Privacy Policy
Last updated: 18 August 2026
DRAFT — wording must be ratified by legal counsel before publication
Product analytics notice
This text is a draft for legal review. It describes the ratified values for product analytics under the purpose product_analytics_v1.
Controller and contact details
Controller: Smaklig Labs AB. Contact for data protection matters: Smaklig Labs AB. Data protection officer, if applicable: to be determined in the lawyer-ratified version.
Why we process the information
We process limited information about how Smaklig's core features are used to measure usage, understand whether features work as intended, and improve the service. The purpose is product analytics (product_analytics_v1). The legal basis is our legitimate interest in developing and assuring the quality of Smaklig.
Information, sources, and recipients
Product analytics covers pseudonymous account and session references, event type, time, platform, app or web version, and strictly limited information such as screen name, block type, or action type. The information comes from your use of Smaklig's web or mobile app and from server events when a core feature is completed. Chat, recipe and search content, allergies, health data, raw URLs, and other free-text fields are not included.
Recipients are limited to authorized Smaklig personnel and the processors needed to operate the analytics flow: Vercel for hosting and server functions, and Neon for database operations. The information is not used for advertising and is not sold.
Pseudonymization, layers, and retention
The information is pseudonymous, not anonymous, in layers 1 and 2 and remains personal data there. Raw events and ended sessions in layer 1 are retained for 90 days. Delivered or permanently failed outbox records are retained for 30 days. Dependency-bound material in layer 2 is purged once the analytics family it feeds is sealed and is retained for no longer than 90 days.
Layer 3 contains anonymous statistics only after the full k=10 policy has passed: results are not released if a group may contain fewer than ten people. Approved anonymous results in layer 3 are retained for 13 months from the end of the analytics family period. Results that have already been anonymized cannot be linked back to you and are therefore not affected by a later objection or erasure.
Your right to object
You have the right to object to the processing at any time under Article 21 of the GDPR. Use the Product analytics card in account settings and choose “Object and turn off”. New product analytics will stop, and identifiable analytics information will be deleted or remain blocked while cleanup is completed. You will not lose access to any other Smaklig features.
If you later withdraw your objection, measurement starts from that point forward. Previously deleted information is not recreated.
Other rights and complaints
Depending on the circumstances, you may request access, rectification, erasure, restriction, and data portability. Contact Smaklig Labs AB to exercise a right. If you believe that we process your personal data incorrectly, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
1. Controller and contact
Smaklig is currently operated by its founder, Alexander Eriksson. The operation will shortly move to a registered company; the controller's identity and company registration number will be updated here when the transition is complete. Postal address: Kungsgatan 64, 111 22 Stockholm, Sweden.
No data protection officer has been appointed during the transition. If one is appointed, their contact details will be added here. Until then, all data-protection questions can be sent to hello@smaklig.app.
2. Scope and where data comes from
This policy applies to Smaklig's web app, mobile app, APIs, and connected features. Data mainly comes from you and your use of the service and, when you connect a feature yourself, from your device, Google or Apple, Stripe, and your chosen grocery retailer. Account and sign-in data is needed for the service; profile, health, marketing, camera, photo-library, Apple Health, and Health Connect features are optional. Declining health consent leaves a basic mode without personalized health processing.
3. Personal data we process
Account, profile, and household: Name, email, profile image, language, verification and session data, sign-in provider, date of birth, country, household, budget, food preferences, equipment, chosen stores, and pantry.
Health and nutrition: Height, weight, body fat, goals, nutrition targets, allergies and intolerances, food log, meals, training data, injuries or limitations, activity, and alcohol preferences. This may be health data under GDPR Article 9.
Apple Health and Health Connect: Apple Health and Health Connect are optional activity sources. If you connect Apple Health on iPhone, Smaklig reads daily steps and active calories from up to the last 30 days available through your Apple Health access. If you connect Health Connect on Android, Smaklig may also read exercise time. For each synced day, Smaklig stores the daily values, selected source type, device read time, and server sync time in your personal account. For Apple Health, Smaklig stores no identifiers for apps or devices that contributed to the total.
The daily values are stored on Smaklig’s server while the account and selected connection are active. They are used for an activity-adjusted daily budget and, when the applicable consents are active, to personalize sous-chef responses through Google Gemini. They are not used for advertising or tracking.
