Privacy Policy
Last updated: 2 October 2026
This policy explains what personal data Mealione collects, why we need it, who else touches it, how long we keep it and what you can ask us to do with it. It covers the Mealione mobile app, our website at mealione.com and the pages we serve at app.mealione.com and quiz.mealione.com.
The short version, before the detail:
- We ask health questions (body measurements, goal, diet, allergies) because a weekly meal plan is calculated from the answers. They are used for your plan and for nothing else.
- We never sell your data and we run no advertising in the app. The website uses web analytics and advertising measurement, described below.
- You can delete your account, and everything attached to it, from inside the app — without writing to us and without waiting. If you cannot open the app, email support@mealione.com and we will do it for you.
1. Who is responsible for your data
HG POINT LIMITED, a company registered in the Republic of Cyprus ("Mealione", "we", "us"), is the controller of the personal data described here. Our registered address is Spyrou Kyprianou 78, Limassol 3076, Cyprus. You can reach us about anything in this policy at support@mealione.com.
2. What we collect and why
We collect data to provide the service, operate paid accounts and understand whether our website and product work. We do not buy personal data from data brokers.
| What | Examples | Why we need it | Legal basis (GDPR) |
|---|---|---|---|
| Email address | the address you give us at checkout, or one you choose to connect to your account later | it is where we send your sign-in link or code, and it is what lets you open the same account on another device or after a reinstall | performance of our contract with you, Art. 6(1)(b) |
| Email contact and preferences | your address, quiz or account identifiers, the source and date we received it, quiz language and checkout currency when known, and any unsubscribe or suppression record | to address quiz follow-ups correctly, respect objections and prevent duplicate or unwanted messages. We do not record a separate marketing opt-in merely because you left an address | our legitimate interest in maintaining accurate contact records, recording objections and preventing unwanted messages, Art. 6(1)(f) |
| Email delivery records | the type and version of a message, scheduling and sending times, delivery status, a delivery-provider identifier, a stop reason and, where applicable, an offer deadline. We also record delivery failures, complaints, unsubscribes and the fact of a tracked link click | to deliver service messages, respect unsubscribes and delivery failures, prevent duplicates and investigate delivery problems. Our history does not contain the message body, clicked link, IP address, browser details or health answers | performance of our contract for service messages, Art. 6(1)(b); our legitimate interest in keeping delivery reliable and respecting your choice, Art. 6(1)(f) |
| Health answers from the quiz | sex, age, height, current and goal weight, how active you are, how fast you want to move, your diet, allergies and foods you do not want to see | the calorie target, the macros and the recipes we pick for you are calculated from these answers | your explicit consent, Art. 9(2)(a), together with Art. 6(1)(a) |
| What you do with your plan | meals you mark as eaten, items you tick off the shopping list, plans generated for you, swaps you make | it drives the app itself: the next week is built around what you already had, and the shopping list remembers what you already bought | performance of our contract, Art. 6(1)(b) |
| Account and session identifiers | your internal user ID, session records, one-time sign-in tokens | they keep you signed in and stop anyone else from using your account | performance of our contract, Art. 6(1)(b) |
| Push token and platform | the notification token your phone hands to the app, and whether it is iOS or Android | it is the address a push notification is delivered to; without it the phone cannot be reached | your consent to notifications, given in the system dialog, Art. 6(1)(a) |
| Time zone | the IANA time zone of your device, for example America/New_York | the week has to start on your Monday, and reminders must not arrive at night | performance of our contract, Art. 6(1)(b) |
| Subscription records | which subscription you hold, when the paid period ends, whether renewal is on, the events the store or the payment provider sends us | it is how the app knows you have paid access, and how we handle renewals, cancellations and refunds | performance of our contract, Art. 6(1)(b); for accounting records, our legal obligations, Art. 6(1)(c) |
| Purchase identifiers from the app store | the profile identifier our subscription provider creates for your device, the identifier the store gives the transaction, and the technical facts your device sends with them: its model, its operating system and its language | it is how a subscription bought in your App Store or Google Play account is matched to your Mealione account, and how we find it again when you ask us to restore a purchase | performance of our contract with you, Art. 6(1)(b) |
