copying of a diary item, meal, or day;
  • paywall, purchase-flow, subscription-lifecycle, and restore outcomes; and
  • synchronization and application-operation outcomes.

Analytics events are designed not to contain your Eatper account identifier, email, provider identifier, food name, search text, barcode, diary contents, nutrition or body values, receipt, or report content. We disable session replay, autocapture, user profiles, location enrichment, and feature-flag collection in this integration.

Analytics is off by default. Withdrawing analytics consent stops new collection immediately and queues deletion of the existing PostHog analytics identifier. If you opt in again later, Eatper creates a new random identifier.

4.10 Essential diagnostics, security, and service records

We process technical information needed to operate and protect the Service, which may include application version, device platform and operating-system version, time, request or response status, sanitized error type, sanitized stack trace, coarse performance measures, synchronization state, security events, IP address or network metadata processed by hosting systems, and server or audit logs.

Eatper uses Sentry Cloud EU for essential error and performance monitoring. The integration is configured without user identity, request or response bodies, headers, cookies, query strings, application breadcrumbs, local variables, or Eatper domain values. Production performance sampling is limited. Network addressing may still be processed transiently when a device connects to the service.

We also record privacy notices shown, consent version and choice, Terms version and acceptance time, export or deletion workflow status, and limited operational evidence needed to demonstrate requests and secure the system.

4.11 Website and support data

The public website stores your selected language in your browser's local storage so that it can use the same language on later visits. Eatper does not use that preference for advertising or behavioural analytics. The public website does not provide account sign-in, identity verification, or direct account deletion.

If you use the website contact form, we process the name, email address, enquiry category, message, and language you submit. The form does not accept attachments. If you email us directly, we process your email address, message, any attachment you choose to send, correspondence, and support status. Do not include passwords, identity documents, payment-card details, or health information unless we specifically ask for information through an appropriate channel.

The contact form uses Cloudflare Turnstile to distinguish people from automated traffic. When the widget loads, Cloudflare processes security signals such as the client IP address, TLS fingerprint, User-Agent header, site key and associated origin, and other browser or client-side signals needed for bot detection. Cloudflare states that Turnstile does not access, store, or transmit the contact-form fields, communications, or other page inputs. Turnstile generates a short-lived, single-use verification token. Eatper's backend sends that token to Cloudflare for validation and checks the approved hostname and contact-form action before accepting the message. The token is not included in the support email.

After successful verification, Eatper uses Resend to transmit the submitted name, email address, category, language, and message to Eatper's monitored support inbox. Resend also processes ordinary email-delivery metadata. The contact endpoint does not create a separate Eatper database record for a successful submission; the delivered message and later correspondence are kept in the support mailbox and relevant provider systems under the retention periods below. Website hosting and security systems may also process IP address, request time, origin, request status, and similar technical metadata.

5. Device permissions and device-only processing

Camera and barcode scanning

If you choose barcode scanning, Eatper asks for camera permission. Camera frames are analyzed on the device to decode the barcode and are not uploaded as video or stored as photographs. The decoded barcode is used to search Eatper's catalogue. If the barcode is missing locally, Eatper's backend may ask Open Food Facts for that exact barcode; it does not include your Eatper account identifier, diary, body, or nutrition data in that request.

Photo library or camera evidence

If you choose to attach packaging evidence to a food-data report, Eatper asks for the relevant camera or photo-library permission. Only the photograph you select or take for the report is uploaded.

Local application data, widgets, and reminders

Eatper keeps a local application database to make the application responsive and support offline use. Some locally stored data may also be synchronized to the cloud if the relevant cloud consent is active. Local reminders remain device-only. If you enable a home-screen widget or similar system surface, nutrition or progress values may be visible to anyone who can view that device surface.

Uninstalling the application normally removes its application storage from that device but does not delete your Eatper cloud account. Deleting the account begins cloud deletion; to remove all copies under your control, also clear or uninstall Eatper on devices that may retain local data.

6. Why we process data and our legal bases

The legal bases below apply where the EU General Data Protection Regulation or a similar lawful-basis framework applies.

