Privacy Policy
Effective date: 4 February 2026
1. Data Controller
The data controller responsible for your personal data is Safe Plated Pte. Ltd. (UEN 202606065Z), a company incorporated in the Republic of Singapore. For all data protection enquiries, contact us at support@safeplated.com.
2. Data We Collect
When you use Safe Plated, we collect:
- Account information: Email address, display name, authentication credentials.
- Health-related preferences: Allergens, allergen severity levels, dietary restrictions, food dislikes, household member details (names, age groups).
- Meal planning data: Generated meal plans, saved recipes, pantry items, shopping lists, favourites, meal history, and reaction logs.
- Budget and lifestyle preferences: Currency, region, budget level, weekly spending targets, cuisine preferences.
- Usage data: Feature interactions, recipe ratings, reviews, device type, browser information, and IP address.
- Payment data: Subscription status and billing history (payment card details are processed and stored exclusively by Stripe, Inc. and are not held by Safe Plated).
3. How We Use Your Data
- Generate personalised, allergen-aware meal plans and recipes.
- Remember your preferences and household profile across sessions.
- Improve the quality, safety, and relevance of AI-generated suggestions.
- Process payments and manage your subscription.
- Send transactional and service-related notifications (e.g., expiry reminders, safety alerts).
- Comply with legal obligations and enforce our Terms of Service.
4. Third-Party Data Processors
We use the following third-party services to operate the Service:
- Supabase (Supabase, Inc.): Database storage and authentication infrastructure. Your profile, preferences, and meal plan data are stored in Supabase-managed infrastructure.
- Google Gemini AI (Google LLC): Recipe generation, substitution logic, and safety analysis. Your allergen profile and dietary preferences are transmitted to Google's AI models to generate personalised content. Google processes this data under their Cloud Data Processing Addendum.
- Stripe, Inc.: Payment processing for subscriptions. Safe Plated does not store or have access to your full payment card details.
- Sentry (Functional Software, Inc.): Error monitoring and performance tracking to maintain service reliability. No health-related data is transmitted to Sentry.
5. AI Data Isolation & Processing
Safe Plated uses the Google Gemini API (a commercial API product, not the consumer chatbot) to generate recipes, meal plans, safety analyses, and chat responses. We understand this data is sensitive — here is exactly how it is handled:
- What is sent to the AI: When you generate a meal plan, recipe, lunchbox plan, safety card, or use the chat feature, we send your allergen profile, household member names and age groups, dietary preferences, food dislikes, and the specific request to Google's Gemini API. We do not send your email address, payment details, or account credentials.
- Your data is not used to train AI models: We access Google Gemini through their Cloud API under Google's Cloud Data Processing Addendum (CDPA). Under this agreement, Google is prohibited from using your inputs or outputs to train, improve, or develop their AI models. Your family's data does not become part of any AI training dataset.
- Processing is ephemeral: Data sent to the Gemini API is processed in real time to generate a response and is not retained by Google after the response is returned, in accordance with Google's Cloud API data processing terms.
- Chat conversations: If you use the in-app chat, your conversation history and allergen context are sent to the AI to generate responses. The same protections apply — Google does not retain or train on this data. Conversation history is stored only in your authenticated account.
- No sharing with other users: Your allergen profile, household details, and generated content are isolated to your account. Other Safe Plated users cannot see your data, and the AI does not carry context between different users' requests.
For full details on Google's data handling commitments, see Google Cloud Data Processing Addendum.
6. Health Data Protection
We treat your allergen, dietary, and health-related information with the highest level of care. We do not sell, rent, or trade your health-related data to any third party for marketing, advertising, or any purpose unrelated to providing the Service. Your allergen profile is shared only with AI services strictly as necessary to generate safe recipe suggestions.
7. Cookies and Tracking
We use essential cookies for authentication and session management only. We do not use advertising cookies, behavioural tracking cookies, or third-party marketing pixels. We do not engage in cross-site tracking.
8. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide the Service. Upon account deletion, we will remove your profile, allergen data, meal plans, pantry items, and all associated records within thirty (30) days. Anonymised, aggregated usage data that cannot be linked to any individual may be retained for service improvement purposes.
9. Data Deletion
You may request deletion of your account and all associated personal data at any time by contacting us at support@safeplated.com or through the Settings page within the application. We will process deletion requests within thirty (30) days.
10. Your Rights
Depending on your location, you may have rights under applicable data protection legislation including the Singapore Personal Data Protection Act 2012 ("PDPA"), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act ("CCPA"). These rights may include:
- Access: Request a copy of the personal data we hold about you.
- Correction: Correct inaccurate personal data via your Settings page or by contacting us.
- Deletion: Request deletion of your personal data.
- Portability: Receive your data in a structured, commonly used, machine-readable format.
- Objection / Restriction: Object to or request restriction of certain processing activities.
- Withdrawal of consent: Withdraw consent for processing where consent is the legal basis.
- Opt-out of sale: We do not sell personal information (California residents: no action required).
To exercise any of these rights, contact us at support@safeplated.com. We will respond within the timeframes required by applicable law.
11. International Data Transfers
Your data may be processed in jurisdictions outside your country of residence, including Singapore, the United States (for Supabase, Google, and Stripe services), and other locations where our service providers maintain infrastructure. Where such transfers occur, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.
12. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS 1.2+), secure authentication, row-level security policies, and access controls. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security of your data.
13. Children's Privacy
The Service is not directed to children under the age of eighteen (18). We do not knowingly collect personal data from children under 13 without parental consent. If you are a parent or guardian and become aware that your child has provided personal data to us, please contact us and we will take steps to delete such information.
We collect allergen and dietary restriction data for household members, which may include children, solely for the purpose of food safety under parental/guardian consent. This data is managed entirely by the parent or guardian account holder and is used exclusively to generate safe, allergen-aware meal plans and recipes. We do not use children's data for marketing, profiling, or any purpose unrelated to food safety.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least fourteen (14) days before taking effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
15. Contact and Complaints
For privacy questions, data protection requests, or complaints, contact:
Safe Plated Pte. Ltd.
UEN: 202606065Z
Email: support@safeplated.com
If you are located in Singapore, you may also lodge a complaint with the Personal Data Protection Commission (PDPC). If you are located in the EU/EEA, you may lodge a complaint with your local data protection supervisory authority.