Meelo
Features Pricing Promises FAQ
Get the app
Meelo
Home01 Features02 Pricing03 Promises04 FAQ05
Get the app
Privacy Terms Imprint [email protected]
Legal

Privacy Policy.

Effective: 1 May 2026 Last updated: 1 May 2026 Version: 1.0
Contents
00At a glance 01Controller 02What we collect 03Why we collect it 04Legal basis (GDPR) 05Sharing 06Storage & retention 07Security 08Your rights 09Children 10Third-party AI 11Health data & health sync 12Changes 13Contact
Plain-language summary

We collect what you log so the app works. We store it on EU servers, encrypted. We never sell or share it with advertisers. You can export or delete everything any time. With your explicit permission, we can read movement data from Apple Health / HealthKit on iOS or Health Connect on Android. Health data is never used for advertising or sold to anyone.

This policy describes how Meelo collects, uses, and protects your personal information. We have written it in plain English wherever possible. Where defined GDPR terminology is required, we use it and explain it.

Section 01

Controller.

The data controller for the personal information described in this policy is Meelo ("Meelo", "we", "us"), a private limited company registered in Estonia, operating the Meelo product ("Meelo", "the App").

Contact for privacy matters: [email protected].

If you are located in the European Economic Area, the United Kingdom, or Switzerland, your relationship under GDPR (or its equivalent) is with Meelo as controller.

Section 02

What we collect.

Account data

  • Email address, display name, and authentication identifier (Sign in with Apple anonymous relay supported).
  • Subscription status and receipt identifiers from Apple's StoreKit (we do not see your payment card).

Logging data you provide

  • Foods logged, portions, timestamps, custom foods and meals you create.
  • Optional weight, body measurements, water intake, mood and notes if you choose to record them.
  • Photos you submit to AI photo logging (Pro); these are processed and discarded. See Section 10.

Health data (with your permission)

  • Step count, active energy and supported movement data from Apple Health / HealthKit or Android Health Connect, only if you grant access.

Technical data

  • App version, OS version, device model, language, for crash diagnostics and compatibility.
  • Approximate region (country-level) inferred from App Store locale, for currency and database ranking.
  • We do not collect: precise location, advertising identifiers (IDFA), contacts, photos library access beyond your explicit picks, or microphone audio outside the voice-logging feature when you trigger it.
Section 03

Why we collect it.

  • To run the app: save and sync your logs across your devices, calculate targets, render charts.
  • To deliver Pro features: identify foods in photos, transcribe voice entries, generate reports.
  • To support you: respond to emails, debug crashes, restore lost data.
  • To meet legal obligations: tax records on your subscription, lawful disclosure on properly-served orders.

We never collect data to build advertising profiles. Meelo runs no ad networks, no analytics SDKs that exfiltrate identifiable usage to third parties for marketing, and no "anonymized" data sales.

Section 04

Legal basis (GDPR).

Under Article 6 of the EU General Data Protection Regulation, we process your data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)), to deliver the app you have signed up for.
  • Consent (Art. 6(1)(a)), for Apple Health / HealthKit access, Health Connect access, third-party wearable connections, marketing emails (which are off by default).
  • Legitimate interests (Art. 6(1)(f)), for crash diagnostics and basic compatibility telemetry, balanced against your privacy expectations.
  • Legal obligation (Art. 6(1)(c)), for tax record retention.

Health-related data (Article 9 special category) is processed under Article 9(2)(a), your explicit consent, and only ever to provide the feature you requested.

Section 05

Sharing.

We do not sell your data. Ever. We share it only where strictly necessary to operate the app, and only with the categories of recipient listed below:

  • Cloud hosting: Hetzner Online GmbH (Germany) and Scaleway SAS (France), storage and compute, EU-only regions.
  • Authentication: Apple Inc., Sign in with Apple identity verification.
  • Subscriptions: Apple Inc., StoreKit payment processing.
  • Crash diagnostics: Sentry GmbH (Germany), self-hosted on our EU infrastructure.
  • Email: Postmark (operated by ActiveCampaign, USA, under SCCs), transactional emails only.
  • AI processing (Pro photo / voice / label features only): see Section 10.

We require all processors to sign a Data Processing Agreement consistent with GDPR Article 28 and to apply equivalent security standards.

Section 06

Storage & retention.

Your data is stored on EU servers (currently Frankfurt and Amsterdam regions). It is encrypted in transit (TLS 1.3) and at rest (AES-256).

Retention periods

  • Logging data: retained for the lifetime of your account; deleted within 7 days of account deletion.
  • Crash logs: 90 days.
  • Email correspondence: 24 months.
  • Subscription/billing records: 7 years (legal tax requirement).
  • AI photo / voice payloads: processed and discarded within 30 seconds; never persisted.
Section 07

Security.

We apply technical and organisational measures appropriate to the risk, including: TLS 1.3 in transit; AES-256 at rest; role-based access controls; least-privilege production access; quarterly access reviews; mandatory two-factor authentication for staff; isolated production environments; encrypted off-site backups with 30-day rotation; documented incident-response procedures.

No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33-34.

Section 08

Your rights.

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten"), delete your account from inside the app.
  • Restrict or object to processing in certain circumstances.
  • Portability, export your data in a machine-readable format (PDF, CSV, plain text). See Data export.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local data protection authority. The lead authority for Meelo is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Most of these rights are exercisable directly inside the app. To request anything we don't expose in-app, write to [email protected] and we will respond within 30 days.

Section 09

Children.

Meelo is not directed at children under 16 and we do not knowingly collect personal data from children under 16. If you believe a child has created a Meelo account, please contact us at [email protected] and we will delete it promptly.

Section 10

Third-party AI services.

Pro AI features (photo logging, voice logging, label scanning) require sending your input to a third-party model provider. We currently use:

  • Anthropic PBC (USA) under Standard Contractual Clauses, with Zero Data Retention enabled, inputs are not used to train models and are not retained beyond the inference call.
  • OpenAI Ireland Ltd. (Ireland, EU), same retention terms.

If you are uncomfortable with third-party AI processing, the AI features are entirely optional and the free tier requires no AI calls.

Section 11

Health data & health sync.

Where you grant Meelo access to Apple Health / HealthKit or Android Health Connect, we read step count, active energy and supported movement data to estimate activity and calories burned. Per platform health-data guidelines and our own commitment:

  • Health data is never used for advertising.
  • Health data is never sold to any third party.
  • Health data is never shared beyond the App and our own EU storage.
  • Health data is processed only for the health purposes described above.
  • You can revoke access at any time from iOS Health settings or Android Health Connect settings.
Section 12

Changes.

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email and an in-app prompt at least 30 days before the new version takes effect. Continued use of the App after the effective date constitutes acceptance of the updated policy. Prior versions are archived and available on request.

Section 13

Contact.

Questions, requests, or concerns about this policy can be sent to:

Meelo
Privacy team
[email protected]

For company address and registered details, see Imprint.

Track gently.
Eat plenty.

[email protected]

Product

  • Features
  • Pricing
  • Promises
  • FAQ

Account

  • Sign in
  • Support

Legal

  • Privacy
  • Terms
  • Data export
  • Imprint
© 2026 Meelo · Made in Europe Powered by PantraLabs