Snugmeal
Privacy Policy
What data the Snugmeal website and app collect, why, how long we keep it and what your rights are. No trackers, no selling of data.
In force from: 21 September 2026 (version 1)
This is the first version of the Privacy Policy. The App is not yet publicly available. Every subsequent version will have its own number, date and permanent address, and we do not alter a version once published. The Polish version is binding; this English text is a courtesy translation provided for convenience.
1. Who is responsible for your data
The controller of your personal data is Olivier Babula, the creator of Snugmeal — a natural person conducting unregistered business activity.
- Address: Kasperków 10A, 34-312 Międzybrodzie Bialskie, Poland.
- E-mail: contact@snugmeal.com.
- Telephone: 796 158 878.
We reply to messages usually within 1–2 business days. Write to the same address about your data — we do not run a separate mailbox.
We have not appointed a data protection officer. The obligation to appoint one arises where the controller's core activities consist of regular and systematic monitoring of data subjects on a large scale or of large-scale processing of special categories of data (Article 37(1)(b) and (c) GDPR). Snugmeal is run by one person and the scale of processing does not reach that threshold. We will repeat the assessment if the scale changes.
We are not joint controllers with anyone. Two companies act alongside Snugmeal as separate controllers, on their own terms: Google — when you sign in with a Google account, and Apple — when you sign in with an Apple account and when you buy a subscription in the App Store (section 7).
2. What this Policy covers and how to read it
The Policy describes three places where we may come into contact with your data: the Snugmeal app for iPhone, the snugmeal.com website (home page, blog, contact form, legal documents, account deletion page) and the e-mails you receive from us. We write „you" because it is your data; „we" is the controller in section 1. The Account is your record with us, the Profile is the data from which we calculate your requirements (section 5), and the Plan is the weekly set of meals with a shopping list, generated at your request.
We describe every processing operation in the same layout: what data, what for, on what legal basis, how long we keep it and to whom we pass it on. The legal bases are the provisions of the GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council.
What you must give us and what is optional. Creating an Account requires an e-mail address — without it the contract cannot be concluded and we cannot confirm that the account is yours — and consent to the processing of health-related data: without it an Account cannot be created (section 5). Generating Plans requires a subscription (section 7). Usage analytics and crash reports are entirely optional, and refusing them restricts nothing in the app (section 8).
The app does not ask you for any photographs and does not access your photo library. The images accompanying recipes are digitally generated, illustrative images — they do not depict any existing person, place or particular meal.
Versions. Each version of the Policy has a number, a date and a permanent address in the form snugmeal.com/polityka-prywatnosci/YYYY-MM-DD/ — version 1 at snugmeal.com/polityka-prywatnosci/2026-09-21/; the current version is also at snugmeal.com/polityka-prywatnosci. The rules for using the app are set out in the Terms: snugmeal.com/regulamin.
3. The snugmeal.com website
The website uses no cookies and no analytics tools. We store nothing on your device when you visit it and we do not track traffic — there is not a single analytics or advertising tool in the website's code. That is why we do not ask you for the consent referred to in Article 399(1)(2) of the Electronic Communications Law (Prawo komunikacji elektronicznej): there is nothing to store and nothing to access.
Contact form. We receive the e-mail address you provide, the subject, the content of the message and a marker of whether it came from the website or from the app. The message goes straight to our mailbox — we do not save it in any database. The basis is our legitimate interest, namely answering the question asked (Article 6(1)(f) GDPR); if you write about your contract — performance of that contract (Article 6(1)(b) GDPR). The same form in the app sends the message by the same route.
Server logs. The software of the server hosting the website may record technical access logs — usually the IP address, the time of the request, the address of the page visited and information about the browser. This serves the security and correct operation of the website, and the basis is our legitimate interest (Article 6(1)(f) GDPR). Logs live for 14 days — that is the default log rotation of the system distribution we use (as at 20 September 2026).
