Last updated: April 2026. Suppr helps you log recipes, nutrition, and discover meals. This policy describes what we process, who we share it with, and your choices.
To provide the service (logging, meal planning, barcode and recipe features), improve reliability, and comply with law. We do not sell your personal data.
If you use optional features, we send the minimum content needed to operate them to our servers and, where described below, to model providers:
We use the following third-party service providers to operate Suppr. Each is bound by a data-processing agreement and processes your data only on our instructions.
| Provider | Purpose | Data received | Region |
|---|---|---|---|
| Supabase | Database, auth, storage | Account, app data, uploads | EU (Frankfurt) |
| Vercel | Hosting, edge network | HTTP requests, IP | Global edge, US primary |
| Upstash | Rate-limit state | IP, request counters | US / EU |
| Stripe | Web billing | Email, payment card (collected by Stripe directly) | US / Ireland |
| Apple (App Store, HealthKit, Sign in with Apple) | iOS purchases, sign-in relay, HealthKit sync | IAP receipt, private relay email, Health permission grants | Global |
| RevenueCat | iOS IAP receipt verification | IAP receipt, user id | US |
| Expo / EAS | Mobile OTA updates, push tokens, crash logs | Device id, push token | US |
| OpenAI | AI features (photo / text meal logging, recipe parsing) | Uploaded image, caption / URL text (no account data) | US |
| Edamam | Food database lookups | Ingredient text query (no account data) | US |
| FatSecret | Food database lookups | Ingredient text query (no account data) | US |
| USDA FoodData Central | Public-domain food database | Ingredient text query (no account data) | US (public sector) |
| Open Food Facts | Product / barcode lookups | Barcode or product name (no account data) | EU (France) |
| PostHog | Product analytics (if not opted out) | Event names, device id, page views | EU (Frankfurt) |
| Sentry | Error reporting (if not opted out) | Stack traces, device type, user id | EU (Frankfurt) |
| Google Play | Android purchases (future) | Purchase token, account email | Global |
Several sub-processors listed above are located in the United States (OpenAI, Stripe, Upstash, RevenueCat, Expo, Edamam, FatSecret, USDA). Where we transfer personal data of EU or UK users to a country not covered by an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum or the UK IDTA, together with supplementary technical and organisational measures (encryption in transit, access controls). A copy of the relevant transfer safeguards for any specific sub-processor is available on request by emailing the address at the foot of this page.
AI-derived nutrition matches, meal photo identification and ingredient parsing are automated but are estimates — a human (you) reviews and edits every saved entry before it enters your tracker. These features do not make decisions that produce legal or similarly significant effects about you.
If you enable the Apple Health integration on iOS, Suppr reads the following data to keep your tracker in sync: steps, active energy, basal energy, workouts, weight, body fat percentage, and any dietary entries already in Apple Health (for example logs you created in other apps). Suppr writes the calories, protein, carbohydrates, fat, and fibre of the meals you log back to Apple Health so other apps on your phone can read them. Data shared with Apple Health is governed by Apple’s privacy policy and stored on your device; Suppr does not send your Health data to our servers unless you explicitly log a meal. You can revoke Suppr’s Health access at any time in iOS Settings → Privacy & Security → Health → Suppr.
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g. billing records may be retained for up to 7 years for tax compliance). Anonymised, aggregated analytics data from which you cannot reasonably be re-identified may be retained indefinitely.
For questions about this policy, data requests, or to exercise your rights, email us at privacy@suppr-club.com. We aim to respond within 14 days.