Privacy Policy

Fitness Media Company Pty Ltd

Last Updated: May 9, 2026

We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how Fitness Media Company Pty Ltd (“Company”, “we”, “us”), operating the Meal Engine platform (“Platform”), collects, uses, discloses, and protects your information when you use our meal planning services, including our website (mealengine.com), iOS app, and Android app.


1. Information We Collect

Personal Information

  • Identity Details: Name, email address, age, gender
  • Body Metrics: Weight, height, desired weight
  • Account Information: Login credentials (password or 6-digit email verification code), password reset tokens, session data
  • Timezone: Your browser or device timezone, captured automatically during login or account creation to ensure accurate date/time display
  • Communications: Messages sent through our support system, AI chat (“the Engine”), and email correspondence

Health & Wellness Data

We collect health-related information to generate personalised meal plans. This includes:

  • Dietary Information: Dietary type (e.g., omnivore, vegan), food preferences, food allergies, food intolerances, foods you dislike
  • Fitness Data: Training schedule, specific training days, activity level, fitness goals
  • Lifestyle Information: Sleep quality, stress levels, energy patterns, alcohol and caffeine consumption
  • Progress Data: Body weight changes over time, meal compliance tracking, check-in responses
  • Pregnancy & Breastfeeding Status: Whether you are currently pregnant or breastfeeding
  • Gastrointestinal Conditions: Diagnosed conditions such as Crohn's disease, ulcerative colitis, IBD, or other digestive conditions
  • Current Medications: Medications you are currently taking (categories only, not specific dosages)
  • Menstrual Cycle Information: Cycle phase and regularity (females only, used for macro timing)
  • Digestive Symptoms: Bloating, bowel patterns, skin conditions related to digestive health
  • Metabolic Indicators: Carb tolerance, fat storage patterns, low-carb response

Sensitive Data Notice: Much of the health data listed above is considered “sensitive information” under Australian Privacy law and “special category data” under GDPR. We process this data only with your explicit consent (see Section 8).

Progress Photos

  • Body Photos: Progress photos you upload (front, side, and back angles)
  • Photo Metadata: Upload date, user identifier, and photo set identifier
  • Storage: Photos are stored on Cloudflare R2 cloud infrastructure (see Section 9 for full details)

Food Photos

  • Photos of Meals: When you log food via the camera feature in our mobile app, the photo is uploaded to our servers and analysed by Google Gemini Vision to identify ingredients and estimate portion sizes
  • Storage: Food photos are stored on Cloudflare R2 alongside the resulting meal entry. They are deleted when you delete the meal or your account
  • No Body Composition Analysis: Food photos are processed only for ingredient and portion identification. We do not run facial recognition, body composition analysis, or any other form of biometric processing

Voice Input

  • Audio Clips: When you log food using the voice feature in our mobile app, short audio recordings (typically under 30 seconds) are sent to OpenAI's Whisper transcription service
  • Retention: We do not store voice recordings on our servers. The audio is transcribed to text, the resulting text is processed alongside other food-log inputs, and the audio is discarded
  • Processing Location: United States (OpenAI Whisper API)

Push Notification Data

  • Subscription Tokens: If you enable push notifications, we store your browser's push subscription endpoint URL, encryption keys, and device/browser information (user agent)
  • Purpose: Used solely to deliver check-in reminders, progress notifications, and service updates

Technical Data

  • Device Information: IP address, browser type, device identifiers, operating system
  • Usage Data: Pages viewed, meal plan interactions, feature usage, button clicks
  • Cookies & Local Storage: Session cookies, consent preferences, advertising identifiers (see Section 6 for full details)

2. How We Use Your Information

Primary Services

  • AI-Powered Meal Planning: Generate personalised nutrition plans using template algorithms and AI language models, tailored to your dietary needs, health conditions, and preferences
  • Weekly Check-Ins: Analyse your progress data and provide AI-powered macronutrient adjustments
  • AI Chat (“The Engine”): Answer your nutrition and meal plan questions using AI, with access to your profile and plan context for accurate responses
  • Supplement Information: Generate educational supplement explanations personalised to your goals and health profile
  • Progress Tracking: Monitor your journey through weight logging, compliance tracking, and photo comparisons
  • Customer Support: Respond to inquiries and provide assistance. When our AI cannot resolve your question, your message and relevant account context may be escalated to our human support team via Telegram.
  • Push Notifications: Send check-in reminders, progress celebrations, meal prep reminders, and re-engagement messages (with your consent)
  • Account Management: Maintain your profile, preferences, and meal plan history

