1. Controller and Scope
The service is operated by Individual Entrepreneur Mikhail Yuryevich Pozyalov, Russia, TIN 583806559387, PSRNIE 323583500053483. This policy applies to the ПоПолочкам mobile app and service websites.
2. Data We Collect
The data depends on the features you choose to use:
- account and contact data: email, name, and language;
- user content: food photos, text, voice transcripts, meal diary, nutrition, hydration, weight, body parameters, goals, activity, and workouts;
- technical data: IP address, device and app identifiers, notification tokens, usage events, error logs, and crash diagnostics;
- access and purchase data: plan, payment or subscription identifier, and status. We do not receive or store bank card details.
3. Why We Use Data
We use data to create and protect accounts, analyze food, answer through the AI coach, maintain diaries and plans, sync devices, deliver selected notifications, process purchases, provide support, prevent abuse, and fix errors.
Depending on the data and applicable law, processing is based on performance of our agreement, user consent, legal obligations, or our legitimate interest in keeping the service secure.
4. Service Providers and Data Sharing
We use providers in the following categories to operate the service:
- hosting, data storage, and content delivery;
- AI processing of photos, text, and voice transcripts when a user starts the relevant feature;
- notifications, email delivery, product analytics, and crash diagnostics;
- payments and website abuse prevention.
On Android, the payment form is provided by the YooKassa mobile SDK. To issue a payment token, prevent payment fraud, and diagnose failures, it may share the IP address, technical identifiers, and device and app information with YooKassa and its technical providers, including AppMetrica. The payment SDK processes card details; ПоПолочкам does not receive them.
They receive only the data needed for a specific function. We do not sell personal data or use nutrition and body data for advertising. Providers must protect data under applicable law and processing terms. Data may be processed in countries where a provider operates when the transfer is permitted by law.
5. Retention and Security
Core data is kept while the account exists or while it is needed for the selected feature. Backups, security logs, payment, and accounting records may be retained longer for recovery, service protection, or legal compliance.
We use encryption in transit, access controls, and other reasonable safeguards. No storage method can guarantee absolute security.
6. User Choices and Rights
You can edit your profile, disable permissions and notifications, withdraw optional consent, or request access, correction, export, or deletion. Promotional email requires separate consent and includes an unsubscribe link.
7. Account Deletion
To delete your account, open Profile, choose Delete Account, and confirm. This permanently deletes the profile and associated user content. Data we must keep by law or for service protection is deleted or de-identified after the relevant period.
8. Changes and Contact
We may update this policy when features or legal requirements change. The current revision date appears at the top of this page. Questions, requests, and consent withdrawal: privacy@mail.eatsnapai.ru.