The blog consists of text files uploaded with the website: there are no accounts, comments or forms there. At snugmeal.com/delete-account we describe how to delete an account from the app and the e-mail route for people who no longer have access to it (section 12). The website works only over an encrypted connection.
4. The Account in the app
What data. With the Account we keep: the identifier, the e-mail address, the name, information on whether the address has been confirmed, the identifier from the login system and the dates of creation and last change. The name comes from what the login system provides and, failing that, from the part of the address before the „@" sign. We do not collect a profile picture.
What for and on what basis. The Account is needed in order to provide the Service: so that the Plan, the consents and the subscription status are available after a reinstallation and on another device. The basis is performance of the contract (Article 6(1)(b) GDPR).
Where your identity lives. Checking who you are is handled by Firebase Authentication — a Google service. Our data (Account, Profile, Plans, consents) sit in our database, linked by the identifier from Firebase. When registering with an e-mail address you set the password in the Firebase window — our code never sees it and never stores it; Google keeps it. When signing in with a Google or Apple account the app receives an identity token from the provider; Apple passes the first name only on the first authorisation and we save it as the Account name.
Confirming the address. Without a confirmed address the server does not let the Account into the app. Confirmation is by a link from the e-mail or by a six-digit code; we keep only a hash of the code in the database, not the code itself, and the code lives for 30 minutes. Resetting the password works the same way. Firebase generates the links, but we send the e-mails (section 10).
What you confirm when creating an Account. Three separate boxes, never pre-ticked: acceptance of the Terms together with confirmation of having read this Policy, consent to the processing of health-related data (section 5) and separate acceptance of the characteristics of the Service described in the Terms. Without all three the form cannot be submitted; the record of these declarations is described in section 11. After the contract is concluded you receive an e-mail confirming it (section 10).
How long and to whom we pass it on. We keep the Account data until it is deleted (section 12). We pass it to Google (Firebase Authentication) and Resend (e-mail delivery) — section 14.
5. The Profile — health-related data
What data. In the Profile we collect: the goal (weight loss, maintenance, muscle building, mass), sex, age, height, weight, starting and target weight, the pace of weight change, activity level, the number of meals per day, the weekly budget, kitchen equipment, the chosen stores, the way of eating, allergens and lactose intolerance, products you dislike, cooking time, the level of variety, the number of favourite dishes per week, the first day of the week, units and the app language. The country is permanently set to Poland.
This is health-related data. Weight, height, age, weight goal, allergens and intolerances reveal information about your state of health, and the GDPR calls such data data concerning health (Article 4(15)). We treat it as a special category of data, with higher requirements.
What for. To calculate your daily energy and nutrient requirements and to compose a menu and a shopping list from them (section 6).
Legal basis. Your explicit consent — Article 9(2)(a) GDPR. The processing itself serves performance of the contract for the Service (Article 6(1)(b) GDPR). You give the consent by ticking a separate box when creating the Account, and you see exactly this text next to it:
„Wyrażam zgodę na przetwarzanie moich danych dotyczących zdrowia (waga, wzrost, cel, alergie, dieta) w celu generowania spersonalizowanych planów posiłków. Zgodę mogę wycofać w każdej chwili w ustawieniach." (I consent to processing my health-related data (weight, height, goal, allergies, diet) to generate personalised meal plans. I can withdraw this consent at any time in settings.)
We record the same wording in the consent register together with its version (section 11), so the evidence under Article 7(1) GDPR relates to the text you actually saw. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal (Article 7(3) GDPR).
Is consent a condition of the contract. Yes — and we say so expressly, because Article 13(2)(e) GDPR requires it: without this consent an Account cannot be created. The Profile data are necessary to perform the contract, the subject of which is calculating your requirements and composing a menu; without them there is nothing to calculate. Consent to analytics (section 8) is entirely independent of this.
