WePlate Privacy Policy
October 7, 2026
Draft: this text has not yet been reviewed by a lawyer.
Who we are
This policy explains how WePlate handles your information. WePlate is provided by Emanuele Picciolo, Via Ugo Foscolo 4, 73040 Neviano (LE), Italy (“we”, “us”).
For people in the European Union and the United Kingdom, Emanuele Picciolo is the data controller. [EU REPRESENTATIVE, IF REQUIRED] [UK REPRESENTATIVE, IF REQUIRED] [DATA PROTECTION OFFICER, IF REQUIRED]
Contact: support@weplate.app.
The short version
• WePlate plans meals and shopping lists for your household. It can estimate calories, macros and portions for each person.
• You can use it without giving us your email. An anonymous account is created when you first open the app.
• We use health data only if you give separate, explicit consent. You can withdraw it at any time in the app.
• We do not sell your data. We do not use advertising SDKs. We do not track you across other companies’ apps or websites.
• Health data is never sent to analytics, crash reporting or AI services.
• You can download or delete your data in Settings > Account and data.
Information we collect
Account
• An account ID, created automatically and anonymously the first time you open the app.
• Your email address, only if you choose to save your account. We use it to send you a 6-digit sign-in code.
Household settings
• Country, and ZIP code or postcode if you enter it.
• Your chosen supermarket chain, budget, kitchen equipment and cooking days.
• Cuisines and foods you like, allergies, intolerances, diets and ingredients you want to exclude.
• Names of household members, as you type them.
What you create in the app
• Meal plans, shopping lists and pantry items.
• Favorites, ratings and notes.
• Food diary (premium feature): foods and grams eaten, and custom targets if you set them.
Health data (only with your explicit consent)
• Sex, birth month and year, height, weight, activity level and goal.
• The result of an eating-disorder screening. We do not store your answer. We store only whether calorie numbers are turned off.
• Which version of the pregnancy and breastfeeding statement you accepted. We do not store your answer.
• Numbers calculated from this data, such as calorie and macro targets and portions.
Health data and your consent
We ask for health data only to estimate calories, macros and portions. We ask for your consent on a separate screen. You can say no.
Before your plan is created, the health data you enter is stored encrypted on your phone. When the plan is created, it is stored on our servers (see “Where your data is stored and who helps us”).
Calories are calculated by our code from USDA FoodData Central data. They are never calculated by AI.
If the eating-disorder screening suggests that calorie numbers may not help you, we turn them off. We store only that the numbers are off, not your answer.
You can withdraw consent at any time in Settings > Account and data. This deletes the health data you entered and all numbers calculated from it.
Other people in your household
You can add other people to your household.
• Adults: you may enter health data for another adult only with their permission.
• Children: for children we store only an age band. We never show calorie numbers for children.
• People under 18 never see calorie numbers.
• Names are stored as you type them. You can use a nickname.
Household members with their own account can see the household’s shared information, such as meal plans and shopping lists. [CONFIRM EXACTLY WHAT EACH MEMBER CAN SEE]
How we use your information
• To create and run your account, and to sign you in.
• To plan meals and shopping lists that fit your household’s settings, budget and equipment.
• To take allergies, intolerances, diets and excluded ingredients into account when suggesting meals.
• With your consent, to estimate calories, macros and portions for each person.
• To find supermarkets near the ZIP code or postcode you enter.
• To keep your food diary, if you use it.
• To provide subscriptions, when available.
• To keep the service secure and fix problems.
• To answer your requests.
We do not use your data for advertising.
Legal bases (EU and UK)
If you are in the EU or the UK, we rely on these legal bases:
• Contract: to provide the service you asked for (account, household settings, meal plans, shopping lists, food diary).
• Explicit consent (Article 9(2)(a) GDPR and UK GDPR): for health data. You can withdraw consent at any time. Withdrawal does not affect processing that happened before.
• Allergies, intolerances and diets may reveal information about health. [CONFIRM LEGAL BASIS FOR ALLERGIES, INTOLERANCES AND DIETS]
• Legitimate interests: to keep the service secure and prevent misuse. [CONFIRM]
• Legal obligation: when the law requires us to keep or disclose information.
Where your data is stored and who helps us
We use these service providers. They process data on our behalf to provide their service. [CONFIRM DATA PROCESSING AGREEMENTS]
• Supabase: database, sign-in and file storage, including recipe photos. Servers in the European Union (Frankfurt, Germany).
• Resend: sends the emails with your sign-in codes. It receives your email address and the code.
• Apple App Store, Google Play and RevenueCat: will handle subscriptions, when available. [CONFIRM DATA SHARED WITH REVENUECAT]
• [LIST ANY OTHER PROVIDERS, E.G. ANALYTICS OR CRASH REPORTING, IF USED]
We may also disclose information when the law requires it. [CONFIRM BUSINESS TRANSFER WORDING]
Nearby supermarket search
To find supermarkets near you, your phone sends the ZIP code or postcode you typed directly to services based on OpenStreetMap: the Photon geocoder run by Komoot, and the Overpass API.
Like any web service, they also receive your IP address. Their own privacy policies apply. [LINKS TO PROVIDER POLICIES]
We do not use your phone’s location or GPS. No health data is sent to these services.
