Draft — pending legal review

This document is a working draft. It describes how Palato works today, but it has not yet been reviewed by a lawyer and will be finalized before public launch.

Privacy Policy

Palato (working title) · Version 2026-07-26 · Last updated July 26, 2026

1. What this policy covers

Palato stores health-adjacent information — what you eat, your weight, your goals. We treat all of it as sensitive. This policy explains what we collect, why, where it lives, and the rights you have over it. The short version: your data is used to run the app for you, it is never sold, and you can export or permanently delete it yourself at any time.

2. Information we collect

Account data: email address, display name, password (stored only as a salted cryptographic hash — we cannot read it), and optional Google sign-in identifiers.

Profile & health data: your goal, diet profile, declared allergies and intolerances, units, optional body stats, calorie/macro targets, meal logs, weight logs, and step logs. Some of this (allergies, weight, dietary restrictions) is sensitive health information, and we treat it that way.

Photos: meal, progress, and profile (avatar) photos you choose to upload. They are stored as private objects and served only to you, unless you attach a photo to a community post you publish. You can remove them at any time.

AI coach conversations: messages between you and your coach, plus rolling memory summaries. These are private to your account — never shown to other users, never used to train models, and deletable by you.

AI provider keys (BYOK): if you choose to bring your own AI provider key, we store it encrypted and use it only to send your own prompts to the provider you selected. Your key is never shown back to you in full, never shared with other users, and never sent to any provider other than the one you chose. See section 6.

Community content: recipes, reviews, posts, comments, and reactions you choose to publish, and any reports you file about other content. Published content is public within the app by design. See section 8.

Payment data: if you subscribe, our payment processor (Stripe) handles your card details directly — we never see or store your card number. We keep a record of your subscription tier, status, and a processor reference so we can grant the right features and issue receipts.

Notifications & devices: if you enable push notifications or reminders, we store the technical subscription needed to deliver them (a browser push endpoint or a mobile device token) and your notification preferences. You can turn these off at any time, which removes the subscription.

Usage events: lightweight product events (for example “signed up”, “logged a meal”) used to understand feature usage. These events are content-free — they never contain the contents of your logs, no calorie values, weights, food names, photos, or messages.

3. How we use it

To provide the Service: personalizing suggestions, computing your analytics, powering the AI coach, screening suggestions against your declared allergies, processing subscriptions, delivering notifications you asked for, and sending transactional email such as verification and account notices. We do not sell your personal data, and we do not use your private health data for advertising.

4. Where your data lives

Data is stored on Cloudflare’s platform: a database for your records, object storage for your photos, and a session store for keeping you logged in — all encrypted at rest and in transit. Every query for your data is scoped to your account on the server, so one user can never read another’s private data.

5. Service providers

We share the minimum data needed with processors that run parts of the Service:

Cloudflare (hosting, database, photo storage); Stripe (payments — card details go directly to Stripe, we never see them); Anthropic (the house AI model behind the coach, via a gateway; your prompts are processed to generate a reply and are not used for model training); Google (maps/places for restaurant discovery, and optional sign-in); Nutritionix and USDA FoodData Central (nutrition lookups — your food queries, not your identity); and Postmark (transactional email delivery).

Bring-your-own AI providers. If you connect your own AI key, the prompts you send to the coach go to the provider you chose (for example OpenAI, Anthropic, or another supported provider) under their privacy terms, using your own key. We facilitate that call; we do not add your data to any house model. [Placeholder — final processor list and data-processing agreements to be confirmed at legal review.]

6. Your AI provider key (BYOK)

You can optionally connect your own AI provider key so the coach runs on your account with the provider you pick. When you do:

Your key is encrypted before it is stored and is only decrypted server-side at the moment it is needed to call your chosen provider. It is never displayed back to you in full, never sent to any other provider, never shared with other users, and never included in analytics or logs. You can disconnect it at any time from your Account, which deletes the stored key. Charges for calls made with your own key are billed by your provider to you, under their terms.

7. Your rights: export and deletion

From your Account page, at any time and without asking us, you can:

Download your data — a complete JSON export of everything the app stores about you: profile, logs, lists, plans, recipes, posts, coach conversations, and more.

Delete your account — permanently removes your personal data (profile, logs, coach history, sessions). You choose whether your public community content is deleted too or kept anonymously attributed to “Deleted user”. Deletion is immediate and cannot be undone. Payment transaction records are retained where required for bookkeeping and fraud prevention; they contain no health data.

This is intended to satisfy the spirit of GDPR and CCPA data rights. [Placeholder — formal legal-basis mapping at legal review.]

8. Community content, moderation & reporting

Content you publish to the community (posts, reviews, finds, comments, reactions, and any attached photos) is visible to other users by design. Your private data — logs, weight, goals, allergies, and coach conversations — is never published as a side effect of posting.

To keep the community safe we operate moderation. You can report content you believe breaks the rules; a report records the item, your reason, and that you reported it, and it enters a moderation queue our team reviews. We may remove content, and we may restrict or suspend accounts that violate the rules. Reports and moderation decisions are retained so we can enforce consistently and handle appeals.

9. Notifications

Notifications and reminders are off until you turn them on. When you enable push, we store the technical subscription needed to deliver it (a browser push endpoint or a mobile device token) and your preferences (categories, quiet hours). Turning notifications off, or revoking permission in your browser or device, removes the subscription. Transactional emails (such as email verification) are separate and are sent because they are necessary to run your account.

10. Cookies and sessions

We use a single essential session cookie to keep you logged in, plus a small cookie remembering your chosen theme. We do not use third-party advertising or cross-site tracking cookies. Our product analytics are content-free (section 2) and are tied to your account server-side, not to advertising networks.

11. Data retention

We keep your data for as long as your account is active so the Service works for you. When you delete your account, your personal data is removed immediately (section 7). Some records are kept longer where we must: payment and tax records for the period required by law; moderation records needed to enforce the rules and handle appeals; and short-lived security records such as rate-limit counters and expiring verification tokens, which age out automatically. Content-free usage events may be retained in aggregate to understand product health. [Placeholder — specific retention periods to be confirmed at legal review.]

12. Age requirement

The Service requires users to be 17 or older. We do not knowingly collect data from anyone younger; accounts found to belong to minors will be deleted.

13. Changes and contact

We will announce material changes to this policy in the app before they take effect, and update the version stamp at the top of this page so you can tell which revision you are reading. [Placeholder — data controller identity and contact email to be added before launch.]