Legal
Privacy Policy
Effective: July 24, 2026 · Last updated: July 24, 2026
1. Who We Are
Supper (“Supper”, “we”, “us”, or “our”) operates the AI-powered nutrition and meal planning service available at heysupper.com. We are the data controller responsible for your personal data.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and your rights regarding it.
2. Data We Collect
A. Account Data
Email address and authentication credentials (managed by Clerk, our identity provider). We receive only your email address; passwords are hashed and never visible to us.
B. Health Profile
Collected during onboarding: age, biological sex, height, weight, fitness goal (e.g., weight loss, maintenance), activity level, dietary preferences, and food allergies or intolerances. This is the core health data used to generate your personalised meal plan. See Section 5 for how we handle this special category data.
C. Onboarding Conversation
If you use the onboarding chat flow, your messages are processed in real-time by our AI to extract your health profile. Conversation history is not stored server-side after your profile is saved; it exists only in your browser session during onboarding.
D. Activity & Progress Data
Meal check-ins (which meals were logged as eaten), daily check-in data (mood rating and optional freeform notes), meal feedback (liked/disliked meal ratings), weight logs, and meal swap requests. This data is used to generate your weekly progress recap.
E. Technical Data
IP address (used transiently for rate limiting and security), browser type, device type, and operating system. We do not store full IP addresses beyond the duration of a request.
F. Analytics & Error Data
Anonymised usage events collected via PostHog (e.g., pages visited, features used) and error reports collected via Sentry. PostHog is configured in identified-only mode — it does not track anonymous visitors. Sentry captures application errors and performance data to help us fix bugs. Neither PostHog nor Sentry receives your health profile data.
G. Security Record (post-deletion)
If you delete your account, your email address is retained in a restricted security table solely to enforce the 14-day re-registration cooldown. See Section 8 for details.
3. How We Use Your Data
Provide the Service
Generate personalised meal plans, process meal tracking, display your progress, and deliver weekly recap summaries.
Improve the Service
Analyse anonymised usage patterns to fix bugs, improve features, and understand how users engage with the app.
Security & Fraud Prevention
Detect and prevent abuse, enforce rate limits, and enforce the post-deletion re-registration cooldown.
Communications
Send a welcome email upon account creation and transactional emails related to your account (via Resend).
Legal Compliance
Comply with applicable laws, respond to lawful requests from authorities, and resolve disputes.
4. Lawful Basis for Processing (GDPR)
If you are in the EU, EEA, or UK, every processing activity has a lawful basis under the EU / UK General Data Protection Regulation:
| Processing activity | Lawful basis |
|---|---|
| Account creation and management | Art. 6(1)(b) — performance of contract |
| Health profile collection and plan generation | Art. 6(1)(b) + Art. 9(2)(a) explicit consent |
| Meal tracking and progress monitoring | Art. 6(1)(b) — performance of contract |
| Weekly recap summaries | Art. 6(1)(b) — performance of contract |
| Anonymised product analytics | Art. 6(1)(f) — legitimate interests (improving the Service) |
| Error tracking and debugging | Art. 6(1)(f) — legitimate interests (Service reliability) |
| Security operations and fraud prevention | Art. 6(1)(f) — legitimate interests (security) |
| Post-deletion security record | Art. 6(1)(f) — legitimate interests (abuse prevention) |
| Welcome and transactional email | Art. 6(1)(b) — performance of contract |
| Legal obligations compliance | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interests (Art. 6(1)(f)), we have balanced these against your rights and interests and concluded they do not override your fundamental interests. You may object to processing based on legitimate interests by contacting us.
5. Special Category Health Data
Your health profile (age, weight, fitness goals, dietary restrictions, allergies, etc.) constitutes special category data under GDPR Article 9 because it relates to your health. We apply a higher standard of protection to this data.
Explicit consent (Art. 9(2)(a)): Before creating your account, you are required to tick a dedicated checkbox explicitly agreeing to: “I have read and agree to the Privacy Policy, including the processing of my health data by AI.” This constitutes your explicit, informed consent to process your health data under GDPR Art. 9(2)(a) and equivalent laws in other jurisdictions. Your consent is freely given — you are not required to continue using the Service — and you may withdraw it at any time by deleting your account (noting that withdrawal of consent means we can no longer provide the Service to you).
What we do with health data:
- —Generate your initial 7-day meal plan via Anthropic's Claude AI model.
- —Fine-tune your calorie and macro targets over time based on your logged progress.
- —Generate weekly recap summaries using a limited data set (see Section 13 for exactly what is sent).
What we do NOT do with health data:
- —Sell your health data to any third party.
- —Use your health data for advertising or profiling.
- —Use your health data to train AI models (not permitted under Anthropic's API usage policy).
- —Share your health data with insurers, employers, or government bodies (except as required by law).
No automated decisions with legal or significant effects. We do not make any automated decisions about you that produce legal effects or similarly significant effects on you (GDPR Art. 22). Our AI generates meal suggestions and nutritional estimates as tools for your consideration, but all dietary decisions remain entirely and always yours.