How you withdraw consent and what follows. If you have access to the app's screens, you withdraw it with a single toggle in the „Me" tab → Consents, without contacting us — as easily as you gave it. If you are held at the offer screen, you withdraw it by writing one sentence to contact@snugmeal.com; we carry out such a request free of charge and without asking for a reason, within one month at the latest. Without active consent the app will not compose a new Plan, recalculate an existing one, replace a meal or adjust the Plan to changes in the Profile; the Plan you already have remains visible, and you can switch the consent back on.
What we do not do with this data. We do not use the Profile data for advertising or marketing profiling and do not share it for that purpose. We do not sell it.
How long. Until the Account is deleted (section 12). Withdrawing consent does not delete the Profile — we stop using it to compose and recalculate the Plan, but the data remain so that you do not have to fill everything in again after switching the consent back on. If you want it gone sooner, delete the Account or write to us (section 17).
To whom we pass it on. The Profile goes to our planning engine (section 6). It does not go to the error reporting system: the engine has request body transmission disabled, so even in the event of a failure your Profile does not go there (section 9).
6. How a Plan is created and what we record alongside it
A Plan is created only at your request. We send the planning engine the Profile data needed for the calculation: weight, height, age, sex, activity, goal, pace, budget, number of meals, kitchen equipment, allergens, products you dislike, and the way of eating. We do not send your e-mail address or the Account name. The engine is an ordinary computational program — there is no language model in it — and the price list it uses to price the list is collected from store websites and contains none of your data.
Is this profiling and does it decide about you. Yes, selecting dishes to fit your data is profiling within the meaning of Article 4(4) GDPR. It is not, however, a decision that produces legal effects concerning you or similarly significantly affects you — the Plan is a proposal of what to cook and what to buy: it neither grants nor withdraws any entitlement, does not assess you and closes no door to you. You decide what to eat and what to buy; you can generate the Plan again, replace a single dish or ignore it entirely. Regardless of whether the law requires it of us, we give you three things: write to contact@snugmeal.com and a human will explain it to you, we will hear your point of view and we will check the Plan manually.
What we record alongside the Plan. The basis here is performance of the contract (Article 6(1)(b) GDPR) and, where the data reveal information about your health (a Plan calculated from the Profile, the weight journal), additionally your explicit consent (Article 9(2)(a) GDPR) from section 5. We keep the data until the Account is deleted (section 12) and pass it to no one other than the hosting providers in section 14. We record: the week's Plan together with a snapshot of the Profile from the moment of generation and frozen prices, the states of the shopping list, meal check-offs, dish ratings (one person has one vote; ratings are an internal signal and other people's ratings are not visible) and favourite dishes.
The weight journal takes one measurement per day, which can be corrected and deleted. The measurements are health-related data — we process them on the basis of the consent in section 5. After the consent is withdrawn we stop keeping the journal; the measurements recorded remain until the Account is deleted.
Staying only on your device are: the „was not in the store" state of the list and the app inbox entries, which live for 30 days (section 13).
7. Subscription
You conclude the subscription contract with us — the controller in section 1. You buy the subscription in the App Store: Apple sells it in its own name but for our account, accepts payment and handles the entire settlement. With regard to your payment data Apple acts as a separate controller. We do not receive and do not store card numbers or any payment data. You address withdrawal from the contract, complaints and refund requests to us, at contact@snugmeal.com — the rules are set out in the Terms, in the chapters „Right of withdrawal from the Agreement" and „Conformity of the Service with the Agreement and complaints".
What RevenueCat does. RevenueCat manages the subscription status for us. We pass it the identifier of your Account in our system — not your e-mail address or name. On our side we record one thing: until when your access is active, including the grace period. We lowered the log level of the RevenueCat library, because the default setting printed the account identifier to the device logs also in the store build.
What for, on what basis and for how long. So that we know whether you may use the paid features; the basis is performance of the contract (Article 6(1)(b) GDPR). We keep the access expiry date until the Account is deleted. Deleting the Account does not cancel the subscription — Apple will continue to charge until you cancel it in the Apple settings; the app warns about this before deletion (section 12).
