Privacy Policy
This Privacy Policy explains how Spot Cloud B.V. ("Spot Cloud", "we", "us", "our") collects, uses, and protects personal data when you use Plant-Maxxing, our web and iOS application, and any related services (together, the "Service"). We are the controller of your personal data within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").
We have designed Plant-Maxxing to collect as little personal data as possible while still providing a useful product. This policy is written in plain language so you can understand what we do. Where legal or technical terms matter, we use them precisely.
01Controller & contact
The controller responsible for your personal data is:
- Spot Cloud B.V., a private company with limited liability incorporated in the Netherlands.
- Contact: yair@cloudevolvers.com
We have not appointed a data protection officer because we are not legally required to do so. For privacy questions, including requests to exercise your rights, email the address above and we will respond without undue delay and in any event within one month.
02Data we collect
We collect only the categories of personal data needed to run the Service:
Account data
- Email address (used to identify your account and send transactional messages).
- Display name, where provided by you or by your sign-in provider.
- Sign-in method, such as Apple, Google, Microsoft, Discord, or email one-time code. We do not receive your password from any sign-in provider.
User content
- Meal photos, text descriptions of meals, and any notes you add.
- Computed protein scores, amino-acid breakdowns, meal log entries, and trends.
- Preferences you set, such as dietary preferences or goals.
- Coach chat messages and the memory the AI coach keeps to make its responses more useful to you.
- Generated weekly menu suggestions.
Subscription & billing data
- Your plan and entitlement status (for example free, Plus, or lifetime) and how it was obtained (web checkout or Google Play).
- A reference to your customer or purchase record at our payment providers (Stripe and Google). We never receive or store your card number — payment details are handled entirely by the payment provider.
- Coach usage counters (how many coach messages you send per day), kept to apply the free-tier limit fairly.
Technical & usage data
- Authentication and session identifiers necessary to keep you signed in.
- Basic request metadata such as timestamps, approximate country (derived from IP at the edge for routing and security), device type, and app version.
- Error and abuse logs kept for a short period to keep the Service stable and secure.
We do not collect precise geolocation, advertising identifiers, contacts, photos from your camera roll (beyond the meal photo you choose to submit for a single analysis), or data from third-party trackers. We do not sell personal data.
03Lawful bases
We rely on the following lawful bases under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)). We process account data, User Content, and session data to provide the Service you requested when you create an account and submit meals. We also process your subscription and entitlement data to deliver the plan you purchased.
- Consent (Art. 6(1)(a)). Where we ask for optional data or for any processing that is not necessary for the core Service — for example, optional preferences that are not required to use the app — we rely on your consent. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legitimate interests (Art. 6(1)(f)). We process limited technical and usage data, and keep short-lived security logs, to prevent abuse, secure the Service, fix bugs, and make reasonable improvements. We also process coach usage counters to apply free-tier plan limits fairly. Our legitimate interest is operating a stable, safe, and sustainable product. This does not override your rights and interests, and we keep this processing minimal.
- Legal obligations (Art. 6(1)(c)). Where we are required to retain or disclose data by applicable law — for example, tax or accounting records, billing and payment records, or a lawful request from an authority — we process that data to comply. Our payment providers retain invoices and other payment records for the periods they are legally required to keep.
04Purposes of processing
We use your personal data to:
- create, maintain, and secure your account;
- analyse meal photos and text, compute protein and amino-acid estimates, and display results;
- store your meal log, trends, preferences, and coach memory so the Service works across sessions;
- generate weekly menu suggestions and AI coach responses tailored to your account;
- process purchases, deliver your plan and entitlements, and apply plan limits such as the free-tier coach message counter;
- send transactional messages such as sign-in codes and important account or legal notices;
- monitor performance, prevent fraud and abuse, and respond to incidents;
- comply with legal obligations.
We do not use your personal data for profiling that produces legal or similarly significant effects about you, and we do not use it for advertising.
05Sub-processors
We rely on the following sub-processors to operate the Service. Each one is bound by a written agreement that requires GDPR-appropriate protection of personal data and limits processing to our instructions.
| Sub-processor | Purpose | Approximate location |
|---|---|---|
| Cloudflare | Hosting, edge delivery, D1 database storage, security and routing. | EU edge nodes; global anycast network. |
| Featherless AI | AI coach responses and weekly menu generation. | May be processed outside the EU under safeguards. |
| Microsoft Graph | Transactional email delivery (sign-in codes, account notices). | May be processed outside the EU under safeguards. |
Before engaging a new sub-processor or materially changing how an existing one is used, we will update this policy or notify you in the Service. You may object to a new sub-processor on reasonable data-protection grounds by contacting us at the email above.
