This Privacy Policy explains how the Super Smoothie Lab mobile application
(the "App") collects, uses, and protects your information. Super Smoothie Lab
is operated by an independent developer based in Portugal ("we", "us", or
"the operator"). By using the App you agree to the practices described
below.
1. Information we collect
We collect only what we need to run the App and the categories of data
you choose to provide.
Profile data: age, sex, height, weight, unit
preferences, timezone, and serving-size preferences.
Health and nutrition preferences: goals, diet types,
allergies, intolerances, likes, dislikes, and personalisation consent.
Recipe and app activity: favourites, custom
collections, generated or matched recipes, smoothie logs, streaks,
medals, and score history.
Weight tracking: weight entries and trend data,
where you choose to log them.
Community content: posts, comments, likes,
follows, blocks, reports, moderation status, and the version and date
of any policy you accept.
Subscription status: plan, platform, subscription
identifier, status, verification status, and renewal or expiry dates.
Support and contact data: any information you send
when you contact us for help.
Security and operations data: IP address, request
metadata, authentication and session logs, rate-limit events, and
webhook logs.
Photos you upload to the community: images you
attach to community posts. Image EXIF metadata (location, device)
is stripped before upload; the cleaned image is stored in our
object storage and shown to other community users.
Voice clips (Premium, optional): short audio
recordings (≤25 seconds) you submit through the voice ingredient
input. Audio is forwarded to OpenAI Whisper for transcription
then discarded — never written to our database, filesystem, or
logs. The resulting text transcript is parsed in memory and
also not persisted. Voice input is a Premium feature; we never
send audio for free or guest accounts.
Behavioural signals for personalisation:
anonymised in-app interactions (recipe impressions, opens,
favourites, dismisses, smoothie logs) used to improve our
recommendation engine. These signals are tied to your account
but are not shared with third parties and are not used for
advertising. You can disable them at any time in
Profile → Privacy → Personalisation & health data.
Crash and performance diagnostics: when our
diagnostics tool (Sentry) is enabled in a release build, the App
reports unhandled crashes and a small sample of performance
traces. These reports include a device/build identifier and a
stack trace; they do not include the contents of your smoothies,
recipes, or community posts.
We do not run third-party advertising in the App, we do
not use cross-app tracking, and we do not
sell personal data.
2. How we use information
To create your account, manage sessions, and let you delete your account.
To match recipes, normalise ingredients, personalise content, and
filter for safety against your declared allergies and intolerances.
To log smoothies and weight, compute scores, track progress and
streaks, and display history.
To enable community posting, commenting, reporting, blocking, and
moderation, and to prevent abuse.
To verify subscriptions and entitlements with the App Store or Play
Store.
To keep the service secure: rate limiting, fraud prevention,
debugging, and reliability.
To meet legal obligations and respond to lawful requests, privacy
requests, data exports, and account deletions.
3. Legal basis (GDPR)
If you are in the European Economic Area or the United Kingdom, our
legal bases under the GDPR / UK GDPR are:
Performance of a contract: running the account,
tracking, and subscription features you signed up for.
Legitimate interests: security, fraud prevention,
moderation, and improving the App. Our interests are balanced against
your rights and you can object at any time.
Consent: for personalisation, health-adjacent
profile data (age, sex, height, weight, goals, diet, allergies,
intolerances), optional voice input, and any feature where we ask
you explicitly. You can withdraw consent at any time in
Profile → Privacy → Personalisation & health data. Withdrawing
health-data consent clears the related fields from your account
without deleting the account itself; withdrawing personalisation
consent stops the App from using behavioural signals for
recommendations.
Legal obligation: when we must keep records to
comply with law (for example, fraud or abuse-related records).
4. Service providers we share data with
We use a small set of providers to operate the App. We share only the
data each one needs.
Crash and error reporting, and a small sample of performance traces (only when enabled in production builds)
EU
OpenAI — Moderation API
Automated content moderation of community posts and photos (never used for content generation or training)
Global
OpenAI — Whisper
Transcription of optional voice ingredient input. Audio is forwarded once for transcription and is not retained by us; OpenAI does not use API requests to train its models.
Global
RevenueCat
Cross-platform subscription verification, entitlement state, and receipt-to-account mapping
Global
Apple App Store / StoreKit
Subscription billing and verification (iOS)
Global
Google Play / Play Billing
Subscription billing and verification (Android)
Global
When you publish a community post, the post text and any uploaded
image are sent to OpenAI's Moderation API to detect harmful content
(violence, sexual content involving minors, severe harassment, and
similar categories). OpenAI does not use Moderation API requests to
train its models. We use this service under a legitimate-interest
legal basis (community safety) and rely on Standard Contractual
Clauses for any transfer outside the European Economic Area.
When you use voice ingredient input (a Premium feature), the
short audio clip is sent to OpenAI's Whisper API for transcription.
We do not retain the clip on our side — it lives only in the
in-memory request buffer and is discarded immediately after
transcription. OpenAI may retain the clip for up to 30 days for
abuse monitoring before deleting it, and does not use Whisper API
requests for model training. The same Standard Contractual Clauses
apply to any transfer outside the European Economic Area.
When you complete a purchase, the platform receipt and a
pseudonymous identifier are shared with RevenueCat so it can
confirm your subscription status with the App Store or Play Store
and unlock Premium features in the App. RevenueCat does not see
your name, email, or health data.
5. Data retention
We keep account data for as long as your account is active. When you
delete your account from the in-app Privacy section, we disable it
immediately and purge personal data after the configured retention
window. Some records (legal, financial, and abuse-related) may be
retained for as long as required by law or to enforce our rights.
Aggregated, anonymised metrics may be retained indefinitely.
6. Your rights
Subject to applicable law, you have the right to:
Access the personal data we hold about you.
Correct inaccurate personal data.
Export your data in a machine-readable format (use the in-app
"Export my data" feature).
Delete your account (use the in-app "Delete my account" feature).
Withdraw consent for personalisation, health-data processing,
or any other consent-based feature, from Profile → Privacy →
Personalisation & health data inside the App.
Object to processing based on legitimate interests.
Lodge a complaint with the Portuguese supervisory authority
(Comissão Nacional de Proteção de Dados, CNPD) or your local data
protection authority.
Some of our service providers process data outside the European
Economic Area. Where this is the case, we rely on European Commission
adequacy decisions or standard contractual clauses to ensure your data
is protected.
8. Children
You must be at least 13 years old to use the App. Community features
are restricted to users aged 18 or older. We do not knowingly collect
personal data from children under 13. If you believe a child has
provided personal data to us, please contact us so we can delete it.
9. Security
We use HTTPS for all traffic, hash passwords, encrypt traffic and
backups, rotate secrets, and rate-limit authentication. No system is
100% secure, but we treat your data with care and respond promptly to
any security incident that affects you.
10. Changes to this Policy
We may update this Privacy Policy from time to time. When we make
material changes, we will update the version and effective date above
and ask you to re-accept inside the App where the change requires it.