To whom we pass it on. RevenueCat (processor) and Apple (separate controller) — section 14.
8. Usage analytics and crash reports — only with your consent
By default we collect nothing. Data collection by Firebase Analytics and Crashlytics is disabled natively, in the app's configuration, so nothing goes to Google before the app even starts. The only thing that switches it on is your consent — one toggle for both, in the „Me" tab → Consents, reading: „Zgadzam się na analitykę użycia aplikacji w celu ulepszania SnugMeal." (I agree to app usage analytics to help improve SnugMeal.)
What we collect once you switch the consent on. Named events sent by our code — onboarding steps, registration and sign-in, address confirmation, a failed Plan generation, the subscription screen being shown and dismissed, a successful, failed and restored purchase, and Account deletion — plus events that the Google library collects on its own (first launch, session start, screen view, app update and engagement time). Along with them Google receives the app installation identifier, technical device data and the IP address; for traffic from the European Economic Area, Switzerland and the United Kingdom Google discards the IP address before the data are logged and does not store it (Google documentation, as at 20 September 2026). We do not pass your e-mail address or Account identifier in these reports — our code sets no user identifier in them, and we do not link the installation identifier to the Account. Crash reports contain the error trace, technical information about the device and the same installation identifier.
Legal basis. Your consent — Article 6(1)(a) GDPR.
Withdrawal. The same toggle — or, if you are held at the offer screen, one sentence to contact@snugmeal.com (section 5). Switching it off stops collection immediately, and in the event of any uncertainty — a network error, session expiry, consent withdrawn on another device — the app switches collection off rather than leaving the state from the previous session. Refusal blocks nothing: consent to analytics does not condition access to the paid features or to any other part of the Service (Article 7(4) GDPR).
How long. Analytics events — no longer than 14 months; that is the longest setting available in the free tier of the service according to Google's documentation (as at 20 September 2026). Crash reports — 90 days from the report; after that time Google begins deleting them from its production and backup systems (as at 20 September 2026).
To whom we pass it on. Google (Firebase Analytics, Crashlytics) — section 14.
9. Remote configuration and server error reporting
Remote configuration. The app downloads a small settings bundle from Google's servers (Firebase Remote Config): the emergency switch, which in the event of a serious error replaces the whole app with an information screen, the subscription screen toggle and the news shown in the app inbox. The configuration refreshes roughly once an hour, and a download error does not block the app. In the configuration request we send no data from your Account or Profile. Google does, however, receive the app installation identifier, which the Firebase library assigns to your copy of the app; it serves to deliver the settings to that particular installation, contains none of your data and is not linked by us to the Account. The identifier lives at Google until we request its deletion, and is also stored on your phone (section 13).
What the „news" is. Short information about changes in the app. We place no advertising or purchase prompts in it. If we ever wanted to send you commercial content, we would first ask for separate consent — Article 398(1) of the Electronic Communications Law requires it — and we would clearly label such a message.
Server error reporting. Errors of our application server and of the planning engine go to the Sentry tool. There is no Sentry in the phone app at all. The collection of personal data is disabled by default in the settings and we do not enable it; performance tracing is set to zero; the planning engine has request body transmission disabled, so your Profile never reaches Sentry. What goes into a report is the error message, the place in the code and the technical context of the request. Reports live for no longer than 90 days according to the provider's documentation (as at 20 September 2026). Our project runs in the European Union region (Frankfurt, Germany).
Legal basis. For both, our legitimate interest (Article 6(1)(f) GDPR): the secure operation of the app and the ability to stop it in the event of a serious failure, and the detection and removal of failures so that the Service works.
To whom we pass it on. Google (Firebase Remote Config) and Sentry — section 14.
10. E-mails and notifications
What e-mails we send. Only those without which the contract would not work: the welcome message with an activation link and code, confirmation of conclusion of the contract (for accounts created with a Google or Apple account — in a separate message), a link to set a new password and a reply to a message from the contact form. The basis is performance of the contract (Article 6(1)(b) GDPR) and, for confirmation of conclusion of the contract, additionally our legal obligation (Article 6(1)(c) GDPR) — confirmation on a durable medium is required by Article 21(1) of the Consumer Rights Act.
