← Plant-Maxxing
Legal

Privacy Policy

Last updated: 9 July 2026 · Controller: Spot Cloud B.V., Netherlands

This Privacy Policy explains how Spot Cloud B.V. ("Spot Cloud", "we", "us", "our") collects, uses, and protects personal data when you use Plant-Maxxing, our web and iOS application, and any related services (together, the "Service"). We are the controller of your personal data within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").

We have designed Plant-Maxxing to collect as little personal data as possible while still providing a useful product. This policy is written in plain language so you can understand what we do. Where legal or technical terms matter, we use them precisely.

01Controller & contact

The controller responsible for your personal data is:

We have not appointed a data protection officer because we are not legally required to do so. For privacy questions, including requests to exercise your rights, email the address above and we will respond without undue delay and in any event within one month.

02Data we collect

We collect only the categories of personal data needed to run the Service:

Account data

User content

Subscription & billing data

Technical & usage data

We do not collect precise geolocation, advertising identifiers, contacts, photos from your camera roll (beyond the meal photo you choose to submit for a single analysis), or data from third-party trackers. We do not sell personal data.

We rely on the following lawful bases under Article 6 of the GDPR:

04Purposes of processing

We use your personal data to:

We do not use your personal data for profiling that produces legal or similarly significant effects about you, and we do not use it for advertising.

05Sub-processors

We rely on the following sub-processors to operate the Service. Each one is bound by a written agreement that requires GDPR-appropriate protection of personal data and limits processing to our instructions.

Sub-processor Purpose Approximate location
Cloudflare Hosting, edge delivery, D1 database storage, security and routing. EU edge nodes; global anycast network.
Featherless AI AI coach responses and weekly menu generation. May be processed outside the EU under safeguards.
Microsoft Graph Transactional email delivery (sign-in codes, account notices). May be processed outside the EU under safeguards.

Before engaging a new sub-processor or materially changing how an existing one is used, we will update this policy or notify you in the Service. You may object to a new sub-processor on reasonable data-protection grounds by contacting us at the email above.

Payment providers act as independent controllers, not sub-processors. Stripe (web checkout) and Google Play (Android purchases) process your payment data under their own privacy policies — the Stripe Privacy Policy and the Google Privacy Policy. We never receive your card details; we only receive confirmation of the purchase and a reference identifier that we store to link your account to your plan.

06International transfers

Because some of our sub-processors operate infrastructure that may process data outside the European Economic Area, your personal data may be transferred to, and processed in, countries that the European Commission has not fully recognised as providing an adequate level of protection.

Where that is the case, we only transfer personal data under appropriate safeguards, including the European Commission's Standard Contractual Clauses, supplementary measures where required, and sub-processor commitments that limit processing to our instructions. If you would like a copy of the relevant safeguards, you can request one by emailing us.

07Retention & deletion

We keep your personal data only for as long as your account is active, plus a limited period afterwards where we are required or permitted to keep specific records (for example, to investigate abuse or to meet accounting obligations).

When you delete your account through Profile → Delete account in the app, we erase your account data, User Content, meal log, scores, trends, preferences, coach memory, coach usage counters, and your subscription and entitlement records (including our reference to your payment-provider record). Records our payment providers must keep for legal or accounting reasons (such as invoices at Stripe) are retained by them for the legally required period. Deletion is irreversible. A small amount of data may remain in encrypted backups for a short period until those backups expire, after which it is also gone.

If you simply stop using the Service without deleting your account, we may retain your data for a reasonable period so that you can return to your history, after which we may deactivate or delete the account.

08Your rights

Under the GDPR you have the following rights, subject to limited exceptions provided by law:

09Exercising your rights

The fastest way to exercise most rights is directly in the app: you can edit your profile and preferences, view your meal log, and delete your account at any time from Profile → Delete account.

For access, portability, rectification you cannot make in-app, restriction, objection, or withdrawal of consent, email us at yair@cloudevolvers.com. We will verify your identity using reasonable means — typically by replying to the email address associated with your account — and respond without undue delay and within one month. That period may be extended by two further months where requests are complex or numerous; if so, we will explain why within the first month.

Using your rights is free of charge. We may charge a reasonable fee or refuse a request where it is manifestly unfounded or excessive, in particular because it is repetitive.

In short

We use only essential cookies — a single session cookie that keeps you signed in. We do not use advertising or third-party tracking cookies, and we do not sell your data.

10Cookies

Plant-Maxxing uses only essential cookies and equivalent storage. Specifically, we set a single authentication/session cookie that identifies your signed-in session so the Service works. This cookie is strictly necessary to provide the Service you requested and is therefore exempt from the requirement to obtain prior consent.

We do not use advertising cookies, social-media cookies, cross-site tracking cookies, or any third-party analytics that would require consent. If we ever introduce non-essential cookies or similar technologies, we will ask for your consent first, disclose them here, and let you withdraw consent at any time.

11Children

The Service is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected personal data from a child under 16, please contact us and we will delete it without undue delay.

12Lodging a complaint

If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the data protection authority in the EU member state where you live or work. We would prefer the chance to fix things directly, but you are not required to contact us before doing so.

13Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our sub-processors, or applicable law. If we make material changes, we will notify you in the Service or by email before the new policy takes effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Continuing to use the Service after changes take effect means you accept the updated policy. If you do not agree, you can delete your account as described above.

If you have any questions about this policy or about your personal data, contact us at yair@cloudevolvers.com.