Eat & Lift Privacy Policy

Last updated: 18 June 2026

Thank you for choosing Eat & Lift. Protecting your privacy is at the core of how we build our services. This Privacy Policy explains what Personal Data we collect, how we use it, the limited circumstances in which we share it, and the choices and rights you have.

Our Core Privacy Commitments

1. Scope of this Policy

This Policy applies when you:

It does not cover third‑party sites or services that link to or from our products.

2. Who We Are

Nedeveon EOOD (reg. no. 207677715) is a company established under Bulgarian law with its registered office at ul. „Bitolya 5", fl. 1, apt. 3, 9002 Varna, Bulgaria. For the purposes of the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and comparable laws, we act as the Data Controller for the processing described here.

Email: [email protected]
Data‑Protection Officer (DPO): [email protected]
Supervisory authority: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria.

3. Key Terms

4. Personal Data We Collect

Account Data

Examples: Email, hashed password, Apple/Google ID token

Source: You

Required: Yes, to create an account

Usage Data

Examples: Food logs, workouts, meal plans, goals, etc.

Source: You

Optional: Local‑first. Synced only if you enable Backup & Sync

Health & Fitness Data

Examples: Steps, calories burned, body weight, workouts, distance, nutrition

Source: Health Connect (Android) / Apple Health (iOS), with your permission

Optional: Off by default. Only if you enable the Health integration. See Section 6

Subscription Data

Examples: Purchase identifier, status, start/end dates

Source: Apple / Google / RevenueCat

Required: Yes, for premium features

Device & Log Data

Examples: IP, device type, OS version, crash traces

Source: Your device; Firebase Crashlytics†

Optional: Opt‑in crash reporting

Analytics Data

Examples: Feature interactions, session duration

Source: Firebase Analytics†

Optional: Opt‑in analytics

Website Data

Examples: IP address, browser details, pages viewed

Source: Your browser; Cloudflare

Note: No cookies used

Support / Feedback

Examples: Emails, messages, attachments

Source: You

Optional: Yes

† Disabled by default; you can enable them in Settings → Analytics (for analytics) or Settings → Crash Reports (for crash reporting).

We never deliberately collect data about persons under 18.

5. Why We Process Your Data & Legal Bases

Provide core App functions (tracking, insights)

Legal basis: Contractual necessity

Account creation & authentication

Legal basis: Contractual necessity

Synchronise data across devices (Backup & Sync)

Legal basis: Consent (opt‑in)

Provide AI‑powered premium features

Legal basis: Contractual necessity or Consent where the feature is stand‑alone

Process payments & manage subscriptions

Legal basis: Contractual necessity

Diagnose crashes & measure performance

Legal basis: Consent (opt‑in analytics/crash)

Secure our services, prevent abuse

Legal basis: Legitimate interests

Comply with legal obligations (tax, accounting)

Legal basis: Legal obligation

Where we rely on legitimate interests, we balance our need to process the data against your rights and expectations.

6. Health Connect & Apple Health

Eat & Lift can connect to your device's health platform — Health Connect on Android and Apple Health on iOS. This integration is optional and off by default; it works only after you enable it in Settings → Health and grant permission on the platform itself.

With your permission, we read and/or write only the following data types, each for a specific in-app feature:

How we handle it. Health platform data is used solely to provide these tracking features for you. We never use it for advertising or marketing, never sell it, and never share or transfer it to third parties for those purposes. It is stored locally on your device by default and is included in encrypted server backups only if you turn on Backup & Sync. We write back only records that you created in the App, and health data is never sent to any AI feature without your separate, explicit action.

Your control. You can disable the integration at any time in App → Settings → Health, and you can review or revoke individual permissions directly in Health Connect (Android) or the Apple Health app (iOS). Revoking stops all further reading and writing.

Our use of Health Connect complies with Google Play's Health Apps requirements and the Health Connect permissions (limited use) policy; our use of Apple Health (HealthKit) data complies with Apple's requirements. In both cases this data is never used for advertising, marketing, or data-mining.

7. Who Receives Your Data

We do not sell Personal Data. We only share it with:

Hetzner Online GmbH

Location: Germany (EEA)

Purpose: Hosting of servers/APIs

Safeguard: DPA

Cloudflare, Inc.

Location: USA

Purpose: Traffic routing, CDN, DDoS protection

Safeguard: EU‑US DPF & SCCs

Google LLC

Location: USA

Purpose: Sign‑in, Gemini API, Firebase

Safeguard: EU‑US DPF & SCCs

OpenRouter, Inc.

Location: USA

Purpose: AI model routing for AI features

Safeguard: SCCs

Apple Inc.

Location: USA

Purpose: Sign‑in, App Store payments

Safeguard: SCCs

RevenueCat, Inc.

Location: USA

Purpose: Subscription management

Safeguard: SCCs

Resend

Location: USA

Purpose: Transactional email

Safeguard: SCCs

Each processor is contractually obliged to act only on our instructions and to implement adequate technical and organisational security measures.

8. International Transfers

Your primary data (and all backups) are stored in the EU. Where we must transfer Personal Data outside the EEA/UK, we rely on:

9. Data Retention

Account & synced data

Until you delete your account + 30 days backup grace period

Local‑only data

Controlled entirely by you on your device

Subscription & purchase records

10 years (statutory accounting)

Transactional email logs

90 days

Crash & analytics data

Up to 14 months or until you disable/erase

Server access logs

30 days

We irreversibly destroy or anonymise data after the retention period expires.

10. Security Measures

While no system is 100% secure, we follow industry best practices to reduce risk.

11. Your Privacy Choices & Rights

Depending on where you live, you may have the right to:

We will never discriminate against you for exercising your rights.

12. How to Exercise Your Rights

In-App Actions

Email Requests

For other requests (access, portability, objection, etc.), email [email protected] from your registered address.

We may verify your identity before responding. We respond within 30 days (or faster where required).

13. Cookies & Similar Technologies

We do not use cookies or any similar tracking technologies on our Website.

14. Children's Privacy

We do not knowingly collect Personal Data from persons under 18. If we learn that such data has been collected without verifiable parental consent, we will delete it promptly.

15. Changes to this Policy

We will post any material changes here and, where appropriate, notify you via the App or email. The "Last updated" date at the top reflects the latest revision.

16. Contact Us

If you have questions about this Policy or our data practices, please contact our DPO:

Email: [email protected]

Postal: Nedeveon EOOD, ul. „Bitolya 5", fl. 1, apt. 3, 9002 Varna, Bulgaria

Website: eatnlift.com

You also have the right to lodge a complaint with your local data‑protection authority; in Bulgaria, that is the CPDP (www.cpdp.bg).