We do not send marketing e-mails. The app has no place where you could sign up for them. If we ever started, we would first ask for consent — Article 398(1) of the Electronic Communications Law requires it. Nor do we track whether you open our mail: there are no tracking pixels in the content, and the links lead directly to the addresses indicated.
Who sends them. Delivery is handled by Resend and, when it is unavailable, by the mail server of our hosting provider. The sender is support@snugmeal.com and the reply address is contact@snugmeal.com, because a reply is sometimes a declaration of withdrawal from the contract or a complaint. We record e-mail addresses in the server logs in masked form and do not log the delivery provider's responses in full. At the delivery provider the content of messages and delivery logs live for 30 days according to its documentation (as at 20 September 2026). We keep correspondence in our mailbox for as long as is needed to settle the matter and to show that it was settled.
Notifications are purely local. Your phone schedules them, from the Plan it already has. Our server sends no push notifications, and the app neither collects nor passes to us any notification tokens. The types are: „Today's plan" every morning, „New week" on Sunday afternoon, and a reminder about the Sunday weigh-in. The content of a notification is created on your device and is not sent anywhere. You give the system permission for notifications to your iPhone, not to us, and you can revoke it in the phone settings; your settings for the individual notifications remain only on the device (section 13). The basis is performance of the contract (Article 6(1)(b) GDPR).
To whom we pass it on. Resend — section 14.
11. The record of consents and Account events
Consent register. Every declaration you make — giving and withdrawing consent — is recorded as a separate entry: the type of consent, whether it was given, the version of the text you saw, and the time. The app's code never changes or deletes these entries; the current state is simply the latest entry. This enables us to show what you consented to and in what wording — Article 7(1) GDPR requires it. A change in the wording of a consent means a new version and collecting it again. What we actually record: health-related data and analytics (the toggles in settings) and acceptance of the Terms, confirmation of having read the Policy and separate acceptance of the characteristics of the Service (stamped when the Account is created).
Event log. Separately we keep a short log: the Account identifier, the name of the event and the time — nothing more. We record three events: a change of consent, a data export and deletion of the Account. We do not record tokens, codes, IP addresses or request bodies there.
Legal basis. Accountability towards you and towards the supervisory authority — our legal obligation (Article 6(1)(c) GDPR) and our legitimate interest in showing that we have fulfilled our obligations and in detecting abuse (Article 6(1)(f) GDPR). The burden of proving that the information obligations referred to in Article 12 of the Consumer Rights Act have been fulfilled rests on the trader — Article 24 of that Act.
How long. The consent register — until the Account is deleted. An entry in the event log survives deletion of the Account, but then loses its link to a person: the field with the Account identifier is cleared and only the name of the event and the time remain. There is then nothing in it that would allow a person to be identified, so such an entry ceases to be your personal data and data protection law no longer applies to it (recital 26 GDPR). We keep it as evidence that the deletion took place and for detecting abuse.
12. Downloading your data and deleting the Account
Downloading your data. In the „Me" tab there is an item „Download my data". You receive a JSON file — a machine-readable format — with the Account, the Profile, Plans, consents, favourites, meal check-offs, ratings, weight measurements and shopping list states. The export is free of charge and can be performed once an hour; each one leaves an entry in the event log (section 11). The basis is your right to data portability (Article 20 GDPR).
What is not in the file. Three things we also keep about you: the access expiry date from the subscription, the counters of generated Plans and the entries in the Account event log. If you want a copy of that data too — and you have a right to it (Article 15(3) GDPR) — write to contact@snugmeal.com and we will send it free of charge, within one month at the latest. By the same route you will receive the whole file if you are held at the offer screen. Separately: after withdrawal from the contract we make available to you on request, in a machine-readable format, the content you created other than personal data — Article 43o(2) of the Consumer Rights Act requires this.
