Effective 30 July 2026
Privacy Policy
JustAte is a nutrition app for adults aged 18 and over. This policy explains the information used to run the app, the separate choice required before sharing with OpenAI, and the controls available to you.
1. Overview
This policy explains how JustAte handles personal information. JustAte is not a medical service and does not provide diagnosis or treatment. Nutrition estimates are informational and should be checked by you before use.
The diary can be used without Cloud AI. We do not send data to OpenAI unless you make a separate in-app choice to allow that sharing for an AI feature. Buying Pro, accepting the Terms, or completing onboarding is not that permission.
Before JustAte configures Supabase or RevenueCat, the first-launch screen asks you to choose Allow Supabase & RevenueCat or Continue local-only. Continue local-only keeps your profile, goals, and diary on this device. This service choice does not give permission to share with OpenAI. If a local-only user later chooses sign-in, purchase, restore, or Cloud AI, JustAte reopens the same service-data screen before any provider request.
Change this service choice at Settings → Privacy & AI → Supabase & RevenueCat. Choosing Continue local-only immediately blocks new JustAte Supabase requests and app-initiated RevenueCat checks. If RevenueCat was configured earlier in the app session, fully close and reopen JustAte to stop the already-configured native RevenueCat SDK. Data already held by either provider is not deleted. Your subscription remains managed through Apple, and account deletion is a separate Settings control. The separate OpenAI choice is unchanged.
2. Information we collect
Depending on how you use JustAte, we may collect:
- Account identifiers such as your anonymous or signed-in Supabase user id; the email address and password you enter for email authentication; session access and refresh tokens; and, when you choose Sign in with Apple, the Apple-linked account identifier, identity token, authorization code, and any name or email Apple returns. Supabase stores the linked identity and encrypted Apple revocation credential for account access, revocation, and deletion. JustAte does not store your password in its profile database.
- Profile details you enter, such as your optional first name, exact date of birth, profile sex, height, weight, goal, activity level, dietary preferences, country, and measurement units.
- Food logging content, including typed meal descriptions, editable voice transcripts, selected photos, recognised text, corrections, favourites, saved foods, portions, nutrition estimates, and confidence scores.
- Coach and recommendation content, such as prompts, replies, insights, and Fix My Day suggestions.
- Selected Apple Health data you authorise, including weight, height, steps, active energy, exercise, sleep, resting heart rate, and heart-rate variability. JustAte can write app-entered weight, meal nutrition, and hydration data to Apple Health when enabled.
- Precise location when you choose nearby restaurant or cafe search. Location is requested in the foreground for that search and is not stored as raw coordinates in Restaurant Memory.
- Subscription and entitlement information from RevenueCat and the Apple App Store, such as product id, entitlement status, renewal state, and transaction-linked identifiers. The RevenueCat SDK automatically receives the pseudonymous Supabase account user ID, device type and operating system, locale and currency, last-seen time, and Apple receipt and purchase status. We do not receive card or bank details.
- Support or privacy email you choose to send, including sender and recipient addresses, subject, message body, attachments, message headers, and ordinary routing and delivery metadata.
- When you visit justatemate.com, Vercel automatically receives ordinary website request data such as your IP address, city or country inferred from IP, browser, device and system configuration, requested page, referrer, timestamp, response, performance or error information, and request metadata.
- Device region and timezone, venue or cuisine searches, barcode lookup queries, and linked feature-use records such as the Cloud AI or nearby-search operation, status, and timestamps.
- Supabase operational, Auth audit, and Edge invocation logs may link your user ID, IP address or coarse country, user agent, route, status, duration, and request or response data.
How we collect information
- Directly from you when you enter profile details, meal content, preferences, or support messages.
- Through device permissions you choose, including camera, microphone and Speech Recognition, Apple Health, and foreground location.
- Automatically through Supabase service records and the RevenueCat SDK when you allow service-data sharing, and from Apple when it supplies subscription or Sign in with Apple information.
