Legal

Privacy Policy

Last updated: 11 February 2026

1

Introduction

Brefast (“we”, “us”, or “our”) is a meal planning application operated from the United Kingdom. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service.

We are the data controller for your personal data. If you have any questions about this policy or how we handle your data, please contact us at support@brefast.com.

2

Data We Collect

Account Data

When you create an account, we collect:

  • Email addressUsed for authentication (passwordless login via one-time codes)

Profile Data

You may optionally provide:

  • NameYour display name
  • AvatarA profile picture URL

Nutrition Data

To use the meal planning features, you configure:

  • Daily calorie targetYour daily energy goal
  • Macro percentagesProtein, carbohydrates, and fat distribution

Content Data

You create and store:

  • ProductsFood items with nutritional information
  • MealsCombinations of products
  • Weekly plansYour meal schedule

Feedback Data

When you submit feedback through the app, we collect:

  • MessageThe text of your feedback (up to 1,000 characters)
  • Page pathThe page you were on when you submitted feedback
  • App versionThe version of Brefast at the time of submission

Feedback is associated with your account and may be reviewed by our team alongside your email address and display name.

Technical Data

We automatically collect:

  • Usage analyticsPage views and feature usage via Fathom Analytics (privacy-focused, no personal data)
3

How We Use Your Data

PurposeData Used
Provide the serviceAccount, profile, nutrition, and content data
Authenticate youEmail (to send one-time login codes)
Improve the appAnonymised usage analytics and user feedback
Respond to requestsEmail (for support and deletion requests)
We do not: sell your data, create advertising profiles, or send marketing emails.
5

Third-Party Services

We use the following third-party services:

Supabase

Purpose
Authentication and database storage
Data shared
All user data
Location
European Union

Open Food Facts

Purpose
Product data import (when you search for products)
Data shared
Search queries only
Location
European Union

Fathom Analytics

Purpose
Privacy-focused usage analytics
Data shared
No personal data (Fathom does not use cookies or track individuals)
Location
European Union

When we introduce paid features in the future, we will update this policy to include our payment processor.

6

Data Retention

Data TypeRetention Period
Account and content dataUntil you request deletion
Feedback data1 year from submission, or upon account deletion
Analytics dataAggregated only, no personal data retained
Server logs30 days
7

Your Rights

GDPR Rights (All Users)

Under the General Data Protection Regulation, you have the right to:

  • AccessRequest a copy of your personal data
  • RectificationCorrect inaccurate data
  • ErasureRequest deletion of your data (“right to be forgotten”)
  • PortabilityReceive your data in a portable format
  • ObjectObject to processing based on legitimate interest
  • ComplaintLodge a complaint with the UK Information Commissioner's Office (ICO)

CCPA Rights (California Residents)

Under the California Consumer Privacy Act, you have the right to:

  • KnowWhat personal information we collect and how it's used
  • DeleteRequest deletion of your personal information
  • Non-discriminationWe will not discriminate against you for exercising these rights

Note: We do not sell personal information, so the “opt-out of sale” right does not apply.

How to Exercise Your Rights

To exercise any of these rights, please contact us at support@brefast.com. We will respond to your request within 30 days.

8

Security

We protect your data through:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest (database-level encryption)
  • Secure hosting infrastructure (Supabase, EU region)
  • Passwordless authentication (reducing credential theft risk)
9

Age Requirement

Brefast is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from someone under 18, please contact us immediately at support@brefast.com.

10

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via email or an in-app notification. The “Last updated” date at the top of this page indicates when the policy was last revised.

11

Contact Us

For privacy-related questions or to exercise your rights, please contact us at: