Privacy Policy

Amu's Meal Tracker

Last updated: 18 September 2026
Effective from: 18 September 2026


1. Who we are

Amu Labs Ltd is the data controller for the personal data described in this policy. We are registered in England and Wales under company number 17175543, with our registered office at 43 Anerley Road, London, England, SE19 2AS.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC233555.

For anything about this policy or your data, contact support@amulabs.io. We aim to respond within 5 working days.

2. What this policy covers

This policy explains what personal data we collect when you use Amu's Meal Tracker, why we collect it, what we do with it, and what rights you have.

3. What we collect

3.1 Information you give us

Data When
Email address When you create an account
Password (stored only as a secure hash — we never see it) When you create an account
Meal descriptions you type Each time you log a meal
Photographs of meals you upload Each time you log a meal with a photo
Nutrition targets and body details you enter in settings (weight, height, age, sex, activity level, and calorie and macro targets) When you set them
Messages you send us, and anything you choose to include in them When you contact support, exercise your rights, or cancel

3.2 Information created by the service

3.3 Information collected automatically

We do not use analytics, advertising, or tracking cookies. We set only the strictly necessary cookies and local storage entries needed to keep you signed in. Because we set no non-essential cookies, we do not show a cookie consent banner.

3.4 What we do not collect

We do not require your name, postal address, date of birth or telephone number to create or use an account, and we never ask for your card details. You may choose to give us some of this information voluntarily when you contact support, exercise your data protection rights, or send us a cancellation request — for example if you use the optional model cancellation form. Where you do, we treat it as part of your support correspondence and keep it as described in section 7.

We do not buy personal data from third parties.

3.5 Health and medical information

Amu's Meal Tracker is a nutrition-tracking service. It is not designed to collect medical or health information.

Please do not include medical conditions, diagnoses, medications, treatment information, or other sensitive health information in your meal descriptions, photographs, goals or any other entry. Where the service asks which foods you avoid, it is asking about the food, not about any medical reason behind it — a food exclusion is all we need, and all we want.

We do not use your meal information to diagnose medical conditions, to infer health conditions from your food history, or to make any medical or clinical decision about you. The nutritional analysis the service produces is an estimate for your information only — see section 11 and clause 4.1 of our Terms of Service.

If you have entered something you would rather we did not hold, you can delete the entry at any time, or email support@amulabs.io to have your account deleted.

4. Why we use it, and our legal basis

Purpose Legal basis
Creating and running your account Performance of a contract
Generating nutritional analyses of your meals Performance of a contract
Taking payment and managing your subscription Performance of a contract
Sending service emails (confirmations, payment failures, notices of change) Performance of a contract
Responding to your support messages and data protection requests Performance of a contract, and legal obligation
Keeping the service secure and preventing abuse Legitimate interests — running a secure service
Debugging and improving the service Legitimate interests — a service that works
Meeting our accounting and tax obligations Legal obligation

Where we rely on legitimate interests, we have considered the impact on you and concluded that our interest does not override your rights. You can ask us for details of that assessment.

We do not use your data for marketing, and we do not sell it.

5. Who we share it with

We use the following service providers. Where they process personal data on our behalf, they do so under contractual data protection obligations. Some providers, including Stripe, may also act as an independent controller for particular processing needed to run their own services or to meet their own legal obligations — for example fraud prevention and financial regulatory compliance. Where a provider acts as its own controller, its own privacy notice governs that processing.

Provider What they do Data involved Where
Supabase Database and authentication Email, password hash, meal logs, subscription status London, UK (eu-west-2)
Vercel Hosting and serverless functions Request data, server logs Application functions configured for London, UK (lhr1); global delivery network
Stripe Payment processing and subscription billing Email, payment details (collected by Stripe directly), subscription records EU / US
Resend (Resend, Inc.) Sending service emails, including your subscription confirmation with the Terms and Cancellation Policy attached Your email address and the contents of those emails Processed in the EU (Ireland); Resend is a US company
Anthropic AI analysis of meal descriptions and photographs The meal text or photograph you submit US
fal.ai (Features & Labels, Inc.) AI generation of illustrative dish images The dish name — no account identifier or photograph is included US
Google Workspace Our support inbox Anything you send to support@amulabs.io EU / US

5.1 AI providers — what is sent, and what happens to it

We use two AI providers, and what we send them is very different in each case.