- Automatically when Vercel serves a website request, and when Cloudflare Email Routing forwards and Gmail stores an email you choose to send.
- Derived in the app from information you provide or authorise, including nutrition targets, daily balance summaries based on meal logging and hydration, estimates, and progress summaries.
3. How we use information
We use information to:
- Log meals, calculate nutrition targets, show progress, and sync your diary across sessions.
- Verify adult eligibility and use age derived from your date of birth together with profile sex to calculate personalised nutrition targets.
- Run a Cloud AI feature only after the separate OpenAI permission described below.
- Remember your usual foods and corrections so future estimates become faster and more useful.
- Manage free-tier metering, subscription access, restores, and entitlement checks, including feature limits.
- Use authorised Apple Health data to provide the import you turn on. JustAte does not calculate a recovery or readiness score from Apple Health data.
- Use device region and timezone to localise units, dates, reminders, and day boundaries.
- Process venue searches and barcode lookups to return the results you request.
- Use RevenueCat entitlement and transaction records for receipt validation, fraud prevention, and subscription analytics.
- Send local app notifications you enable, such as reminders and milestone updates.
- Maintain security, debug errors, prevent abuse, and improve product reliability.
- Respond to support, privacy, access, correction, or deletion requests.
- Deliver, secure, monitor, and troubleshoot the public website; route, store, and respond to support or privacy correspondence; detect phishing, spam, abuse, and delivery failures; and meet legal obligations.
We do not sell personal information. We do not use food logs to shame users, and we do not use tracking data for third-party advertising.
4. Service providers
JustAte uses these providers to operate the current iOS app, public website, and support channels:
- Supabase for anonymous and email authentication, database, Storage, sync, row-level access controls, and authenticated Edge functions, including the Supabase-hosted gateway used for Cloud AI and Places requests. Supabase operational, Auth audit, and Edge invocation logs may link your user ID, IP address or coarse country, user agent, route, status, duration, and request or response data. JustAte uses these logs for request delivery, security, abuse prevention, debugging, and service analytics. At this policy's 30 July 2026 update, JustAte's Supabase project is on the Free plan: Supabase retains API and database logs for one day, and no log drain is configured.
- Vercel hosts and serves justatemate.com and receives the website request data listed in section 2 to deliver, maintain, secure, monitor, and troubleshoot the site. The current static site has no JustAte analytics, advertising scripts, cookies, or web forms. Vercel retains information for the minimum period needed for contractual or legal obligations and legitimate service purposes, then deletes or anonymises it; where deletion from backups is not immediately possible, Vercel stores the data securely until it is deleted.
- Cloudflare Email Routing receives mail sent to support@justatemate.com and privacy@justatemate.com and forwards it to JustAte's verified Gmail mailbox. The message headers and body transit Cloudflare in real time; Cloudflare says Email Routing does not store or access email content. Cloudflare may process the SMTP envelope, routing and network metadata, phishing signals, and delivery metrics to route and protect delivery. Google Gmail then receives and stores the message, headers, and attachments so JustAte can respond. Google also processes Gmail data for delivery, spam and security controls, assistive mailbox features, and reliability, and says it does not use Gmail content for personalised advertising.
- OpenAI for feature-dependent Cloud AI processing only after the separate permission described in section 5.
- Apple Speech Recognition may process spoken audio on Apple's servers after you grant microphone and Speech Recognition permission. JustAte receives the editable transcript and does not retain the raw recording. Apple may retain transcripts and related request data under a rotating device-generated identifier for up to two years and use them to develop and improve Siri, Dictation, Search, and limited other language processing features. Only the transcript—not raw audio—is sent to OpenAI, and only after separate Cloud AI permission.
- Google Places for temporary nearby restaurant and cafe results when you request location search. Google receives the precise coordinates needed for that search, but not your Supabase account identifier. Google and its affiliates may use and retain the coordinates and associated request data to provide and improve Google products and services. Read the Google Privacy Policy.