Social Media Marketing & Advertising

With your consent, we may use your information for:

  • Success Stories: Share client transformations and testimonials across Instagram, Facebook, TikTok, and YouTube (only with your separate, explicit written consent)
  • Targeted Advertising: Create custom audiences for Meta advertising campaigns using hashed data
  • Marketing Communications: Send promotional emails about our services
  • Analytics: Understand how users interact with our platform to improve services

Legal Basis for Processing

  • Explicit Consent: Processing of sensitive health data, marketing communications, social media usage, success story sharing, push notifications
  • Contract Performance: Providing meal planning services, AI chat, check-ins, food swaps, supplement information, account management
  • Legitimate Interest: Service improvement, fraud prevention, system security, error monitoring, analytics
  • Legal Obligation: Tax records, regulatory compliance, responding to lawful requests

3. AI & Automated Processing

How AI Processes Your Data

Our platform uses artificial intelligence to provide personalised services. This section explains what data is processed, by whom, and your rights regarding this processing.

AI Systems We Use

  • Template Algorithms: Our primary meal plan generation uses in-house template-based algorithms that run on our own servers
  • Anthropic (Claude): AI chat responses, check-in coaching analysis, and fallback meal generation. Based in the United States.
  • OpenAI (GPT-4o, GPT-4o-mini, Whisper): Fallback AI provider for chat / coaching / meal generation, plus voice-to-text transcription via Whisper when you log food by voice. Based in the United States.
  • Google (Gemini, Gemini Vision): Tertiary fallback AI provider, supplement information generation, and food-photo ingredient identification via Gemini Vision. Based in the United States.
  • Perplexity (Sonar): Branded food and restaurant nutrition lookups when you log a packaged or restaurant item that isn't in our local database. Based in the United States.

What Data is Sent to AI Providers

For meal plan generation: Dietary preferences, allergies, intolerances, training schedule, weight, goals, protocol type

For AI chat (“the Engine”): All of the above, plus: pregnancy status, gut conditions, current medications, your current week's meal plan, check-in history (last 8 weeks), and your chat message

For check-in coaching: Weight history, compliance data, energy/sleep/stress levels, current macros, protocol type

For supplement information: Goal, activity level, carb tolerance, metabolic symptoms, sleep, stress, energy, training days, age

For voice food-logging (Whisper): Short audio clips of you describing the food (e.g. “eggs and toast for breakfast”). Transcribed to text and immediately discarded

For food-photo logging (Gemini Vision): The photo itself plus optional target-calorie context. No body or identity data attached

For branded food lookup (Perplexity): Only the food name and approximate region (e.g. “Big Mac, Australia”). No identifying user data

AI Consent

Before any personal data is sent to AI providers, you are presented with a consent modal in our mobile app that names the third-party AI providers your data is sent to (Anthropic, OpenAI, and Google) and explains what types of data are shared. You must explicitly agree before AI features are activated. Your consent is stored in your account settings and persists across devices.

Provider Selection

Our system automatically selects AI providers based on availability and reliability. You do not choose which provider processes your data. The system uses a fallback chain — if the primary provider is unavailable, your request is routed to the next available provider.

Data Retention by AI Providers

We use API-based processing with these providers. Where contractually permitted by each provider's API terms, we configure access in opt-out mode for AI training so that your data is not used to train their general AI models. Providers may nonetheless retain data for abuse monitoring, safety review, and the periods set out in their respective privacy policies. We encourage you to review the privacy policies of Anthropic, OpenAI, Google, and Perplexity.