Apple Health has a separate explicit consent from Android Health Connect. Disconnecting one source withdraws only that source’s consent and deletes only that source’s stored daily values. Manage Apple’s read permission separately in Settings or Apple Health. Account deletion removes all activity sources, while consent history is handled as described in the policy’s retention section.
Content and use: AI conversations and generated content, recipes, menus, food logs, favourites, notes, meal plans, shopping lists, checked items, retailer matches, and choices you make in the service.
Images and payments: Meal, receipt, and product images, barcodes, and derived analysis results when you use those features. For payments, Smaklig stores customer, subscription, and status IDs; Stripe handles card details.
Consent, communication, and security: Your health, analytics, and email choices with time and policy version; delivery status and unsubscribe information; IP address or hashed IP, device and browser data, error and usage events, feedback, and security and admin audits.
Locally on mobile: Sign-in data and feature choices, shopping/cart state, unfinished scans, and last sync time may be stored in SecureStore or AsyncStorage on your device.
4. Health data and explicit consent
We process health data for the personalized nutrition, allergy, activity, and training features you choose. Processing is based on providing the feature you request under Article 6(1)(b) and on your explicit consent under Article 9(2)(a). Apple Health, Health Connect, and food logging have their own choices and deletion flows.
You can accept, decline, or withdraw in the relevant feature or through hello@smaklig.app. Withdrawal does not affect processing that was already lawful. Personalized health features may then be disabled, but the service's basic mode should remain available.
5. Purposes and legal bases
Contract — Article 6(1)(b): Create and secure an account and provide the chat, recipes, menus, food log, shopping lists, household collaboration, retailer matching, and payment that you request.
Consent — Articles 6(1)(a) and 9(2)(a): Optional health features, Apple Health, Health Connect, certain food-log features, marketing email, and non-essential Google Analytics. Device permission is also requested when camera, photo library, Apple Health, or Health Connect is used.
Legitimate interests — Article 6(1)(f): Protect the service, prevent abuse, troubleshoot, keep limited security and admin logs, and handle voluntary feedback. You may object to this processing.
Legal obligation — Article 6(1)(c): We may need to retain limited information for accounting, regulatory requests, or legal claims.
6. AI and personalization
Google Gemini is Smaklig's primary AI provider. To create the response you request, we may send the relevant instruction, conversation history, recipe or menu, retailer material, profile choices, consented health and allergy context, or an image to Gemini. We limit the material to the feature.
Conversations and generated content are stored in the service. Limited AI logs are used for operations and safety. AI responses are recommendations and estimates, not medical advice. For the paid Gemini API, Google states that prompts and responses are not used to improve Google's products. The contractual and billing tier the production project falls under is currently being finalized.
7. Recipients and service providers
Operations: Neon for the PostgreSQL database in Frankfurt and Vercel for hosting, server functions, files, and web analytics.
AI and analytics: Google for Gemini, Google Analytics 4 when enabled, and Google sign-in when you choose it.
Email, payment, and security: Resend for email, Stripe for payment and subscriptions, and Upstash Redis for abuse prevention.
Sign-in and device: Apple for Sign in with Apple when you choose it; Apple and Google also provide the app stores and device permissions.
Grocery retailers: ICA or Coop receives data when you use that retailer's product matching or start checkout yourself in the retailer's web view, such as the chosen store and items and what you enter on the retailer's page. Server-fetched catalogue data does not by itself make other retailers recipients of your personal data.
Authorized staff: A limited number of administrators may read what is needed for support, security, and audit. The consumer directory in the separate admin app is limited to two narrow views.
8. Transfers outside the EU/EEA
Some providers may process data in the United States or other countries outside the EU/EEA. We use an adequacy mechanism where it applies and otherwise the European Commission's Standard Contractual Clauses (SCCs), with the technical and organizational safeguards described in the provider's agreement.
Google Gemini: According to Google, the paid Gemini API is covered by Google's data-processing terms, which include SCCs. The production project's paid status is being established. Read Google's data-processing terms.
Google Analytics: Google LLC is DPF-certified and states that it uses the DPF for transfers to the United States and SCCs when the DPF cannot be used. Read Google's analytics transfer information.
Vercel: Vercel is DPF-certified and its DPA includes SCCs as an alternative transfer mechanism. Read Vercel's DPA.
Neon: Smaklig's primary database is located in Frankfurt, so database storage and operation take place within the EEA and are not a third-country transfer. Neon's DPA includes SCCs for possible support or onward processing outside the EEA. Read Neon's DPA.