Anthropic — your meal content. When you log a meal, the description you type, and the photograph if you upload one, is sent to Anthropic to generate the nutritional analysis.

When you ask the service for meal suggestions or a weekly plan, we also send the preferences you have selected on that screen — your goal, any food exclusions, cuisine preference and calorie target — together with figures summarising the nutrients your recent logged meals were lower in. These preferences are not stored. They are held only while that screen is open, are sent with the request you have just asked for, and are gone when you leave the screen.

We use Anthropic's API under its commercial terms. Under those terms, inputs and outputs are not used to train Anthropic's models, and are automatically deleted from Anthropic's systems within 30 days. Where content is flagged under Anthropic's usage policy, it may be retained longer for trust-and-safety purposes.

fal.ai — the dish name. When the service produces an illustrative image of a dish, we send fal.ai the name of the dish — for example "spinach and chickpea curry with brown rice" — together with our own generic photography instructions, which are the same for every dish. We do not intentionally include your account identifier, your email address, your uploaded photograph, or any other account information in the request. Because the dish name is text you write, please keep it to a description of the food — see the note below.

We configure each request so that fal does not retain the request or the generated image beyond what is needed to serve it, and we copy the generated image into our own storage immediately.

fal is based in the United States. Its terms permit it to use anonymised and aggregated data derived from requests to improve and develop its services and models. Our requests carry the dish name and our own generic instructions, and are not accompanied by anything that identifies you.

Please keep meal descriptions to a description of the food. Do not include personal information about other people, or sensitive information about yourself. Once submitted, it is processed as described above.

5.2 Generated dish images are shared

Illustrative images generated from a dish name are cached in a shared store and may be shown to other users who log a similar dish. These images are generated from the dish name, not from your photograph, and are not linked to your account. Your own uploaded photographs are never shared with other users.

5.3 Others

We may also disclose personal data where we are required to by law, or to establish, exercise or defend legal claims. If our business is sold or transferred, personal data may transfer with it — we will tell you if that happens.

6. International transfers

Your account and your meal logs are stored in the UK. Our primary database is hosted in London, and our application functions are configured to execute in Vercel's London region. Vercel also operates a global network used to route and deliver the service.

Personal data may be processed outside the UK in the following circumstances:

Requests to fal.ai are also served from the United States. As explained in section 5.1, we do not intentionally send information that identifies you to fal.ai — the request carries the dish name you entered together with our own generic instructions. fal's data processing addendum incorporates the EU Standard Contractual Clauses and the UK Addendum to them.

Where personal data is transferred outside the UK, we rely on:

You can ask us for more detail about the safeguards for any particular transfer.

7. How long we keep it

Data Retention
Account and meal logs For as long as your account is open
After you delete your account Deleted within 30 days, except as below
Payment and transaction records At least 6 years from the end of the relevant accounting period, or longer where required by law
Server logs 24 hours, then automatically deleted
Support correspondence 2 years
Cached generated dish images Retained as part of the shared image store; not personal to you

8. Security

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours and, where the risk is high, tell you directly.

9. Your rights

Under UK data protection law you have the right to:

To exercise any of these rights, including to export your data as a JSON file or to delete your account, email support@amulabs.io. We will respond within one month. We will not charge you unless a request is manifestly unfounded or excessive.

We are building self-service export and account deletion into the app, and will update this policy when they are available.

10. Data protection complaints

If you think we have not handled your personal data properly, you can complain to us directly. Email support@amulabs.io and tell us what the problem is.

It helps if you include the email address on your account and what you would like us to do about it, but we will accept your complaint however you send it and we will not turn it away because it is not in a particular form.

When we receive a data protection complaint we will:

You also have the right to complain to the Information Commissioner's Office at any time — ico.org.uk, or 0303 123 1113. We would appreciate the chance to put things right first.

11. Children

The service is not intended for anyone under 18. We do not knowingly collect data from children under that age. If you believe a child has given us personal data, email support@amulabs.io and we will delete it.

12. Automated decision-making

The nutritional analysis the service produces is generated automatically by an AI model. It is an estimate for your information only — it does not produce any decision with legal or similarly significant effects for you, and no automated decision is made about you.

13. Changes to this policy

We may update this policy. If a change materially affects how we use your data, we will email you before it takes effect. The "last updated" date at the top always shows the current version.