1. Who is responsible
MealFact is operated by Marbel Trading LLC, 8206 Louisiana Blvd NE, Ste A #6781, Albuquerque, NM 87113, United States.
Privacy questions and rights requests: privacy@mealfact.com.
2. Information MealFact may process
- Profile and goals: declared age, height, weight, activity level, language, units, and nutrition goals.
- Meals and nutrition: foods, quantities, calories, macronutrients, recipes, timestamps, questions, and confirmed corrections.
- Photos and scans: meal, tableware, nutrition-label, and optional progress photos; barcode numbers and scanner results rather than a barcode photo.
- Account and server session: an optional permanent account may include email, sign-in provider, and synchronized content. Cloud features may also use a pseudonymous server session without an email or social sign-in.
- Purchases: subscription product, status, dates, and pseudonymous transaction identifiers from Apple, Google, and RevenueCat. MealFact never receives your card number.
- Activity and device health data: only the limited categories you choose to import, as described below.
- Technical data: app version, request timing, reliability, security events, and limited usage events if optional analytics is enabled.
MealFact does not request precise location. Unneeded photo metadata is removed before remote processing where technically available.
3. Where information is handled
- Local by default: manual exercise, hydration, reminders, progress photos, and Apple Health or Health Connect imports stay on the device in the current version.
- MealFact servers: cloud analysis requests, optional account synchronization, consent records, subscription entitlement, security controls, and support operations.
- Image analysis by OpenAI: when you request analysis of a meal photo or transcription of a nutrition label, MealFact sends through its protected backend a resized image, a pseudonymous safety identifier, and the minimum nutrition context needed to return the requested result.
- Barcode lookup: barcode number, language and country parameters, and ordinary network request data sent to Open Food Facts; returned records may be cached locally for about seven days.
- Correspondence: support and privacy emails are routed through Cloudflare and received through Google’s email service.
4. Why we process information
We use information to provide the feature you request, keep your journal, synchronize an optional account, manage subscriptions, prevent abuse, answer support requests, meet legal obligations, and improve reliability.
For people in the EEA, UK, or Switzerland, the legal basis is normally performance of the requested service, explicit consent where health or optional contribution data requires it, legitimate interests in security and service reliability, or compliance with law. Consent can be withdrawn at any time without affecting earlier lawful processing.
5. Meal photos and estimates
MealFact uses OpenAI as a service provider to analyze meal photos and transcribe nutrition labels. The service may propose foods, portions, calories, macronutrients, confidence, label text, and possible follow-up questions. You can correct or reject the result.
OpenAI states that data submitted through its API is not used to train or improve OpenAI models by default unless the API customer explicitly opts in to share data for that purpose. Under OpenAI’s standard API data controls, abuse-monitoring logs may contain certain customer content and derived metadata and are generally retained for up to 30 days, subject to longer retention when required by law or reasonably necessary to protect services or third parties from harm.
This processing provides the analysis you requested. It does not enroll you in or authorize the separate optional MealFact contribution program, which is closed in V1 and remains off by default.
6. Optional contribution to improve MealFact
This program is separate from normal meal analysis, off by default, and available only after a clear opt-in by an eligible adult with a permanent account. Refusing does not block or reduce normal analysis.
When the program is available, the permission can cover only future color meal photos and structured corrections that you confirm. It never covers:
- Apple Health or Health Connect data, weight, activity, medications, or symptoms;
- audio, free-text notes, progress photos, before-and-after images, labels, or barcodes;
- faces, people, biometric information, depth maps, or raw depth measurements.
Contributions first enter a restricted review area and are checked for consent, content, metadata, provenance, and quality. Withdrawing stops new collection and future exports and starts deletion of copies that remain separately identifiable. Improvements already incorporated into the service may not be technically reversible; a limited exclusion record may be retained to prevent reuse.
7. Apple Health and Health Connect
These connections are optional and require both your MealFact choice and the system permission. MealFact reads only the selected steps, active calories, and workouts during a manual foreground sync. No GPS routes are read.
Imported health data stays in the local app database, is never sent to MealFact’s servers, is never used for advertising or to improve future estimates, and is deleted when you disconnect, withdraw permission, or delete local data. Active calories never increase a food-calorie target.
8. Service providers and international transfers
MealFact uses specialized providers only for the work they perform, including:
- Supabase for optional accounts, database, storage, and protected server functions;
- OpenAI for the minimum content needed to analyze a meal photo or transcribe a nutrition label;
- RevenueCat for subscription entitlement status;
- Apple and Google for distribution, sign-in where selected, purchases, and device services;
- Open Food Facts for barcode and food-catalog lookups;
- Cloudflare for this website, domain security, and email routing.
- Google’s email service for receiving support and privacy correspondence.
Processing may occur in the United States and other countries. Where law requires it, we use recognized transfer safeguards and contractual protections. We do not sell personal information, share it for cross-context behavioral advertising, or use health data for advertising.
9. Retention
- MealFact-controlled transient copies used for ordinary meal or nutrition-label analysis: targeted for deletion within 15 minutes. This does not describe OpenAI’s separate handling.
- OpenAI standard API abuse-monitoring logs: generally up to 30 days, subject to the exceptions described above.
- Local journal and optional synchronized profile: until you delete the entry, profile, or account.
- Local analysis-result cache: up to 30 days.
- Network and security logs: normally no more than 7 days.
- Minimized analysis diagnostics: successful records up to 365 days and failed records up to 30 days.
- Optional product analytics: up to 180 days and deleted when the related consent is withdrawn.
- Apple Health and Health Connect imports: a rolling 30-day local window.
- Backups: deletion is targeted to propagate within 30 days.
- Optional contribution program, when opened: original review copy up to 72 hours, pending material up to 30 days, and accepted cropped photo plus confirmed correction up to 24 months.
- Purchase and legal records: only as long as required by tax, accounting, fraud-prevention, or other law.
10. Your controls and rights
In MealFact, open Settings → Privacy and consent to export data, delete data, withdraw health consent, disable optional analytics, or manage the optional contribution program.
Depending on where you live, you may request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or an appeal of a denied request. California and certain US state residents may also request categories, sources, purposes, and recipients and may limit certain uses of sensitive information. MealFact does not sell or share personal information as those terms are used for behavioral advertising.
You may also contact us through Privacy choices or request account deletion on the account deletion page. We may verify identity before fulfilling a request.
11. Security, age, and changes
We use encryption in transit, access controls, server-side secrets, row-level database policies, minimized logs, purchase verification, and deletion controls. No system can be guaranteed completely secure.
MealFact is intended only for adults aged 18 or older. The service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from people under 18; if we learn that we have done so, we will take reasonable steps to delete it.
MealFact produces estimates that you can review and correct. It does not make a legal, medical, employment, credit, or similarly significant decision about you.
We may update this policy when the service, providers, or law changes. Material changes will be communicated in the app or through another appropriate channel, and renewed consent will be requested where required.