PurposePersonal dataLegal basis
Create, authenticate, secure, and administer an accountAccount, sign-in, profile, eligibility, settings, and basic technical recordsPerformance of the Eatper contract; legitimate interests in preventing abuse and securing accounts
Provide local and cloud Service features requested by youProfile, settings, diary, food, recipe, nutrition, weight, target, and synchronization dataPerformance of the contract for ordinary service data; for health-related cloud data, your consent under Article 6(1)(a) and explicit consent under Article 9(2)(a) GDPR
Generate personalized weekly and monthly reports and insightsDiary, nutrition, weight, target, and derived report dataSeparate consent under Article 6(1)(a) and explicit consent under Article 9(2)(a) GDPR
Provide private custom foods, operate the shared food catalogue, and moderate optional contributionsPrivate custom foods, submitted product facts, internal ownership and reporter links, review status and notes, correction reports, and evidencePerformance of the contract; legitimate interests in maintaining an accurate and safe catalogue; consent is not used to make private health data public
Verify and provide subscriptionsStore, plan, transaction, purchase-token, entitlement, and anti-fraud dataPerformance of the contract; compliance with accounting, tax, and consumer-law duties; legitimate interests in fraud prevention and legal claims
Deliver notifications you enableDevice token, preferences, report type and opaque identifier, delivery statusYour request and consent or device permission; performance of requested Service features
Run optional product analyticsRandom analytics identifier and coarse product eventsConsent under Article 6(1)(a) GDPR
Diagnose, secure, and maintain the ServiceSanitized error, performance, request, network, security, audit, and system recordsLegitimate interests in providing a reliable and secure Service and preventing misuse; legal obligations where applicable
Protect the public contact form from automated abuseTurnstile token and browser, device, network, site-key, origin, and challenge signalsLegitimate interests in protecting the website and support channel, preventing spam and abuse, and maintaining service security
Handle exports, deletion, privacy choices, and legal evidenceRequest status, temporary files and tokens, Terms and notice versions, consent records, and deletion auditPerformance of the contract; compliance with privacy and consumer-law obligations; legitimate interests in demonstrating compliance and defending legal claims
Respond to website, support, or business enquiriesName, email, enquiry category, language, message, correspondence, and support metadataSteps requested before a contract or performance of the contract; legitimate interests in responding to enquiries and operating support
Comply with law and protect rightsRelevant account, transaction, security, support, and legal recordsLegal obligation; legitimate interests in establishing, exercising, or defending legal claims

Where we rely on legitimate interests, we consider the necessity of the processing, its impact on you, and the safeguards available. You may object as described in Section 14.

7. Explicit consent for health-related data and reports

7.1 Core cloud processing

Before Eatper sends diary, nutrition, weight, body-detail, or goal information to the cloud, it asks for a specific explicit consent. This consent is separate from agreement to the Terms.

If you do not consent, cloud synchronization and server-dependent features using that data are unavailable. If you withdraw the consent in Settings, Eatper stops new cloud processing for that purpose, restricts affected features, and queues the affected cloud health and nutrition data for erasure. Withdrawal does not affect processing that was lawful before withdrawal.

7.2 Personalized reports and insights

Eatper asks separately for consent to create personalized weekly and monthly reports and insights. If you do not consent, your core diary and target features can still operate to the extent otherwise enabled, but personalized reports are not generated.

If you withdraw report consent, future report processing stops and stored report snapshots and derived insights are queued for deletion. The underlying diary or target data is retained only if the separate core-cloud consent remains active.

7.3 Other optional choices

Product analytics, push notifications, and device permissions use separate controls. You may change them in Eatper Settings or the device operating-system settings. Analytics withdrawal also queues deletion of the existing random analytics identity. Turning off push permission stops display by the operating system; Eatper also removes or expires the associated registration when it is no longer active.

You may withdraw consent at any time without charge. A feature that technically requires the withdrawn data may stop working, but withdrawal does not cancel an app-store subscription.

8. When we disclose personal data

We disclose personal data only as needed for the purposes in this policy, under appropriate contractual and security safeguards.

