Skip to main content
Back to Supper

Legal

Privacy Policy

Effective: July 24, 2026 · Last updated: July 24, 2026

1. Who We Are

Supper (“Supper”, “we”, “us”, or “our”) operates the AI-powered nutrition and meal planning service available at heysupper.com. We are the data controller responsible for your personal data.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and your rights regarding it.

For EU / EEA / UK users→ Section 16
If you are located in the EU, EEA, or UK, our EU Representative and UK Representative (appointed under Art. 27 GDPR and UK GDPR) are the designated points of contact in those regions. See Section 16 for their details.

2. Data We Collect

A. Account Data

Email address and authentication credentials (managed by Clerk, our identity provider). We receive only your email address; passwords are hashed and never visible to us.

B. Health Profile

Collected during onboarding: age, biological sex, height, weight, fitness goal (e.g., weight loss, maintenance), activity level, dietary preferences, and food allergies or intolerances. This is the core health data used to generate your personalised meal plan. See Section 5 for how we handle this special category data.

C. Onboarding Conversation

If you use the onboarding chat flow, your messages are processed in real-time by our AI to extract your health profile. Conversation history is not stored server-side after your profile is saved; it exists only in your browser session during onboarding.

D. Activity & Progress Data

Meal check-ins (which meals were logged as eaten), daily check-in data (mood rating and optional freeform notes), meal feedback (liked/disliked meal ratings), weight logs, and meal swap requests. This data is used to generate your weekly progress recap.

E. Technical Data

IP address (used transiently for rate limiting and security), browser type, device type, and operating system. We do not store full IP addresses beyond the duration of a request.

F. Analytics & Error Data

Anonymised usage events collected via PostHog (e.g., pages visited, features used) and error reports collected via Sentry. PostHog is configured in identified-only mode — it does not track anonymous visitors. Sentry captures application errors and performance data to help us fix bugs. Neither PostHog nor Sentry receives your health profile data.

G. Security Record (post-deletion)

If you delete your account, your email address is retained in a restricted security table solely to enforce the 14-day re-registration cooldown. See Section 8 for details.

3. How We Use Your Data

Provide the Service

Generate personalised meal plans, process meal tracking, display your progress, and deliver weekly recap summaries.

Improve the Service

Analyse anonymised usage patterns to fix bugs, improve features, and understand how users engage with the app.

Security & Fraud Prevention

Detect and prevent abuse, enforce rate limits, and enforce the post-deletion re-registration cooldown.

Communications

Send a welcome email upon account creation and transactional emails related to your account (via Resend).

Legal Compliance

Comply with applicable laws, respond to lawful requests from authorities, and resolve disputes.

4. Lawful Basis for Processing (GDPR)

If you are in the EU, EEA, or UK, every processing activity has a lawful basis under the EU / UK General Data Protection Regulation:

Processing activityLawful basis
Account creation and managementArt. 6(1)(b) — performance of contract
Health profile collection and plan generationArt. 6(1)(b) + Art. 9(2)(a) explicit consent
Meal tracking and progress monitoringArt. 6(1)(b) — performance of contract
Weekly recap summariesArt. 6(1)(b) — performance of contract
Anonymised product analyticsArt. 6(1)(f) — legitimate interests (improving the Service)
Error tracking and debuggingArt. 6(1)(f) — legitimate interests (Service reliability)
Security operations and fraud preventionArt. 6(1)(f) — legitimate interests (security)
Post-deletion security recordArt. 6(1)(f) — legitimate interests (abuse prevention)
Welcome and transactional emailArt. 6(1)(b) — performance of contract
Legal obligations complianceArt. 6(1)(c) — legal obligation

Where we rely on legitimate interests (Art. 6(1)(f)), we have balanced these against your rights and interests and concluded they do not override your fundamental interests. You may object to processing based on legitimate interests by contacting us.

5. Special Category Health Data

Your health profile (age, weight, fitness goals, dietary restrictions, allergies, etc.) constitutes special category data under GDPR Article 9 because it relates to your health. We apply a higher standard of protection to this data.

