Privacy Policy

Version 1.0  ยท  Last updated: 28 April 2026  ยท  Effective: 28 April 2026
UK GDPR Compliant This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are located in the EU, the EU GDPR also applies to your use of this service.

1. Who we are

Family Fit Eats ("we", "us", "our") is a vegetarian nutrition tracking service available at familyfiteats.com and via Telegram.

Data controller: Family Fit Eats
Contact: privacy@familyfiteats.com

We are the data controller for all personal data described in this policy. Where we use third-party services to process data on our behalf, those services are data processors operating under data processing agreements.

2. The data we collect

โš ๏ธ Health data notice Weight, calorie intake, nutritional information, and body measurements constitute health data under Article 9 of the UK GDPR. This is special category data requiring your explicit consent before we collect it. We only collect this data after you have given that consent.

2.1 Data you provide directly

DataExamplesWhy collected
Personal detailsName, age, biological sexPersonalising your calorie target using the Mifflin-St Jeor formula
Body measurementsHeight, weight, target weightCalculating a safe, personalised daily calorie goal
Nutrition logsFood descriptions, meal photos, calorie estimates, macronutrientsTracking your progress against your daily goal
Children's dataChild's name, age, biological sex, nutrition logsProviding family nutrition tracking for your children
Goal preferenceLose weight / eat healthier / gain weightTailoring daily targets and advice to your objective

2.2 Data collected automatically

DataPurpose
Telegram Chat ID (Telegram users only)Identifying your account in our Cloudflare KV store to retrieve your logs
Scan count per day (web app)Enforcing the free-tier limit of 3 photo scans per day
Consent recordRecording that you gave informed consent, when, and to which version of this policy

2.3 Data we do NOT collect

3. How and where data is stored

3.1 Web app (browser local storage)

โœ“ Your device only When you use the Family Fit Eats web app, all of your profile data, food logs, and settings are stored exclusively in your browser's local storage. This data never leaves your device and is never transmitted to our servers. We have no access to it.

The only data that leaves your device is the content of food photos or meal descriptions you submit for AI analysis โ€” see Section 4 for details.

3.2 Telegram bot

If you use Family Fit Eats via Telegram, your profile, food logs, and children's data are stored in Cloudflare KV, a key-value data store operated by Cloudflare, Inc.

4. Third-party processors

4.1 Anthropic (AI analysis)

When you submit a food photo or meal description for calorie analysis, that content is sent to Anthropic, PBC via their Messages API. Anthropic processes this data as our data processor under a Data Processing Addendum.

4.2 Cloudflare (infrastructure)

Our application runs on Cloudflare Workers and Cloudflare KV. Cloudflare acts as a data processor. They are certified under the EU-US Data Privacy Framework.

4.3 Netlify (web hosting)

The Family Fit Eats web app is hosted on Netlify. Netlify may process standard web server access logs (IP addresses, request timestamps) as part of normal CDN operation. These are not linked to your Family Fit Eats account.

5. Lawful basis for processing

Processing activityLawful basis
Collecting and processing health data (weight, nutrition, calories)Explicit consent โ€” Article 9(2)(a) UK GDPR. You provide this during onboarding and can withdraw it at any time.
Processing children's health dataExplicit consent of person with parental responsibility โ€” Article 9(2)(a). You confirm parental responsibility before adding a child's account.
AI analysis of food photos and descriptionsExplicit consent โ€” you consent to Anthropic processing during onboarding
Storing your profile to provide the serviceContract performance โ€” Article 6(1)(b). Processing your profile is necessary to provide the personalised nutrition tracking you have requested.
Retaining your consent recordLegal obligation โ€” Article 6(1)(c). We are required to demonstrate lawful processing.

6. Children's data

โš ๏ธ Children under 13 We do not knowingly collect data from children under 13 years old as primary account holders. The minimum age to create your own account is 13. Children's accounts may only be created by a parent or guardian with parental responsibility.

When you add a child's account, we apply the following additional protections:

7. Your rights

๐Ÿ—‘๏ธ
Right to erasure
Delete all your data instantly from Settings โ†’ Delete my data (web app) or /deleteaccount (Telegram). No waiting, no forms.
๐Ÿ“‹
Right of access
Request a copy of all data we hold about you. Web app users: your data is already visible in your browser. Email us for Telegram data.
โœ๏ธ
Right to rectification
Correct any inaccurate data from the Goals & Profile screen at any time.
๐Ÿšซ
Right to withdraw consent
You can withdraw your consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal.
๐Ÿ“ฆ
Right to portability
Request your data in a machine-readable format by emailing privacy@familyfiteats.com.
โš–๏ธ
Right to complain
You have the right to lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk.

To exercise any right, contact us at privacy@familyfiteats.com. We will respond within 30 days.

8. Data retention

DataRetention period
Web app data (local storage)Until you clear your browser data or delete your account in the app
Telegram food logs (Cloudflare KV)7 days, then automatically deleted
Telegram profile and goalsUntil you use /deleteaccount
Children's dataSame as parent account โ€” deleted when parent deletes account
Consent recordRetained for 3 years after account deletion to demonstrate lawful processing

9. International transfers

Your data may be transferred outside the UK in the following circumstances:

10. Security

We take appropriate technical and organisational measures to protect your data:

No system is 100% secure. If you believe your data has been compromised, please contact us immediately at privacy@familyfiteats.com.

11. Cookies and tracking

The Family Fit Eats web app does not use cookies, advertising trackers, or analytics. We do not use any third-party tracking scripts. The only storage used is your browser's local storage, which is used solely to save your profile and food logs on your own device.

12. Changes to this policy

We may update this privacy policy from time to time. When we do:

13. Contact us

For any privacy-related queries, requests, or complaints:

Email: privacy@familyfiteats.com
Response time: Within 30 days
ICO registration: Pending

You also have the right to complain directly to the UK Information Commissioner's Office:

ICO: ico.org.uk
ICO helpline: 0303 123 1113