- Open Food Facts for editable community barcode matches. A direct lookup sends the scanned product barcode and ordinary request metadata, including your IP address and the JustAte User-Agent. Open Food Facts may infer country from the IP address when a country parameter is not supplied. Open Food Facts request logs use the IP address for debugging, security-breach detection, usage statistics, service management, and preventing automated abuse. Open Food Facts' public policy does not clearly state whether direct third-party app lookups use its three-year visit-log period or its indefinite mobile-scan IP period. Until Open Food Facts confirms the classification, the IP address and request log should be treated as potentially retained indefinitely. Open Food Facts does not receive your JustAte account ID, profile, other meal text or diary entries, photos, or the foreground precise coordinates used for nearby search. Its product data may be incomplete or inaccurate.
- RevenueCat and the Apple App Store for subscription entitlement, purchase, renewal, and transaction-linked status. The RevenueCat SDK automatically receives the pseudonymous Supabase account user ID, device type and operating system, locale and currency, last-seen time, and Apple receipt and purchase status. RevenueCat uses them for entitlement, receipt validation, fraud prevention, App Functionality, and dashboard analytics; JustAte does not receive card or bank details. RevenueCat says personal data is kept while the customer account exists and for six years after. Customer-directed deletion is completed within a reasonable timeframe subject to legal obligations, disputes, or agreements. JustAte account deletion requests provider customer deletion.
- Apple handles App Store purchases. Sign in with Apple is available on supported iOS devices for optional account authentication. New or re-authorized Apple sign-ins register a server-side credential used to revoke Apple access during in-app deletion. An older Apple-linked account without a stored revocation credential may still require manual Apple Account action under Apple's terms and privacy policy.
JustAte shares personal information only when a provider's applicable contractual, privacy, security, and data-processing commitments provide the same or equal protection of user data as stated in this policy and required by Apple's App Review Guidelines. We review those commitments and will stop the affected sharing if they no longer meet that standard. The links below are provider-specific references to the commitments we rely on.
Provider-specific references:
- Supabase's Terms of Service define the service-purpose licence for Customer Data, address aggregated data separately, and impose confidentiality duties. The Supabase Data Processing Addendum requires processing on JustAte's documented instructions, confidentiality, appropriate organisational and technical security measures, data-protection terms no less protective than the DPA for each Sub-processor, and return or deletion of Covered Data after the service ends, subject to its lawful-retention terms. Its SOC 2 security statement describes independently audited controls for security, availability, processing integrity, confidentiality, and privacy. Supabase also documents platform logs, Auth audit logs, and Edge invocation logging, including plan-dependent retention and the request metadata those surfaces can contain.
- Vercel's Privacy Notice identifies the website traffic data it receives for customer sites and the service and security purposes for which it is used. Vercel's Terms require reasonable information-security safeguards, and its Security and Compliance documentation describes encryption, access controls, and independent assurance. JustAte's hosting team uses Vercel Pro. Vercel's Data Processing Addendum applies to Pro and Enterprise customers. It requires processing only on JustAte's documented, lawful instructions, confidentiality, technical and organisational security measures, and substantially similar data-protection obligations for each Subprocessor. Customers may delete or export Customer Data while using the service; termination instructs Vercel to delete it within a commercially reasonable timeframe, subject to lawful retention.
- Cloudflare's Email Routing description states that routed email content is forwarded in real time and is not stored or accessed by Cloudflare. Its published Data Processing Addendum, where applicable, requires purpose-limited processing, confidentiality and security, no-less-protective subprocessors, and return or deletion. Cloudflare's Privacy Policy covers routing and service-generated metadata. Google provides the destination consumer Gmail account under the Google Privacy Policy, not under a JustAte Workspace processor agreement. Google's Gmail privacy and security information describes encryption, restricted access, spam and security processing, and the rule against personalised ads based on Gmail content. Google's retention policy describes deletion timing and account-holder controls.
