Privacy Policy — MealTracker
Privacy Policy
MealTracker — EMAAT ApS Effective date: 1 April 2026 Last updated: 1 April 2026
1. Introduction
MealTracker (“the App”) is developed and operated by EMAAT ApS (“we”, “us”, “our”), based in Denmark. We are committed to protecting your privacy and handling your data transparently. This policy explains what data we collect, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).
EMAAT ApS Lungstedløkken 1, 5250 Odense SV, Denmark CVR: 44934302 Email: [email protected]
2. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract — processing necessary to provide the service you signed up for (cloud sync, account management)
- Consent — where you actively choose to create an account and enable sync
- Legitimate interest — to maintain and improve the security and functionality of the App
3. Data We Collect
3.1 Data stored locally on your device
By default, all meal tracking data is stored only on your device. This includes:
- Meals and calorie entries
- Meal types and templates
- Calorie targets and settings
- Custom food items you create
No account is required to use MealTracker. If you never create an account, no personal data leaves your device.
3.2 Data collected when you create an account
If you choose to create an account to enable cloud sync, we collect:
- Email address — used for authentication and account recovery
- Meal data — meals, calorie entries, and associated nutrition information
- Settings and preferences — meal types, templates, calorie targets, sync preferences
- Authentication tokens — stored securely in your device’s Keychain
3.3 Data we do NOT collect
- We do not use analytics SDKs or ad trackers
- We do not collect device identifiers for advertising
- We do not track your location
- We do not access your camera, contacts, or photos
- We do not sell or share your data with third parties
4. How We Use Your Data
We use your data solely to provide and improve the MealTracker service:
- Authentication — to verify your identity and secure your account
- Cloud sync — to synchronise your meal data across your devices
- Service operation — to maintain and improve app functionality
5. Third-Party Data Sharing
We do not share your personal data with any third parties. No third-party SDKs, analytics tools, or advertising networks have access to your data.
6. Data Storage and Security
- Local data is stored in your device’s app sandbox
- Authentication tokens are stored in the iOS Keychain
- All network communication uses encrypted connections (HTTPS/TLS)
- Server data is stored on secure infrastructure within the European Union (Germany)
- We store only the minimum data necessary to provide the service
7. Data Transfers
Your data is processed and stored within the European Union. Server infrastructure is located in Germany. No data is transferred outside the EU/EEA. As both Denmark and Germany are EU member states, your data is protected by the same GDPR framework throughout.
8. Data Retention
- Local data is retained on your device until you delete the app
- Server data is retained for as long as your account is active
- When you delete your account, all associated server data is permanently deleted within 30 days
9. Third-Party Data Sources
MealTracker uses nutritional data from the following public databases, licensed under Creative Commons Attribution 4.0 International (CC-BY 4.0):
- Frida Food Database — National Food Institute, Technical University of Denmark (frida.fooddata.dk)
- Livsmedelsdatabasen — Livsmedelsverket, Swedish Food Agency (livsmedelsverket.se)
- USDA Nutrition Database — United States Department of Agriculture (public domain)
No personal data is shared with these sources.
10. Your Rights (GDPR)
As a data subject under GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Data portability — receive your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing of your data
- Withdraw consent — withdraw consent at any time without affecting prior lawful processing
To exercise any of these rights, contact us at [email protected].
11. Data Deletion
- Local data: remove the MealTracker app from your device
- Server data: use the “Delete Account” option in Settings, or contact us at [email protected]
12. Children’s Privacy
MealTracker is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
13. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of the App after changes constitutes acceptance.
14. Contact
For questions, concerns, or data requests:
EMAAT ApS Lungstedløkken 1, 5250 Odense SV, Denmark CVR: 44934302 Email: [email protected]
This privacy policy is available in English and Danish.