Last updated: 29 June 2026
This Privacy Policy explains what personal data tribae ("we", "us", "our") collects when you use the tribae application and website (collectively, the "Service"), how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable laws.
The data controller is the operator of tribae, reachable at [email protected]. For any data-related requests, use this address.
When you sign in with Google we receive your name, email address, and profile picture URL from Google OAuth. We store these to identify your account and personalise the Service.
You may provide optional health-related information: biological sex, age, height, current weight, goal weight, activity level, dietary preferences, and food restrictions. This data is used solely to generate personalised meal plans and nutrition guidance. We treat it as sensitive personal data under GDPR Art. 9 and process it only with your explicit consent (given during onboarding).
We store the meal plans, shopping lists, weight log entries, and chat messages you create while using the Service. This data is tied to your account and is necessary to provide the Service.
Payment processing is handled entirely by Stripe, Inc. We receive a Stripe customer ID and subscription status from Stripe but never see or store your full card number, expiry date, or CVV. Stripe's privacy policy is available at stripe.com/privacy.
We store server-side logs (IP address, request path, timestamp, HTTP status code) for up to 30 days for security and debugging. We set a single strictly-necessary session cookie (__session) to keep you signed in; it does not track you across websites and does not require consent under ePrivacy rules.
| Purpose | Legal basis |
|---|---|
| Providing the Service (meal plans, shopping list, chat) | Contract performance (Art. 6(1)(b)) |
| Processing health/diet preferences | Explicit consent (Art. 9(2)(a)) |
| Billing and subscription management via Stripe | Contract performance (Art. 6(1)(b)) |
| Security monitoring and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Responding to support requests | Legitimate interests (Art. 6(1)(f)) |
We do not use your data for advertising. We do not sell or rent your data to third parties.
Meal plans, nutrition guidance, and chat responses are generated using the Claude API provided by Anthropic, PBC. When you request a meal plan or send a chat message, relevant parts of your profile (dietary preferences, calorie targets, location) and your message are sent to Anthropic's API. Anthropic processes this data as a data processor under our instructions. Content sent to the API is subject to Anthropic's Privacy Policy.
| Processor | Purpose | Location |
|---|---|---|
| Google LLC | OAuth sign-in | USA (SCCs) |
| Anthropic, PBC | AI-generated content | USA (SCCs) |
| Stripe, Inc. | Payment processing | USA (SCCs) |
| Google Cloud (GCP) | Hosting, database | EU (europe-central2) |
| Cloudflare, Inc. | CDN and DNS | USA/EU (SCCs) |
SCCs = Standard Contractual Clauses (EU-approved transfer mechanism under GDPR Art. 46).
We retain your account and usage data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes (e.g. billing records are kept for 7 years under Polish accounting law).
You have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in Poland: UODO).
We use one cookie: __session — a strictly-necessary HTTP-only session cookie set after sign-in. It expires when you close your browser or after 14 days of inactivity. No tracking, analytics, or advertising cookies are used. No cookie consent banner is required.
Data is stored on Google Cloud SQL (PostgreSQL) in the EU (europe-central2 region) with encryption at rest and in transit. Access is restricted to the Service backend via private networking. We use RS256-signed JWTs and rotate secrets regularly.
The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy. Material changes will be notified via email or in-app notice at least 14 days before they take effect. Continued use of the Service after that date constitutes acceptance.