Skip to privacy policy
meowl
Back to Meowl

Privacy at Meowl

Privacy Policy

This policy explains what Meowl collects, why it is used, when it is shared, and the choices available to you across the Meowl mobile app and website.

Effective date

The short version

Your data supports your experience.

Health is optional

Apple Health and Health Connect access requires your permission and can be revoked in device settings.

AI is transparent

Meal-planning inputs and relevant profile details are sent to a third-party AI service provider when you choose Meowl AI.

Sharing is controlled

Accepted friends can see selected progress and activity; photos can be friends-only or private.

No data sales

Meowl does not sell personal data. The free service uses Google AdMob, which may process ad data.

Who this policy covers

This Privacy Policy applies to the Meowl mobile application, meowl.app, and related services that link to it. Meowl operates from Türkiye and is the controller of the personal data described here, except where a third party acts as an independent controller under its own policy.

Meowl is a nutrition and fitness companion, not a medical service. This policy covers registered users, website visitors, and people whose information a user provides through optional features such as contact matching.

Personal data Meowl processes

The data collected depends on the features you use. Health, nutrition, activity, and allergy information can reveal sensitive details and is treated as health-related data where applicable.

  • Account and authentication: Firebase user ID, email address, authentication status, and, for Google Sign-In, the profile and email scopes you approve. Firebase handles passwords; Meowl does not receive your plain-text password.
  • Profile and goals: name, gender selection, date of birth, height, current and target weight, fitness goal and intensity, language, water target, optional hashed phone number, and an optional Deezer profile song.
  • Nutrition and wellness: foods, barcodes, meal type and date, serving information, calories and macronutrients, water logs, fasting schedules and history, workouts, notes, weight, calorie targets, progress statistics, streaks, XP, badges, and quests.
  • AI meal planning: chat messages, food and cuisine preferences, allergies or intolerances, generated plans and alternatives, fasting context, language, and AI usage counters.
  • Social and content: friend code, requests and relationships, name search, hashed contact numbers, nudges, activity feed events, progress photos, captions, visibility, likes, stories, and story viewer identifiers.
  • Technical and commercial data: device and platform type, Firebase Cloud Messaging token, notification choices, subscription entitlement and purchase status, local cache and preferences, and ordinary API, security, and diagnostic logs such as IP address, request time, route, and response status.

Camera, contacts, health platforms, and notifications

Optional device permissions are requested when a feature needs them. You can deny or later revoke a permission, although the related feature may stop working.

  • Apple Health and Health Connect: with permission, Meowl reads steps, active and total calories burned, recent weight, workouts, and nutrition totals. Current server sync stores daily summaries of steps, calories, weight, and workouts. Meowl may write logged meal nutrition and weight back to the health platform when write access is granted.
  • Data obtained from Apple Health or Health Connect is not sold, transferred to advertising platforms or data brokers, or used to serve or personalise ads.
  • Camera and photos: barcode images are analysed on the device; the decoded barcode is sent for product lookup. If you take or select a progress photo or story, the selected image and caption are uploaded to Meowl.
  • Contacts: with permission, phone numbers are normalised and SHA-256 hashed on your device. Meowl uploads and stores the hashes, not your contact names or raw address book numbers, to find matches. Hashing reduces direct exposure but does not make matching data anonymous.
  • Notifications: Meowl stores a device push token, platform, notification settings, and limited delivery records for friend requests, nudges, fasting events, and streak reminders. Local reminders and preferences may also remain on your device.

Purposes and legal bases

Meowl uses personal data only for the purposes below. Under GDPR and UK GDPR, the legal basis depends on the context and may be performance of a contract, consent, legitimate interests, or compliance with law. Where required, explicit consent is used for health data.

  • Provide accounts, calculate nutrition and progress targets, log meals, water, fasting and workouts, sync health summaries, and restore subscriptions.
  • Personalise dashboards, reminders, gamification, meal plans, food alternatives, language, and other requested features.
  • Enable friend discovery, accepted-friend activity, photos, stories, likes, nudges, and related notifications.
  • Authenticate requests, prevent abuse, enforce limits, troubleshoot failures, maintain service reliability, and protect users and Meowl.
  • Process purchases, show and measure ads in the free service, answer privacy requests, and meet legal obligations.

AI meal planning

Meowl AI is optional. When you start an AI session, Meowl sends a third-party AI service provider the conversation and the profile context needed to build a plan: name, age, gender, height, weight, goal, target weight, calorie and macro targets, relevant fasting schedule, language, food preferences, allergies or intolerances, and cuisine choices. Dish names may also be sent to that provider to generate meal images.

AI conversations, tool selections, pending plans, generated plans, and usage counters are stored on Meowl servers. Avoid entering information that is not needed for meal planning. AI output may be inaccurate and is not medical diagnosis or treatment; consult a qualified professional for medical or allergy advice.

  • Google processes AI inputs and outputs under its service terms and privacy commitments.
  • Accepted plans are saved to your account; a current plan can be deleted in the app.
  • AI data is not automatically shared with friends unless you separately log or share resulting activity.

What other users can see

Meowl includes social features. Your name, level, and friend code can appear in authenticated user search and contact-match suggestions. A friend relationship requires a request and acceptance, but you should only connect with people you know.

  • Accepted friends can see your name, level, XP, streaks, badges, profile song, daily calorie total, meal count, water progress, and feed events such as a logged meal type, streak milestone, level, or water goal.
  • Progress photos marked friends-only, captions, like counts, and recent stories are visible to accepted friends. Private progress photos are visible only to you. Story viewer IDs are recorded to show seen status.
  • Removing a friend stops future friend-only access, but it cannot retract information the other person already saw, saved, or captured.
  • Do not upload another person’s photo or personal information without permission. Meowl does not currently promise automated moderation of every upload.

