Angiochef

Privacy Policy

Version 1.0  ·  Effective date: 31 May 2026

In plain language: Angiochef is run by an individual in Spain. We collect what we need to run the app: your sign-in identity, the dietary preferences and allergies you choose to give us, what you cook and plan, and pseudonymous usage analytics. Your dietary and allergy information can be sensitive "health data", so we process it only with your explicit consent, to personalise the app for you. We use a small number of trusted providers (Supabase, Google, RevenueCat, Apple/Google); your account and content are stored in Europe, though some providers may process certain data outside the EU with safeguards. We do not sell your data. You can see, correct, export and delete your data, withdraw consent, and complain to the Spanish data-protection authority. Details below.

1. Who is responsible for your data (Data Controller)

The controller of your personal data is Rubén Antonio López García, an individual sole trader (autónomo) established in Spain, at C/ Lepant 270, Bajos, 08013 Barcelona, Spain, who also acts as our privacy officer. For any privacy question or to exercise your rights, contact us at support@angiochef.com.

2. About this policy

This Privacy Policy explains what personal data Angiochef ("we", "us") collects when you use the App, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. It applies to the Angiochef mobile app and related services. It forms part of, and should be read with, our Terms & Conditions.

3. Health data, and an important clarification about HIPAA

Some information you give us — in particular your dietary restrictions and the allergies/ingredients you choose to avoid — can be treated under EU law as special-category "health" data (Article 9 GDPR). We process it only with your explicit consent, only to personalise the App for you (see §5), and you can withdraw that consent at any time.

Angiochef is a general wellness and educational app, not a healthcare provider. We are not a "covered entity" or "business associate" under the U.S. HIPAA law, and the information you provide is not protected health information under HIPAA and is not a medical record. The App does not provide medical advice (see the health disclaimer in our Terms & Conditions).

4. What data we collect

CategoryExamplesSource
Account & identityA unique user ID; the email address and (if you allow it) name associated with your Apple or Google sign-in; which provider you used.You / Apple / Google at sign-in
Dietary profile (may be special category)Your dietary preferences and the ingredients/allergens you choose to avoid.You
Your activity in the AppRecipes you view, cook, plan and log; meal plans; recipes you personalise ("forks") and custom ingredients you create, including any notes you add; your saved filters and preferences.You
AI feature inputsText or images you submit to AI-powered features — e.g. a search term, an ingredient name, recipe notes, or a food photo for image recognition.You
Subscription & transactionYour subscription/entitlement status and related identifiers needed to grant Pro access. We do not receive or store your full payment-card details — payment is handled by Apple/Google.RevenueCat / Apple / Google
Usage analytics & device dataPseudonymous usage events tied to a random user identifier (for example, that a recipe was viewed, a paywall was shown, a feature was used), grouped into ranges/"buckets"; app and device information; crash and performance diagnostics. We deliberately do not log the content of your searches, and analytics events do not contain your name or contact details.Automatically
Legal acceptance recordsWhich version of the Terms and Privacy Policy you accepted, when, and how (e.g. at sign-up or on a consent screen).Automatically
On-device dataSmall settings and feature flags stored only on your device (e.g. which in-app tips you've seen), and your assistant chat history, which is stored only on your device and not on our servers. This stays on your device.On device

Notifications are local to your device only (meal reminders and timers). We do not use push-notification services and do not collect push tokens.

4.1 Apple Health and Health Connect

With your permission, the App can write nutrition estimates (such as energy, protein, carbohydrates and fat) that you log in Angiochef to Apple Health (iOS) or Health Connect (Android). We do not read any data from Apple Health or Health Connect — the integration is write-only. Health data written this way is never used for advertising or marketing, never sold, and never mined for any purpose beyond showing it back to you in Apple Health / Health Connect. You can revoke this permission at any time in your device's Settings — under Health (iOS) or Health Connect (Android) — or in the App's own permission settings.

5. Why we use your data, and our legal bases

PurposeLegal basis (GDPR)
Create and run your account; provide recipes, meal planning, forks and other core features.Performance of a contract (Art. 6(1)(b)).
Personalise the App using your dietary information — tailoring recipes and recommendations to your preferences and the ingredients you avoid.Your explicit consent (Art. 9(2)(a)), which you can withdraw at any time.
Provide AI-powered features you choose to use.Performance of a contract (Art. 6(1)(b)); explicit consent where the input concerns your health.
Manage subscriptions and entitlements (Angiochef Pro).Performance of a contract (Art. 6(1)(b)).
Understand usage and improve the App (analytics, diagnostics, stability).Your consent where required for non-essential analytics; otherwise our legitimate interest in maintaining and improving the App (Art. 6(1)(f)).
Keep the App secure, prevent abuse, and enforce limits and our Terms.Legitimate interest (Art. 6(1)(f)).
Keep records of which legal terms you accepted.Legal obligation and legitimate interest (Art. 6(1)(c)/(f)).
Comply with the law and respond to lawful requests.Legal obligation (Art. 6(1)(c)).