Deleting the Account. You delete the Account in the app: the „Me" tab, the „Delete account" item. If you no longer have access to the app, the e-mail route is described at snugmeal.com/delete-account. An account with a password asks for the password again, a Google or Apple account for re-authorisation with the same provider, so that nobody deletes your Account from someone else's phone. If you have an active, renewing subscription, the app will first warn that deleting the Account does not cancel it and that Apple will continue to charge; the warning is not a block, and if checking the subscription status fails, the deletion proceeds anyway — your right to erasure cannot depend on the availability of the billing provider.
What disappears. Along with your row in our database the following disappear: the Profile, subscription status, Plans, consents, shopping list check-offs, favourites, dish ratings, generation counters, meal check-offs and weight measurements; we delete the Firebase account first. What remains is an entry in the event log, stripped of its link to a person (section 11). Deletion at our end is permanent and irreversible — download your data beforehand.
What remains at the providers. Apple — the record of your purchase and subscription, on Apple's terms (section 7). RevenueCat — a subscriber record with the identifier of the deleted Account; we apply for its deletion at your request. Sentry — error reports from our server, no longer than 90 days (section 9). The mail delivery provider — message content and delivery logs, 30 days (section 10). Google — analytics data and crash reports, if you had the consent switched on (section 8), and the installation identifier on the terms in section 9.
Legal basis. Your right to erasure (Article 17 GDPR) and performance of the contract (Article 6(1)(b) GDPR). Account deletion in the app is also an Apple requirement for every app that allows accounts to be created.
13. Data on your device
Some things stay on the phone and never reach us:
- The login token is held by the Firebase library. Our code fetches a fresh token with every request and does not store it itself.
- The notification inbox — entries from the last 30 days.
- Notification settings — which of the three reminders are switched on.
- The setting of consent to analytics and crash reports is stored natively and survives an app restart; that is why, in the event of any uncertainty, the app explicitly switches it off (section 8).
- The app installation identifier — assigned by the Firebase library on first launch. It serves to download the settings bundle, including the emergency switch (section 9). It contains none of your data and is not linked by us to the Account. You delete it by uninstalling the app.
The Plan and the shopping list are held in memory and fetched from the server; onboarding data are not written to disk until you create an Account.
Why we do not ask for consent to most of this. Storing this information is necessary to deliver the service you request — so provides Article 399(3)(2) of the Electronic Communications Law. The exception is analytics and crash reports: there we ask for consent, say what it is for and show a toggle with which you can change your mind — Article 399(1) of the Electronic Communications Law requires that. What exactly survives uninstalling the app depends on the behaviour of iOS; if you want to be sure the session has ended, sign out before uninstalling.
14. To whom we pass data on and transfers outside the EEA
We do not sell your data and do not share it for advertising purposes. Apart from the entities listed below, data may go only to public authorities where the obligation arises from a provision of law.
- Google — Firebase Authentication. Processor. E-mail address, password (which you set with them and which we do not see), Account identifiers and login tokens. Section 4.
- Google — Firebase Analytics and Crashlytics. Processor. Named events and technical information about the device — only if you switch the consent on. Section 8.
- Google — Firebase Remote Config. Processor. Downloading the settings bundle; without data from the Account or Profile. Section 9.
- RevenueCat. Processor established in the United States. The identifier of your Account and the subscription status. Section 7.
- Apple. Separate controller. Purchase and settlement of the subscription in the App Store and signing in with an Apple account — on Apple's terms. Section 7.
- Resend. Processor established in the United States. The recipient's address and the content of the e-mail sent. Section 10.
- Sentry. Processor established in the United States. Error messages from our server and planning engine, without request bodies. The project runs in the European Union region (Frankfurt, Germany). Section 9.
- Railway. Processor established in the United States. Hosting of the application server, the planning engine and the database, in the Western Europe region (Amsterdam, the Netherlands).