Who receives data

Meowl does not sell personal data. Data is disclosed only as needed to provide features, run the service, meet legal duties, or complete a transaction. Relevant recipients include:

  • Google Firebase for authentication and Cloud Messaging; Google Sign-In for optional login; and a third-party AI service provider for AI meal planning and meal imagery.
  • Google AdMob for banner and rewarded advertising in the free service.
  • RevenueCat and Apple App Store or Google Play for subscriptions, purchases, receipts, and entitlement management.
  • Apple Health and Health Connect when you direct Meowl to read from or write to those platforms.
  • Deezer when you search for or play a profile song; Deezer receives search terms or track requests and returns track metadata and preview links.
  • Hosting, database, caching, network, and security providers that operate the Meowl API and its infrastructure under contractual or confidentiality obligations.
  • Other users as described in the social section, and authorities or advisers when disclosure is legally required or reasonably necessary to protect rights, safety, and the service. Data may also transfer in a merger or business reorganisation subject to applicable law.

Advertising, analytics, and crash reporting

The free service uses Google AdMob banner and rewarded ads. Google may process device or advertising identifiers, IP-derived approximate location, ad interactions, diagnostics, and related data to deliver, limit, secure, and measure ads. Depending on settings and applicable law, ads may be personalised; such processing may be considered targeted advertising or “sharing” in some US states.

As of the effective date, the Meowl app does not integrate a dedicated Firebase Analytics or Firebase Crashlytics SDK, and the backend does not initialise a dedicated Sentry service. Meowl still processes ordinary API and security logs, and its providers may generate their own operational diagnostics.

Meowl does not sell personal data. You can use operating-system advertising controls and contact [email protected] to exercise an applicable opt-out right. A subscription may remove or reduce advertising as described in the app.

How long data remains

Meowl retains data while your account is active and for as long as reasonably needed for the purpose collected, security, dispute handling, and legal obligations. The current app does not provide a single in-app control that erases the entire account, so request full account deletion at [email protected].

  • Stories are configured to expire about 24 hours after posting. Friends-only and private progress photos remain until you delete them or request account deletion.
  • Meals, water, workouts, fasting records, progress, gamification, friend records, AI sessions and plans, and contact hashes may remain with the account unless a feature-specific delete action exists or you request deletion.
  • Push tokens are removed on sign-out when possible and stale tokens reported by Firebase are deleted. Some local caches and preferences remain on the device until sign-out cleanup, app data clearing, or uninstall.
  • Security, transaction, and legal records may be retained longer where needed. Deleted data may remain temporarily in restricted backups until those backups rotate.
  • When data is no longer required, Meowl aims to delete or de-identify it, subject to technical and legal constraints.

Where data is processed

Meowl operates from Türkiye and uses providers with infrastructure and personnel in multiple countries, including Google, RevenueCat, Apple, and platform or infrastructure providers. Your data may therefore be processed outside your country, the EEA, or the United Kingdom.

Where transfer rules apply, Meowl relies on an available lawful transfer mechanism, such as an adequacy decision, standard contractual clauses, or another permitted safeguard, together with technical and organisational measures appropriate to the transfer.

How Meowl protects data

Meowl uses measures designed to protect data, including Firebase ID-token verification for API access, HTTPS service endpoints, access controls, input limits, security headers, masked logging of push tokens, and on-device hashing before contact matching.

No online service can guarantee absolute security. Keep your account credentials private, review friend requests carefully, and contact [email protected] if you suspect unauthorised access. Meowl may need to verify identity before acting on a security or rights request.

Age and child safety

Meowl is not intended for children under 14, and the current onboarding date picker is designed for users aged 14 or older. If local law requires a higher age to consent to online or health-data processing, a parent or guardian must authorise and supervise use. Do not create an account if you cannot lawfully consent.

Social, photo, health, advertising, and AI features deserve particular care for young users. Minors should connect only with people they know, avoid sharing identifying images or sensitive details, and involve a parent or guardian in health goals. A parent or guardian can request review or deletion at [email protected].

  • Meowl does not knowingly permit use by children under 14.
  • If Meowl learns that data was collected from an ineligible child, it may restrict the account and delete the data where required.
  • Users must have permission before uploading content that identifies a child or another person.

Access, deletion, consent, and controls

Depending on where you live, you may have rights to know or access data, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a data protection authority. UK and EEA rights are subject to GDPR or UK GDPR conditions and exceptions.

Residents of California and other US states may also have rights to know, access, correct, delete, obtain portability, opt out of sale, sharing, or targeted advertising, limit certain uses of sensitive data, and receive no discriminatory treatment for exercising a right. Meowl does not sell personal data.

  • Email [email protected] from your account email and describe your request. Meowl may verify your identity and an authorised agent’s authority.
  • Revoke Apple Health or Health Connect access in platform settings; previously synced summaries must be deleted separately.
  • Change notification preferences in Meowl and device settings, and revoke camera, photo, contact, or notification permissions in the operating system.
  • Use private photo visibility, remove friends, delete eligible photos or meal plans, and avoid optional contact matching or Meowl AI.
  • Use device-level advertising privacy controls and contact Meowl for a legally applicable targeted-advertising or sharing opt-out.

Policy updates and privacy contact

Meowl may update this policy as features, providers, or legal requirements change. A new effective date will be posted here, and a more prominent notice will be used when a change materially affects your rights or the way personal data is used.

For questions, complaints, child-safety concerns, account deletion, or any privacy request, email [email protected]. Include enough detail to identify the account and request, but do not email passwords, full authentication tokens, or unnecessary health information.