1. Introduction
GenFitPlan ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered recipe generation and nutrition management platform.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable privacy laws. By using our Service, you consent to the data practices described in this policy.
2. Information We Collect
Account Information
- Name, email address, and password
- Profile picture (optional)
- Subscription and billing information
- Account preferences and settings
Health and Dietary Data
- Dietary preferences and restrictions
- Nutritional goals and targets
- Physical characteristics (age, weight, height) - optional
- Activity level and lifestyle information
- Food allergies and medical dietary requirements
Usage Data
- Inventory items and expiry dates
- Generated recipes and cooking history
- Meal planning and nutrition logs
- App usage patterns and preferences
- Search queries and feature interactions
Technical Data
- IP address and location data
- Device type, operating system, and browser
- App version and performance metrics
- Cookies and similar tracking technologies
3. How We Use Your Information
Service Provision
- Generate personalized AI recipes based on your preferences
- Track nutrition and manage your food inventory
- Provide meal planning and health insights
- Process subscription payments and manage accounts
Service Improvement
- Analyze usage patterns to improve AI recommendations
- Develop new features and enhance user experience
- Conduct research using anonymized, aggregated data
- Optimize app performance and fix technical issues
Communication
- Send important service updates and notifications
- Provide customer support and respond to inquiries
- Share promotional content (with your consent)
- Send expiry alerts and meal reminders
Legal Compliance
- Comply with applicable laws and regulations
- Respond to legal requests and prevent fraud
- Protect our rights and the safety of our users
4. Information Sharing and Disclosure
We do not sell your personal data. We may share your information in the following circumstances:
Service Providers
- OpenAI: For AI recipe generation (anonymized data only)
- Payment Processors: For subscription billing and payments
- Cloud Hosting: For secure data storage and app infrastructure
- Analytics Providers: For app performance and usage insights
Legal Requirements
- When required by law or legal process
- To protect our rights, property, or safety
- In connection with legal disputes or investigations
- To prevent fraud or illegal activities
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to the same privacy protections.
5. Data Security and Retention
Security Measures
- Encryption of data in transit and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Secure server infrastructure and data centers
- Regular backups and disaster recovery procedures
Data Retention
- Account Data: Retained until account deletion
- Usage Data: Retained for 2 years for service improvement
- Billing Data: Retained for 7 years for legal compliance
- Analytics Data: Anonymized data retained indefinitely
Data Deletion
You can request deletion of your personal data at any time. We will delete your data within 30 days, except where retention is required by law.
6. Your Privacy Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
Access and Portability
- Right to Access: Request a copy of your personal data
- Data Portability: Export your data in a structured format
- Right to Information: Understand how your data is processed
Control and Correction
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we process your data
Consent and Objection
- Withdraw Consent: Revoke consent for data processing
- Object to Processing: Object to data processing for marketing
- Automated Decision-Making: Object to purely automated decisions
To exercise these rights, contact us at privacy@genfitplan.com. We will respond within 30 days and verify your identity before processing requests.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience:
Essential Cookies
- Authentication and session management
- Security and fraud prevention
- Basic site functionality
Analytics Cookies
- Usage analytics and performance monitoring
- Feature usage and user behavior analysis
- Error tracking and debugging
Advertising Cookies (Mobile App)
- AdMob advertising for free tier users
- Ad personalization and frequency capping
- Revenue optimization for sustainable service
You can manage cookie preferences in your browser settings. For detailed information, see our Cookie Policy.
8. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries with equivalent data protection
- Certification schemes and binding corporate rules
- Your explicit consent where required
9. Children's Privacy
Our Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
Users between 13-18 must have parental consent to use our Service and should use it under parental supervision.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email and/or through our Service. The updated policy will be effective when posted, and your continued use constitutes acceptance of the changes.
11. Contact Information
For questions about this Privacy Policy or to exercise your privacy rights, contact us:
- Privacy Email: privacy@genfitplan.com
- Data Protection Officer: dpo@genfitplan.com
- General Support: support@genfitplan.com
- Address: Bucharest, Romania
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.