Explicit consent (Art. 9(2)(a)): Before creating your account, you are required to tick a dedicated checkbox explicitly agreeing to: “I have read and agree to the Privacy Policy, including the processing of my health data by AI.” This constitutes your explicit, informed consent to process your health data under GDPR Art. 9(2)(a) and equivalent laws in other jurisdictions. Your consent is freely given — you are not required to continue using the Service — and you may withdraw it at any time by deleting your account (noting that withdrawal of consent means we can no longer provide the Service to you).

What we do with health data:

  • Generate your initial 7-day meal plan via Anthropic's Claude AI model.
  • Fine-tune your calorie and macro targets over time based on your logged progress.
  • Generate weekly recap summaries using a limited data set (see Section 13 for exactly what is sent).

What we do NOT do with health data:

  • Sell your health data to any third party.
  • Use your health data for advertising or profiling.
  • Use your health data to train AI models (not permitted under Anthropic's API usage policy).
  • Share your health data with insurers, employers, or government bodies (except as required by law).

No automated decisions with legal or significant effects. We do not make any automated decisions about you that produce legal effects or similarly significant effects on you (GDPR Art. 22). Our AI generates meal suggestions and nutritional estimates as tools for your consideration, but all dietary decisions remain entirely and always yours.

6. Third-Party Services and Data Processors

We use the following third-party processors to deliver the Service. Each is bound by applicable data processing terms (a Data Processing Agreement or equivalent contractual commitments) and is required to process your data only for the stated purpose.

ProviderPurposeData sharedLocation
ClerkAuthentication & identityEmail, auth tokensUSA (SCCs)
SupabaseDatabase hostingAll account & health dataUSA/EU (SCCs)
Anthropic PBCAI processingHealth profile, meal data (see § 13)USA (SCCs)
PostHogProduct analyticsAnonymised usage eventsUSA/EU (SCCs)
SentryError trackingError logs, device infoUSA (SCCs)
VercelHosting & CDNRequest metadataUSA/global (SCCs)
ResendTransactional emailEmail addressUSA (SCCs)

SCCs = EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

7. International Data Transfers

We are based in India and use cloud service providers predominantly located in the United States. When personal data is transferred from the EU, EEA, or UK to countries without an adequacy decision, we use the following safeguards:

Standard Contractual Clauses (SCCs)

All our US-based processors have signed the European Commission's approved Standard Contractual Clauses (Decision 2021/914). These contractually bind processors to EU-equivalent data protection standards and are our primary transfer mechanism.

EU–US Data Privacy Framework (DPF)

Where our processors are certified under the EU–US Data Privacy Framework (DPF), this provides an additional adequacy-equivalent layer for US transfers, supplementing the SCCs we already have in place.

UK International Data Transfer Agreement (IDTA)

For UK users, international transfers are covered by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, as required by UK GDPR.

India: We comply with the Digital Personal Data Protection Act 2023 (DPDP Act) for cross-border transfers of Indian residents' data.

Brazil: Transfers are governed by LGPD Chapter V and rely on SCCs or other mechanisms approved by the ANPD.

To request details of the specific transfer mechanism applicable to your data, contact us at hello@heysupper.com.

8. Data Retention

Data typeRetention period
Account data (email, profile)Retained while your account is active. Deleted immediately upon account deletion.
Health profileRetained while your account is active. Permanently deleted upon account deletion via cascade delete.
Meal plans, check-ins, weight logsRetained while your account is active. Permanently deleted upon account deletion via cascade delete.
Onboarding conversationNot stored server-side. Exists in browser session only during onboarding; not retained after profile extraction.
PostHog analytics eventsUp to 12 months in anonymised form. Not linked to your account after deletion.
Sentry error reports90 days. May contain technical session identifiers but no health profile data.
Post-deletion security record (email only)Retained in a restricted, access-controlled security table solely to enforce the 14-day re-registration cooldown. This record is not used for marketing, analytics, or any other purpose, and is not accessible from your account if you re-register after the cooldown period expires.

How to delete your account: Go to Settings › Delete my account (at the bottom of the Settings page). This initiates an immediate, permanent cascade delete of all your personal data — health profile, meal plans, check-ins, weight logs, and all related records — from both our authentication provider and database.

9. Your Privacy Rights

Your rights depend on where you live. To exercise any right, email hello@heysupper.com. We will respond within the timeframe required by applicable law (generally within 30 days). We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive.