What we do not do
• We do not sell your data.
• We do not use advertising SDKs.
• We do not use attribution or tracking tools, and we do not track you across other companies’ apps or websites.
• We never send health data to analytics, crash reporting or AI services.
• We do not use AI to calculate calories.
International transfers
Our servers are in the European Union (Frankfurt, Germany).
If you live in the EU or the UK, your data stays in the EU. [CONFIRM UK ADEQUACY REGULATIONS COVER THE EU/EEA]
If you live in the United States, your data is transferred from the United States to the EU and stored there. [CONFIRM ANY US-TO-EU TRANSFER MECHANISM OR NOTICE REQUIRED]
If a service provider processes data outside the EU, we rely on [APPROPRIATE SAFEGUARDS, E.G. EU STANDARD CONTRACTUAL CLAUSES, UK INTERNATIONAL DATA TRANSFER ADDENDUM, OR THE PROVIDER’S EU-US DATA PRIVACY FRAMEWORK CERTIFICATION].
You can ask for a copy of these safeguards at support@weplate.app.
How long we keep your data
• We keep your data while you have an account.
• If you delete your account, we delete your account and your data. [CONFIRM DELETION TIMING] [BACKUP RETENTION PERIOD]
• Anonymous accounts that never set up a household are deleted after 30 days.
• If you withdraw health-data consent, we delete the health data you entered and all numbers calculated from it.
• We may keep some information longer when the law requires it. [SPECIFY, E.G. SUBSCRIPTION RECORDS]
Your rights and controls
In the app, go to Settings > Account and data. There you can:
• Download my data: get a copy of your data as a JSON file.
• Withdraw health-data consent: delete the health data you entered and all numbers calculated from it.
• Delete account: delete your account and your data. If you own a household, it passes to another adult member who has an account. If there is none, the household is deleted.
Depending on where you live, you may also have the right to access, correct, delete or move your data, to restrict or object to processing, and to withdraw consent. To use these rights, write to support@weplate.app. We will answer within the time the law requires.
If you are in the EU or the UK, you can complain to a data protection supervisory authority, for example the Garante per la protezione dei dati personali (Italy), the Agencia Española de Protección de Datos (Spain), the Information Commissioner’s Office (UK), or the authority where you live or work. [LEAD SUPERVISORY AUTHORITY, IF ANY]
Consumer health data (Washington and other US states)
This section is our Consumer Health Data Privacy Policy under Washington’s My Health My Data Act and similar US state laws. [CONFIRM APPLICABLE STATES]
Categories we collect
• Sex, birth month and year, height, weight, activity level and goal.
• Whether calorie numbers are turned off after an eating-disorder screening (not your answer).
• Which version of the pregnancy and breastfeeding statement you accepted (not your answer).
• Calorie, macro and portion numbers calculated from this data.
• Allergies, intolerances, diets and excluded ingredients.
• Food diary entries: foods, grams eaten and custom targets.
• Age bands of children in your household.
Why we collect it
• To estimate calories, macros and portions for each person.
• To suggest meals that fit allergies, intolerances and diets.
• To keep your food diary.
Sources
• You, when you enter it in the app.
• Another adult in your household who enters it with your permission.
• Our own calculations, using USDA FoodData Central data.
Who we share it with
• Supabase, which stores it for us (database, sign-in and file storage, Frankfurt, Germany, European Union).
• Members of your household, as described in “Other people in your household”. [CONFIRM]
We do not sell consumer health data. We do not share it with advertisers, analytics, crash reporting or AI services.
Your rights
• To confirm whether we collect, share or sell your consumer health data, and to access it.
• To get a list of the third parties and affiliates we share it with, and how to contact them.
• To withdraw consent.
• To have it deleted.
How to use your rights
• In the app: Settings > Account and data (download my data, withdraw health-data consent, delete account).
• By email: support@weplate.app.
We will answer within 45 days. [CONFIRM] If we refuse your request, you can appeal by writing to support@weplate.app. [APPEAL PROCESS] If your appeal is refused, you can contact the Washington State Attorney General. [CONFIRM]
Children
WePlate is not for children under 13. We do not knowingly allow children under 13 to create an account. If you think a child under 13 has an account, contact us at support@weplate.app and we will delete it.
People under 18 never see calorie numbers.
Adults can add children to their household. For children we store only an age band, and we never show calorie numbers for them.
[MINIMUM AGE AND PARENTAL CONSENT IN THE EU/UK — CONFIRM; THE AGE OF DIGITAL CONSENT VARIES BY COUNTRY]
Security
Health data is stored encrypted on your phone until your plan is created.
[DESCRIBE SERVER-SIDE SECURITY MEASURES, E.G. ENCRYPTION IN TRANSIT AND AT REST, ACCESS CONTROLS]
No system is completely secure. If we learn of a breach that affects you, we will tell you as the law requires.
Changes to this policy
We may update this policy. We will change the date at the top.
If a change is important, we will tell you in the app. [CONFIRM HOW USERS ARE NOTIFIED]
If a change affects how we use health data, we will ask for your consent again when the law requires it.
Contact
Emanuele Picciolo
Via Ugo Foscolo 4, 73040 Neviano (LE), Italy
VAT no. IT05278500755
Email: support@weplate.app