- OpenAI's Services Agreement states that OpenAI will only use Customer Content as necessary to provide the services, comply with law, enforce its policies, and prevent abuse, and will not use it to develop or improve the services unless JustAte explicitly agrees. Its incorporated Data Processing Addendum requires processing on documented instructions, confidentiality, reasonable and appropriate organisational and technical security measures, comparable obligations for each Sub-Processor, and return or delete Customer Data after the agreement ends, subject to its stated legal-retention exception. JustAte relies on these safeguards as the same or equal protection for personal data sent to OpenAI and will stop the affected sharing if they no longer meet that standard.
- RevenueCat's Terms of Use protect Customer Data through confidentiality, reasonable safeguards, service-purpose use, customer ownership, return or destruction, and aggregate or de-identified-only secondary use. The Terms incorporate RevenueCat's Data Processing Addendum where applicable. RevenueCat's Privacy Policy says End User Information is used only to provide services under the customer agreement, and its Security & Compliance statement describes SOC 2 Type II controls and encryption.
- The Google Maps Platform Terms identify the location, search, and request data Google receives and state that Google may use and retain it to provide and improve Google products under the Google Privacy Policy. They incorporate the Google Controller-Controller Data Protection Terms, under which each party is an independent controller and must comply with applicable national privacy law. Google documents encryption at rest and in transit. JustAte sends coordinates only after explicit, revocable nearby-search permission and does not send the Supabase account identifier to Google Places.
- Apple describes Speech Recognition data use and retention in its Siri, Dictation & Privacy notice. Apple describes App Store transaction handling and Apple-linked account privacy under its platform terms and Apple Privacy Policy.
- Open Food Facts' Privacy Policy and Terms describe request-log processing, security practices, and user rights. Its Privacy Policy and Terms of Use apply to the lookup service and data reuse. Its API documentation permits read-only product lookups without authentication, requires an identifying User-Agent, and asks API reusers to submit a usage form; JustAte has submitted that form. Because its published retention categories do not clearly classify direct requests from a third-party mobile app, and its public policy does not clearly state whether direct third-party app lookups use the three-year visit-log period or indefinite mobile-scan IP period, JustAte conservatively treats the IP address and request log as potentially retained indefinitely.
These providers may process information in Australia, the United States, France, or other regions where they operate, subject to their provider-specific terms and applicable law.
5. Optional Cloud AI and OpenAI
Before the first action that may use Cloud AI, JustAte explains the recipient and asks for separate permission. If you choose Allow, JustAte sends only the information needed for that feature to OpenAI through our authenticated Supabase-hosted gateway. Depending on the feature, this may include:
- meal or menu text, editable voice transcripts, selected meal or menu photos, Coach messages, and venue or cuisine searches or restaurant or cafe names you enter;
- nutrition goals, including hydration target, daily or weekly nutrition totals, current water total, logging patterns and goal-hit rates, and names of recent, usual, or matching foods; and
- when relevant, the Cloud AI feature or input mode you use, local time (HH:mm only), your first name, dietary preferences, dislikes, and non-Health daily exercise totals. Saved allergy information is not sent to OpenAI, and Cloud AI does not verify allergen safety.
JustAte does not include your email, exact date of birth, profile sex, Supabase user id, purchase data, raw Apple Health data, or precise location in the OpenAI request contracts. Raw data read from Apple Health/HealthKit is not sent to OpenAI; app-entered nutrition goals and totals may be sent only after separate Cloud AI permission, as described above. Location is not sent to OpenAI, and voice logging sends only the editable transcript—not raw audio—to OpenAI.
OpenAI states that API data is not used to train its models by default. Under its standard API data controls, abuse-monitoring logs may retain prompts and outputs for up to 30 days unless a different eligible account control applies. We have not represented that this account has a stricter account-specific retention setting.
The OpenAI safeguards described in section 4 provide the same or equal protection for personal data sent through Cloud AI. JustAte's separate in-app permission and withdrawal controls apply independently.