EU / EEA / UK — GDPR and UK GDPR

  • Right of access (Art. 15) — request a copy of your personal data.
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data.
  • Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data, subject to legitimate retention grounds.
  • Right to restriction of processing (Art. 18) — restrict how we process your data in certain circumstances.
  • Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — object to processing based on our legitimate interests.
  • Right to withdraw consent (Art. 7(3)) — withdraw consent to health data processing at any time; this requires account deletion.
  • Right to lodge a complaint — with your national supervisory authority (find yours at edpb.europa.eu/about-edpb/board/members_en).

India — DPDP Act 2023

  • Right to access information about your personal data being processed (Sec. 11).
  • Right to correction and erasure of your personal data (Sec. 12).
  • Right to grievance redressal — file a complaint with our Grievance Officer (Section 17).
  • Right to nominate a person to exercise your rights in the event of death or incapacity (Sec. 14).

California, USA — CCPA / CPRA

  • Right to know what personal information we collect and why.
  • Right to delete your personal information.
  • Right to opt out of the sale or sharing of personal information. (We do not sell personal information.)
  • Right to non-discrimination for exercising your privacy rights.
  • Right to correct inaccurate personal information.
  • Your health profile constitutes Sensitive Personal Information under CPRA. We use it only to provide the Service and do not use it for cross-context behavioural advertising.

Brazil — LGPD

  • Rights of confirmation, access, correction, anonymisation, portability, deletion, and information about third parties with whom we share data.
  • Right to withdraw consent at any time.
  • Right to lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
  • Contact our Brazil DPO (Section 18) for LGPD-specific requests.

Canada — PIPEDA and Quebec Law 25 (Loi 25)

  • Right to access your personal information and request corrections (PIPEDA Principle 9).
  • Right to withdraw consent (subject to legal and contractual restrictions).
  • Right to complain to the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
  • Quebec residents have additional rights under Law 25 (in force since September 2023): right to data portability in a structured, technology-neutral format; right to be informed of any profiling or automated processing that affects you; right to request human review of any automated decision that produces a significant effect on you; right to de-indexation of personal information from a technology where applicable.

Australia — Privacy Act 1988

  • Right to access your personal information (APP 12).
  • Right to correct your personal information (APP 13).
  • Right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
  • Your health information is Sensitive Information under the Privacy Act and is subject to enhanced collection and use restrictions.

10. Children's Privacy

Supper is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you are the parent or guardian of a child who has provided us with personal data without consent, please contact us at hello@heysupper.com and we will delete that data promptly.

In jurisdictions with a higher digital age of consent (e.g., 16 in some EU member states), we require verifiable parental consent for users below that threshold. Where we become aware that a user is below the required minimum age without parental consent, we will delete that account.

11. Cookies and Local Storage

Supper uses a minimal set of cookies and browser storage. We do not use third-party advertising, tracking, or profiling cookies.

NamePurposeExpires
Clerk auth cookiesAuthentication session tokens. Strictly necessary for login and maintaining your signed-in state.Session / 30 days
__nsNavigation session cookie — records that you have visited /plan, enabling access to gated routes (/profile, /settings, etc.). Strictly necessary for Service navigation.7 days
_bcBlock cache — stores your user ID to cache the account-block status check, reducing database load. Strictly necessary for security enforcement.1 hour
ph_* (PostHog)Anonymised product analytics. Identifies you as a returning user using an anonymised persistent ID. Does not link to your health data.1 year
Local StorageApp preferences (e.g., tour completion, notification permission state). Not transmitted to our servers.Until cleared

The Clerk, __ns, and _bc cookies are strictly necessary for the Service to function. You cannot opt out of these without also being unable to use the Service. The PostHog analytics cookie can be blocked via your browser settings without affecting Service functionality.

12. Push Notifications

With your explicit permission, Supper may send push notifications for meal reminders and streak alerts. Push notification permission is requested in-app and is entirely optional — the full Service is available without it.

You can withdraw push notification permission at any time via your device or browser settings, or by toggling off notifications in Settings › App.

13. AI Processing — What Data Is Sent to Anthropic

Supper uses Anthropic's Claude AI models for several features. The following table specifies precisely what data is sent to Anthropic for each feature. Anthropic processes this data only to return a response and does not use API inputs to train its models, per Anthropic's published API usage policy.

