Last updated: 18 June 2026
Thank you for choosing Eat & Lift. Protecting your privacy is at the core of how we build our services. This Privacy Policy explains what Personal Data we collect, how we use it, the limited circumstances in which we share it, and the choices and rights you have.
This Policy applies when you:
It does not cover third‑party sites or services that link to or from our products.
Nedeveon EOOD (reg. no. 207677715) is a company established under Bulgarian law with its registered office at ul. „Bitolya 5", fl. 1, apt. 3, 9002 Varna, Bulgaria. For the purposes of the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and comparable laws, we act as the Data Controller for the processing described here.
Email: [email protected]
Data‑Protection Officer (DPO): [email protected]
Supervisory authority: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria.
Examples: Email, hashed password, Apple/Google ID token
Source: You
Required: Yes, to create an account
Examples: Food logs, workouts, meal plans, goals, etc.
Source: You
Optional: Local‑first. Synced only if you enable Backup & Sync
Examples: Steps, calories burned, body weight, workouts, distance, nutrition
Source: Health Connect (Android) / Apple Health (iOS), with your permission
Optional: Off by default. Only if you enable the Health integration. See Section 6
Examples: Purchase identifier, status, start/end dates
Source: Apple / Google / RevenueCat
Required: Yes, for premium features
Examples: IP, device type, OS version, crash traces
Source: Your device; Firebase Crashlytics†
Optional: Opt‑in crash reporting
Examples: Feature interactions, session duration
Source: Firebase Analytics†
Optional: Opt‑in analytics
Examples: IP address, browser details, pages viewed
Source: Your browser; Cloudflare
Note: No cookies used
Examples: Emails, messages, attachments
Source: You
Optional: Yes
† Disabled by default; you can enable them in Settings → Analytics (for analytics) or Settings → Crash Reports (for crash reporting).
We never deliberately collect data about persons under 18.
Legal basis: Contractual necessity
Legal basis: Contractual necessity
Legal basis: Consent (opt‑in)
Legal basis: Contractual necessity or Consent where the feature is stand‑alone
Legal basis: Contractual necessity
Legal basis: Consent (opt‑in analytics/crash)
Legal basis: Legitimate interests
Legal basis: Legal obligation
Where we rely on legitimate interests, we balance our need to process the data against your rights and expectations.
Eat & Lift can connect to your device's health platform — Health Connect on Android and Apple Health on iOS. This integration is optional and off by default; it works only after you enable it in Settings → Health and grant permission on the platform itself.
With your permission, we read and/or write only the following data types, each for a specific in-app feature:
How we handle it. Health platform data is used solely to provide these tracking features for you. We never use it for advertising or marketing, never sell it, and never share or transfer it to third parties for those purposes. It is stored locally on your device by default and is included in encrypted server backups only if you turn on Backup & Sync. We write back only records that you created in the App, and health data is never sent to any AI feature without your separate, explicit action.
Your control. You can disable the integration at any time in App → Settings → Health, and you can review or revoke individual permissions directly in Health Connect (Android) or the Apple Health app (iOS). Revoking stops all further reading and writing.
Our use of Health Connect complies with Google Play's Health Apps requirements and the Health Connect permissions (limited use) policy; our use of Apple Health (HealthKit) data complies with Apple's requirements. In both cases this data is never used for advertising, marketing, or data-mining.
We do not sell Personal Data. We only share it with:
Location: Germany (EEA)
Purpose: Hosting of servers/APIs
Safeguard: DPA
Location: USA
Purpose: Traffic routing, CDN, DDoS protection
Safeguard: EU‑US DPF & SCCs
Location: USA
Purpose: Sign‑in, Gemini API, Firebase
Safeguard: EU‑US DPF & SCCs
Location: USA
Purpose: AI model routing for AI features
Safeguard: SCCs
Location: USA
Purpose: Sign‑in, App Store payments
Safeguard: SCCs
Location: USA
Purpose: Subscription management
Safeguard: SCCs
Location: USA
Purpose: Transactional email
Safeguard: SCCs
Each processor is contractually obliged to act only on our instructions and to implement adequate technical and organisational security measures.
Your primary data (and all backups) are stored in the EU. Where we must transfer Personal Data outside the EEA/UK, we rely on:
Until you delete your account + 30 days backup grace period
Controlled entirely by you on your device
10 years (statutory accounting)
90 days
Up to 14 months or until you disable/erase
30 days
We irreversibly destroy or anonymise data after the retention period expires.
While no system is 100% secure, we follow industry best practices to reduce risk.
Depending on where you live, you may have the right to:
We will never discriminate against you for exercising your rights.
For other requests (access, portability, objection, etc.), email [email protected] from your registered address.
We may verify your identity before responding. We respond within 30 days (or faster where required).
We do not use cookies or any similar tracking technologies on our Website.
We do not knowingly collect Personal Data from persons under 18. If we learn that such data has been collected without verifiable parental consent, we will delete it promptly.
We will post any material changes here and, where appropriate, notify you via the App or email. The "Last updated" date at the top reflects the latest revision.
If you have questions about this Policy or our data practices, please contact our DPO:
Email: [email protected]
Postal: Nedeveon EOOD, ul. „Bitolya 5", fl. 1, apt. 3, 9002 Varna, Bulgaria
Website: eatnlift.com
You also have the right to lodge a complaint with your local data‑protection authority; in Bulgaria, that is the CPDP (www.cpdp.bg).