- OVH. Processor. The server in Warsaw hosting the snugmeal.com website, the images of dishes and the instance handling the contact form.
Processing agreements. With every processor on this list the processing takes place on the basis of a data processing agreement (Article 28 GDPR). Every entity listed in this section — whether as a processor bound by such an agreement or as a separate controller (Apple) acting on its own terms — affords your data protection at least equivalent to that described in this Policy. No processing agreement is concluded with a separate controller, so the paragraph on standard clauses does not apply to Apple or to Google when you sign in with a Google account.
Where your data are. The database with the Account, Profile and Plans sits on Railway in Amsterdam, the website and the images of dishes on the OVH server in Warsaw, and error reports in the Sentry project in Frankfurt — all within the European Economic Area.
Transfers outside the European Economic Area. Google, RevenueCat, Resend, Sentry and Railway are United States companies. Data passed to Google, RevenueCat and Resend go to their infrastructure; in the case of Sentry and Railway the data sit in the Union, but the provider's personnel may have access to them from outside the European Economic Area. In both cases the basis is the standard data protection clauses adopted by the European Commission (Article 46(2)(c) GDPR), forming part of the processing agreement concluded with the provider; where a provider appears on the list maintained under the EU-U.S. Data Privacy Framework, the transfer is additionally covered by Commission Implementing Decision (EU) 2023/1795 finding an adequate level of protection. Write to contact@snugmeal.com and we will tell you which mechanism we apply to which provider, and send you a copy of the clauses.
15. How long we keep data
- Account, Profile, Plans, shopping lists, favourites, ratings, meal check-offs, weight measurements, generation counters, subscription status and the consent register — until the Account is deleted (section 12). Withdrawing consent to health-related data does not delete the Profile (section 5).
- The code confirming the e-mail address — 30 minutes, and only as a hash (section 4).
- The Account event log — until the Account is deleted. After deletion the entries lose their link to a person and cease to be personal data (recital 26 GDPR); in that form we keep them as evidence that we performed our obligations and for detecting abuse (section 11).
- The notification inbox on the device — 30 days; the remaining data on the device — until the app is uninstalled (section 13).
- Correspondence from the contact form and the help screen — for as long as is needed to settle the matter and to show that it was settled; complaint and disputed matters until the limitation period for claims expires (section 3).
- Analytics events — no longer than 14 months; crash reports — 90 days, after which Google begins deleting them. Both periods according to Google's documentation, as at 20 September 2026 (section 8).
- Error reports in Sentry — no longer than 90 days according to the provider's documentation, as at 20 September 2026 (section 9).
- Messages at the mail delivery provider — 30 days according to its documentation, as at 20 September 2026 (section 10).
- Website server logs — 14 days, in line with the default log rotation of the system distribution used, as at 20 September 2026 (section 3).
- The app installation identifier at Google — until we request its deletion; it then disappears from the provider's systems within 180 days, according to Google's documentation, as at 20 September 2026 (section 9).
16. Security
We select measures appropriate to the risk (Article 32 GDPR). Specifically:
- Connections to the website, the application server and the providers are encrypted; the website enforces an encrypted connection and has headers restricting its embedding in other sites.
- Your password is not held by us — Firebase keeps it. We keep confirmation codes as hashes, not as codes, and e-mail addresses in the server logs in masked form.
- We check the login token with every request together with information on whether it has been revoked; a refusal of access immediately signs the app out.
- The number of requests per minute is limited, and the most sensitive operations — sending the activation link, confirming by code, password reset, recording consent and downloading data — have their own, stricter limits. The server's response is always the same regardless of whether an account with a given address exists, so that other people's addresses cannot be checked this way.
- The application server restricts which sites may address it from a browser, and which request methods may be used.
- Only the administrator indicated in section 1 logs in to the database; there are no other user accounts. Technical access to the infrastructure is, in the nature of things, also held by the hosting providers listed in section 14 — they are bound by a processing agreement and by an obligation of confidentiality.