Meal Plan Generation

Claude Sonnet

Data sent: Your full health profile: age, biological sex, height, starting weight, current weight, goal weight, activity level, goal type (e.g., weight loss), dietary preferences, and food allergies/intolerances.

Triggered: When you generate or regenerate your meal plan.

Onboarding Chat

Claude Sonnet

Data sent: Your chat messages during the onboarding flow only, used to extract your health profile. Once your profile is saved, this chat route returns a 403 and cannot be used again.

Triggered: During initial onboarding only.

Meal Swap

Claude Haiku

Data sent: The current meal name, your dietary preferences, and your food allergies/intolerances. No weight data or other health profile fields.

Triggered: When you request to swap a specific meal.

Calorie & Macro Estimate

Claude Haiku

Data sent: The food description text you type. No health profile or any other personal data is included.

Triggered: When you use the macro estimator feature.

Weekly Recap Insight

Claude Haiku

Data sent: Meal adherence percentage (meals logged out of total slots), liked meal names, disliked meal names, and weight change in kg over the past two weeks. No check-in mood or notes, no full health profile.

Triggered: When your weekly recap summary is generated.

14. Security

We implement technical and organisational security measures appropriate to the risk of processing health-related personal data, including:

  • Encryption in transit (TLS 1.2+) for all data between your device and our servers.
  • Row-Level Security (RLS) policies in our database, ensuring each user can only access their own data.
  • API rate limiting and account-block checks on all routes that access user data.
  • Content Security Policy (CSP) headers with nonce-based script whitelisting to mitigate injection attacks.
  • Access controls and API key rotation for all third-party service integrations.
  • Restricted access to production data limited to authorised personnel.

Data breach notification. In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law (GDPR Art. 33 and equivalents). Where the breach poses a high risk to your rights and freedoms, we will also notify you without undue delay (GDPR Art. 34).

No transmission over the internet or electronic storage method is 100% secure. If you discover a potential security vulnerability, please disclose it responsibly to hello@heysupper.com.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by displaying a prominent notice within the app at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

The current version is always available at heysupper.com/privacy.

16. EU & UK Representatives

Required before launching in EU or UK

Under Article 27 GDPR (EU) and Article 27 UK GDPR, organisations outside those territories that process EU/EEA/UK residents' personal data must appoint a designated representative within those territories. The placeholders below must be replaced with the details of an appointed representative before Supper is made available to EU or UK users. Representative services (e.g., DataRep, EDPO, VeraSafe) provide this for approximately €300–€700 per year.

EU / EEA Representative (Art. 27 GDPR)

Organisation[EU REPRESENTATIVE NAME — TO BE APPOINTED]
Address[ADDRESS, CITY, EU MEMBER STATE]
Email[eu-representative@example.com]

EU and EEA residents may contact the EU Representative directly with any GDPR enquiry or complaint in addition to contacting Supper directly.

UK Representative (Art. 27 UK GDPR)

Organisation[UK REPRESENTATIVE NAME — TO BE APPOINTED]
Address[ADDRESS, CITY, UNITED KINGDOM]
Email[uk-representative@example.com]

UK residents may contact the UK Representative directly with any UK GDPR enquiry or complaint in addition to contacting Supper directly.

17. Grievance Officer (India)

In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act 2023, we have designated a Grievance Officer for India:

NameTatwam Pandey
DesignationGrievance Officer
CompanySupper

Grievances will be acknowledged within 24 hours and resolved within 30 days of receipt, as required by the IT (Intermediary Guidelines) Rules 2021.

18. Brazil — Data Protection Officer (LGPD)

In compliance with the Lei Geral de Proteção de Dados Pessoais (LGPD), Art. 41, we have designated an Encarregado de Dados (Data Protection Officer) for Brazil:

NameTatwam Pandey

Brazilian users may contact the Encarregado de Dados directly with any LGPD-specific request or complaint. You also have the right to lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd.

19. Contact Us

For general privacy questions, data subject access requests, complaints, or to exercise any of your rights, contact us at:

Supper

hello@heysupper.com

We aim to respond to all privacy enquiries within 5 business days.