| Your answer to the cancellation question | the reason you pick from the list and the comment you may write | it tells us why people leave, which is the only way we can fix it | our legitimate interest in improving the service, Art. 6(1)(f) |
| Crash and performance reports | when the app crashes or misbehaves: the error and its stack trace, the app version, and the model, operating system and language of the device it happened on | an app that crashes silently stays broken; these reports are how we find and fix it | our legitimate interest in keeping the service working, Art. 6(1)(f) |
| App product analytics events | a fixed set of eight events, each tied to your internal user ID: an account was created from a purchase, you signed in (and by which route), you connected an email address to an account that started on your device (and whether the address was free or already had an account of its own), a plan was built for a given week, our server prepared a response to your request for the current plan (with the week start date, without confirming delivery or display), a payment happened (with the plan and the amount), a cancellation was started (with the reason you picked from the list) or finished (whether you left or stayed) | we need to know whether the product works before we spend more on it | our legitimate interest in understanding and improving the service, Art. 6(1)(f) |
What we do not collect. We do not collect your name, your postal address, your phone number, your precise location, your contacts, your photos or your card details in our app or our own analytics database. We do not collect mobile advertising identifiers such as IDFA or GAID — the SDK that handles subscriptions is able to read one, and we have that switched off. Mealione does not read Apple Health, Health Connect or any other health tracker. The app contains no advertising SDK and no attribution SDK, and shows no ads.
What you do inside your plan stays inside it. The meals you mark as eaten and the items you tick off your shopping list are not sent to our analytics provider — not their contents, and not even the bare fact that you ticked something. What you eat is health data, and health data has no business leaving for measurement.
Website and advertising measurement. On our web quiz and checkout, we measure page and step views, quiz completion, checkout progress and payment outcomes. Our own funnel records contain a pseudonymous quiz or visit identifier, event time, quiz and paywall version, experiment variant where present, language, device platform, country code and available campaign tags or click identifiers, such as UTM parameters, gclid, gbraid and wbraid. The country code is supplied by our web service provider; we do not request GPS location. When a quiz is linked to an account, we can connect this navigation record to the eight app events above and the fact of a payment to understand whether a website visitor became a paying customer and used the product.
Our own funnel records do not contain your email, quiz answers, health measurements, free text, card details or complete page URLs. We discard those contents before saving an analytics record. We keep only recognised navigation event names and allowed technical fields. We also mark explicitly identified service requests and our own test visits so they can be excluded from reports. This does not send your quiz answers or plan contents to our app analytics provider.
Your device's IP address reaches the services it connects to as part of how the internet works. We do not store raw IP addresses or raw browser user-agent strings in our own analytics database. The eight app events are sent by our backend with IP resolution switched off. Website analytics services receive requests from your browser and may use network and browser information for measurement; our web quiz and payment providers also receive that information when delivering their services. These website services are separate from the eight app events. Section 4 lists the providers.
Your account does not need an email address. The app creates an account on your device the first time you open it, and that account has no address attached to it. It does not need one: the quiz, the plan built from it and a subscription bought in the app all work without you telling us who you are. Connecting an address later is your choice — it is what lets you open the same account on another device, or find it again after a reinstall.
Your quiz emails and choices. If you provide your address in the web quiz and do not purchase, we may send your sample meal day as a PDF and follow up about Mealione, including a limited-time introductory offer. The first email is scheduled one hour after you provide your address; a recorded purchase stops the remaining recovery emails. The web quiz has no separate marketing opt-in checkbox, and we do not create a record claiming that you selected one. You can stop these follow-ups through the unsubscribe link in a message, or by writing to support@mealione.com. This stops pending marketing follow-ups; it does not stop necessary sign-in, email-connection or purchase messages. A delivery failure or spam complaint can stop all messages to an address until the delivery problem is resolved. We do not turn an unsubscribe back into a subscription because a provider reports the address as subscribed.