Resend: Resend is DPF-certified and its DPA includes SCCs for transfers not covered by adequacy. Read Resend's DPA.
Stripe: Stripe uses the DPF first for transfers to its certified US entity and SCCs as a fallback. Read Stripe's Data Transfers Addendum.
Upstash: Upstash states that it uses the DPF for receipt in the United States and SCCs if the DPF does not apply or ceases to apply. Read Upstash's DPA.
Apple: Apple states that international transfers from the EEA are governed by SCCs. Read Apple's Privacy Policy.
The applicable agreement version for each provider is checked. You can follow the links above or ask hello@smaklig.app for a copy or more information. We do not sell personal data.
9. Retention and deletion
Account, profile, conversations, and content you save are normally retained while the account is active. When you delete the account at /en/radera-konto, the account and directly linked records are removed. Shared household content may remain for other members, and limited information may be retained where law or security requires it.
Technical logs and diagnostics are retained briefly: normally 30–90 days depending on the data. For example, raw AI data is retained for 30 or 90 days depending on active health consent, meal photos for 30 days, and their analysis results for 90 days. Provider backups and logs are deleted on their own cycles.
Consent and email: Consent evidence is retained while the account exists and for three years after withdrawal or account deletion to demonstrate how the choice was handled. Unsubscribe tokens are valid for 30 days. Delivery logs, including an expired token copy, should be deleted within 90 days.
If you cannot sign in to delete your account, contact hello@smaklig.app. A de-identified record of the deletion request and information required for accounting or legal claims may be retained longer.
10. Email and marketing consent
Marketing is off by default. You choose separately between Campaigns & offers, Recipes & weekly menus, and News about Smaklig. You can turn off a category in settings or through the unsubscribe link; we check the current choice before every send.
Account verification, password reset, security notices, and other necessary service emails are transactional, not marketing, and are therefore not controlled by the marketing choices.
11. Cookies, analytics, and device storage
Necessary: Session cookies and similar storage keep you signed in, protect the service, and store basic choices. cookie_consent stores the web cookie choice for 12 months.
Google Analytics 4: Loaded only if a measurement ID exists and you consent. Consent Mode denies analytics and advertising storage by default. You can opt out by declining in the banner or deleting cookie_consent and choosing again.
Vercel Analytics: Mounted globally and measures page views, referrer, country, device, and browser without cookies. Vercel states that the data is aggregated and anonymous and that the visitor hash changes daily. It is not yet controlled by the same cookie choice; consent gating is an open improvement item. You can block analytics requests with browser privacy protection or contact hello@smaklig.app to object.
Mobile app: SecureStore and AsyncStorage store local session and feature choices. Camera, photo library, Apple Health, and Health Connect are used only after your choice and device permission, which you can revoke in device settings or Apple Health.
12. Your rights
Under the GDPR, depending on the circumstances, you may request information and access, rectification, erasure, restriction, and data portability, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing that was already lawful.
A signed-in user can download a JSON copy through the data export and start deletion at /en/radera-konto. The export has not been verified as complete for every current table. Therefore contact hello@smaklig.app if you want to exercise a right or obtain other data in a portable format. We may need to verify your identity, and statutory exceptions may limit a request.
If you believe we process your data incorrectly, you can lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
13. Automated decisions
Smaklig uses AI for recipes, menus, nutrition estimates, training content, product matching, and recommendations. You choose whether to use the result and should check it, especially for allergies or health. The feature does not make decisions intended to produce legal or similarly significant effects under GDPR Article 22.
14. Children
Smaklig is intended for people aged 18 or older. You must be at least 18 to create an account and use the service. We process health and nutrition data (a special category under the GDPR), and our AI features are provided via Google Gemini, whose terms do not permit services directed at or likely to be accessed by people under 18. Because the minimum age is 18, we do not seek guardian consent. If we learn that someone under 18 has created an account, we delete the data.
15. Security
The code uses measures including hashed passwords, encryption for selected tokens, secure sessions, validation, rate limiting, access controls, separate admin authentication, and audit logs. No technical or organizational measure can guarantee complete security. Contact hello@smaklig.app if you suspect your account or data has been compromised.
16. Changes to this policy
We update the policy when the service, providers, or legal requirements change and show the date above. For a material change, we provide notice in the service or by email. If a new or changed purpose requires consent, we ask for it before the processing begins.