Privacy Policy

Effective date: 2026-05-10 Last updated: 2026-05-10 Policy version: 1.0


1. Who we are

GoalPlate (the "app", "we", "us", "our") is operated by Eric Vicente Zepeda Juarez, operating as GoalPlate (a sole proprietor; not yet incorporated). You can reach us at privacy@goalplate.app.

This policy explains what personal data we collect about you when you use GoalPlate, how we use it, who we share it with, how long we keep it, and the rights you have over it.

2. What data we collect

Data you give us when you create an account

When you sign in with Apple, Google, or Facebook, the auth provider gives us:

We do not see or store your password. With "Sign in with Apple", we receive a private relay email if you choose that option.

Data you give us by using the app

Data we collect automatically

Data we do NOT collect

3. How we use your data

Purpose Data used Legal basis (GDPR)
Run the service (generate recipes, track goals, store meal plans) Account, goal, recipe, meal plan, preferences Performance of the contract you accepted
Personalise AI suggestions (tailor recipes to your profile and dietary filters) Fitness profile, dietary preferences, prompt Legitimate interest in giving you a useful product
Send push notifications you enabled (reminders, weekly recap) Push token, goal data, preferences Consent (you can disable per-type in Settings)
Bill you for paid tiers Subscription state from RevenueCat Performance of the contract
Detect and fix bugs, prevent abuse Diagnostic logs, usage counters Legitimate interest in keeping the service up
Comply with legal requests Whatever the request specifies Legal obligation

We do not use your data for advertising, profiling for credit decisions, or any automated decision that has legal or significant effect on you.

4. Who we share your data with (subprocessors)

GoalPlate runs on third-party infrastructure. Each subprocessor sees only the data they need to do their job:

Subprocessor What they see Their purpose Where
Microsoft Azure (Cosmos DB, Functions, Application Insights, Azure OpenAI) All of your account, goal, recipe, and meal-plan data; recipe prompts and AI completions Hosting, compute, AI inference West US 3 (Phoenix, Arizona, USA)
Google Firebase (Authentication, Cloud Messaging) Email, Firebase UID, push tokens, sign-in events Identity and push delivery Google data centres (multiple regions)
RevenueCat A pseudonymous user ID, subscription tier, transaction events from the stores Subscription management and webhooks United States
Apple (Sign in with Apple, App Store) Apple ID identifier, payment events for App Store purchases Identity and billing Apple data centres
Google (Google Sign-In, Play Store) Google account identifier, payment events for Play Store purchases Identity and billing Google data centres
Meta (Facebook Login) Facebook account identifier, when you choose Facebook sign-in Identity Meta data centres

We do not sell your data, lend it, share it for advertising, or transfer it to anyone outside the list above except as described in section 9 (legal requests).

5. International transfers

GoalPlate operates from the United States and primarily processes data in the United States (Microsoft Azure West US 3). Some subprocessors operate in additional regions (see section 4). When we receive data from jurisdictions with stricter cross-border-transfer rules (EU/EEA, UK, California), we rely on the standard contractual clauses or the equivalent mechanism each subprocessor publishes.

6. How long we keep your data

If you ask us to delete your account, we cannot retrieve it. Deletion is permanent and immediate.

7. Your rights

Depending on where you live, you have some or all of the following rights:

To exercise a right, email privacy@goalplate.app. We will respond within the time required by your local law (45 days under CCPA, 30 days under GDPR).

8. Children's privacy

GoalPlate is not for children under 13. We confirm age at first launch. If you believe we have collected data from a child under 13, contact us and we will delete it.

In some EU member states the minimum age for consent to data processing is 16. If you are between 13 and 16 in such a jurisdiction, please use the app only with the consent of a parent or guardian.

9. Legal disclosures

We may disclose your data when required by a valid legal request (court order, subpoena, lawful government request) or when we have a good-faith belief disclosure is necessary to protect our rights, your safety, or the safety of others.

10. Security

We use TLS for all network traffic, encrypt data at rest in Azure Cosmos DB, sign authentication tokens, and limit internal access to the minimum needed. No system is perfectly secure — if we discover a breach affecting your data, we will notify you and the relevant authorities as required by your local law.

11. Changes to this policy

When we change this policy materially, we will:

  1. Post the new version at the same URL with an updated "Last updated" date
  2. Bump the policy version (current: 1.0)
  3. Re-prompt you for consent the next time you open the app

For minor edits (typo fixes, clarifications), we update the document without re-prompting.

12. Contact

If you do not get a response within 30 days, you can lodge a complaint with the data protection authority in your jurisdiction (see section 7).