We keep our own contact and delivery history so your choices do not depend on how long an email provider keeps its logs. Health answers remain in the separate quiz record and are not copied into that history or into marketing contact properties. A separate temporary preview contains the sample meals, recipes and shopping list needed to prepare your PDF. Resend receives that PDF and the email contents for delivery, including the personalised meals and nutrition shown in them, but not your raw quiz answers. We do not retain a separate copy of the PDF file.
Email return and purchase measurement. We keep the original advertising source separately from email campaign tags. A signed email link and a first-party HttpOnly cookie, valid for one hour and bound to that return, let us connect a subsequent interaction on our website and checkout to the message that brought you back and, where the records can be matched, a confirmed order, amount and currency. An email open or an automatic link scan does not by itself count as this website interaction. These records contain technical identifiers and timestamps, not your answers, meal plan, card details or raw IP address. This describes an observed purchase path and does not prove that the email caused a purchase.
Purchase activation reminder. If a web purchase has not been activated, we may send one reminder after 24 hours with store links and the original sign-in link and code while they remain valid. A short-lived encrypted copy lets us repeat those original details without issuing new credentials. Activation, replacement or use of the credentials cancels the reminder and removes that temporary copy.
Where your quiz answers go. You can answer the quiz before any account of yours exists. The answers are stored against an anonymous quiz session first, so that a plan can be built the moment you pay, and in the app they are attached to the account on your device as soon as you finish the quiz. If you answered on our website instead, they stay with the anonymous session — together with the address you gave at checkout — until you open the account by using a sign-in link. Answers that never reach an account are erased on the schedule in section 6.
3. Health data and your consent
Your answers about your body, your goal, your diet and your allergies are special category data under Art. 9 GDPR. In the mobile app, we ask for them on a separate screen, before the first question of the quiz, with a checkbox that does nothing else — it is not bundled with accepting these documents, and it is not implied by continuing.
We keep a record of that consent — the version of the text you were shown and the moment you gave it — and you can see it in the app's settings.
You can take that consent back whenever you like: delete your account (section 7), and the answers go with it. Taking it back does not undo what we did while it was in force. Because the health answers are the plan, withdrawing consent means we can no longer build one for you — this is a service that cannot exist without them, not a condition we attached to something unrelated.
4. Who else processes your data
We use the following providers to run the app and backend. The website also uses the quiz, payment and measurement services listed after the table. Their roles and the information they receive depend on the service they provide.
| Who | What they do for us | What they see |
|---|---|---|
| Railway | hosting for our backend and our database | everything stored in the database, as the infrastructure it runs on |
| Resend | delivers sign-in, purchase and activation reminder emails, and the quiz follow-ups described above | your email address, message contents and PDF attachments, delivery identifiers and status, and your unsubscribe status when a contact is synchronised. We do not copy quiz health answers into Resend contact properties |
| Expo (push service, then Apple Push Notification service or Firebase Cloud Messaging) | delivers push notifications to your device | your push token and the text of the notification |
| Mixpanel (EU data residency) | product analytics | the eight events listed in section 2 with the properties named there, tied to your internal user ID. Nothing else reaches them: not your email, not a single health answer, not what you marked as eaten or ticked off, not the free text you write, not your IP address |
| Sentry | collects the crash and performance reports described in section 2 | the error and its stack trace, the app version, and the model, operating system and language of your device. It is not told who you are: we never attach your user ID or your email, and the lines the app writes to its own log are dropped before an event leaves the device |
| Cloudflare | stores and delivers the recipe photographs | the IP address of the device requesting a picture; recipe photographs are our own catalogue content and carry nothing about you |
| Adapty | runs the subscriptions bought inside the app: it fetches the prices we show you, asks the App Store or Google Play to take the payment, and tells our servers when a purchase, a renewal or a cancellation happens | the purchase itself — which subscription, when, in which store, and the identifiers the store and Adapty give it — tied to your internal user ID, together with your IP address and the model, operating system and language of your device. It never receives your email address, a single health answer, or anything from your plan |
Services on our website. Our web quiz and checkout also use:
- Web2Wave, which hosts the quiz and checkout flow and provides web navigation, campaign and subscription information to us. It receives the answers and contact details you enter on those pages. Our own analytics copy contains only the restricted fields described in section 2; the answers needed to build your plan are processed separately. We can also mirror your unsubscribe status against the existing quiz identifier; this does not subscribe you to a Web2Wave email sequence.