6. Third-Party Services and Data Processors
We use the following third-party processors to deliver the Service. Each is bound by applicable data processing terms (a Data Processing Agreement or equivalent contractual commitments) and is required to process your data only for the stated purpose.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Clerk | Authentication & identity | Email, auth tokens | USA (SCCs) |
| Supabase | Database hosting | All account & health data | USA/EU (SCCs) |
| Anthropic PBC | AI processing | Health profile, meal data (see § 13) | USA (SCCs) |
| PostHog | Product analytics | Anonymised usage events | USA/EU (SCCs) |
| Sentry | Error tracking | Error logs, device info | USA (SCCs) |
| Vercel | Hosting & CDN | Request metadata | USA/global (SCCs) |
| Resend | Transactional email | Email address | USA (SCCs) |
SCCs = EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
7. International Data Transfers
We are based in India and use cloud service providers predominantly located in the United States. When personal data is transferred from the EU, EEA, or UK to countries without an adequacy decision, we use the following safeguards:
Standard Contractual Clauses (SCCs)
All our US-based processors have signed the European Commission's approved Standard Contractual Clauses (Decision 2021/914). These contractually bind processors to EU-equivalent data protection standards and are our primary transfer mechanism.
EU–US Data Privacy Framework (DPF)
Where our processors are certified under the EU–US Data Privacy Framework (DPF), this provides an additional adequacy-equivalent layer for US transfers, supplementing the SCCs we already have in place.
UK International Data Transfer Agreement (IDTA)
For UK users, international transfers are covered by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, as required by UK GDPR.
India: We comply with the Digital Personal Data Protection Act 2023 (DPDP Act) for cross-border transfers of Indian residents' data.
Brazil: Transfers are governed by LGPD Chapter V and rely on SCCs or other mechanisms approved by the ANPD.
To request details of the specific transfer mechanism applicable to your data, contact us at hello@heysupper.com.
8. Data Retention
| Data type | Retention period |
|---|---|
| Account data (email, profile) | Retained while your account is active. Deleted immediately upon account deletion. |
| Health profile | Retained while your account is active. Permanently deleted upon account deletion via cascade delete. |
| Meal plans, check-ins, weight logs | Retained while your account is active. Permanently deleted upon account deletion via cascade delete. |
| Onboarding conversation | Not stored server-side. Exists in browser session only during onboarding; not retained after profile extraction. |
| PostHog analytics events | Up to 12 months in anonymised form. Not linked to your account after deletion. |
| Sentry error reports | 90 days. May contain technical session identifiers but no health profile data. |
| Post-deletion security record (email only) | Retained in a restricted, access-controlled security table solely to enforce the 14-day re-registration cooldown. This record is not used for marketing, analytics, or any other purpose, and is not accessible from your account if you re-register after the cooldown period expires. |
How to delete your account: Go to Settings › Delete my account (at the bottom of the Settings page). This initiates an immediate, permanent cascade delete of all your personal data — health profile, meal plans, check-ins, weight logs, and all related records — from both our authentication provider and database.
9. Your Privacy Rights
Your rights depend on where you live. To exercise any right, email hello@heysupper.com. We will respond within the timeframe required by applicable law (generally within 30 days). We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive.
EU / EEA / UK — GDPR and UK GDPR
- —Right of access (Art. 15) — request a copy of your personal data.
- —Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- —Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data, subject to legitimate retention grounds.
- —Right to restriction of processing (Art. 18) — restrict how we process your data in certain circumstances.
- —Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- —Right to object (Art. 21) — object to processing based on our legitimate interests.
- —Right to withdraw consent (Art. 7(3)) — withdraw consent to health data processing at any time; this requires account deletion.
- —Right to lodge a complaint — with your national supervisory authority (find yours at edpb.europa.eu/about-edpb/board/members_en).
India — DPDP Act 2023
- —Right to access information about your personal data being processed (Sec. 11).
- —Right to correction and erasure of your personal data (Sec. 12).
- —Right to grievance redressal — file a complaint with our Grievance Officer (Section 17).
- —Right to nominate a person to exercise your rights in the event of death or incapacity (Sec. 14).
California, USA — CCPA / CPRA
- —Right to know what personal information we collect and why.
- —Right to delete your personal information.
- —Right to opt out of the sale or sharing of personal information. (We do not sell personal information.)
- —Right to non-discrimination for exercising your privacy rights.
- —Right to correct inaccurate personal information.
- —Your health profile constitutes Sensitive Personal Information under CPRA. We use it only to provide the Service and do not use it for cross-context behavioural advertising.
Brazil — LGPD
- —Rights of confirmation, access, correction, anonymisation, portability, deletion, and information about third parties with whom we share data.
- —Right to withdraw consent at any time.
- —Right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
- —Contact our Brazil DPO (Section 18) for LGPD-specific requests.
Canada — PIPEDA and Quebec Law 25 (Loi 25)
- —Right to access your personal information and request corrections (PIPEDA Principle 9).