Your Rights Regarding AI Processing

  • Human Review: You may request that a human member of our support team review any AI-generated recommendation, meal plan, or macro adjustment
  • Opt Out of AI Chat: You may choose to use email support instead of the AI chat feature
  • EU/EEA/UK Users (GDPR Article 22): You have the right to not be subject to decisions based solely on automated processing that significantly affect you, and to request meaningful information about the logic involved
  • Request Information: Contact us to request details about what data was processed by AI systems in relation to your account

4. Information Sharing & Third Parties

We never sell your personal data. We share information only with the following categories of service providers who help us deliver and improve our services. Every third party listed below is bound by a data processing agreement that contractually requires them to protect your data to a standard equal to or greater than the protections described in this policy, to use it only for the purposes we specify, and not to sell it or use it for their own purposes:

AI & Meal Generation Providers

  • Anthropic (Claude): AI meal generation, chat responses, and coaching analysis (US)
  • OpenAI (GPT-4o, Whisper): Fallback AI provider for chat / coaching / meal generation, plus voice-to-text transcription (US)
  • Google (Gemini, Gemini Vision): Tertiary fallback AI provider, supplement information generation, and food-photo ingredient identification (US)
  • Perplexity: Branded food and restaurant nutrition lookups (US)

Food Database Providers

  • Open Food Facts: Open-source product database we query when you scan a barcode. Only the barcode UPC/EAN string is sent — no user identifier or account data leaves our servers

Infrastructure & Hosting

  • Render.com: Cloud hosting and PostgreSQL database (Singapore region)
  • Cloudflare: DNS, content delivery network (CDN), and R2 object storage for progress photos and backups

Communication Services

  • SendGrid: Transactional and marketing email delivery
  • Telegram: When our AI chat assistant cannot resolve your question, your message and relevant account context (name, email, protocol, week number) are shared with our support team via a private Telegram group for human follow-up

Payment Processing

  • Stripe: Payment processing and subscription management for purchases made via our website. Stripe handles credit card data directly — we do not store your card numbers on our servers (US)
  • Apple App Store / Apple In-App Purchase: When you subscribe inside our iOS app, Apple processes the purchase under their App Store payment terms. Apple shares anonymised purchase tokens and subscription status with us — we never see your Apple ID payment details (US, EU, AU regions per Apple's data residency)
  • Google Play Billing: When you subscribe inside our Android app, Google processes the purchase. Google shares purchase tokens and subscription status with us — we never see your Google Play payment details (US)
  • RevenueCat: Manages mobile subscription state across Apple and Google. Receives the anonymised purchase token + a hashed user ID so the correct subscription can be applied to your account. RevenueCat does not see your name, email, or payment details (US)

Data Collection

  • Typeform: Questionnaire data collection and webhook delivery for onboarding assessments

Error Monitoring

  • Sentry: Application error monitoring and performance tracking. Error logs may incidentally contain personal data (e.g., email addresses) when errors occur during data processing. We configure data scrubbing to minimise personal data exposure in error reports.

Advertising & Analytics

  • Meta/Facebook: Advertising pixel, Conversions API, and custom audiences. We use Advanced Matching, which sends hashed (one-way encrypted) versions of your email address, name, gender, and general location to Meta for advertising measurement and audience creation
  • Google Analytics (GA4): Website usage analytics, event tracking, and conversion measurement

5. Your Rights & Data Control

Data Deletion & Erasure Rights

Complete Data Deletion

You have the right to request complete deletion of your personal data from our systems.

How to Delete Your Account:

  1. In the mobile app: Go to Account Settings → scroll to the bottom → tap “Delete Account”. This immediately and permanently deletes your account, meal plans, progress photos, check-in history, chat threads, and cancels any active subscription.
  2. Via email: Email us at [email protected] with “Data Deletion Request” in the subject line. Include your full name and email address.
  3. We will process your request within 30 days
  4. You will receive confirmation once deletion is complete

What gets deleted: Your user account, all meal plans (recommended and modified), weekly check-in data, progress photos (from cloud storage), chat conversations, session tokens, supplement data, saved meals, and food preferences. Payment records are anonymised (not deleted) for financial compliance. Support ticket content is anonymised but retained for service improvement.

