← tribae

Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains what personal data tribae ("we", "us", "our") collects when you use the tribae application and website (collectively, the "Service"), how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws.

1. Data controller

The data controller is the operator of tribae, reachable at [email protected]. For any data-related requests, use this address.

2. Data we collect

2.1 Account data

When you sign in with Google we receive your name, email address, and profile picture URL from Google OAuth. We store these to identify your account and personalise the Service.

2.2 Profile and health data

You may provide optional health-related information: biological sex, age, height, current weight, goal weight, activity level, dietary preferences, and food restrictions. This data is used solely to generate personalised meal plans and nutrition guidance. We treat it as sensitive personal data under GDPR Art. 9 and process it only with your explicit consent (given during onboarding).

2.3 Usage data

We store the meal plans, shopping lists, weight log entries, and chat messages you create while using the Service. This data is tied to your account and is necessary to provide the Service.

2.4 Billing data

Payment processing is handled entirely by Stripe, Inc. We receive a Stripe customer ID and subscription status from Stripe but never see or store your full card number, expiry date, or CVV. Stripe's privacy policy is available at stripe.com/privacy.

2.5 Technical data

We store server-side logs (IP address, request path, timestamp, HTTP status code) for up to 30 days for security and debugging. We set a single strictly-necessary session cookie (__session) to keep you signed in; it does not track you across websites and does not require consent under ePrivacy rules.

3. How we use your data

PurposeLegal basis
Providing the Service (meal plans, shopping list, chat)Contract performance (Art. 6(1)(b))
Processing health/diet preferencesExplicit consent (Art. 9(2)(a))
Billing and subscription management via StripeContract performance (Art. 6(1)(b))
Security monitoring and abuse preventionLegitimate interests (Art. 6(1)(f))
Responding to support requestsLegitimate interests (Art. 6(1)(f))

We do not use your data for advertising. We do not sell or rent your data to third parties.

4. AI processing

Meal plans, nutrition guidance, and chat responses are generated using the Claude API provided by Anthropic, PBC. When you request a meal plan or send a chat message, relevant parts of your profile (dietary preferences, calorie targets, location) and your message are sent to Anthropic's API. Anthropic processes this data as a data processor under our instructions. Content sent to the API is subject to Anthropic's Privacy Policy.

5. Third-party processors

ProcessorPurposeLocation
Google LLCOAuth sign-inUSA (SCCs)
Anthropic, PBCAI-generated contentUSA (SCCs)
Stripe, Inc.Payment processingUSA (SCCs)
Google Cloud (GCP)Hosting, databaseEU (europe-central2)
Cloudflare, Inc.CDN and DNSUSA/EU (SCCs)

SCCs = Standard Contractual Clauses (EU-approved transfer mechanism under GDPR Art. 46).

6. Data retention

We retain your account and usage data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes (e.g. billing records are kept for 7 years under Polish accounting law).

7. Your rights (GDPR)

You have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in Poland: UODO).

8. Cookies

We use one cookie: __session — a strictly-necessary HTTP-only session cookie set after sign-in. It expires when you close your browser or after 14 days of inactivity. No tracking, analytics, or advertising cookies are used. No cookie consent banner is required.

9. Security

Data is stored on Google Cloud SQL (PostgreSQL) in the EU (europe-central2 region) with encryption at rest and in transit. Access is restricted to the Service backend via private networking. We use RS256-signed JWTs and rotate secrets regularly.

10. Children

The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes will be notified via email or in-app notice at least 14 days before they take effect. Continued use of the Service after that date constitutes acceptance.

12. Contact

[email protected]