Privacy
Privacy Policy
What personal data Food Info collects, why we collect it, where it's stored, and the rights you have over it under the UK GDPR and the Data Protection Act 2018.
Last updated:
Who is responsible for your data
The data controller is DCPNET LTD (Company No. 15734157, VAT 512 3682 13), trading as Food Info, of 30 Vane Close, Norwich NR7 0US, United Kingdom. DCPNET LTD is registered with the UK Information Commissioner's Office under registration number ZC168463, in accordance with the Data Protection (Charges and Information) Regulations 2018; its registration covers the processing activities described in this policy and is verifiable on the ICO public register. Questions about this policy can go to
What we collect
The free, anonymous parts of Food Info, searching foods and viewing nutrition panels, do not collect personal data on the server. Only the items below leave your device.
If you create an account
- Email address, used as your sign-in identifier and for password-reset emails.
- Password, stored only as a salted hash (PBKDF2 via ASP.NET Core Identity); we cannot read it.
- Display name, if you provide one.
- If you sign in with Google, the Google account identifier and the email Google releases to us. We do not receive your Google password.
- Account timestamps (created, updated, last sign-in attempt) for security and account-lifecycle purposes.
If you use the site signed in
- Your search-click history (which foods you opened) and your UI preferences (theme, default serving unit), stored against your account so the site is consistent across browsers.
- Food-diary entries, if you use the Tracker, each entry stores the food identifier, food name, the date you logged it for, the serving size in grams, and a snapshot of the nutrient values for that serving. These are stored against your account so the diary follows you between devices.
Stored on your device only
- An access token, refresh token, theme preference, anonymous search history and any food-diary entries you log while signed out are kept in
localStorageon the device you used. They never leave that device unless you later sign in, at which point they are merged into your account. See the Cookie Policy for the full list of storage keys.
About the food diary specifically
The diary records what you chose to log, not anything inferred about your health. We do not treat diary entries as special-category data under UK GDPR Art. 9, because they describe foods eaten, not diagnoses, conditions, or treatments. We still apply the same security controls to diary data as to the rest of your account record, and you can delete an entry from the Tracker page at any time.
Analytics
Food Info loads Google Analytics 4 on its pages. It is off by default until you grant consent via the cookie banner on first visit, and you can withdraw consent at any time using the Cookie Policy page's preferences button.
- Google Analytics 4, when allowed, Google receives your IP address, device and browser characteristics, the pages you view, and approximate location (city-level, derived from IP and then discarded). Google processes this to give us aggregate visit and page-level statistics. Cookies and retention windows are itemised in the Cookie Policy.
We use Google Consent Mode v2 to communicate your choice to Google. While consent is denied, Google's tags load only in cookieless-ping mode and do not write the cookies described in the Cookie Policy.
Why we collect it (lawful basis)
- Performance of a contract (UK GDPR Art. 6(1)(b)), for account creation, authentication and the synced features that depend on a signed-in account.
- Legitimate interests (Art. 6(1)(f)), for security logging, abuse prevention, and keeping the service running. We balance these against your rights and minimise what we collect.
- Consent (Art. 6(1)(a)), for setting analytics cookies (Google Analytics 4). These are off by default; consent is collected via the banner and can be withdrawn at any time from the Cookie Policy page. PECR reg. 6 also requires consent for the same cookies and we treat that requirement and the UK GDPR Art. 6(1)(a) basis as one combined ask.
We do not sell your personal data. Aside from the analytics activities described above, we do not use your data for marketing, automated decision-making, or any processing not listed in this policy.
Who we share it with
Food Info uses a small number of carefully-chosen third-party services to operate the site. We have a written data-processing agreement with each of them and only the data strictly necessary for the relevant service is shared.
Payment processing
- Stripe Payments Europe Ltd (Dublin, Ireland), with its subprocessor Stripe, Inc. (San Francisco, United States), processes every payment, manages your subscription, hosts the customer-portal cancellation flow, and issues receipts. Stripe receives your email address, payment card details (which we never see ourselves), billing address and the metadata needed to reconcile the transaction.
Transactional email
- Resend, Inc. (San Francisco, United States), delivers account-confirmation, password-reset, refund, security and (if you opt in) marketing emails. Resend receives the recipient address, subject and the email body itself.
AI meal-plan generation (Pro tier only)
- Anthropic PBC (San Francisco, United States), generates the AI meal-plan output when you click "Generate plan". Anthropic receives the free-text fields you entered (goal, diet, avoid list, calorie target), the relevant nutrient gaps computed from your last two weeks of diary entries, and the system prompt that instructs the model. It does not receive your email address, password or any other account identifier, only an opaque generation id used to bill our metered usage.
