Privacy Policy
Last updated: May 24, 2026
1. Who We Are
PlatePuls Health ("we", "our", "us") operates the PlatePuls mobile app and web platform. We are based in [Your Country]. Contact: privacy@platepuls.app
2. What Data We Collect
- Account data: email address, password (hashed), name, timezone.
- Health data: meal photos, food items, nutritional estimates, symptom logs, severity ratings, and date/time of entries.
- Usage data: app interactions, device type, IP address, crash reports.
- Shared report data: when you generate a share link, the report contents become accessible to anyone with the link or token for the duration of the link's validity.
3. How We Use Your Data
- To provide and improve the PlatePuls service.
- To generate AI-powered nutritional analysis of meal photos (processed via OpenAI API — see Section 5).
- To create PDF health reports at your request.
- To send transactional emails (OTP codes, account notices) — no marketing without explicit consent.
4. Health Data & Medical Disclaimer
PlatePuls is not a medical device and does not provide medical advice. All AI-generated nutritional estimates and observations are informational only. Always consult a licensed healthcare professional before making clinical decisions. Reports shared with doctors are provided as-is with no warranty of accuracy.
5. Third-Party Services
- OpenAI: Meal photos and descriptions are sent to OpenAI for analysis. OpenAI's Privacy Policy applies to data processed by their API.
- Amazon Web Services (AWS): Data is stored on AWS infrastructure in us-east-1 (N. Virginia). AWS is our Data Processor under a signed Business Associate Agreement (BAA).
- Mailhog / SMTP: Used only in development. Production email uses a transactional provider.
6. Data Sharing
We do not sell your data. We share data only:
- With service providers listed in Section 5, under data processing agreements.
- When you explicitly create a share link — the linked report is accessible by anyone with the token.
- If required by law or to protect safety.
7. Data Retention
We retain your data for as long as your account is active, plus 90 days after deletion for backup purposes. Share links expire after 30 days by default. You may request earlier deletion at any time.
8. Your Rights
Depending on your location, you may have rights to: access, correct, delete, or export your data; object to processing; withdraw consent. Email privacy@platepuls.app to exercise any right. We will respond within 30 days.
9. Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS). Access tokens expire after 7 days. We maintain audit logs of data access. In the event of a breach affecting your data, we will notify you within 72 hours.
10. Children
PlatePuls is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.
11. Changes to This Policy
We will notify registered users by email at least 14 days before material changes take effect.