Turn sharing off at any time in Settings → Privacy & AI. Once JustAte confirms the choice was saved, future Cloud AI requests remain blocked across relaunch. If saving fails, Cloud AI stays off for the current app session and JustAte asks you to retry before closing the app. Manual text entry, barcode lookup, editing, and local or offline food logging remain available. You can manage existing JustAte records through in-app editing, a meal-history CSV, account deletion, or a privacy request.
6. Apple Health, location, and third-party content
Apple Health is optional and has a separate native permission. If enabled, Health-derived weight and height, steps, active energy, exercise minutes, sleep, resting heart rate, heart-rate variability, and daily Health snapshots may sync to your Supabase account. JustAte does not calculate a recovery or readiness score from Apple Health data. App-entered meal nutrition, weight, and hydration can be written separately to Apple Health. Turn Health off in JustAte to stop future JustAte Health reads and writes, and manage the native permission separately in Apple Health or device Settings.
Nearby search is optional. After you request it and allow foreground location, the foreground precise location is linked to your JustAte account for App Functionality. Your Supabase user ID and session token, coordinates, restaurant or cafe mode, search radius, result limit, and request metadata are sent to the authenticated Supabase Places function. Supabase relays the coordinates, mode, radius, and result limit to Google Places for nearby results. Raw coordinates are not kept in Restaurant Memory and are not sent to OpenAI. You can use manual restaurant entry without location. Google and its affiliates may use and retain the coordinates and associated request data to provide and improve Google products and services, subject to the Google Privacy Policy.
Google Places content is temporary except for permitted Place IDs and is subject to the Google Maps Platform Terms. Open Food Facts barcode data is community-provided and editable. Its database uses the Open Database License, individual contents use the Database Contents License, and identified product images use CC BY-SA 3.0.
7. Retention and deletion
We keep JustAte account information while the account is active or as needed to provide the service, maintain security, resolve disputes, or meet legal duties. Use Settings → Delete account & data to delete the account and app data JustAte can directly erase. Provider operational or security logs may remain under provider, legal, security, fraud-prevention, or plan retention. Apple and RevenueCat may also retain billing records under their own legal, accounting, security, or fraud-prevention duties. Deleting JustAte does not cancel an App Store subscription.
Abandoned local meal-photo captures become cleanup-eligible after seven days. A committed photo remains on-device with the meal. Deleting a meal deletes its photo, and replacing or removing a photo removes the old local file.
JustAte keeps support and privacy correspondence while handling the request and afterward only as needed for follow-up, security, disputes, or legal duties. Gmail retains a message until JustAte deletes it. Google says deletion generally takes about two months, while encrypted backups may retain copies for up to six months, subject to security and legal exceptions. Cloudflare says it does not store routed email content; routing and security metadata follows its purpose-based retention policy. Vercel follows the minimum-necessary retention described in section 4.
8. Your choices and rights
You can:
- Correct meal details, profile settings, and preferences in the app. Use Settings → Export meal history to create a CSV copy of meal-entry history. For access to other personal data, email privacy@justatemate.com.
- Turn off future OpenAI sharing in Settings → Privacy & AI.
- Manage or cancel subscriptions through your Apple App Store account settings.
- Request access or correction help from privacy support. Account deletion remains directly available in Settings.
If Australian privacy law applies to your information, the Australian Privacy Principles may give you rights to access and correct personal information and to complain about how it is handled.
Visit Privacy Choices for request options and subscription, notification, analytics, and deletion guidance.
9. Security
We use technical and organisational safeguards designed to protect personal information, including authenticated access, encrypted transport, database security rules, and limited access to production systems. No online service can guarantee absolute security.
10. Adult eligibility
JustAte is currently designed for adults aged 18 and over. We use the exact date of birth entered during setup to enforce that access rule and derive age for nutrition-target calculations.
11. Changes
We may update this policy as the product, providers, or legal requirements change. The latest version will be posted on this page with its effective date.
12. Contact
For privacy requests or complaints, use Privacy Choices. For product help, visit Support.