Analytics (consent only)
- Google Ireland Limited (Gordon House, Dublin 4, Ireland) and its subprocessor Google LLC (Mountain View, United States), operate Google Analytics 4 when you have granted consent via the banner. Google Ireland is our processor for Analytics. Their own privacy notice applies to data Google holds about you. Google LLC is also the entity you authenticate against if you choose "Sign in with Google".
Infrastructure
- Fly.io, Inc. (Chicago, United States), operates the application servers that run Food Info. Process every request you make to the site.
- Neon, Inc. (Brisbane, California, United States), hosts the Postgres database in which your account record, diary entries and subscription state are stored. Configured to run in our Europe-West region; the operator entity is US.
- Cloudflare, Inc. (San Francisco, United States) and its UK affiliate Cloudflare Ltd, provide DNS, edge routing and DDoS protection. Cloudflare can see request headers (including your IP address and user-agent) but request bodies are encrypted to our origin servers.
We do not share your data with marketing networks, data brokers, social-media trackers, or third parties outside the operations described here.
International data transfers
Several of the services above are headquartered in or processed in the United States. Where personal data is transferred outside the United Kingdom, we rely on one of the following Article 46 safeguarding mechanisms:
- For Stripe, the Stripe UK Addendum to its EU Standard Contractual Clauses, plus the EU Commission's Data Privacy Framework adequacy decision where applicable.
- For Resend, the Resend Data Processing Agreement and the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (UK IDTA).
- For Anthropic, the Anthropic Data Processing Addendum and the UK IDTA.
- For Google, the Google Cloud Data Processing and Security Terms plus Google's published international data-transfer terms.
- For Fly.io, Neon and Cloudflare, the UK IDTA with the respective Data Processing Addendum.
Transfers within the European Economic Area (Ireland in particular) rely on the UK Government's adequacy decision for the EEA and do not require additional safeguards.
How long we keep it
- Account records (email, password hash, display name, linked Google identifier) are kept while the account is active and deleted within 30 days of account closure.
- Synced preferences, search history and food-diary entries are kept against the account while it is active and deleted with the account.
- You can delete an individual diary entry yourself from the Tracker page at any time.
- Application logs are kept for up to 90 days for security and operational diagnostics, then rotated out.
- Contact-form submissions, name, email, message, IP address and user agent are kept while the case is open. IP address and user agent are nulled 90 days after submission, and the entire row is deleted 2 years after the case is marked resolved.
- Payment records, Stripe retains payment records for 7 years to comply with HMRC record-keeping rules; we keep only the Stripe customer identifier and the period(s) you were a paying customer. Receipts can be retrieved at any time from your Stripe customer portal.
If something goes wrong
If a personal-data breach affects Food Info, we will notify the UK Information Commissioner's Office within 72 hours of becoming aware of it, as required by UK GDPR Art. 33. If the breach is likely to result in a high risk to your rights or freedoms, for example exposure of email addresses, account state or diary entries, we will additionally notify you directly without undue delay, explaining what happened, the likely consequences and the measures we are taking, as required by Art. 34. We will post a notice on the home page describing the incident at the same time. Our internal incident-response runbook is reviewed annually.
Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal data we hold about you (right of access).
- Have inaccurate data corrected (rectification).
- Have your data erased, i.e. close your account (erasure / "right to be forgotten").
- Restrict or object to processing in certain circumstances.
- Receive your data in a portable format.
- Withdraw consent at any time, where consent is the lawful basis.
The fastest way to exercise the rights to access, portability and erasure is through your Account page, "Download my data" returns a single JSON file of every record we hold about you; "Delete my account" cancels any active subscription and irreversibly clears every satellite record by user id. For rectification, restriction or objection, or if you'd prefer email, write to
How we protect it
Passwords are hashed using ASP.NET Core Identity's default PBKDF2 with a per-user salt; we cannot recover them. Authentication uses bearer tokens with a short-lived access token and a separate refresh token. All traffic is served over HTTPS in production. The data-protection keyring is encrypted at rest using a certificate held outside the source repository. A more detailed technical summary is in the Security Report.
Children and the ICO Age Appropriate Design Code
The free, anonymous browse of nutrient data is open to anyone. Free accounts are intended for users aged 13 and over (in line with industry practice for online services that store personal data); paid plans and AI credit packs require you to be 18 or older because minors cannot validly enter paid contracts under English consumer law. We confirm this at the Stripe checkout step.
For any user who may be under 18, we have applied the ICO Age Appropriate Design Code's standards by (a) defaulting analytics cookies to off until explicit consent is granted, (b) collecting only the personal data strictly necessary for each feature, (c) never sharing diary entries with third parties, and (d) offering parental contact at the email address below. If you believe a child under 13 has created an account, please contact us and we will delete it.
Changes to this policy
We will update the "Last updated" date above whenever this policy changes. Material changes will be highlighted on the home page for at least 30 days.