Privacy Notice
Last updated: April 25, 2026
1. Who we are
PlateAI is operated by STTLLC ("PlateAI", "we", "our", "us"). We are the data controller of personal data we collect about you when you use the PlateAI website and Service.
2. What we collect and why
| Category | Examples | Why we collect it | Legal basis |
|---|---|---|---|
| Account data | Name, email, password (hashed), profile picture | Create and secure your account; sign-in | Contract performance |
| Profile & preferences | Goals, diet, allergies, family size, budget, cuisines | Personalise meal plans and recipes | Contract performance |
| App content | Saved recipes, generated meal plans, favourites, streaks | Provide and improve the Service | Contract performance |
| Support communications | Messages you send us, support tickets | Respond to questions and resolve issues | Legitimate interests / contract performance |
| Usage & device data | IP address, device type, browser, pages viewed, error logs | Security, fraud prevention, performance, analytics | Legitimate interests |
| Marketing preferences | Newsletter opt-ins | Send product updates you've asked for | Consent |
Payment data (card details, billing address, tax info) is collected directly by our Merchant of Record, Paddle, and is not stored on our servers. See Paddle's Privacy Notice.
3. How AI features handle your data
When you use AI features (meal plan generation, dinner suggestions), your profile and prompt are sent to our AI processing partners to generate the response. We do not sell or use your prompts to train third-party models for other customers.
4. Who we share data with
- Service providers / sub-processors — hosting and database (Lovable Cloud, Supabase), AI providers (Google, OpenAI, and others routed via the Lovable AI Gateway), email and analytics tooling, and customer-support tooling.
- Merchant of Record — Paddle.com, for sale of subscriptions, payment processing, billing, tax compliance, and invoicing.
- Professional advisers — legal, accounting, and similar advisers where reasonably necessary.
- Authorities — when required by law, court order, or to protect rights, property, or safety.
We do not sell your personal data.
5. International transfers
Some of our service providers are located outside your country, including in the United States. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms to protect your data when it is transferred internationally.
6. Data retention
We keep your personal data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer needed, we delete or anonymise it. You can request deletion of your account at any time (see "Your rights" below).
7. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, secure authentication, and infrastructure managed by reputable providers. No system is 100% secure, but we work continuously to safeguard your information.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request deletion of your data ("right to be forgotten");
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent (where processing is based on consent);
- Lodge a complaint with your local data-protection authority (for UK/EEA users).
We aim to respond to requests within one month. To exercise any of these rights, email STTLLC at PlateAIhelp@gmail.com.
9. Cookies
We use a small number of essential cookies to keep you signed in and to remember your preferences. We may use privacy-friendly analytics to understand how the Service is used in aggregate. You can control cookies through your browser settings.
10. Children
PlateAI is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe we have, please contact us so we can delete it.
11. Changes to this notice
We may update this notice from time to time. If we make material changes, we'll notify you (for example, by email or in the app). The "Last updated" date at the top of this page indicates when it was last revised.
12. Contact
Questions about this notice or your personal data? Email STTLLC at PlateAIhelp@gmail.com.