- —Right to withdraw consent (subject to legal and contractual restrictions).
- —Right to complain to the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
- —Quebec residents have additional rights under Law 25 (in force since September 2023): right to data portability in a structured, technology-neutral format; right to be informed of any profiling or automated processing that affects you; right to request human review of any automated decision that produces a significant effect on you; right to de-indexation of personal information from a technology where applicable.
Australia — Privacy Act 1988
- —Right to access your personal information (APP 12).
- —Right to correct your personal information (APP 13).
- —Right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
- —Your health information is Sensitive Information under the Privacy Act and is subject to enhanced collection and use restrictions.
10. Children's Privacy
Supper is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you are the parent or guardian of a child who has provided us with personal data without consent, please contact us at hello@heysupper.com and we will delete that data promptly.
In jurisdictions with a higher digital age of consent (e.g., 16 in some EU member states), we require verifiable parental consent for users below that threshold. Where we become aware that a user is below the required minimum age without parental consent, we will delete that account.
12. Push Notifications
With your explicit permission, Supper may send push notifications for meal reminders and streak alerts. Push notification permission is requested in-app and is entirely optional — the full Service is available without it.
You can withdraw push notification permission at any time via your device or browser settings, or by toggling off notifications in Settings › App.
13. AI Processing — What Data Is Sent to Anthropic
Supper uses Anthropic's Claude AI models for several features. The following table specifies precisely what data is sent to Anthropic for each feature. Anthropic processes this data only to return a response and does not use API inputs to train its models, per Anthropic's published API usage policy.
Meal Plan Generation
Claude SonnetData sent: Your full health profile: age, biological sex, height, starting weight, current weight, goal weight, activity level, goal type (e.g., weight loss), dietary preferences, and food allergies/intolerances.
Triggered: When you generate or regenerate your meal plan.
Onboarding Chat
Claude SonnetData sent: Your chat messages during the onboarding flow only, used to extract your health profile. Once your profile is saved, this chat route returns a 403 and cannot be used again.
Triggered: During initial onboarding only.
Meal Swap
Claude HaikuData sent: The current meal name, your dietary preferences, and your food allergies/intolerances. No weight data or other health profile fields.
Triggered: When you request to swap a specific meal.
Calorie & Macro Estimate
Claude HaikuData sent: The food description text you type. No health profile or any other personal data is included.
Triggered: When you use the macro estimator feature.
Weekly Recap Insight
Claude HaikuData sent: Meal adherence percentage (meals logged out of total slots), liked meal names, disliked meal names, and weight change in kg over the past two weeks. No check-in mood or notes, no full health profile.
Triggered: When your weekly recap summary is generated.
14. Security
We implement technical and organisational security measures appropriate to the risk of processing health-related personal data, including:
- —Encryption in transit (TLS 1.2+) for all data between your device and our servers.
- —Row-Level Security (RLS) policies in our database, ensuring each user can only access their own data.
- —API rate limiting and account-block checks on all routes that access user data.
- —Content Security Policy (CSP) headers with nonce-based script whitelisting to mitigate injection attacks.
- —Access controls and API key rotation for all third-party service integrations.
- —Restricted access to production data limited to authorised personnel.
Data breach notification. In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law (GDPR Art. 33 and equivalents). Where the breach poses a high risk to your rights and freedoms, we will also notify you without undue delay (GDPR Art. 34).
No transmission over the internet or electronic storage method is 100% secure. If you discover a potential security vulnerability, please disclose it responsibly to hello@heysupper.com.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by displaying a prominent notice within the app at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
The current version is always available at heysupper.com/privacy.
16. EU & UK Representatives
Required before launching in EU or UK
Under Article 27 GDPR (EU) and Article 27 UK GDPR, organisations outside those territories that process EU/EEA/UK residents' personal data must appoint a designated representative within those territories. The placeholders below must be replaced with the details of an appointed representative before Supper is made available to EU or UK users. Representative services (e.g., DataRep, EDPO, VeraSafe) provide this for approximately €300–€700 per year.
EU / EEA Representative (Art. 27 GDPR)
EU and EEA residents may contact the EU Representative directly with any GDPR enquiry or complaint in addition to contacting Supper directly.
UK Representative (Art. 27 UK GDPR)
UK residents may contact the UK Representative directly with any UK GDPR enquiry or complaint in addition to contacting Supper directly.
17. Grievance Officer (India)
In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act 2023, we have designated a Grievance Officer for India:
Grievances will be acknowledged within 24 hours and resolved within 30 days of receipt, as required by the IT (Intermediary Guidelines) Rules 2021.
18. Brazil — Data Protection Officer (LGPD)
In compliance with the Lei Geral de Proteção de Dados Pessoais (LGPD), Art. 41, we have designated an Encarregado de Dados (Data Protection Officer) for Brazil:
Brazilian users may contact the Encarregado de Dados directly with any LGPD-specific request or complaint. You also have the right to lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd.
19. Contact Us
For general privacy questions, data subject access requests, complaints, or to exercise any of your rights, contact us at: