Privacy Policy
Last updated 5 August 2026
This policy explains what personal data Momo collects, why we collect it, and the choices you have. [Company legal name] is the controller of that data.
Data we collect
Data you give us:
- Account details — email address and, if you sign in with Apple or Google, the identifier they return to us.
- Profile and goals — details such as height, weight, age, activity level, and dietary targets, which you choose to enter so we can personalise estimates.
- Meal photos and logs — the images you capture, the food entries derived from them, and any notes or corrections you add.
- Support messages — what you write to us, so we can reply.
Data collected automatically:
- Device and app data — device model, operating system version, app version, language, and time zone.
- Usage data — which screens and features you use and when, for diagnostics and product decisions.
- Crash and performance diagnostics.
- Purchase data — subscription status and receipt validation from Apple or Google. We never receive your full payment card details.
Some of this — your weight, dietary intake, and goals — is health-related and is treated as a special category of personal data under GDPR. We process it on the basis of your explicit consent, which you can withdraw at any time by deleting the data or your account.
How we use your data
- To provide the Service — analysing your meal photos, returning nutritional estimates, and keeping your history in sync across devices.
- To personalise your targets and the tips you see.
- To process subscriptions and verify entitlements.
- To provide support and respond to you.
- To keep the Service secure, prevent abuse, and debug problems.
- To improve the Service, using aggregated or de-identified data wherever it will do the job.
- To send service messages, and — only with your consent, and with an unsubscribe link in every message — product updates.
Under GDPR our legal bases are: performance of our contract with you (providing the Service), your consent (health data, marketing, optional analytics), our legitimate interests (security, abuse prevention, product improvement), and compliance with legal obligations.
How your meal photos are processed
When you photograph a meal, the image is sent to our servers and to the AI providers we use for image analysis, which return an estimate of the food and its nutritional content.
We do not sell your photos, and we do not use them to train third-party AI models. Our providers act as processors under contract and are not permitted to use your images to train their own models.
Photos are retained so you can review your history. You can delete any individual entry, or all of them, from within the app.
Who we share data with
We do not sell your personal data. We share it only with:
- Service providers acting on our instructions — cloud hosting, AI image analysis, crash reporting, analytics, and email delivery — each under a contract that limits them to our instructions.
- Apple and Google, for payment processing and subscription management.
- Authorities or other parties, where we are legally required to, or where it is necessary to establish or defend legal claims or protect someone's safety.
- An acquirer, if we are involved in a merger, acquisition, or sale of assets — we will give you notice before your data becomes subject to a different policy.
International transfers
We operate internationally, so your data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or an adequacy decision.
How long we keep it
We keep your account data for as long as your account is active. Meal logs and photos are kept until you delete them or delete your account.
When you delete your account we remove your personal data within 30 days, except where we must keep something longer to meet a legal obligation (for example, transaction records for tax purposes). Residual copies may persist in encrypted backups for up to 90 days before they age out.
Security
We encrypt data in transit with TLS and at rest, restrict internal access to those who need it, and review our practices regularly. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant regulator as the law requires.
Your rights
Wherever you live, you can access, export, correct, or delete your data from within the app, or by writing to us.
If you are in the EEA or UK, you also have the right to object to or restrict processing, the right to data portability, the right to withdraw consent at any time, and the right to lodge a complaint with your local data protection authority.
If you are in California, you have the right to know what personal information we collect and how we use and disclose it, the right to delete and correct it, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
To exercise any of these rights, contact [privacy@example.com]. We respond within 30 days and will not charge you for a reasonable request.
Automated decision-making
The nutritional estimates in the app are generated automatically, but they are informational only — they produce no legal or similarly significant effect, and you are always free to correct or ignore them.
Children
Momo is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact [privacy@example.com] and we will delete it.
Changes to this policy
We will update this page when our practices change, and revise the date at the top. If a change materially affects your rights, we will notify you in the app or by email before it takes effect.
Contact
Privacy questions and requests: [privacy@example.com]
[Company legal name], [Registered address]