Your Data Rights

  • Access: Request a copy of all personal data we hold about you
  • Correction: Update or correct inaccurate information
  • Portability: Receive your data in a machine-readable format (JSON or CSV) within 30 days of request
  • Erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Restrict Processing: Request that we limit how we use your data
  • Object to Processing: Object to processing based on our legitimate interests
  • Restrict AI Processing: Request that your data not be processed by AI systems (note: this may limit our ability to provide personalised meal plans and AI chat)
  • Withdraw Consent: Withdraw consent for any processing based on consent at any time, without affecting the lawfulness of processing before withdrawal

Marketing & Notification Opt-Out

  • Email Marketing: Click unsubscribe in any marketing email or contact us directly
  • Push Notifications: Disable notifications through your browser settings or unsubscribe via the platform
  • Success Story Usage: Withdraw consent for featuring your results on social media at any time
  • Advertising: Opt out of targeted ads through Meta and Google ad settings, or contact us for assistance

California Residents (CCPA / CPRA)

If you are a resident of California, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: Request the categories of personal information we have collected, the sources, purposes, and any third parties with whom we shared it
  • Right to Delete: Request deletion of personal information we hold (subject to legal retention requirements)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt Out of Sale or Sharing: We do not sell personal information for monetary value. We do share hashed identifiers with Meta for advertising attribution, which may constitute “sharing” under CPRA. You may opt out by emailing [email protected] or by adjusting your Meta ad preferences (see Section 6)
  • Right to Limit Use of Sensitive Personal Information: Request that we limit the use and disclosure of your sensitive health data to what is necessary to provide our services
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights — your service will not be denied, your prices will not change, and your features will not be reduced
  • Authorised Agent: You may designate an authorised agent to make a request on your behalf, subject to verification of the agent's authority

To exercise any of these rights, email [email protected] with the subject line “California Privacy Request.” We will verify your identity (typically by confirming the email address associated with your account) and respond within 45 days, with a one-time 45-day extension where reasonably necessary.

Right to Lodge a Complaint

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • European Union: Your local supervisory authority (Data Protection Authority)
  • Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca
  • California, USA: California Attorney General — oag.ca.gov or California Privacy Protection Agency — cppa.ca.gov

6. Cookies, Tracking & Local Storage

Cookies We Use

  • Essential Session Cookies: Required for login and session management. Client sessions expire after 7 days. These are httpOnly and secure cookies that cannot be accessed by JavaScript.
  • Analytics Cookies (Google Analytics 4): Track page views, feature usage, and conversion events to help us understand how you use our platform
  • Advertising Cookies (Meta Pixel): Track conversions and enable targeted advertising on Facebook and Instagram
  • Preference Cookies: Remember your settings such as dark/light mode preference

Local Storage

In addition to cookies, we store the following data in your browser's localStorage:

  • Consent Preferences: Your cookie consent choice
  • Advertising Identifier: A randomly generated device identifier used by Meta for advertising attribution
  • Pending Analytics Events: A queue of analytics events awaiting delivery to Meta's Conversions API

Meta Advanced Matching

When you interact with our site, we may send hashed (one-way encrypted) versions of your email address, name, gender, and general location to Meta for advertising measurement and custom audience creation. This data cannot be reversed to reveal your original information.

Cookie Consent

Users in the EU/EEA are presented with a consent banner before non-essential cookies are set. Users in other regions may have analytics enabled by default but can opt out at any time via browser settings or by contacting us.

App Tracking Transparency (iOS Mobile App)

When you first launch our iOS app, you will see Apple's App Tracking Transparency (ATT) prompt asking whether you allow us to track your activity across other companies' apps and websites. If you choose “Ask App Not to Track,” we will not use your iOS Identifier for Advertisers (IDFA) and Meta Pixel attribution will be disabled for your device. Declining the prompt does not affect any core service functionality. You can change this choice at any time via iOS Settings → Privacy & Security → Tracking.

