Privacy Notice
Last updated: May 3, 2026
This Privacy Notice explains how Elazar Shlomo ("we", "us") — operating PlateAI (the "Service") — collects, uses, shares, and protects your personal data. We act as the data controller (or "Responsible Party" under POPIA) for personal data processed in connection with the Service.
1. Personal data we collect
- Account data — name, email address, login credentials (processed via Supabase Auth).
- Profile & preferences — dietary preferences, household size, saved recipes, and meal plans.
- Support communications — messages sent when contacting support.
- Usage & technical data — IP address, browser type, device identifiers, and basic telemetry needed for service operation, security, and improvement.
- Payment data — Card details and billing addresses are collected directly by Paddle (our Merchant of Record) and are never stored on our servers.
2. Why we use your data
- To provide the Service — Creating accounts and generating AI meal plans (Performance of Contract).
- Processing payments — Handled via Paddle (Performance of Contract).
- AI Generation — We share your dietary preferences with AI providers (e.g., Google, OpenAI) to generate your plans. Your personal identifiers (like email) are not shared with these AI providers for plan generation.
- Security & Legal — Fraud prevention (Legitimate Interests) and tax/accounting compliance (Legal Obligation).
3. Who we share data with
- Infrastructure — Supabase and Lovable Cloud for hosting and database management.
- AI Providers — Google or OpenAI for processing meal plan requests.
- Merchant of Record — Paddle, for billing, tax compliance, and refunds.
- Authorities — Only where required by law or to protect rights, property, or safety.
4. International transfers
PlateAI is operated from South Africa. Your data may be stored or processed in countries outside your own (including the USA or EU) where our infrastructure providers are located. We ensure appropriate safeguards (such as Standard Contractual Clauses) are in place to protect your data during these transfers.
5. Your rights
Depending on your location (e.g., South Africa, UK, or EEA), you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing.
To exercise these rights, contact supportgetplateai@gmail.com.
South African Users: You have the right to lodge a complaint with the Information Regulator at enquiries@inforegulator.org.za.
6. Retention & Security
We keep personal data for as long as your account is active and for a reasonable period afterward to comply with legal obligations. We use encryption in transit (SSL/TLS) and managed database security to protect your information. While no system is perfectly secure, we work to minimize risk.
7. Cookies & Analytics
We currently use only strictly necessary cookies to keep you signed in. If we implement analytics tools (like Google Analytics) in the future to improve the Service, we will update this notice and provide a way for you to manage your consent.
8. Changes
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email.
9. Contact
Questions about this notice or your data can be sent to supportgetplateai@gmail.com or through the in-app support channel.