Recipient or categoryRole and purposeTypical data
SupabaseAuthentication, database, storage, and related backend infrastructureAccount data, synchronized Service data, reports, private evidence, settings, and operational records
VercelBackend application hosting, API execution, delivery, and technical logsRequests needed to provide server features and associated technical metadata
Apple and GoogleSign-in when chosen, app distribution, subscription billing and verification, and independent app-store servicesAuthentication data selected by you; product, transaction, token, entitlement, device, and store data
Firebase Cloud Messaging and Apple Push Notification serviceDelivery of generic report-ready notificationsDevice registration token, application environment, generic message, opaque report reference, and delivery data
PostHog Cloud EUOptional product analyticsRandom analytics identifier and minimized product events described in Section 4.9
Sentry Cloud EUEssential privacy-minimized diagnostics and performance monitoringSanitized error, stack, platform, version, timing, and performance data described in Section 4.10
Cloudflare TurnstileProtect the website contact form from bots and automated abuseClient IP address, TLS fingerprint, User-Agent header, site key and associated origin, other browser or client-side challenge signals, and a short-lived verification token; not the contact-form fields
ResendTransactional and security email delivery, export notices, and transmission of website contact messagesEmail address, message template and delivery metadata, short-lived action link or token where needed, and for contact submissions the submitted name, email, category, language, and message
Support mailbox providerReceive, store, and organize support correspondenceDelivered contact message, email addresses, correspondence, attachments sent by email, and ordinary mailbox metadata
Other authenticated Eatper usersUse approved entries in the shared food catalogueAccepted, de-identified factual product information from an approved catalogue submission; not the contributor's account identity, private custom-food record, diary, or internal moderation notes
Professional advisers and authoritiesLegal, accounting, audit, security, insurance, dispute, or regulatory mattersOnly data reasonably necessary for the matter, under confidentiality or legal controls
Business successorA merger, reorganization, financing, or sale involving the ServiceRelevant records subject to confidentiality, notice, and continuing privacy obligations

Our providers may use approved subprocessors. Some recipients, such as Apple and Google for their app-store relationship, determine certain purposes independently and provide their own privacy notices.

Open Food Facts is a public data source, not the host of your Eatper account. When a missing exact barcode is queried, Open Food Facts receives the barcode and technical server request information, not your Eatper account identifier, email, diary, body, nutrition, or report data.

We may disclose information if required by law, a binding court or authority order, or where necessary and proportionate to protect users, the public, Perplatform Oy, or the Service. We will assess requests and disclose only what is legally required where permitted.

We do not:

  • sell personal data for money or other value;
  • share personal data for cross-context behavioural or targeted advertising;
  • use advertising networks in Eatper;
  • provide personal health, diary, weight, or nutrition data to employers, insurers, healthcare providers, or data brokers; or
  • publish your account identity with a custom-food contribution.

9. Open Food Facts data

Eatper's catalogue includes data from Open Food Facts. Food product data is © Open Food Facts contributors and is used under the Open Database License 1.0; individual database contents are available under the Database Contents License. Eatper does not import Open Food Facts product images.

Open Food Facts-derived catalogue data is kept logically separate and may be provided in a separately identified export where licence obligations require it. Public product data is not your personal data merely because you viewed or logged a product; your diary association with that product remains private account data.

10. International transfers

Eatper is operated from Finland. The primary Supabase project is configured in an EU region, and PostHog and Sentry are configured for their EU cloud regions. Some providers or their subprocessors may nevertheless process data outside Finland or the European Economic Area, including in the United States, for hosting, support, security, app-store, email, or notification functions. Resend states that its customer data, including message content and delivery logs, is stored in the United States.

When European personal data is transferred to a country that does not have an applicable European Commission adequacy decision, we use an appropriate transfer mechanism such as the European Commission's Standard Contractual Clauses, together with supplementary technical or organizational measures where required. A provider may instead rely on an applicable adequacy framework. You may contact us for more information about the relevant safeguards.

11. How long we keep data

We keep personal data only for the period needed for the purposes described below, then delete or irreversibly de-identify it unless law requires a longer period. Retention runs may be asynchronous, and isolated backups expire on their normal rotation rather than being edited record by record.