What we do not promise. Transmitting data over the internet is never free of risk. The weakest link is often the device and the mailbox: take care of your screen lock and an up-to-date system, use a unique password and do not give it to anyone. We do not ask for passwords in e-mails — a message that does is not from us.
17. Your rights
In relation to your data you have the right to:
- access and to obtain a copy (Article 15 GDPR) — fastest through „Download my data" (section 12),
- rectification of incorrect data (Article 16 GDPR) — you correct the Profile in the app,
- erasure (Article 17 GDPR) — „Delete account" in the app or by e-mail (section 12),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR) — the JSON file from section 12,
- object to processing based on our legitimate interest (Article 21(1) GDPR) — this concerns the website's server logs (section 3), remote configuration and server error reporting (section 9) and the Account event log in the part serving the detection of abuse (section 11). It does not cover the consent register: we keep it because the law requires it (Article 6(1)(c) GDPR),
- withdraw consent at any time (Article 7(3) GDPR) — with the toggles in the „Me" tab, and from behind the offer screen by one e-mail (section 5). Withdrawal does not affect the lawfulness of processing that took place earlier.
How to exercise them. Some rights you exercise yourself in the app — that is the fastest route. Otherwise write to contact@snugmeal.com. We reply without undue delay, within one month of receiving the request at the latest; if the matter is complex or there are many requests, we may extend that period by at most two further months — we will tell you within the first month and give the reason (Article 12(3) GDPR). We do all of this free of charge (Article 12(5) GDPR), with one exception provided for by that very provision: if your requests were manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee corresponding to the administrative costs or refuse to act — demonstrating that a request is of that character is for us. If we conclude that we cannot do what you ask, we will tell you within one month, explain why and remind you of your right to lodge a complaint and to go to court (Article 12(4) GDPR). We may ask for additional information if we are unable to establish that the request comes from you.
Complaint to the supervisory authority. If you consider that we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77(1) GDPR). In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warszawa (uodo.gov.pl).
18. Age, changes to the Policy and contact
Snugmeal is for adults. The app asks for your age during onboarding and does not let you proceed below 18, and the server rejects a Profile with an age below that threshold. We check age on the basis of what you state yourself: we do not require a document. We knowingly do not collect data of persons under 18. A contract concluded by a person who has not reached the age of 13 is invalid by operation of law (Article 12 in conjunction with Article 14 § 1 of the Civil Code), unless it is one of the contracts commonly concluded in minor everyday matters and has been performed (Article 14 § 2); a contract concluded by a person between 13 and 18 without the consent of a legal representative requires that representative's confirmation (Articles 15, 17 and 18 § 1 of the Civil Code). If we learn that an Account was created by a person between 13 and 18, we set that person's legal representative a time limit to confirm the contract and only after it has expired without effect or after a refusal do we delete the Account together with the data; we delete the Account of a person under 13 immediately. The procedure and the refund of fees are set out in the Terms, chapter „The Account and conclusion of the Agreement".
Changes to the Policy. The Policy is not a contractual template — you do not conclude it with us and you do not have to accept it; it is the performance of our information obligation, so we change it when what we actually do with data changes. We do not alter a version once published: new content means a new date and a new version number, and the previous one remains at its permanent address. We will give notice of a change that matters for your data in the app or by e-mail before it takes effect. If a change were to require new consent, we will ask for it separately — we do not infer consent from silence.
Contact. In any matter concerning personal data, and also in matters concerning the Service:
- E-mail: contact@snugmeal.com
- Address: Olivier Babula, Kasperków 10A, 34-312 Międzybrodzie Bialskie, Poland
- Telephone: 796 158 878
We reply usually within 1–2 business days; to requests concerning your rights — within one month at the latest (section 17). In the app you will find the same contact under „Help and contact" in the „Me" tab. The rules for using the app are set out in the Terms — in particular the chapters „Characteristics of the Service and their separate acceptance" and „Personal data, disputes and final provisions", which refers to this Policy.