Payment providers act as independent controllers, not sub-processors. Stripe (web checkout) and Google Play (Android purchases) process your payment data under their own privacy policies — the Stripe Privacy Policy and the Google Privacy Policy. We never receive your card details; we only receive confirmation of the purchase and a reference identifier that we store to link your account to your plan.
06International transfers
Because some of our sub-processors operate infrastructure that may process data outside the European Economic Area, your personal data may be transferred to, and processed in, countries that the European Commission has not fully recognised as providing an adequate level of protection.
Where that is the case, we only transfer personal data under appropriate safeguards, including the European Commission's Standard Contractual Clauses, supplementary measures where required, and sub-processor commitments that limit processing to our instructions. If you would like a copy of the relevant safeguards, you can request one by emailing us.
07Retention & deletion
We keep your personal data only for as long as your account is active, plus a limited period afterwards where we are required or permitted to keep specific records (for example, to investigate abuse or to meet accounting obligations).
When you delete your account through Profile → Delete account in the app, we erase your account data, User Content, meal log, scores, trends, preferences, coach memory, coach usage counters, and your subscription and entitlement records (including our reference to your payment-provider record). Records our payment providers must keep for legal or accounting reasons (such as invoices at Stripe) are retained by them for the legally required period. Deletion is irreversible. A small amount of data may remain in encrypted backups for a short period until those backups expire, after which it is also gone.
If you simply stop using the Service without deleting your account, we may retain your data for a reasonable period so that you can return to your history, after which we may deactivate or delete the account.
08Your rights
Under the GDPR you have the following rights, subject to limited exceptions provided by law:
- Access. You can ask what personal data we hold about you and receive a copy.
- Rectification. You can ask us to correct inaccurate or incomplete personal data. Most data (display name, preferences, meal notes) you can edit directly in the app.
- Erasure. You can ask us to delete your personal data, or do it yourself via Profile → Delete account.
- Restriction. You can ask us to limit processing in certain circumstances, for example while we verify the accuracy of data.
- Data portability. You can receive certain personal data you provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller.
- Objection. You can object to processing that relies on our legitimate interests or that is for direct marketing (we do not do direct marketing).
- Withdrawal of consent. Where processing relies on your consent, you can withdraw it at any time without giving a reason.
- Right not to be subject to a decision based solely on automated processing. The Service produces informational scores and suggestions, but we do not make binding decisions about you based solely on automated processing that produces legal or similarly significant effects.
09Exercising your rights
The fastest way to exercise most rights is directly in the app: you can edit your profile and preferences, view your meal log, and delete your account at any time from Profile → Delete account.
For access, portability, rectification you cannot make in-app, restriction, objection, or withdrawal of consent, email us at yair@cloudevolvers.com. We will verify your identity using reasonable means — typically by replying to the email address associated with your account — and respond without undue delay and within one month. That period may be extended by two further months where requests are complex or numerous; if so, we will explain why within the first month.
Using your rights is free of charge. We may charge a reasonable fee or refuse a request where it is manifestly unfounded or excessive, in particular because it is repetitive.
We use only essential cookies — a single session cookie that keeps you signed in. We do not use advertising or third-party tracking cookies, and we do not sell your data.
10Cookies
Plant-Maxxing uses only essential cookies and equivalent storage. Specifically, we set a single authentication/session cookie that identifies your signed-in session so the Service works. This cookie is strictly necessary to provide the Service you requested and is therefore exempt from the requirement to obtain prior consent.
We do not use advertising cookies, social-media cookies, cross-site tracking cookies, or any third-party analytics that would require consent. If we ever introduce non-essential cookies or similar technologies, we will ask for your consent first, disclose them here, and let you withdraw consent at any time.
11Children
The Service is not intended for children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected personal data from a child under 16, please contact us and we will delete it without undue delay.
12Lodging a complaint
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the data protection authority in the EU member state where you live or work. We would prefer the chance to fix things directly, but you are not required to contact us before doing so.
- Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
13Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our sub-processors, or applicable law. If we make material changes, we will notify you in the Service or by email before the new policy takes effect. The "Last updated" date at the top of this page indicates when the policy was last revised. Continuing to use the Service after changes take effect means you accept the updated policy. If you do not agree, you can delete your account as described above.
If you have any questions about this policy or about your personal data, contact us at yair@cloudevolvers.com.