Privacy Policy

Plan Track Eat · Effective 20 April 2026

This Privacy Policy explains what information Plan Track Eat ("the App") collects, how it is used, and your rights. The App is operated by James Rendall, based in the United Kingdom. We are the data controller for the purposes of UK GDPR.

Summary

1. What We Collect

DataStored wherePurpose
Meal plans, recipes, logs, macros, goals, profile info (name, height, weight, dietary prefs)Locally on your device (browser localStorage / iOS app storage)Core app functionality
Content of AI prompts (e.g. "suggest a high-protein breakfast")Sent to Google Gemini via our Vercel proxy; not stored by usGenerate meal suggestions & recipes
AI usage count (0–3 per month) & subscription statusLocally on your device; RevenueCat holds entitlement stateEnforce free-tier limits and unlock Pro features
Apple ID transaction info (if you subscribe)Apple & RevenueCatProcess payments, manage subscriptions
Cloud-synced meal data (Pro users who opt in)Google Firebase (Firestore)Sync across your devices

2. What We Don't Collect

3. Third-Party Services

The App relies on the following third parties. Each has its own privacy policy governing their handling of data.

4. Legal Basis (UK & EU users)

5. Data Retention

Local data stays on your device until you delete it or uninstall the App. Cloud-synced data remains in Firebase until you delete it in-app or request deletion from us. AI prompt data is not retained by us after a response is returned.

6. Your Rights

Under UK GDPR you have the right to:

To exercise any of these rights, email James_rendall@hotmail.co.uk. You can also complain to the UK Information Commissioner's Office at ico.org.uk.

7. Children

The App is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us personal data, please contact us and we will delete it.

8. International Transfers

Our third-party providers (Apple, Google, Vercel, RevenueCat) may process data outside the UK, including in the United States. They use standard contractual clauses or equivalent safeguards to protect data transferred internationally.

9. Security

We use HTTPS for all network traffic. Local data is protected by the standard security of your device's operating system. No system is perfectly secure — please use a device passcode and keep your OS up to date.

10. Changes

If this policy changes, the updated version will be posted here with a new effective date. Material changes will be surfaced in the App.

11. Contact

James Rendall, United Kingdom
James_rendall@hotmail.co.uk