DataRetention
Account identity, basic profile, and non-health settingsWhile the account is active; queued for deletion when the account is deleted, subject to the limited exceptions below
Diary, recipes, meals, nutrition profile and targets, weight, body details, goals, and other synchronized health-related Service dataWhile the account is active and the relevant cloud-health consent remains valid; queued for deletion when the account is deleted or that consent is withdrawn, subject to the limited exceptions below
Personalized report snapshots and insightsWhile the account and separate report consent remain active; deleted after report-consent withdrawal or account deletion
Private, user-owned custom foodsUntil you delete or deactivate them where supported, or until account deletion; this deletes the private item but does not automatically remove a separate public catalogue entry previously created from accepted facts
Catalogue-submission and factual-correction recordsFor as long as the submitted or corrected facts and moderation history remain useful to catalogue integrity; the account or author link is removed on account deletion, while de-identified accepted product facts may remain public
Open food-data report and private evidence photographWhile needed to investigate the open report, no more than 180 days for the evidence photograph
Resolved, rejected, withdrawn, or otherwise terminal food-report evidenceNo more than 30 days after terminal status; de-identified factual corrections may remain in the catalogue
Account-export or report-export packageUp to 7 days after creation, then deleted
Account-export email tokenUp to 24 hours; signed download authorization is limited to approximately 5 minutes
Active push registrationWhile needed for an enabled device; inactive registrations are removed after up to 90 days
Push outbox and delivery historyUp to 30 days after terminal delivery state
Optional PostHog analytics eventsUp to 12 months; earlier deletion is queued when consent is withdrawn
Analytics activation-delivery recordsDelivered records up to 30 days; an undelivered activation record remains only until accepted or analytics consent is withdrawn
Sentry diagnostic events and sampled tracesUp to 90 days
Ordinary server and security logsUp to 30 days, unless an event must be isolated for investigation
Security-incident, fraud, abuse, or legal-claim recordsFor the investigation and up to 24 months afterward, or longer where a live claim or law requires it
Website language preferenceOn your device until you change it, clear browser storage, or the browser removes it
Turnstile verification tokenValid for no more than five minutes and single-use; Eatper uses it for validation and does not include it in the support message
Resend contact-message copy and delivery logsNormally up to 30 days under Eatper's current Resend service retention; the copy delivered to the support mailbox follows the correspondence period below
Website contact and support correspondenceWhile the matter is active and up to 12 months after resolution, unless a contract, dispute, or law requires longer
Subscription entitlement and transaction evidenceWhile needed to provide or restore access and for the accounting, tax, consumer, fraud-prevention, and claims periods required by law; accounting records are commonly retained for up to six years or the longer applicable statutory period
Terms acceptance, privacy-notice presentation, and consent recordsWhile the account is active; deleted with the account unless limited evidence is needed to meet a legal duty or resolve a live claim
Minimal deletion auditFor the period reasonably necessary to verify that the deletion workflow completed and protect the integrity of the system; designed not to identify the former user directly
Isolated backupsOverwritten or expired on a rolling schedule of no more than 90 days; backups are not used to restore deleted data into the live Service

The 12-month PostHog, 90-day Sentry, 30-day ordinary-log, 12-month resolved-enquiry, and 90-day backup limits are maximum retention periods that Perplatform Oy applies to the Service.

12. Account deletion, local copies, and subscription status

You can request account deletion in Eatper Settings. Once submitted, Eatper restricts account access and begins an asynchronous process that deletes or de-identifies account data across the relevant service stores. This includes cloud diary, nutrition, body, weight, target, report, private evidence, device-registration, and private user-owned custom-food data. If accepted product facts or factual corrections remain in the shared catalogue, Eatper removes the account or author link rather than deleting the separate de-identified catalogue entry solely because the account was deleted.

Deletion may retain only limited information described in Section 11, such as records required by tax or accounting law, evidence needed for a live security or legal matter, and a minimal non-identifying completion audit. Copies of deleted account data may remain temporarily in isolated backups for up to 90 days and expire automatically through normal backup rotation. They are unavailable through the Service and are not used to restore the deleted account.

Before deletion, you may request an account export. The temporary package, token, and signed link expire according to Section 11.

Deleting an account does not cancel an Apple App Store or Google Play subscription. You must cancel through the store to prevent future renewal. Uninstalling Eatper does not delete the cloud account; after deleting the account, also remove local copies from any device you control.

13. Security

We use technical and organizational safeguards designed for the sensitivity of the data, including:

  • encrypted network transport;
  • provider encryption at rest for cloud database and storage systems;
  • authentication, row-level access controls, least-privilege administrative roles, and environment separation;
  • restricted production access, currently limited to the authorized Perplatform Oy operator and service providers that need access for their functions;
  • encrypted storage of sensitive device-registration or provider tokens where implemented;
  • short-lived signed download links and expiring export packages;
  • removal of EXIF and device metadata from accepted food-evidence photographs;
  • minimized analytics and diagnostic payloads, EU analytics and diagnostics regions, and no session replay; and
  • monitoring, audit trails, deletion queues, backups, testing, and incident-response procedures.