We do not use your personal data to make decisions about you that produce legal or similarly significant effects solely by automated means.

6. AI processing — what is sent, and to whom

When you use an AI-powered feature, the input you provide is sent to our AI provider, Google (Gemini / Google AI), to generate the result, which is returned to you. We minimise and sanitise inputs, label user-provided text, and constrain the output format. We do not use AI inputs for advertising. Please do not submit other people's personal data, or anyone's sensitive data, to AI features. AI features are identified as such in the App; when you use them, you are interacting with an AI system, not a human.

7. Who we share data with (our processors and partners)

We share personal data only with the service providers we need to run the App, and only as necessary. Each acts under a data-processing agreement and/or its own controller obligations.

ProviderRoleData involved
SupabaseCloud database, authentication, secure functions and file storage (our core backend).Account, profile, dietary data, activity, legal-acceptance records.
Google — Gemini / Google AIAI processing for search, personalisation, summaries and image recognition.The inputs you submit to AI features.
Google — Firebase / Google AnalyticsUsage analytics, crash and performance diagnostics.Pseudonymous usage events tied to a random user identifier, only after your consent and off by default; device and diagnostic data.
PostHog (hosted in the EU)Product analytics — understanding feature usage and improving the App.Pseudonymous usage events tied to a random user identifier; only after your consent, off by default.
RevenueCatSubscription management and entitlement checks.User ID and subscription/entitlement status.
Apple / Google PlayApp distribution, sign-in, and payment processing.Sign-in identity; purchase/transaction data they process as merchant of record or billing agent.

We may also disclose data where necessary to comply with the law or a lawful request, to protect the rights, safety or security of users, the public or us, or in connection with a reorganisation, merger or sale of the business (in which case we will require the recipient to respect this policy).

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

8. Cookies and similar technologies

As a mobile app, Angiochef does not use website cookies. It does use software development kits (notably for analytics and subscriptions) that may use device identifiers. Where the law requires (for example in the EU), we ask for your consent before using non-essential analytics. We do not use Apple's advertising identifier (IDFA) and do not track you across other companies' apps or websites for advertising.

9. International data transfers

Our main backend (database, authentication and file storage) is hosted in the European Union, so your account and content stay within the EU/EEA. Some other providers may process certain data outside the EU/EEA, including in the United States — for example our AI provider (Google), analytics (Google/Firebase), subscription management (RevenueCat), and the app stores (Apple, Google). Where personal data is transferred outside the EU/EEA, we rely on a lawful transfer mechanism appropriate to each recipient: Google is certified under the EU–US Data Privacy Framework; RevenueCat and Supabase rely on the European Commission's Standard Contractual Clauses for any data processed outside the EU/EEA. You can ask us for a copy of the relevant safeguards using the contact details above.

10. How long we keep your data

We keep your personal data for as long as your account is active and for as long as needed for the purposes in §5. When you delete your account, we delete or anonymise your personal data associated with it, except where we must keep certain records (such as proof of which legal terms you accepted, or information needed to comply with the law or resolve disputes) and except for copies that remain in routine backups for a limited period before being overwritten. Anonymous, aggregated analytics that can no longer be linked to you may be retained. Concretely: chat-quality observability metrics are kept for up to 180 days; rate-limit logs are kept for up to 2 days; routine backups are overwritten on a rolling basis.

11. Your rights

Under the GDPR and Spanish data-protection law you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to certain processing; data portability; and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these, contact support@angiochef.com. We will respond within the time limits set by law (generally one month).

You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), www.aepd.es, or with the supervisory authority in your EU country of residence.

If you are in the United States (e.g. California and other states), you may have rights to know, access, correct, delete and obtain a copy of your personal information, and to opt out of any "sale" or "sharing" — note that we do not sell or share your data for advertising. To exercise these rights, contact us at the same address. We will not discriminate against you for exercising your rights.

12. Managing your data in the App

You can review and change much of your data directly in the App — for example update your dietary preferences, and edit or delete your custom content. You can delete your account from the in-app account settings; this removes your associated personal data as described in §10, and cancels any device notifications. You can also request deletion by email — see our Delete Account page.

13. Children

Angiochef is intended only for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

14. How we protect your data

We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls and row-level security on our database, and encrypted on-device storage for local data. No system is perfectly secure, but if a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the AEPD (and you, where required) in line with our legal obligations.

15. Changes to this policy

We may update this Privacy Policy. When we make material changes we will update the version and effective date and, where appropriate, ask you to review and accept the new version in the App. Where the change relies on your consent, we will ask for it.

16. Contact

For any privacy matter, or to exercise your rights, contact Rubén Antonio López García (who acts as our privacy officer) at support@angiochef.com, or by post at C/ Lepant 270, Bajos, 08013 Barcelona, Spain.