- Stripe, which processes website payments. Payment details are entered in Stripe's payment form. We receive payment and subscription identifiers, status, currency and amounts; we do not store your card number in our app or our analytics database.
- Google Analytics and Google Ads, which measure website visits and advertising results, including web event information, browser and campaign identifiers and conversion amounts. These services are used on the website, not through an advertising or attribution SDK in the Mealione app. Google's handling is also described in How Google uses information from sites or apps that use its services.
Apple and Google. If you buy a subscription in the app, Apple or Google take the payment and act on their own account, not on ours. We receive the fact of the purchase, its renewal status and the identifiers needed to match it to your account — never your card number. Their handling of your payment is governed by their own privacy policies.
Everyone else. We do not share your data with anyone else, other than where we are legally obliged to (a valid order from a court or an authority), or where it is necessary to establish or defend a legal claim. If the business is ever sold or merged, the data may pass to the buyer, who would remain bound by this policy or tell you in advance what changes.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We have never done so.
5. Where your data is processed
Our backend and our database run on servers in the United States (Railway, US West). Our analytics project is held on Mixpanel's European infrastructure. Adapty, which runs subscriptions bought in the app, processes and stores what it holds in the United States. Our other providers are companies established in the United States and may process data there or elsewhere.
If you live in the European Economic Area or in the United Kingdom, that means your data travels outside it. Every such transfer is covered by the European Commission's standard contractual clauses, agreed with the provider concerned and read together with the technical measures in section 8. You can ask us for a copy of those clauses at support@mealione.com and we will send it to you.
6. How long we keep it
| What | How long |
|---|---|
| Everything attached to your account | while the account exists; erased when you delete it (section 7) |
| An account created on your device that never got an email address and never had a subscription | deleted in full once it is 90 days old and the device has stopped using it (the session a device holds lasts 30 days and is renewed while you keep using the app) |
| Quiz answers given before an account exists, where no purchase followed | the health answers are erased 90 days after the quiz |
| The email address, acquisition and preference record from a quiz that never became an account | up to 3 years from the first quiz or receipt of the address, after which the record is deleted in full. An unsubscribe stops quiz recovery messages; we use the remaining record to respect that objection and, if needed, establish the contact and delivery history. Those limited purposes rely on our legitimate interest in preventing unwanted mail and defending against a claim, Art. 6(1)(f) |
| Our own email contact identities, scheduled follow-ups, delivery history and provider reconciliation records | deleted with the contact: when its account is deleted; for an address without an account, within the same 3-year period from the first quiz or receipt of the address; for paid access that never became an account, 6 months after the paid period ends. A message, click, repeated event or later contact update does not restart the 3-year period |
| The temporary preview used for the first PDF | expires 25 hours after receipt of the quiz email address and is removed at the next scheduled cleanup, or sooner when the profile changes or the contact is erased. Our server renders PDF bytes for delivery but does not save a separate PDF file |
| The encrypted original credentials held for an activation reminder | removed after sending, activation, replacement or invalidation; otherwise the envelope expires within 36 hours of credential issue and is removed at the next scheduled cleanup. This does not extend the validity of the original credentials |
| Email return interactions and the original advertising snapshot for contacts without an account | return records are removed 90 days after receipt, and the advertising snapshot 90 days after enrollment. Linked records are erased when the account is deleted |
| Copies held by our email provider | Resend states that email and log data are held for 30 days on Free, Pro and Scale plans. Deleting a marketing contact is separate from deleting those operational logs; we request contact deletion when we remove the contact from our own records. That 30-day period is not a stated lifetime for an active marketing contact |
| Paid access recorded for someone who paid but never created an account | until 6 months after the paid period ends |
| Sign-in tokens and codes | deleted 30 days after they are used or expire |
| Your answer to the cancellation question | kept as a statistic after your account is gone, with the link to you removed, the free-text comment erased and the timestamps coarsened to a date |
| Crash and performance reports | held by Sentry for the retention period of our plan and deleted automatically when it expires; we keep no copy of our own |
| Our own web navigation records that have not been linked to an account | 90 days after receipt; linked records are erased when the account is deleted |
| Our own collection diagnostics and rejected-event diagnostics | 30 days; rejected-event diagnostics contain a reason code and minimal identifiers, not the rejected answers or free text |
| Payment records | 10 years from the end of the year of the transaction, because VAT and accounting rules require it |
A job runs on our servers and enforces these periods automatically; deletion is real deletion of the rows, not a hidden flag.