No service can guarantee absolute security. Keep your device and sign-in methods secure, use a unique password where you create one, and contact support@eatper.com if you suspect unauthorized access. Do not send passwords, store receipts, or unnecessary health details by email.

14. Your privacy rights

Depending on where you live and the law that applies, you may have the right to:

  • receive information about processing and access a copy of your personal data;
  • correct inaccurate or incomplete data;
  • erase data in applicable circumstances;
  • restrict processing;
  • receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing that was lawful before withdrawal;
  • complain to a data-protection authority; and
  • avoid solely automated decisions that produce legal or similarly significant effects, where that right applies.

Many records can be viewed or corrected in the application. Account and report exports are available through Eatper's export features. To make another request, email support@eatper.com from the address connected to your account and describe the request.

We may request information reasonably necessary to confirm your identity and protect the account. We normally respond without undue delay and within one month where the GDPR applies; a lawful extension may apply for a complex or numerous request. Requests are normally free, although applicable law may allow a reasonable fee or refusal for a manifestly unfounded or excessive request.

Rights are not absolute. For example, we may retain transaction records required by law or information needed for a legal claim. If we cannot fulfill a request, we will explain the applicable reason and available complaint route.

Our lead supervisory authority is the Office of the Data Protection Ombudsman of Finland. You may report suspected unlawful processing or contact the Office of the Data Protection Ombudsman. If you live elsewhere in the EEA, you may also complain to your local supervisory authority.

15. Automated calculations and decisions

Eatper uses rule-based formulas to estimate calorie and macronutrient targets and automated processing to create trends, comparisons, and reports when enabled. It also uses the date of birth you provide to enforce the 18+ eligibility rule. These features do not diagnose you and are not used to make a solely automated decision that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

You can change manual targets where the feature allows, stop using a calculation, withdraw report consent, or contact support if you believe an input or result is wrong.

16. Children

Eatper is not intended for anyone under 18, and we do not knowingly offer accounts to children. The age check relies on the date of birth entered by the user; Eatper does not collect identity documents for age verification.

If you believe a person under 18 has created an account, contact support@eatper.com. We will investigate and restrict or delete the account as appropriate.

17. Cookies, software development kits, and similar technology

The mobile application uses software development kits needed for authentication, subscriptions, notifications, optional analytics, and essential diagnostics as described in this policy. Eatper does not use an advertising SDK or advertising identifier.

The public website does not use advertising or behavioural-analytics cookies. It stores the selected language in browser local storage. Pages containing the contact form load Cloudflare Turnstile, which may use strictly necessary cookies or similar technical methods and the security signals described in Section 4.11 to prevent automated abuse. Eatper does not use Turnstile for advertising, and Cloudflare states that Turnstile does not collect the contact-form fields or other page inputs.

Other strictly necessary cookies or similar technical storage may be used for security, load balancing, or basic website operation. If we add non-essential website analytics or advertising technology, we will provide any required consent control and update this policy before using it.

18. U.S. consumer health data notice

This Section supplements the rest of the policy for consumer health data laws that apply to wellness information outside traditional healthcare settings, including Washington's My Health My Data Act and Nevada's consumer health data law. It applies to Washington residents, people whose consumer health data is collected in Washington, Nevada consumers, and others entitled to similar rights under applicable law.

Categories of consumer health data and how we use them

Eatper may collect the following consumer health data, as those laws define it:

CategorySourcesPurposes and manner of processing
Body and physical characteristicsDirectly from youRecord height, weight, target weight, weight history, body-fat estimate, age-related input, and sex selection used in formulas; synchronize when consented; calculate requested targets and trends
Nutrition, food, and dietary informationDirectly from you, Eatper catalogue records you select, and calculations from your entriesMaintain diary and meal records, calculate nutrient totals, support recipes and targets, synchronize requested features, and provide reports when separately consented
Goals, activity, and wellness preferencesDirectly from youPersonalize targets, settings, progress views, and separately consented reports
Inferences and derived wellness informationGenerated from the information aboveProduce totals, adherence measures, trends, comparisons, and general wellness insights; never diagnose a condition
Health-related Service and notification metadataYour device and the ServiceSynchronize requested data, secure the account, generate or export reports, record that a report is ready, and deliver a generic notification if enabled

The categories of sources are you, your device and Eatper application, catalogue data you choose to associate with your diary, calculations performed by Eatper, and the processors that return operational status for a requested feature. Eatper does not collect consumer health data from data brokers, advertising networks, precise location providers, medical records, or connected health platforms.