How to Control Cookies & Tracking


7. Data Retention & Storage

Retention Periods

  • Active Accounts: We retain account data while your account is active. To delete your account, see Section 5
  • Meal Plans: Stored for the lifetime of your account so you can reference your history. Deleted on account deletion
  • Progress Photos: Retained while your account is active. Deleted upon account deletion or upon your request
  • AI Chat Messages: Retained for the lifetime of your account to provide conversation continuity and support context. Deleted on account deletion
  • Voice Recordings: Not stored. Audio is transcribed by Whisper and discarded immediately
  • Push Notification Tokens: Retained while your device subscription is active. Automatically removed when the device reports the subscription as expired
  • Mobile Auth Tokens: Stored on your device only — in iOS Keychain and Android EncryptedSharedPreferences via expo-secure-store. Not stored server-side beyond the session record
  • AI Processing Cache: Temporary nutritional data cached for up to 60 days for performance
  • Marketing Data: Retained until you withdraw consent
  • Subscription Receipts: Apple App Store / Google Play / Stripe payment records retained for 7 years to comply with tax and financial reporting obligations. Email anonymised on account deletion
  • Error Logs (Sentry): Retained for 90 days
  • Legal Requirements: Some data may be retained longer for tax, legal, or regulatory compliance as required by law

Data Security

  • Encryption: All data encrypted in transit (TLS/SSL) and sensitive data encrypted at rest
  • Access Controls: Access to personal data restricted on a need-to-know basis
  • Secure Authentication: Sign in with Apple, Google OAuth, and email-based sign-in. Email sign-in uses a magic link on our website (single-use, 30-minute expiry) or a 6-digit verification code in our mobile app (single-use, 10-minute expiry). Sessions are JWT token-based
  • Mobile Token Storage: Auth tokens are stored securely in iOS Keychain or Android EncryptedSharedPreferences via Expo's secure-store module — they never leave your device unencrypted
  • Security Headers: Helmet.js security headers, rate limiting on all API endpoints
  • Secure Hosting: Infrastructure hosted on enterprise-grade platforms with SOC 2 compliance

8. Sensitive Health Data

What We Consider Sensitive

The following categories of data we collect are considered sensitive information under Australian Privacy law and special category data under GDPR:

  • Pregnancy and breastfeeding status (including gestational week)
  • Gastrointestinal conditions (Crohn's disease, ulcerative colitis, IBD, IBS, SIBO)
  • Current medications
  • Menstrual cycle information (including logged period start dates)
  • Digestive symptoms and bowel patterns
  • Skin conditions related to digestive health
  • Food allergies and intolerances (where these reveal an underlying medical condition)
  • Dietary restrictions arising from medical conditions

Legal Basis for Processing

We process sensitive health data on the basis of your explicit consent (GDPR Article 9(2)(a)), which you provide when you complete our health questionnaire and agree to these terms. Under the Australian Privacy Act, we collect sensitive information only with your consent and only where it is reasonably necessary for our services (APP 3).

Enhanced Protections

  • Access Restriction: Sensitive health data is accessible only to authorised automated systems and support personnel
  • No Marketing Use: Sensitive health data is never used for marketing, advertising, or promotional purposes
  • Purpose Limitation: Processed solely for meal plan generation, check-in coaching, and personalised nutrition guidance
  • AI Processing: Sensitive health data may be sent to third-party AI providers (see Section 3) solely for generating personalised meal plans and coaching. Data is transmitted via encrypted API calls and is not used to train AI models.

Withdrawal of Consent

You may withdraw consent for processing your sensitive health data at any time by contacting [email protected]. Please note that withdrawal of consent may limit our ability to provide personalised meal plans and nutrition services, as these rely on understanding your health profile. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.


9. Progress Photos & Biometric Data

  • What We Collect: Body progress photos you upload in up to 3 angles (front, side, back), along with upload timestamps and associated metadata
  • Storage: Photos are stored securely on Cloudflare R2 cloud infrastructure. All photos are encrypted in transit.
  • Access: Your photos are accessible only to you and authorised support staff. They are not visible to other users of the platform.
  • Marketing Use: Your progress photos are never used for marketing, advertising, or promotional purposes without your separate, explicit written consent
  • No AI Training: Your photos are not used to train any AI or machine learning models
  • No Biometric Processing: We do not perform facial recognition, body composition analysis, or any other form of biometric processing on your photos
  • Deletion: You may request deletion of your progress photos at any time by contacting [email protected]. Photos are permanently removed from storage within 30 days of your request.
  • Account Deletion: All progress photos are deleted when your account is deleted

10. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place for all international transfers:

Where Your Data is Processed

  • Singapore (Render): Primary database and application hosting
  • United States: AI providers (OpenAI, Anthropic, Google), error monitoring (Sentry), email delivery (SendGrid), payment processing (Stripe)
  • Global CDN (Cloudflare): DNS, content delivery, and progress photo storage — data may be cached at Cloudflare edge locations worldwide

Transfer Safeguards

  • Standard Contractual Clauses: EU-approved standard contractual clauses with US-based service providers
  • Data Processing Agreements: Formal agreements with all third-party providers governing data handling, security, and retention
  • Encryption: All data encrypted in transit between our systems and third-party providers
  • Adequacy Decisions: Where available, we rely on adequacy decisions recognising equivalent data protection standards

11. Data Security & Breach Notification

Security Measures

  • Encryption: All data encrypted in transit (TLS/SSL) and sensitive data encrypted at rest
  • Access Controls: Role-based access on a need-to-know basis
  • Authentication Security: Sign in with Apple, Google OAuth, magic link via email on the website (single-use, 30-minute expiry), 6-digit verification code in the mobile app (single-use, 10-minute expiry), JWT token sessions, 3-tier rate limiting
  • Mobile Token Storage: Auth tokens stored in iOS Keychain or Android EncryptedSharedPreferences via expo-secure-store
  • Infrastructure Security: Helmet.js security headers, CORS protection, enterprise-grade hosting
  • Monitoring: Sentry error monitoring for rapid detection and response to issues. Error logs configured to scrub personal data before storage

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • Supervisory Authority: We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR requirement)
  • Australian Notification: We will notify the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme of the Privacy Act 1988
  • Individual Notification: We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Notification Contents: Notifications will include: the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach

12. Children's Privacy

Our services are intended only for adults aged 18 years or older. We do not knowingly collect personal information from individuals under 18. If we become aware that an account was created by, or is being used by, an individual under 18, we will delete the associated personal information.

Where local law sets a lower age of digital consent, we comply with that local threshold for the purpose of handling reports about minors who may already have created an account:

  • EU/EEA: GDPR Article 8 sets the default at 16, with Member States permitted to set a lower age (no lower than 13). We follow the threshold applicable in your country
  • United Kingdom: The Information Commissioner's Office (ICO) sets the equivalent threshold at 13
  • United States: The Children's Online Privacy Protection Act (COPPA) sets the threshold at 13. Our service is not designed for users under 18 in any case

If you believe a minor has registered for our services, please contact us at [email protected] with the subject line “Minor Account Report” and we will take steps to verify and delete the account.


13. Updates to This Policy

We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. When we make significant changes:

  • Email Notification: For material changes, we will notify active subscribers by email at least 14 days before the changes take effect
  • Website Publication: Updated policy will be published on our website with the new effective date
  • Effective Date: Changes take effect on the date stated in the updated policy, no sooner than 14 days after notification for material changes
  • Review Period: You may review changes and withdraw consent or cancel your subscription if you disagree with the updated policy

14. Legal Compliance

This Privacy Policy is designed to comply with:

  • Australian Privacy Act 1988 — including the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme
  • General Data Protection Regulation (GDPR) — for EU/EEA and UK residents
  • California Consumer Privacy Act (CCPA) — for California residents
  • Personal Information Protection and Electronic Documents Act (PIPEDA) — for Canadian residents

Where local data protection laws provide greater protection than this policy, those laws will prevail. If you believe we are not handling your data in accordance with applicable law, you have the right to lodge a complaint with your local data protection authority (see Section 5).


15. Contact Us & Data Protection

For any questions about this Privacy Policy, data deletion requests, or to exercise any of your data rights, please contact us:

Meal Engine Support
Email: [email protected]
Subject Line for Data Requests: “Data Request” or “Data Deletion Request”
Response Time: We will acknowledge your request within 7 days and process it within 30 days

If you are not satisfied with our response to your request, you have the right to lodge a complaint with your local data protection authority (see Section 5 for contact details).