The periods for our own records are separate from provider copies. Web2Wave holds the information you enter on its quiz and checkout pages; its exact category-specific retention periods have not been confirmed to us. For deletion of website quiz data held there, contact support@mealione.com so we can arrange removal with the provider.
7. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. If the GDPR applies to you, you also have the right to restrict or object to processing, the right to receive your data in a portable format, and the right to withdraw a consent you have given. If you are in California, you have the right to know what we collect and why, to request deletion or correction, and not to be treated differently for exercising those rights; we sell nothing, so there is nothing to opt out of. Residents of Washington, Nevada and Connecticut have specific rights over consumer health data, described in our Consumer Health Data Privacy Notice.
There are two ways to have your data deleted:
- Delete your account from the app — Profile → Delete account. You can do this yourself, without asking us and without waiting. It removes your plans, your preferences, your shopping list marks, your push tokens, your sessions, your own web navigation records linked to that account, our email contact and delivery history and the account itself. It also requests deletion from our analytics provider and of synchronised Resend contacts. Provider copies follow their own deletion procedures; removing our rows does not itself confirm that those copies have been erased. It cannot be undone.
- Ask us. If you cannot open the app, or if you answered the quiz, or paid, but never created an account, write to support@mealione.com and we will find and erase what we hold. We answer within one month.
One thing deletion does not take with it: the record that a payment happened. Tax and accounting law requires us to keep those for ten years (section 6), so they stay after the rest of your data is gone, and they are kept for that purpose alone.
For anything else — a copy of your data, a correction, an objection — write to support@mealione.com. We may need to check that the request comes from the owner of the address. We answer within one month, and tell you if we need longer.
Deleting your account never cancels a subscription, whichever way you bought it, so cancel first and delete after. A subscription bought on our website is cancelled in the app, under Profile → Subscription — once the account is gone you can no longer do it yourself and would have to write to us. A subscription bought through Apple or Google lives in your store account, and only the store can stop it: cancel it in your App Store or Google Play settings.
If you think we have handled your data badly, we would rather hear it first — but you can complain to the data protection authority of the country you live in, and, because we are established in Cyprus, to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
8. How we protect it
Traffic between the app and our servers is encrypted in transit, and the database credentials are held as secrets, never in our source code. There are no passwords to steal: signing in works through a one-time link or code sent to your email address, valid for fifteen minutes and usable once. Sign-in links are never written into our logs, and neither are the addresses they were sent to. Access to production data is limited to the people who run the service. No system is perfectly secure, and we will tell you and the relevant authority if a breach ever affects you.
9. Age
Mealione is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone younger, and if we learn that we have, we delete it. If you believe a child has given us their data, write to support@mealione.com.
10. Email and notifications
We send you email you cannot switch off while you have an account, because it is how the service works: the sign-in link or code, and messages about your subscription or your data. Push notifications are optional — the app asks for permission the first time a plan is ready, and you can withdraw it in your phone's settings at any time. Quiz follow-ups are described in section 2. Each recovery message includes an unsubscribe link and supports one-click unsubscribe in compatible email clients.
11. Changes to this policy
We will update this page when the product changes. The date at the top always shows the current version. If a change materially affects your rights or how we use your health data, we will tell you in the app or by email before it takes effect, and where the law requires it, ask for your consent again.
12. Contact
support@mealione.com — for anything in this document, including all data protection requests.
HG POINT LIMITED Spyrou Kyprianou 78, Limassol 3076, Cyprus