Consumer health data disclosed or shared

Eatper discloses the categories above only to processors needed to provide a feature you request:

  • Supabase: account-linked nutrition, diary, body, weight, goal, report, export, and related operational data for authentication, EU-region database, and storage services;
  • Vercel: the request data needed to execute Eatper backend and report functions, plus associated technical metadata;
  • Firebase Cloud Messaging and Apple Push Notification service: a device token, generic report-ready message, opaque report reference, and delivery data when you enable remote notifications; and
  • professional advisers, security responders, or authorities: only the limited consumer health data necessary for a specific legal, security, or dispute matter.

Resend receives an email address and a temporary action link for transactional mail, not the health content of an export or report. PostHog is configured to exclude body, nutrition, diary, food, search, barcode, and report values. Sentry is configured to exclude Eatper domain values and account identity. Apple and Google receive purchase and store-entitlement data but not your Eatper diary, body measurements, or nutrition values.

We do not disclose consumer health data to an affiliate. We do not share it with a third party for that party's own advertising, profiling, data-broker, insurance, employment, healthcare, or other independent commercial purpose. We do not sell consumer health data. We do not use a geofence around a healthcare facility or collect precise location. No third party is permitted by Eatper to collect consumer health data over time across unrelated websites or online services when you use Eatper.

Consent and requests

Eatper obtains affirmative explicit consent before cloud processing of the core health-related categories and a separate consent before personalized report processing. Disclosures to processors are limited to what is necessary to provide the requested Service and are governed by processing contracts. If a future use or disclosure requires a separate consent under applicable law, Eatper will obtain it before the use or disclosure.

You may:

  • confirm whether Eatper collects, shares, or sells your consumer health data;
  • access the consumer health data and, where applicable, a list of recipients;
  • correct consumer health data;
  • withdraw consent and ask Eatper to stop future collection or sharing;
  • request deletion from Eatper and notification to processors or other recipients required to honor the request; and
  • appeal a refusal of a request.

Use the Settings controls for consent withdrawal, export, correction, or account deletion, or email support@eatper.com with Consumer Health Data Request in the subject. You do not have to create a new account to submit a request, although we may ask you to use an existing account or provide information reasonably necessary to authenticate it.

We will respond within the period required by applicable law. For a Washington request, this is generally within 45 days, with one additional 45-day extension where reasonably necessary and properly notified. Consumer health data in archived backups is deleted within the shorter 90-day rotation promised in Section 11. Requests are free at least as often as required by law.

To appeal, reply to the decision or email support@eatper.com with Privacy Appeal in the subject and explain why you believe the decision should be changed. We will respond in writing within the applicable appeal period. If a Washington appeal is denied, you may contact the Washington Attorney General. If a Nevada appeal is denied, you may contact the Nevada Attorney General.

19. Information for residents outside the EEA

Perplatform Oy applies the core safeguards in this policy to Eatper users worldwide. Local law may provide additional rights or different terminology.

Where a United States state privacy law applies to Perplatform Oy and your data, you may request access, correction, deletion, or a portable copy and may appeal a denied request by replying to our decision. We will not discriminate against you for exercising an applicable privacy right. We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use health-related data for purposes incompatible with providing the Service. We do not offer a financial incentive in exchange for personal data.

Because Eatper does not engage in sale or targeted-advertising sharing, it does not provide a “Do Not Sell or Share” link. You may still contact support@eatper.com with an applicable request. Authorized agents may act where local law permits, subject to verification of the request and authorization.

20. Changes to this policy

We may update this policy to reflect changes in the Service, providers, law, or data practices. We will make the current version available on the Eatper Privacy Policy page and in the application. Earlier numbered versions remain available at their versioned legal-document URLs.

For a material change, we will provide prominent in-app notice before the change takes effect where practicable. If a new purpose requires consent, we will ask for that consent rather than treating continued use as consent. A privacy-policy presentation record shows that a version was displayed; it is not treated as your acceptance of the policy.

21. Contact us

Privacy questions and requests may be sent to:

Perplatform Oy
Vilkastuksenkatu 7
20320 Turku
Finland
support@eatper.com