Consumer health data we may collect
Depending on the features you choose, MealFact may process information that identifies or could reasonably be used to infer health status, including:
- meals, recipes, calories, macronutrients, dietary preferences, corrections, and nutrition goals;
- declared age, height, weight, activity level, and progress information;
- meal, tableware, and optional progress photos;
- steps, active calories, and workout summaries imported from Apple Health or Health Connect, which remain local to your device;
- health-feature consent, export, deletion, and account records.
Sources
We receive this information from you, the choices and entries you make in MealFact, photos or labels you submit, supported device health stores when you authorize a manual import, and service providers that return the requested meal estimate or subscription status.
Why it is collected and used
- provide meal analysis, nutrition logging, corrections, goals, progress, and other features you request;
- synchronize an optional account and respond to support or privacy requests;
- secure the service, prevent abuse, and maintain reliability;
- comply with law;
- only after separate consent, process narrowly eligible future meal-photo contributions as described on the contribution page.
Who may receive it
We disclose only what is necessary to processors working under our instructions. This includes Supabase for optional account infrastructure and OpenAI for requested meal-photo analysis or nutrition-label transcription. Through MealFact’s protected backend, OpenAI receives a resized image, a pseudonymous safety identifier, and the minimum nutrition context needed to return the requested result. Open Food Facts receives barcode or food-catalog lookup requests. Apple, Google, and RevenueCat process purchase or entitlement information under their respective roles. When you separately join a private group, invited members receive only your chosen nickname, days logged, and streak—not meals, calories, photos, weight, or health imports.
OpenAI states that API data is not used to train or improve its models by default unless the API customer explicitly opts in. Under OpenAI’s standard API data controls, abuse-monitoring logs may contain certain customer content and derived metadata and are generally retained for up to 30 days, subject to longer retention when required by law or reasonably necessary to prevent harm. This ordinary processing is separate from the optional MealFact contribution program, which is closed in V1 and off by default.
Apple Health and Health Connect imports are not disclosed to MealFact’s servers. We do not disclose consumer health data to data brokers or advertising networks.
Your rights
Subject to applicable law, you may confirm whether we collect, share, or sell consumer health data; access it; withdraw consent; or request deletion. You may also appeal a denied request.
Use Settings → Privacy and consent in MealFact, visit Privacy choices, or email privacy@mealfact.com. For an appeal, include “Appeal” in the subject. We may take reasonable steps to verify the request. We normally respond to a Washington request or appeal within 45 days, with one lawful 45-day extension if needed. If an appeal is denied, you may contact the Washington State Attorney General.
Changes and contact
We will update this notice before materially changing the categories, purposes, or recipients described here and will request consent where required.
Controller: Marbel Trading LLC, 8206 Louisiana Blvd NE, Ste A #6781, Albuquerque, NM 87113, United States. Privacy contact: privacy@mealfact.com.